Tuesday, September 6, 2016

Tabula Rosa Systems Technical Term (9-6-16) - Bug Bounty Program



 








Bug Bounty Program
A bug bounty program, also called a vulnerability rewards program (VRP), is a crowdsourcing initiative that rewards individuals for discovering and reporting software bugs. Bug bounty programs are often initiated to supplement internal code audits and penetration tests as part of an organization's vulnerability management strategy.


Many software vendors and websites run bug bounty programs, paying out cash rewards to software security researchers and white hat hackers who report software vulnerabilities that have the potential to be exploited. Bug reports must document enough information for for the organization offering the bounty to be able to reproduce the vulnerability. Typically, payment amounts are commensurate with the size of the organization, the difficulty in hacking the system and how much impact on users a bug might have.

Mozilla paid out a $3,000 flat rate bounty for bugs that fit its criteria, while Facebook has given out as much as $20,000 for a single bug report. Google paid Chrome operating system bug reporters a combined $700,000 in 2012 and Microsoft paid UK researcher James Forshaw $100,000 for an attack vulnerability in Windows 8.1. In 2016, Apple announced rewards that max out at $200,000 for a flaw in the iOS secure boot firmware components and up to $50,000 for execution of arbitrary code with kernel privileges or unauthorized iCloud access.

While the use of ethical hackers to find bugs can be very effective, such programs can also be controversial. To limit potential risk, some organizations are offering closed bug bounty programs that require an invitation. Apple, for example, has limited bug bounty participation to few dozen researchers.
================================
    Another Special Announcement - Tune in to my radio interview,  on Rider University's station, www.1077thebronc.com I discuss my recent book, above on "Your Career Is Calling", hosted by Wanda Ellett.   
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” has just been published and will be followed by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:
 www.amazon.com/author/paulbabicki

In addition to this blog, I maintain a radio show on BlogtalkRadio  and an online newsletter via paper.li.I have established Netiquette discussion groups with Linkedin and  Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and I have been contributing to the blogs Everything Email and emailmonday . My work has appeared in numerous publications and I have presented to groups such as The Breakfast Club of NJ and  PSG of Mercer County, NJ.


I am the president of Tabula Rosa Systems, a “best of breed” reseller of products for communications, email, network management software, security products and professional services.  Also, I am the president of Netiquette IQ. We are currently developing an email IQ rating system, Netiquette IQ, which promotes the fundamentals outlined in my book.

Over the past twenty-five years, I have enjoyed a dynamic and successful career and have attained an extensive background in IT and electronic communications by selling and marketing within the information technology marketplace.Anyone who would like to review the book and have it posted on my blog or website, please contact me paul@netiquetteiq.com.
=============================================================

Tabula Rosa Systems Security Bulletin - SB16-249: Vulnerability Summary for the Week of August 29, 2016



 








National Cyber Awareness System:

09/05/2016 06:12 AM EDT

Original release date: September 05, 2016 | Last revised: September 06, 2016
The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.
The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:
·         High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0
·         Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9
·         Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9
Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis=================================
    Another Special Announcement - Tune in to my radio interview,  on Rider University's station, www.1077thebronc.com I discuss my recent book, above on "Your Career Is Calling", hosted by Wanda Ellett.   
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” has just been published and will be followed by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:
 www.amazon.com/author/paulbabicki

In addition to this blog, I maintain a radio show on BlogtalkRadio  and an online newsletter via paper.li.I have established Netiquette discussion groups with Linkedin and  Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and I have been contributing to the blogs Everything Email and emailmonday . My work has appeared in numerous publications and I have presented to groups such as The Breakfast Club of NJ and  PSG of Mercer County, NJ.


I am the president of Tabula Rosa Systems, a “best of breed” reseller of products for communications, email, network management software, security products and professional services.  Also, I am the president of Netiquette IQ. We are currently developing an email IQ rating system, Netiquette IQ, which promotes the fundamentals outlined in my book.

