<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>freethecityone.co.uk &#187; Security</title>
	<atom:link href="http://www.freethecityone.co.uk/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.freethecityone.co.uk</link>
	<description>Geek in the city</description>
	<lastBuildDate>Tue, 03 Jan 2012 09:11:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Beware of the hoax</title>
		<link>http://www.freethecityone.co.uk/2010/09/beware-of-the-hoax/</link>
		<comments>http://www.freethecityone.co.uk/2010/09/beware-of-the-hoax/#comments</comments>
		<pubDate>Fri, 24 Sep 2010 17:35:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Support]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[small business]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://www.freethecityone.co.uk/2010/09/beware-of-the-hoax/</guid>
		<description><![CDATA[I have just had from a client what appears to be the latest scare, which will inevitably result in some kind of infection. This is how it looks, which by the way appears very genuine. From: Abuse Department [mailto:abuse-uk-irl@ripe.net] Sent: 24 September 2010 14:32 To: XXXXXXXXXXXXXX Subject: ISP DISCONNECTION WARNING - ADVISORY ABUSE NOTICE From: [...]]]></description>
			<content:encoded><![CDATA[<p>I have just had from a client what appears to be the latest scare, which will inevitably result in some kind of infection. This is how it looks, which by the way appears very genuine.</p>  <blockquote>   <p>From: Abuse Department [mailto:abuse-uk-irl@ripe.net] </p>    <p>Sent: 24 September 2010 14:32</p>    <p>To: XXXXXXXXXXXXXX</p>    <p>Subject: ISP DISCONNECTION WARNING - ADVISORY ABUSE NOTICE</p>    <p>From: &lt;abuse-uk-irl@ripe.net&gt;</p>    <p>Date: Fri, Sept 24, 2010 at 12:44 PM</p>    <p>Investigation Number: 1171</p>    <p>Subject: ISP DISCONNECTION WARNING - ADVISORY ABUSE NOTICE</p>    <p>For The Attention Of: The Bill payer/Owner of this ISP account.</p>    <p>Our investigations have determined that your Internet Services account has been used to scan, flood or attempt to gain unauthorized access to another computer, (please see the details of the incident(s) attached to this e-mail). This activity is a violation of our Internet Services Acceptable Use Policy and the our Internet Services Account Agreement, under which you have been provided service.</p>    <p>THIS NOTICE IS TO ADVISE YOU THAT FURTHER ABUSE OF YOUR INTERNET SERVICES ACCOUNT MAY RESULT IN A SUSPENSION OR TERMINATION OF YOUR ACCOUNT, WITHOUT FURTHER NOTICE TO YOU. We are empowered to take such action if, in our sole determination, you have violated the terms of our Acceptable Use Policy or our Internet Services Account Agreement.</p>    <p>The alleged incident originated from the local IP address of 192.168.1.100 which, at the time of the incident, was assigned to a device with the unique physical address of 00:13:10:24:45:F8. This address identifies the network adapter or router connected to your ADSL/Broadband modem.</p>    <p>If you are unaware of this type of activity coming from your account, you may wish to inquire with others who may have access to your account and/or change the password to your account to ensure that only authorized users have access to it. IT IS ALSO POSSIBLE THAT YOUR COMPUTER MAY BE INFECTED WITH A VIRUS OR YOUR COMPUTER SYSTEM MAY HAVE SOME OTHER SECURITY PROBLEM SUCH AS AN UNSECURED MAIL OR PROXY SERVER WHICH COULD ACCOUNT FOR THIS ACTIVITY ORIGINATING FROM YOUR SYSTEM.</p>    <p>In the event you are not able to attend to the situation immediately, please disconnect your computer from the ADSL modem to prevent further abuse.</p>    <p>A full description of the incident including realtime IP addresses and web traffic can be found in the attachment.</p>    <p>Any questions of help can be obtained from out staff during office hours 0900-1700 Monday to Friday.</p>    <p>Our complete contact information can also be found in the PDF report.</p>    <p>Kind Regards</p>    <p>The Abuse Team</p> </blockquote>  <p>Attached to the email is a so called 'report' which is a 'RAR' file. Inside of the 'RAR' file is another file which is named 'Incident-Report-201009241171.pdf.exe'. So far it all looks like an elaborate hoax as the network the client is on is not on the range mentioned in the email and since when is a report sent as an executable file?</p>  <p>Any which way I will be putting it through the lab machine later to see what comes out, either way it will be interesting. </p>  <p>If you do hear of anyone receiving this tell them not to open it.</p>  <p>- Rob</p>]]></content:encoded>
			<wfw:commentRss>http://www.freethecityone.co.uk/2010/09/beware-of-the-hoax/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Essential free to SMB&#8217;s</title>
		<link>http://www.freethecityone.co.uk/2010/09/microsoft-security-essential-free-to-smbs/</link>
		<comments>http://www.freethecityone.co.uk/2010/09/microsoft-security-essential-free-to-smbs/#comments</comments>
		<pubDate>Thu, 23 Sep 2010 12:05:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[small business]]></category>
		<category><![CDATA[spyware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[security essentails]]></category>

