Editor : Martin Simamora, S.IP |Martin Simamora Press

Selasa, 21 Desember 2010

Electronics Engineers Help Sustain ICT Development

MANILA, Philippines - The past few years have seen some of the most tremendous growth in the information and communications sector in the Philippines, benefiting many other industries and communities.
Investments in ICT, coupled by a widening demand for faster and more efficient services, have opened the doors for new business opportunities, which also contributed to a sustained growth in the country’s economy.


Since the passage into law of Republic Act 8792, otherwise known as the E-Commerce Act of 2000, ICT has become a socio-economic enabler and not just an end-goal.

All aspects of the society, from business to politics, education to the sciences, have relied on the use of ICT to increase productivity, innovate existing technologies, and make new discoveries that have otherwise taken years to do.

Investments in ICT infrastructure among small to medium scale businesses (SMBs) have been growing especially with more entrepreneurs tapping into cyberspace as a platform to sell their products and services.

Many SMBs have expanded their operations by investing in hardware, software, and telecommunication services to centralize and monitor their operations.

Other than the SMBs, large corporations have capitalized on ICT infrastructure not only for competitive advantage but also to streamline their operations, which would have otherwise been a daunting and expensive task.

The unique demands of SMBs up to the large corporations have also given rise to a new breed of service providers that develop specific, modular services, which can be modified to suit the demands of their growing clients.

Even telecom companies have played a role in expanding the use of ICT as they implement next-generation networks, which also have given rise to a variety of unique service propositions, such as cloud computing and hosted services.

Even the “sunshine” industry of business process outsourcing (BPO) also credits its success to strong investments in ICT. This has resulted in the establishment of dozens of BPO providers, providing about 500,000 jobs and contributing at least $10 billion in revenues to the Philippines.

All this growth in the ICT sector also demands expertise and it is also a major challenge to all industries dependent on ICT to find the right professionals to maintain ICT equipment, services, and infrastructure.

This demand is ever growing and the electronics and communications engineering (ECE) sector is taking the challenge of filling up the need for professionals in the ICT sector.

It is the advocacy of the Institute of Electronics and Communications Engineers of the Philippines (IECEP) to provide the ICT sector with skilled engineers.

The organization is built upon a vision of sustainable expansion in all sectors of development. With ICT as one of the fastest growing sectors, it has mandated itself to create a new breed of professionals who are able to fill the specific necessities of ICT.

The passage of Republic Act 9292 or the Electronics Engineering Law in 2004 saw a positive aspect in terms of government support for electronics engineers and professionals.

It also paved the way for opening new channels of opportunities where skills development is intertwined with the various aspects of growth in many industries.

ICT is no exception and it is a positive challenge for the IECEP to produce the best people for the right jobs in this sector.

This year’s IECEP conference dubbed the International Electronics Conference and Expo focused on the ICT sector and its effects on other industries.

The event, held last Dec. 7-9 at the SMX Convention Center, viewed how else the country’s engineers can support traditional industries that are ever depending on ICT. The theme, “Sustainable Professional Excellence for ICT Development,” marks the IECEP’s commitment to be part of a sector that has already been an integral part of all other industries.

(PhilStar.com)

Senin, 20 Desember 2010

BlackBerry 6: Wipe Your Smartphone, Restore Factory Settings

Many reasons exist for why you might want or need to "security wipe" a BlackBerry, or completely erase all personal data stored on your handheld: You got a new smartphone and plan to retire the older device; you're trading in your existing BlackBerry for a new one from your wireless carrier; you and a friend are swapping devices; you loaded too many applications or media and just want to start over from scratch; etc.



Whatever your reason, BlackBerry-maker Research In Motion (RIM) makes it very easy to security wipe a BlackBerry using its latest mobile OS software, BlackBerry 6. Waaaaay back in the fall of 2008, I wrote a post on how to clean or wipe your BlackBerry smartphone running RIM's OS 5, so those of you with a BlackBerry 5 smartphone will want to jump over to that older tutorial.

