Friday, December 03, 2010

Bring out the Dancing Pigs!

"Given a choice between dancing pigs and security, users will pick dancing pigs every time."

Once someone explained that line to me, I loved it. Basically, Bruce Schneier (a US computer security consultant and cryptographer) explained, "If the computer prompts him with a warning screen like: "The applet DANCING PIGS could contain malicious code that might do permanent damage to your computer, steal your life's savings, and impair your ability to have children," he'll click OK without even reading it. Thirty seconds later he won't even remember that the warning screen even existed."

That basically seems to summarize computer security these days. Users often get taken in by phishing schemes, download viruses, give out personal information, and do other things that compromise security...for the promise of dancing pigs. Smart hackers do this and create attractive links that people will click on.

As you can see, there are tutorials taking potential phishers through the process of stealing information. Stopping sites posting information like that is like playing Whac-A-Mole.


Congrats, you shut down a phishing site! Put down the hammer, I don't think others will pop up!

I do not know that most Americans are adequately prepared to figure out what sites are legitimate and which ones are not (and to read warnings). Sadly, people seem to learn by making mistakes and losing their personal information or getting hacked.

Tuesday, November 30, 2010

Proper Hardware Disposal

In one of my classes last week, we discussed the proper way to get rid of old computer hardware, to avoid privacy issues.

I've gotten rid of old computers, but I generally either keep the hard drives (to destroy) or use software to do a thorough wipe of the drive's data When I say "thorough wipe", I am not talking about deleting files, because data can easily be recovered from a hard drive, EVEN AFTER YOU DELETE IT. Really. As a matter of fact, Microsoft's pre-Windows operating system, DOS, used to include an undelete tool which could recover deleted files easily.

eBay is one place people can purchase used hard drives, and they even provide information on why you need to thoroughly wipe a hard drive before you sell it. You can see that the site shows that social security numbers, credit card numbers, and all sorts of stuff can be found on these hard drives. This means your identity can be stolen even if you do nothing wrong, if a company you have purchased from does not follow good procedures for hard drive disposal. Aside from eBay, there are sites like Craigslist where people get rid of old hardware, and there are always garage sales. In the corporate environment, many colleges and companies pay companies to dispose of old hardware (such as eRevival locally). If you go with a cut-rate company, you may find that though they promise to clean hard drives, they may not do so thoroughly. Any of these are ways that data can be leaked if the hard drives are not wiped.

One way you can provide a level of security is to physically destroy the hard drive, though someone could pick it out of the trash and recover something. The best way is to do a full wipe of the hard drive, or what we used to call a "zeroize" at the company I used to work for. We were putting defense systems in military crafts, and one of the requirements was that the pilot needed to have a button to wipe all the data in the system, to prevent classified data from falling in to the enemy's hands. (Yes, that information is public.)

The Department of Defense has pretty high standards for data wiping, and there are a number of tools that meet their standards. The problem is most of these tools cost money. The one that I recommend is a free tool called Darik's Boot and Nuke (available for download at www.dban.org). Despite the informal name, it is a legitimate program (referenced by CNN and the BBC). There are commercial tools that do this sort of thing as well, but the major difference is not function, it is speed (DBAN has a reputation for being slow - the BBC article says it took two hours for an 80GB drive). DBAN is cool because it gives you a CD to boot off of, and you select the depth of the wipe you want. The more depth you want, the longer it will take to run. If you are going to do this, I would recommend choosing the most in-depth wipe, doing it before you go to bed (as a home user) or before you leave work in the evening (at work), and just letting it run overnight. That way, there is no time wasted waiting for wipe to be completed. In a professional environment, having a DBAN CD around is not a bad thing, especially so your company does not end up in violation with the standards that govern your industry (Sarbanes-Oxley, HIPAA, FACTA, etc.).

A larger company may want to invest in faster, packaged software for this, or a hard drive sanitizer (such as this one - though I am certain their claim of 7 minutes per drive is for the simple wipe and not the seven-pass version).

Any of these options are better than the ol' sledgehammer method, because who wants to clean up that mess?

Spring 2011 Schedule

I just wanted to post my tentative Spring 2011 schedule at Bergen.

I am scheduled to teach:
INF 163 001 (Monday/Wednesday 3:55 PM to 5:50 PM)
INF 101 009 (Tuesday/Thursday 3:55 PM to 5:50 PM)

I may also be teaching a Summer I 2011 course, if that information is solidified, I shall announce it here.

