The latest in all things related to cyber security and privacy for individuals, homes, families and small groups.
Thursday, February 27, 2014
Wednesday, February 5, 2014
My CTO Was Hacked!
You see a lot of interesting things when you are in the business of internet security and privacy. The neat thing for me is that we are at such a momentous time in the evolution of mankind's relationship with technology that almost every day feels a bit like history. Some days it's obvious, like the Target breach. Or, earlier last year, when the Snowden story broke. Other times it is anecdotal, and more personally observed. It's the latter I want to talk about today.
At one point early in the process of building a commercially viable ecosystem for online security and privacy for my customers, I needed some help with network architecture. I was introduced to an exceptionally experienced engineer from Orlando, FL, referred to here, for the sake of this story, as Mr. Nethead. Long story done short; I decided to hire him for a temporary assignment with me in order to help take my project to the next level. In going with my better judgement, I'm going to leave Mr. Nethead's real name out. You will understand why later in my story.
Back to the basics for a minute; clearly cyber-risk has been democratized. The internet is probably, at the out-most, 6 months away from being considered entirely infected. The details of 110 million individuals from the Target breach are just a piece of the big-data pie that includes many, many other large breaches. In an environment like this, you have to take the responsibility to immune yourself and not rely on the government or any other 3rd hand to protect you and those around you. Total Digital Security exists to empower all of us with the best tools available today to insulate ourselves, our homes and families, offices and small businesses, from the escalating probabilities and deepening consequences of being victimized by cyber-crime.
So, the "best tools available today"? Where do the best defenses for online security and privacy come from? The answer; at the enterprise, or institutional level. These entities are governments, corporations, and other institutions that have invested vast sums of money over the past few decades in a very intense effort to protect themselves from precisely the same things that you worry about today; the safety and security of your identification, your passwords and credentials, your "content" (such as pictures, videos, scans, and documents). Also, their employees, (think; your family or office team), their reputation, and so on. You get the idea. And, as technology goes, these online security and privacy solutions are more powerful than ever, very easy to use, and now, extremely affordable to almost anyone. But, I needed someone to help me design the infrastructure in which to deliver these institutional tools to my consumer-level market, which operates outside of a server environment. Really it was almost that simple.
With this concept in mind, we set off to figure out how to put the pieces in place. We had to make it enormously scalable, very efficient, and I wanted it open-source in order to deliver the best architecture from a security stand-point. At the same time, I wanted my customers to know they were completely in control with total portability and assured compatibility. So, while I wanted fresh thinking with the business, I wanted to use established technology that had served and proven itself to the business customer for a long time.
It's not hard to imagine Mr. Nethead. He started back when no one knew how to spell LAN. He grew up in the environment and standards of the time, and though while experienced and knowledgeable, he wasn't exactly an "out-of-the-box" thinker. Also, he had that imperial attitude of impatience and disdain for anyone that wasn't following everything just the way he saw it. Like, we just didn't "get it". On one hand it was aggravating but on the other hand it was reinforcing. Much of my 35 years in personal and professional experience with IT-land wasn't too far off this mark. The experience with Mr. Nethead was kind of validating to the reason for Total Digital Security's existence.
Well, some weeks in to the project it was clear he was not really buying in to what we were doing and frankly I was never even sure that he ever "got it". It was clear to me that Mr. Nethead didn't think the general public was smart enough to spend $10 or $20 bucks a month on online security and privacy services. That they didn't understand or appreciate the real risks at hand, to them and their family, and wouldn't be able to distinguish what we were doing as opposed to say, the retail versions of some of this stuff, like McAfee, Symantec, and the others. It left me wondering what he did for himself and his home. I knew he had young daughters, loved his family and valued his time with them so, I guessed he probably had some techie version of firewall security and maybe a home local area network, running some industrial-strength software that he found someplace, file sharing with his network-geek friends. Right?
