Archive for the ‘Security Issues’ Category

Configuring Windows XP Auto-Login

Saturday, July 29th, 2006

For shared laptops that users borrow mostly for remote access, I usually configure no password for the Administrator login and even set Windows to automatically log in to that user account. Of course, I usually have an image of the base configuration, which makes it easy to restore to our company default settings and apps if users manage to fry the system.

So how do you get Windows XP to automatically log in? Click Start / Run and type the following:
control userpasswords2

In the Users tab of the pop up box, uncheck “Users must enter a user name and password to use this computer.” Then click the Advanced tab and also uncheck “Require users to press Ctrl+Alt+Delete.” Then click the Apply button. You’ll be prompted to select the user and password that you want to use as your default login (for example, Administrator, leaving password fields blank if you haven’t assigned a password for that account). Then click OK to close the box.

That’s it. If you restart the computer, you’ll see it logs in to the default account you’ve set up for your users. That avoids your having to hand out and manage login information for your shared computers.

CAUTION: There is nothing secure about this setup. This is supposed to make it easy for anyone to use this computer, so it assumes that nothing of consequence is stored on its harddrive. Obviously, you should ensure that users avoid saving confidential information on a laptop that has been configured for auto-login. But even a laptop set up with a Windows login and password is vulnerable. Hacks are widely available that allow clearing or resetting Administrator passwords. So make sure you have a no-local-saving policy (best option) or at least encryption software when deploying laptops with minimal or no password protection.

Identity Theft: Stolen Laptop Response

Thursday, June 8th, 2006

Encrypt, secure, prohibit or pay the price!

That’s what Congress and State legislators should tell Ernst & Young, Veterans Affairs and other companies and agencies that play fast and loose with our personal data.

In the last several days, major news networks and countless online news sources reported two more incidents of lost or stolen laptops containing personal data of millions of individuals. The first theft involved a laptop stolen from a Veterans Affairs employee. Follow-up reports on that theft go from bad to worse, indicating 2.2 million active-duty personnel are now at risk for identity theft. The lost data in this case includes Social Security numbers.

The second incident involved a laptop stolen from an Ernst & Young employee. That laptop contained the personal data, including credit card information, of approximately 243,000 customers of Hotels.Com who had booked rooms between 2002 and 2004. In a way, this second incident is more egregious because losing laptops is reportedly commonplace for Ernst & Young.

According to The Register, a British technology news site, password protection was the only security available on some of the laptops lost by Ernst & Young during a prior incident, which any avid computer user knows can be easily compromised. What about the laptops more recently lost by Ernst & Young employees? Was the data contained in those laptops encrypted? Are there any company policies limiting the extent of personal data that may leave the office where presumably network security standards and firewall protection are in place? Are there any company rules prohibiting employees from leaving laptops unattended (though you would think common sense would be enough)? Or better still, are there rules prohibiting the transfer of personal data to employee laptops? I expect there aren’t. If any such measures were in place, Ernst & Young’s public relations people would have plastered that all over the media to reassure clients and the public in an attempt to save the firm’s corporate derriere.

Ernst & Young and the VA are not the only entities that have lost laptops with personal data, and most of these entities have developed a typical response straight from the Corporate Playbook. Ernst & Young has agreed to offer Hotel.Com customers a year’s free credit monitoring. That’s no compensation for someone who will have to spend potentially years clearing up a resulting bad credit history. Anyone who’s been in the tenuous position of having to prove they do not owe a debt they do not owe will tell you that.

If Ernst & Young created a task force to help consumers clear identity theft issues, then maybe that could be considered compensatory. If they offered to pay legal fees for anyone having to clear resulting bad credit histories, or pay state fines for prosecution of identity thieves, that might be considered compensatory. If they committed to and implemented a program to encrypt and secure the data and, in particular, prohibited downloading of personal data to portable computers in the first place, that would be considered the best move of all.

