Tuesday, July 19, 2016
Wi-Fi (In)Security
One of the fastest growing trends over the last decade had been the availability of wireless internet. From homes and businesses to coffee shops and restaurants Wi-Fi has significantly changed the way we work and play. We have the ability to interact with the virtual world from pretty much anywhere, and that access is on the rise, with new networks and mobile hotspots popping up everywhere. However, the convenience of free Wi-Fi comes with some very real threats – from viruses to identity theft.
Wi-Fi is a type of wireless local area network (WLAN) technology that allows laptop or smartphone users to exchange data or connect to the internet using radio waves. The core technology behind Wi-Fi is a hardware device called an access point, which connects the wired network and broadcasts the radio waves to extend the network wirelessly.
All of the transmissions sent and received on a Wi-Fi network are encrypted using one of 3 different protocols (WEP, WPA, WPA2) to attempt to protect the data from theft. If your device uses WEP replace it immediately, it is outdated and insecure. A hacker can break through WEP in about 10-15 minutes of being within range of the network. WPA2 is the newest and most popular, and generally considered to be the most secure. There are more considerations that go into protecting your own network, and even some steps you can take to make your Wi-Fi network more secure, but what about public Wi-Fi? What risks do you face, and how can you know if you are safe?
Public access points, called “hotspots” allow many people within a certain area to “tune in” to the specific radio waves used my that network to access the internet. An example of this is going to Starbucks and connecting to the “Starbucks Wi-Fi” while you are there.
One of the biggest risks of public Wi-Fi like Starbucks is called Network Sniffing. If a hacker has gotten access to the wireless network they can use a “sniffing” application to intercept and sort through all visible traffic on the network. Anything you would do online could potentially be watched by someone else.
Even without the presence of active hackers, your privacy is never guaranteed when you access a public hotspot. One of the biggest breaches of privacy is often perpetrated by the organization or business offering the free Wi-Fi. Often, when joining a public network you will be asked to leave an email address, phone number, or even like a page on social media. In addition they can use signal strength to track where you are in the store, and what types of websites you visit. Next thing you know, you are getting advertisements targeted to you based on your browsing history and location data. These may be less malicious that some threats, but can certainly be intrusive.
One of the most dangerous threats you can face with public Wi-Fi is a spoofed or rogue access point. A savvy hacker could hook up their own access point next to a legitimate one and name it something similar, luring unsuspecting individuals to connect to it in error. Once you have connected to a malicious hotspot they can use it to install malware on your system, or track your activity to steal passwords or bank information. For example, if you try to go to facebook.com they may redirect you to a spoofed “look-alike” site they put together that will steal your password and any other information you give them. Before you even know if you could be well on your way to becoming a victim of identity theft.
Although you always run a certain amount of risk when using public Wi-Fi there are certain measures you can take to protect against attackers. Here are the most common precautions:
1. Always confirm the legitimacy of a Wi-Fi network before connecting to it; do not reply on the name alone. If there are multiple access points showing up for the same venue, ask a staff member which one to use. Also, be sure to read that venue’s Terms of Service carefully to ensure that your privacy will not be breached.
2. Ideally, you should only use public Wi-Fi to browse websites that do not require login credentials (e.g., news websites, Wikipedia, etc.). However, if you do need to access sensitive data or enter login credentials, only go to websites that start with HTTPS ( a more secure version of the HTTP web protocol).
3. Never install software while using public Wi-Fi, it can often introduce viruses or malware into your computer. For example, a common attack is to inform a user of an outdated service like Adobe Flash and take them to a spoofed website to download the “update”
4. A good way to ensure good security while accessing public Wi-Fi is to use a VPN. A VPN essentially creates a secure tunnel between your device and a third party server. All data that passes through the tunnel is encrypted, and therefore protected from prying eyes like the Wi-Fi provider or anyone trying to “sniff” the network.
It is easy to take free Wi-Fi access for granted. Unfortunately, as public hotspots become more prevalent, so will hackers. Your best protection against data theft is an understanding of Wi-Fi and its vulnerabilities, and taking a few precautions.
If you want to look further into some of the different ways you can protect yourself, or how you can further protect your wireless network from breaches, please give us a call. We would be more than happy to review your current setup and make recommendations for any changes needed.
Wednesday, October 14, 2015
How Do You Know When Enough is Enough?
