Saturday, 12 September 2009

The laptop that shouts 'Stop, thief' when stolen

“Get your hands off me, I have been stolen,” the laptop shouted. That is a new solution to laptop computer theft: a program that lets owners give their property a voice when it has been taken.

The program allows users to display alerts on the missing computer's screen and even to set a spoken message. Tracking software for stolen laptops has been on the market for some time, but this is thought to be the first that allows owners to give the thief a piece of their mind.

Owners must report their laptop missing by logging on to a website, which sends a message to the model: a red and yellow “lost or stolen” banner pops up on its screen when it is started. Under the latest version of the software, users can also send a spoken message.

The theft-busting program, Retriever, has been produced by Front Door Software Corporation, a small company based in Evergreen, Colorado. Carrie Hafeman, its chief executive, said that if owners tick a box indicating that their computer has gone, when it is started up, “a big red and yellow banner pops up, saying 'This laptop is lost or stolen'.”

The message can be set to reappear every 30 seconds, no matter how many times the thief closes it. “One customer sent a message saying, 'You are being tracked. I am right at your door',” Ms Hafeman said.

In the latest version, people can add a spoken message. The default through the computer's speakers is: “Help, this laptop is reported lost or stolen. If you are not my owner, please report me now.”

Others have introduced more direct alerts. “You can record your own. You can say, ‘Get your hands off me, you S.O.B.',” Ms Hafeman said.

The Retriever software package, which costs $29.95 (£21) but has a free trial period, has the functions of many security software programs. Owners can remotely switch to an alternative password prompt if they fear that the thief has also got hold of the log-in details.

If a thief accesses the internet with the stolen laptop, Retriever will collect information on the internet service provider in use and nearby wi-fi access points, so that the police can be alerted to its location.

Thousands of laptops are stolen every year from homes and offices, but with the use of laptops increasing, the number stolen while their owners are out and about has been rising sharply.

Other laptop security software allows users to erase data remotely or lock down the computer.

The Undercover software from Orbicule for Macintosh laptops sends back screenshots from the stolen computer and takes pictures with the laptop's built-in camera.

The “talk” update of the Retriever program works with Microsoft Windows XP and Vista and a version for Mac users is in the pipeline, Ms Hafeman said.

http://technology.timesonline.co.uk/tol/news/tech_and_web/personal_tech/article5828105.ece

Posted via email.

Thursday, 3 September 2009

Defense-contract discs sold in African market for $40

Dumped hard drives with US defense data have turned up for open sale in a West African market. A team of Canadian journalism students bought a hard drive containing  information on multi-million dollar contracts between military contractor Northrop Grumman and the Pentagon for just $40 in a market near Accra, Ghana. The exercise was part of shooting a documentary on e-waste by Vancouver journalism students, researching what happens to the West's discarded and donated electronics.

"You'd think a security contractor that constantly deals with very secret proprietary information would probably want to wipe their drives," Blake Sifton, one of the three graduate journalism students told CBC. The team bought seven hard drives at a market in the port of Tema, a major point of entry for electronic waste from Europe and North America into Africa.

Northrop Grumman is reported to be investigating how an unencrypted hard drive containing sensitive data on the firm ended up on an African market, in violation of its established kit disposal procedures.

"Based on the documents we were shown, we believe this hard drive may have been stolen after one of our asset-disposal vendors took possession of the unit," Northrop Grumman told CBC.
Blogged with the Flock Browser

Pensions Trust faces grilling over stolen laptop security lapse

The Information Commissioner has launched an investigation into the theft of a laptop containing the details of 57,000 members of social housing pension schemes.

The commissioner will attempt to find out how the details, held by the Pensions Trust, came to be put at risk and whether action is needed to prevent similar data losses.

The computer stolen on 23 March held the details of around 50,000 members of the Social Housing Pension Scheme and a further 7,000 members of the Scottish Federation Housing Association Pension Scheme.

The data, which included bank account details, National Insurance numbers and salary details, was password-protected but not encrypted. It was taken from the offices of Northgate Arinso, which supplies the trust’s computerised pensions administration system.

The commissioner launched the investigation after it was contacted about the theft by the trust on 22 May.

When you have Backstopp installed you have protection against breaches like these.

News Source:http://tinyurl.com/ncoa75
Blogged with the Flock Browser

Wednesday, 2 September 2009

Laptop security and data protection in schools

Schools, as is the case with any person or organisation handling personal data, must comply with the Data Protection Acts. Personal data collected by schools for their own purposes is the responsibility of the schools as they are the Data Controller. The website of the Data Protection Commissioner has advice and information in relation to the responsibilities of Data Controllers.

Sensitive data should not leave the school unless it is absolutely necessary. Other options of accessing the school based data such as remote accessing your schools network can ensure that the data does not physically leave the network and any information used in the manipulation of the data can be securely disposed of. This may be considered before transferring data onto a device that will be accessed outside of school.

Laptop and Portable Data Security – Some advice and support

All schools should have a policy pertaining to use of all portable data storage (PDS) media i.e. laptops, USB sticks, external hard drives, PDA’s, memory cards etc.

The assignment of laptops or other devices to teachers should always be recorded so that they can be easily tracked from an asset management point of view. A record of serial numbers, list of hardware features (DVD, wireless mouse, etc.) and other information that can be used to identify the laptop or device should be compiled and retained in the school. These items should be included on the school insurance policy. If the laptop is for teachers’ work at home use , this should also be noted in the school insurance policy. Any policy should include procedures for reporting loss/theft. It may also be useful to inform the manufacturer technical support in case the laptop or device is sent back for repairs.

