Wednesday, February 11, 2015

Tabula Rosa Special Feature - Celerbrate Safer Internet Day!

 
Yesterday was Safer Internet Day. Also this post is late, the message it carries is not Please read the article below. There are some good thoughts here. As the Internet expands its reach and capabilities, it is, and will continue to be, more difficult to maintain your desired level of privacy!
=============================================


3 questions you should be asking on Safer Internet Day

by Paul Ducklin on February 10, 2015 

What's in a word? 
Sometimes, quite a lot
.
That's how we feel about the fact that today is Safer Internet Day.
In fact, we're happier about helping you learn to be safer than telling you how to be safe.
That's because internet safety isn't absolute, not least because the internet's threats, as well as its benefits, keep changing.
Even Facebook, which many youngsters already consider a social network for old-timers, only arrived in 2004.
We couldn't have advised you on how to behave on Twitter until 2006, briefed you on WhatsApp until 2009, given you tips for Instagram until 2010, or explained what was wrong with Snapchat's promises until 2011.
In other words, keeping safe online is a journey, not a destination.
So, instead of trying to be prescriptive, and giving you a list of tips and tweaks, such as configuration options to turn on, we'll be descriptive instead.
Instead of telling you what to do, we're going to give you three questions you can ask yourself whenever you want to try something new online.
Better yet, they're questions you can ask out loud, and even encourage your children to ask out loud, without ever sounding ignorant or out of touch.
Whatever you do online, whether it's agreeing to an app's terms and conditions, clicking through to a website, uploading a photo, or merely looking at an email, go through this checklist:
1.    Who am I talking to?
2.    What am I telling them?
3.    Could anyone else be affected?

We're not being judgmental here.
We're not saying, "Don't turn on location services because you should always keep your location confidential."
We're not insisting, "It's dangerous to give details about your interests and hobbies to online forums."
We're not instructing you, "Never, ever upload photos taken in public to avoid publishing the pictures of other people in the photo."
But all of these are excellent examples of online behaviours that many people enter into without going through our question checklist above.
So, let's look at what can go wrong in the examples above.
Location services
Many operating systems, mobile devices and online services have Location Services turned on by default.
Learn how to control how and when you share your location, and don't feel compelled to enable Location Services because an app or your operating system promises you cooler results if you do.
You may be letting the whole world track your every move.
Go through our checklist, and make your own mind up for each app's use of location data: if in doubt, don't give it out.
Interests and hobbies
Sharing information about your lifestyle and your hobbies is fun, and if you aren't giving away any intimate details, then it doesn't feel any riskier than simply going about living your lifestyle.
After all, if you like mountain biking, then all your cycling friends probably already know what bike you've got, which trails you like to ride, and where you had your last prang.
But beware of giving too many details to the whole world that would usually only be known to someone you actually meet up with regularly and trust.
Otherwise it may be possible for a crook to learn enough about you to guess your passwords; to answer your security questions at websites or banks; or to trick other people into thinking that he knows you well and is a trusted insider in your circle.
Go through our checklist, and make your own mind up for information you are about to share: if in doubt, don't give it out.
Group photo uploads
Remember that you may very well be "on the internet" even if you've never opened a browser or gone online in your life.
That's because other people who have taken photos in which you appear, and who might not have the same sense of privacy that you do, could have uploaded them without asking, or even thinking about you.
So, when one of your friends or family whips the camera out, don't be afraid to ask if you can duck out of the photo if you don't want to be in it, or to ask them what they plan to do with it.
And return the favour by asking them up front when it's your turn to take the pictures.
By the way, also be mindful of what's in the background: don't do a "Prince William", who was photographed in an RAF office - with a username and password clearly visible on the noticeboard behind.
Go through our checklist, and make your own mind up for upload: if in doubt, don't give it out.
Safer Internet Day
Never feel compelled to give away more data about yourself than you need.
As we've said several times above: if in doubt, don't give it out.
===================================

**Important note** - contact our company for very powerful solutions for asset protection, data leakage, log, IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Tabula Rosa Security Alert Of The Day - Microsoft Vulnerabilities From US-CERT


======================================

National Cyber Awareness System:
02/10/2015 09:22 PM EST

Original release date: February 10, 2015
Microsoft has released updates to address vulnerabilities in Windows as part of the Microsoft Security Bulletin Summary for February 2015. Some of these vulnerabilities could allow remote code execution, security feature bypass, elevation of privilege, or disclosure of information.
US-CERT encourages users and administrators to review Microsoft Security Bulletin Summary MS15-FEB and apply the necessary updates.


This product is provided subject to this Notification and this Privacy & Use policy.
===================================

**Important note** - contact our sister company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Tuesday, February 10, 2015

Tabula Rosa Systems Critical Security Alert Form US-CERT





 National Cyber Awareness System:
02/10/2015 12:53 PM EST

Original release date: February 10, 2015

Microsoft has released Security Bulletin MS15-011 to address a critical vulnerability in Windows. Exploitation of this vulnerability could allow a remote attacker to take complete control of an affected system.

