Week 7 blog - CYBR650
This blog is to make up for Week 7. I was working on my post for the Security Trends forum and posted that but am still thinking about it. The subject is Verizon and AT&T's use of supercookies in order to track their customer's data useage and utilize the information gathered from this tracking to allow advertisers to focus their attention to users. While this is the main purpose of this time, the information gathered with the use of these supercookies can also be used by other commercial and government agencies for a whole range of things.
These supercookies are supposed to be stronger than the cookies we are used to seeing and are supposed to keep the users information confidential, even though it has been proven time and again that this is an unrealistic expectation.
How do I feel about this? I'm torn. On one hand, I suppose in this day and age advertisers and businesses have to do what they can to catch the consumer's attention.
However, as a private citizen, I'm not sure I like this idea. Number one, I pay enough for my cell phone service that I should not have to wonder if my information and my activity is private. I think that is an expectation consumers have. I also think that by advertisers focusing on consumers based on their useage, it is unfair to the consumers and limits their decision making ability.
One example I have for that is, I was looking for a trivet to set in my electronic pressure cooker to keep the meat and potatoes I cook in there up out of the liquid I use in it so it doesn't taste so watered down. I didn't know what I was looking for when I started hunting, I started out actually looking for round cooling racks. Found a few things on Google and followed the links. Now, every time I open ebay or Facebook, bam, there is the advertisement for the last item I looked at. Sure, I was looking for it, but I would like the advertising to perhaps be alternated or something so I don't see the same thing from the same company time after time. I now just ignore the advertisements.
As far as my personal information being at risk, I'm not sure how much of it would be. Probably more than I think since I am trying to become more organized and using my phone like more of an organizer these days rather than just a phone.
How do you feel about this? What are your thoughts?
Thursday, November 6, 2014
Sunday, November 2, 2014
Week 10 Blog - Angel Dooley - November 2, 2014
Admittedly, I have had a rough couple of weeks, both physically and mentally. I am feeling hella guilty for falling behind, but know there really is not anything I can do.
Anyway, speaking of health, it is time to sign up for benefits for next year at work. Of course, we have had all these frightening emails about making sure to get in and get our benefits picked because this year every person has to sign up or they will be assigned to basically the worse plan available because of "Obamacare".
One new thing they are pushing is the change in wellness incentives for next year. Last year, we could earn a max of $150 by meeting certain markers, such as having our cholestrol (sp?) checked, quitting smoking, etc. This year they have added more to the pot and other markers to reach, including taking a million steps between October 1, 2014 and September 15, 2015. They are also offering the fitbit in the bookstore at a reduced price and in addition to the monetary reward for reaching a million steps, if you have fitbit and track your progress with the same, they will reimburse you for the cost of the bookstore fitbit flex.
So, after a little obsession, I went out and got the fitbit flex for both my daughter and I. We sat them up on our laptops at home, on iPads, and our phones, we are covered with the fitbit. It is a bluetooth device, so easy enough to set up on the iPads and phones. However, to sync it up with your laptop (wirelessly) and/or your desktop, there is a USB dongle that goes through it to get that accomplished. So, off I went to work to set up my fitbit on my computer at work. Made sense to me, it's being promoted by the University, the feedback from the fitbit is recommended for our healthy rewards, this should be easy. Well, nope, not so much.
Couldn't download the dashboard from the fitbit site because I don't have the correct permissions. So, I called my friend in our Department IT dept., Margaret, and asked her if they could install it or what the deal was. Well, of course, they are still trying to decide how to handle it. They are fearful that there could be an issue with the dongle and system security. Which, I understand, but what I don't understand is why they would promote the use, and actually tie in the use and feedback from the fitbit into our benefits. I have not felt up to looking into this matter, but will try to, by next posting, look into this subject a little further and see what the possible issues would be and how any risks could be mitigated.
Admittedly, I have had a rough couple of weeks, both physically and mentally. I am feeling hella guilty for falling behind, but know there really is not anything I can do.
Anyway, speaking of health, it is time to sign up for benefits for next year at work. Of course, we have had all these frightening emails about making sure to get in and get our benefits picked because this year every person has to sign up or they will be assigned to basically the worse plan available because of "Obamacare".
One new thing they are pushing is the change in wellness incentives for next year. Last year, we could earn a max of $150 by meeting certain markers, such as having our cholestrol (sp?) checked, quitting smoking, etc. This year they have added more to the pot and other markers to reach, including taking a million steps between October 1, 2014 and September 15, 2015. They are also offering the fitbit in the bookstore at a reduced price and in addition to the monetary reward for reaching a million steps, if you have fitbit and track your progress with the same, they will reimburse you for the cost of the bookstore fitbit flex.
So, after a little obsession, I went out and got the fitbit flex for both my daughter and I. We sat them up on our laptops at home, on iPads, and our phones, we are covered with the fitbit. It is a bluetooth device, so easy enough to set up on the iPads and phones. However, to sync it up with your laptop (wirelessly) and/or your desktop, there is a USB dongle that goes through it to get that accomplished. So, off I went to work to set up my fitbit on my computer at work. Made sense to me, it's being promoted by the University, the feedback from the fitbit is recommended for our healthy rewards, this should be easy. Well, nope, not so much.
