TiGra Networks

Hints, tips, industry insight, news and views and occasional light relief from the Small Business IT Specialists

Recent Posts

Tags

News

  • Microsoft awards TiGra's founder Tim Long with the prestigious Most Valuable Professional award, with a competency of Windows Server System - Small Business Server, for the second year running, making Tim one of only two SBS-MVPs in the UK.

Site Visitors

Locations of visitors to this page

Community

Email Notifications

Small Biz Community

TiGra Networks

Business Partners

Archives

June 2009 - Posts

10 Immutable Laws of Security

Why You Need a Strong Password

MCj04414360000[1] It is worth reminding ourselves occasionally why we need passwords and computer security and what we are protecting ourselves from. I often talk to people in small businesses who hate the idea of having to use passwords and permissions. They consider that their people are trustworthy and that they should have open access. But computer security is not about protecting you from the people you trust. It is just as much about accountability, protecting your trusted people from themselves, and from you, and from the unknown elements outside of the organisation such as malicious software and hackers. Any organisation with a server needs to implement security policies and not always for the obvious reasons. The number one delivery vehicle for malicious software, for example, is email. We all use email and we are all human, we make mistakes, we can be tricked into opening a malicious attachment. The chances are that despite countermeasures, sooner or later some malicious code is going to find its way on to your systems. At that point, everyone in the organisation who has a blank or trivial password will have plenty of reason to regret it. Defending yourself from these situations requires a defence-in-depth approach. The firewall is one layer of defence, your antivirus software is another. Your Windows username and password is your last line of defence. If a bad guy can guess your password, it’s “game over”.

Ten Immutable Laws

Microsoft TechNet has a great article about security: 10 Immutable Laws of Security. In summary:

Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore
Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore
Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore
Law #4: If you allow a bad guy to upload programs to your website, it's not your website any more
Law #5: Weak passwords trump strong security
Law #6: A computer is only as secure as the administrator is trustworthy
Law #7: Encrypted data is only as secure as the decryption key
Law #8: An out of date virus scanner is only marginally better than no virus scanner at all
Law #9: Absolute anonymity isn't practical, in real life or on the Web
Law #10: Technology is not a panacea

Click on any law to link back to a more in-depth description at the Microsoft TechNet site. I’ll bet at least one of those laws is already ringing a few alarm bells in your head.

It always pays to remember that your Windows user name and password protects a lot of valuable and/or sensitive information. When you log in to your computer each day, you are unlocking access to that information. If your network has an internet connection, you could potentially be exposing that information to persons unknown. The Internet is an amazing, powerful resource that has massive benefits for businesses and individuals, but it also has a dark underbelly. The threats can be mitigated when they are understood, but following security best-practices and understanding the Ten Immutable Laws is a key part of that mitigation strategy. There really is no acceptable alternative.

Pesky Passwords

I understand that creating and remembering strong passwords is a chore. It is a necessary evil and the inconvenience can be minimised with some thought. System Administrators often get this very wrong, forcing users to create passwords that are hard to use and remember, which often leads to them being written on a post-it note stuck to the users’ monitor or top drawer (Immutable Law #3). A password that has to be written down is self-defeating. I’ve covered strategies for creating strong passwords elsewhere, essentially there are two techniques:

  1. Use a mnemonic – a password that is complex but memorable.
  2. Use a passphrase – a sentence or phrase in plain text and including spaces and punctuation. Size is everything, each additional word makes the passphrase massively more secure.

Additionally, password pain can be eliminated using a physical security device. Some solutions available today are:

  • Biometric devices, such as fingerprint readers, are now affordable and accurate. They are becoming popular because of their convenience, ease of use and affordability. Many laptops and keyboards are available with fingerprint recognition built-in. The best devices have software that lets you register your Windows login password and passwords for various web sites and services, so that all of your passwords can be protected by a quick scan of one or more fingers.
  • Smart cards rely on a certificate stored in the memory of a credit-card style device. Logging in is as simple as inserting your smart card. Pulling the card out typically locks your workstation.
  • Time-dependent key generators such as RSA SecureID generate passwords that are only valid for a minute or so. Even if a password is discovered, it is useless outside of that time window.
Share this post: | | |
Free Office 2007 Training on Microsoft Business Resource Centre

image Microsoft’s new Business Resource Centre provides personalised help, support, training, articles and tips customised specifically for you and the products you have. I particularly like some of the Office 2007 videos particulary the advanced version showing SharePoint integration.

Share this post: | | |
Windows 7 RTM set for July

Windows 7 splash Microsoft will deliver Release to Manufacturing (RTM) code to partners in the second half of July. Windows 7 will become generally available on Oct. 22, 2009, and Windows Server 2008 R2 will be broadly available at the same time.

Windows Server 2008 R2 was previously known as Windows 7 Server. More details at the UK SBSC Blog.

Share this post: | | |
Free Windows 7 Desktop Theme - Yellowstone
Yellowstone National Park
Yellowstone National Park

This Windows 7 desktop theme features the magical landscape of Yellowstone National Park, centred on Wyoming, USA. The park also extends into Montana to the north and Idaho to the west.

The whole area is a boiling cauldron of geothermal activity, having more geysers and geothermal features than the rest of the world put together. The terrible geological history and probable future of the area make it a fascinating yet foreboding place to visit.

 

In celebration of the release candidate of Windows 7, TiGra Networks is pleased to provide you with this free desktop theme.  The word on the grapevine is that Windows 7 will RTM (release to manufacturing) as early as July, with availability on the shop shelves as early as September. Our trials with Windows 7 have been very positive and we’ll be updating our range of Office-ready desktops with 64-bit versions of Windows 7 as soon as possible.

All photos are Copyright © 2001 Timothy P. Long, please do not redistribute.

Share this post: | | |