Sunday, November 21, 2010

The Gmail Killer

Facebook is preparing to come out with a new email service, where users can get email sent to an email address @facebook.com. There were a number of headlines that advertised this as "the Gmail killer", though it could just as easily be "the Hotmail killer" or "the Yahoo! Mail killer".

First, Facebook started to try to be your "one true login". They seem to be succeeding in this, because a number of sites have started to give you the option to sign in using Facebook instead of creating an account. For example, here are some random sites that came up when I Googled "Facebook Connect":

Evony
Joost
SurveyMonkey
TravelPod

Facebook even has taken so much of Myspace's market that they are introducing a "connect with Facebook" option. That's the ultimate admission on Myspace's part that Facebook has won the war.

Facebook has succeeded there, so they are looking to expand. The next horizon seems to be Facebook email, which they've announced plans to implement. Facebook's CEO says that this email will be even better because they know who your friends are. No, really.

"Because we know who your friends are," said Facebook CEO Mark Zuckerberg, "we can do some really good filtering for you."

There is something a little creepy about that, but I do think this idea will take off. The interesting part is this: back in the early 2000's, sites like AOL had email and chat services, and tried to expand in to profiles...same with Yahoo! and MSN. None of those transitions worked well. However, Facebook starting with profiles and expanding to chat and then email might actually work.

So, Facebook vs. Google...who wins? Time will tell.

Link to story

Saturday, November 13, 2010

Keeping up with the Jobses

There's a saying "Keeping up with the Joneses" which goes back to the early 1900's (thanks Wikipedia). It basically has to do with people needing to keep up with the neighbors (in this case, the generic Joneses). I feel like Microsoft has this same symptom at points.

According to recent numbers, Microsoft Windows Mobile was only on 2.8% of cell phones, according to Gartner Research. Compare this with 36.6% for the open-source Symbian OS, 25.5% for the Android OS, 16.7% for iPhone OS, and 14.8% for the Blackberry OS. In other words, Microsoft Windows Mobile just is not cutting it.

Since Microsoft needs to keep up with the Jobses (Steve Jobs is often considered the Face of Apple), Microsoft released Windows Phone 7 last month. Microsoft basically redesigned the operating system, because as we see it wasn't working. According to USA Today, the first phone to run this OS is the Samsung Focus through AT&T, which was released on November 8.

According to cNet reviews, Microsoft does seem to have done a nice job on the operating system, but as they point out, it is an uphill battle to overtake some of the companies above them on the list. One interesting feature that jumped out from the review (since I haven't used it myself yet) was the integration with Xbox Live. That could be something that sets this phone apart, if it gives people access to their games and accounts in a mobile fashion.

We'll see how it shakes out, but Microsoft does have a long way to go.

Thanks to Kevin for the heads-up!

Friday, November 05, 2010

Twitter and Poor NBA Etiquette v2.0

Charlie Villanueva, an NBA player, recently played against Kevin Garnett. During the game, Villanueva claims Garnett called him a cancer patient. Garnett, for what it is worth, said he called Villanueva "a cancer", which isn't as far fetched as it sounds. According to urbandictionary, the term cancer "[is] often used as an insult when referring to someone who is a pathelogical [sic] source of trouble and discord within a group."

Now, who knows what happened and what did not, but I can see someone exaggerating because they are annoyed. Either way, the point is he came out and put it out there, and as we know about Twitter, there is no undo button.

If this guy's name sounds familiar, it is because he is the same guy who was benched for tweeting during halftime of a game in 2009. I blogged about that here. I would think the guy would have learned his lesson about Twitter, but nope. If it is getting in the way of your professional life, perhaps it is time to let someone else serve as your filter.

Friday, October 29, 2010

Death by Farmville

Wow.

We've seen this story on the news before...a parent shakes a child and it dies. Sad, unfortunate, but also not uncommon. This happened down in Jacksonville, Florida. What makes this sensational is the fact that the mother got upset with the child over it interrupting her playing Farmville.

Facebook's role is being overblown in the media. Notice it is not "Mother Shakes Baby to Death". Headlines seem to be more "Child Dies due to Facebook Game". The focus is put on Facebook. News articles do report she was playing it through Facebook, but Facebook did not create Farmville. You don't have to be on Facebook to use Farmville (Myspace and Twitter also work, as I understand). Putting Facebook in the headlines is sexier than putting Farmville in the headline.

Of course, this is also going to be something people cite when they say Facebook is bad for society. I have a friend who hates Facebook, and I am sure this friend will see this headline and just tie it to Facebook.

