Tuesday, April 14, 2015

8 reasons to use 1Password that don't involve storing passwords

Macworld 8 reasons to use 1Password that don't involve storing passwords

Available for Mac, iOS, Windows, and Android, 1Password is a must-have for desktop and mobile users seeking equal parts online security and convenience. But there's far more to this software than its single-purpose name might imply.

1Password owners managing only logins and passwords are missing out on tons of other goodies already bundled inside the desktop versions. (The mobile versions require a paid Pro upgrade to unlock some additional features.) Read on and learn how to make your old password manager perform a few new tricks!

Credit cards

Sure, 1Password takes the heavy lifting out of logging into your favorite websites, but it does an equally fabulous job filling in payment details for online stores—no matter how many different credit or debit cards you happen to use.

1password credit cards

Managing credit cards on the iPad is just as easy as passwords with 1Password.

1Password also goes far beyond the basic details of Apple's own iCloud Keychain, allowing shoppers to store a wealth of additional information, including the issuing bank, toll-free and international contact numbers, interest rate, PIN codes, and cash withdrawal or credit limits.

Pro tip: Jot down eligible rewards categories in the Notes field of each card to see where you can accumulate the most points while shopping.

Secure notes

We're big fans of Evernote, but if you're looking to reduce the number of apps on your devices, 1Password's built-in Secure Notes could be just the ticket. While not as robust as Evernote, 1Password secures notes with the same tamper-proof authenticated encryption used for passwords, along with any files attached to those bits of data. Like other 1Password categories, users can also add tags, making information easier to find in a search.

1password secure notes

Add a secure element to taking notes by using 1Password instead of Apple's built-in app.

Pro tip: Tick the star icon to add frequently used notes to your Favorites for faster access.

Membership and loyalty cards

Between frequent flyer programs and retail loyalty cards, key rings are used less for unlocking doors and more as a place to store plastic barcode widgets. But how many of those do you actually need to carry in your pocket? How about zero?

1password membership

Unload all the plastic from your key ring by porting those loyalty card numbers to 1Password instead.

1Password includes a pair of convenient Memberships and Reward Programs categories for this very purpose, which can be used to enter all of those digits and potentially free up space on your keychain or in your wallet.

Pro tip: Next time you rent a car or book a flight online, leave those cards at home—you'll have them safely stored inside the mobile app, should you need to look them up again.

Online identities

Between work and home, many of us now have more than one identity online—for example, freelancers might prefer to have payments and related correspondence sent to a work address (even if it's just a P.O. box), while personal items such as credit card and utility bills go directly to a house or apartment.

1password identities

You don't have to have a secret identity to make use of 1Password's Identities feature.

Web browsers typically aren't great about remembering credentials for more than one user at a time, but 1Password is more than up to this task. Simply create a separate item in the Identities category, give it a unique name, and the next time you need to choose a specific online identity, just select the corresponding entry.

Pro tip: Set up the initial identity, then use the Duplicate option and edit accordingly to save keystrokes for new entries.

Licenses and passports

We're not yet living in a future where smartphones can replace physical identification cards such as a state driver's license or government-issued passport, but that doesn't mean it's not a good idea to have the information represented on those documents securely backed up, should they become lost or stolen.

1password licenses

Use 1Password to keep a virtual backup of passports and ID cards for the entire family.

1Password once again comes to the rescue, with dedicated Driver's License and Passports categories specially built for storing details from these sensitive documents.

Pro tip: Scan your originals and attach to their electronic counterparts, rather than carrying around photocopies while traveling overseas.

Software licenses

Although the Mac App Store has largely eliminated the need for serial numbers or license keys for new software, there are still plenty of titles sold outside of Apple's virtual storefront, with 1Password is a great way to manage important ownership details.

1password software licenses

1Password can also wrangle serial numbers and license keys for software purchased outside the Mac App Store.

1Password can keep track of version numbers, purchase and support information, and how much the software cost, all with a colorful icon pulled straight from the application itself.

Pro tip: Create new entries quickly by dragging the application onto Software Licenses, which also extracts the current version number at the same time.

Social Security cards

By this point, it shouldn't be much of a surprise to discover 1Password includes a category dedicated to storing Social Security numbers—the nine digits all Americans are assigned soon after birth, and which are now required when verifying employment, borrowing money, or checking a credit score.

1password ssn

Keep your Social Security Number safe at home and let 1Password remember those digits for the next time.

Many security experts advise consumers to keep original Social Security cards safely locked away at home, so if your memory isn't what it used to be, rely on 1Password to get the job done instead. Pro tip: Add entries for the entire family, including elderly parents or grandparents under your care.

