IMPORTANT NOTIFICATION

This site is an archive of Simon's first blog.
Current writing and commentary is now published at
simonedwards.com.
Showing posts with label protection in the cloud. Show all posts
Showing posts with label protection in the cloud. Show all posts

Tuesday, 12 May 2015

12 computer security tips

The bad guys can try to break in using computers only or they can try to trick you into providing them with access. Or they can use a mixture of tactics. Let's consider two main types of attack:

* Technical – breaking in via computers only
* Human – tricking people into aiding the attack

For the technical attacks you might consider the following, in order of priority/effectiveness:

Wednesday, 11 June 2014

Are Chromebooks insecure travel companions?

Do not connect a Chromebook to a public wireless network if you don't want to risk leaking personal information.

This advice is not some half-baked journalistic opinion but comes direct from the UK government’s National Technical Authority for Information Assurance (CESG).

The CESG advises that even for data with the lowest security classification [PDF], labelled 'OFFICIAL', Chromebooks are unsuitable for a number of reasons, one being that the Virtual Private Network (VPN) included is not up to scratch and there are no viable alternatives.

Yesterday the organisation published its End User Devices Security Guidance: Chrome OS, which states:
"The VPN has not been independently assured to Foundation Grade, and does not currently support some of the mandatory requirements expected from assured VPNs. The VPN can be disabled by the user and some Google traffic is sent prior to the VPN being established resulting in potential for data leakage onto untrusted networks. Without assurance in the VPN there is a risk that data transiting from the device could be compromised"
There is a similar warning in the Android guide that the in-built VPN for Android 4.4 has not been assured, although it does not appear to leak data automatically and there are alternatives available.

If you don't use a VPN when using public WiFi then you are at no greater risk when using a Chromebook than any other device, but if you are security conscious and want to stay safe when moving around at home and abroad it's better to stick with an Android tablet than move over to a Chromebook.

Thursday, 5 June 2014

Three Android Security Essentials

I recommend the following three tools for improving your security when using Android phones.

These will allow you to:

  1. Locate or disable a lost or stolen phone
  2. Prevent surveillance of your WiFi and mobile data use
  3. Further improve the security of your internet accounts
Additionally protection from malware is provided by the second tool but, for Android, I don't believe that such threats are currently significant for users who avoid unofficial application stores.

Two tools are free. I've included one that is not because I believe that the free alternatives are not sufficient.

Google Android Device Manager
Why: Ring, lock or erase your phone remotely
Cost: Free
Where: Already installed or Google Play Store


Install the application if necessary and visit the management console using another computer (phone, tablet or PC), logging in with a Google account that is present on your phone.

If you lose your phone nearby you can locate it using its ringer. If you lose it further afield you can locate it using GPS. If it's really lost or stolen you can wipe it.

More information, including a video on what the wiping process looks like.

F-Secure Freedome
Why: Use public WiFi networks safely
Cost: £20.99/year (or £2.99/month)
Where: Google Play Store


Prevent others from monitoring your internet use, passwords and other sensitive data by clicking the Protection button.

When it says 'On' your connection to the internet is encrypted, even if the websites you use do not use encryption.

Additionally this product claims to protect against web-based threats including harmful applications, websites and sites that track your online activity.

If you are considering a free VPN bear in mind that you don't necessarily know who is running it and what information they are taking from you to fund it.

Google Authenticator
Why: Increased security for your internet accounts
Cost: Free
Where: Google Play Store


Not only available for Android, this security tool makes your internet accounts much harder to crack.

Compatible services include Google Apps and Mail; Dropbox; LastPass; and WordPress. That is just a short list of those using Authenticator.

Monday, 5 August 2013

The mystery of Google's app for wiping and locating phones

Late last week the media predicted the imminent launch of a new Google application for Android phones that would allow users to locate or wipe their devices.

The Register wrote, "Google has announced that it will begin offering a free device location and security service for Android phones and tablets for the first time later this month, addressing a longstanding (sic) omission in Mountain View's mobile OS."

Such security features are often included with anti-malware applications, while there are also dedicated apps that provide only the location and memory-wiping abilities.