Running a business can be full of challenges. One of the biggest challenges to face is knowing when to cut your losses and move on when something isn’t carrying it’s weight. Whether it is a workstation, server, or service; we have all faced that hard decision in one way or another.
An easy trap to fall into is to live by the old adage “If it ain’t broke, don’t fix it”. All too easily it becomes “If it kinda works, don’t fix it”, and there is a BIG difference between something that “ain’t broke” and something that works the way it should. One method to evaluate if it is time to move on is to measure how much time you are losing each day to inefficiencies and problems. For example, if you are operating under a slower internet speed, you are probably spending time waiting on pages to load or content to refresh. Even if everything else runs perfectly this still adds up to an average of 10 minutes or more every day of wasted time. That may not seem like a lot, but over the course of a single year that adds up to more than a 40-hour workweek of wasted time.
Another trap that a lot of businesses fall prey to is to sign up for internet service and the “set it and forget it”, paying the bill each month and renewing each year without reviewing their account to make sure they are paying for what they need and what they are getting. Technology moves so fast nowadays that before you know it, you are still paying for the same internet speed you had 5 years ago, and paying WAY more than need for what you are getting.
So, how do you know when enough is enough? There are two types of checks that should be performed regularly to make sure that you are able to run your business efficiently and “get the most bang for your buck”. The first check is a network analysis to examine the current health and status of everything on your network to make sure that everything is running as smoothly as it should. This allows you to prepare for and make changes as they are needed; it is always better to be proactive than reactive!
The second check is to have someone perform a telecom audit of your internet and phone service to make sure that you are not paying for things you don’t need, not paying too much for what you are getting, and not paying for service that is inappropriate to your needs.
If you are interested in taking a deeper look at your network and telecom service please let us know. We can work with you to analyze your current situation and put together a personalized plan of any recommended action steps based on the findings. We have recently had a number of clients interested in upgrading their internet service; dropping older, slower, less reliable service for super-fast fiber internet - available at deep discounts in many areas through the end of the year.
Tuesday, September 15, 2015
Why Backup? The Importance of Protecting Your Data
One of the keys to running a successful business is to set goals and have strategic steps in place to get you there. We all set goals - whether at the CEO level, or the ground level, we all have something we are working towards. However, we live in an uncertain world. What would you do if disaster struck and derailed you from your course? What would your employees do if you lost all of your files, or if your customer information was corrupted or missing? One of the most important things you can do to protect your business is to have a plan in place before something happens to help you recover your data and get back to work quickly.
The scary truth about data loss is that if you don't have a plan in place in advance, there is a less than 10% chance that you will be able to recover from a major data loss. That is 90% of businesses closing their doors within two years of a disaster!
The good news is that the ugly aftermath of a disaster can mostly be avoided by having a plan in place in advance. You may never be the victim of a hurricane or tornado, but data loss comes in many forms. Hardware failure, computer viruses, and human error can be just as destructive as natural disasters, and often are harder to predict.
You don't have to recreate the wheel and come up with a contingency plan to backup your data and to recover from a disaster on your own. We are happy to work with you to come up with a plan that fits the needs of your business and leverages available technology to help you be as prepared as possible. Give us a call if you want to discuss what that plan looks like for you.
If you would like to get some more information on backup and recovery solutions we invite you to join us on September 15th for our Lunch and Learn "Why Backup? The Importance of Protecting your Data". Contact us for more info or to RSVP.
Wednesday, August 12, 2015
Windows 10 is Here!
Windows 10 has arrived, and brought with it a number of changes. Microsoft added many new features to their newest OS, but they removed a few "old favorites" too. Here are some of the biggest new features of Windows 10, as well as the things we will miss the most.
One of the most welcome changes in Windows 10 is the return of the Start menu. Microsoft has designed a new start menu bringing back the familiarity and ease of use of Windows 7 with the information and customization allowed by the live tiles of Windows 8.
Cortana, the digital Windows Phone Assistant will be making an appearance on your computer, allowing you to easily and quickly search your PC, set reminders, check the weather, and much more. Cortana even learns more about you over time, becoming more intuitive and providing more useful information based on your needs and preferences.
Ever feel like you spend half of your time switching between different windows and apps trying to find the information you want? Windows 10 is introducing the ability to have multiple virtual desktops, so you can easily organize what information you see and when. This is especially useful if you are working on different projects at the same time and want to keep the information grouped together so nothing gets mixed up.