		<guid isPermaLink="false">http://www.freethecityone.co.uk/2010/09/microsoft-security-essential-free-to-smbs/</guid>
		<description><![CDATA[Yesterday Microsoft announced that as from early October (no actual date as yet) it will be making Microsoft Security Essentials available for small businesses with up to 10 PC's FREE OF CHARGE. If you are not already aware of it I would highly recommend taking a look this move signifies a shift in the way [...]]]></description>
			<content:encoded><![CDATA[<p><img style="display: inline; margin-left: 0px; margin-right: 0px" align="left" src="http://www.sectechno.com/wp-content/uploads/2009/09/Microsoft-Security-Essentials.jpg" width="172" height="173" />Yesterday <a href="http://www.microsoft.com/" target="_blank">Microsoft</a> announced that as from early October (no actual date as yet) it will be making <a href="http://www.microsoft.com/security_essentials/" target="_blank">Microsoft Security Essentials</a> available for small businesses with up to 10 PC's FREE OF CHARGE. If you are not already aware of it I would highly recommend taking a look this move signifies a shift in the way that software is delivered to the SMB space. Microsoft have always supplied <a href="http://www.microsoft.com/security_essentials/" target="_blank">Security Essentials</a> to home users free of charge but the SMB space has always been covered by <a href="http://www.microsoft.com/forefront" target="_blank">Microsoft Forefront Security</a> as part of their Business Ready Security Suite. </p>  <p>So what's the difference? The core difference between the two products is that <a href="http://www.microsoft.com/forefront" target="_blank">Microsoft Forefront Security</a> is a centrally managed product which had updates and definitions distributed from a central source which is traditionally the office server. In contrast <a href="http://www.microsoft.com/security_essentials/" target="_blank">Microsoft Security Essentials</a> is ideally suited to Small businesses that may not have a server in place, for example when they are using cloud services, or that do not require central management. Either way it is a compelling and interesting move by <a href="http://www.microsoft.com/" target="_blank">Microsoft</a> in to a market space which they currently do not have a significant market share in.</p>  <p>Either way this is great news for Small Businesses everywhere!</p>  <p>- Rob </p>]]></content:encoded>
			<wfw:commentRss>http://www.freethecityone.co.uk/2010/09/microsoft-security-essential-free-to-smbs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>There&#8217;s a price on yer head</title>
		<link>http://www.freethecityone.co.uk/2009/02/theres-a-price-on-yer-head/</link>
		<comments>http://www.freethecityone.co.uk/2009/02/theres-a-price-on-yer-head/#comments</comments>
		<pubDate>Sat, 14 Feb 2009 11:11:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Support]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conflicker]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.freethecityone.co.uk/2009/02/14/theres-a-price-on-yer-head.html</guid>
		<description><![CDATA[Some of you may have read that latest news that Microsoft has put out a $250,000 reward to find who is behind the Conficker worm that is said to have infected as many as 12 million computers.&#160; They are doing this because it has taken the firm view that the creation of the Conficker worm [...]]]></description>
			<content:encoded><![CDATA[<p>Some of you may have read that latest news that <a href="http://www.microsoft.com" target="_blank">Microsoft</a> has put out a $250,000 reward to find who is behind the <a href="http://en.wikipedia.org/wiki/Conficker" target="_blank">Conficker</a> worm that is said to have infected as many as 12 million computers.&#160; They are doing this because it has taken the firm view that the creation of the <a href="http://en.wikipedia.org/wiki/Conficker" target="_blank">Conficker</a> worm as a criminal act.</p>
<p>This may seem like a bold move but it is not the first time they have done this. In 2005 they paid $250,000 to two individuals who helped identify the creator of the <a href="http://en.wikipedia.org/wiki/Sasser_worm" target="_blank">Sasser</a> worm.&#160; Rewards were also offered of $250,000 for the creators of the other three major computer worms <a href="http://en.wikipedia.org/wiki/Blaster_(computer_worm)" target="_blank">Blaster</a>, <a href="http://en.wikipedia.org/wiki/Mydoom" target="_blank">MyDoom</a> and <a href="http://en.wikipedia.org/wiki/Sobig" target="_blank">Sobig</a> however the authors of these were never caught.</p>
<p>In reality this amount of money is a small drop in the ocean for a company like <a href="http://www.microsoft.com" target="_blank">Microsoft</a> but in doing so they are trying to send out a strong message to the authors of such worms.&#160; They are simply saying that they will not sit idly by while the creators wreak havoc on their clients systems.&#160; In reality the fact of the matter is that regardless of what <a href="http://www.microsoft.com" target="_blank">Microsoft</a> or <a href="http://www.microsoft.com/mscorp/twc/default.mspx" target="_blank">Microsoft Trustworth Computing Group</a> offer it seems that it will offer very little in the way of a deterrent for such authors as it is a challenge that they enjoy rising to.&#160; What it does do is help their clients to feel that they are doing all they can to try an prevent such hassles returning in the future.</p>
