Showing posts with label technology. Show all posts
Showing posts with label technology. Show all posts

Tuesday, April 3, 2018

Keeping Up with the Podcasts!

   I listen to a lot of podcasts.  Probably way to many.

   But podcasts are just such a great way to keep up with timely information in security, technology, news, finance, sports and other topics.  So I listen... a lot!

   I did a post on this topic nearly 6 years ago!  In that post I provided a list of podcasts.  It's way short compared to the list I'll be sharing here.  I also wrote about using podcasts as a learning resource here and here.

   Before I provide the actual list, here are few important notes:

  • I’ve tried to put these into categories
  • Within each category, the order is not how much I like the podcast but just the order they are in my podcatcher (and that order has little rhyme or reason)
  • Yes, I am crazy
  • Yes, I do constantly have earbuds in my ears
  • I do use a podcatcher that has variable speed and I typically listen at 2.2x! (I still use DoggCatcher)  Yes, we’ve already established that I’m crazy.  And, I have a lot of casts to get through.
  • Some of these podcasts may no longer exist.  Since my list is so long, if some drop out of existence I really don’t notice unless they are one of my few top favs.
  • I actually left some off – I have an casual interest in real estate investing and subscribe to 6-8 casts on that subject
   With that... let's get to the list!

Tuesday, March 13, 2018

We Encounter a Serious Issue



   I just received this voice message on my home phone (landline).

   Here's the text:
   We encounter a serious issue coming out of your computer.  It seems to be someone is trying to hijack your computer and try to steal your personal information.  If it's not fixed right away then your computer will become obsolete and all of your credential information may got compromised.  If you are the one who is using Microsoft Windows in your computer then please call 302-316-9259 or press 1 now to speak with security team now.  Please ignore if we called you by mistake.  Thank you.

   The only serious issue here is that people fall for these scams.  Let's break it down:
  • The Voice - who wouldn't believe a bad computer-generated voice?  Seriously though, there are plenty of pre-recorded and generated junk voice messages we get all the time.  My general rule of thumb - ignore them all and erase is your friend.
  • Bad Grammar - this is practically a throw-back to the old days of spam.  I've written about this in the past.  Someone willing to get past the bad grammar is more likely to continue on to other poor choices.
  • Fear Factor - the message is playing on many people's fear of technology and loss of their personal information.  While we've become almost numb to breach announcements, the idea that there is an attack on our personal home computer is still a scary concept.  Words like "hijack", "steal", "obsolete", and "compromised" invoke fear.
  • Call To Action - "if it's not fixed right away...".  For a person who doesn't understand the complex issues of their computer, the call for immediacy further plays upon the fear state.
  • Microsoft Windows - what are the odds that if a call was made to any household, someone would be using, or would have used int eh past 24 hours, Microsoft Windows?  I'd guess that's pretty high.
  • Politeness - bad voice and grammar aside, the call does say please and thank you.  That further instills a sense of confidence in a person already affected by fear and the call to action.

   As I covered in a past posts, while I did not call the number (and I suspect it's already been disconnected), if I did get through to someone I bet that they would be very helpful!  That is, as long as I was cooperating.  If I was not forthcoming with information, then these kinds of folks often get forceful.

   Obviously, the best course of action is to just have a good laugh and hit delete when you get a message like this.  We also need to assure that less technical, or more vulnerable, people understand the issues and are prepared when the call comes.

   Have you, or someone you know, received a call like this?  What happened?

Tuesday, April 11, 2017

Cyberbullying and the New Math

   According to Cyberbullying Research Center, the National Crime Victimization Survey (NCVS) is a large-scale data collection effort led by the U.S. Census Bureau and the Bureau of Justice Statistics.  This study has been going on since 1973.  In 1989 they added supplemental questions focused on school-related incidents, and stepped this up to a more in-depth biennial survey in 2005.

   Cyberbullying is still a major issue.  It's been over 4 years since I've written on this subject.  While there is perhaps more visibility, the basic problems haven't changed.

  Based on the above benchmark, at first glance, bullying appears to be trending down over the past decade.


   While there have been some high-profile cases over the years, this is a real, current and ongoing issue.