Employees of the auditing companies don’t seem to care what happens to your personal data. The Register reported that, in one case, employees left laptops in an unattended conference room while they went off to lunch. You can just see how that might happen. They’re in Miami at yet another conference. The conference is at a downtown hotel they’ve been to a couple times. They’re familiar with the hotel and the area so already they feel some sense of false security. Someone’s been talking for hours about converting more sales, pushing certain investments, or their company’s new data recovery center that will help clients feel more “secure.” Anyway, the speaker stops to take a breath and everyone realizes it’s a good time to break for lunch. They’re coming back to the room so, hey, why lug around those heavy laptops? Aren’t they coming back to the room for the second half of the conference? Do they even ask if the conference room will be locked during lunch? Of course not. They’re company laptops. What’s a few lost laptops to a big corporation like Ernst & Young. Right?

Maybe these irresponsible employees need a little incentive to show better judgment. Suspending reality for just a moment, wouldn’t it be interesting if, any time one of these employees acted that irresponsibly, his or her Social Security number were posted on StupidIrresponsibleJerks.Com? That way they could sweat it out with the rest of us who have personal data floating out there and possibly in the wrong hands. While we’re at it, lets also expose the personal data of corporate policymakers at these auditing companies who are too shortsighted to better secure your data and the company’s reputation. Let them sweat it out, too.

At a minimum, how about if these employees immediately lost their jobs, were required to be individually named in negligence lawsuits filed by victims of identity theft, or at a minimum SIMPLY HAD TO PAY FOR THE LOST LAPTOPS? I bet we’d see a decrease in stolen laptops then. Seriously people, some of these employees were so careless you can almost imagine them extending their arms and presenting the laptop to Joe Thief. “Here, take it. I’d give you my Windows password, too, but you won’t need it. I didn’t bother to log off before going to lunch – check out my Paris Hilton screen saver.”

Most of these companies who have lost laptops with sensitive data try to pacify the public by saying the thieves are just after the hardware. Sure. That’s like telling a home burglary victim the burglar just wants your jewelry box. He’s not really interested in the $50,000 tear-drop diamond earrings you had inside. Bull. When a thief steals, every part of the stolen item has value. Everything. And even if the thief was simply opportunistic and is otherwise computer illiterate, the person buying or fencing the laptop may not be computer illiterate.

Ernst & Young’s web site praises the company’s network security measures in their section titled Security and Technology Solutions. These measures may well be admirable. However, too often individuals, companies, and the public in general are so focused on stuff going over the Internet that they forget about stuff sitting in hard drives. A truly secure network focuses on data stream (information being transferred) and on data storage (information waiting to be used).

In my dreams, my personal data is properly stored in a secure location, in a building with armed guards, vicious dogs, and an unfriendly receptionist. Well, I can hope. I can also hope that some of that data might also be encrypted. I realize my personal data with one institution may be stored in more than one location; for example, Building A (their main offices) and Building B (a branch office or, better still, a data recovery center). But, not in my wildest imagining would I expect that any business storing my personal data would allow it to be downloaded and stored on a laptop that an employee can take home where he does his online shopping. I know I also don’t expect that the laptop with my personal data is being left unattended in a hotel conference room, a bar counter or someone’s car. I don’t care how many financial or online banking agreements I sign. I’m never consenting to anyone downloading my personal information to a laptop. No one consents to the mishandling of their personal data.

I have yet to read any banking or credit agreement that expressly states the information will be downloaded to a laptop or in any way made available to anyone outside the secured network of the financial institution. There is a vague all-encompassing comment about information sharing, but the appearance given by these institutions is that the information will be handled and “shared” in a secure method over an encrypted Internet connection. Everything they say about their security has to do with their firewall and encrypted data streams. To me that means that anyone working from home and needing access to my personal data is doing that over a “Virtual Private Network” (VPN) or is at least using one of the many encrypted remote access programs that are out there: for example, Windows Remote Desktop or GoToMyPC or some other Citrix product. These programs are by no means impenetrable, but they are available and somewhat secure given that the data streams between host server and remote client computer are encrypted (coded).

