Monday, January 23, 2012

Password management - Bane or a boon


Password are the most crucial form of privacy in the Internet (and basically on all computer technologies). Its importance is similar to our own brain. It is what separates us to the rest of the world. It is our "key" to the privacy. That is why there are lots of password management (i.e. changing passwords, unlinking passwords, renewing password based on reset policies), password encryption (i.e. , password requirements and password retrieval measures enacted on most Internet applications. The problem is that passwords are so crucial that it is usually a big problem specially on people who have problems remembering or suffering from selective memorization (i.e. fails to completely give time to memorize the pattern or password they made). In this episode I would give the ideas on how important passwords are, how to make a formidable password, what to avoid making the common failures in password generation (or creation) and how to secure passwords. I hope that I could light up some "bulbs" in you so you could immediately make your way into lesser passwords management (and lesser concern on privacy or personal security) and focus more on productive works.

Why Passwords are important?

Passwords add extra layer of security to your accounts. It gives your both personalization and privacy when you use password. Due to the personalization nature (or uniqueness), passwords are the best forms of security you could provide to yourself. Since it is intangible, no form, and kept on the safest part of the world (yes, your brain is the safest part of the world), it gives yourself FULL CONTROL to it. Your privacy and personal security is most protected when you have full control and that is achievable through passwords. Real life analogy dictates that passwords are like keys to your bank vaults. As long as the passwords are safe, so whatever you are protecting or keeping.

How to make a formidable password?

A formidable password should have some form of disguise. It makes it hide its form and use and can only be used by the one who owns it (or authorized to use it). In computing technology, the advisable passwords should be:

  1.  Composed of mixed upper case and lower case alphanumeric and special characters with password lengths greater than eight (8).
  2. Does not relate to ANY of your personal records like birthdays/anniversaries, cellphone number, land line number, credit card number or even bank account numbers, or car registration number)
  3. Easily remembered but not easily known to others (i.e. somewhat in a coding scheme which will be discussed further)
  4. Has no copy written anywhere that is purely unsafe or not under your full control (i.e. notepads, unencryted documents, shared drives in your companies, and even on your mobile computers and phones)

I learned a scheme in memory enhancement programs about how to do this. It is called Linking methodology where one takes a portion of some very known thing to you then you chain it to the resource you are accessing PLUS a certain breakthough character. This is a powerful mechanism that will help you memorize different passwords without even writing them down anywhere.

Example:

I am using Yahoo! Email. My very known item is a computer mouse (or simply a mouse). Since the mouse is almost always available when you are using your computer, it is a good start idea. I'll take "M" (capital "M") from the mouse while I imagine one (1) hundred mice running across biting Yahoo!'s smiley face icon. When the mice are finished, the smiley face is dropped on the floor with a huge bubble on its head saying "#" (which is usually used as emoticon for anger). Now linking (or chaining) a portion of the information, I could create a possible formidable password to my Yahoo! Email without giving me headaches on remembering it. You can modify the system as it suits you and gives you a little bit easier approach to it (like instead of taking the first letter, you take the last letter of Yahoo)

Capital "M" + "100" + "Y" + # + "email"  =  M100Y#email

The resultant of the little exercise is a formidable password. It is a mixture of uppercase and lower case alphanumeric characters and special characters. It has a password length greater than 8. It is not related to any of your personal information. Since the linking of these things exists only in your mind, it cannot be copied (unless it is phished from you while you are entering it which we will discuss on other episodes). And lastly, you do not need to write it down as you have a formidable system wrapping your password scheme.

All in all, passwords that are wrapped in a system or methodology known only to you gives you all the freedom to create a lot of passwords from different application without injuring yourself on remembering them. Passwords that are safe and in your full control will give you the promise it serves, and that is to provide security to your personality and privacy.

Sunday, January 22, 2012

Software suites - Antivirus VS Internet Security Suites


Now, we will dwell a little bit about your personal computing. I wouldn't say much about Mobile computing  (yet) for this episode as I see that the topic on antivirus and Internet security suites does not suit mobile computing as the necessity is not just as rampant on desktop computing. But be aware though as this must not put complacency on us. Constant vigilance (reminds me of a known best seller novel said in one of its volume) is still necessary.