Tuesday, October 8, 2013

Online Self Defense - Your Computer

   It's Cyber Security Month!  And the more things change, the more they stay the same.  The key advice for online self-defense I've given in the past is just as true now.  So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.



   Happy US Cyber Security Month!  This partnership between Homeland Security, NCSA and MS-ISAC is an opportunity to recognize the importance of information security.  How are you celebrating?

   Last week I ran a couple of sessions at work on awareness and security.  Over the next few posts I will be reviewing some of the 3 themes I covered in a talk entitled "Online Self-Defense". You can view the slides on my slideshare page. (actually, the talk focuses on just 2 of the themes but that's OK!). Since everything comes in threes (omne trium perfectum), I will give 3 easy tips for each theme (and some bonus tips as well).

   The first theme is protecting your computer or device.

Tuesday, October 1, 2013

Things That Make Me Crazy: "We've Always Done it This Way"

   There aren't many things about our InfoSec and IT industry that really bug me.  There are certainly things we can do better.  We're really just starting to get the idea of connecting with the business and that business leads technology (not the other way around).  Or that security controls and technology have to work for people.  These ideas are part of our evolutionary process.

   But there are some things that do get to me.  Call them pet peeves (what a strange phrase!),
annoyances, complaints... whatever.

   Right at the top of the list is when someone says "We've always done it this way".

Tuesday, September 10, 2013

What Works in Tech #Leadership - Keep It Simple

   As I'm heading toward the end of my current job, and getting ready for the challenges of my next opportunity, I've been thinking and reflecting on a few things.  One of these is leadership.
   I've had the opportunity to lead some great programs and teams in my career so far.  I went directly from being a technical individual contributor to management without any formal managerial training.  Earlier in my career I had titles and responsibilities including: software developer/programmer, engineering support, systems administration, architect, systems support, web developer, email administrator, security administrator/architect.  All of these positions can offer leadership opportunities, but this is very different than formal management.

   When I was in purely technical positions I had no interest in management, and couldn't even imagine going in that direction.  But then an opportunity came my way and I started down the "dark path" of management!  And I figured it out as I went along, with some results better than others.

Tuesday, September 3, 2013

Putting the Face in Facebook

   As can happen in a month whose name contains an "a", "e" or "u" :-), Facebook has once again made
changes to its privacy policy and practices.  And, as always we all have two choices: accept the changes (and adjust our settings and practices appropriately), or; leave Facebook.

   Of course most people won't leave Facebook, and if anything they will add more users than those that leave.

   As I look through the changes (see Facebook's notice here with links to the details), I think there are three things to know...

Tuesday, August 27, 2013

People and Process First!

   I've been reading, and hearing, lately about the ideas of client-centric or human-centric IT.  Here's a cool article and interactive infographic from GovLoop.com.  It describes a roadmap approach to get to a people-centric approach while showing examples of what some US federal agencies are doing to advance the cause.

   I like infographics!  They are fun, impactful, and this is a good one.  But, sometimes they are so busy that the simplest parts of the message gets obscured.

   It's not just infographics that obscure simple ideas.  Security and IT are experts at over-complicating things.  We get so caught up in the cool tools that we sometimes miss the main point.

   In the Security and IT world, we should always look at any project or program through the lenses of:
  1. People
  2. Process
  3. Technology
   And definitely in that order!

Tuesday, July 9, 2013

The More Things Change...

   As the saying goes... the more they stay the same.  In our ever-changing world of technology and security, it always amazes me how things often don't change!

   Let me clarify... there's always a totally new technology, programming language or social network to learn. Of course, computing power has changed drastically.  Many of the techniques used by attackers to gain improper access to our information have changed.

   Though many have not.  And the advice we give to consumers and business users to protect themselves has not changed!   Consider...

Tuesday, May 21, 2013

The Business (not Blind) Side

   A Doctor, Lawyer, Salesperson and Systems Adminstrator walk into a bar...

   As I mentioned last week, the Secure360 conference was in town.  And as always, it was a great show.  I was pretty busy and had 3 different talks.  The first was a 4 hour pre-conference session on BYOD. (slides here)

   After talking about the history of portable devices and framing the issues with which organizations struggle, we did something a bit different.

