Russell Mickler Russell Mickler

10 Things You Can Do to Enhance Your Privacy and Security Online

identity_theft.jpg

Safeguarding your Personal Private Information (PPI) and thwarting identity thieves is your responsibility; nobody else is going to do it for you. And if you aren't taking reasonable precautions, you're likely to become a victim. Here's a couple of practical tips for safeguarding your PPI from wrong-doers.

Get a Secure Physical Mailbox.

Take a look at your mailbox. You know: that little tin drop box used to house your most confidential PPI ever? If you can't lock it, why are you using it? Remedy that. Get a secure mailbox at The UPS Store or your local postal service. Addendum: make all of your critical utility and consumer banking payments electronically and reduce the need for physical mail entirely. The less PPI that transfers in the actual mail, the better.

Get a Dedicated Credit Card.

Set up a credit/debit account with your financial institution that's exclusively used for all of your online purchases. It should be a unique account and separate from all of your other assets. Run online purchases through this account. Kill the card and account at any time without any real consequence to your actual banking accounts.

Use Complex Passwords.

A complex password is a password that's at least 10 characters long, mixed-case, with meta-characters like punctuation in it. Example: G0lfc0urs3! - read as "Golfcourse". Why? It takes a typical microcomputer 5 minutes to hack a simple password and over 500 years to crack the variability of a complex password. The time it takes to hack a complex password is an effective deterrent. Yeah, it's tough to remember, and that's the point. Convenience is the enemy of security. Don't make it convenient for somebody to hack you.

Don't Use the Same Password Everywhere.

Okay, sure, using multiple passwords can be a pain, but - hey, didn't I just say this? - convenience is the enemy of security. If somebody hacks one account and it's easy to guess the credential to other accounts. That kind of behavior only makes you more vulnerable.

Ditch Facebook ... or Constrain It.

Facebook is a huge repository of consumer PPI and it's only becoming more sophisticated at revealing private details about your life to others. Those details make it easier to case (or investigate) who you are and what you do online. Leaving Facebook, though, may not be entirely an option, so your next best approach would be to constrain what Facebook shares about you. Check out Facebook's Privacy Settings and seriously limit what Facebook shares about you. 

Ditch Microsoft Windows ... or Constrain It.

The Microsoft Windows operating system is less secure than Mac O/S or Linux; security experts recommend avoiding using the product. Still, chances are, your behaviors are already changing and you're using more secure operating systems found on your phones (iOS and Android) for transferring critical PPI, and that's probably a good thing and a strategy for containing your risk. If you can't abandon Windows, at least curtail your banking and utility payments on the platform in favor of paying by mobile apps. The less PPI you share on Windows, all the better.

Use Google's Chrome Browser. On Every Device. Optimize it's Privacy. Install HTTPS Everywhere.

Google Chrome is a browser designed around better Internet security. It's faster and more secure than Windows Internet Explorer and Mozilla's Firefox. Chrome is free and available for all platforms: PC, Mac, iOS, and Android. Install Chrome and optimize it's privacy features. Then, install HTTPS Everywhere: a free tool built in to Chrome that forces a secure connection to the places you go on the Internet.

Invest in Teathering.

Teathering refers to using your cell phone as a data hotspot. Carrier plans that include teathering are really inexpensive these days and are considered a standard feature. Instead of using public wifi access points (which can be designed as a honeypot to have unsuspecting users connect to it and expose PPI), you'd want to teather your laptop or tablet computers against your mobile device. Your cell carrier is ultimately more secure than any random wifi hotspot you might find in the field. It'll help keep the information you transfer confidential and private. 

Reduce Your Attack Profile.

Be conscious of where you share your personal private information; who you give your business card and personal information to. Question why somebody wants a critical identifier like a driver's license or a Social Security Number and even consider not doing business with these people. Limit your applications for credit and your banking products to a single provider. Don't sign up for everything you see online and delete online accounts that are no longer in use. Shred any physical documents instead of throwing them into the mail. Sit down with your spouse or partner and discuss strategies for limiting each other's exposure.  Be conscious and take specific actions to reduce how someone could acquire your PPI and exploit a vulnerability.

Be Conscious of Social Engineering.

