Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, 7 May 2014

10 Computer Tricks Every Geek Should Know

We've talked before about the things every computer user should know how to do, but we geeks are special: we want to go above and beyond, to explore every nook and cranny of our system and make everything easier. Here I, Anubhav Sachan ,would be telling you ten ways to do just that.


1. Program Your Own Dead Simple Scripts
You don't need to learn an entire programming language to write advanced scripts. Windows users can do a ton of awesome stuff with AutoHotkey, from creating simple keyboard shortcuts to controlling their PC remotely. To get started, just check our beginner's guide to AutoHotkey and our list of the best AutoHotkey tricks. Mac users don't have anything quite like AutoHotkey, but you can do quite a bit with the built-in, insanely easy-to-learn AppleScript. If you aren't the coding type, check out Automator on the Mac and its clone, Actions on Windows
When all is said and done, this is probably way more than 10 tricks, but if you don't know any of the below, they should keep you busy for awhile. If you have an idea we didn't list, be sure to mention it in the comments below.

 
2. Squeeze More Power Out of Your Hardware
With a bit of tweaking, you can push your hardware past its original limits and get some pretty serious bang for your buck. When it comes to your PC, you can overclock your processor and video card, and even install OS X on non-Macs by building a Hackintosh. And, while you're at it-even though it isn't a computer trick specifically-you should try turning your $60 router into a $600 router with DD-WRT.


3. Run a Basic Linux Distribution
Even if you don't want to switch operating systems, knowing a few Linux basics can be really handy. With a live CD on hand you can troubleshoot your machine, revive an old, slow PC, and make your way through Linux-based DIY projects. Check out our five-part guide to getting started with Linux, and be careful-it can be quite the rabbit hole once you get into it!

 
4. Navigate Everything With Your Keyboard
There are certain basic keyboard shortcuts everyone should know, but if you really want to use your computer more efficiently, you can take it so much further. Learn the most common shortcuts for your favorite programs, like Gmail, Microsoft Word, basic text boxes, and even Facebook. After a little while, you'll be able to blow through menus and text boxes with unbelievable speed. Check out our guide to becoming a keyboard ninja, complete with a bunch of cheat sheets to help get you off the ground.


5. Learn to Crack Passwords (and Protect Yourself)
Everyone should know how to create a secure password, but responsible geeks can take it a step further by learning how to break into a comptuer. This skill-whether used on a Windows machine or a Mac-can really help you understand how computer thieves and hackers will try to get at your data. Learning the process means you know how to protect yourself against the process-not just with strong passwords but with encryption and other settings tweaks that keep thieves out. Similarly, you may also want to learn how to crack a Wi-Fi network's WEP and WPA password.


6. Know Your OS's Hidden Features
Every operating system has hidden things lying under the hood, you just have to know where to look. Windows users should check out the hidden features of Windows 7 and Windows 8, while Mac users should peruse the hidden features of OS X Lion and Mountain Lion. If you want to find even more, you can often find them in Windows' Registry or in OS X's terminal. System tweakers like Ultimate Windows Tweaker, OnyX for Mac, and Ubuntu Tweak are also great places to find secret features.
 

7. Run Everything on a Schedule
Stop performing all that system maintenance yourself and set it all up to run on a schedule. With Windows' built-in Task Scheduler, you can run just about any kind of task-whether it's maintenance, picture uploads, or even a simple alarm-through Windows' built-in tools (in fact, it's one of the best Windows 7 features you've probably forgotten about). Mac users looking for something similar should check out Tasks Till Dawn.


8. Read and Understand Your Resource Usage
When your computer starts acting a little slow, a lot of people jump to their resource monitor to see what's causing problems. However, just looking at a bunch of charts and graphs isn't going to tell you what's wrong unless you really know what you're looking for. High CPU is a common problem with one app slowing your system down, and as soon as you close it, the issue should go away. High network activity could be the cause of slow internet or slow file transfers over the network. RAM usage, however, is where a lot of people get thrown off: high RAM usage isn't inherently a bad thing. Know the difference between good and bad RAM usage before you start blaming processes. If you want to keep an eye on your resources, check out our favorite system monitors for Windows, Mac, and Linux, too.
 

9. Use the Command Line Like a Ninja
Using the command line isn't as exciting as it looks in the movies, but it can be a very useful tool (in fact, some tools are just better in the command line). It's pretty easy to learn, too-check out our command line primer for beginners to learn some basic commands. Once you've got that down, read up on the best shortcuts that help you navigate the command line like a ninja. Those guides apply to UNIX-based systems like Linux and OS X, but if you're a Windows user you can grab something like Cygwin to get a similar experience (or, if you want a more Windows-centric tool, try Powershell).


10. Find New Uses for the Programs You Already Have
Chances are, you've probably already found a few awesome tools and added them to your productivity arsenal, but most programs can be used for more than just their inteded purpose. The file-syncing Dropbox, for example, is also great for monitoring your home computer, printing files from afar, and even downloading stuff with BitTorrent. Savvy folks can use Gmail to store files in the cloud or find out if someone's stolen your laptop. Any tool can become multipurpose if you know its ins and outs.

 
 

Sunday, 20 April 2014

Cloud security challenges go all the way to the board



Short Description: "Less hardware, scalable infrastructure, falling prices and maturing services all make cloud computing very difficult to ignore. Organisations must ensure they don't also ignore the security challenges of cloud models."