Tuesday, April 16, 2013

Bring It On Home

   There have been a number of discussions about the value of Security Awareness training floating around the net.  Some say that even with training, people will still fall for phishing attacks and social engineering, and that networks and servers will still get hacked.  I wrote about this a while back.

   I think there is great value to awareness training.  To me, the content and delivery are key considerations.  If the security messages are the same old, rehashed information then it will be hard to get people to pay attention, care and retain information.  No one wants to see yet another dry review of an organization's security policies.

    But there is a better way...

Tuesday, February 26, 2013

Tech-Smart Parents and Preschoolers

   This past weekend I had the opportunity to do something fun and different!

   I've been lecturing on Internet Safety and Awareness to all kinds of groups for about 15 years.  I've met with parents and professionals at conferences, businesses, churches, school district parent fairs and have even provided training to law enforcement personnel.  I enjoy doing this and always learn something new.

   After presenting at a school district parent fair last fall, I was invited to present at a local Young Children and Technology conference, specifically covering technology for the preschool and younger set!  Since most of my material is targeted for parents of preteens, teens and older, I knew I had some work to do!

   As I dove into the research, I found that there are similar categories of issues, but clearly preschoolers and toddlers use technology different than teens.

Tuesday, December 25, 2012

A Few of My Favorite Things - Apps

   I recently (finally) got modern smartphone.  My previous phone was the "free" phone from over 2 years ago.  Even when I had a basic smartphone I very quickly found useful apps that used everyday.

   Someone was recently asking me what apps I use on my phone.  I thought it would be useful to make a list of some of my favorites here and focus on those that I use most.

Tuesday, December 4, 2012

Keeping Up and Podcasts

   Recently I was talking with a colleague about keeping up with information. We actually were comparing smartphones. During the conversation we talked about podcasts and podcatching software. I'll talk about what I use below.
   We are talking about what podcasts we listen to.  One thing that was surprised me was that he mentioned that many technical people he interacts with don't listen to podcasts! I found that surprising. I figured most technical and security people know all about podcasts. Podcasts are hardly new.
   There are podcasts for all kinds of subjects. I listen to podcasts about security, technology, sports, news, science, leadership, getting things done/productivity and other subjects.
   I think that listening to podcasts is one of the best ways to both learn and keep up.

Tuesday, October 9, 2012

Online Self Defense - Part 1 - Your Computer

   Happy US Cyber Security Month!  This partnership between Homeland Security, NCSA and MS-ISAC is an opportunity to recognize the importance of information security.  How are you celebrating?

   Last week I ran a couple of sessions at work on awareness and security.  Over the next few posts I will be reviewing some of the 3 themes I covered in a talk entitled "Online Self-Defense". You can view the slides on my slideshare page. (actually, the talk focuses on just 2 of the themes but that's OK!). Since everything comes in threes (omne trium perfectum), I will give 3 easy tips for each theme (and some bonus tips as well).

   The first theme is protecting your computer or device.

Tuesday, October 2, 2012

Stuff I Say - No One Has Ever "Read and Understood"

   Most organizations have policies.  Most medium-to-large sized organizations have security policies.  I hope that yours does!  Policies are a cornerstone to a security program.  People need to know what to do and policy is that high-level guidance.

   Of course, people need to read those policies!

   Many organizations will have staff sign a form that states they have read and understood the policies.  Sometimes this happens just once.  Sometimes it's annually, perhaps at the same time as an annual performance review.  Sometimes it's when a person joins the organization, or shortly thereafter.

   But does that work?  What is the goal?  I say that doesn't work!  No one has ever "read and understood"!

Tuesday, September 18, 2012

Just Say No to "Just Say No"!

   Last week I spoke at The Security Standard conference put on by CSO Magazine.  While not the main point of my talk, one key theme that I addressed is that in Security and IT we cannot use "Just Say No" as an operating strategy.

   Five, Ten or more years ago, security and IT divisions were often considered to be roadblocks.  In many organizations, security and IT existed for self-fulfilling reasons... to support the technology they chose.  IT and security would dictate to the business.  But that's not the right way...