The news that Google was going to launch its new Android Device Manager security service and application made me a little confused. I thought it already had put out something similar ages ago. In fact I remember seeing an app called Google Apps Device Policy on pretty much every device that I've used.



Here is Google's description of Google Apps Device Policy:
***THIS APP IS FOR GOOGLE APPS FOR BUSINESS, EDUCATION, AND GOVERNMENT USERS ONLY***
Google Apps Device Policy makes your Android device more secure
* Ring or locate a lost device via My Devices (https://www.google.com/apps/mydevices)
* Remotely lock device or change pin
* Administrators can enforce security policies and remotely wipe devices



The app is clearly only available to use for those who pay for Google Apps. Indeed, if you visit the URL above you'll see a message verifying that fact.



My confusion was compounded, however, when I came to verify the name of the app before writing this article. My current phone and tablet, a Nexus 4 and Nexus 7, are running the latest version of Android (4.3) and now no longer show Google Apps Device Policy as being available.

As the first screenshots above show, though, the program was certainly installed at some point. In fact it has been installed not only on the devices I use day to day but also on the first Android phone I ever bought and all devices bought since.

It's great news that ordinary users will have access to these features. It's just a little surprising that a similar, installed product seems to have become invisible or been removed.

Monday, 3 October 2011

Facebook links scanned for malware

Facebook has joined forces with security firm Websense to protect users from links to malicious web sites.

Websense's Advanced Classification Engine (ACE) will analyse links that users click on in real time. If it considers them to be dangerous the page will be blocked and a warning message will appear. Reckless users may still choose to click through to the site.
Source: Websense
Testing pages dynamically is an interesting approach. Many similar types of systems, such as those offered by desktop anti-virus programs, use website reputation rather than looking through the content each time the site is visited.

Monday, 22 June 2009

Most Malware Spreads Via USB

Anti-virus companies frequently state that the majority of malware threats exist on the internet, and specifically on websites. For this reason, they are developing reputation-based systems that can block websites and the malware that they try to download onto victims' computers. However, the world's largest anti-virus company has recently discovered that more than half of malware floating around in Europe is spread using USB drives. This contradicts the prevailing opinion.

Symantec's 2009 Internet Security Threat Report found that 65 per cent of malicious code is spread using removable media. From a Symantec press release, dated 15th June 2009:

"The popularity and increased use of USB-based media, such as memory sticks and MP3 players, has resulted in a resurgence of this historically successful method of malware."

Common, high-profile worms that use this method include four of the top malicious code samples in the EMEA (Europe, Middle East and Asia) region:
  • Mabezat
  • SillyFDC
  • Sality
  • Gammima

This demonstrates that you still need a traditional anti-virus program running on your PC rather than relying 100 per cent on options that rely solely on website reputation, that need an internet connection to operate 'in the cloud' or that deal only with network traffic.

Sunday, 23 November 2008

The Complete Internet Security Handbook 2009

If you want to keep your family safe and your data private then The Complete Internet Security Handbook 2009 is the book for you. It includes the following:

What do you want to protect?
Learn how to manage risk and provide the best protection you can for the people and things you care about the most.

Cyber-criminals
Why do viruses, hackers, spam and fake bank websites exist? Discover the criminal underworld of the internet and find out how the scammers and conmen operate.

Chapter 1: Basic Desktop Protection
Take advantage of Windows' built-in security features and protect your computer for free.

Chapter 2: Viruses
Learn how to avoid viruses, recognise them when they appear and remove infections from your computer.

Chapter 3: Hackers, spies and other criminals
Prevent the bad guys on the internet from gaining control of your computer, internet connection and personal details.

Chapter 4: Spam and how to avoid it
Is your email inbox overwhelmed with annoying messages? We'll show you how to regain control and banish spam forever.

Chapter 5: Protect your child
The internet is a great educational resource, but threats abound. Ensure your kids stay safe online with our comprehensive guide.

Chapter 6: Lost and stolen
Reduce the chances of computer theft and encrypt your files to keep them private, even if they are stolen.

