<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance &#187; network security</title>
	<atom:link href="http://blog.kraasecurity.com/tag/network-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 06 Jul 2011 01:12:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Can you protect yourself on Social Media?</title>
		<link>http://blog.kraasecurity.com/2010/03/01/can-you-protect-yourself-on-social-media/</link>
		<comments>http://blog.kraasecurity.com/2010/03/01/can-you-protect-yourself-on-social-media/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 02:44:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Social network]]></category>
		<category><![CDATA[Antivirus software]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=189</guid>
		<description><![CDATA[Image via Wikipedia One of the greatest challenges to privacy and security in the next several years is Social Networks and Social Media. Sites like Facebook, Twitter, LinkedIn, MySpace and others can be the downfall of valuing information. The ability to share and provide information is completely the opposite of network security requirements.  This is [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 105px; height: 47px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Facebook.svg"><img title="Facebook, Inc." src="http://upload.wikimedia.org/wikipedia/commons/thumb/0/06/Facebook.svg/266px-Facebook.svg.png" alt="Facebook, Inc." width="89" height="26" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Facebook.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>One of the greatest challenges to privacy and security in the next several years is <strong>Social Networks</strong> and <strong>Social Media</strong>. Sites like <a title="Facebook" href="http://facebook.com/">Facebook</a>, <a class="zem_slink freebase/en/twitter" title="Twitter" rel="homepage" href="http://twitter.com/">Twitter</a>, <a title="LinkedIn" href="http://www.linkedin.com/">LinkedIn</a>, <a title="MySpace" href="http://myspace.com/">MySpace</a> and others can be the downfall of valuing information. The ability to share and provide information is completely the opposite of <strong><a title="Network security" href="http://www.kraasecurity.com/consulting-services/network-solutions/vulnerability-assessment">network security</a></strong> requirements.  This is really encouraging people to do things that are not security conscious activities. Social media encourages:</p>
<ul>
<li>Lack of privacy</li>
<li>Encouraging information sharing</li>
<li>Giving away answers to security questions</li>
<li>Social engineering</li>
</ul>
<p>As we have seen recently, a lot of spam, <a class="zem_slink freebase/en/spyware" title="Spyware" rel="wikipedia" href="http://en.wikipedia.org/wiki/Spyware">spyware</a> and <a title="Malware" href="http://www.kraasecurity.com/managed-services/email-defense/antivirus">malware</a> is attacking social network. Just in the past week I have probably recieved a 100 requests to be my friend on Facebook from people who I do not know and funny enough, all the message have the exact same personal message. Malicious people are attracted to social networks because of the ease of gaining trust and availability of data for social engineering.  Relationship building is easier through social media which can easily lead to <strong><a title="Phishing malware" href="http://www.kraasecurity.com/managed-services/email-defense/antivirus">phishing</a></strong> attacks.</p>
<p>With these sites, people install applications without knowing what goes on in the background, and its easy to download <strong>malicious code</strong> to your computer. There are no external third party audits of these applications before the make it to your Facebook application. Your computer can be easily infected by a virus or <a title="content filtering" href="http://www.kraasecurity.com/managed-services/email-defense/content-filtering">spyware</a>.</p>
<p>What does the <strong>Social Media</strong> user to protect their information?<br />
No Personal information &#8211; This is anti-social network, but there are things you can limit about what you post. Don&#8217;t post your Birthday! Or your address or your mothers middle name or any really personal data.</p>
<p><strong>Limit who can view and contact you</strong> &#8211; Don&#8217;t let your profile be truly public, restrict to people you know for requested users.  Remember you can&#8217;t retract information you put out there. </p>
<p><strong>Don’t trust strangers</strong> &#8211; Your mother was right, don&#8217;t open the door to strangers. Limit who you accept chat or friend requests from and well as even communicate with.</p>
<p><strong>Trust no Profile</strong> &#8211; People lie, it’s sad but true. So profiles lie, they might say they went to your college or high school.  They might be interested in your groups, so don’t take anyone at their word.</p>
<p><strong>Restrict your privacy</strong> &#8211; There are some configuration setting in all the social media applications that can allow you to turn on some restrictions on your privacy. Take a minute to actually look at them. One easy example is in Facebook you can create groups that you can place friend in; you don&#8217;t want business people seeing what your friends are posting.</p>
<p><strong>Password management</strong> &#8211; An oldie but a goodie, always use a strong password and don&#8217;t share it. And change it periodically.</p>