Bank accounts

Not everyone needs more than one bank account, but for those who do, 1Password is once again a godsend, securely storing account, routing, and PIN code numbers for checking or savings accounts—particularly handy for a new generation of bank customers who have little need for paper checks.

1password bank

No matter how many bank accounts you have, 1Password will keep their details safe and secure.

Pro tip: Don't forget bank address and SWIFT codes, which you'll need prior to receiving domestic or international wire transfers.




http://www.macworld.com/article/2909673/8-reasons-to-use-1password-that-dont-involve-storing-passwords.html#tk.rss_all

Sent with Reeder



Brief message sent from a mobile device

Thursday, April 9, 2015

5 things you need to know about big data

TechRadar: All latest feeds 5 things you need to know about big data

5 things you need to know about big data

Introduction

Big Data SAP

Big in name and big in nature, big data is a technology buzzword that isn't going away any time soon. ABI Research thinks that big data spending on a global basis exceeded $31 billion (around £20.8 billion, or AU$40.2 billion) in 2013 and will motor on to hit $114 billion (around £76.6 billion, or AU$148 billion) in 2018, and yet there are many who are still befuddled as to what big data actually is and why it might be worth that eye-watering amount in just three years time.

1. What is it?

Big Data server

Purely and simply it's a term used to describe the huge data sets that are being produced by the digital processes and social media exchanges that are currently increasing by the bucket-load every minute of every day. It's a mish-mash of both structured, semi-structured and unstructured data that cannot be handled by regular databases or software, and instead has to be funnelled through specific analytical programs.

Processing big data is already big business and the lack of skills out there to properly use the analytics to decipher actionable insights is something that is still a very real problem, even though we are reasonably far along when it comes to understanding what big data is.

2. Solid analytics are the key

Cloud analytics

Drawing any sort of business advantage from big data means having solid analytics in place as well as the skills to use them. Possessing a successful analytics model means that your business will be able to find new correlations to solve problems, identify trends and basically make more money.

A succinct analysis of big data analytics was given by Michael Watson of the Supply Chain Quarterly, where he wrote that there are three different types of analytics: descriptive, predictive and prescriptive. Descriptive presents data in a way that lets you know what is going on in the place the data is drawn from. Predictive describes the way you can take data and make better predictions using it. Prescriptive, meanwhile, concerns using data combined with the subsequent predictions to take action that will improve business.

Marrying these together and asking the right questions at the beginning of the whole analytical process are key to making sure your model works and delivers the results you desire.

3. Internet of Things contributes a lot

Plant

Believe it or not, Gartner has a Hype Cycle for Emerging Technologies and after topping the table in 2013, big data has slipped behind another of the technology buzzwords of the moment - the Internet of Things. Even though this is the case, big data has a huge amount to benefit from when it comes to the IoT.

Cisco's conservative estimate on the IoT mentions that the number of connected devices will hit 21 billion by 2018 and the bad news for any unprepared firms is that there is going to be zettabyte upon zettabyte of data to keep a handle on. Making sense of all this data is something that is still proving to be a huge challenge and the skills gap, which we will come to in the next slide, is something that has the potential to make or break the success of the data drawn from all these "things".

4. There is still a big skills gap

Hadron Collider

Data scientists are tasked with handling the data sets on offer and producing insights from them, and for anyone looking to kick off a career the news is good: the skills gap for data scientists is currently huge. Research from Gartner found that 85% of companies on the Fortune 500 list will fail to exploit data in an effective way in 2015 and deciding how to bridge this gap is critical for enterprises to realise the benefits of big data.

Accenture, meanwhile, carried out a year-long research project on data scientists and found that the United States will create around 39,000 new jobs for analytical experts through 2015, but will only actually be able to assign candidates to 23% of those roles.

An easy way to fill in the gaps is, obviously, to train and promote from within although this depends on the right training being in place as well as having the "right" people within the organisation in the first place. The other way is education.

One such educational institution trying to help is the European Data Science Academy, which is an online platform for training data scientists across Europe. It claims that the demand for professionals with the skills to manage big data will grow by 160% by 2020 and has already secured a €2.9 million (£2.2 million, or $3.25 million) investment from the EU to run a range of courses, which get underway in late 2015. More schemes like this are also in the pipeline and they can only help to address the shortfall.

5. Rich data could be even more important

Rich data

Dr. Rado Kotorov, chief innovation officer at Information Builders, put it well when he described the difference between big data and rich data as the way that crude and refined oil differ. Rich data, in layman's terms, is what comes out when data from different systems is combined and given a context so that it becomes a practical proposition for businesses and individuals.

It solves one of the main complaints about big data in that the unstructured data produced doesn't provided a detailed enough insight compared to the level of contextualised data that is possible with rich data. The fact that rich data needs big data in order to exist means that big data will never go away, yet for the higher level of insights and benefits, rich data has to be a part of the picture.