Microsoft is introducing a new browser called Edge that is designed to help move you from browsing to doing. With the ability to take notes on webpages, read articles without distractions, and save your articles and notes for review later; Microsoft Edge is bringing some great new tools to help you be more productive. One thing to mention is that even though Windows 10 includes Microsoft Edge, Internet Explorer is still going to be around to support older applications and programs.
Those are a few of our favorite new features, but what is going away?
One of the biggest changes in Windows 10 is the removal of Windows Media Center. Got a DVD movie you want to watch on your PC? You will need to either use a 3rd party media player or purchase Microsoft's DVD player app from the Windows Store.
Some older programs and equipment may not be compatible with the new OS. Before deciding to upgrade to Windows 10 it is recommended to make sure that all of your software programs and business applications will be compatible with the new OS. We have already seen users that have upgraded to Windows 10 that need assistance in reloading Windows 7 or 8 because their software did not function as expected, or because there were not drivers for some of their equipment. You don't want to run into a situation where you cannot work until you reload your PC.
There are many more changes and considerations that may weigh in on your decision regarding if and when to upgrade. Contact us if you would like assistance in evaluating your setup and determining the best plan of action for your business.
Tuesday, July 28, 2015
Telecom Audit
Just about every week I encounter someone with concerns over how much they are spending each month on their internet or phone service. It seems that rates just keep going up and up, and then you have to remember those “Other Charges and Fees”.
Some of those charges and fees are completely legitimate, but with all of the lawsuits and stories floating around regarding subscribers paying for services they don’t want or need, I wouldn’t blindly trust what is listed on the bill. We have worked with a lot of businesses recently to perform what is called a Telecom Audit – reviewing the current bill for Internet, phone, TV, to make sure that the business is getting what they are paying for, and not paying for things they are not receiving or do not want.
Performing a Telecom Audit can be very useful in a couple of different ways. It can help you strip any “junk fees” or any unwanted services or charges from your bill to reduce your “monthly recurring cost”. This one easy step can help you feel like you are throwing less money away every month!
The other benefit of a Telecom audit is that it can help you recognize when you are overpaying for the service you are receiving. We have worked with a number of clients to evaluate what services are available from different providers and can often assist them in securing better services for much less than they have been paying. In fact, we recently helped one customer save over 60% of their monthly internet and phone service bills by switching them to a more reasonably priced competitor. That is hundreds of dollars every month that your business does not have to spend!
One of the biggest dangers a company can face is to sign up for services and “set it and forget it” never following up to make sure the billing stays accurate. It is all too easy for expenses to get out of control while you are focused on other aspects of your business. Let us help you with that. You should be able to run your business without worrying about “junk fees” or excessive charges costing you money. Contact us today for more information about Telecom Audits and what we can do to help!
Friday, May 29, 2015
Emerging Threats
It seems that every time you turn on the news you are hearing about a new data breach. From Social Security Numbers to credit card numbers, important data is out there and somebody wants it. The information security landscape can look bleak at times, with many U.S. companies experiencing an average of 1,400 security attacks weekly.
Cyber-attacks were once mainly the concern of governments and large corporations, but the amount of sensitive information out there has put small and medium sized business in just as much danger of a serious breach. The potential financial reward associated with the theft of credit card info or other sensitive info has given rise to a new breed of malware called Advanced Persistent Threats or APTs.
Imagine someone breaking into your home or business and stealing everything, but instead of leaving afterwards they hide and wait for you to replace everything and then rob you again. That is how APTs work – they are designed to get access to your system through a security flaw such as a zero day vulnerability and then steal your data or damage your network, and then morph and hide so it can remain undetected and attack you again and again.
The good news is that there are ways to protect yourself and your network from a security breach. From forming a plan to implementing layered security measures there are steps you can take and we can assist with this process. Call us today to assess your current setup and get your sensitive information locked-down.
Wednesday, August 10, 2011
Hope to see you tomorrow!
On behalf of Computer St. Louis you have been chosen to receive a complimentary VIP pass to the...