<p>The worm itself infects a computer that is not fully up to date with the latest updates from the Microsoft Update website. If you are in any doubt then the best action is to visit the <a href="http://update.microsoft.com" target="_blank">Microsoft Update</a> website and apply all the latest critical updates.&#160; Once this is complete continue to revisit the site until you are told there are no further critical updates. You should also ensure that your Anti-Virus software is fully up-to-date, if you don&#8217;t already have one then visit either <a href="http://www.avg.com" target="_blank">AVG</a> or <a href="http://www.avast.com" target="_blank">aVast</a> who both provide free versions for home use.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freethecityone.co.uk/2009/02/theres-a-price-on-yer-head/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security via Interguard</title>
		<link>http://www.freethecityone.co.uk/2009/01/security-via-interguard/</link>
		<comments>http://www.freethecityone.co.uk/2009/01/security-via-interguard/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 16:51:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[small business]]></category>
		<category><![CDATA[corporate security]]></category>

		<guid isPermaLink="false">http://www.freethecityone.co.uk/2009/01/05/security-via-interguard.html</guid>
		<description><![CDATA[I have just had the heads-up from a good friend of mine to let me know that he will be sending over my copy of Interguard software for home, laptop and corporate security.&#160; All being well I should have the stuff over this evening and all things being equal will get something posted up over [...]]]></description>
			<content:encoded><![CDATA[<p>I have just had the heads-up from a good friend of mine to let me know that he will be sending over my copy of Interguard software for home, laptop and corporate security.&#160; All being well I should have the stuff over this evening and all things being equal will get something posted up over the next couple of days.&#160; As products go this is shaping up to be a great product with a very comprehensive range for features for such things as monitoring web access.&#160; DataLock which helps prevent data leakage from a business as well as laptop security so should your beloved laptop be stolen or lost then it can located, data retrieved and the notebook disabled from ever working again.</p>
<p>Awesome stuff so you&#8217;ll have the review as soon as I have it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freethecityone.co.uk/2009/01/security-via-interguard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Better safe than sorry (part 2)</title>
		<link>http://www.freethecityone.co.uk/2008/03/better-safe-than-sorry-part-2/</link>
		<comments>http://www.freethecityone.co.uk/2008/03/better-safe-than-sorry-part-2/#comments</comments>
		<pubDate>Sat, 22 Mar 2008 14:03:11 +0000</pubDate>
		<dc:creator>robfranklin</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[it security]]></category>
		<category><![CDATA[notebook security]]></category>

		<guid isPermaLink="false">http://www.freethecityone.co.uk/2008/03/22/better-safe-than-sorry-part-2.html</guid>
		<description><![CDATA[Yesterday I wrote about encrypting data on your notebook computer when you are carrying data around. Within that posting I mentioned TrueCrypt as a program which can be used for this task so for those of you that are interested in it, I mean who wouldn&#8217;t as it&#8217;s open source, here&#8217;s a brief tutorial. Once [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday I wrote about encrypting data on your notebook computer when you are carrying data around.  Within that posting I mentioned <a href="http://www.truecrypt.org/" target="_blank">TrueCrypt</a> as a program which can be used for this task so for those of you that are interested in it, I mean who wouldn&#8217;t as it&#8217;s open source, here&#8217;s a brief tutorial.<span id="more-52"></span></p>
<p>Once TrueCrypt is installed then you can create a new secure volume using the wizard which can be launched from the main program screen.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/tcmain.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/tcmain-thumb.png" style="border: 0px none " alt="TrueCrypt Program Screen" border="0" height="345" width="404" /></a></p>
<p>From here click on the &#8220;Create Volume&#8221; button to launch the wizard.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-1.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-1-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="left" border="0" height="197" width="324" /></a></p>