Couldn't download the dashboard from the fitbit site because I don't have the correct permissions. So, I called my friend in our Department IT dept., Margaret, and asked her if they could install it or what the deal was. Well, of course, they are still trying to decide how to handle it. They are fearful that there could be an issue with the dongle and system security. Which, I understand, but what I don't understand is why they would promote the use, and actually tie in the use and feedback from the fitbit into our benefits. I have not felt up to looking into this matter, but will try to, by next posting, look into this subject a little further and see what the possible issues would be and how any risks could be mitigated.
Monday, October 6, 2014
Week 6:
For this week's blog we are asked to discuss the sources we mentioned in our blog in the second week of class. We are asked if we have actually used these sources this week or if there are additional sources we found, or if we have decided that any would not be a good source to use.
The sources I mentioned in week 2 were techtarget.com, IT News Daily, and CNet. I have to say I did not use any of these sources for last week's assignment. Instead I utilized our textbook and a couple other sites, not anything worth mentioning.
However, I did find myself in the position where I could not get Visio and get it downloaded onto my new laptop in time to use it to get the network diagram done. So, I had to go out and find some freeware to do this. This was not an easy task. I did find one I liked and used, but of course, I have had trouble finding it a second time so I'm still looking. Ugh!
For this week's blog we are asked to discuss the sources we mentioned in our blog in the second week of class. We are asked if we have actually used these sources this week or if there are additional sources we found, or if we have decided that any would not be a good source to use.
The sources I mentioned in week 2 were techtarget.com, IT News Daily, and CNet. I have to say I did not use any of these sources for last week's assignment. Instead I utilized our textbook and a couple other sites, not anything worth mentioning.
However, I did find myself in the position where I could not get Visio and get it downloaded onto my new laptop in time to use it to get the network diagram done. So, I had to go out and find some freeware to do this. This was not an easy task. I did find one I liked and used, but of course, I have had trouble finding it a second time so I'm still looking. Ugh!
Thursday, October 2, 2014
Week 5 Blog - CYBR650
Well, I have continued to struggle this week with my new laptop. Needed Visio for a class assignment, of course, could not get it to load to save my soul. Wasted two days on trying to get it on before finally giving up and searching for an alternate freeware program to use in the meantime. Finally got my network diagram done and turned in, but later than expected. Hoping the Professor understands.
This week I caught an article "Breach Prevntion: The Missing Link" that looked interesting. This piece addresses gaps in mobile policies and how those gaps threaten corporate data protection. I found this interesting because I know BYOD is becoming more and more popular. They had just started allowing it at TD Ameritrade while I was interning. I know I bring my own iPad to my current job to work with, not anything to do with my job, but I do access the network with my own device.
This piece opens up stating that one of the huge issues, and what managers find most often, is that a large portion of their workforce are using mobile devices, applications and cloud services that are outside of an organization's sanctioned and approved services, and out of the organization's control.
This leaves organizations struggling to determine what "shadow IT" services are being utilized by their workforce, as well as what type of security and privacy aspects are being exercised by the providers, if any.
Apparently many IT departments are playing catch up with this issue, as well as the organizations themselves. This increased personal device usage many times find Company policy and standards and procedures lagging behind and containing gabs and other inconsistencies on their use and their security.
The piece did suggest that in order to increase breach prevention in these circumstances, they need to account for mobile pieces and incorporate the following:
Recognize the advanced sophistication of malware attacks on mobile applications and work to mitigate those risks;
Go beyond implementing a mobile device management system to address application and network layer security;
Encrypt mobile devices, including laptops, in order for them to safely and securely store sensitive company information; and
Consider establishing a mobile center of excellence to educate employees on safe mobile device use.
Well, I have continued to struggle this week with my new laptop. Needed Visio for a class assignment, of course, could not get it to load to save my soul. Wasted two days on trying to get it on before finally giving up and searching for an alternate freeware program to use in the meantime. Finally got my network diagram done and turned in, but later than expected. Hoping the Professor understands.
This week I caught an article "Breach Prevntion: The Missing Link" that looked interesting. This piece addresses gaps in mobile policies and how those gaps threaten corporate data protection. I found this interesting because I know BYOD is becoming more and more popular. They had just started allowing it at TD Ameritrade while I was interning. I know I bring my own iPad to my current job to work with, not anything to do with my job, but I do access the network with my own device.
This piece opens up stating that one of the huge issues, and what managers find most often, is that a large portion of their workforce are using mobile devices, applications and cloud services that are outside of an organization's sanctioned and approved services, and out of the organization's control.
This leaves organizations struggling to determine what "shadow IT" services are being utilized by their workforce, as well as what type of security and privacy aspects are being exercised by the providers, if any.
Apparently many IT departments are playing catch up with this issue, as well as the organizations themselves. This increased personal device usage many times find Company policy and standards and procedures lagging behind and containing gabs and other inconsistencies on their use and their security.