One of the big concerns about rich data, however, will ultimately be that it is more detailed and as such could present a privacy risk to consumers that unstructured big data may not end up doing. What this could well present is a situation where consumers become even more guarded over their personal data and choose to give less up to the companies asking for it, and perhaps even use it as a bargaining tool in the future.

"In the future, people may choose to control information that they are creating and then monetise this back to companies – this may be in the form of lowering their bills or getting better service quality from one provider," admitted Matt Pfeil, Chief Customer Officer at DataStax.











http://rss.feedsportal.com/c/669/f/9809/s/45403af3/sc/28/l/0L0Stechradar0N0Cnews0Cworld0Eof0Etech0Cfuture0Etech0C50Ethings0Eyou0Eneed0Eto0Eknow0Eabout0Ebig0Edata0E1290A5750Dsrc0Frss0Gattr0Fall/story01.htm

Sent with Reeder



Aron

Brief message sent from a handheld device.

Wednesday, March 11, 2015

Create a Distributed File System Namespace in Windows Server 2012 R2

Petri IT Knowledgebase Create a Distributed File System Namespace in Windows Server 2012 R2

WinServer2012 logo

In this Ask the Admin, I'm going to demystify the process of setting up a Distributed File System (DFS) namespace in Windows Server 2012 R2.

Sponsored

DFS namespaces provide users with a logical way to access files without needing to know their physical location. Sitting in front of your physical file servers, a DFS namespace is a hierarchy of UNC paths that don't reference the actual file servers, but transparently redirect users to the nearest copy of the data via NTFS shares. DFS can also help to mitigate some of the issues commonly associated with migrating or consolidating existing file servers, such as maintaining UNC paths during migration projects.

When used with DFS replication, IT can provide users access to local copies of their data in different geographical locations without needing to pull data across expensive wide-area networks. DFS replication is an optional feature, and in this article I want to concentrate only on the namespace aspect of the equation.

Distributed File System Concepts and Terminology

A DFS namespace can be created even if you only have one file server, and the file server itself can act as a namespace server, i.e. the server where DFS will be installed and the namespace configured. The folders that contain the data to be accessed are known as folder targets, and even when they are located on the namespace server, they must be shared because DFS doesn't differentiate between folder targets located on the namespace server or remote file servers.

When configuring a DFS namespace, you create a DFS root on a namespace server. This root must also exist as a shared folder. In Figure 1 below, you can see a DFS root (\\contoso\public) configured on a namespace server with folder targets (Tools and Training Guides) being directed to a series of remote file servers.

A Distributed File System (DFS) Namespace (Image Credit: Microsoft)

A Distributed File System (DFS) Namespace (Image Credit: Microsoft)

There's also a folder called Software. DFS folders are optional, existing purely to provide extra flexibility in organizing the namespace hierarchy. So for example, a user can access Tools using \\contoso\public\software\tools\ and will be transparently redirected to the London or New York server depending on their physical location. Similarly, \\contoso\public\Training Guides will direct users to the Training share on the New York server.

Sponsored

Create a DFS Namespace

For simplicity I'm going to create a DFS namespace called files in Windows Server 2012 R2. Theres only one file server (contososrv1) in my domain, and this will be where I install the DFS bits, and it will act as the namespace server. To configure and install the DFS namespace feature, log in to the file server with domain administrative privileges, open a PowerShell prompt and type the command below:

Install-WindowsFeature FS-DFS-Namespace

The file server currently has no shared folders, so I'm going to create three folders: sales, accounts, and production; and a folder for the namespace (DFS root), using the mkdir cmdlet. Note that you can use existing shared folders that are already populated with files.

$folders = ('C:\dfsroots\files','C:\shares\sales','C:\shares\accounts','C:\shares\production')   mkdir -path $folders

Once the folders have been created, they need to be shared. The code below shares each folder using the New-SMBShare cmdlet, giving Everyone full access.

$folders | ForEach-Object {$sharename = (Get-Item $_).name; New-SMBShare -Name $shareName -Path $_ -FullAccess Everyone}

Now that the necessary folders and shares are in place, I can create the DFS namespace using the New-DfsnRoot cmdlet. \\ad.contoso.com\files is the UNC path for accessing the namespace, and \\contososrv1\files is used to specify the DFS root namespace server and path. The –Type parameter can be set to one of three values:

  • Standalone for a namespace that's not integrated with Active Directory
  • DomainV1 for a Windows 2000 Server mode domain namespace
  • DomainV2 for a Windows Server 2008 mode domain namespace
Sponsored

For more information on the differences between standalone and domain-based namespaces, see Planning a DFS Architecture, Part 1 on the Petri IT Knowledgebase. Before selecting the DomainV2 mode, make sure that the forest-functional level is set to Windows Server 2003 or higher, the domain functional level is set to Windows Server 2008 or higher, and that all namespace servers are running Windows Server 2008 or later.