<p>From here select the &#8220;Create a File Container&#8221; option the create a new secure volume on your Hard Disk.  From here you can also choose to Encrypt the entire system partition which means that the partition that Windows is installed on would be encrypted and require a password to be entered before Windows can boot.  You can also encrypt a non-system partition which would be another partition on your drive or a USB memory stick.  In this example we will create a &#8220;File Container&#8221;; once selected click next.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-2.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-2-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="right" border="0" height="197" width="324" /></a></p>
<p>At the next screen you have the option to select a &#8220;Standard TrueCrypt Volume&#8221; or a &#8220;Hidden TrueCrypt Volume&#8221;.  A Standard volume is simply an encrypted volume which when the password is entered it mounts and the data is visible.  The &#8220;Hidden Volume&#8221; however is a little more sophisticated; what happens is when the volume is created it will create another volume within that one.  Both volumes are located as a single file on the disk however the one that becomes visible is dictated by the password entered.  This is especially useful if you have to enter your are forced to enter your password under duress; in this scenario you would enter the password for the volume which does not contain the actual secure data but is in fact the &#8220;fake&#8221; secure data.  For this example however we will create a &#8220;Standard Volume&#8221;; once selected click Next.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-3.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-3-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="left" border="0" height="197" width="324" /></a></p>
<p>Once the next screen you will be asked to &#8220;Select File&#8221; which basically speaking means that you need to specify the filename and location.  The actual filename you use should be a obscure as possible as this will make the file harder to locate to would be attackers.  In this example we have called the file &#8220;readme.txt&#8221;  Once you have done this click on Next.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-4.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-4-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="right" border="0" height="197" width="324" /></a></p>
<p>From the next screen you have the option to select what encryption algorithm you want to use for your volume.  The algorithm that you use simply dictates how the data is encoded when the file is created and more importantly when data is stored on the volume.  For most of us AES will be sufficient so we will select that and click Next.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-5.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-5-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="left" border="0" height="197" width="324" /></a> Now we have to specify the size of our encrypted volume.  This will be entirely down to personal choice and will be dictated by the amount of data that you want to carry with you.  For simplicity we will enter a value of 100MB and then click on Next.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-6.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-6-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="right" border="0" height="197" width="324" /></a></p>
<p>At this point we are now required to enter a password.  It cannot be impressed enough how important it is to choose as strong enough password for this file.  Lets face it if you simply enter the password as &#8220;password&#8221; then it isn&#8217;t going to take much to guess it.  So no kids names, no pets, no car registration, no spouse&#8217;s, nothing that is anything to do with you.  Lets face it if you used you favourite nursery rhyme that would be more secure as a password; for example &#8220;tw1nkle tw1nkle l1ttle star how 1 wonder what you are&#8221; would be completely random, nothing to do with you and yet easy to remember.  So think long and hard what you will use and make sure it&#8217;s something easy to remember but still strong.  Once this is done then click Next.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-7.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-7-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="left" border="0" height="197" width="324" /></a></p>
<p>The next screen is for formatting the volume however before you click &#8220;Format&#8221; you need to move your mouse randomly within the Window.  This is done to help to create a completely random key and the more you move the mouse then more random it becomes.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-7a.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-7a-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="right" border="0" height="197" width="324" /></a></p>
<p>When you have done this and you are happy with it click on &#8220;Format&#8221; and wait until a box appears telling you it is complete.  Now click on &#8220;OK&#8221;</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-8.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/create-vol-wiz-8-thumb.png" style="border: 0px none " alt="Create Volume Wizard" align="left" border="0" height="197" width="324" /></a></p>