**2011 St. Louis Tech-Security Conference**
Place: Doubletree Hotel & Conference Center
16625 Swingley Ridge Road
Chesterfield, MO. 63017
Date: Thursday, August 11th, 2011
8:15am-4:00pm
Click on the following link to register for your free VIP pass:
http://www.dataconnectors.com/events/2011/08StLouis/inv_sp.asp
VIP passes include Lunch and conference materials.
Gift Cards, iPods, software and many other give-aways!
Featuring 8 Tech-Security speakers and 30 exhibits!!
For full conference agenda click on:
http://www.dataconnectors.com/events/2011/08StLouis/agenda.asp
Or call Dawn Morrissey at 636-778-9495 for more information.
www.DataConnectors.com
**2011 St. Louis Tech-Security Conference**
Place: Doubletree Hotel & Conference Center
16625 Swingley Ridge Road
Chesterfield, MO. 63017
Date: Thursday, August 11th, 2011
8:15am-4:00pm
Click on the following link to register for your free VIP pass:
http://www.dataconnectors.com/events/2011/08StLouis/inv_sp.asp
VIP passes include Lunch and conference materials.
Gift Cards, iPods, software and many other give-aways!
Featuring 8 Tech-Security speakers and 30 exhibits!!
For full conference agenda click on:
http://www.dataconnectors.com/events/2011/08StLouis/agenda.asp
Or call Dawn Morrissey at 636-778-9495 for more information.
www.DataConnectors.com
Monday, June 20, 2011
Windows 7 � Should You Upgrade?
Windows 7 – Should You Upgrade?
Windows 7 has good benefits but it’s hard for some small businesses to determine if it’s worth the investment of upgrading to this new version. Here is a simple guide for small businesses to consider.
Who should consider upgrading to Windows 7:
Who shouldn’t upgrade to Windows 7:
Contact one of our support specialists at Computer St. Louis to discuss Windows 7 and your upgrade today.
Windows 7 has good benefits but it’s hard for some small businesses to determine if it’s worth the investment of upgrading to this new version. Here is a simple guide for small businesses to consider.
Who should consider upgrading to Windows 7:
- Those running Vista. If you happen to be using Vista, you should definitely go ahead and upgrade to Windows 7. Microsoft provides a fairly simple upgrade path to do so, and Windows 7 fixes the problems that Vista still has.
- Those running XP on new machines. If you’re running Windows XP on a new machine, it most likely has the horsepower to run Windows 7 just fine. While you don’t need to upgrade – Windows XP is still a very effective operating system – you can upgrade if you believe that Windows 7 has enough benefits to justify the expense. That being said, the expense will be considerable, as upgrading from Windows XP requires a complete “wipe” of your existing operating system, which means that you or someone else will have to spend hours on the process.
Who shouldn’t upgrade to Windows 7:
- Those running XP on an older machine. If you are running a machine that is a couple of years old or older, you shouldn’t bother with the expense of upgrading to Windows 7 on this computer. It most likely will not handle the upgrade well, and the money would be better spent on a new computer that will come pre-loaded with Windows 7.
- Those running older and/or custom applications that have not been thoroughly tested for Windows 7. Some applications will not run on Windows 7, or will at least experience some significant performance problems. Don’t upgrade until you can determine that all of your applications have tested fine on Windows 7.
- Those looking for major feature enhancements. There aren’t really any major feature enhancements in Windows 7 that are “must haves”. The operating system is cooler, faster, and more stable and secure - but those are all things you may not really even notice depending on how your current system is performing. Don’t expect to be knocked over by all of the amazing new productivity you get from Windows 7, because you probably won’t be.
- Those that are particularly budget conscious. Windows 7 is not cheap, particularly if you are upgrading from Windows XP.
Contact one of our support specialists at Computer St. Louis to discuss Windows 7 and your upgrade today.
Thursday, May 19, 2011
5 Tips for Top-notch Password Security
by Kim Komando
used with permission from the Microsoft Small Business website
Whether it's a few PCs or hundreds on your network, there's one thing that can separate your system from being compromised: a great password.
Why? Hackers want access to anything and everything. If they can guess your user name and password, you might as well have given them your wallet and the keys to your building.
Before we talk about what makes a good password, let's begin with the first of five things to know and practice in using passwords.
1. Don't be complacent: Attacks can and do happen.
Hackers are a devious bunch and will stop at nothing to get into your network and files. They use three different methods to get to you: brute force, dictionary attacks, and social engineering.