Over the past twenty-five years, I have enjoyed a dynamic and successful career and have attained an extensive background in IT and electronic communications by selling and marketing within the information technology marketplace.Anyone who would like to review the book and have it posted on my blog or website, please contact me paul@netiquetteiq.com.
=============================================================

Monday, September 5, 2016

Tabula Rosa Systems Blog Of 9/5/2016 - Definition Of Kerberos



 







Kerberos
Posted by: Margaret Rouse
Contributor(s): Michael Cobb
Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet. Kerberos is built in to all major operating systems, including Microsoft Windows, Apple OS X, FreeBSD and Linux.
Take a closer look at the ISACA Certified Information Security Manager certification, including the value it provides security professionals, how it compares to other security professionals, and what the CSX program offers
Since Windows 2000, Microsoft has incorporated the Kerberos protocol as the default authentication method in Windows, and it is an integral component of the Windows Active Directory service. Broadband service providers also use Kerberos to authenticate DOCSIS cable modems and set-top boxes accessing their networks.
Kerberos was originally developed for Project Athena at the Massachusetts Institute of Technology (MIT). The name Kerberos was taken from Greek mythology; Kerberos (Cerberus) was a three-headed dog who guarded the gates of Hades. The three heads of the Kerberos protocol represent a client, a server and a Key Distribution Center (KDC), which acts as Kerberos' trusted third-party authentication service.
Users, machines and services using Kerberos need only trust the KDC, which runs as a single process and provides two services: an authentication service and a ticket granting service. KDC "tickets" provide mutual authentication, allowing nodes to prove their identity to one another in a secure manner. Kerberos authentication uses conventional shared secret cryptography to prevent packets traveling across the network from being read or changed and to protect messages from eavesdropping and replay attacks.
A simplified description of how Kerberos works follows; the actual process is more complicated and may vary from one implementation to another. For the purposes of this discussion, the initiating client in the scenario below is a corporate laptop running Windows, and an end user is trying to log into the corporate network.
To start the Kerberos authentication process, the initiating client sends a request to an authentication server for access to a service. The initial request is sent as plaintext because no sensitive information is included in the request.
The authentication server retrieves the initiating client's private key, assuming the initiating client's username is in the KDC database. If the initiating client's username cannot be found in the KDC database, the client cannot be authenticated and the authentication process stops. If the client's username can be found in the KDC database, the authentication server generates a session key and a ticket granting ticket. The ticket granting ticket is timestamped and encrypted by the authentication server with the initiating client's password.
The initiating client is then prompted for a password; if what is entered matches the password in the KDC database, the encrypted ticket granting ticket sent from the authentication server is decrypted and used to request a credential from the ticket granting server for the desired service. The client sends the ticket granting ticket to the ticket granting server, which may be physically running on the same hardware as the authentication server, but performing a different role.
The ticket granting service carries out an authentication check similar to that performed by the authentication server, but this time sends credentials and a ticket to access the requested service. This transmission is encrypted with a session key specific to the user and service being accessed. This proof of identity can be used to access the requested "kerberized" service, which, once having validated the original request, will confirm its identity to the requesting system.
The time stamped ticket sent by the ticket granting service allows the requesting system to access the service using a single ticket for a specific time period without having to be re-authenticated. Making the ticket valid for a limited time period makes it less likely that someone else will be able to use it later; it is also possible to set the maximum lifetime to 0, in which case service tickets will not expire. Microsoft recommends a maximum lifetime of 600 minutes for service tickets; this is the default value in Windows Server implementations of Kerberos.
The MIT Kerberos Consortium was founded in September 2007 to further the development of Kerberos. In 2013, the consortium was expanded and renamed the MIT Kerberos and Internet Trust Consortium.
==================================
   Another Special Announcement - Tune in to my radio interview,  on Rider University's station, www.1077thebronc.com I discuss my recent book, above on "Your Career Is Calling", hosted by Wanda Ellett.   
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” has just been published and will be followed by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:
 www.amazon.com/author/paulbabicki

In addition to this blog, I maintain a radio show on BlogtalkRadio  and an online newsletter via paper.li.I have established Netiquette discussion groups with Linkedin and  Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and I have been contributing to the blogs Everything Email and emailmonday . My work has appeared in numerous publications and I have presented to groups such as The Breakfast Club of NJ and  PSG of Mercer County, NJ.