The security-wipe process is very similar in both BlackBerry OS 5 and BlackBerry 6--in fact it's even more intuitive in the newer OS. And the following four steps will wipe your BlackBerry smartphone clean and restore the handheld to factory settings in no time. Keep moving for specifics. (Note: If you BlackBerry is connected to a corporate BlackBerry Enterprise Server BES, you may be unable to completely restore your device to factory settings, though you should still be able to wipe it clean, depending on the specific IT policies associated with your device. Check in with your BlackBerry administrator if you encounter issues.)

How to Security Wipe Your BlackBerry 6 Smartphone

1)Begin the BlackBerry security wipe process by opening up the main BlackBerry Options menu--the icon looks like a wrench when using the default BlackBerry theme. (Learn more about BlackBerry themes here.)
2) Next, scroll down to and select the Security option on the following screen, then choose the Security Wipe listing on the next page.
3) The Security Wipe screen displays a number of options and associated checkboxes that let you specific whether you want to delete E-Mail, Contacts, etc., User Installed Applications and/or all the data stored on your Media Card.
4) Finally, to initiate the process, type in the word "BlackBerry" in the confirmation field on the Security Wipe screen, accept any final confirmation pop-ups you may see, and voila, your BlackBerry device is on its way to its factory state. It may take up to an hour to completely wipe your device, depending on how many messages and other data you have stored on-device, so be patient.
When the deletion process is complete, your BlackBerry will restart and another dialogue box appears to ask if you'd like to run the device Set Up Wizard. At that point, your BlackBerry is wiped clean of all data--unless you chose to let third-party app information remain--and factory settings should be restored.
Got a broken BlackBerry keyboard that's keeping you from wiping your handheld using the process above? No worries, you can use any of a number of workarounds, including the free JL_Cmder application.
Check out a full list of all my BlackBerry tips and tricks stories on the CIO.com BlackBerry Bible page.
=========
Al Sacco covers Mobile and Wireless for CIO.com. Follow Al on Twitter @ASacco. Follow everything from CIO.com on Twitter @CIOonline. Email Al at ASacco@CIO.com.

(NetworkWorld.com)


Internet Hit by Wave of Fake PC 'defrag' Tools

Fake AV has morphed into expensive 'disk fix'

A spate of scareware apps that trick users into buying useless hard disk repair tools appears to be part of a concerted campaign to push fake 'defrag' software, a security company has said.

The Internet abounds with Windows utilities, usually free, some not very good. Users have an unquenchable appetite for them.


According to a GFI-Sunbelt Security blog, a new type of bogus disk software has suddenly become very common on the back of this, with a clutch of convincing examples appearing in recent weeks.
Users encountering new examples HDDRepair, HDDRescue and HDDPlus should ignore them. They are bogus applications that claim to defragment a user's hard disk even though such a requirement is barely needed given that Windows does a lot of this work behind the scenes anyway.

The apps will, however, claim that a user's hard disk is riddled with problems, as will the slightly older examples UltraDefragger, ScanDisk, Defrag Express and WinHDD. Sorting out the non-existent issue can cost anything from $20 and up.

Such apps have been around for some time in fact but have simply been less documented compared to the fake antivirus programs that have caused chaos on the Internet in the last two years.

The phenomenon of fake software is now deeply entrenched on the Internet and criminals have even taken to aping the way security companies are creating all-purpose security programs. Fake apps adopting this verisimilitude tactic include PCoptomizer, PCprotection Center and Privacy Corrector.
A quick trawl of Google reveals that all of the above scareware examples are easy to encounter. So how does a user tell the real and useful from the fake and expensive?
Depending on the type of app, it is sometimes easier to consult lists of real apps that worry about working out which ones aren't genuine. 

As the author points out, the overworked Virus Total is one site that allows files and URLs to be checked against known rogue lists, while certification company ICSA Labs publishes a separate, more high-level list of known vendors. These are not perfect warning systems however. Rogue URLs change constantly and might not be spotted by Virus Total, for instance.