Brute force is the most time-consuming method. Basically, it involves a program that tries every combination of letters, numbers, and keyboard characters to guess your password. It starts with trying every character, then tries two-character combinations, and so on.
The longer the password is, the exponentially more difficult it becomes to crack. According to George Shaffer, a password expert, a password that is eight characters in length and utilizes lower- and upper-case letters, numbers, and keyboard characters won't be cracked for two years. This underscores the importance of being as random as possible when choosing your password. (More tips from Shaffer on creating passwords are available at www.geodsoft.com/howto/password ).
Another method of attack is through the use of custom dictionaries. These dictionaries are filled with words and names, but also number and letter combinations, such as 11111 and abc123. Simple passwords such as "duke" or "ilovemydog" can easily be guessed.
The third and most effective method of attack is social engineering. This involves someone with criminal intent soliciting a password directly from a user. Many people divulge their passwords to co-workers and strangers without even realizing it.
For example, most small businesses don't have a dedicated information-technology staff. A hacker posing as someone from your company's Internet service provider could call in and get an unsuspecting employee's password by "testing the service." The hacker might request the employee's user name and password to log in and test the connection from the ISP's end. If the hacker sounds authoritative and legitimate enough, your whole network could be compromised.
If your business rents space in a larger facility, strangers probably roam the hallways unnoticed. A few innocent questions or a watchful eye can be disastrous.
2. Know what makes for a bad password.
Because the attacks described above are becoming increasingly more common, you don't want to use anything in your password that's personal and easy to guess. Keep in mind the following don'ts:
•Don't use only letters or only numbers.
•Don't use names of spouses, children, girlfriends/boyfriends or pets.
•Don't use phone numbers, Social Security numbers or birthdates.
•Don't use the same word as your log-in, or any variation of it.
•Don't use any word that can be found in the dictionary — even foreign words.
•Don't use passwords with double letters or numbers.
Some of the worst passwords are: password, drowssap, admin, 123456, and the name of your company or department. Finally, never leave it blank. That's a surefire way to let the bad guys into your system.
3. Get proficient at creating good passwords.
A good password is one that is easy to remember but difficult to guess. That sounds like a paradox, but it's really not.
There are a couple of different ways to create difficult-to-crack passwords. One is substituting letters with characters and numbers. To make it easier on yourself, try to use numbers and characters that resemble the letters they are replacing.
For example, you would never want to use the word "password" as your password. If you change it to p@7sw0rd!, you've got something that would take some time to crack but is fairly simple to remember.
Another method is to use the first letters of the words in a favorite line of poetry or a verse of song. "Hail, hail the lucky ones, I refer to those in love" becomes "H,hTL0,IR2t1L."
The best passwords are at least eight characters in length and use a combination of numbers, keyboard characters and upper- and lower-case letters. The longer your password is, the longer it will take someone (or more likely, some program) to crack it.
4. By all means, safeguard your password.
At first, it may be difficult to remember your password. Did you substitute an "i" with a "1" or did you use a "1" to represent "L?" Most people will want to write the password on a piece of paper and place it underneath their keyboard or mouse pad. Or worse, they'll stick the password right on their monitor.
To help remember the password, use it immediately. Then log in and out several times the first day. Just don't change it on a Friday or right before leaving for vacation. You could write it out several times on a piece of paper. This helps record it in your mind. Just be sure to shred the paper when done.
Invariably, there may come a time when a password has to be shared. Let's say an employee is out of town to give a presentation but left the PowerPoint file on his desktop. You will have to get his user name and password to access that file. After you open the file, change the password and give him the new password upon his return. Then, as soon as the person gets back into the office, have him change the password again. Yes, it's a lot of work but well worth it.
5. Change your password often—as in several times a year.
Your network administrator can force your employees to change their password every so often. Microsoft recommends having users change their passwords every 30 to 90 days, but encourages you to go with the smaller number. I think 30 days is a reasonable number here. You always want to side with caution when it comes to sensitive information.
If you're like me, you allow your employees to do light surfing at lunch and on breaks. Encourage your employees to change their passwords to personal Web sites as well—such as to banking, Internet e-mail accounts, shopping sites, and so on. Advise them not to use the same password for all of their sites. A particularly good hacker can cause personal financial ruin by gaining access to one username and password.