After a couple of months on the project, one Saturday night, the Nethead family was enjoying the weekend when one of the daughters' computer was hacked. Unfortunately, it was of the creepiest version of cyber-crime; spyware. Spyware is when an outsider, the hacker, takes control of the computer and uses the audio and visual inputs, your webcam for example, to spy on you. It happened, in one case, to Miss Teen USA. Last year, a hacker that has also attacked at least two dozen other women in the US, Ireland and elsewhere, posted naked photos on the internet and blackmailed them by demanding more pictures. Sadly, this type of cyber-crime, again the creepiest of all and obviously linked to one's physical security as well, is not all that uncommon. The Nethead girls were enjoying themselves that Saturday night, jumping up and down on their bed, and unknowingly being filmed in the process.
Fortunately this story ends with no major consequences, other than a complete re-set in Mr. Nethead's notion of "risk management" and "value". And so fast-forwarding my thought process here; is there a better risk/reward, or economic decision you can make in 2014 for the sake of you, your family, and your business? With these types of stakes at hand, and the increasing probabilities of being victimized increasing daily, at prices that are $10 to $20 bucks a month? And in my mind, protecting one's self is not like buying just insurance alone, but also akin to battening down the hatches for the coming storm. In the case of insurance, the risk is unpredictable, like a flood. With a storm, you see it on the horizon, it's on the radar, and you take precautionary measures. With cyber-crime, it's time to do both.
It is almost assured that if you are a user of technology in your daily life, you will either be proactive or reactive to the emerging threats. But, one way or the other, you will have to change your approach to online security and privacy. We all want to continue to leverage the awesome power of technology in our busy and productive lives, but we must do it responsibly and we must claim control now. 2014 is the pivotal year to shore up your digital footprint and create systems that will insure a sustainable state of online security and privacy for you, your home, family and business.
Thanks for reading,
Brad
brad@totaldigitalsecurity.com
www.totaldigitalsecurity.com
At one point early in the process of building a commercially viable ecosystem for online security and privacy for my customers, I needed some help with network architecture. I was introduced to an exceptionally experienced engineer from Orlando, FL, referred to here, for the sake of this story, as Mr. Nethead. Long story done short; I decided to hire him for a temporary assignment with me in order to help take my project to the next level. In going with my better judgement, I'm going to leave Mr. Nethead's real name out. You will understand why later in my story.
Back to the basics for a minute; clearly cyber-risk has been democratized. The internet is probably, at the out-most, 6 months away from being considered entirely infected. The details of 110 million individuals from the Target breach are just a piece of the big-data pie that includes many, many other large breaches. In an environment like this, you have to take the responsibility to immune yourself and not rely on the government or any other 3rd hand to protect you and those around you. Total Digital Security exists to empower all of us with the best tools available today to insulate ourselves, our homes and families, offices and small businesses, from the escalating probabilities and deepening consequences of being victimized by cyber-crime.
So, the "best tools available today"? Where do the best defenses for online security and privacy come from? The answer; at the enterprise, or institutional level. These entities are governments, corporations, and other institutions that have invested vast sums of money over the past few decades in a very intense effort to protect themselves from precisely the same things that you worry about today; the safety and security of your identification, your passwords and credentials, your "content" (such as pictures, videos, scans, and documents). Also, their employees, (think; your family or office team), their reputation, and so on. You get the idea. And, as technology goes, these online security and privacy solutions are more powerful than ever, very easy to use, and now, extremely affordable to almost anyone. But, I needed someone to help me design the infrastructure in which to deliver these institutional tools to my consumer-level market, which operates outside of a server environment. Really it was almost that simple.
With this concept in mind, we set off to figure out how to put the pieces in place. We had to make it enormously scalable, very efficient, and I wanted it open-source in order to deliver the best architecture from a security stand-point. At the same time, I wanted my customers to know they were completely in control with total portability and assured compatibility. So, while I wanted fresh thinking with the business, I wanted to use established technology that had served and proven itself to the business customer for a long time.
