News coverage of the recent flash flooding along the Guadalupe River in the Travis and Kerr counties of Texas has focused on the tragedy and resulting political drama, not on how to prevent similar tragedies in the future. The flood claimed 120 lives, and three persons remain unaccounted for. A significant portion of those lost were campers and staff at Camp Mystic, an all-girls Christian camp…
A recent ArsTechnica article raised questions about Chinese-supplied encryption chips, specifically the possibility that the chips could include backdoors allowing information to be compromised or decrypted by other than the authorized parties. This is a serious concern, but in my opinion the article erred by taking a far too narrow perspective on the implications. ...
Full applications shutdowns do not happen as frequently as in the past. However, the increasing tempo of revisions means that real-time and online systems component shutdowns and restarts are inevitable. Controlled shutdowns and restarts differ dramatically from uncontrolled shutdowns resulting from hardware and power failures. Despite the undeniable reality, many software components lack a…
We live in an interconnected world. We think nothing when we open our mobile phone to order something from an online store or to video chat with someone anywhere in the world. Distance matters little. Many people and businesses use online merchants with overnight delivery in place of local stock. Meeting and shopping online became second nature during the COVID-19 pandemic. Business organizations…
The general public is rarely impacted by poor choices in IT implementations. Unfortunately, the COVID-19 vaccination program has become an example of how not to implement important public-facing computer systems. ...
Regularly, I come upon reports that customer accounts at a website have been compromised. Invariably, users are told to change the passwords to their accounts, and consider the password compromised if it was used on other sites. ...
The COVID-19 pandemic has skyrocketed interest in and deployment of remote access arrangements. Previously, many organizations had arrangements for a limited amount of remote access - often professionals, IT staff, and field personnel. Some larger organizations, particularly those in finance and related industries, have already had long-standing contingency plans for remote working situations when…
Targeted SPAM calls soliciting payments are an escalating scourge, particularly when they target seniors. Exercising common sense when dealing with such calls is not difficult, and vigilence is essential. ...
The WebSocket protocol is a new facility; originally conceived as part of the HTML5 effort. Together with its applications programming interface (API), the WebSocket protocol provides a standard framework for ongoing communications between web clients and servers. The authors of the protocol deserve kudos for leveraging the existing HTTP/HTTPS infrastructure to provide an extended-lifetime link…
Forensically capturing a conventional disk is straightforward: power down the system, attach the drive to a portable forensic unit using a protective write blocking device, and then capture the device bit-for-bit. Since the drive is protected by a write blocking device, the drive is presumed completely intact. Non-conventional mass storage devices (e.g., "solid-state disks," hereafter "SSD")…
The sheer volume of electronically stored documents (ESI) often seems to obscure the actual business data stored on information systems. Digital forensics and electronic discovery (e-discovery) procedures encompass the full spectrum of digital information. In the legal community, electronic data is known as "Electronically stored information" (ESI). The sheer volume of documents, presentations,…
Pervasive communication is more than a convenience; the societal landscape has been significantly altered by pervasive connectivity and the resultant availability of information. Our practices must correspondingly be revised to reflect this new landscape. The pervasiveness of wireless communications has reached the threshold where the integrity of jury trials is at risk. ...
Recently, I received a call from a former client about an incident involving an outsourced business-critical application. His experience illustrates both the advantages and hazards of outsourcing a business-critical application. These issues affect all pay-as-you-go providers, whether Software-as-a-Service (Saas) or Applications Service Providers (ASP).
X-ray exposure and damage to human dignity are not the only potential hazards of recent changes in US Transportation Security Agency (TSA) procedures. While I freely admit that I have not had to go through a TSA checkpoint in the last few weeks, I note that the last time I traveled, I do not recall seeing a sight that should have been obvious: a supply of disposable gloves. In many ways, this is…
The US Transportation Security Administration (TSA) implementation of enhanced security for air travelers has raised a well-spring of protest. What has been absent from the conversation has been a full discussion of the efficacy of these measures versus the risks. ...
Reconnaissance has gone retail. Capabilities that used to be the costly province of nation states have been democratized. Communications technologies have become so pervasive that a newborn's first pictures are likely to be transmitted wirelessly within moments of birth, arriving at beaming grandparents half a world away within seconds, if not in real-time. ...
There was never much of a question: Google Street View's cars logged unencrypted Wi-Fi data as they traversed streets and neighborhoods around the world. Given the number of networks surveyed, it is unsurprising that some of the logged data contained messages or passwords. However, the reaction to this episode is out-of-scale to the actual risk that it poses. It is well-known that unencrypted…
The Patient Protection and Affordable Care Act of 2010 (PL 111-148) enacted a dramatic expansion of transactional reporting. Under the enacted changes, all payments made in a trade or business for goods and/or services whose aggregate value exceeds US$600.00 must be reported whether the recipient is an individual or a corporation. Previously, only services provided by proprietorships had been…
Decreasing technology costs challenge privacy. In the United States, privacy is protected by law and economics. Economic feasibility is the often unmentioned leitmotif behind our constitutional rights. Government surveillance can broaden substantially when the costs dwindle to insignificance. This is a challenge. For example, telephones were a century in the future when the US Constitution and its…
Processor virtualization is trendy. It is a buzzword often used in corporate and professional IT. While undoubtedly highly useful in professional contexts; processor virtualization has far wider applicability. Disposable Virtual Machines are one such use. ...