<p>When this has finished you can either continue with the wizard to create another volume or you can click on &#8220;Exit&#8221; to return to the main TrueCrypt screen.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/tc-mount-vol1.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/tc-mount-vol1-thumb.png" style="border: 0px none " alt="Mount Volume" align="left" border="0" height="256" width="324" /></a></p>
<p>From them main TrueCrypt screen click on the &#8220;Select File&#8221; button and you will be presented with a screen titled &#8220;Select a TrueCrypt Volume&#8221;.  From here we can select our newly created volume, in our example we will select the file &#8220;readme.txt&#8221; and click on &#8220;Open&#8221;.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/tc-mount-vol2.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/tc-mount-vol2-thumb.png" style="border: 0px none " alt="Mount Volume" align="right" border="0" height="277" width="324" /></a></p>
<p>Now select the drive letter from the top part of the screen that you want to assign the volume to, in our case this will be &#8220;F:&#8221;, now click on &#8220;Mount&#8221;.  This will then prompt you for the password that you entered earlier as below.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/tc-mount-vol3.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/tc-mount-vol3-thumb.png" style="border: 0px none " alt="Mount Volume" align="left" border="0" height="81" width="244" /></a></p>
<p>Enter your password and then select &#8220;OK&#8221;.  If you need to you can check the &#8220;Display Password&#8221; box so that you can see what you are typing but obviously make sure no-one is around to see it.</p>
<p>That is basically it, you can now go into &#8220;My Computer&#8221; and you will see your newly create volume as shown below.</p>
<p><a href="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/mounted-volume.png"><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/mounted-volume-thumb.png" style="border: 0px none " alt="Mounted Volume" border="0" height="192" width="404" /></a></p>
<p>I hope this is of help to some of you and if you have any questions then please post them up and I will try help where possible.  The program is just one of many that are around and each of these vary in the way that they work however this all work towards the same end result which is that they all try to make your data more secure.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.freethecityone.co.uk/2008/03/better-safe-than-sorry-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Better safe than sorry</title>
		<link>http://www.freethecityone.co.uk/2008/03/better-safe-than-sorry/</link>
		<comments>http://www.freethecityone.co.uk/2008/03/better-safe-than-sorry/#comments</comments>
		<pubDate>Fri, 21 Mar 2008 09:36:40 +0000</pubDate>
		<dc:creator>robfranklin</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[file encryption]]></category>
		<category><![CDATA[it security]]></category>

		<guid isPermaLink="false">http://www.freethecityone.co.uk/2008/03/21/better-safe-than-sorry.html</guid>
		<description><![CDATA[Over here in the UK there has been a lot in the paper recently about the data losses by some of the key government agencies such as HMRC as well as businesses such as Skipton Building Society much of which was not encrypted data. As you will know there has been much public outcry and [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://79.170.44.115/freethecityone.co.uk/wp-content/uploads/2008/03/9380.png" alt="Security" align="left" />Over here in the UK there has been a lot in the paper recently about the data losses by some of the key government agencies such as <a href="http://news.bbc.co.uk/1/hi/uk_politics/7117291.stm" target="_blank">HMRC</a> as well as businesses such as <a href="http://news.bbc.co.uk/1/hi/business/7156030.stm" target="_blank">Skipton Building Society</a> much of which was not encrypted data.  As you will know there has been much public outcry and quite rightly so but do we have any room to talk?</p>
<p>The fact is that almost every business today owns at least 1 notebook computer and typically that will be taken out to meet clients, to work from home etc.  On that notebook there will typically be a great deal of data regarding either your own business or possible about your clients data so do you encrypt your data?  The answer is almost certainly no, so how on earth can we complain when other organisations do they same.  While I understand that these organisations should know better as they have much larger funding budgets to get people onboard that should be telling them this but the fact of the matter is that very few businesses do this themselves.  Recent figures show that the public is 80% more cautious with their personal data than before the HMRC data loss which is a positive move for security.  You may think that the data on your notebook is of no value to anyone else but lets just assume for one minute that you loose your notebook and you have the following on it:</p>
