Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, May 21, 2010

The Cobbler wears no shoes

Since there might be a few people visiting my website to follow up my previous blog post, I figured that I should finally do something about fixing up my lack of a security certificate. I have previously registered with CACert but never finished the paperwork to install one of their certificates.

When I went there today I discovered that the cobbler wears no shoes...

Friday, April 23, 2010

Can anyone explain this security failure in Domino?

I've never seen this problem before and I hope I never see it again.

A customer's branch office based in Sydney, Australia sends out a daily industry newsletter to their customers but for reasons specific to their industry they doesn't want any of the customers to realize who the other customers are. Consequently the author mails the newsletter to himself with all of the customer addresses in the BCC field.

Two days ago he mailed the newsletter out as normal but it bounced at one address (let's say for 'Mr Smith') because Mr Smith no longer worked at the target organization. After that all of the other 100+ customers listed in the BCC field received the Non-Delivery Report for Mr Smith addressed to themselves, and since they were given the original email encapsulated within the NDR then they could see the contents of the BCC field and thereby understand who all of the other 100+ customers were. So somehow the Router task had taken the contents of the BCC field and used that to address the NDR.

The customer had been getting random corruptions in their mail.box file on a monthly basis for over a year but Lotus support hadn't been able to determine the reason for this. Recently the corruptions had been hitting mail files also but Fixup never found a problem. I have a sneaking suspicion that the files weren't actually corrupt, and that a wayward Router Task is somehow to blame for all of this, but the server has been taken up and down more times than a Bride's nighty and there is still no end to the problem. The next step is to completely reinstall the server and patch it to R7.04 but that still doesn't answer the question of what happened.

The customer is standardized on Notes across the world and is unlikely to abandon the platform. They are looking at upgrading to R8.5 later this year, but for now they would like some reassurance that the problem won't occur.

Anyone seen this kind of problem before?

The server is an unclustered R7.02 FP3 running on Windows 2003 server. A PMR has been raised for this issue and if any Loti wants to investigate it further then I'm happy to give them the reference.
.

Thursday, April 15, 2010

"Microsoft's" new mailing list

I had an interesting email this morning which concluded with...

About this mailing:
You are receiving this e-mail because you subscribed to MSN Featured Offers Microsoft respects your privacy. If you do not wish to receive this MSN Featured Offers e-mail, please click the "Unsubscribe" link below. This will not unsubscribe you from e-mail communications from third-party advertisers that may appear in MSN Feature Offers. This shall not constitute an offer by MSN. MSN shall not be responsible or liable for the advertisers' content nor any of the goods or service advertised. Prices and item availability subject to change without notice.

©2010 Microsoft | Unsubscribe | More Newsletters | Privacy

Microsoft Corporation, One Microsoft Way, Redmond, WA 98052


Funny... I don't remember subscribing to "MSN Featured Offers". Ten seconds of detective work showed that the return address was in Russia and the "Unsubscribe" button would take me somewhere that anti-virus filters feared to tread.

I'll give them an A+ for innovation and simultaneously wish that the fleas of a thousand camels would infest their armpits.
.

Monday, January 18, 2010

German Government warns against using Internet Explorer...

The German government has warned against using Internet Explorer after a security flaw left it vulnerable to hackers.


Sometimes there's nothing that a Blogger can say. The facts speak for themselves.
.

Monday, November 30, 2009

Strike Two! Cloud Computing loses more customer data

Last month I highlighted an incident where users lost their data which had been hosted by a Microsoft subsidiary. Now a similar problem has hit Palm OS devices and once more the hosting provider is 'working' with users to assist in recovering their data.

The way I read it, the data is gone forever but the loss to each individual user is far below the entry cost for a lawsuit so the maximum downside for Palm etc. is a PR hit for a couple of weeks then back to business as usual. One day a hosting provider will lose a lawyer's data and then it'll be pass the popcorn while we watch the customers fighting the PR flacks with lawsuits at dawn.

If anyone wants to tell me that the Palm and Danger scenarios weren't technically Cloud Computing then perhaps you can preface your remarks by telling me the difference from a customer's point of view... "I gave you my data and now it's gone. Everything else is irrelevant."
.

Monday, October 12, 2009

Microsoft DID warn you...

Naming their subsidiary 'Danger' was only a subtle hint, but the hint was there.

My last post highlighted the problem of maintaining a secure Cloud Computing environment in the face of easily guessed login names and general password apathy. Now Microsoft has had to admit that their cloud may not be as resilient as they hoped it was. One of their subsidiaries (aptly named 'Danger') has lost customer data. Note that this data is not just misplaced or waiting for a restore of backup tapes - it is no more, it has ceased to be, it has expired and gone on to meet its maker. It is ex-data.

If you were an IT Manager and you had just 'lost' some data, imagine explaining that situation to your boss. What are your chances of escaping this situation with just a formal apology and an offer to forgo your bonus for the quarter? Probably quite small, but I'm betting that's exactly what Microsoft/Danger will offer. A snail-mailed letter on good quality paper printed where-ever its cheapest and an offer of an additional three months service for free. But first you must manually re-enter all of your data into our system...

I was also interested to read of a potential problem where lost data can be retrieved, but because of a massive server farm breakdown (terrorist attack?) there is insufficient bandwidth to restore all of the data in a timely manner.