New-DfsnRoot -Path \\ad.contoso.com\files -TargetPath \\contososrv1\files -Type DomainV2

Creating a DFS namespace in Windows Server 2012 R2 (Image Credit: Russell Smith)

Creating a DFS namespace in Windows Server 2012 R2 (Image Credit: Russell Smith)

Finally, we need to add the folder targets to the namespace, i.e. sales, accounts, and production, which are separated from the DFS root in the shares folder. The code below adds each share to the files namespace:

$folders | Where-Object {$_ -like "*shares*"} | ForEach-Object {$name = (Get-Item $_).name; $DfsPath = ('\\ad.contoso.com\files\' + $name); $targetPath = ('\\contososrv1\' + $name);New-DfsnFolderTarget -Path $dfsPath -TargetPath $targetPath}

Now users can access the namespace in File Explorer from any domain-joined device using \\ad.contoso.com\files\, and the sales, accounts, and production folders can be populated with files.

The post Create a Distributed File System Namespace in Windows Server 2012 R2 appeared first on Petri.




http://feedproxy.google.com/~r/Petri/~3/4VMYZElo3q0/create-a-distributed-file-system-namespace-in-windows-server-2012-r2.htm

Sent with Reeder



Brief message sent from a mobile device

Thursday, February 12, 2015

The top 5 reasons why Google Hangouts never works

Geek Tech The top 5 reasons why Google Hangouts never works

Editor's note: To be fair to Google Hangouts, Skype has its problems, too. But it's Google Hangouts that PCWorld's editors have, for several years, tried and largely failed to use for staff meetings with remote users. Just when we think we've figured out all the kinks, something else goes awry. So we feel our readers' pain on this one, and that's why we asked videoconferencing expert Christopher Null how to cure five of its most notable headaches. Did we miss a Hangouts hangup that's making your life hellish? Let us know in the comments. 

1. Hangouts doesn't work in Internet Explorer from the Windows 8 Start screen

google hangouts 1 Image: Christopher Null

Sorry, Metro fans! Launch your browser from the Windows desktop in order to use Chrome.

If you're using the Start screen to launch Internet Explorer, you may find that Hangouts simply doesn't work. That's because Hangouts requires a plug-in to operate on IE, and the full-screen, Metro-style version of IE doesn't allow any plug-ins at all. To work around this, you have a couple of choices. You can run IE in Desktop mode by launching it from the desktop instead of the Start screen, and then install Hangouts, or you can simply switch to another browser.

2. If you run Hangouts on multiple devices, Hangouts sends notifications to everything that's running, causing alert overload

google hangouts 2 Image: Christopher Null

Stem the flood of notifications by closing the Hangouts app or signing out.

If you have Hangouts open on your desktop and your phone simultaneously, notifications will pop up on both devices, even if you aren't actively engaged with one of them.

This is unfortunately a known issue with Hangouts. It's a pain for some users, while other users actually prefer it to work this way. 

If you're getting too many notifications, a few solutions are available. First, you can sign out of Hangouts on devices or browsers form which you don't want notifications, or close the app altogether.

On Android devices, you have a few more options. You can use Menu > Snooze notifications to suspend alerts on that device. Notifications can also be suspended indefinitely on a per-user basis by selecting the gear icon in a Hangout window and unchecking the Notifications box there.

3. Photos sent via Hangouts over MMS taken in portrait mode automatically rotate and turn into landscape photos

This is a specific issue related to Hangouts on certain Android phones when pictures are sent over MMS. Many users report that the problem is erratic and that clearing application data from the Android Applications Manager may help, at least some of the time.

The more reliable solution is not to use the camera within Hangouts to snap photos, but to take pictures separately, using the standard Android camera. When portrait photos are attached from your photo library, they seem to come through with the proper rotation intact.

4. Video calls don't work

While there are many potential reasons that Hangouts won't initiate a video call, here are a few of the most common troubleshooting tips.

First, the Chrome browser doesn't require a plug-in for Hangouts to work… unless your company uses Google Apps, in which case you will still have to install the Hangouts plug-in to make video calls. It's also a good idea to install the Hangouts Chrome app, which adds Hangouts to the Chrome App Launcher, where you can initiate a new video call.

Note that Hangouts does not support a handful of webcams, microphones, and audio devices. Presuming this is not your issue, make sure the correct audio gear is selected within Hangout's settings menu. To find this menu, initiate a new video, then click the gear icon.Hangouts may work better if you select specific devices for each of the three options instead of "Default."

