Wednesday, January 19, 2011

The New Wallet: Is it Dumb to Carry a Smartphone?

When I was a teenager, I used to have one of those cool nylon surfer wallets with the Velcro close, you remember those don’t ya?  While pumping diesel (had a VW Rabbit) one day at an old Gulf station, I left the wallet on top of the car and drove off.  Realizing that my wallet was not snug in the sun visor when I got home, I retraced my path and found it - parts of it - scattered all over Route 1.  Luckily, I got most of my belongings back but had that sickened feeling of almost losing my most precious possession at the time, my fake I……um, my driver’s license.  I then got a leather wallet and shoved so many things in there I could have been mistaken for George Costanza, not to mention the hole that evolved right at the bottom point of my back pocket.  Not liking the bump on my butt, I eventually moved to ‘money-clip’ type holders, you know those money holder things you carry in your front pocket.  I felt ‘safer’ knowing it was in my front pocket and I only carried the essentials that I needed, rather than the reams of receipts I’d have in my wallet.  When I was younger, I’d use tie clips, metal binder clips, and other things until I got a nice Harley-Davidson one which holds credit cards and clips currency.  I’d still feel sick if I lost it however.

Not having a wallet, purse, money clip or other currency container at all, may eventually be our new reality.  You see, our smartphones are starting to carry all that digital information for us and according to a recent CNNMoney article, our smartphones are becoming one of our most dangerous possessions.  We can do banking, make payments, transfer money, use the phone for loyalty card swipes along with credit card transactions.  At the same time, mobile users more vulnerable to phishing attacks, some banking apps for Android, iPhone expose sensitive info, Android Trojan Emerges In U.S. Download Sites and how IPv6: Smartphones compromise users' privacy.  We knew it would eventually happen but the crooks are now adapting to the explosive mobile growth, the rise of mobile banking and our never ending connection to the internet.  Don’t get me wrong, like many of you, I love having email, contacts, calendar and entertainment at my fingertips along with the convenience of having all my stuff with me; but the chances of losing much more greatly increase since you have the equivalent, or even more, of all your credit cards, personal and private information and other sensitive stuff right on your smartphone.  Sure there are backup programs but how many of you actually backup your computer on a weekly basis?  How many have wipe or lock software installed to destroy everything on the smartphone if it is stolen?  How many have tracking software if it is lost?  How many have your actual home address in the GPS navigator so the offender can find where you live and visit while you are away?  How many have sensitive corporate information stored on the smartphone since you use it for both personal and business use?  Now I’m starting to spook myself. 

Many people will willingly trade some personal info for personal convenience.  You might never give a total stranger your home address and phone number but if they add, ‘in exchange, we’ll give you this branded card and you’ll get 10% off every purchase,’ more than likely, we’ll turn that personal info over.  If you understand that every purchase will be scanned, sent to a database and used for marketing or as the merchant describes, to ‘provide you with the best service and offerings,’ then you might accept that.  If you accept and understand the risks of doing mobile banking, transferring money, making payments and carrying around your entire life on your mobile device….and take actions to mitigate those risks, like using encryption, backups, wipe/locate software, antivirus, OS updates and other mobile security precautions along with practicing the same discretion as you would with your home computer (like not clicking links from strangers) then you should stay relatively safe.  Unless, of course, you leave that digital wallet on the top of your vehicle and drive off.

ps

Resources

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, banking, trojan, Pete Silva, security, business, education, technology, application delivery, ipad, cloud, context-aware, mobile, iPhone, web, internet, security, android, privacy, smartphone

Wednesday, January 12, 2011

iDo Declare: iPhone with BIG-IP

Who would have imagined back in 1973 when Martin Cooper/Motorola dialed the first portable cellular phone call, that one day we'd be booking airline tickets, paying bills, taking pictures, watching movies, getting directions, emailing and getting work done on a little device the size of a deck of cards.  As these 'cell-phones' have matured, they've also become an integral part of our lives on a daily basis.  No longer are they strictly for emergency situations when you need to get help, now they are attached to our hip with an accompanying ear apparatus as if we've evolved with new bodily appendages.  People have grown accustomed to being 'connected' everywhere. There have been mobile breakthroughs over the years, like having 3G/4G networks and Wi-Fi capability, but arguably one of the most talked about and coveted mobile devices in recent memory is the Apple iPhone.