<p><strong>Layers of protection</strong> &#8211; You should be running a <strong><a title="Firewall management" href="http://www.kraasecurity.com/managed-services/intrusion-defense/firewall">personal firewall</a></strong> and <strong>antivirus</strong> software on the machine you are viewing social networks. This will help if a malicious piece of software tries to download something to your machine. Keep your protection software up to date as well and run the patch management software on your machine, this is especially important for you Windows users.</p>
<p><strong>Child protection software</strong> &#8211; You should have some kind of <strong>child protection</strong> software running on machines where children under 13 are using. This will help with all that shady software that is out there.</p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong><em>Address</em></strong><em>: 200 Se 1st St #601 Miami FL 33131</em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p>*FREE Website Security Test </p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://seekingalpha.com/article/191290-half-of-online-adults-use-social-networks-at-least-monthly?source=feed">Half of Online Adults Use Social Networks at Least Monthly</a> (seekingalpha.com)</li>
<li class="zemanta-article-ul-li"><a href="http://arstechnica.com/business/news/2010/02/firms-worry-about-social-networks-but-not-blocking-access.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss">Firms worry about social networks, but don&#8217;t block access</a> (arstechnica.com)</li>
<li class="zemanta-article-ul-li"><a href="http://thewayoftheweb.net/2010/02/google-buzz-proves-problems-with-single-online-identities/">Google Buzz proves problems with single online identities</a> (thewayoftheweb.net)</li>
<li class="zemanta-article-ul-li"><a href="http://www.marketingvox.com/are-consumers-becoming-more-suspicious-of-social-networks-046260/?utm_campaign=rssfeed&amp;utm_source=mv&amp;utm_medium=textlink">Are Consumers Becoming More Suspicious of Social Networks?</a> (marketingvox.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.dominica-weekly.com/ramblings/seven-steps-to-safe-social-networking/">Seven Steps to Safe Social Networking</a> (dominica-weekly.com)</li>
<li class="zemanta-article-ul-li"><a href="http://mashable.com/2010/03/25/b2b-marketer-lessons/">13 Essential Social Media Lessons for B2B Marketers from the Masters</a> (mashable.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.slideshare.net/pr2020/social-media-for-ceos-3542229">Social Media for CEOs</a> (slideshare.net)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/6e138ad0-af9e-40d2-ab77-da1094d4aa21/"><img class="zemanta-pixie-img" style="float: right; border-style: none;" src="http://img.zemanta.com/reblog_e.png?x-id=6e138ad0-af9e-40d2-ab77-da1094d4aa21" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"> <script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2010/03/01/can-you-protect-yourself-on-social-media/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stolen laptop with employee information- yet again</title>
		<link>http://blog.kraasecurity.com/2009/08/07/stolen-laptop/</link>
		<comments>http://blog.kraasecurity.com/2009/08/07/stolen-laptop/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 22:53:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Identity theft]]></category>
		<category><![CDATA[American International Group]]></category>
		<category><![CDATA[Consultants]]></category>
		<category><![CDATA[HSBC]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=106</guid>
		<description><![CDATA[Stolen laptop with employee information- yet again The Associated Press reported that a Williams Cos. Inc. laptop containing personal and compensation information was stopen from a workers vehicle. The laptop had over 4,400 current and former employees records. Information like names, birth dates, Social Security numbers and compensation data was on it. How many times [...]]]></description>
			<content:encoded><![CDATA[<h1>Stolen laptop with employee information- yet again</h1>
<p>The <a class="zem_slink freebase/guid/9202a8c04000641f800000000005ebe2" title="Associated Press" rel="homepage" href="http://www.ap.org/">Associated Press</a> reported that a <a class="zem_slink freebase/guid/9202a8c04000641f80000000007d954b" title="Williams Companies" rel="homepage" href="http://www.williams.com/">Williams Cos.</a> Inc. laptop containing personal and compensation information was stopen from a workers vehicle. The laptop had over 4,400 current and former employees records. Information like names, birth dates, <a class="zem_slink freebase/guid/9202a8c04000641f80000000000600c3" title="Social Security number" rel="wikipedia" href="http://en.wikipedia.org/wiki/Social_Security_number">Social Security numbers</a> and compensation <a class="zem_slink freebase/guid/9202a8c04000641f8000000000011b16" title="Data" rel="wikipedia" href="http://en.wikipedia.org/wiki/Data">data</a> was on it. How many times have wee seen this story?</p>
<p>They said the laptop was password protected. Well then lets not worry eh? A password, run for Ze Hillz! They did not say whether other security measures like <a href="http://www.kraasecurity.com/consulting-services/application-solutions/application-security-assessment">application security risk assessment</a> and <a href="http://www.kraasecurity.com/consulting-services/network-solutions">network security audit</a> tools were used in place other than the <a class="zem_slink freebase/en/pretty_good_privacy" title="Pretty Good Privacy" rel="wikipedia" href="http://en.wikipedia.org/wiki/Pretty_Good_Privacy">PGP</a> Whole Disk encryption , or of any kind of remote wiping utility was in place or even if a <a class="zem_slink freebase/en/hard_disk" title="Hard disk drive" rel="wikipedia" href="http://en.wikipedia.org/wiki/Hard_disk_drive">hard disk</a> password was used. The people with stolen data can only hope this might be the case.</p>