Finally, in general, restarting your browser and/or your computer is also a good cure-all for any video-related problem within Hangouts.

5. The Hangouts Browser plug-in won't install (or disappears)

Can't install the Hangouts plug-in? First, make sure you aren't running 64-bit Internet Explorer, as the plug-in is not supported on this browser. If you're using Chrome, check chrome://plugins/ to see if the Google Talk plug-in is installed and enabled. (The name is a remnant of Hangouts' prior incarnation.)

You can also try uninstalling this plug-in (instructions can be found here) and reinstalling it. Remember that the Hangouts app is different from the Hangouts plug-in. (You don't need the former, but all browsers except Chrome require the latter.) If the Hangouts app has vanished from Chrome, simply re-enable it by re-downloading it from the Chrome Web Store.




http://www.pcworld.com/article/2883313/the-top-5-reasons-why-google-hangouts-never-works.html#tk.rss_all

Sent with Reeder



Brief message sent from a mobile device

Friday, February 6, 2015

Small firms wrestle with IT security

BBCTech Small firms wrestle with IT security

Man in waves
The tidal wave of security threats is almost overwhelming for almost every business

Keeping cyber thieves at bay is hard. They are busy, well-motivated and well-financed.

Just one example serves to show just how prolific they are. Every day, come rain or shine, they crank out about 250,000 novel variants of viruses.

Their vigour has helped them steal data from some really big companies, Target, Home Depot and eBay, in the last few months.

And, what is a problem for the big companies is even more acute for the smaller firms. They have an even tougher time keeping the bad guys out.

"They are exposed to many of the same attacks as much larger enterprises, yet they don't have the security expertise and resources available to those larger firms," said Maxim Weinstein, a security advisor at security firm Sophos.

While attacks on the eBays and Sonys of the world make the headlines there's no doubt that smaller firms are getting hit. And getting hit hard.

Figures from Sophos suggest about 30,000 websites a day are being compromised by cyber bad guys - most of those will be the public face of one SME or others.

Smartphones
The rise of the smartphone means few small businesses do not rely on technology to some extent

Becoming a victim of a hack or breach costs smaller firms between £65,000 and £115,000, according to the PWC survey of the worst data breaches among small firms. Those worst hit will suffer up to six breaches a year, PWC suggested, so the total cost could be even higher.

For a smaller firm finding that much cash to clean up after a breach could mean the difference between keeping trading and going bust.

This lack of focus on cyber security is understandable, said Mr Weinstein, as most small and medium-sized enterprises (SMEs) spent most of their time on core commercial activity such as keeping customers happy, seeking out new clients and engaging in all the basic day-to-day admin needed to keep their enterprise afloat.

Worrying about computer security comes a long down their To Do lists, he said.

Cyber commerce

But they do need to worry because the nature of commerce in the 21st century means that there are relatively few SMEs that do not make heavy use of technology, said Stephen Harrison, lead technologist at IT services firm Exponential-e.

Ruined fort
A fortress-style security stance is no longer possible, say experts

"You do see a knowledge gap," he said "in that you have these smaller companies that are smaller in terms of people and revenue but they are not smaller in terms of the IT they use."

Ecommerce, websites, apps, smartphones, tablets, social media and cloud services were all now standard ways of doing business in the 21st century, he said.

And, he added, there were some SMEs that were based entirely around technology but that did not make them experts in how to keep their digital business secure.

"There are some businesses that are much more than just users of technology," he said. "They have huge computing requirements as well as massive storage and bandwidth requirements - far more than their head count would suggest."

Either way, he said, everyone is a target and they all need to look externally to security firms for help.

"In the same way they don't run your own bank or accountancy firm they shouldn't run their own security operation," he said adding that SMEs often need help to understand the sheer range of threats arrayed against them.

Everyone is familiar with attempts to penetrate internal networks to steal payment information or customer data records but may be less knowledgeable about invoice fraud, ransomware, malvertising, or even attacks that "scrape" websites with automated tools to steal all the information about prices and products they contain.

Cash question

And that was where they hit their first problem, he said. How much do they spend? Estimates vary on how much SMEs spend on IT security.

The most recent government figures published 18 months ago suggest SMEs with 100 or more employees spend about £10,000 per year. The smallest small firms, with less than 20 staff, spend about £200. Other estimates put the spend at about £30 per employee.

Mr Weinstein from Sophos said SMEs should start with the basics.

This includes anti-virus software, firewalls, spam filters on email gateways and keeping devices up to date. This, he said, would defeat the majority of the low level threats that those busy cyber thieves are churning out.

