Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, October 11, 2013

ADINTL: Why IBM Notes is Secure

This post is ripped from the headlines, literally, my Facebook headlines.

Many times I am questioned why IBM Notes requires it's own password. People are quick to point out Outlook does not and they do not like the interruption. (Technology people stop laughing! Talking about end users here) By the way, Outlook does have it, but, well, read this where they state:
This password feature however shouldn’t be regarded as a sturdy protection mechanism though and it was never intended as such either. The passwords are easy to crack via various tools such as Atomic Pst Password Recovery and the encryption of the pst-file isn’t based on the password either.
Yes, well you know Facebook, Twitter, et al have passwords which you can choose to bypass via your browser saving password option. Outlook does it similarly via Windows server and clients, this is called Single Sign On or SSO in my world.

IBM Notes has a similar SSO option. Not going to debate the pros and cons of it. If you know the topic, you get it already. In short, we need more security in some organizations and in others we need the users to just get work done and not have to remember yet another password.

As a computer user you have the option to set your Windows or Linux or Mac screen saver or timeout setting to ask you login after some amount of unused time. Same thing in IBM Notes.

However, if you make your password for IBM Notes different from your primary system login, you have an extra layer of security for your email client. In my case, where I leverage many widgets in my sidebar that connect to some important systems, this is very helpful. I rarely worry about someone logging into my email client.

But, if you choose to leverage SSO or just make all your passwords the same and never set a logooff time, you could end up with, as an example, a Facebook messages like this one day:


And yes the comments are growing and quite amusing as well. What could there be on Facebook that anyone would care enough about to secure it?

Why do I bring this up? Because in the time it takes for you to go to the bathroom, get a drink of water or a coffee or in some places get the document you printed, you could be the victim of an internal or external security breach.

It may be funny and a nice prank on your friends, but in business, some serious problems can be started this way. Hackers know it is easier to get to you from inside your own company than outside of it. The hackers may look like gardenersfire rescue people....or your spouse.

I am open and trusting in my collaboration at work and at home, but when I am traveling or at a client site ,I always manually turn on the screen lock whenever I leave my desk.

If you do not make use of the security your systems have already, you have no one else to blame when these things happen to you. IBM Notes has been and always will be a very secure product and if that is important to you or your company, I can help you leverage it.

I can also get you over your fear of people writing on Facebook as you.

ADINTL= A Day In The Life



Tuesday, April 5, 2011

Novell's Vibe collaborates differently for the better



I have been spending some time lately playing with Novell's Vibe which is in beta, you can sign up at the link.

It is far from polished or ready for prime time, but some interesting findings which I want to share with you.

Privacy is a luxury. One of things I always found odd about Groupwise was the way they enabled anyone to read and send email as though it was the originator. Nothing new, we have this in Notes too, but Novell took the view that it's not a security issue or a privacy one, if you know someone is doing this. Thus their view of collaboration is also not weighted down by security or privacy, compared to Lotus ones.

Novell is working to bring the Google Wave idea to some usage, but to me at least, it is still as confounding as Google's product. Maybe I am too linear and old school but the almost random items that fly past you in the stream/river(they call it the Biglist) troubles me. I was told there is an icon to let me know what is a private message but at the time everything appeared open.

Novell wants people to share information truly collaboratively. And I applaud that effort and look to Project Vulcan to bring some of this as well. But my original posting, or message is editable by anyone right now. That is just mind blowing to me. Scarily so. From the threads it looks like that will not be the case at Live date but needless to say that raises questionable ideas. I'd like to see my posts ask me if they can be edited or not. And I'd like to see items not be allowed to be copied, printed or forwarded or "bring in" someone else to read it. Funny thing was the developer I was talking with said they did not have these limitations/security in Groupwise.

Before you think I am killing on Vibe, I am not. It's beta, it needs feedback. It is rather fun to be playing with code that the developers are using and logged in to as well so they can listen and chat to me while I am experiencing the quirkiness of a new product. I can't remember the last time we had this in Lotus.

Also, in the grand scheme of consumer vs. corporate philosophy I think Novell has a perspective that IBM should think about. Are you writing a product that will foster or hinder collaboration? Is too much security and lock downs bad in this day and age? As an admin and speaker at conferences I know the pros and cons of this question well. I also see companies not truly recognizing the path they are on may lead to a down side where employees may not choose to work there.