This security update contains a new policy feature (UNC Hardened Access) which is not enabled by default. To enable this feature, a system administrator must deploy the update, then apply the Group Policy settings described in the bulletin. For complete protection against this vulnerability, system reboots are required. Other than the update and configuration instructions contained in the Security Bulletin, there are no known workarounds or mitigations for this vulnerability. Updates are not available for Windows XP, Windows Server 2003, or Windows 2000.
     
US-CERT strongly recommends administrators prioritize the application of the patch, and concurrently review and test the necessary configuration changes discussed in the associated Knowledge Base article (KB3000483).
===================================

**Important note** - contact our sister company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Monday, February 9, 2015

Tabula Rosa Systems Blog Of The Day - TRS Product Summary Of Tripwire




Tripwire is the market leader for security configuration management, configuration compliance management, vulnerability management, and reliable log collection management. 

Auditing the configurations of IT systems and monitoring changes in those configurations is critical to reducing security risk and achieving compliance.  Tripwire Security Products shore up defenses against threats, provides visibility and context into your infrastructure, helps you focus corrective efforts on the events that matter, and lets you get your security operational. With Tripwire, you prevent breaches from occurring—and protect the business when they do—to minimize their consequences.

Tripwire's solutions help organizations of all sizes and types quickly address the first four, truly foundational, security controls. Conquering the first four then lays the foundation for addressing additional controls—which Tripwire can also help with. Using Tripwire, enterprises can achieve accelerated progress on:
  • CSC 1 - Inventory of Authorized and Unauthorized Devices
  • CSC 2 - Inventory of Authorized and Unauthorized Software
  • CSC 3 - Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers
  • CSC 4 - Continuous Vulnerability Assessment and Remediation
Regardless of the security control framework your organization may be considering or has begun to implement, the SANS 20 is a flexible starting point, applicable to nearly any organization regardless of size, industry, geography or government/commercial. See how Tripwire can help you make rapid progress in establishing a strategy, quickly implementing and then measuring and reporting against your organization's goals.

For further information, please contact us at 609-818-1802 or email sales@tabularosa.net
 ===================================

**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Tabula Rosa Security Alert From US-CERT Product Vulnerbilities

================================================


National Cyber Awareness System:
02/09/2015 06:22 AM EST

Original release date: February 09, 2015
The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.
The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:
·         High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0
·         Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9
·         Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9
Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis
=======================================
**Important note** - contact our company for very powerful solutions for mail, network, systems and  IP management (IPv4 and IPv6, security, firewall and APT solutions):

www.tabularosa.net

In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:

 www.amazon.com/author/paulbabicki

 If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio  Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications. 

Lastly, I am the founder and president of Tabula Rosa Systems, a company that provides “best of breed” products for network, security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT product information for virtually anyone.
==============================================

Sunday, February 8, 2015

Tabula Rosa Technical Term Of The Day - The Theory Of Relativity

 ==================================


Theory of relativity from whatis.com

Albert Einstein's theory of relativity is actually two separate theories: his special theory of relativity , postulated in the 1905 paper, The Electrodynamics of Moving Bodies and his theory of general relativity , an expansion of the earlier theory, published as The Foundation of the General Theory of Relativity in 1916. Einstein sought to explain situations in which Newtonian physics might fail to deal successfully with phenomena, and in so doing proposed revolutionary changes in human concepts of time, space and gravity.

The special theory of relativity was based on two main postulates: first, that the speed of light is constant for all observers; and second, that observers moving at constant speeds should be subject to the same physical laws. Following this logic, Einstein theorized that time must change according to the speed of a moving object relative to the frame of reference of an observer. Scientists have tested this theory through experimentation - proving, for example, that an atomic clock ticks more slowly when traveling at a high speed than it does when it is not moving. The essence of Einstein's paper was that both space and time are relative (rather than absolute), which was said to hold true in a special case, the absence of a gravitational field. Relativity was a stunning concept at the time; scientists all over the world debated the veracity of Einstein's famous equation, E=mc2, which implied that matter and energy were equivalent and, more specifically, that a single particle of matter could be converted into a huge quantity of energy. However, since the special theory of relativity only held true in the absence of a gravitational field, Einstein strove for 11 more years to work gravity into his equations and discover how relativity might work generally as well.

According to the theory of general relativity, matter causes space to curve. It is posited that gravitation is not a force, as understood by Newtonian physics, but a curved field (an area of space under the influence of a force) in the space-time continuum that is actually created by the presence of mass. According to Einstein, that theory could be tested by measuring the deflection of starlight traveling near the sun; he correctly asserted that light deflection would be twice that expected by Newton's laws. This theory also explained why the light from stars in a strong gravitational field was closer to the red end of the spectrum than those in a weaker one.