Government advice on how SMEs can be safer revolves around a 10 steps programme that emphasises basic, good practice. It's big on those simple steps such as keeping software up to date and applying the widely used software tools that can spot and stop the most prolific threats.

Cash next to keyboard
Small firms have to spend their money wisely to be as secure as possible

But it also stresses that smaller firms understand more about how they use data and how it flows around their organisation.

This is important, said Greg Hanson from services firm Informatica, because security is no longer about setting up a fortress around your systems, servers and staff to keep the bad guys out. Now, he said, the way data flows between SMEs, their supply chains and customers has made it impossible to maintain the fortress-like security stance.

Having a good sense of where data goes and who uses it can help limit the damage if it goes astray, he said.

"There's a proliferation of data flowing through organisations that really needs to be controlled better," he said.

Having control of that data, knowing its value and where it is going, can help a company guard against it leaking out accidentally and maliciously. For instance, having that control might help a firm spot that a server was accidentally exposed to the net and private information was viewable by anyone.

It can also help SMEs keep an eye on their suppliers and partners to ensure that data is handled appropriately.

And finally, said Mr Harrison from Exponential-e, firms need to put in place a plan for what happens when a breach or security incident does occur.

"It's not a question of if something bad will happen," he said. "It will, but it's all about what they do about it."




http://www.bbc.co.uk/news/technology-31039137#sa-ns_mchannel=rss&ns_source=PublicRSS20-sa

Sent with Reeder



Brief message sent from a mobile device

Friday, January 30, 2015

Industry voice: Seven cyber-security risks your business should be aware of in 2015

TechRadar: All latest feeds Industry voice: Seven cyber-security risks your business should be aware of in 2015

With Sony being the latest major victim of hacking, large organisations are witnessing yet again how data breaches cause serious damage to the tune of millions. The prevalence of hacking in the media begs the question: what's in store for 2015?

Against a background of more frequent and dangerous XSS attacks, third-party code and plugins remaining the Achilles heel of web applications, and growing chained attacks, organisations will be looking to new ways to protect their online properties.

Unfortunately, it's pretty difficult to make information security predictions, and even more difficult to verify them afterwards – we can only judge the effectiveness of information security by the number of public security incidents, as the majority of data breaches remain undetected.

However, in this article we're going to make some web security predictions based on common sense profitability (profit/cost ratio) for hackers…

1. Vulnerable web applications will remain the easiest way to compromise companies

When almost any company has one or even several vulnerable web applications, hackers will not bother to launch complex and expensive APT attacks with zero-day exploits. Companies continue to seriously underestimate the risks related to their web applications and website. A tiny vulnerability, such as XSS, can lead to the compromise of the entire local network, emails and databases of a company.

2. XSS will become a more frequent and dangerous vector of attacks

It's very difficult to detect high or critical risk vulnerabilities in well-known web products (e.g. Joomla, WordPress, SharePoint, etc). However, low and medium risk vulnerabilities, such as XSS, will still regularly appear. Sophisticated exploitation of an XSS can give the same outcomes as an SQL injection vulnerability, therefore hackers will rely on XSS attacks more and more to achieve their goals.

3. Third-party code and plugins will remain the Achilles heel of web applications

While the core code of well-known CMS systems and other web products are pretty safe today, third-party code such as various plugins or extensions remain vulnerable even to high risk vulnerabilities. People tend to forget that one outdated plugin or third-party website voting script endangers the entire web application. Obviously hackers will not miss such opportunities.

4. Chained attacks and attacks via third-party websites will grow

Today it's pretty difficult to find a critical vulnerability on a well-known website. It's much quicker and thus cheaper for hackers to find several medium risk vulnerabilities and use a combination of these to get complete access to the website.

Another trend is to attack a reputable website that the victim regularly visits. For example, when chasing for a C-level executive, hackers may compromise several high-profile financial websites or newspapers, and insert an exploit pack that will be activated only for a specific IP, user-agent and authentication cookie combination belonging to the victim. Such attacks are very difficult to detect, as only the victim can notice the attack.

5. Weak passwords and password re-use will remain a very serious problem

Many people still use the same or similar passwords for all their accounts. Hackers cannot miss such opportunities and actively exploit this human weakness. The first step of attack is to identify all websites or blogs where the victim is registered or has an account. The second step is to select the weakest website from the list and to compromise it. Password encryption techniques commonly used in web applications today are far from being resistant, and a password in plaintext can be obtained pretty quickly.

Even if the victim uses a very strong password and it's being properly encrypted in the database. hackers will just Trojan the web application to intercept the password in plaintext during login. The last step is to try the password for all the victim's accounts and resources.