While certainly there should be some security, the premise of true collaboration is everything should be open all the time to everyone. Not a place that has a public and a private side and then squirreled away secret rooms inside those. Thinking like a customer I would like to see better security on offer, even if clients do not use it all, than see less security available.

What will be of interest to me is how Novell deals with this product from a mobile device. Will there be a special app for the big3(Apple, Google, RIM) or will it just be a browser? Will the promise of 4G speeds make this work well or be bogged down?

The same could be asked of IBM and Project Vulcan. Right now the argument goes on about how to build traveler and support what and where. I am looking beyond these devices to understand the future and it seems no one really has a great handle on it.

I don't care about devices or OS, I care about getting my data to me no matter what I am using. And my clients ask the same of me. But I do care about privacy(Yes I use social media and location based programs but that is different from inside the company firewall privacy) perhaps more than security because in the end all systems will have their security methods but privacy seems to be the forgotten step child.

After all, BCC was created for a reason, maybe not a good one, but there are good reasons for it as well.

Friday, August 27, 2010

An Invasion of Privacy by Citibank and AT&T

Dear Citibank and AT&T,

If you robocall someone, ask for their name and zip code, which is not that hard to produce for criminals and then ask for me to speak to someone to assist me, they should be able to let me know what account # we are discussing BEFORE asking me for real information like Social Security #, birth date or my bank details.

I asked for them to let me know which card(we have a few between corp and personnel) it is, tell me the last 4 digits of the card or the last digits of one of our accounts, but they are unable to comply unless I give out my details?! YOU CALLED ME!

So you get to invade my privacy and request personnel information BEFORE your people can tell me anything? and you expect me or anyone else to believe you are Citibank or whatever?

The person suggested I call back the number on the back of my card, I asked, which card, they can't tell me.

Thank you,

A not very happy customer

Thursday, October 15, 2009

SNTT- Secure your RDP

If there is one thing an administrator needs, it's remote access.... to just about anything.

Some companies frown on this, but honestly, do you really want to wait for someone to get in a car, drive 40 miles to the office, just to enter a few commands on a Windows server at the OS level?

So the early days we had PCAnywhere which was most common, but we used a bunch of things and then VNC and finally Microsoft RDP (Remote Desktop Protocol) and now gotomypc, logmein and tons of others.

And how it makes life easier, except for one thing, and I have watched this at many companies be the case if no VPN exists or their Domino servers are on the outside of the firewall.

One can RDP to any server set up for it in Windows. But, just as much as I can connect...so could a malicious user. If one knows the name of the server, one can start a dictionary attack or today's equivalent especially if no one limits the attempted logins. Windows has various ways to lock this down, Transport Layer Security (TLS) is suggested, but if not feasible, at least set the account lockout thresholds, account lockout duration, etc.. One can also narrowly define who has such access and from what IP address and well, this can go on forever as far as options go but let's presume you are an SMB and cheap too.

One simple and free way is to change the RDP ports.
Regular RDP runs on Port 3389.
3389/TCP Microsoft Terminal Server (RDP) officially registered as Windows Based Terminal (WBT)

But you can change this number in your registry settings to any port number you wish.

Follow this Microsoft technote to change the port number which says:

Start Registry Editor.
Locate and then click the following registry subkey:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TerminalServer\WinStations\RDP-Tcp\PortNumber
On the Edit menu, click Modify, and then click Decimal.
Type the new port number, and then click OK.
Quit Registry Editor.


If you need help figuring out what port to use, this Wikipedia page is a good place to start. But you should be able to use 3389-3395 and many at the higher end of the list. (I know someone will correct me if not)

Then when you go to use RDP make sure to add the port at the end of the server name. For example: lotusevangelist.com:3395 (nope, not my port #)

And you are done. Now do it for each server(either all port 3392 or each one unique. Yes, I know this can cause some problems, but if you create a logic to the numbers it can work for you.

Why should you do this, even inside your own company or if you have a VPN? Because of this and scarily this as well.

Your own people may try to hurt you, sadly, so be careful out there.

Thursday, October 1, 2009

What would you do if...

Your service provider of a collaborative nature decided to lock you out or disable your account...permanently.