Security issues to consider

There are a number of issues and questions to consider before removing sensitive data from a school location.

* Is the need to access information outside of school justifiable?
* Has the data been backed up before it leaves the building?
* Have you reduce the risk of the device being lost or stolen?
* Have you taken efforts to make it more difficult for an unauthorised person to access that device?
* Have you taken efforts to make it more difficult for an unauthorised person to access data on that device?


Security measures to implement

* All essential data leaving the office should be adequately backed up. In regards to email, it is important that there is a copy backup not on the physical laptop. Consider using web based mail (or use IMAP) or ensure a copy of mail is saved on the server.
* Where possible the School name and contact details should be identifiable on purchased equipment to deter thieves and aid recovery. A well secured security label on the frame of the laptop is advisable. The desktop background could contain the name and address of the school to aid return if the laptop is lost.
* Cable locks should be used wherever possible to secure the laptop to the desk if used in areas where there is a risk of theft.
* Schools should also ensure that security features within the Operating System are enabled and user profiles are protected. It is possible to set a password at the boot up stage of the laptop to make it more difficult to access the hard drive or reinstall the operating
system.
* Strong passwords should accompany any log in user authentication
* A secure password policy should be implemented, requiring staff to
change their passwords on a regular basis (monthly is industry standard
practice).
* Use “strong” passwords consisting of letters (both uppercase and lowercase),
numbers and symbols such as w£Ty78&Q
* Check your password strength at http://www.passwordmeter.com/
* A school should give serious attention and thought to where sensitive data is stored and accessed. For example if a laptop contains sensitive data it may then not be wise that this laptop is used throughout the school by many users. It may be best kept in the principals’ office.
* Where sensitive data is saved on the laptop, schools should make the effort to ensure data security of that data. It is possible to password protected files and folders within the popular operating systems used in schools.
* There are different levels of data sensitivity. Data relating to a person’s bank details will be more sensitive than results of in school exams. The level of security should reflect the data it is protecting.
* There are also different encryption solutions available if required. These cost of these solutions range from free to expensive and have varying degrees of encryption which may make it more difficult to access the data.

Blogged with the Flock Browser

Tuesday, 1 September 2009

The Green Cloud: Hype or Reality?


The cloud, as we all know, is the hot IT topic of the moment; in Gartner's latest Hype Cycle, published last month, Cloud Computing holds the dubious honor of being tied with e-book readers at the top of the "peak of inflated expectations."
From the press release announcing the latest Hype Cycle:
The “Hype Cycle for Emerging Technologies” is the longest-running annual Hype Cycle, providing a cross-industry perspective on the technologies and trends that IT managers should consider in developing emerging-technology portfolios. This Hype Cycle features technologies that are the focus of attention in the IT industry because of particularly high levels of hype, or those that may not be broadly acknowledged but which Gartner believes have the potential for significant impact.

“Technologies at the Peak of Inflated Expectations during 2009 include cloud computing, e-books (such as from Amazon and Sony) and Internet TV (for example, Hulu), while social software and microblogging sites (such as Twitter) have tipped over the peak and will soon experience disillusionment among enterprise users,” said Jackie Fenn, vice president and Gartner Fellow.
 But in the last week, I've happened upon a number of blog posts and news items talking about the most important (from my perspective, at least) element of the cloud: Is it green?

I raised this question, somewhat indirectly, in July from the standpoint of Microsoft's online-Office announcement:
Both Microsoft and Google have extremely efficient large-scale data centers; both companies are aiming for an industry-leading PUE of 1.12 in their computing centers. Expanding the use of these services means more incentive to concentrate IT operations in these top-of-the-line facilities, and will continue the shift that individuals are already undertaking toward netbooks -- cheap, web-centric laptops that forgo much of the established abilities of desktops and full-sized laptops for more portability and lower price.
We'll come back to my take on this topic, but first, the rundown. In a new article on NetworkWorld, Tom Jowitt looks at the findings of Rackspace's latest Green Survey, and finds plenty of skepticism:
over 21% of IT managers believe that cloud computing is a much greener alternative to traditional computing infrastructures, but it seems that the vast majority still remain to be convinced.

Thirty-five percent said they were not convinced on the green benefits of cloud computing, and 25 percent felt that there was too much hype around the green benefits of cloud computing. Meanwhile 19% felt that the true green benefits of cloud computing have not yet been realized.

Seven percent admitted that cloud computing was critical to their company becoming greener; 14% are currently evaluating cloud computing and its environmental benefits; 13% have considered the benefits of cloud computing as part of their overall environmental strategy; and 20% would be interested in learning more about the green benefits of cloud computing.

But a sizable portion (46%) said that cloud computing was not a part of their overall environmental strategy.
 While CIOs and IT managers as a whole are still uncertain about the green benefits of the cloud, big business -- and industry experts -- see the green lining. Exhibit A: a blog post from David Talbot at MIT's Technology Review, which kicks off thusly:
Cloud computing may raise privacy and security concerns, but this growing practice -- offloading computation and storage to remote data centers run by companies such as Google, Microsoft, and Yahoo -- could have one clear advantage: far better energy efficiency, thanks to custom data centers now rising across the country.

"There are issues with property rights and confidentiality that people are working out for mass migration of data to the cloud," says Jonathan Koomey, an energy-efficiency expert and a visiting professor at Yale University. "But in terms of raw economics, there is a strong argument," he adds. "The economic benefits of cloud computing are compelling."
 Original Article - http://us.mobile.reuters.com/mobile/m/AnyArticle/p.rdt?URL=http://www.reuters.com/article/gwmTechnology/idUS350327231420090928