Juggling all of these passwords is not easy. You might want to consider a program that can do all of this for you. Account Logon (www.accountlogon.com) and Roboform (www.roboform.com) are two well-reviewed password management programs; both offer free versions.
Now the following is an eerie thought — but it's something that must be taken into consideration.
What if you or your network administrator dies?
Well, if you've used best practices when creating a password, nobody else knows your password. And it's so complex that it could take months to crack the code or money to buy the right software for the job. Just in case, you might consider keeping a copy of all passwords in the company's safe. As for your personal passwords, keep them stowed away somewhere along with your will.
used with permission from the Microsoft Small Business website
Why? Hackers want access to anything and everything. If they can guess your user name and password, you might as well have given them your wallet and the keys to your building.
Before we talk about what makes a good password, let's begin with the first of five things to know and practice in using passwords.
1. Don't be complacent: Attacks can and do happen.
Hackers are a devious bunch and will stop at nothing to get into your network and files. They use three different methods to get to you: brute force, dictionary attacks, and social engineering.
Brute force is the most time-consuming method. Basically, it involves a program that tries every combination of letters, numbers, and keyboard characters to guess your password. It starts with trying every character, then tries two-character combinations, and so on.
The longer the password is, the exponentially more difficult it becomes to crack. According to George Shaffer, a password expert, a password that is eight characters in length and utilizes lower- and upper-case letters, numbers, and keyboard characters won't be cracked for two years. This underscores the importance of being as random as possible when choosing your password. (More tips from Shaffer on creating passwords are available at www.geodsoft.com/howto/password ).
Another method of attack is through the use of custom dictionaries. These dictionaries are filled with words and names, but also number and letter combinations, such as 11111 and abc123. Simple passwords such as "duke" or "ilovemydog" can easily be guessed.
The third and most effective method of attack is social engineering. This involves someone with criminal intent soliciting a password directly from a user. Many people divulge their passwords to co-workers and strangers without even realizing it.
For example, most small businesses don't have a dedicated information-technology staff. A hacker posing as someone from your company's Internet service provider could call in and get an unsuspecting employee's password by "testing the service." The hacker might request the employee's user name and password to log in and test the connection from the ISP's end. If the hacker sounds authoritative and legitimate enough, your whole network could be compromised.
If your business rents space in a larger facility, strangers probably roam the hallways unnoticed. A few innocent questions or a watchful eye can be disastrous.
2. Know what makes for a bad password.
Because the attacks described above are becoming increasingly more common, you don't want to use anything in your password that's personal and easy to guess. Keep in mind the following don'ts:
•Don't use only letters or only numbers.
•Don't use names of spouses, children, girlfriends/boyfriends or pets.
•Don't use phone numbers, Social Security numbers or birthdates.
•Don't use the same word as your log-in, or any variation of it.
•Don't use any word that can be found in the dictionary — even foreign words.
•Don't use passwords with double letters or numbers.
Some of the worst passwords are: password, drowssap, admin, 123456, and the name of your company or department. Finally, never leave it blank. That's a surefire way to let the bad guys into your system.
3. Get proficient at creating good passwords.
A good password is one that is easy to remember but difficult to guess. That sounds like a paradox, but it's really not.
There are a couple of different ways to create difficult-to-crack passwords. One is substituting letters with characters and numbers. To make it easier on yourself, try to use numbers and characters that resemble the letters they are replacing.
For example, you would never want to use the word "password" as your password. If you change it to p@7sw0rd!, you've got something that would take some time to crack but is fairly simple to remember.
Another method is to use the first letters of the words in a favorite line of poetry or a verse of song. "Hail, hail the lucky ones, I refer to those in love" becomes "H,hTL0,IR2t1L."
The best passwords are at least eight characters in length and use a combination of numbers, keyboard characters and upper- and lower-case letters. The longer your password is, the longer it will take someone (or more likely, some program) to crack it.
4. By all means, safeguard your password.
At first, it may be difficult to remember your password. Did you substitute an "i" with a "1" or did you use a "1" to represent "L?" Most people will want to write the password on a piece of paper and place it underneath their keyboard or mouse pad. Or worse, they'll stick the password right on their monitor.
To help remember the password, use it immediately. Then log in and out several times the first day. Just don't change it on a Friday or right before leaving for vacation. You could write it out several times on a piece of paper. This helps record it in your mind. Just be sure to shred the paper when done.