<p>So not we have the hoke pokey dance of checking credit, getting free one year membership to <a class="zem_slink freebase/guid/9202a8c04000641f80000000048544dc" title="Credit report monitoring" rel="wikipedia" href="http://en.wikipedia.org/wiki/Credit_report_monitoring">credit monitoring</a>, buring down the barn now that the horse was stolen, all that good stuff.</p>
<p>Here is a list fo some recent thefts</p>
<table border="0">
<tbody>
<tr>
<th style="text-align: center;">records</th>
<th style="text-align: center;">date</th>
<th style="text-align: center;">organizations</th>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2260-email-containing-names-and-social-security-numbers-of-1-084-accidentally-sent-to-co-workers">1,084</a></td>
<td style="text-align: center; width: 70px;">2009-08-06</td>
<td style="font-size: 11px;">Colorado Department of Corrections</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2251-stolen-laptop-with-names-and-social-security-numbers-could-affect-over-130-000">131,000</a></td>
<td style="text-align: center; width: 70px;">2009-08-04</td>
<td style="font-size: 11px;">United States Army National Guard</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2243-inmate-found-with-list-of-all-nhdoc-workers-including-names-and-social-security-numbers-of-1000">1,000</a></td>
<td style="text-align: center; width: 70px;">2009-08-04</td>
<td style="font-size: 11px;">New Hampshire Department of Corrections</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2224-stolen-laptop-contains-names-social-security-numbers-and-dates-of-birth-for-4-400">4,400</a></td>
<td style="text-align: center; width: 70px;">2009-07-31</td>
<td style="font-size: 11px;">Williams Companies, Inc.</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2222-stolen-laptop-may-have-contained-personal-information-of-766">766</a></td>
<td style="text-align: center; width: 70px;">2009-07-28</td>
<td style="font-size: 11px;">University of Colorado CO Springs</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2216-breach-exposes-over-500-000-credit-card-accounts">573,928</a></td>
<td style="text-align: center; width: 70px;">2009-07-25</td>
<td style="font-size: 11px;">Network Solutions</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2215-social-security-numbers-of-900-accidentally-sent-via-postal-mail">900</a></td>
<td style="text-align: center; width: 70px;">2009-07-24</td>
<td style="font-size: 11px;">Hampton Redevelopment and Housing Authority</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2209-policyholders-credit-card-details-of-1000-exposed-by-unknown-leak">1,000</a></td>
<td style="text-align: center; width: 70px;">2009-07-23</td>
<td style="font-size: 11px;">American International Group (<a class="zem_slink freebase/en/american_international_group" title="NYSE: AIG" rel="stockexchange" href="http://finance.yahoo.com/q?s=AIG">AIG</a>), American Life Insurance Co Japan</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2205-hsbc-life-lost-a-cd-containing-the-details-of-180-000-policyholders">180,000</a></td>
<td style="text-align: center; width: 70px;">2009-07-22</td>
<td style="font-size: 11px;">HSBC Holdings plc, HSBC Life</td>
</tr>
<tr>
<td style="text-align: right;"><a href="http://blog.kraasecurity.com/incidents/2206-hsbc-actuaries-lost-a-floppy-disk-containing-the-personal-information-of-1-917-pension-scheme-members">1,917</a></td>
<td style="text-align: center; width: 70px;">2009-07-22</td>
<td style="font-size: 11px;">HSBC Holdings plc, HSBC Actuaries</td>
</tr>
</tbody>
</table>
<p>The main problem with these events is that the user is uneducated when it comes to security and don&#8217;t bother to go for a  <a href="http://www.kraasecurity.com/freewebsitetest">security penetration test</a> or <a href="http://www.kraasecurity.com/">information security risk assessment</a>.  No matter what kind of technology you put in place, the user can find a way around it to compromise your security. First educate them, then worry about technology to protect them from their own stupidity.</p>
<p>Gary Bahadur</p>
<p><strong><a href="http://www.kraasecurity.com/">http://www.kraasecurity.com</a></strong></p>
<p><strong><a href="http://blog.kraasecurity.com/">http://blog.kraasecurity.com</a></strong></p>
<p><strong><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></strong></p>
<p><strong>o</strong>:888-KRAA-911,  <strong>c</strong>: 917-568-7917, <strong>f</strong>: 866-633-6601</p>
<p><strong><em>Address</em></strong><em>: 20801 Biscayne Blvd, Suite 403, Aventura, FL 33180</em></p>
<p>*Managed Security Services</p>
<p>*Vulnerability Management</p>
<p>*Compliance &amp; Policy Development</p>
<p>*PGP Security</p>
<p>*FREE Website Security Test</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://smarterware.org/3490/what-do-you-do-to-protect-your-laptops-data-on-open-networks-and-in-case-of-theft">What do you do to protect your laptop&#8217;s data on open networks and in case of theft?</a> (smarterware.org)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/a7d51bbc-cded-482e-8325-d419759ee940/"><img class="zemanta-pixie-img" style="float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=a7d51bbc-cded-482e-8325-d419759ee940" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info paragraph-reblog"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/08/07/stolen-laptop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