As we go forward in our endeavor on our Internet computing, days are gone by when intrusions on our productivity has been purely on offline attacks. The "enemy" has evolved into a more sinister form and so should our defenses. Early Internet days are plagued with so much insecure channels that caused millions of dollars of collateral damages (both from stolen credit card accounts to unrecoverable data/information) . Those were the days of the viruses. Viruses evolved from productivity stealing to data stealing. They propagate on network channels. The heroes back then were the antivirus programs. Antivirus programs tracks the computers from malicious programs (a.k.a. virus executables) from their activities. Antivirus evolved to several other features that hinders release of the known (and unknown) viruses such as heuristic scanning (best described as a feature of antivirus programs that track dormant or active programs that does "fishy" things to your computer)

When the rise of Internet usage, programs such as firewall, anti-malware, anti phishing and other forms of programs that specifically blocks all known (and unknown) forms of intrusion and destruction programs. I would like to emphasize on the "unknown" which I said earlier twice that these programs are not really unknown in form. We can only say a program to be "known" if it has a definite signature (i.e. program signature) and has been given a name. Basically, those are the programs that carries signatures like the "known" forms but has not yet been given a name (i.e. identified formally).  Defensive programs for our computing environment now becomes instead of one single program (i.e. antivirus programs), it becomes multiple programs. Those programs as a whole are called Internet Security suites.  There are several known developers/publishers of these Internet Security suites throughout the Internet (such as Norton, McAfee, Kaspersky, AVG, Avira). The choice resides on the users and unlike before, high tier antivirus suites fight intrusions and viruses/malicious softwares (a.k.a. malwares), and worms similarly. Their usability and feasibility lies on the forms of how far your security protection requirements. These Internet security suites are really pricey and it should be assessed back to you on how much you "want" to shell out versus acceptable exposures (a.k.a. how much protection you want against the known and "unknown" programs).

In the end, knowing which one your need and your budget is an important aspect to consider specially if you just need to avail Antivirus only or the full Internet Security suites. An important aspect is that full Internet Security suites combines Antivirus with other programs as well to give you a better online protection.

For additional readings, you can check out the following links


Difference Between Antivirus and Internet Security

Internet security

Antivirus Software vs. Internet Security Suites

Friday, January 20, 2012

Your Portal to the Internet


Our technology already worked wonders nowadays. Devices (or gadgets) that were for the "special ones" becomes utilities for the commoners. These things are not anymore special. They are just similar to a scissor the leather worker uses or a frying pan a cook uses. I am referring to the electronic equipments or devices such as computers, tablets, smartphones, and other mobile Internet devices. Anything that connects you to the Internet is considered as your "doorstep", "portal", or "entry" to the world wide web.

It all starts in your knowledge of the gadgets your got. Since the "utilities" I mentioned are personal to you, it is wise and decisive to know what those got and what they are doing.  Using computers, smartphones and other mobile Internet devices should be similar on how you manages your other assets (or liabilities) likes cars, houses, etc. In your car (if you have car), you are expected to know the insides and outs of it like where does the transmission located, where is the key slot, or even where is the engine. These tiny little things are specific moves for you to know, identify and ultimately, personalize the car.  Similarly, gadgets should be treated this way. You must know it inside and out, from hardware to the software inside it. If we practice these simple run through of the device, you could personalize it to suit your needs and know what it does and how it could benefit you. A mobile internet device or a computer would be a tool for your productivity OR a device that could wreck havoc to your privacy.

Have a happy Internet hour.

Thursday, January 19, 2012

You and your Internet


We are on the era of world wide networks. Our lives are intertwined not just with our families, neighbors and even acquaintances. We live in an era of connectivity and convergence. Everything that are not related becomes now connected. Before, Internet is for technology geeks (a special privilege or a mere fascination). Now, it has infiltrated our personalities so far that we are not anymore anonymous or just us. It has become far and wide that everything becomes anything.  Our existence becomes universal.

I, myself, is an invocator of privacy. I believe that even if we are so "open" does not meant we cannot become "close".  We might have built houses that do not have fences or have houses that are locked with walls. Even in the necessity of openness (for collaboration with others or through convergence of communication facilities) , privacy is still something personal and important.

First things first, is to be open minded. No, I do not meant this related to being "closed" as per privacy. I meant that one should be open minded in realizing this one universal statement that I think holds true, "there is nothing impossible". Knowing that there is nothing such as impossibility, it let us harness awareness further than locking ourselves in the idea that one thing or activity might exist. It gives us the tendency to look beyond the borders, seeking reality and become whole.

In the series of blogs I am about to write pertains about Internet security, privacy and raising awareness about these. I believe there are lots of materials already in the Internet about these but to each is to own. I hope that more than being technically inclined, I would help instill awareness, actions and progression to a healthy Internet, as we are dubbed now as "Netizens" or people of the Internet.