The piece did suggest that in order to increase breach prevention in these circumstances, they need to account for mobile pieces and incorporate the following:
Recognize the advanced sophistication of malware attacks on mobile applications and work to mitigate those risks;
Go beyond implementing a mobile device management system to address application and network layer security;
Encrypt mobile devices, including laptops, in order for them to safely and securely store sensitive company information; and
Consider establishing a mobile center of excellence to educate employees on safe mobile device use.
Roman, J. (2014,
September 30). Breach Prevention: The Missing Link. Retrieved from
databreachtoday.com:
http://www.databreachtoday.com/breach-prevention-missing-link-a-7369
Wednesday, September 24, 2014
Well, what to write about. Besides my week from hell, hum. I'll start with that. My luck was shining through, starting last Friday. Got off work a couple hours early and thought I was going to have a nice long relaxing weekend. Huh. The car overheated and broke down, luckily it was just a hose, then my laptop decided it didn't like me and died as I was finishing up my homework and getting ready to submit it. Found out it is just dead. Waiting to get my files off of it, if I can. I did manage to get a new one, but gosh, what a decision to make. There are so many systems out there anymore to choose from. Try reading reviews and researching and it's not any less confusing. My daughter tried to take me to the dark side and tried to convince me to by a MAC, but I was able to resist...this time. Bahahaaha. Ended up getting an HP Envy, which I'm a little concerned because it reported that I already a ton of things that needed to be cleaned off when I installed the virus protection, which was a whole other decision.
I have some type of protection offered through my local cable company, but you know the salesman, it's on sale, here, you gotta get it. Last time I bought virus protection for my computer I bought Kaspersky and loved it. This time they talked me into trying Webroot. We'll see how I like that one, I guess.
The other big thing this week is all the hacking being done and all the celebrity photos being leaked that are stored on the cloud. I find this interesting because I wondered how long it would take for someone to hack into a cloud provider. The cloud was being presented as being more secure and reliable and it hasn't taken hackers long at all to figure out how to get in. So, do the pics belong to the celebrities who are in the pics or into the cloud service and who is going to attempt to pursue these hackers? I guess first of all, you should really think about what you store in the cloud until it is proven to be a little more secure, and second, you would think they would have learned by now, there is no way in this day and age that you can say or do anything or take a pic that you don't want released for public consumption. It is just far too easy for people to get their hands on things whether you think they are secure or not.
I have some type of protection offered through my local cable company, but you know the salesman, it's on sale, here, you gotta get it. Last time I bought virus protection for my computer I bought Kaspersky and loved it. This time they talked me into trying Webroot. We'll see how I like that one, I guess.
The other big thing this week is all the hacking being done and all the celebrity photos being leaked that are stored on the cloud. I find this interesting because I wondered how long it would take for someone to hack into a cloud provider. The cloud was being presented as being more secure and reliable and it hasn't taken hackers long at all to figure out how to get in. So, do the pics belong to the celebrities who are in the pics or into the cloud service and who is going to attempt to pursue these hackers? I guess first of all, you should really think about what you store in the cloud until it is proven to be a little more secure, and second, you would think they would have learned by now, there is no way in this day and age that you can say or do anything or take a pic that you don't want released for public consumption. It is just far too easy for people to get their hands on things whether you think they are secure or not.
Sunday, September 14, 2014
September 14, 2014
Gosh, what to address this week. It's kind of been a busy week, so not much time to do any extra reading besides what has been required for class. Our reading and assignments had to do with Threat Modeling and tools that can be used to perform threat modeling. It was very interesting to read about the different tools available. It seems like they all have some step that incorporate STRIDE. To me, that shows how beneficial STRIDE is to the security community.
This week I did hear that the Home Depot breach may be even bigger than the Target breach last winter. I have not had time to dig into this incident very much, but found it entertaining when I heard on my local news the other night that Home Depot will not force it's customers to pay for any unauthorized charges to their account. I found that laughable as I thought that was the standard with credit cards. Plus, when the organization itself is the one that has the breech, that seems like a no-brainer.
Sunday, September 7, 2014
Credible Sources
This
week we are told that one of the first steps in our threat modeling process
should be to identify credible sources of information for threats,
vulnerabilities, updates, and security news in general. In our blog post this
week, we are told to include a list of sources we consider to be credible and
why we consider them to be credible.
1. One of my favorite sites, and one I subscribe
to and get regular updates from, is techtarget.com, also has SearchSecurity. I have utilized techtarget.com over and over
for various information. They also have
SearchSecurity which contains information on a multitude of topics regarding IT
security, Access Management, Governance and more. I have always found techtarget and
SearchSecurity to be reliable and current on all their information and consider
them a very credible source.
2. Another newsletter that I get that I consider
a credible source is IT News Daily. They
discuss everything; issues with Android, MAC; they also discuss patches and
other news in the IT world. I have found
them to be up to date and credible. They
are a good source of both news of what is going on in the IT world as well as
information on current issues out there.
3. I also find CNet a reliable source. They are another source that is a wealth of
information, including information security issues. They have always proved to be dependable and
timely.
Subscribe to:
Posts (Atom)