Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, July 25, 2011

RoboForm for iPad

Church communicators often have multiple online account logins -- web site administration, email administration, blog accounts, YouTube accounts, etc. These can be a nightnmare to remember if you adopt good security practices of using multiple user name s and different passwords everrywhere.

The solution is to use good password mamnagement software. Roboform is one such program.

RoboForm Everywhere 7 now is available for iPad 2, iPhone, and iPod Touch. It requires purchase of an annual subscription to RoboForm Everywhere. RoboForm Everywhere is a "cloud solution" that keeps your web site, login name, and password data on a remote server.
I wanted to know how the app compares with the Roboform Desktop/laptop edition. Here's what I found so far...
  • Tough to contact. I had a hard time finding out how to contact the RoboForm developer (Siber Systems) by email to ask some questions.
    Here's the tech support URL -- they reply by email.
  • Annual ssubscription fee. The 1-yr. subscription cost is currently discounted to $10. Added years are the normal $20. I'm not sure I like that. The Desktop edition lets you keep one version for several years and get updates for the version you buy free. New version upgrades cost $20. I guess that their rationale is that the RoboForm Everywhere edition can be used on multiple computers. Also, this cloud subscription service is in keeping with the software industry cloud service fee schemes. But to me it smacks of a way to keep the dollars flowing for the developer.
  • App security issue. I do not like being limited to a 4-digit PIN for access to the RoboForm app itself. It should allow at least the option to use a strong password (upper case letters, lower case letters, numerals, and symbols). After all, this one app password opens up a storehouse of all your key web sites, login names, and passwords. The reply to my question about this from Siber Systems is that PIN to access the app is in addition to the complex password you can use to access your actual Roboform data stored online. But since the iPad iOS 4.0 and higher lets you choose a 4-digit PIN or a complex password, as an app dealing in information security, I'd like to see RoboForm adopt that option too.
  • Data protection. Like with many cloud services, the quality of protection your data gets is at the mercy of the company that stores your data. Banks, credit card companies, and other businesses keep showing up in the news as getting hacked. So if you always keep your own computer patched and always practice safe computing, you may want to use the local desktop/laptop version. 
  • Convenience vs. security trade-off. Using Roboform Everywhere to store information at a remote server and be able to access it from anywhere may be too tempting to pass up.
Related links

Monday, July 18, 2011

Managing a lot of passwords

I have tons of web sites that require logins and passwords. Remembering them all is not really feasible, since I use a different name and password for most sites. So I researched password manager programs.

I like RoboForm for managing web site login names and passwords. The program is available for the below Operating Systems:
  • Windows
  • MacOS
  • Linux
RoboForm also has three "flavors":
  • RoboForm Desktop.
    This edition is for one desktop or laptop computer. The encrypted password-related files are stored on that computer. If you use this solution, remember to "back up" your lengthy site, login name, and password data and store it somewhere other than on your computer.
  • RoboForm Everywhere.
    This is a cloud solution. Your login and password data is stored on remote servers. Since the solution is a cloud one, your login and password data is available from any computer with Internet access. I'm personally hesitant to blindly trust most companies' information system security, but the choice is there. Using RoboForm on a mobile device requires this edition.
  • RoboForm2Go.
    This is portable solution for one USB flash drive. This may be a handy solution if you use both a desktop and a laptop, as you could use RoboForm2Go on the USB drive on each computer. The license is per USB drive, not per computer.
Platforms supported by RoboForm:
  • Desktop/laptop
    • Internet Explorer
    • FireFox
    • Chrome
    • Opera
    • Safari (MacOS)
  • USB Drives (RoboForm2Go)
    • U3 flash drives
  • Mobile (app is free, but use requires the RoboForm Everywhere edition)
    • Android
    • iPad, iPhone, iPod Touch
    • Blackberry
There are other program managers on the market, but I'm fond of this one. It also originally came recommended by Fred Langa (Senior Editor, Windows Secrets newsletter), which encouraged me to check it out.

I'll report on RoboForm for an iPhone/iPad/iPod in a future post.

Friday, July 08, 2011

Password tips

Anyone associated with a church web presence usually has a slug of sites and passwords they need to remember.

Some cautions and tips for login names and passwords.
  • Use a different login name for different web sites.
  • Avoid using your real name as any part of your login name.
  • Don't use the same password for multiple web sites. Use a different one for each.
  • Make passwords strong (8 or more characters plus a mix of upper case letters, lower case letters, numerals, and symbols such as ^). Ideally, use 13 or 14 total characters.
  • Don't use any part of your name, birthdate, pets names, etc. in your password -- nothing a criminal could pull from some part of the web (including a social media profile you think is "locked down").
To help you remember passwords, use a long passphrase, then adjust for the character mix as above. A password/phrase that is at least 13 characters is very hard to crack.
Example: Thyrpualptaftcmaa is the first letter of each word in the prior paragraph's first sentence. We can then adjust that and change some to characters, insert numerals, and remove a couple letters to set the total here to 14: ThYrPu^13ptae$
If you feel the need for good password manager software, stay tuned for a future post "Managing a lot of passwords".

Thursday, March 19, 2009

Don't catch a "Social" disease

Social networking sites are quite popular these days. But the very nature of these sites makes them ripe for criminal activity. In order to protect both your own personal information and that of your family and friends, you'd need much tighter security and less information sharing than social networking demands.

