<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lithik Systems &#187; privilege</title>
	<atom:link href="http://www.lithik.com/tag/privilege/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lithik.com</link>
	<description>Transforming businesses by bending technology to the will of our clients</description>
	<lastBuildDate>Thu, 26 Jan 2012 15:28:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Traveling Safely With a Laptop</title>
		<link>http://www.lithik.com/2009/04/09/traveling-safely-with-a-laptop/</link>
		<comments>http://www.lithik.com/2009/04/09/traveling-safely-with-a-laptop/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 03:11:07 +0000</pubDate>
		<dc:creator>Karl Fox</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[autorun]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[FDE]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[notebook]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[privilege]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[USB drive]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://www3.lithik.com/?p=142</guid>
		<description><![CDATA[Carrying a laptop has always meant a bit of risk. If you&#8217;re like me, you watch your bag like a hawk when you&#8217;re in a restaurant or or in an airport. Laptops have always had great resale value on the black market, but with HIPAA, PCI, GLB and Sarbanes-Oxley violations costing organizations millions of dollars [...]]]></description>
			<content:encoded><![CDATA[<p>Carrying a laptop has always meant a bit of risk.  If you&#8217;re like me, you watch your bag like a hawk when you&#8217;re in a restaurant or or in an airport.  Laptops have always had great resale value on the black market, but with HIPAA, PCI, GLB and Sarbanes-Oxley violations costing organizations millions of dollars to recover from a single information theft incident, the danger is at an all-time high.</p>
<p>It doesn&#8217;t have to be that way.</p>
<p>There are some tried-and-true, basic steps you can take to dramatically reduce the cost to your organization of data loss due to laptop theft or malicious penetration when using your computer in a public place.  Implement them all and you can come close to eliminating the possibility of a data breach.  The following steps are organized by the threat they mitigate.<br />
<span id="more-142"></span></p>
<h2>Theft</h2>
<p>The best way to deal with the risk of laptop theft is to ensure that the thief cannot possibly get any of your information off of the computer.  If you work for a real business, the cost of having private information (proprietary data, HIPAA Protected Health Information, PCI records, etc.) fall into the hands of the bad guys is immeasurably greater than the value of the physical laptop.  Insurance will probably pay for new equipment anyway.  Fortunately, good technology is available to protect your information at a reasonable price.  My favorite price is free.</p>
<p><a href="http://www.truecrypt.org">TrueCrypt</a> is a free, open-source, high-quality Full Disk Encryption (FDE) product.  It supports a wide variety of modern encryption algorithms that are sure to foil any information thief.  But remember that once somebody has possession of your computer, it would be a very simple thing to boot it from a CD-ROM containing an FDE password cracker, a tool that would make short work of a simple boot-time encryption password like &#8220;<a href="http://modernl.com/article/top-10-most-common-passwords">letmein</a>&#8220;.  So <a href="http://www.lithik.com/2009/08/04/creating-good-passwords">choose a really good password</a>, where really good means really long.  Something like &#8220;till the end of time&#8221; (20 characters) will keep any current password cracker hunting for a few hundred years, or until someone adds phrases from popular songs or the Bible to the word lists employed by these hacker tools. You can mix it up with strange capitalization or a misspelling (say, &#8220;@ the end of Time&#8221;) to make it even harder, but the best way to make it better is to make it longer.</p>
<h2>Packet Sniffing</h2>
<p>You may have confidence in your WPA2 wireless G network at work, but what about when you&#8217;re on the unencrypted wireless network at Starbucks or plugged into the Ethernet at your hotel?  This is where the Virtual Private Network (VPN) shines, and there&#8217;s a really nice one out there at my favorite price.</p>
<p><a href="http://openvpn.net">OpenVPN</a> is a free, open-source VPN tool that runs on Windows, Linux, and even wireless access points.  When using <a href="http://en.wikipedia.org/wiki/Secure_Sockets_Layer">TLS</a> (the successor to SSL) to negotiate 256-bit AES encryption authenticated with 1024-bit RSA certificates, this is a solid protocol with excellent credentials.  When carried over UDP, it has none of the difficulty traversing <a href="http://en.wikipedia.org/wiki/Network_address_translation">NAT</a> routers or firewalls that bedevils <a href="http://en.wikipedia.org/wiki/IPsec">IPSec</a> users.  We set it up so that it&#8217;s always on, staying out of the way when no network is attached or when accessing public web sites, but connecting automatically when possible to allow secure access to corporate internal systems.  It&#8217;s especially secure if <em>all</em> your traffic goes through the VPN, even when performing such mundane tasks as browsing public web sites.  Setting up OpenVPN, however, is not for the faint of heart, so hire a professional to do it for you.</p>
<h2>Network Attacks</h2>
