Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, September 26, 2014

If You're Running OSX or Linux, Check for Shellshock but DON'T Panic

A while ago, I took the wife's old laptop that had been running Windows XP and installed Linux Mint. I thought it was a great move at the time, and I still do. One of the up sides to Linux is that you have less to worry about in the way of virus, etc. But, that doesn't mean it is invulnerable. Just like OSX is not invulnerable.

If you made a similar switch to me or you're running OSX, then you need to check to see if your system has what is being called the Shellshock vulnerability. Let me make one thing clear: there is no need to panic over this. The world isn't ending. And for most, the test is easy and the fix is simple.

PCWorld has all the information on how to check for the vulnerability.

Sure enough, my Linux box which I hadn't used in a couple of days was vulnerable. Fortunately, the patch had already been released. To install it, all I had to do in the terminal was:

sudo apt-get update

and then:

sudo apt-get upgrade

And with that, the vulnerability appears to have been resolved based upon the PCWorld test.

So, if you've got a machine that could be subject to this type of vulnerability, check it out and get it fixed. But, please, please, please, whatever you do, take the advice on the cover of the Hitchhiker's Guide to the Galaxy.

Friday, August 15, 2014

YEAH, YOU SHOULD PROBABLY USE 2-STEP VERIFICATION WITH GOOGLE

If you haven't noticed by now, I am a Google fanboy. I'm not ashamed of that; I openly admit it. Yet, in those moments when I think about it closely, it is amazingly scary the amount of information Google knows about me and the extent to which I trust Google.

It keeps track of some of my passwords via Chrome. Google's Android OS runs my phone and is synced with my Google account. My email, my documents, and who knows how much else are all with Google in one way or another it seems.

To put it mildly, if my Google account were hacked, the amount of damage that could be done is downright scary. I imagine this is the case for nearly anyone with a Gmail account or using any of Google's apps or who has an Android phone.

With that amount of exposure possible, I think it makes sense to use Google's 2-step verification. Basically, to access my Google account on a non-trusted device (think trying to access it at the public library), not only will I have to put in my Google password, but then I will get a text message on my phone with a verification code.

Unless someone has both my password and my phone, they will be unable to get into my account. Moreover, if someone does guess my Google password, I'll get the text message and know that someone's trying to get into my account.

Yeah, it might be some initial work setting up and a bit of a pain when trying to access your account in new locations, but the peace of mind that comes with the increased security is more than worth it.

You can set up 2-Step verification for your Google account here.

Wednesday, August 6, 2014

USE TASKER TO KEEP YOUR PHONE UNLOCKED WHEN IT'S SAFE

I've previously discussed how incredibly important it is that we keep our phones locked so that prying eyes can't see any of our client confidential information that may be on them. Of course, that doesn't mean that constantly having to unlock your phone isn't a pain. Especially when you're in the office or at home.

Tasker and the Secure Settings plug-in can help with this. For example, I have my phone set up so that if I am on my home WiFi network or if my Smartwatch is connected, it won't ask me for my PIN. Of course, when neither are connected, it will then require a PIN to unlock it.

As a practical matter, this means that nearly any time I want to use my phone, I don't have to unlock it, but if anyone outside my house were to try to use it, it would be locked. In this way, the security doesn't become a nuisance and lead to it not being used. The best part, at least on the Galaxy S4 and the older Galaxy Tab 10.1, you do not have to be rooted to do this.

For those unfamiliar with Tasker, it can be intimidating. It is definitely geared towards those who are willing to spend some time learning it and learning to think like a programmer at least a little. Not much more than basic logic, but I feel obliged to make that announcement.

Now, let's walk through how to do this so that when you're connected to a particular WiFi router you won't have to put in your password.

To start, purchase and install both Tasker and the free Secure Settings plug-in.

Next, open up Tasker and click on the profile tab. Then click on the "+" in the lower right. Then, choose State.

Next, choose Net and then WiFi Connected. This tells Tasker that you want to create a profile that will run whenever you connect to a particular WiFi.

On the next screen, I would recommend filling in the the SSID line with the SSID of the WiFi network you use. For example, if the name of your office WiFi is "LawFirm", you would put in LawFirm. Case counts. If you leave it blank, then this will run any time your WiFi connects, even if it is just some open WiFi network.

Next, hit the left arrow at the top. This step, for me at least, was not entirely intuitive.



Next, a little popup will ask you what task you want to do. Click on "New Task +", and you can just hit the check mark instead of giving the task a name.

On the Task Edit screen, click on the the "+" at the bottom. This time, choose Plugin and "Secure Settings".

On the Action Edit screen, click on the pencil next to Configuration. Choose "Dev Admin Actions". Then choose "Password/Pin".

On the next screen, check the Device Admin Enabled box. Then save this setting by clicking on the save or diskette button near the top.