Below are a few quotes that should make you shudder and "go very slow" if approached about your church setting up a page on a social networking service. Can you justify deliberately adding risk for your church's children and members as well as its visitors?
  • "With more than 150 million members worldwide and a huge amount of data on every user, [FaceBook] is a dream come true for spammers and identity thieves." (WindowsSecrets newsletter)
  • "[Facebook] site has been hit by five separate security problems in the last seven days, say security experts. ... Security firms warn that the popularity of social networking sites makes them a tempting target for hi-tech thieves." (BBC news)
  • "Get used to this [Koobface worm attack]. I think we'll see a steady stream of these kinds of stories with malware propagating via social networking contacts throughout the next few years. And, given the increasingly flexible APIs the social network sites are implementing, bad guys will be able to mine this information for attacks far more effectively." (SANS Security Newsletter)
  • "In an analysis of cyber crime activity in the 2nd half of 2007, security vendor Symantec Corp. found that two social networking sites [FaceBook and MySpace] together were the target of 91 percent of U.S.-based phishing Web sites." [And it will likely only get worse] (The Washington Post)
If you insist on taking personal risks with your own computer and identity and that of your family, at least consider the impact on your friends if they get infected, attacked, or scammed after visiting your web site or using the social network more extensively after visiting your site.

Churches place great emphasis on providing a "Safe Sanctuary" for children. But they leap onto FaceBook without any concern for their congregation or the visitors they hope will visit there. Taking some teens on a picnic lunch in a park is a great idea. But if that park is a known hangout for drug pushers, muggers, and rapists, we would never take them there.

Yet most churches ignore the very real (and increasing) criminal activity related to social networking sites because the sites are neat, modern, and popular. Churches need to do better at protecting our children, members, and web site visitors. Fun and fad should never trump the safety of our flock.

Maybe it's time for a "Safe Web" policy for churches. Does your church have such a policy? Does it enforce it?

The US-CERT governmental organization has issued some tips for people who just have to risk everything and have a social networking page/site. (See the US-CERT tips) These tips appear aimed at getting teenagers to be less naive about Internet use in general, but there are lots more steps that people should take. Why don't many take these steps? Because if they followed them, it would take some of the "fun" out of their (risky) surfing. Here are a few:
  • Never use your real name in your email address. Give away as little information about yourself as possible.
  • Use disposable email addresses when singing up at online stores or services (including social networking sites). If an address starts getting tons of Spam, you may be able to determine where it came from. You may even be able to alert a "friend" that their computer may be infected and that any email addresses on it may have been "harvested".
  • Whenever possible, do not give out your real name or other information that identifies you personally.
  • Do not identify other people by name, especially a full name, while online.
  • Always provide the minimum required information when signing up for a service or buying a product. Don't fill in every field on a form just because it's there.
  • Never "assume" that Jane Doe is really Jane Doe, even if "she" has a cute photo icon that is really her and she's using "her" email address. Anyone can copy images that appear on the web. And criminals steal email addresses all the time.
  • If you want to share photos, use a photo service such as Google Photos or Flickr. Don't use a social networking site for photos. That's just one more thing the criminals can steal.
  • Avoid associating personal information with online photos.
  • If you really must create a social networking page, tighten the security by customizing the configuration. The social networking site usually has info on how to do that. But the default for nearly all social networking sites is very "open" and not very secure.
  • Be paranoid. Be very, very paranoid. It's a good and righteous thing to be paranoid when the "bad guys" really are "out to get you"!

Wednesday, March 15, 2006

Analyze church computers for security

You, like many web developers at churches, may well be one of the people (or the only one) who gets asked to help with "computers" -- you know ... recommending what to buy, installing them, installing software, helping with problems, educating users, ...

If so, you should download, install, and run on those computers the latest Microsoft Baseline Security Analyzer (MBSA) -- version 2.0. MBSA not only checks security patch status, but also will look at several other aspects of system security and give you cautions and advice.

You may also want to check out the Puter Gnome blog, which often has security tips.

Friday, March 10, 2006

Protect your Blogger blog from splog

Creating and using a blog via Blogger is fast and easy. So many have joined the rage. But it seems that sometime in the summer of 2005, spammers caught onto the "opportunities" that blogs presented. Thus started two types of unsolicited annoyances -- spamming of blogs ( splog) and creation of blogs solely to link to other blogs and web sites to try to drive traffic and search rankings to them. The other sites are notoriously worthless or worse.

Google bought Blogger and offered free blogs. But soon the splog activity was overwhelming them and seriously aggravating actively blogging Blogger bloggers (I couldn't resist). Problogger.net slammed Blogger and asked if it was a haven for sploggers. It even suggested that blog search sites might have to start excluding blogspot.com blogs. Google responded to these threats to the blogosphere:
  • They added a word verification option for adding comments to a blog posting. If you an Admin of a blog, you should turn this feature on in self defense.
  • They added a "Flag" button in the blogger navbar. Clicking it alerts Blogger that someone finds the blog offenseive or against the terms of service. Unfortunately, some sploggers have found a way to leave the navbar displayed but hide or delete the Flag icon.
  • Supposedly, Google now reviews blogs that are included in their "Next Blog" (using the navbar), but it's not totally effective. Some still slip through. Actually, it's not just "some". One check of 50 "Next Blog" clicks revealed about 20% were splogs.
Other reading about splogs:
Splog Reporter, Started 8/20/2005 in response to spamming of blogs. It equates sploggers with terrorists.
How to fight surging splogs. Wired Mag offers tips and a bit of background.
Splog Reporter adds Firefox extension
Splog Spot lets you search for splogs! Really! It bills itself as the world's largest splog database.
Fight Splog! reports 442 servers splogging.
Blogging industry infected with splog flu