(NetworkWorld.com)



Sabtu, 18 Desember 2010

CIO Gets Six Years for Embezzlement Scheme

Former Auto Warehousing Company CIO gained fame for switching to Apple after Microsoft dispute

The former CIO at a large U.S. automobile processing company has been sentenced to nearly six years in prison for embezzling more than $500,000 from the company by faking expense reports and reselling company equipment.


Dale Frantz, 46, was sentenced Friday in U.S. District Court for the Western District of Washington, after pleading guilty to fraud charges. Auto Warehousing Company (AWC) hired him in 1998, even though he had served a prison stint in the 1990s for a similar crime. Frantz made headlines three years ago for switching the company to the Mac after a software licensing dispute with Microsoft. 

Between 2007 and 2009, Frantz used a number of techniques to steal money from AWC, a Tacoma, Washington, company that delivers cars from ports and manufacturing plants to dealerships. He wrote up fake invoices for expense reports and altered legitimate ones to boost his reimbursements, and used company funds to buy computer equipment that he later resold on the Internet. He had a co-conspirator set up a company called Asyncritus Technology to generate invoices for nonexistent services, taking a split of the profits, the U.S. Department of Justice said.

In 2007, Franz tried to switch AWC to the Mac OS platform, after becoming involved in a public dispute with Microsoft, after the software vendor pressured him to audit his company's software licenses. That project was delayed after employees and partners pushed back, but the company now has more than 100 Macintosh computers helping to run operations, according to Apple's Web site.
In a Dec. 9 letter to the judge in the case, Franz said he led a tortured double life as both successful executive and embezzler, a life that came to an end when he was fired from his job. "I was relieved to be terminated," he wrote. 

In addition to the 71-month sentence, Frantz must pay $516,358 in restitution to AWC.
In 1996, Franz got a four-year sentence for stealing $200,000 while office manager at an Indiana audio shop.
======================
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

(NetworkWorld.com)

Microsoft ends record security year with huge Patch

Microsoft's security team broke all sorts of records for issuing patches this year, and 2010's final Patch Tuesday was the biggest one of all.
"Microsoft is ending this year on a high note, with their highest number of bulletins ever," nCircle director of security operations Andrew Storms notes. "With a record 17 bulletins ... we are getting a huge number of individual bug fixes."


With today's update, Microsoft has issued 106 security bulletins patching a total of 266 vulnerabilities in 2010, both of which are also records for the company. Whether this is due to Microsoft products becoming more vulnerable, or greater attention being paid to vulnerabilities (or a combination of both) is an open question. Microsoft has said its policy of supporting products for up to ten years means a lot of older pieces of software have to continue receiving patches.

In this year's final Patch Tuesday, Microsoft fixed a critical Internet Explorer problem as well as the final known bug exploited by the Stuxnet worm.
"The most important bug this month is clearly the IE update that includes a fix for the outstanding zero-day bug discovered in early November," Storms says. "With more and more people shopping online this time of year, it's important for everyone to patch their browsers."

Storms was referring to MS10-090, which resolves four vulnerabilities that could allow remote code executive when users view malicious pages with IE6, IE7 and IE8. "The security update addresses the vulnerabilities by modifying the way that Internet Explorer handles objects in memory and script during certain processes," Microsoft said.

This was one of only two bulletins that were rated "critical" by Microsoft. The other was MS10-091, which patches bugs in the Windows Open Type Font driver. "An attacker could host a specially crafted OpenType font on a network share. The affected control path is then triggered when the user navigates to the share in Windows Explorer, allowing the specially crafted font to take complete control over an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights," Microsoft said.

Separately, Microsoft has fixed the fourth and final known vulnerability related to the Stuxnet worm with MS10-092, which affects Windows Vista, Windows Server 2008, Windows 7 and Windows Server 2008 R2.
MS10-092 was rated important, rather than critical, as were most of the rest of the 17 patches. However, Qualys vulnerabilities lab manager Amol Sarwate says one of the "important" bulletins should have been rated critical by Microsoft.