It's not hard to imagine Mr. Nethead. He started back when no one knew how to spell LAN. He grew up in the environment and standards of the time, and though while experienced and knowledgeable, he wasn't exactly an "out-of-the-box" thinker. Also, he had that imperial attitude of impatience and disdain for anyone that wasn't following everything just the way he saw it. Like, we just didn't "get it". On one hand it was aggravating but on the other hand it was reinforcing. Much of my 35 years in personal and professional experience with IT-land wasn't too far off this mark. The experience with Mr. Nethead was kind of validating to the reason for Total Digital Security's existence.
Well, some weeks in to the project it was clear he was not really buying in to what we were doing and frankly I was never even sure that he ever "got it". It was clear to me that Mr. Nethead didn't think the general public was smart enough to spend $10 or $20 bucks a month on online security and privacy services. That they didn't understand or appreciate the real risks at hand, to them and their family, and wouldn't be able to distinguish what we were doing as opposed to say, the retail versions of some of this stuff, like McAfee, Symantec, and the others. It left me wondering what he did for himself and his home. I knew he had young daughters, loved his family and valued his time with them so, I guessed he probably had some techie version of firewall security and maybe a home local area network, running some industrial-strength software that he found someplace, file sharing with his network-geek friends. Right?
After a couple of months on the project, one Saturday night, the Nethead family was enjoying the weekend when one of the daughters' computer was hacked. Unfortunately, it was of the creepiest version of cyber-crime; spyware. Spyware is when an outsider, the hacker, takes control of the computer and uses the audio and visual inputs, your webcam for example, to spy on you. It happened, in one case, to Miss Teen USA. Last year, a hacker that has also attacked at least two dozen other women in the US, Ireland and elsewhere, posted naked photos on the internet and blackmailed them by demanding more pictures. Sadly, this type of cyber-crime, again the creepiest of all and obviously linked to one's physical security as well, is not all that uncommon. The Nethead girls were enjoying themselves that Saturday night, jumping up and down on their bed, and unknowingly being filmed in the process.
Fortunately this story ends with no major consequences, other than a complete re-set in Mr. Nethead's notion of "risk management" and "value". And so fast-forwarding my thought process here; is there a better risk/reward, or economic decision you can make in 2014 for the sake of you, your family, and your business? With these types of stakes at hand, and the increasing probabilities of being victimized increasing daily, at prices that are $10 to $20 bucks a month? And in my mind, protecting one's self is not like buying just insurance alone, but also akin to battening down the hatches for the coming storm. In the case of insurance, the risk is unpredictable, like a flood. With a storm, you see it on the horizon, it's on the radar, and you take precautionary measures. With cyber-crime, it's time to do both.
It is almost assured that if you are a user of technology in your daily life, you will either be proactive or reactive to the emerging threats. But, one way or the other, you will have to change your approach to online security and privacy. We all want to continue to leverage the awesome power of technology in our busy and productive lives, but we must do it responsibly and we must claim control now. 2014 is the pivotal year to shore up your digital footprint and create systems that will insure a sustainable state of online security and privacy for you, your home, family and business.
Thanks for reading,
Brad
brad@totaldigitalsecurity.com
www.totaldigitalsecurity.com
Thursday, January 23, 2014
This is the Last Email Account I Will Ever Need.
Governments, Corporations, Criminals & Creeps
I did it. I bit the bullet, and it hurts. I've decided to change my personal email address, again, and the transition is just what I expected; a pain in the arse. But, I'm motivated. As a father, friend, businessman and simply a human engaged in life, I am no longer willing to let my email be scanned, sniffed, snooped and shared by governments, corporations, criminals and creeps, relentlessly, all day and everyday. I'm opting out of the madness, and I'm taking my family and my business with me.As security guru Bruce Schneier says, the metadata that rides along with your email today includes enough information about you to be classified as surveillance. To allow my personal information to leak, day in and day out, to some of society's most unseemly characters, is just not acceptable to me anymore. I know too well how inevitably deep the consequences are, and I see the increasing rate of connectivity between digital security and physical security. This is meaningful, I am a head-of-household and seriously accountable on several levels, and I have found a far, far better way to operate as consumers in the digital age.