What about your data, your emails, your photos, RFP's, lists or whatever you have stored there?

Someone on Twitter that I follow was told by Facebook they will be shut out of Facebook.

So what does this person potentially lose that is so important to him?

This is just some of what he stands to lose from this account which he has had for over 2 years:

* Thousands of personal correspondence messages in his inbox
* Thousands of his posts throughout Facebook
* Control of approximately 40 groups and pages with hundreds of thousands of combined members
* Membership of over 200 other groups and pages
* 30 photo albums containing hundreds of images
* Nearly 4,000 friends acquired over the years, due to his hard work


Some of this may not be of interest, but how would your customers feel if they were locked out of Gmail or any other service in the Cloud because the company went under or hey opted to lock you out.

Who owns your data?
What choice do you have?
Who do you complain to?
Is there damages to sue for?
Is a social network a data centric network?
If so, how do you protect your data and back it up?

Something to think about before you go storing your data all over the place.

Friday, September 11, 2009

Epic Fail Natwest Bank

What started out so promising turns sour because banks have forgotten why they exist, to help us store our money with them and in return they pay a nominal interest rate while they leverage our money for their investments.

Some of the banks have forgotten the basic ideas of customer service.

Evidently being a virtual/online customer allows them to treat you like you don't exist.

I saw this with Citibank over the years went from an excellent bank to being nearly useless. American Express as well went from being exceptionally helpful to being a nickel and dime operation.

But Natwest has gone too far, or perhaps not far enough.

I understand in the modern world security is important but if the processes do not make sense, neither does your security methods.

Having banked with them for 11 years now and perpetually frustrated by their myopic view of their customers who live outside the UK, this has broken the camel's back.

Called them to the UK to arrange for a transfer for some bills from our summer trip. Provide all the usual numbers, codes, pins and I thought passwords.

Turns out their system claimed my password submitted was invalid and after 3 tries locked me out.

No problem or so I thought, just reset it for me.

No dice.

Natwest has absolutely no way to reset one's password without mailing by postal mail, from the UK, a password change code. One then signs it and returns it, again via postal mail before the password can be changed. Knowing the UK/US postal route, the round trip is at least 2 weeks if all is efficient without Fedexing it.

There is no other way to resolve this I was told. They asked for my debit card # which I never carry obviously here in the US. Will try again from home with it to see if it makes a difference. But seeing how this is working, I wouldn't bet on it.

And once your password is bad, you are locked out of online banking until the new one can be issued, again via postal mail after the previous 2 weeks, so we are looking at 3 weeks before I can get access to MY MONEY.

Having worked with many banks through the years, I know the processes in place and also recognize when a major fault in process exists. And this is huge.

Asked the 12th person I spoke with in 45 minutes what would they do for someone who had 100,000's or millions of pounds with Natwest? And was told, in a very British way, they would have to wait.

You could bet all your money no one in their right mind would leave their money hostage with a stupid bank like Natwest. If I was in the UK I would write a check for the whole amount and move it to anyone.

But as I am in the US, it makes it more complicated although I certainly intend to move all my money out of there now.

So evidently no matter how much I know about myself, or can provide information, if I was traveling in Singapore and really had none of this information but needed my money I would be stuck there indefinitely.

You see Natwest, for security reasons, ONLY sends the mail to the address on record. So you are SOL if you are traveling and need money that badly. So beware you Natwest account holders, make sure you know all your details and they are valid.

Still don't understand why I can't just change it online like I do for my credit cards, utility bills, other banks and systems. Something which is so simple and could be done with NO human interaction,but Natwest doesn't do it and instead holds my money hostage.

Natwest uses at least 5 pieces of information for me before I can do anything with them, someone would need to know all 5 pieces to NOT be me and I find it hard to imagine they would know them all. account #, sort code, Pin #, Cust #, unique reference #, 1st school I think or college but they stopped asking that one.

And yet they think a letter mailed to my house and replied to and signed guarantees someone is not stealing my identity? Are they serious? I can't do it via email, fax or secured anything but the regular totally unsecured postal mail?

Natwest you got a lot to learn.

Monday, July 6, 2009

Exposing Security holes is not funny business

This is being written for CYA purposes.