This particular bulletin, MS10-105, describes a vulnerability targeting numerous versions of Microsoft Office, in which a graphics filter flaw can allow remote code execution.
"I personally think it's critical because you could get an Excel spreadsheet, or any Office document with one of these graphics filters, and it could allow an attacker to execute code on a computer," Sarwate says.
While the vulnerability affects Office 2007 and 2010, it only allows remote code execution on older versions.
Speaking of Office, Microsoft said Office File Validation will be made available for the 2003 and 2007 versions of the software starting in Q1 2011. The software is already available on Office 2010, and opens files in a safe mode when security threats are detected.

But that won't help IT managers who apply today's patches immediately.
As PC World notes, "The security bulletins cover the range of Microsoft software including all versions of Windows, as well as Internet Explorer, Microsoft Office, SharePoint, and Exchange. All 17 of the security bulletins are listed as either 'Requires restart' or 'May require restart', so IT admins should be prepared for the fact that systems will need to be rebooted to complete the patch process."

(NetworkWorld.com)

Jumat, 17 Desember 2010

How to Prevent a WikiLeaks-Like Breach

Technologies and processes exist to prevent a WikiLeaks-style breach, but most IT security experts haven't instituted the proper safeguards, says a leading computer expert on insider threats.
"With the right people, process and technology, you could be able to put a system together that would greatly reduce the impact these types of attacks have," Eric Cole, a SANS Institute faculty fellow and founder of the network security consultancy Secure Anchor Consulting, says in an interview with Information Security Media Group (transcript below).

Cole says one of the biggest failures deals with how organizations control and manage access to data. Individuals should have access to data for a limited time. "If you look at just about everything else we do, your driver's license has an expiration date; your passport has an expiration date; so when you are given access to sensitive data, it is typically infinite and there no expiration," he says. By placing time constraints on entree to sensitive data, Cole says, the burden shifts to the user from the data owner on justifying access. 

Search and indexing technologies also can help limit access to data and reduce the danger of improver exposure. Each document would be indexed by page, paragraph or sentence. Users could conduct a search without getting details or access to the document. "You can get the details you need on a specific area, but the bigger risk of getting more access than what is required to do your job is reduced," Cole says. "At the end of the day ... we see insider threat and information leakage (when) the person needed some of the information in the document but not the entire document, but because most organizations don't know to hand it off in a more granular fashion, it is an all or nothing, and then they end up getting this repository with a lot more information than really is required." 

Another approach to safeguard data that doesn't require new technology is to limit access to sensitive information from a thin client or virtual machine; that means no local storage on users' own devices. Users Cole says, "could have a profile and they could have a directory on the server where they can save their searches, but everything is stored and controlled at the server level and nothing is put at the client level, and then all of the sudden, once again, you are taking away yet another avenue of exploitation from that user."
In the interview, conducted by Information Security Media Group's Eric Chabrow, Cole also:
  • Assesses how the WikiLeaks breach occurred,
  • Laments that most organizations won't learn the lesson from the WikiLeaks episode and
  • Poses three critical questions organizations should answer to assess their vulnerabilities.
Cole is an industry-recognized security expert and has authored several books, including Hackers Beware, Hiding in Plain Site, Network Security Bible and Insider Threat. (with Sandra Ring). He is an inventor who holds more than 20 patents. Cole serves on the Commission on Cybersecurity for the 44th President and is actively involved with the SANS Technology Institute and SANS working with students, teaching and maintaining and developing courseware.

What Went Wrong?

ERIC CHABROW: From an IT security perspective, what went wrong? How preventable was the WikiLeaks breach?

ERIC COLE: That's a very interesting question because typically when we look at security we always look at access control and the idea of the insider threat is people can access information that they need to perform their jobs, but they are using it for other purposes in which it wasn't intended.
And in this particular case, it is interesting because first, I can't imagine, based on the amount of information that was leaked out that one person would need access to all of that data in order to perform their job function. I would immediately think that there was clearly a problem in terms of controlling, managing and limiting access within the enterprise.
While that could never be prevented, that could have been reduced greatly by better controlling and managing who can store what and in which media. But the other important thing gets down to the data loss prevention controls and the classification.