Let's be honest. If this woman would shake a baby to death over a Facebook game, she probably have done it over a TV show, or cooking, or a phone call, or any of another thousand reasons.

Link to CBSNews Article

Friday, October 22, 2010

Time Machine: Everything Old is New Again

Some topics of interest from this week's classes.

We discussed the Do Not Call Registry, which was a way to prevent telemarketers from calling you. Someday, we may see a Do Not Email Registry, but I wouldn't expect that for a while. I remember telemarketing being annoying in the 80's, and it took them until 2003 to do anything about it. Here's my original post about how to get on the registry and save yourself from telemarketers.

Second of all, passwords came up in one class this week. Microsoft has a free password strength checker on their Web site, where you can see how strong or weak your password is. Here's the link. We also discussed passwords, and how you can make a better password. I discussed the mnemonic device method for creating and remembering a password in class, and here is my original post on that.

Of course, for people majoring in the IT area, it's always a struggle to find a balance between security and ease of use. If you require difficult passwords, your users may end up writing them on a sticky note, or putting them in a passwords document.

Friday, October 15, 2010

Stalking a criminal

The Internet has obviously changed many things. One thing it has changed is crime. Criminals are known to use sites like Craigslist and eBay to sell stolen goods.

It's interesting how people have also used this in the investigation of crimes. For example, a woman recently had a GPS stolen, and used Craigslist to get in touch with someone who was selling a GPS of the same brand the next day. She contacted the guy, got his email address, used that to find his profile on an online dating site, used that information to find him on Myspace....

The police were able to get video footage from a McDonald's where he used her card, and the Myspace profile matched the face of the person on the video.

It's a lesson that (as she says) you never know who you are robbing.

Link to story

Thursday, October 07, 2010

Charging for Web design work

One of my former students emailed me to ask about freelance Web design work, and how much to charge. This is always a very difficult question, and I don't know many people who are comfortable setting rates coming out of college.

Keep in mind that companies will pay what sounds like a really high hourly rate because they are not subject to the overhead that their regular employees have, such as health benefits, office supplies, and other such items.

The difficult part in freelancing early on is figuring out how long things will take. I found as a programmer I had no sense for how long projects would take me to do. People would ask me how long things would take, and I would think it should be a 2 hour project, and I would spend 25 hours on it. I developed that sense over time. Classes like Systems Analysis and Design were great in theory, but when it came to applying the lessons, I fell a little short.

Customers don't really want to pay based on how good you are, so generally, customers should not see your hourly rate. I would suggest creating some base packages. For example, a 5 page Web site should cost X, a 10 page Web site costs Y, etc. You want to be clear with a customer what they are paying for. I found a company that does something like that here, for reference.

You can see they have a base package for $600. For a basic 5-page site, $500-$750 seems to be the going rate. This would generally include the basics of meeting with them, gathering content, designing it, having the user test it, fixing the errors they find, and making the site live. In reality, the technical end of the work will probably take less time than the other components of the project.

Other stuff that is extra, and this is where I would run in to issues. If the customer wants e-commerce stuff, or they want Flash animations, that would be stuff that would cost extra. When they describe the requirements, that is when you have to determine the cost of it. If they describe a Flash animation, keep in mind that is rarely a two-hour gig. Flash animations, Web programming, and e-Commerce projects should include testing and bug fixing time. There have been times where I wrote a program in an hour and then spent 5 hours trying to hunt down a bug. Flash programmers can charge rates of $50-$75 an hour, so a site that is heavy on customization like that will be more costly.

What is very clever is that there is a maintenance package is $50 a month for two hours worth of work, and additional hours are extra. You may want to offer options like "10 hours of updates over the next year for $250, or updates at an hourly rate of $40" rather than constraining someone to a number of hours in a month. By offering a package deal, you may have someone pay for the 10 hours even if they don't need them, just because it looks like a better deal. Also figure most updates will be small changes, so a lower hourly rate is fine.

You can of course work with people on price. There are people I've been eager to work with, and made allowances for them.

You also have to decide if you are going in to the hosting business, or if you are going to arrange for the customers to host things elsewhere. I generally would not want to get in the middle of a transaction between a customer and a Web hosting service. If this is the case, make sure you provide them the username and password for the site. Even if they don't use it, it's professional to make sure they have access to this. I've dealt with people who have no clue about this, and if they ever need to change hosting sites, it's a pain for them. Same idea goes for the domain name purchase. You can direct them, but you probably don't want to be the person in the middle since domain names do need to be renewed.