<p>Being sniffed is not the only threat you face on public networks.  You are also open to direct attack from other network dwellers, so don&#8217;t make it easy on them by leaving your file shares open to the world.  The best configuration is termed &#8220;stealth&#8221;, where your computer refuses to respond to any incoming traffic at all.  No file sharing, no iTunes sharing, no remote desktop and no ping.  Only <a href="http://en.wikipedia.org/wiki/Address_Resolution_Protocol">ARP</a> remains operational, but it has to because you need it so that other devices can respond to your outbound web and other requests.</p>
<p>Fortunately, you can probably have your cake and eat it too.  Windows XP has two separate sets of firewall configuration rules, one for when you&#8217;re attached to a corporate Active Directory domain and one for when you&#8217;re not.  If you use Active Directory at work, you can set up the &#8220;domain profile&#8221; to allow management by your IT staff and configure the &#8220;standard profile&#8221; to be stealth when you&#8217;re on the road.</p>
<p>If you use Vista, you have even more choices.  There are three different firewall profiles: domain, public and private.  With Vista, you can have one set of rules for work, one for your home, and one for Starbucks and other dangerous places.</p>
<p>But what if you work at a small place that doesn&#8217;t use Active Directory?  You still have options.  On Vista, you can use your private firewall profile for work and the public one for everywhere else.  If you&#8217;re running XP, though, it&#8217;s a little tougher.  Have your IT folks set up rules in your standard firewall profile that are very tightly fitted to their setup.  Perhaps allow Remote Desktop and remote administration only from the corporate server&#8217;s IP address.  It&#8217;s not perfect, but an attacker will never know the difference unless you just happen to be on a public network with the same IP network number as your office <em>and</em> he happens to have the same IP address as your corporate server.  Not perfect, but pretty darn good.</p>
<h2>Passive Attacks</h2>
<p>Nearly all successful penetrations of home or corporate desktops occur through passive attacks such as visiting an infected web site or opening an infected e-mail attachment.  We&#8217;re so familiar with this kind of attack that it should come as no surprise that the mitigation is also familiar.  Keep your computer up-to-date with all the latest Windows and other patches, and use a good antivirus system.  Set your computer to update automatically with Windows as well as other applications: Adobe Reader, Flash, Apple QuickTime, etc.  Not all antivirus systems are created equal, either.  Check out <a href="http://www.av-comparatives.org">AV-Comparatives.org</a> to find out which are the best.</p>
<h2>&#8220;Drive-by&#8221; Attacks</h2>
<p>Someone plugs a hacked USB drive into your computer.  Or they load a CD-ROM while you&#8217;re in the bathroom.  Or you leave it unattended and someone reads your e-mail or steals a file by e-mailing it to himself.  These scenarios tend to be more paranoid than the ones above because you typically leave your computer unattended only in environments where the people are trustworthy.  Or so you think.</p>
<p>We keep hearing the statistic that 80% of all data breaches are perpetrated by insiders, but we can&#8217;t think of anyone where we work who would ever do that.  But they must exist, and, of course, any such person would keep such evil thoughts very, very private.  So let&#8217;s make a few changes that keep easy access to your computer just out of reach.</p>
<p>The first and easiest step is setting up a locking screensaver.  On nearly ever screensaver, there is an option to have it prompt for a password before returning to normal operation.  Some computers also allow you to set up a quick and easy way to engage the screensaver, such as moving the mouse pointer to one of the corners of the screen.  Or you can press the Windows logo key (if you have one) plus the L key to immediately engage the screensaver.</p>
<p>Sometimes the Windows autorun feature is handy, but just as often I find it annoying.  But it can be positively dangerous if inserting a USB drive or CD-ROM automatically runs software from the device, especially if you think your computer is safe because the screen is locked.  Get rid of this behavior by <a href="http://www.lithik.com/2009/10/22/disabling-the-windows-autorun-feature">disabling autorun</a> (not autoplay&mdash;that&#8217;s different and not dangerous).  Just google for the phrase &#8220;disable autorun&#8221; and you&#8217;ll find dozens of step-by-step recipes.</p>
<p>Finally, any malicious person or software will find it much more difficult to infect your computer if you log in under an account that does not have administrative powers.  You need to be an administrator to do things like install new software, but that&#8217;s best done in a separate account.  Go to Control Panel -> User Accounts and create a new login with account type set to Computer administrator, then change the type of your regular account to Limited.  This is what Apple recommends its users do on OS X, and it plays a significant role in making Macs more secure than Windows computers.</p>
<h2>Summary</h2>
<p>You <em>can</em> carry a secure laptop, and it doesn&#8217;t have to be painful or expensive.  Here&#8217;s the list again:</p>
<ul>
<li>Use Full Disk Encryption (FDE)</li>
<li>Choose a <em>long</em> FDE password</li>
<li>Use a VPN to connect to your company&#8217;s systems</li>
<li>Set Windows firewall to <em>stealth</em></li>
<li>Configure Automatic Updates</li>
<li>Install a good antivirus system</li>
<li>Use a locking screensaver</li>
<li>Disable autorun</li>
<li>Use a non-privileged account for normal computer uses</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.lithik.com/2009/04/09/traveling-safely-with-a-laptop/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