That’s just not the case with data downloaded to laptops without encryption or adequate password protection (though passwords are simply not enough). Over the years, I have used a number of remote access programs to log into my office and work on client files. I’ve even used a laptop to work downstairs on files stored on my main computer in an upstairs bedroom. The remote desktop creates a window that shows me the programs and data files on the main workstation or network server that is hosting my connection and contains what I need to see. I am NEVER required to download any data to the laptop to work remotely on it. That’s the whole point of the remote access software.

By compelling employees to log in, do the work and immediately exit the remote access program, Ernst & Young, the VA and any other entity that stores personal data minimizes the window of opportunity for your personal data to fall into the wrong hands. Since the laptop only “sees” the data as long as the remote connection is open (and presumably sees it over an encrypted data stream), there’s nothing sensitive actually stored on the laptop’s harddrive.

During remote access sessions, the company retains control of your information and there is oversight of the employee’s use of your information. Best of all, if your personal data is not needed during that particular remote access session, it never even becomes part of the encrypted data stream traveling over the Internet. Furthermore, employees can be trained to log off their sessions before leaving their laptops unattended, but assuming they stay stupid and don’t comply with corporate security policies, network administrators can easily set their servers shutdown all remote connections that have been idle for a certain amount of time (say, 10 minutes).

These protocols would expose even fewer people from the threat of identity theft. Think about it. Can any Ernst & Young employee work on the data of 243,000 Hotel.Com customers during one remote access session? Can one VA employee work on the accounts of 2.2 million active-duty personnel during one online remote access session? And yet, both these individuals collectively had the personal data of nearly 2.5 million people stored on their laptops and immediately available to anyone who gained possession of their laptops. Why?

There ought to be a law, right? Oh, absolutely. Congress should immediately implement its own measures, including possibly levying fines against any entity that acts irresponsibly with your personal data, and should impose broader guidelines regarding access to your personal data. In 1996 Congress enacted the Health Insurance Portability and Accountability Act (HIPAA) regulating the use of and access to personal health information and related identifying personal data, like medical record numbers and Social Security numbers contained in patient medical records. Though HIPAA caused a lot of headaches in the medical and legal communities, it validated concerns over privacy. HIPAA was still a step in the right direction even if, like most legislation, it needs to evolve to better reflect the legislative intent. Similar, legislation needs to be considered with respect to the personal data maintained by businesses and financial institutions. A person shouldn’t have to get sick to protect his or her personal data, though the apparent lack of security is sure to make you sick.

Although HIPAA addressed privacy concerns, the issue of protecting personal data isn’t a question of privacy; it’s a question of security. Protecting personal data could easily fall within the purview of Homeland Security. Personal data needs to remain secure because the casual criminal is not the only one making use of it. Whether it’s to raise fear or awareness, consistently our government tells us about the manner in which terrorists make use of other people’s personal data to create phony IDs, buy cell phones, or book plane tickets. It’s not a leap of logic to suggest that protecting personal data thwarts terrorist activity. A bold politician might even say failure to do so is a breach of national security. But that’s going a bit too far, don’t you think? Certainly, though, it’s conceivable that personal data has the potential of falling into the hands of someone desiring more than just an overpriced pair of shoes, hair extensions or HDTV.

Other measures offer consumers far more protection than we’ve been seeing. There are currently legislative initiatives in certain states that would allow their residents to place a security freeze on their credit files prohibiting any new credit or loan application to go through without the consumer’s authorized PIN number. The freeze would allow consumers to lock their credit and temporarily unlock it when they know they will be applying for a loan or need to make some other type of major purchase.

Ernst & Young is not a small operation. It is a successful business with, I imagine, an exceptional track record and the ability to provide solid services or it would not be retained by so many reputable businesses. However, the best company can show poor judgment and in this case it has. To be fair, I surmise that, like all companies, Ernst & Young has careless employees and most certainly careful ones. The company as a whole may be undeserving of the resulting bad reputation it’s getting. On the other hand, it has not shown it’s done enough to curb the loss of personal data. Frankly, even the most careful employee can be overwhelmed during a crime, or overly fatigued, and become dispossessed of his or her laptop. There is little compelling reason for those laptops to contain personal data in the first place. Every entity that handles personal data needs to implement a zero-download policy and issue essentially dumb terminals to their employees (laptops just for remote access).