Wikipedia on Metadata
@schneierblog Metadata = Surveillance
So, I'm creating a digital domain, including our email accounts, that will protect and share our data, for as long as we like, generations for that matter, without undue influence, theft or loss. I will determine how it operates and what it shares, or doesn't, where it is physically located and how it is inherited. I don't trust "free", I don't trust the "system", and I value these digital assets more than ever. Actually, much of it I consider as irreplaceable, including 20,000 family photos, videos, scans, notes and what is the family's eternal scrapbook. Plus, it is ridiculously inexpensive to do this and as a professional risk manager for over 25 years, the risk/reward equation at this price is simply a no-brainer. Online security and privacy is now a serious consideration in everything I do, personally and professionally.
Why location of digital assets is important; Local law trumps everything, including technology and terms of service.
My trusty, old personal email@mac.com account of the last 13 years did it's job very well. I know I feel better about the experience than many others that are on Yahoo, AOL, and some of the other "free" email services. But the game has changed, and it's time to think very differently about this now crucial aspect of our lives. The business of running an email service, especially the ones most popular in the U.S., have morphed, or been perverted, into business models that have little to do with your experience as a customer. Well, that's because you are not the customer. The buyer of your information is the customer, and you are their product. Guess who gets the short stick?
"If you aren't paying for the product, you are the product." George Greve +Georg Greve
Then, to add insult to injury, your information is used back on you in very clever ways in order to manipulate you to buy something or perhaps even better yet, give them more information about you! Then, I suppose, the business can perpetuate itself in an endless cycle of economic bliss. When you think about it, isn't that the business model that creates sub-25 year old billionaires today? And now, the NSA is exacerbating the problem by essentially gifting their tools and techniques to the worst characters in our global society. We are, literally at this moment, past the point of no return and, as Marc Cuban says so well, "I'm out".
Building My Own Digital Domain
Now, I have a domain for my family and business registered in Switzerland. We have our own private email service, there are no limitations or restrictions, and we have rid ourselves of IP address tracking, metadata scanning, content stealing and the host of abuses that are standard procedure, literally billions of times a day. I'm operating on open-source software crafted for security, portability and long-term compatibility. I can synch across all my devices, I have webmail access and I use it's open-source groupware that is as hardy as Exchange or any of the other hairball email client solutions that are out there today (though I do like Thunderbird).We have a Digital Family Vault, also based in Zurich and in a separate secure data storage facility away from our email servers. The facility is built by the people that built the same thing for almost every bank in the country. Switzerland that is. I can set access, restriction, and contribution levels across silos of data and my passwords have a named beneficiary. Digital assets are now represented as a slice in a family's wealth pie and being in control of it's operation and security, feels extremely satisfying right now.I created a permanent solution, one that will endure through my fully engaged and tech-levered life. My investment in digital security and privacy today, at this juncture of enormous change in our digital lives, will pay in ways we cannot even fathom yet. And, when you find out how absurdly inexpensive it is to do this, you will want to do precisely the same thing I did, and you can.
Ok so now this is where the shoe pinches; it is not a seamless, brainless, painless process. But, honestly, it's manageable. Better than manageable really. The tools are better, and I'm better organized and prepared than I have been in my past email migrations. Don't get me wrong, I'm not done with the process, but I'm letting myself take the time I need to do this fully, completely and hopefully with as little disruption to me and the others that invariably have to adjust their records and such. The journey to total online security and privacy is never really over, there is not an end-point other than managing effective and adaptable defenses. But this approach to creating a family digital domain covers some of the most important and fundamental bases in the process, and in an enduring and scalable way.