Ever since the launch of the iPhone in 2007, it has changed the way people perceive and use mobile devices.  It's not just the tech-savvy that love the iPhone, it's Moms, Florists, Celebrities, Retailers and everyone in between that marvel at the useful ways iPhone can be used, and for their very own novel purpose.  There are literally hundreds of thousands of apps available for iPhone, from the silly and mundane to banking and business. Browsing the web is a breeze with the iPhone with the ability to view apps in both portrait and landscape modes.  The ability to zoom and 'pinch' with just your fingers made mobile browsing tolerable, even fun from an iPhone.  Shopping from your cell phone is now as common as ordering a cup of coffee - often at the same time!  iPhone developers are pushing the limits with augmented reality applications where you can point your iPhone into the sky and see the flight number, speed, destination and other such details as planes fly by.

When the iPhone was first introduced and Apple started promoting it as a business capable device, it was missing a few important features.  Many enterprises, and small businesses for that matter, use Microsoft products for their corporate software - Exchange for email, Word for documents, Excel for spreadsheets and PowerPoint for presentations.  Those were, as expected, not available on the iPhone.  As new generations of iPhones hit the market and iOS matured, things like iPhone Exchange ActiveSync became available and users could now configure their email to work with Exchange Server.  Other office apps like Documents-to-Go make it possible for iPhone users to not only to view Microsoft Word and Excel documents, but they were able to create and edit them too.  Today, there are business apps from Salesforce, SAP and Oracle along with business intelligence and HR apps. Companies can even lock down and locate a lost or stolen iPhone.

Business users are increasingly looking to take advantage of Apple iOS devices in the corporate environment, and as such IT organizations are looking for ways to allow access without compromising security, or risking loss of endpoint control.  IT departments who have been slow to accept the iPhone are now looking for a remote access solution to balance the need for mobile access and productivity with the ability to keep corporate resources secure.

The F5 BIG-IP Edge Portal app for iOS devices streamlines secure mobile access to corporate web applications that reside behind BIG-IP Access Policy Manager, BIG-IP Edge Gateway and FirePass SSL VPN.  Using the Edge Portal application, users can access internal web pages and web applications securely, while the new F5 BIG-IP Edge Client app offers complete network access connection to corporate resources from an iOS device; a complete VPN solution for both the iPhone and iPad.

The BIG-IP Edge Portal App allows users to access internal web applications securely and offers the following features:

  • User name/password authentication
  • Client certificate support
  • Saving credentials and sessions
  • SSO capability with BIG-IP APM for various corporate web applications
  • Saving local bookmarks and favorites
  • Accessing bookmarks with keywords
  • Embedded web viewer
  • Display of all file types supported by native Mobile Safari

Assuming an iPhone is a trusted device and/or network access from an iPhone/iPad is allowed, then the BIG-IP Edge Client app offers all the BIG-IP Edge Portal features listed above, plus the ability to create an encrypted, optimized SSL VPN tunnel to the corporate network.  BIG-IP Edge Client offers a complete network access connection to corporate resources from an iOS device.  With full VPN access, iPhone/iPad users can run applications such as RDP, SSH, Citrix, VMware View, VoIP/SIP, and other enterprise applications.  The BIG-IP Edge Client app offers additional features such as Smart Reconnect, which enhances mobility when there are network outages, when users roaming from one network to another (like going from a mobile to Wi-Fi connection), or when a device comes out of hibernate/standby mode. Split tunneling mode is also supported, allowing users to access the Internet and internal resources simultaneously.