<ul>
<li><font color="#555555">On it is the payroll figures as you needed to work on them tonight </font></li>
<li><font color="#555555">You also have the sales figures for your clients </font></li>
<li><font color="#555555">Details of a new proposal for a potential client </font></li>
<li><font color="#555555">Documentation regarding a client(s) site, not including passwords </font></li>
</ul>
<p>So what is the value of this to anyone else:</p>
<ul>
<li><font color="#555555">The payroll data would be invaluable to a headhunter for example.  If you had a member of staff who had some very coveted knowledge then they would be able to know where to start with pay offers</font>
<ul>
<li><font color="#555555">If the payroll figures included home addresses of employees then this would also be of interest to criminals for identity theft.</font></li>
</ul>
</li>
<li><font color="#555555">Sales figures would be of great interest to your competition as they would be able to ascertain the financial value not only of your own company month in month out but also the value of each of you clients each month.</font></li>
<li><font color="#555555">Details of a new proposal would again be of interest to your competition as they would then know what you are proposing but more importantly what you are planning to change for this fantastic service.  If this proposal is for an IT system this may also be of use to a potential hacker as it may provide information regarding internal systems or security information.</font></li>
<li><font color="#555555">Documentation regarding a clients site would almost certainly hold value to a potential intruder if it was technology documentation as it would provide valuable insight into what internal systems they had.  If it related to equipment such as phones, plant machinery then again it would have value to competitors or companies in that field.</font></li>
</ul>
<p><span id="more-21"></span>The fact of the matter is that whatever data you have it will be of use to someone and simply putting a password on Windows is just not going to cut it.  By simply booting of a CD such as <a href="www.ubcd4win.com" target="_blank">UBCD4WIN</a> you don&#8217;t even need to crack the password for Windows, it will let you access the data on the hard disk and transfer it off and with the price of notebooks so low now (from £299) the data is often worth many times the value of the notebook.</p>
<p>So what can you really do to stop this?  Well quite simply encrypt the data, this can be done a number of ways.</p>
<ol>
<li><font color="#555555">You can use Windows XP EFS (<a href="http://en.wikipedia.org/wiki/Encrypting_File_System" target="_blank">Encrypting File Service</a>) to encrypt data and lock it to the individual user account.  This means that should anyone who is not logged in with the user account that encrypted the files then they will not be able to access the data.</font></li>
<li><font color="#555555">There is also <a href="http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption" target="_blank">Bitlocker Drive Encryption</a> which available to Windows Vista (Enterprise and Ultimate) and Windows 2008 server.  This system uses full disk encryption to encrypt and entire volume rather than individual files.  It requires an area of the disk to be created as a Bitlocker volume.</font></li>
<li><font color="#555555">There are also a host of third party application which will either encrypt individual files or create PSD&#8217;s (Personal Secure Drive) which is essentially a encrypted file on your hard disk that is mounted up as a volume (Drive letter) so that you can save your files.  While it is mounted it is unsecured but once it is dismounted or the system is shut down it becomes encrypted again.</font></li>
</ol>
<p>One such package that I have found to be a very good product for this particular task is <a href="http://www.truecrypt.org/" target="_blank">TrueCrypt</a>, it&#8217;s an open source package for on-the-fly encryption.  While you can encrypt the entire drive you can also create encrypted volumes which can be mounted up as disks on your system by using a password.  I personally like this method as it allows me to create a volume to store all of my &#8220;data&#8221; in rather than being mixed up with the rest of the system.</p>
<p>There are a great many package which do the same or similar and they are all equally able to secure your data whether using a password, keyfile or a hardware USB key combines with passwords etc.  Some are certified for government users while others are not but in the end it is personal choice however whatever the case it is something that should definitely be looked at.</p>
<p>For more information on using TrueCrypt then please read <a href="http://www.freethecityone.co.uk/2008/03/22/better-safe-than-sorry-part-2.html">Better safe than sorry (Part 2)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.freethecityone.co.uk/2008/03/better-safe-than-sorry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