Based on the fact that this information was supposed to be classified, you would think that if they had some monitoring in place they would have once again either been able to be detected or prevented very quickly and the amount of damage would be reduced. Based on the shear size of the leakage, it makes me think that there is minimal detection and minimal outbound controls in place that could have either reduced or greatly prevented the damage.
CHABROW: I wonder in such a large bureaucracy or organization as the federal government is, the responsibility of limiting people access to specific information - I mean this is a situation that if the allegations are to be believed that you had someone in the Army getting access to State Department documents. What kind of challenge does that present in a sense of who governs who gets access?

COLE: That brings up the whole issue of data portability. You always hear different organizations that are being accused of not sharing information with other government entities or other offices that it presents an interesting problem because if you had data at one organizational unit, they could have the best access controls, they could have the best audited, they could have the best manageability of that information, but if they allow one authorized person to be able to copy that information, they can copy it and put it on a different government entity's server and now, in essence, be the owner of that data and be able to create their own access lists, create their own permissions and do whatever they want.

This creates a huge problem because now how do you go in and limit distribution without going in and prohibiting the function. This is where a lot of this new technology is coming into play, which is when you go and view and read information without being able to actually download, save a local copy or do anything with the data, and it brings up an interesting concept because if you could do that, a lot of these problems and a lot of the complexities would go away.

CHABROW: So the technology exists to do that? 

COLE: Some of it exists in commercial products and some of it is how you would set up the data, but the answer is yes, with the right people, process and technology you could be able to put a system together that would greatly reduce the impact these types of attacks have.

The Biggest Failure

CHABROW: When you have information like this, should there be a single owner?

COLE: Well ultimately, with any piece of information, you should clearly define who is responsible for the protection of that data. You should then clearly have guidelines and policies of what is required in order for somebody to get access to the information and how long should they have access to that data.
In my opinion, probably one of the biggest failures in how we control and manage access is the fact that a lot of access has no expiration. If you look at just about everything else we do, your driver's license has an expiration date; your passport has an expiration date; so when you are given access to sensitive data, it is typically infinite and there no expiration.
What if we went in and every time you were given access to the data you were only given that access for 10 day or 15 days; there was an expiration on it and then if you still needed the information, you would then request a new approval for it and have to be able to be reauthorized to get access. Now what you are doing is you are shifting the burden on the user, which is where it should be, as opposed to this data owner that is too busy and too over-tasked to really track and recognize other people really do or don't need it over a long period of time.

CHABROW: A lot of the systems developed over the past two years in government and as a result of the idea that different agencies need to share information after the 9/11 attacks; before then everything was in silos and people didn't know what other agencies were doing. That sounds good, but then you have the problem that we just saw with the WikiLeaks.
A user of information doesn't necessarily know what other agencies have and which could be very valuable for them to do their jobs. How does this play into this whole area of gaining access to information that could be critical, but then again protecting it from people who shouldn't be getting it?

COLE: That is at least a challenge because one of the phrases we use is, "Anything that could be used for good and be used for evil. So, on the one hand, you want the information to be accessible to a large number of people, you want high-end correlation of data and you want high-end details to be obtained, but on the other hand you want to reduce the risk of information being leaked out.

Once again, lots of different strategies where there are actually searching techniques where you can go in and find out information about a source without getting the details, or without getting the actual document. The idea now is instead of going in and letting somebody have full access to a 40-page document, when they might only need two of the 40 pages, what if we went in and actually did a better job indexing it where now you are indexing it at a more granular level. You are indexing at a paragraph or a page level so that now you are not requesting documents, you are requesting sentences or paragraphs. Now, now all of the sudden, you can get the details you need on a specific area but the bigger risk of getting more access than what is required to do your job is reduced.