Too many times, these institutions forgo implementing some security measures because, they argue, no measure is 100% foolproof. They claim it would not be cost-effective for them to implement measures that can be breached. Well, every one of them has already implemented security measures which are not impenetrable. Most of these places already use encrypted Internet security connections for their data streams because failure to do so in this day and age is unthinkable, right? I’ve even heard that some of these places lock their doors at night so someone can’t walk in and steal the CEO’s favorite coffee cup. Obviously, building security systems can still be breached; it doesn’t mean we therefore throw up our hands and stop locking the doors. So why adopt the same all-or-nothing philosophy when it comes to securing data?

Frankly, adopting a company policy prohibiting the download of personal data to laptops is about as expensive as sending around a memo about the upcoming company picnic. There is no need to download the data. Workers can still remote access the encrypted data using adequate alphanumeric passwords through a secure Internet connection behind firewalls on both sides, on the host computer and remote computer. No, it’s not 100% foolproof. That’s true. But when you’ve got employees with a track record for losing laptops, it’s time to try something new.

Firefox: Recommended Browser

Thursday, April 20th, 2006

Earlier this month, I stopped using Microsoft’s Internet Explorer and switched to Mozilla’s Firefox (browser) and Thunderbird (email program). I really like them. They both offer a great deal more security than Microsoft’s alternatives. They’re both open source programs, which means developers around the world add improvements, detect and patch vulnerabilities. Nice.

I had been thinking about switching browsers for some time. Firefox was the frontrunner. A lot of tech sites and forums talked about how much more secure Firefox is over IE. I was sitting on my hands about switching browsers, then something happened. I ran another Windows update in January, 2006, which fubarred my computer completely. Their new security patches were so thorough I couldn’t establish any Internet link. I guess that’s Microsoft’s best solution to Internet security - cut off all access. No thanks. I get claustrophobic when I’m cut off from the net.

Okay well, in Microsoft’s defense, I’ll say no one can fully guarantee everything on my computer (the huge diversity of programs and .dlls they load) will all work perfectly together. But, the update and subsequent problem really frustrated me. It was so screwed up that not even loading up a 2-month old backup drive image could fix the problem. (I still haven’t figured that one out since re-imaging would have wiped everything clean.) Ultimately, I decided to load Windows and all my programs fresh. On the plus side, that reconditioned my computer which is always a good thing. I was able to leave out programs I had tried but didn’t like or was no longer using, which takes those unique .dlls and setups out of the mix.

I know I was probably scapegoating Microsoft’s browser, but it was time to try something else. Internet security was my main reason for deciding to go with another browser. Firefox has consistently gotten good write-ups. Google it and you’ll see what I mean. I like the tabbed views Firefox offers (rather than having it open a bunch of separate windows that fill my task bar). Plug-ins and add-ons are easier to load and manage, and Firefox is skinnable (is that a word?). When you’re on the computer 24/7 it’s nice to be able to change the look of a program and freshen up your desktop from time to time. I also like that Firefox has “Live Bookmarks” which allow you to more easily incorporate RSS feeds and be notified of updates to your favorite sites.

I know there’s little chance of finding a browser that’s completely secure. Firefox does have security patches that need to be loaded from time to time. I can’t imagine there’s any browser out there that won’t require updates from time to time and frankly I’d worry about using a program that doesn’t get updates.

At any rate, there are more options available than Microsoft’s Internet Explorer. W3Schools (a terrific web developer site) has quick summaries and links about available browsers. I’m on a PC using Windows XP and don’t think I’ll ever experience “Safari” unless I buy a Mac (which I’m considering). Right now we have nothing but PC’s in the house (3 workstations, a laptop and a tablet). We should probably give Apple a turn. Regardless, for PC’s and Windows users, there are plenty of options in how you browse the net. I like having a choice. You get a better product that way, I think.