Showing posts with label PC. Show all posts
Showing posts with label PC. Show all posts

Tuesday, April 22, 2008

Are you ready for emerging threats?

Are you ready for the next wave of cyber attacks? My guess is probably not. How could you if you don't know what's coming?

You see, I have a really bad feeling about the next couple of years, at least as far as the technology field. We will continue to see cyber threats making huge leaps and bounds as malware writers continue to become well funded, organized operations. In the "old" frontier days of spyware, you pretty much only got the really nasty spyware/malware if you went somewhere on the web that you probably shouldn't have in the first place. That's already changing, as we see malware writers are now beginning to target ANY website that they can crack into and place their malware distribution software on. That means that even the knitting blog that your grandmother visits isn't safe anymore. And your uncle's website where he sells fishing lures is now a target, since his website was built three years ago with an e-commerce package that now resembles swiss cheese to a determined malicious hacker. These newer malware packages are also getting smarter about avoiding detection.

I'm not even to the good part yet. Unfortunately Microsoft Windows Vista has been a big flop and proven that it's not really ready for prime time mass adoption. It's unfortunate because it would be a welcome scenario if a larger installed base of users had a more secure operating system and more secure browser. The new Windows Service pack 3 for XP will do some good as far as security goes, but without User Account Control, it still isn't as secure as Vista.

A recent high profile "pwn to own" contest showed us that operating systems are more hardened and less vulnerable than ever before. None of the base operating systems were hacked on the first day. On the second day, hackers were allowed to go after bundled software on the system, such as web browsers. Apple's Safari web browser on the Mac platform was hacked by going to a prepared website where the hacker had prepared an exploit for an unknown vulnerability. The third day the hackers were allowed to go after third party installed software, and the Vista PC was compromised by an exploit with the Adobe Flash player software, a very ubiquitous add on that anyone needs to view most sites on the internet. This showed us that while browsers are still a target, no matter what operating system you are running, common applications running on computers are going to be the next thing that malware writers attack. I know most of you are well trained by now to perform your operating system updates, and web browsers, but are you prepared to keep track of every application that runs on your computer and keep every one up to date? You need to start getting used to doing that now.

So what can the Small Business owner/IT department/Consultant do to prepare yourself for these threats? Enforcing strict user policies and locking down computers so that end users can do the least damage should be high on your list. I know, user will cry and moan, but it must be done. Make no mistake, USERS SHOULD NOT HAVE ADMINISTRATIVE RIGHTS to their local computers. That point is so important, I feel it should be repeated. I repeat, USERS SHOULD NOT HAVE ADMINISTRATIVE RIGHTS to the local computer. More than ever, KEEPING SECURITY SOFTWARE CURRENT is another top priority. Consider ADDING A UTM (Unified Threat Management) device to protect your network, such as the ones made by Astaro. Such a device will allow you to FILTER INTERNET CONTENT, which is a good idea for many reasons, including security.

No matter what steps you take, you can never be 100% secure. But by taking practical steps you can be prepared to face new cyber threats with the confidence that you computer systems are not easy pickings for malware, malicious hackers, or identity thieves.

Monday, July 30, 2007

The Curse of the White Box

Sometimes when picking up a new client, I'll be asked to work on a computer that's having trouble. Well, right now you're saying “that's what you do, isn't it?” Of course, but this computer is not an ordinary computer. Wait, maybe that IS the problem, it's so ordinary that it's a “White Box.” I'm sure you may be scratching your head right now and saying, “what is a white box?”.

The White Box that I am referring to is a computer that is built from available off the shelf parts. It's usually put together by smaller computer builders, often known as “OEMs”. When done right, White Boxes can offer a good value. Many OEMs provide great product and great service, I'm not going to bad mouth all of them. Like any business, there are great companies and there are, well, not so great ones. I am not against OEM computers, but I am against small businesses buying them I think that small businesses are better off buying from larger computer manufacturers such as Dell or HP and here's why:

Warranty: While many OEMs do offer extended warranty, the warranty that's offered through someone like Dell or HP is more dependable. Why? Well, simple economies of scale. When Dell(or HP) puts together a business class system, they engineer for that system to have a certain life cycle. They also keep exchangeable parts on hand for a number of years to support the standard and extended warranties for those systems. With a white box there's no guarantee that you'll be able to find an exact replacement for critical components such as Processors or Motherboards if you're outside the OEM builder's warranty. Longer warranties are also usually more expensive with the white box than with a Dell or an HP system. And here's another REALLY big thing about warranties. A Dell or an HP can offer you next business day onsite warranties. I have yet to see a system builder that offers the same. Even if they can come onsite for service, can you really expect them to be out there the next business day? There's no reason that a business should not expect that any hardware problem with a single computer should not be corrected completely by the next business day, at least under normal circumstances. Now to be fair, all the big guys subcontract all their support out to smaller companies. And you can get some real jokers out to work on your system. But if your IT person or department has done their job to the best that they can in diagnosing what exactly needs replacing, many problems with repair techs can be minimized.

Price: For the most part, base prices are comparable. But because the bigger manufacturers buy in much larger quantities, they usually offer better specials and promotions. Things such as large LCD flat panel monitors bundled with the computer can save you some money. Also, add ons such as MS Office Suite costs you less when bought with a new system from a large manufacturer.

Easy of Support: If your small business has a larger number of desktops(20+), then your IT budget will be easier to swallow if you invest the time having all the same type of desktop. This will ease IT support costs, since all the systems are the same that makes troubleshooting easier. Drive imaging can also be a big help. With all the same model of PC, your IT help can create a disk image that will enable software problems to be quickly fixed by simply re-imaging the computer. This will save hours over the traditional method of reinstalling an Operating System, applications and installing all patches.

Keeping your business running smoothly is top priority. Anytime you or your employees are unable to do their job, money is lost. So getting computers back into a working condition should be a priority. Buy the systems that are going to help you meet that goal, whatever color they may be.