Feasibility tests are important. Many ideas seem logical and well-thought out, only to show fatal flaws when implemented under real conditions, even on a small scale as pilot projects. Demonstrating feasibility and uncovering hazards and side effects are the raison d'etre of pilot studies, innovation demonstration programs, and medical trials. Sometimes such experiments are a success, sometimes…
Each December, my office receives a flurry of requests from clients by facsimile, electronic mail, and conventional mail. In and of itself, each request is simple: A request that we supply a current Form W-9 certifying our Employer Identification Number (EIN) or Social Security Number. This despite the fact that our billhead clearly includes our Employer Identification Number on the masthead. We…
A provision deep within the recent Patient Protection and Affordable Care Act (Public Law 111-148) will drastically change record keeping and processing beginning in January 2012. This has dramatic and serious implications for Information Technology professionals, who must architect, design, and implement the business and information processes needed to collect the required data and produce the…
At the 2009 Trenton Computer Festival Professional Conference in April 2009, I presented “Web Efficiency: Using XHTML, CSS, and Server-side to Maximize Efficiency”. The focus of my presentation was that efficiency, scale, and costs are inextricably connected. ...
Parentheses often seem an afterthought. Readable code is deemed important, but often the emphasis seems to focus on typographical concerns such as indentation and spacing. The same can be said for good commenting, which is non-operative commentary. These practices are part of every introductory programming class. Documentation and readability are important, yet correctness of code is even more…
The recent news of unintended acceleration incidents involving Toyota-made automobiles raises an interesting, but unsurprising question of preparedness: Why are more people not prepared to deal with the unexpected while driving? This is not a question of reducing the manufacturer's liability or responsibility, but a simple matter of self-preservation: It is better to be a survivor able to bear…
Cyberspace is not a universe unto itself. For businesses, cyberspace is intimately connected to the real world. Most of the time, these connections are beneficial. Sometimes they are not.
Some network security incidents are so obviously preventable that it is mind boggling. Such was the case with a recent Wi-Fi-based network security breach at a client. It was eminently preventable. It was even more upsetting when I found out that the source of the incident was a carrier-supplied device that had been configured by the broadband provider's technician.
A recent episode involving an online site, Switched.com, brought the 1964 Simon and Garfunkel song, “The Sounds of Silence” to mind. In this case, the reminder was not pleasant. It was the realities of censorship, albeit a subtle censorship. It is a censorship that seems to happen without notice in the online world. ...
Last week, there were several articles about Vanish, a technology to automatically render electronic data unrecoverable at a specified future time. Vanish was developed by a team at the University of Washington. The goal of Vanish is to enhance privacy by creating data that will automatically self-destruct at a specified time in the future, making protected electronic information immune to future…
Thursday, June 25, 2009 was eventful. In the morning (Eastern Time in North America), Farrah Fawcett passed away after an extended battle with cancer. In the evening, Michael Jackson suffered an apparent cardiac arrest, and passed. Somewhat overshadowed by these event in the entertainment and culture world, a political drama was unfolding with the revelations of an extra-marital relationship…
Micro-blogging is all the rage. Social networking sites including Twitter, Facebook, MySpace, LinkedIn, and numerous others encourage us to share details about our daily lives with all those we know, even passing acquaintances. While this can be entertaining, there are numerous hazards from widely sharing unfiltered information about our lives, whether personal or professional.
In the mid-1990's, I was on-site when a bank's data center was caught by a power failure. As is the case with most “interesting” events, the incident exposed a number of shortcomings in the contingency plans. One of these shortcomings was that the data center, located in the upper reaches of the building, lost touch with the IT staff, who were domiciled on a far lower floor of the same building.…
Sometimes, one gets asked a question in an informal context, and it triggers a whole line of thought. The other day, I was waiting for my car to have an oil change. Another customer asked what I did, when I told him, he asked if I thought that the whole “running a computer” thing would disappear in a few years. He was asking about whether the answer to backup was to put everything “in the cloud”…
Requirements to preserve records always need to achieve a complex balance between costs, accuracy, and public policy. The February 13 introduction of S.436, the "Internet SAFETY" Act offered by Senator John Cornyn (R-Texas) proposes to mandate long term storage of dynamic address assignments presents several interesting policy and technical challenges.
The New York Enterprise Windows Users Group has invited Robert Gezelter to speak on March 5. My presentation will be on a topic which is delicate for most organizations: What should the response be when something happens involving the network or computers attached to it?
This morning's paper had yet another story about a major security breach at a payment card processor. In "Credit Card Processor Says Some Data Was Stolen", the compromise of a large number of credit card numbers and other data was recently reported. Presumably this processor was reviewed under the applicable standards, so why are data breaches continuing?