I am the president of Tabula Rosa Systems, a “best of breed” reseller of products for communications, email, network management software, security products and professional services.  Also, I am the president of Netiquette IQ. We are currently developing an email IQ rating system, Netiquette IQ, which promotes the fundamentals outlined in my book.

Over the past twenty-five years, I have enjoyed a dynamic and successful career and have attained an extensive background in IT and electronic communications by selling and marketing within the information technology marketplace.Anyone who would like to review the book and have it posted on my blog or website, please contact me paul@netiquetteiq.com.
=============================================================

Sunday, September 4, 2016

Tabula Rosa Systems Blog Of 94/2016 - Don’t Take Notes with a Laptop



 







A Learning Secret: Don’t Take Notes with a Laptop www.scientificamerica.com
By Cindi May on June 3, 2014
Students who used longhand remembered more and had a deeper understanding of the material
The old fashioned way works better. Credit: Credit: Szepy via iStock
“More is better.”  From the number of gigs in a cellular data plan to the horsepower in a pickup truck, this mantra is ubiquitous in American culture.  When it comes to college students, the belief that more is better may underlie their widely-held view that laptops in the classroom enhance their academic performance.  Laptops do in fact allow students to do more, like engage in online activities and demonstrations, collaborate more easily on papers and projects, access information from the internet, and take more notes.  Indeed, because students can type significantly faster than they can write, those who use laptops in the classroom tend to take more notes than those who write out their notes by hand.  Moreover, when students take notes using laptops they tend to take notes verbatim, writing down every last word uttered by their professor.
Obviously it is advantageous to draft more complete notes that precisely capture the course content and allow for a verbatim review of the material at a later date.  Only it isn’t.  New research by Pam Mueller and Daniel Oppenheimer demonstrates that students who write out their notes on paper actually learn more.  Across three experiments, Mueller and Oppenheimer had students take notes in a classroom setting and then tested students on their memory for factual detail, their conceptual understanding of the material, and their ability to synthesize and generalize the information.  Half of the students were instructed to take notes with a laptop, and the other half were instructed to write the notes out by hand.  As in other studies, students who used laptops took more notes.  In each study, however, those who wrote out their notes by hand had a stronger conceptual understanding and were more successful in applying and integrating the material than those who used took notes with their laptops.
What drives this paradoxical finding?  Mueller and Oppenheimer postulate that taking notes by hand requires different types of cognitive processing than taking notes on a laptop, and these different processes have consequences for learning.  Writing by hand is slower and more cumbersome than typing, and students cannot possibly write down every word in a lecture.  Instead, they listen, digest, and summarize so that they can succinctly capture the essence of the information.  Thus, taking notes by hand forces the brain to engage in some heavy “mental lifting,” and these efforts foster comprehension and retention.  By contrast, when typing students can easily produce a written record of the lecture without processing its meaning, as faster typing speeds allow students to transcribe a lecture word for word without devoting much thought to the content.
To evaluate this theory, Mueller and Oppenheimer assessed the content of notes taken by hand versus laptop.  Their studies included hundreds of students from Princeton and UCLA, and the lecture topics ranged from bats, bread, and algorithms to faith, respiration, and economics.  Content analysis of the notes consistently showed that students who used laptops had more verbatim transcription of the lecture material than those who wrote notes by hand.  Moreover, high verbatim note content was associated with lower retention of the lecture material.  It appears that students who use laptops can take notes in a fairly mindless, rote fashion, with little analysis or synthesis by the brain.  This kind of shallow transcription fails to promote a meaningful understanding or application of the information.
If the source of the advantage for longhand notes derives from the conceptual processes they evoke, perhaps instructing laptop users to draft summative rather than verbatim notes will boost performance.  Mueller and Oppenheimer explored this idea by warning laptop note takers against the tendency to transcribe information without thinking, and explicitly instructed them to think about the information and type notes in their own words.  Despite these instructions, students using laptops showed the same level of verbatim content and were no better in synthesizing material than students who received no such warning.  It is possible these direct instructions to improve the quality of laptop notes failed because it is so easy to rely on less demanding, mindless processes when typing.