If you are not doing the hosting yourself, you have to assume some customers may have a URL purchased and a hosting agreement, and others will not. If the customer does not have the infrastructure in place, there is some startup work you have to do to get them up and running, and that may be something you want to charge for. This may be something you want to charge $100 for.

I would recommend the customer set up a billing arrangement directly with the hosting service (like godaddy). If you end up in the middle, your credit card is the one the hosting service has on file. If, however, you are planning on hosting sites yourself, that is something different.

You should always have some sort of portfolio available. For my PCCC students, your capstone project can be a start, but you may want to expand on it and upload it to a server somewhere.

The main problem I think most customers have is that they don't understand that you don't provide content. When they pay for a site, you are taking their existing information and turning it in to a Web site. You will need to meet with someone in their organization, and they should be providing you electronic copies of the information they want on the site. Some customers think you are going to actually write the text for the site, and (unless you want to do this) it needs to be made clear that this is their responsibility, and that you don't provide proofreading services.

As you get better at doing basic Web sites, you can probably get things done quicker and therefore make your business more profitable. You can also change prices as you go along. Notice the site I linked above also includes a year (2010 rate card). You can always change rates yearly (or project to project).

Wednesday, September 29, 2010

Census and computing

The US census brings to mind one of the reasons computers advanced.

The 1880 census took 8 years to tabulate. Of course, the census is done every 10 years, so a long wait for results makes this data almost useless. The fear was that the 1890 census would take more than 10 years to tabulate, which of course makes no sense.

Enter Herman Hollerith and his fabulous mustache. He invented a tabulating machine that helped with this purpose. This tabulating machine allowed them to count survey results in one year. Of course, many early computers used punch cards, so this was one of the forefathers of those computers. I did not know (until I read a little bit of the Wikipedia article) that his company was one of the companies that would merge to form IBM in 1924. Thanks, Wikipedia!

Anyway, the 2010 census results are being tabulated, and you can already see the response rates posted for all towns. Making things more interesting is the use of data mining. We can now use the computers to not only count results, but to do projections, spot trends, and all sorts of stuff that would have been impossible 100 years ago. It looks like President Obama will get the first report by December 31, 2010. Considering surveys were sent out in March and data collection ended in July, that's really amazing turn around time. Now, if everyone just did the data entry on the computer, imagine how quickly it would go!

Anyway, here's the site with the response rates:
http://2010.census.gov/2010census/take10map/

Tuesday, September 21, 2010

Using Google Earth to make $75,000

Just another case of learning from my students...

In class today, we were discussing Google services, including the advanced Google search options, image search, and Google Maps. It came out during class that the town of Riverhead, NY used Google Earth in a very interesting way. People started getting summonses for having illegal pools, and it came out that they were using Google Earth to find this out. Really! Turns out they wrote about $75,000 worth of summonses before people caught on and complained.

NPR did an interview with the chief building inspector of the town, and he said they did it for the protection of the neighborhoods, saying "I use it strictly for safety." Of course, there is some validity there, because as he states, there are requirements to make sure children don't drown, and I agree with that. I also think that, well $75,000 had something to do with it. I'm a little cynical when someone won't admit to that. Of course money making is part of it. It's not just about safety.

In the "DUH" statement of the year, he stated "Most of the people that complained were the ones that didn't have the permits." Of course those are the people that complained, because they were the ones who were directly affected and may or may not have had their right to privacy violated.

The town is no longer doing this, so I think that tells us how they feel about whether it was a good decision. If they thought it was, they would have kept on doing it. My opinion? As someone who worked for a company doing government contracting, we were told that the government could not spy on its own citizens. The government tried to implement domestic spy-satellite imaging through the innocuous-sounding National Applications Office, but this idea was withdrawn over privacy concerns. If the government can't do it using our own satellites, why can they do it using Google's? Again, my opinion, they shouldn't be doing that, but that's me.

The other interesting part is Google. This sort of use of Google Earth is not prohibited, either in the main terms of service or the government agency terms of service addendum. Yes, I checked. In theory, this is fine per Google's viewpoint. Then again, they haven't updated the terms of service in a while.

Thursday, September 16, 2010

Dead Online

Had an interesting discussion during class the other day. We were talking about online gaming and I mentioned the case of Shawn Wooley, the 21-year old who killed himself over Everquest back in 2002.