In fact, I'm so pleased with the results and the value, I've created a business that will do the same thing for you, and we can provide online security and privacy solutions like these at rates as low as $10/mo. You can contact me personally of you would like to know more, at my Swiss email address:
brad@tdsw.ch
Some liken the use of online security software and services to buying insurance. It is, but for this particular moment in history, it's different. There is mega-storm on the horizon. Making sure your insurance policies are current, is not enough. It is time to batten down the hatches at home and work and to expect to emerge from the storm only stronger. The exponentially advancing clock of technology marches forward, and cyber-risk has now been fully democratized all the way to the capillaries of the Internet, where you and I reside. Email me and begin your journey to total online security and privacy, today, and subscribe to peace of mind.
Brad
brad@tdsw.ch
Saturday, January 11, 2014
Top 3 Personal Online Security & Privacy Threats for 2014
Top 3 Online Security Threats for Individuals, Families and Small Businesses in 2014
#1) Super-scale Ransomware Attacks in the U.S. -
Ransomware is the evolution of extortion. It is the hijacking of your digital life. The successor to last year's enormously successful CryptoLocker virus is being developed as we speak and it will wreak havoc on millions of unsuspecting email users in 2014. If there is one word to know in cyber-risk for 2104, it is ransomware. Refer to The Democratization of Cyber-Risk in 2104 for more, including a screenshot of the CryptoLocker virus.#2) Mobile Malware Infections go Viral-
98% of mobile viruses are aimed at Android devices. If you are on an Android you will either prepare for, or recover from, a virus sometime in 2014. Apple devices are still safer but not as immune as they once were. Apple aficionados need to raise the awareness level more than just another notch in order to be informed and protected for the new era of cyber-risk.#3) Social Media is Used as a Source of Information for Criminals -
Obviously, using social media does nothing to help protect your privacy but in 2014 sophisticated criminals will use FaceBook, LinkedIn and other channels to perpetrate their crimes. They gather passwords, user-names and other sensitive information that will ultimately be used against you in an online attack of some sort or another. Hackers do what the NSA does; they collect enormous amounts of data, as well as information about that data (metadata), and they sort and sift it using big-data software technology. They are relentless, but patient, and when the hackers have enough pieces of information to crack the code on you and a few million other unsuspecting internet users, they go to work with massive campaigns of extortion, fraud, deceit and digital terror. Unfortunately, in the past, the best outcomes are for those that simply pay the ransom, typically affordable when you need to make a serious problem go away, fast.2014 is a crucial year for individual users of the internet. The democratization of cyber-risk has suddenly created a massive new target for cyber-criminals and that target includes you, your family and home, and small business. You are viewed as the most vulnerable, unprepared and unsophisticated of their targets and if they can line up enough of you to be extorted into handing over a few bucks, they can quickly walk away economically satisfied potentially for many years to come.
From here on there are 2 types of users on the internet; Those that prepare and those that recover. It is in fact "when" and not "if" it will happen to you. Accept this, take some action, and avoid what could be a trans-formative event in your life in 2014.
Thanks for reading and let me know if we can help with any of your online security and privacy needs.
Brad
Total Digital Security for you, your family, home and small business. Protect that which is irreplaceable with plans that start at just $9.95/mo. www.totaldigitalsecurity.com
Private, offshore email accounts.
![]() |
| The Last Email Account You Will Ever Need |
Thursday, January 2, 2014
The 4 Components of Complete Online Security & Privacy for 2014
2014 is sure to be a watershed year for individuals and small business when it comes to internet security and privacy. The entire internet is now infected, and the most vulnerable of those online are the ones square in the bullseye of the worst form of cyber-criminals.
This post is meant to be a guide to help think through the process of immunizing yourself and those around you from the rapidly increasing risks associated with the use of our everyday technology. 2014 may be the last year in which you, your family and your small business, have the opportunity to circle-the-wagons and position yourself to be in control of your digital assets and effectively protect from the risks associated with online activities.