In reading some tweets from someone I noticed a link to a site which was personally and professionally relevant.

A nice usage of a shared calendar and I investigated it deeper.

As I usually am want to do, I tested their network for basic security holes which would usually point to junior admins work or one of those "damn forgot to fix this" moments of us senior admins.

And sure enough their NAB is exposed. Not only that but the server IDs as well as most employee ID files are attached in the NAB and free to be downloaded. Oh and employee personal details are exposed as well, kids, home address, etc.

Odds the server IDs have a password? I'm not going to check to find out but my guess is they don't.

And the top 2 senior executive ID files? Yes, you guessed it attached.

I sent one of the executives, responsible for IT, an email outlining what we can do to help them with this problem and that they should really take notice of it.

Sometimes this leads to clients, sometimes not. But it does point out the larger picture which is just because you run Domino on a non-Windows platform, doesn't mean your IT staff knows anything about securing Domino, although I am sure they are excellent at their OS of choice.

This is NOT funny and sadly it is an R8.5 server too which means that either they did this on their own, with no advice or worse another BP did it and really exposed them to potential lawsuits and other potential issues.

Either way hopefully we will at least be able to discuss this with them further before it goes on like this for too long.

The bottom line is NEVER make your NAB open to the outside world. Default should always be No Access. If you have an internet connected server you are just asking for trouble.

Luckily they have it set to reader and not editor! I will NOT test delete but my guess is that is available to me, although adding a person is not.

And for those who question how bad is this, I COULD recreate any of their servers, then their certs, after all I have valid server IDs and user IDs and can read the NAB so I could build a server to match theirs and then create accounts as the executives and start sending out 100% valid emails. In fact this is how I had to save 2 customers in the last year, I posted about them too.

Not funny at all. A great write up case potentially for Lotusphere.

Friday, April 24, 2009

Fud Buster Friday #37 - Exchange 2010 is Going to Kill Domino

While perusing InfoWorld magazine this week I came across an amazing piece of fluffy reporting from someone who should be able to do better.

His quote
Reliability has improved in Exchange 2010
Damn well hope so! One of our clients who we are migrating from Exchange report failures monthly if not weekly. Conversely my Domino servers stay up until I down them for upgrades(OS,Domino,Java etc.) once a quarter.

So aside from the great title, "First look: Exchange 2010 beta shines", what is so great?

First, Support for Windows Server 2003 is dropped in favor of Windows Server 2008 only. Okay, so we will see more push to move up to Windows 2008.

OWA (Outlook Web Access) will finally be ported to work with Safari and Firefox. Nice, iNotes and DWA under Domino has had it for some time, in various iterations(yes I know version specific, but at least it exists today).

Voice Mail Previews?
OK, it provides a speech to text way to read your voice mail. Hmm, so why send the vmail at all as an attachment? Google just showed this recently. Nice piece actually, I hate listening to vmails and my phone doesn't play them so this I would like to see in Domino.

Users can create server distribution lists.
WOW! And to think users had that capability, with proper security in place since version 1 of Lotus Notes. Welcome to the security world Microsoft.

Managers can search other employees mail files.
With approved security. I hope so!

And they could not do it now because? Microsoft saw no reason to let you do it. Only Admins could search across mail files.

"The Exchange Control Panel (ECP) allows users to control their own server settings. Changing a user's mobile phone number in the global address list used to require a help desk call." It does? Really? Granular security coming to Microsoft finally. Thanks Ray for adding Lotus Notes functions that are 20 years old!

He says
Users can also control who can see their calendar information and in what detail: I might want my supervisor to know when I have a doctor's appointment, but all a colleague needs to know to schedule a meeting with me is when I'm free and when I'm busy.
What a concept, again, where have you been Exchange?


Mailboxes can now be moved live
without taking the user offline. Isn't that how it should always be done? Again, Microsoft plays catch up.

But he says
Moving a mailbox from one server to another formerly required taking the user offline for at least a couple of hours, not to mention night and weekend hours for the mail administrator.
OUCH!