This takes you back to the Tasker Action Edit screen. Click on the left arrow as before in the top left to get out of the action edit screen. Do it again to get back to the profile screen. Now, when your phone connects to the WiFi network you listed, it will no longer require you to put in the password (Note, you might have to turn your WiFi on and then off to get it to take effect, and there is sometimes a small lag time).

Of course, you will want the password to come back when you leave the WiFi network. To do this, on the WiFi Connected profile you created, tap and hold on the Secure Settings Clear Password after the green arrow. This will bring up a popup where you can choose to "Add Exit Task".

Again, choose to add a new task, click the check mark, and add a new task. As before, you will be adding a plugin and secure settings. Click on the pencil next to Configuration, then Dev Admin Actions, and Password/Pin.

This time, click on the "Disabled" button. Choose either the Password or Pin Code radio button and put in the password or pin you want to use. Save, and back out to the profile. On your profile you should have both a green arrow pointing right and a red arrow pointing left for your WiFi Connected profile.

Now, whenever you connect to your WiFi network, your phone will stop asking for a password, and when you disconnect, it will start asking for a password again.

Friday, September 13, 2013

ONLINE OR OFFLINE PASSWORD MANAGEMENT?

I recently came across this article on Tech Republic regarding online password managers. The long and short: the jury is still out on just how safe it is to store your passwords in the "cloud". For what it's worth, I disfavor this approach and store my passwords on my phone in an encrypted file. To get at all of my passwords, someone would have to have access to my phone. In this way, I control the access point. With the online password managers, you are letting someone else control the entry point.

For this reason, I prefer Password Keeper, which stores the files locally with the option of cloud synchronization through Google Drive. I know I had previously said that I was ok giving up a good deal of my privacy to Google, but there are some things I'm not ready to hand over so easily to a third party. The password to my bank accounts is one of them.

Thursday, August 22, 2013

KEEPING TRACK OF THOSE PASSWORDS

How many usernames and passwords do you have? Email, PACER, electronic filing, bank accounts, and the list keeps going. For example, I have more than 50 different website's username/password combinations stored on my phone, and there are surely sites that I never bothered keeping track of. Recently, I was asked how I keep all of them organized.

One way to do it would be to just use the same username and password for everything I do and never change it. Of course, that would be about the least secure thing to do. If someone got your password for your email account, they would then also have access to your bank accounts and who knows what else.

Instead, I try to have a different username and password for everything. To keep track of them all, I use a free, open source program called Password Safe.



One of the great things about Password Safe is that it stores all of your files locally in an encrypted file. To open the file, you only have to remember one master password. It will automatically generate new passwords for you, alert you if your passwords are too weak, and even remind you to change your passwords on a regular schedule if you like. It even remembers prior passwords so that you don't accidentally reuse one.

They also have Android and iPhone versions so that you will always have your passwords with you wherever you go. You also have the option of storing your encrypted password file in the cloud for Android with another app.

So, if you're still using the same password you have been using for the past 15 years, update your passwords and use Password Safe to keep it all organized.

Thursday, August 15, 2013

IS YOUR PHONE LOCKED?

If you had all of your passwords, credit card numbers, account numbers, addresses, phone numbers, your social security number, and your client's confidential information stored on paper, you'd make sure it was in a locked box, right? After all, if someone took the box, you wouldn't want them to be able to just open it right up and take all of your stuff?

So why isn't your phone locked? It probably has all of the above information on it. If you would lock that information up if it was in paper form, why not when it is in digital form on your phone.

Android phones make locking your phone easy and even give you several lock options. To access them, open up your phones setting's and find the screen lock menu. From there, you will have the option of enabling several different locks, including a dot pattern (my lock of choice), a pin number, and a password. And on at least the Galaxy S4, there is the option of using the camera to allow your face to serve as the unlocking method.

WHAT IF YOUR SMARTPHONE WAS LOST OR STOLEN?

For many lawyers, our smartphones and tablets are essential tools in the practice of law. It's replaced the paper calendars that used to be lugged around. It's where we send and receive email about cases and clients. We do legal research on it using apps like Westlaw and FastCase. Not to mention, it has a lot of our personal information stored in it.

So, what are you going to do if it gets lost or stolen? How are you going to protect both your client's confidences and your own personal information?

If you're using an Android operating system, the answer is easy: the Android Device Manager. To enable it, open up the Google Settings on your phone, choose "Android Device Manager", and check the "remotely locate this device" and "allow remote factory reset".

Then, from any computer, you can go to https://www.google.com/android/devicemanager and log in with your Google account. You'll be able to see in Google maps where your phone is. You can make your phone ring at full volume - useful when you've lost it under your couch cushions and can't find it. And, perhaps most importantly, you can essentially tell your phone to forget everything it knows about you and your client by clicking the erase device button.

So protect yourself and your clients. Turn on the device manager settings and hope you only have to use it when your two year old has hidden it in his pile of stuffed animals.