It’s important to note that most of the studies that have compared note taking by hand versus laptop have used immediate memory tests administered very shortly (typically less than an hour) after the learning session.  In real classroom settings, however, students are often assessed days if not weeks after learning new material.  Thus, although laptop users may not encode as much during the lecture and thus may be disadvantaged on immediate assessments, it seems reasonable to expect that the additional information they record will give them an advantage when reviewing material after a long delay.
Wrong again.  Mueller and Oppenheimer included a study in which participants were asked to take notes by hand or by laptop, and were told they would be tested on the material in a week.  When participants were given an opportunity to study with their notes before the final assessment, once again those who took longhand notes outperformed laptop participants.  Because longhand notes contain students’ own words and handwriting, they may serve as more effective memory cues by recreating the context (e.g., thought processes, emotions, conclusions) as well as content (e.g., individual facts) from the original learning session.
These findings hold important implications for students who use their laptops to access lecture outlines and notes that have been posted by professors before class.  Because students can use these posted materials to access lecture content with a mere click, there is no need to organize, synthesize or summarize in their own words.  Indeed, students may take very minimal notes or not take notes at all, and may consequently forego the opportunity to engage in the mental work that supports learning.
Beyond altering students’ cognitive processes and thereby reducing learning, laptops pose other threats in the classroom.  In the Mueller and Oppenheimer studies, all laptops were disconnected from the internet, thus eliminating any disruption from email, instant messaging, surfing, or other online distractions.  In most typical college settings, however, internet access is available, and evidence suggests that when college students use laptops, they spend 40% of class time using applications unrelated to coursework, are more likely to fall off task, and are less satisfied with their education.  In one study with law school students, nearly 90% of laptop users engaged in online activities unrelated to coursework for at least five minutes, and roughly 60% were distracted for half the class.
Technology offers innovative tools that are shaping educational experiences for students, often in positive and dynamic ways.  The research by Mueller and Oppenheimer serves as a reminder, however, that even when technology allows us to do more in less time, it does not always foster learning.  Learning involves more than the receipt and the regurgitation of information.  If we want students to synthesize material, draw inferences, see new connections, evaluate evidence, and apply concepts in novel situations, we need to encourage the deep, effortful cognitive processes that underlie these abilities.  When it comes to taking notes, students need fewer gigs, more brain power.
==================================
   Another Special Announcement - Tune in to my radio interview,  on Rider University's station, www.1077thebronc.com I discuss my recent book, above on "Your Career Is Calling", hosted by Wanda Ellett.   
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” has just been published and will be followed by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:
 www.amazon.com/author/paulbabicki

In addition to this blog, I maintain a radio show on BlogtalkRadio  and an online newsletter via paper.li.I have established Netiquette discussion groups with Linkedin and  Yahoo.  I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and I have been contributing to the blogs Everything Email and emailmonday . My work has appeared in numerous publications and I have presented to groups such as The Breakfast Club of NJ and  PSG of Mercer County, NJ.


I am the president of Tabula Rosa Systems, a “best of breed” reseller of products for communications, email, network management software, security products and professional services.  Also, I am the president of Netiquette IQ. We are currently developing an email IQ rating system, Netiquette IQ, which promotes the fundamentals outlined in my book.

Over the past twenty-five years, I have enjoyed a dynamic and successful career and have attained an extensive background in IT and electronic communications by selling and marketing within the information technology marketplace.Anyone who would like to review the book and have it posted on my blog or website, please contact me paul@netiquetteiq.com.
=============================================================