At the end of the day, a lot of these problems that we see insider threat and information leakage, usually what occurs, and my guess is it would be true in this situation, the person needed some of the information in the document but not the entire document, but because most organizations don't know to hand it off in a more granular fashion, it is an all or nothing, and then they end up getting this repository with a lot more information than really is required.

Thin Client, Virtualization Reduce Risks

CHABROW: Would new tools need to be developed to automate this process, or can this process be automated?

COLE: If you think about the idea of having to go in and index everything at a sentence or paragraph level, it is a huge amount of work. The good part is, most of it can be done from an automated perspective. Now, there would be some costs in terms of the warehousing of this information, but you could argue that if the information is in electronic form, whether you are storing it as a single paragraph or as an entire document, it really takes up the same amount of space. So it is really the indexing form a high-end search engine to be able to build a meta- database to be able to find and access that particular data.
The other important thing is we have to better control that information. Right now today, all of the information is on servers; we have strict access control lists on the server but if you can get one person to copy that data who is authorized to their laptop, all of the access controls now are completely bypassed and they can give it out to anyone they want.
What if every time you are allowing somebody to access that sensitive information they had to do it from a thin client or a virtual machine? Anything they access could not be stored locally long-term; it would have to be maintained on the server. They could have a profile and they could have a directory on the server where they can save their searches, but everything is stored and controlled at the server level and nothing is put at the client level, and then all of the sudden once again you are taking away yet another avenue of exploitation from that user.

CHABROW: Obviously, at some point people would need to somehow store it; I mean the president of the United States isn't going to be working on a thin client, would he?
COLE: It depends on how transparent you make it. If you have the ability to open, view, access, store and read information, whether it is on your local hard drive or whether it is remote across the network, that really doesn't matter, and I don't think the president would care, it is all about can he get access to the information, when, where and how he needs it. And, if you look at all of the different communication mediums we have now between wireless, satellite and wired networks in almost every location, someone is always connected to a network; we can even do it at 40,000 feet now in airplanes and be able to have full access to the internet. As this access anywhere continues, I think you can do it in a way where it is completely transparent to the person and they just are not storing anything on a local portable media that has a greater risk of exposure and compromise.

3 Critical Questions

CHABROW: Any other takeaways you would like to share? 

COLE: Probably the big takeaway is, and I know when I say it sounds obvious, but we are amazed at how many organizations can't answer these simple questions. If you really want to have good security, you have to remember that especially when dealing with the insider threat, it is not about firewalls, IP addresses or technology. What it all comes down to is your data, and I would urge you - can you answer three questions.
  • What is your critical data?
  • What business processes utilize that critical data?
  • And, on what servers does that critical data reside?
If you can't answer those fundamental questions, how are you going to be able to manage, control and implement access controls, authentication and the other protection measures that are required long-term? We have to make sure we focus on the basics before we start dealing with the complex issues. 
CHABROW: Do you think people have learn the lesson of the WikiLeaks or do you think this is going to be a struggle for many organizations in the years to come?

COLE: I definitely think some folks have learned a lesson, but unfortunately in a lot of cases there is a small percentage of people though who they may see harm to others, they don't want the harm to them and they will learn from that activity. However, a large percentage of folks we found, until they personally suffer pain, they don't think it is something that can happen to them.
Unfortunately, I think there will be a large percentage of folks who will look at that, shake their heads and think how could this have happened, but then in the next sentence they say this can't happen to us. What everyone needs to realize is it absolutely, positively can happen to you. The question I would ask is: If there was somebody in your organization who is accessing information or more information than they should, if they were putting it on USB or other mechanisms and leaking it out of your organization, how would you know?
If the answer to that question is that you wouldn't, then you have to realize that you could have just put your name instead of the government's and the whole WikiLeaks thing could now be focused on your organization and all the issues you have.

( Eric Chabrow, Executive Editor, GovInfoSecurity.com)


Corruption Perceptions Index 2018

Why China is building islands in the South China Sea

INDONESIA NEW CAPITAL CITY

World Economic Forum : Smart Grids Explained

Berita Terbaru


Get Widget