1) Secure Your Computers, Smartphones & Tablets
This includes desktops, laptops, mobile phones and all “end-user” devices.2) Protect Yourself When on the Internet
Usually at least 2 or 3 stages including home and public wi-fi’s, local internet service provider and the Internet backbone.
3) Own & Control Your Personal Email Account
This includes attachments, the email message content, the IP address and the metadata attached to your email.
4) Backup & Lock-down Your Data Storage
The data on your local hard-drive as well as cloud and
external disks need to be protected and backed-up.
The risks of not being protected are many but include:
•Being
spied on
•Financial
fraud
•Identity
theft
•Physical
harm
•Extortion
•Reputational
risk
•Loss
of the irreplaceable
Now, for some detail around each component to
Complete Online Security and Privacy in 2014:
Component #1 - Secure Your Computers, Smartphones & Tablets
- This includes desktops, laptops, mobile phones and any device that connects to the internet.
- Every one of your devices contains significant information and data that is valuable to you and others.
- You want to control and protect everything that comes in and everything that goes out of your devices.
- Securing your computer, mobile phone and tablet is an essential part of online security and should be a priority in your effort to protect yourself from outside harm and system failures.
Component #2 - Protect Yourself When on the Internet
- Banking, shopping, surfing, browsing, social media and anything you do when on the internet.
- There are usually at least 3 stages to an internet connection, you must protect from each of them.
- Home and public Wi-Fi networks
- Local internet service provider
- Internet backbone
Component #3 - Own & Control Your Personal Email Account
- To be secure, you must protect attachments, the content of the email message itself, the IP address and the metadata attached to your email.
- Most people are unaware at the quantity and level of detail that is available in a typical email as it travels across the internet to it’s destination.
- Metadata is considered, by many, to contain enough information to put you under surveillance by another.
Component #4 - Backup & Lock-down Your Data Storage
- Hard-drives, external disks and cloud–based data storage needs to be protected from theft and backed-up for redundancy.
What You Can do to Get Back in Control of Your Digital Life
• Be
Aware, Take Action – If you are aware and informed you
will realize the best decision you can make for 2014 in terms of value,
risk/reward and long-term results, is to secure yourself and those that matter
to you, from what would otherwise be almost certain harm from online activity.
• Use
the Very Effective Solutions That are Available To You – Today, the
protection that is available at incredibly affordable prices works very well
and effectively mitigates almost all of the risks and probabilities of a
problem. Properly implemented and maintained, these solutions require virtually
no work on your part and does not impact your computers performance.
• Think
of Your Security as a Service, and Not a Product – There is no final destination or a “set-it & forget it” when it comes to any type of security, especially digital security. The rate of change in technology and the evolvement of online threats, coupled with the increasing value to our digital assets, demands constant vigilance and immediate adaptation.
• Protect
From Governments, Companies, Criminals and Creeps- Remember, if you aren’t paying for the product (Gmail, Facebook, Yahoo, AOL, etc.), you are the product. Your information and data is so valuable today that these characters will be endlessly relentless in their quest to steal it from you. Protect yourself and be in control of all your digital assets, much of it is irreplaceable and includes the things you most value.
• Protect All 4 of the Components That Connect Your Digital Life – A chain is only as strong as it’s weakest link. Unfortunately there is not one universal solution for the vast set of risks and problems we address in the use of our technology. The good news is that there is a way to manage these 4 components and it is not expensive or difficult.
• Use
Good Judgment With Passwords – None of us is designed well to remember many passwords, much less complex ones. Unless you are a savant, it’s foolish to think otherwise and risk serious loss. For the moment the only way to deal effectively with our online environment is with a password manager. They are cheap, if not “free”, and are getting easier to use almost every day. Be deliberate in your strategy with passwords as they need to be long, complex, encrypted and backed-up, & synced across all your devices. Finally, should be included in your overall estate plan for smooth and secure inheritance by your beneficiary.
Subscribe to:
Posts (Atom)