Am I the only one worried about this? Sometimes I feel like Private James Frazer from Dad's Army with his oft-repeated observation of "We're dooooomed". I see many advantages in Cloud Computing, but the whole thing is moving too fast and aiming too high for my liking. My advice? Make haste slowly with the cloud and keep on-site backups of everything.
.

Thursday, October 8, 2009

Is outsourced email fundamentally insecure?

How secure can you make a hosted service? I was reading about the recent Hotmail/Google username blunder and the thought struck me that the security model might be fundamentally flawed. After all, if they force the use of an email address as a login identity then you have automatically given away your login identity to everyone whom you have sent an email, and by extrapolation a hacker could figure out the login for most other employees in your company eg

'Let's see now... if "John Smith" becomes "jsmith@xyz.com" then his boss "Rita Rose" should be "rrose@xyz.com".'

The same article pointed out that around 40% of people had the same password for every website they used and when you consider that most people on that list had a very simple password then it shouldn't take too long for a dedicated hacker to get external web access to a couple of email accounts in your corporate system.

Am I missing something here or is this a time bomb waiting to explode in Google's face?
.

Monday, January 19, 2009

Reasons to outsource your IT department?

My searches picked up a blog about reasons to outsource your IT department. I don’t have a problem with the not-so-surprising revelation that the writer of the blog supplies out-sourcing services (Heck … I blog and I also provide consulting services… its all part of marketing yourself) but I was disappointed in the level of arguments he provided:
  1. Cut Employee Costs – OK so you can retrench your full-time IT staff but who do you then use to liaise with the external service provider? You either completely trust your new external IT department to look after your own organization’s bottom line or you allocate one of your other managers to deal with them. If that manager is not fully IT-literate (remember you’ve just sacked all of your regular IT staff) then how do you verify what the service provider wants to do?

    You want us to pay $10,000 to replace all of the server magnetos and then reboot the network cables… well, I guess you guys are the experts.

    This strategy might work if you are a small (<10 employee) company and you have a great long-term relationship with a trusted supplier but I certainly wouldn’t recommend it as the first engagement you have with a new service provider. You need to maintain sufficient internal IT staff to “keep the bastards honest”.

  2. Benefit from Expanded Knowledge Base- C'mon now - you don’t need to outsource your entire IT department in order to gain knowledge from external consultants. Remember that all service providers (myself included) want to sell you a service and its quite OK to pick our brains for free now and again. Of course, if you do it too often without tossing the occasional chocolate frog the other way then you’ll destroy a beautiful relationship, but in this era of Wikis and on-line discussion Forums there’s no need to stay locked in your own technical tower. Cruise the internet for a while and tell the consultants they can either play the game your way or you’ll go and talk to their competition.

  3. Buying in Bulk Really Does Save - Using terminology like “…you don’t have to overpay an underproductive employee” is an unwarranted slur against your staff for their personal work habits and your management ability in not keeping them productive. Surely there are better ways to get your point across than descending to that kind of marketing.

  4. Remote Technology Cuts Time and Expense – Wow! These guys are really getting stuck into the negative marketing tactics. Suggesting that your own IT employees are incapable of using remote access technology is insulting to them and to you.

  5. After-Hours Accessibility- I’ve never met a system administrator that saw their job as nine to five on Monday to Friday. So if your IT person works on Saturday then give them Monday off. That’s not rocket science.

Bonus: Supplement your IT- Now you’re talking! This should have been your headline with all that guff about outsourcing as your secondary point. It does make sense for a business to have a friendly IT person at the end of a phone ready to and help when needed, but why buy the cow when all you want is the occasional steak?

P.S. “Bastard” is quite acceptable terminology in Australia eg “You lucky bastard”, “Where has that bastard gone” or “Which one of you bastards called this bastard a bastard?”. I realize that some UK readers may have a problem with the word but this is an Australian blog and when in Rome …
.

Wednesday, November 19, 2008

SBS 2008 obviously wasn't built on a secure Foundation.

Duffbert et. al. have already blogged about Microsoft killing off their "One-Care" subscription security service but I'd like to chew on the implications for SBS2008 for a couple of paragraphs.

So Microsoft spends five years and umpteen gazillion dollars to research and develop their replacement for SBS2003 and only ONE WEEK after releasing the product they find it necessary to declare End-Of-Life on a key component of the bundle and announce its replacement by a new software package that won't be delivered for another seven months. Microsoft Watch quoted Microsoft as saying:

“Microsoft will continue to support Windows Live OneCare for Server on SBS 2008 through June 30, 2009. Windows Live OneCare for Server subscribers will be supported for the duration of their subscription.”


So pick your favorite theory:
  • Microsoft discovered some impossible-to-fix code cancer deep in the bowels of OneCare and decided to put it out of its misery before some geek publicly exposed the flaw.
  • OneCare was never more than smoke and mirrors and was only kept around long enough for Microsoft to fulfill its SBS2008 upgrade pledges for customers who couldn't wait to get off SBS2003.
  • Microsoft installed a copy of Lotus Foundation server and realized that their own products were so far behind the technology curve that their only chance was to throw some FUD into the market.
Actually all of these theories could be true. Whichever way you look at it, there are some serious questions to be asked about whether SBS2008 is "Ready for Business".

EDIT: D'oh!... I left out the traditional Microsoft strategy. Since they can't beat Macafee and Symantec in the marketplace then they'll just develop a freeware version of their products and erode their revenue until either (or both) of the competitors go out of business. Just like they did with Netscape Navigator ...
.