 In the rush to take advantage of cloud's benefits, businesses must properly manage the risks of handing over data, systems, and infrastructure to a third-party.  As with any risk management process this is a challenge for the board as much as for the technical security team. 

Security keeps cropping up as a (if not the) major obstacle to cloud adoption — whether it’s applications or infrastructure that is hosted in a private, hybrid or public cloud environment.
But are concerns about security in the cloud misplaced? Evidence in the 2013 Data Breach Incident Report from Verizon (which also owns cloud provider Terramark) suggests it is. Based on 47,000 breach investigations in 2012, Verizon notes that "attacks against virtualisation were not present, but attacks against weakly configured devices that happened to be hosted in an external location were common — but not more common than among internally hosted ones."

Do CIO's agree with these facts? Yes and no. For every CIO who believes cloud security concerns are overrated, there's another who believes cloud security issues are very real.

However, whether security concerns about the cloud are exaggerated or not isn't the question under discussion here. The key issue for businesses considering moving a workload to the cloud is to quantify and address risks; from assessing which applications or infrastructure can be moved to the cloud with an acceptable level of risk, to how they will be protected once moved. 


Cloud security: Same concept, different implementation

While the same concepts behind on-premise security management apply in the cloud, there are nuances in their implementation that may escape the board-level view, but could nonetheless be vital.
For example, customers may find security tools they're familiar with on-premise are stripped back in the cloud. Network access controls are just one example. 

"Network access controls are typically far more basic in the cloud compared to physical architectures, and the tools used to manage the access controls are also more basic. This can lead to poorly implemented network access controls that lead to unnecessary access to systems and services," said Ty Miller, founder of security firm Threat Intelligence. 

"Physical security appliances ensure high performance and can be made highly scalable with low level networking to load balance packets across multiple security devices. Cloud environments are designed to be scalable, but some virtual security devices don't have the same performance as their hardware equivalent."

So how should businesses go about security risk management when considering cloud service providers?  Those considering the cloud can be confronted by providers that only offer opaque visibility into how they manage security and data. But isn't that scenario also true when assessing a provider of closed-source software or an outsourcer that offers assurances based on service level agreements? 

The customer needs to build a framework to assess a provider and compare them with rivals but not overburden the provider with assurance requirements. In the end, the rigour of the risk assessment process comes down to the depth of research a buyer is willing to go into ahead of making a commitment. 

"The first thing we're talking to clients about is that not all clouds are equal," said Intelligent Business Research Services security analyst James Turner. 

"A prospective buyer should research what the cloud vendor is prepared to commit to. Most cloud vendors have realised that committing to SLAs has to be a token gesture that immature buyers will pay attention to."

Different maturity levels on the buyer-side explain why, in a recent survey (pdf) by cloud-management vendor RightScale, a third of 'cloud beginners' saw security as the major obstacle to moving to the cloud, but only 13 percent of 'cloud focused' organisations (those that make "heavy use' of cloud) shared that view. 

"Mature buyers will know that no amount of service credits can ever replace the business impact of a cloud failure. Cloud vendors are in the unenviable position of offering to provide outstanding business service and at the same time, putting themselves on the hook for protecting their customer's information assets," said Turner.

The mega-bug outlier and the perennial question of data sovereignty
Last week's discovery of a security hole, dubbed Heartbleed, in OpenSSL should give pause for thought to anyone weighing up risks in the cloud. Implementing OpenSSL on a web server should have provided encrypted communications over the internet, but instead, could be abused to leak user passwords, private keys and session tokens. 

The flaw affected components of on-premise systems, private clouds and public cloud providers. But it has different ramifications for the buyer, signs that a service provider supports good security practices turned out to be a major vulnerability. How does a buyer asses that?
Before Amazon Web Service applied the Heartbleed patch, its elastic load balancers were vulnerable to the bug. 

Microsoft's popular web server IIS is immune to the bug, but it's not uncommon today to rely on a cloud provider for backup services, such as Amazon Web Service's (AWS) Elastic Load Balancer. 
"There are definitely lessons that have been learnt via the Heartbleed vulnerability in relation to risks introduced by cloud providers," Ty Miller, CEO of Threat Intelligence told ZDNet.

"The AWS load balancer could still be exploited to capture your private SSL certificates, and potentially usernames, passwords and session cookies."

Fortunately, bugs like Heartbleed don't come along every day. A more persistent issue has been data sovereignty and the fuzzy legal risks that come with shifting data to a different jurisdiction. It's a deal-breaker for many government agencies and some regulated industries, particularly for those outside the US.

Sweden's Data Inspection Board last year undertook legal action against one municipality and several schools that migrated from on-premise systems to Google Apps. In addition to data sovereignty concerns, Google's standard contract, in the Board's view, gave too much leeway for it to do as it saw fit, which conflicted with the organisations' duties as a "data controller".
The Swedish cloud cases occurred against the backdrop of a much bigger shift within the European Union, which updated its Data Protection Directive amidst calls by some Members of European Parliament to cancel the US-Europe Safe Harbour Act that had allowed some US firms to process data about EU citizens outside the continent.  

"As part of any migration to the cloud, enterprises need to ensure they are aware of and comfortable with the locations where the data will be stored and the legal implications associated with those locations," said Craig Searle, head of cyber for BAE Systems' Applied Intelligence in the Asia Pacific region.  

These are weighty issues that go past the technical and into the legal and management sphere, and demonstrate why it's so important board level executives are on top of cloud security challenges and exposures.