6. Application logic errors will become more frequent and critical

Examples with AliExpress and Delta Airlines highlight the impact of application logic vulnerabilities that are almost undetectable by automated solutions. Web developers have become aware about XSS and SQL injections flaws and code much better than before, however they forget about application logic vulnerabilities that may be even more dangerous than SQL injections or RCEs.

7. Automated security tools and solutions will not be efficient anymore

Web Application Firewalls, Web Vulnerability Scanners or Malware Detection services will not be efficient anymore if used separately or without human control. Both web vulnerabilities and web attacks are becoming more and more sophisticated and complex to detect, and human intervention is almost always necessary to properly detect all the vulnerabilities.

It's not enough anymore to patch 90% or even 99% of the vulnerabilities – hackers will detect the last vulnerability and use it to compromise the entire website. As a solution to the rise of new threats, High-Tech Bridge launched ImmuniWeb last year – a unique hybrid that efficiently combines automated security assessment with manual penetration testing.




http://rss.feedsportal.com/c/669/f/9809/s/42de7c7e/sc/4/l/0L0Stechradar0N0Cnews0Cworld0Eof0Etech0Cseven0Ecyber0Esecurity0Erisks0Eyour0Ebusiness0Eshould0Ebe0Eaware0Eof0Ein0E20A150E12827380Dsrc0Frss0Gattr0Fall/story01.htm

Sent with Reeder



Brief message sent from a mobile device

Tuesday, January 20, 2015

Download of the day: CrystalDiskInfo

TechRadar: All latest feeds Download of the day: CrystalDiskInfo

Download of the day: CrystalDiskInfo

Get to the bottom of any problems ailing your computer with CrystalDiskInfo, which shows you exactly what's wrong in an easy to use interface.

Why you need it

If there's something wrong with your computer, it's not always obvious what the problem is. Even experienced PC users can be stumped by a faulty computer, which makes CrystalDiskInfo such a useful program.

Get it up and running and it displays the S.M.A.R.T. information of your PC – that stands for Self-Monitoring, Analysis and Reporting Technology, and it lets you see exactly what's ailing your computer.

CrystalDiskInfo breaks this down and makes it easy to know exactly whether a drive is too hot or whether your computer is in general good health or is about to lay down and die. Even better, this useful little app can automatically send you alerts if a problem arises, meaning you can quickly address the problem before any serious damage is caused.

Key features

  • Works on: PC
  • Versions: Free
  • Diagnose problems: Find out exactly what is ailing your computer and solve the problem fast
  • Monitor PC health: CrystalDiskInfo can send you alerts when things go wrong, especially useful if you need to monitor several systems at once

You'll also like











http://rss.feedsportal.com/c/669/f/9809/s/42843139/sc/4/l/0L0Stechradar0N0Cus0Cnews0Csoftware0Cdownload0Eof0Ethe0Eday0Ecrystaldiskinfo0E1280A30A70Dsrc0Frss0Gattr0Fall/story01.htm

Sent with Reeder



Brief message sent from a mobile device

Friday, January 9, 2015

Download of the Day: Easy YouTube Video Downloader

TechRadar: All latest feeds Download of the Day: Easy YouTube Video Downloader

Download of the Day: Easy YouTube Video Downloader

Simple to use and quick to install, Easy YouTube Video Downloader enables you to grab your favourite videos from YouTube.

Why you need it

We all have our favourite online videos, but downloading them to our devices or viewing them offline can be a complicated process. Thankfully there's a quick and simple way to download YouTube videos to your computer: the suitably-named Easy YouTube Video Downloader extension for Firefox.

After installing the extension, you'll see a new bar directly below the YouTube video. This presents you with a few simple options for downloading the video in question: choose quality (Normal, 720p or 1080p) and format (FLV, 3GP, MP4 or just the MP3 audio) and you're good to go.

So that means whether you want to watch a video on a long journey or strip out the audio in order to listen to it as a podcast, you're able to do so with this little Firefox extension.

Key features

  • Works on: PC, Mac, Linux
  • Versions: Free
  • Download: Easy YouTube Video Downloader lets you grab any video featured on the world's most popular video site, and you can download audio, too
  • Convert: Download the file in a number of different formats and qualities

You'll also like











http://rss.feedsportal.com/c/669/f/9809/s/421fdafe/sc/4/l/0L0Stechradar0N0Cus0Cnews0Csoftware0Cdownload0Eof0Ethe0Eday0Eeasy0Eyoutube0Evideo0Edownloader0E12794690Dsrc0Frss0Gattr0Fall/story01.htm

Sent with Reeder



Aron

Brief message sent from a handheld device.

Wednesday, January 7, 2015

Should you rent or buy a home in retirement?

Consumer Reports Should you rent or buy a home in retirement?

Should you rent or buy a home in retirement?