Invariably, there may come a time when a password has to be shared. Let's say an employee is out of town to give a presentation but left the PowerPoint file on his desktop. You will have to get his user name and password to access that file. After you open the file, change the password and give him the new password upon his return. Then, as soon as the person gets back into the office, have him change the password again. Yes, it's a lot of work but well worth it.
5. Change your password often—as in several times a year.
Your network administrator can force your employees to change their password every so often. Microsoft recommends having users change their passwords every 30 to 90 days, but encourages you to go with the smaller number. I think 30 days is a reasonable number here. You always want to side with caution when it comes to sensitive information.
If you're like me, you allow your employees to do light surfing at lunch and on breaks. Encourage your employees to change their passwords to personal Web sites as well—such as to banking, Internet e-mail accounts, shopping sites, and so on. Advise them not to use the same password for all of their sites. A particularly good hacker can cause personal financial ruin by gaining access to one username and password.
Juggling all of these passwords is not easy. You might want to consider a program that can do all of this for you. Account Logon (www.accountlogon.com) and Roboform (www.roboform.com) are two well-reviewed password management programs; both offer free versions.
Now the following is an eerie thought — but it's something that must be taken into consideration.
What if you or your network administrator dies?
Well, if you've used best practices when creating a password, nobody else knows your password. And it's so complex that it could take months to crack the code or money to buy the right software for the job. Just in case, you might consider keeping a copy of all passwords in the company's safe. As for your personal passwords, keep them stowed away somewhere along with your will.
Friday, November 19, 2010
Thursday, October 7, 2010
10 Emails You Should Never Send
used with permission from the HP Small Business Center
used with permission from the HP Small Business Center
Here’s a scenario most of us are familiar with, whether first-hand or as a witness to a colleague’s faux pas: an email with a crude joke or a funny picture that crosses into the personal-email realm is sent to a cluster of friendly internal contacts and accidentally included on the recipients’ list is the company CEO. Embarrassing for the sender? Yes. Grounds for dismissal? Unlikely.
What can prove far more detrimental to your career, however, is the way you compose your everyday emails. We often treat email communication in the same casual manner as we do informal telephone conversations, and it’s all too easy to forget that there’s a flawless digital record of what’s been communicated.
Unlike verbal conversations, emails can be forwarded to the wrong people. Likewise, if a message is written in a hurry, it can end up sloppy or leave itself open to misinterpretation and, as a result, it can have nasty repercussions. It’s always better to think before you send.
Convenient email enabled devices such as the Palm® smartphone and HP notebook also allow you to send emails from anywhere these days too, but it’s important to train yourself to send in “work mode”. Next time you reach for your smartphone, remember that you’re representing yourself and your company, no matter where you are.
10 email mistakes that could cost your job:
- Emails sent after happy hour
Company happy hour after work? It’s probably best to save the Palm responses for the next day and not to respond to emails from home after a night out.
- Sarcasm and dry humor
Email is not a good medium to convey the intricacies of sarcasm, and often it can be taken out of context — with disastrous repercussions.
- Private matters
Always better to separate business and pleasure — and using company resources for personal matters is generally a bad idea.
- Professional criticisms
If it’s a small thing, say it over the phone; otherwise it looks too official and can cause unnecessary worry. If it’s really bad, discuss it in person.
- Personal remarks and gossip
It’s very easy to treat email like water cooler conversation, but these emails can have a tendency to get ‘Forwarded’.
- Angry responses
It’s easy to fire off an angry response without thinking, but not always easy to retract it. Best to put a delay on your email if possible, or wait a day before you respond if you’re really that upset.
- Bad language
Most people just don’t do it, but for the few who do — it’s a terrible idea; swearing has no place in work emails.
- Company or industry secrets
This one may well get you sued as well as sacked. Most companies have a confidentiality agreement you sign at the beginning of your employment that would be violated in this case.
- Racist/sexist language
It’s best to avoid this in your everyday speech, as well as your work emails. Like the above, most people sign a zero-tolerance agreement which would be violated and such violations are grounds for termination.
- Sloppy writing
Even if it’s sent from your Palm while you’re at the beach, remember that your image is on the line.
Last but not least, if you work in government or other offices of interest to the general public, be extra cautious. Very abundant in the news are email leaks that get government and other official people in serious trouble.
Subscribe to:
Posts (Atom)