Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

You cannot trust e-mail with such information. As your message moves from one server to another, several people have the opportunity to read it. So what should you do? You have a few options.

Public/private key encryption: Outlook 2007 and other apps support this approach. The public key can encrypt but not decrypt so you can share it. You keep the private key, which decrypts. Both sender and recipient must set up this type of encryption, and it isn’t easy for the less technically adept. It’s a good choice in a business environment where everyone has the help of an IT department.

Password-protected .zip files: Depending on what software you use to create .zip archives, you may have an option to password protect them. Don’t go this route, however, if the app doesn’t support high-quality AES encryption; the .zip format’s standard password protection is easy to hack. Many .zip programs do support AES encryption, including WinZip (fi nd.pcworld.com/64000) and the free, open-source 7-Zip (find.pcworld.com/61828). Unfortunately, Windows’ built-in .zip tool doesn’t support AES, so you can’t assume that your recipient will be able to open your encrypted archive.

Secure message and file-sending services: Instead of e-mailing the data, put it on a secure Website for the recipient to download. I recommend Send (www.sendinc.com). It’s free, and you don’t even have to share any passwords. When you post something on Send, the site e-mails a notice to the recipient, who will need their own free Send account to access your information.

Source of Information : PC World July 2010

Paid Hotspots: Safety Not Included

While researching this article, I encountered a common misconception among business travelers and coffee enthusiasts— namely, the idea that commercial hotspots that require pay-per-hour or monthly subscription fees (AT&T, Boingo, GoGo, T-Mobile) are more secure than their free counterparts because a payment and a password are involved. In fact, these hotspots are almost always unencrypted, and they employ what is called a “captive Web portal” only to prevent access to the Internet until you enter a payment method (or a subscriber password). Tough this “gateway” Web portal is usually delivered over HTTPS (to protect the credit card in - formation or the password), all the post-authentication traffic on the wireless network is unencrypted. As a result, paying the service’s $10 monthly fee gives you access but not security. In fact, due to the nature of radio frequency transmissions, another person—even someone who isn’t a subscriber to the service—can view any unencrypted traffic you send, just by joining the same wireless network. This means that outsiders can easily observe and capture any regular HTTP Websites you visit, any unencrypted POP3 e-mail you access, and any FTP transfers you make. Talented hackers can even modify their own wireless card to clone the identity of your wireless card, thus obtaining free access through a commercial hotspot by “piggybacking” on your signals.

Source of Information : PC World July 2010

Stick to a Secure Webmail Connection

First, to combat e-mail snoops, use a Webmail system with HTTPS for the whole session. Almost all Webmail systems use HTTPS when asking you to log in, so your password is transmitted securely. After authentication, however, they usually switch back to HTTP because it reduces the computational strain on their servers and makes serving advertisements easier. That means that everyone who is on the same wireless network (either unencrypted or with a shared password) can read the content of your e-mail. In certain cases, a person can even steal your session cookie and log in to your Webmail session without your password. (That is, until you click the ‘Logout’ link—which you make sure to do every time, right?) Two very notable exceptions are Gmail and your corporate e-mail system (such as Outlook Web Access). Earlier this year, Gmail switched from the common practice of using HTTPS just for logins to using HTTPS throughout the entire Webmail session. Previously, Google Apps users could opt in to this feature, but it is now the default setting, with the ability to opt out (if you hate security). This change, combined with Google’s new suspicious login detection algorithms, makes Gmail a standout among free Webmail providers. If you were looking for a reason to switch from your AOL, Hotmail, or Yahoo account, you’ve found it. Your company’s Webmail system is also likely protected by HTTPS at all times, because that is the default configuration for most systems. Note, however, that if you check your work messages using local software (Outlook, T underbird, Mac OS X’s Mail) instead of HTTPS Web-based e-mail, you may or may not be using encryption.

Source of Information : PC World July 2010

Your Business Is your Rivals’ Business

But what if you think your data isn’t important enough for someone to snoop on? Perhaps you are just browsing sites, without logging in to any e-mail systems or Web applications that require passwords. Your system should be safe then, right? Not necessarily. Imagine that you’re using airport Wi-Fi while returning from a trade show. Instead of checking the hundreds of e-mail messages waiting for you (unlikely, right?), you decide to browse your competitors’ Websites, looking for ideas. Or maybe you elect to research potential acquisition targets. In the background, however, your e-mail software detects an Internet connection and starts to download your e-mail. A colleague back at headquarters sees your instant-messenger status change to ‘online’ and sends you a panicked plea: “Huge problem @ factory. Possible recall. Call Bob ASAP!” Armed with nothing more than wireless packet analyzer software, a fellow conference attendee in the same seating area may be able to glean competitive intelligence based solely on the Websites that you visit and the (probably unencrypted) instant messages you receive—not to mention the personal e-mail from the recruiter indicating that you’re ready to jump ship, or the notes reflecting your relationship problems with your signify cant other. In short, the “other guy” is reading your personal messages before you are, and you didn’t even do anything.

Source of Information : PC World July 2010

Nothing Is Private on Open Wi-Fi

Today, most tech users know how (and why) to secure their home wireless routers. Windows 7 and Vista now pop up a dialog box to warn you when you are connecting to an unencrypted wireless network. In a coffee shop, an airport lounge, or a library, however, people frequently connect to the network without thinking twice—and though using an unencrypted connection to check a baseball score or a flight status might be acceptable, using it to read e-mail or perform any Web activity that requires a login is akin to activating your speakerphone in the middle of a crowd. So why don’t all businesses encrypt their public Wi-Fi networks? The answer lies in the difficult key distribution system in the IEEE 802.11 design specification: To encrypt traffic, the network owner or manager must first select a password, also known as a “network key.” The arrangement requires one password per network, shared among all of the users whether the owner has selected the less secure, outdated WEP or the more secure WPA or WPA2. At home, all you have to do is set up the security measures once, tell your family the password, and surf worry-free from a poolside lounge chair. In a coffee shop, the barista would have to tell each patron the password (or the 26-character hexadecimal WEP key) and perhaps even troubleshoot their connection—definitely not a chore that your typical java slinger would relish. In that situation, nothing beats a blank password for ease of use. Even if the network is encrypted, however, you’re still not fully protected. Once your computer knows the password, your communication is safe only from people who aren’t on the network; all the other customers sitting in the cafĂ© can see your traffic because they are using the same password.

Source of Information : PC World July 2010


Subscribe to Developer Techno ?
Enter your email address:

Delivered by FeedBurner