Deciding whether to rent or buy a home was never an easy question for my parents. Now age 83 and 84, they always treated homeownership as sacrosanct. Not only was owning their home a symbol of success, but it provided a haven that offered security and comfort. 

But when my parents recently left the home they owned in New Jersey for 43 years to move near my sister in California, they opted to rent. And after decades of do-it-and-pay-for-it-yourself, they are finding—surprise!—that it's nice to have someone else handle the landscaping and call in the plumber.

My husband and I might do the same in retirement. And as I'm learning, though some factors in the decision to rent or buy are the same at any age, others take on more significance in retirement.

Check out Consumer Reports' advice on smart real estate moves, and find out how to judge Top 10 lists for relocating in retirement.

A first consideration is how long you expect to live in your new residence. Just because you're retired doesn't mean you'll stay in your new digs. Down the road, you might want something smaller or more accommodating to a disability.

But the shorter the stay, the less financially attractive owning a home in retirement becomes. For one, you'll have to spread points and other closing costs over less time. If you finance, you're likely to have little new equity to show because you'll pay so much in interest in a mortgage's first years.

For that reason, if you are retired, you should rent your home if you don't expect to stay more than three or four years, says Josh Fatoullah, founder and CEO of JR Wealth Advisors in Great Neck, N.Y. "The last thing we would want is where you've paid the closing costs and then you're just not happy," he says.

Assuming you can determine the minimum time you'll stay in a new home, you can then compare the costs of homeownership and renting. Early retiree Darrow Kirkpatrick provides an analysis in his insightful blog Can I Retire Yet?. He took a hypothetical $300,000 home in his Tennessee town and added up its expected maintenance and repair costs, property taxes, and homeowners insurance, then figured in the opportunity cost—what his money could earn in stocks and bonds if it wasn't tied up in home equity.

Kirkpatrick's estimated, effective cost of homeownership over a 10-year period was $834 per month for every $100,000 of a home's value. In other words, a $300,000 home would generate $834 x 3, or about $2,500 per month in ownership costs. If a retiree could find a comparable property to rent for less than $2,500 per month, he should rent.

Online mortgage calculators can personalize calculations like that for you. The New York Times' sophisticated rent-vs.-buy tool is among the better ones I've seen.

The Times' tool and Kirkpatrick's calculations also consider the impact of buying a home outright vs. getting a mortgage. If you can stomach holding on to debt late in life, you might benefit from getting a mortgage and investing in stocks, bonds, and other holdings rather than paying for your home outright. The National Association of Realtors says that since 1968 (when it began tracking real-estate inflation) through 2013, single-family home prices have increased 5.3 percent annually on average. In that same period, 10-year Treasury bonds returned an average 7.4 percent annually (neither figure accounts for inflation).

Of course, future stock, bond, and real-estate markets won't necessarily act as they have historically. Point is, the opportunity cost could be greater if you tie up money in a home rather than taking out a mortgage.

I can't speak of mortgages without mentioning the federal tax deduction on mortgage interest. It's often held up to justify owning. But it may be worth less if your retirement income puts you in a lower tax bracket than when you were working. (Income from required minimum distributions also can raise you to a higher tax bracket.)

Other, non-monetary factors may dominate your decision. If your pug requires a backyard lair or you'll feel lost without a home-improvement project, you'll want to buy—or find an owner who is OK with Roxy's ranging or welcomes your tinkering.

As for my mother, she's gardening at her rental home, just as she did in her New Jersey yard. This spring she expects to greet blooms of chocolate cosmos, hyacinths, tulips, bluebells, and daffodils. As a tribute to her new locale, she's adding California poppies.

They add a homey touch. 

—Tobie Stanger

This article also appeared in the January 2015 issue of Consumer Reports Money Adviser.

Consumer Reports has no relationship with any advertisers on this website. Copyright © 2006-2015 Consumers Union of U.S.

Subscribe now!
Subscribe to ConsumerReports.org for expert Ratings, buying advice and reliability on hundreds of products.
Update your feed preferences

                submit to reddit    




http://simplefeed.consumerreports.org/l?s=100003s276p6jt92ia3&r=feedly&he=687474702533412532462532467777772e636f6e73756d65727265706f7274732e6f726725324663726f2532466e65777325324632303135253246303125324673686f756c642d796f752d72656e742d6f722d6275792d612d686f6d652d696e2d7265746972656d656e742e68746d2533464558544b455925334449373252534841&i=727373696e3a687474703a2f2f7777772e636f6e73756d65727265706f7274732e6f72672f63726f2f6e6577732f323031352f30312f73686f756c642d796f752d72656e742d6f722d6275792d612d686f6d652d696e2d7265746972656d656e742e68746d

Sent with Reeder



Brief message sent from a mobile device