There was also this amazing insight:
Exchange 2010 now allows mail federation between trusted companies. This is especially powerful when it comes to scheduling meetings using shared free/busy calendars; suddenly, you can schedule meetings with your business partners as easily as you can schedule meetings within the company. You have the same fine-grained control over the detail that business partners can see in your calendar as you do over what colleagues can see. Another improvement in scheduling is that conference rooms and other meeting resources can be scheduled along with the attendees.
Ho Hum, thanks for following the Lotus Notes world, again. And that improvement in scheduling is also nice to hear so you can gain some parity with Lotus Notes calendaring.

So your boss wants to stay, or go with Exchange because he likes being the laggard instead of the industry leader?
You can also go back and read Ed Brill's post from last week about this and the volumes of comments about it.

Friday, July 25, 2008

Vista Insecurity from yesterday's MS FAM

From the Seattle Times

Microsoft's annual financial analysts meeting, referred to as FAM, typically covers the breadth of the world's largest software maker.

Bill Veghte, Microsoft senior vice president of Online Services and the Windows Business Group, talked about Windows Vista and the improvements in the product and its adoption in the past year.

On security, for example, Windows Vista is 62 percent more secure than Windows XP SP2, he said.

Thanks, Bill. How comforting to know there is no secure operating system from Microsoft yet. Shame about all that money spent on it.

Monday, March 3, 2008

Going Mobile with Sametime, Why aren't you?

Nope, no Traveller yet :-(

This is about Sametime Mobile. I love it, especially the R8 version. So much faster and more intuitive, and the lookup on users is fantastically fast.

The problem was my Blackberry users could not get to it. My fault, wrong IP address entered. Hey, we all mistype now and then.

But they rally missed having it. I didn't even think they used it.
Taught me a great lesson. Users really like when we are proactive in helping them extend their reach, even if we don't always know how many people it helps or in that one circumstance.

Sure I know that, but many people still deny their user's rights as simple as this.
If you can not do everything from your mobile phone by the end of this year, what on Earth are you waiting for?

Try Lotus Expeditor, enable your apps(within reason) for mobile fidelity. HR apps, vacation schedule workflows, even sales information mashups should be there, if they aren't already.

The cost?
Negligible next to the productivity gained. Talk about ROI, it's a huge winner.

If any of you have not en bled Sametime Mobile, tell me why?

It's just a configuration(yes I know ports on firewalls, etc. but you already have it opened via 1533 anyway if you run Sametime or 80 for http tunneling, so no excuses). Security? If you go via a BES it makes its own VPN so to speak and tunneling. Proxy, not an issue we work with it, reverse proxy, we work with it too.

Next time you are in the airport use it, amaze yourself what you can do. Yes you can call people but this way you do not get a busy signal or vmail.

Thursday, January 3, 2008

Stability vs. Cutting Edge

We would all like to think of ourselves as bleeding edge, top of the line tech managers, staff or whatever your range of business.
But reality kicks in sometimes.

I know, I'm a Miami Dolphins fan and right now, there are
many questions, few answers. The biggest, how did a great team hit rock bottom?

In the IT world, it's easier sometimes to see the slide coming because the signs are there and no one is reading them, usually because we have no time.

Last post I showed a graphic of a Lotus Domino server which ran, without fail or stoppage for 177 days. Which is cool, great and impressive from a stability perspective.
BUT, what if that is a bad sign from an operations perspective?

If you can't answer these questions well enough for your CXO, maybe you should revisit what you are doing for your clients and/or employers.

Does this imply my client is adverse to change or was I told not to do something?
Is change control systems (if you use them) threatening your advancement and opportunities ?
Did we/me not manage their servers properly?
Who should have upgraded the Lotus server application level
Who should have upgraded the Windows server Operating System level?
Are we missing something we could benefit from either of these 2 upgrades, do we even know what?
Quarterly updates come out almost regularly for Lotus and IBM software, why did these not get installed?
Microsoft releases updates monthly usually, evidently these were turned off since usually we have to reboot the server once the patches are installed, are we open to security vulnerabilities now?
Do we do IT Audits in our company? If so, why did they not say anything to us about this as well?
Are we a leadership organization or a follower? Take a look at our competitors market cap or stock price or recent quarter/annual numbers and see, you may not like the answer.

If IT is essential, why are we not treating it that way?

Your car needs oil and an oil change or it will come to a grinding halt, your server may be more forgiving, or not, but the marketplace is not and rewards those that advance or live on the cutting edge.

So in the end which are you really?