Imagine being in a checkout lane at the supermarket. You have somebody behind you looking at their phone. Meanwhile, you remove your credit card and swipe it, then, enter a PIN code, into a reader device in plain sight. All the while, the guy behind you on the phone is recording your activities, capturing your card data and PIN on video. Your assumption of privacy got the best of you. Be aware of your surroundings and of those who may be using electronic devices around you. Take immediate action to protect yourself.

R

 

Read More
Info System Security Russell Mickler Info System Security Russell Mickler

Remove GPS Data from iPhone Pictures

image.jpg

The iPhone, like many modern cell phones, can take pictures. When those pictures are taken, information about the location of where the picture was taken is embedded into the photo. This is called metadata, and specifically it's referred to as a geotag.

Geotags are an interesting feature in that they can be pulled up on a map, then, sequenced in time to replay where you were when the photo was taken, even down to the very accurate location of a room within a household.

Very clever and fun. Until you start thinking about children using iPhones - their privacy and security become compromised in that it lays out a predictable pattern of their whereabouts.

Photos (along with the metadata) are uploaded conveniently into social media networks and distributed to whomever in uncontrolled ways. 

This date is also used by professional computer forensics technicians (hey, like me!) to identify potential evidence in the court of law. 

Further, if someone wanted to "case" another (a term used in hacking meaning we collect personal private information about individuals in order to break into their accounts), geotagging provides a unique and easy exploit. Imagine a stalker determining the predictable locations and timing to harm a victim?

So ... You may be curious on how to turn off geotagging on your iPhone or iPad.

1. Go to Settings.

2. Privacy. 

3. Location Services. 

4. Camera Setting and flip to OFF position. 

Doing this will prevent the device from storing geo-tag metadata in future photographs.  The photos you've already taken and uploaded probably already have the geotag information in them and it cannot be removed, other than deleting the photo, or, Using an app like deGeo (you can find it in the iTunes App Store).

It's not perfect, but it is one step you can take to control the distribution of your whereabouts, and the whereabouts, safety, and privacy of your children. 

R

 

Read More
Management, Systems Russell Mickler Management, Systems Russell Mickler

When You Need an App

Want to make an app for your small business? Think again. Why? How will the app empower the user and be differentiated from your website? Let's talk strategy here.

An app is a program downloaded to a smart phone or tablet computer. There are zillions of apps.  Most people's mobile devices are cluttered with them.

Because of that, apps produce a lot of noise: that is to say that the clutter from all of those apps makes it more difficult to use the device.

Over time, people instinctively try to cut down on the noise and manage the number of apps they own. They prune, categorize, and delete the apps they don't need.

If you create an app, you're competing against a ton of other apps for a very small space on the smartphone.

Many small businesses that I meet are all over this craze and want to create an app. Ooo we've got to have an app, they say! So when I ask what it'll do and what value it'd bring to the user experience, they look at me puzzled. "It will tell them about our services and give them a fast way to contact us," they say, and I shoot back, "Oh ... like your website?"

Then I try to get them to think about how quickly such an app would be deleted because it's noisy. It doesn't add any real value or differentiation, so why would anyone keep it?

And that's the trick with apps. Good apps should enable the user to do something:

  • it should be a tool;
  • it should be a way to collect and review information;
  • it should extend your customer service to the palm of their hand;
  • it should be a way to reduce friction (calling or emailing your offices to get something done);
  • it should be a way to share experiences with your products to potential customers in their social community.

Apps should empower a user. If an app doesn't do this, it's valueless, and will likely be perceived as clutter and deleted from the mobile device.

Meanwhile, companies should make their websites mobile-aware so that they change perspective to fit a smaller screen with less resolution. If a website isn't mobile-aware, it'll present itself as a site better viewed on a desktop machine, making it very difficult to read and access information. Companies should make their website mobile-aware so that they're easier to read, consume, and use, thus making it easier to work with the company.

But a website isn't an app. And even more horrendously, an app's purpose shouldn't be to just drag the user to a website. If you want to get into the app business, think about how the app extends the consumer experience and empowers their relationship with you. Otherwise, stick to the website, and make that as easy as possible to use on mobile devices.

R

 

Read More