Chapter 7: Accidents and malfunctions
Discover the easiest way to keep your files safe and find out how to recover them if the worst happens.

Chapter 8: Personal privacy
Learn how to prevent your personal data falling into the wrong hands.

Chapter 9: Scams, fraud and hoaxes
Learn how to protect yourself against identity theft, email hoaxes and fake websites designed to steal your money.

BONUS CHAPTER: Wireless networking
They are convenient, but how safe are wireless networks? We show you how to build and bullet-proof your network.

The Complete Internet Security Handbook 2009 is available now from Borders and costs £7.99. It will also be available in WHSmiths from 27/11/2008. Amazon is currently selling it for £6.39 (as of 23/11/2008).

ISBN: 1-906372-18-7
Cover price: £7.99
Edited and (mostly) written by Simon Edwards.

Tuesday, 18 November 2008

Microsoft stops charging for virus protection

Microsoft will end its subscription-based OneCare security package and offer consumers free protection against viruses and other malware by the middle of 2009.

The company has just announced (one hour ago) that it will launch a new and free anti-malware system codenamed 'Morro' by the second half of 2009. It will also cease selling OneCare subscriptions by the 30th June 2009.

The 'Morro' system aims to "protect against a range of online threats including viruses, spyware, rootkits and trojans."

The press release, which was sent to UK journalists around bedtime, said that the new security system will "address the demands created by smaller PC form factors, rapid PC growth in emerging markets and the increasing threat from global malware."

This probably means that it will work 'in the cloud', rather than using a large, sluggish and system-crippling application that downloads megabytes of updates every few hours. Small PCs often lack the processing power necessary to run demanding security applications alongside productivity-based programs (software that lets you actually do things, rather than avoid bad things).

There are security implications with running software and services online, and this applies just as much to anti-virus software as it does to online word processing and photo editing services. For example, what happens when your laptop is working offline and someone hands you an infected flash drive? If the computer can't ask a server whether or not a file is bad, it may allow malware to infect the system.

In the meantime, new and old OneCare subscribers can expect to receive a service for the lifetime of their paid-for subscriptions.

More information is available directly from Microsoft.

Tuesday, 12 June 2007

Hacked Websites Spread Spyware

Recently a web hosting company was attacked by hackers, who put malware on some of the sites that the company hosted. This meant that, when visitors viewed the sites, their computers could have been infected with spyware without them knowing.



The web host made a couple of obvious mistakes in the way that it set up its systems, which you can deduce for yourself if you are interested. However, I don't think that concentrating on the specific details of the web host's security measures is the most useful thing for us to do. As Google's recent analysis of web-based malware [PDF] indicates, bad guys are attacking legitimate sites in order to upload malware. DreamHost's recent incident is likely to be just one of many. The main point is that malware can appear on potentially any website, regardless of whether it is hosting dodgy pictures of Paris Hilton losing the plot or world-class news.



This has consequences for regular websites visitors and for anti-malware companies that believe they can combat spyware using reputation-based detection systems. For example, Trend Micro is moving towards just such a system, referring to "in the cloud" reputation-based technology. Its rational is that bad sites provide malware, and there are a limited number of these bad sites. According to a newsletter on the Trend Micro website, "web reputation works by associating a reputation with a URL. It essentially performs a background check on a URL ensuring Internet users of a safer surfing experience and protecting them from visiting malicious URLs."



This is quite a limited approach, even if the bad guys stuck to their own small group of servers. For example, you'd expect an anti-virus program to detect a virus on a flash drive or in an email from a friend, not just when it's downloaded from a known naughty website. The bad news for people using this kind of protection service is that those who spread malware are not just using a small pool of servers that can be categorised easily as 'bad'. They are attacking sites that you, I and reputation-based services consider to be safe.



The recent misfortunes of DreamHost and its clients (and their visitors) illustrates that this is not a far-fetched, paranoid scenario. Spyware can and does appear on legitimate, trusted websites. In these situations reputation-based detection fails and you'll have to trust in your more traditional, definition-based security software. And we all know how effective (or not) these programs can be...