It always made me wonder how word would get out about things like this. If you are part of online communities (aside from Facebook, where people can post information to the "wall"), how do people find out? When my aunt Judy died in 2000, I remember the hassle of having to get copies of a death certificate to places like banks, retirement companies, health insurance providers, and other places, and with the advent of the Web, this becomes even more complicated. How do you get access to Web sites and other accounts if someone dies? Are things like World of Warcraft, Amazon Associates, Paperback Swap, and other sites things you would want people to have access to after you died? At this point, a World of Warcraft (or Starcraft, or whatever) account might actually be something people would put in their will...a site like Amazon Associates or Google AdWords might have unclaimed income (and continue to generate income). No one is going to change their will every time they change their passwords, so there has to be some other solution.

This is one of those areas where no one has *the* solution yet, so here are a few sites that I have read about.

First of all, there is Death Switch. Death Switch will send you a message at various times and if you do not click on the link and enter a password, they will assume you are dead. At that point, you can have the site email out your usernames, passwords, etc. that you might want your wife, children, friends, etc. to have. Of course, if you take a really long vacation, or if you die and forget to change the email address of the recipient, there are problems!

Another way to do this is to use Legacy Locker. This is a site that is similar in concept, without the replying to emails. The person would assign two verifiers to verify that they weredead, and if so, the information stored on the site would then be released. Of course, there are security issues there as well, if the two verifiers are people who conspire against you!

A little morbid, to be certain, but it's interesting that companies have found ways to make money off of this.

They both have very limited free versions. For the paid versions, Legacy Locker costs $29.99 a year at this point (or a one-time, $299.99 fee), and Death Switch is $19.95 a year.

Thursday, September 09, 2010

Zero-Day exploits

I have pretty tight security on my home system. I have my anti-virus, my anti-spyware, and router with built in firewall. I keep my operating system and anti-virus up-to-date. I feel pretty safe on a day-to-day basis. I sometimes forget that this is not true. We are all vulnerable to "zero-day exploits". These are basically newly discovered ways for you to get a virus (or get hacked, etc) even if your virus scanner and operating system are 100% up-to-date. This is the part of computer security that people don't always understand. Anti-virus programs, anti-spyware programs, the operating system, and things like that all get updated AFTER problems happen, so someone needs to be the first group of people to get this virus. Unfortunately, fixes are often reactive (oh, no, we didn't think of that!) rather than proactive (hmm, how would I exploit this system if I were a hacker?).

Yesterday, Adobe (the company that makes Acrobat and Flash, among other tools) released a statement saying there was a vulnerability in even the latest version of Adobe Reader. This is a free tool most people have installed that reads read-only versions of documents. Sounds pretty innocuous, right? Well, there is an exploit that allows this to beat security. If I were to download a file, my firewall, anti-virus, anti-spyware, and operating system would all be beaten by this exploit.

What helps is avoiding high-risk activities online. File sharing networks and torrents obviously present advantages in the form of free stuff, but even if you have all the protection I mentioned before, you are subject to zero-day exploits. This one is an exploit with Adobe Reader, but it could happen in iTunes, or in Windows Media Player, or Internet Explorer, or Firefox, or any other software package. It can also happen when people download software through these networks and actually run a program on their machine. Just remember that despite the updated anti-virus, you are vulnerable. This doesn't even take in to account the folks who have anti-virus software that they don't subscribe to and don't receive updates to.

(For those of you who understand digital signatures, this is a very clever exploit that seems to take advantage of stolen certificates. Who knows, maybe the hackers used a zero-day exploit to steal the certificates!)

Wednesday, September 08, 2010

Back to School (Fall 2010 Edition)

Today starts a new semester...as I mentioned at some point, I will be teaching two classes at Bergen.

I think in my case I have become very comfortable in Passaic. As a full time faculty member, I have a lot of freedom as to what I do in my classes. As I am a creature of habit, when I found something that worked, I stuck with it.

I have been teaching since 2001, and I hope I have improved each year, but the only place I have taught a formal class is at PCCC. I am impressed with the amount of work the department chair does at Bergen to provide support for the faculty teaching the intro course. I know some faculty resist things like standard tests, etc. However, I generally do not find this offensive. I may be in the minority, but I feel like if we as a community college want four-year colleges to accept our courses, there needs to be some standardization. I have heard it argued that the four-year schools do not standardize, but all we can do is keep our side of the street clean.

My prep time is less because the full time folks have done work setting up tests, assignments, etc. I generally spend a lot of time on assignments, so they have freed up my time. As such, I am going to try new things that I would not have had the time to do at PCCC. There is no doubt that this will make me a better educator.

So today I have INF 101 004, an Intro to IT course similar to PCCC's CIS 107, and INF 163 001, similar to PCCC's CIS 152. My experience at Bergen will certainly serve me well, and I am excited to get started.