BIG-IP Edge Client and Edge Portal work in tandem with BIG-IP Edge Gateway, BIG-IP APM and FirePass SSL VPN solutions to drive managed access to corporate resources and applications, and to centralize application access control for mobile users.  Enabling access to corporate resources is key to user productivity, which is central to F5’s dynamic services model that delivers on-demand IT.

ps

Resources

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, ipad, cloud, context-aware, infrastructure 2.0, iPhone, web, internet, security, hardware, audio, whitepaper, apple, iTunes

Monday, January 10, 2011

Audio Tech Brief - Secure iPhone Access to Corporate Web Applications

The way corporations operate around mobile devices is currently shifting—employees are starting to use their own devices for business purposes, rather than company-owned devices. With no direct control of the endpoints, IT departments have generally had to prohibit this or risk insecure access inside the firewall. But as more mobile devices appear on the corporate network, mobile device management has become a key IT initiative.  This technical brief describes how the BIG-IP Edge Portal app for iOS devices provides simple, streamlined access to web applications that reside behind BIG-IP APM, without requiring full VPN access, to simplify login for users and provide a new layer of control for administrators.  Running Time: 18:54  Read full white paper here.  And click here for more F5 Audio.

ps

Resources:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, ipad, cloud, context-aware, infrastructure 2.0, iPhone, web, internet, security, hardware, audio, whitepaper, apple, itunes

Posted via email from psilva's prophecies

Thursday, January 6, 2011

PCI Turns 2.0

…Or 6 years old in human time.  When PCI DSS was born, it was actually five different procedures from each of the major credit card issuers: Visa, MasterCard, American Express, JCB and Discover.  Each program was comparable in that they wanted merchants to have minimum security requirements when handling (process, transmit, store) cardholder data as a protection mechanism.  The industry came together and formed the PCI Security Standards Council (SSC) which aligned the distinctive policies and then released the Payment Card Industry Data Security Standard (PCI DSS) v1.0.  Over the years there have been clarifications, slight revisions, wireless guidelines, the addition of PIN Entry devices and of course, version updates – 1.1, 1.2 and 1.2.1, the most recent standard.  PCI DSS v2.0 was released on Oct 28, 2010 and went into effect January 1, 2011.  Organizations have until New Year’s Eve 2011 to implement and comply with the new changes and can actually still validate compliance against v1.2 until the ball drops again in 360 days.

It’s been an interesting ride for PCI with supporters hailing it’s mission and others complaining that it’s expensive, confusing and subjective.  If nothing else, it’s made business focus on and consumers more aware of Data Security, which is a good thing.  PCI v2.0 does not have any extensive new requirements but it does clarify some requirements for easier understanding and makes adoption, especially for small merchants, simpler and easier.  Some of the important updates include the need for a comprehensive audit prior to assessment to understand where all the cardholder data resides within the infrastructure.  Knowing all the locations and flows of sensitive data can help in protecting those assets.  An evolving requirement is allowing merchants to execute a risk-based approach, based on business circumstances, for ranking, addressing and prioritizing vulnerabilities.  I’ve mentioned before that Security is really about Risk-Management, and while I’m not sure that merchants with limited IT security experience could determine if they are more susceptible to Forceful Browsing, Hidden Field Manipulation, or SQL Injection, I do think it’s a step in the right direction in terms of an exercise.  It encourages organizations to conduct a risk-assessment and focus on areas that are the most vulnerable.  This can help a smaller merchant target their limited resources to a specific area of concern. 

Another evolving requirement is the need for more effective and centralized log management.  Scouring logs from various systems looking for that one nasty IP address can be cumbersome and the ability to centralize log management is important whether you’re trying to be PCI compliant or not.  Cloud Computing comes to mind as a big beneficiary of centralized management.  And speaking of the Cloud, there is also some guidance on virtualization – not much – but some.  For one, they’ve included virtualization in that, they’ve expanded the definition of system components to include virtual components.  You can only implement one primary function per server, so functions like web, app, db, DNS and so forth should be running on separate virtual machines.  They want to avoid situations where different functions that may have different security levels are cohabitating on the same server.  Also, since VMs can move around, if only one of your VMs is handling cardholder data, then the entire virtual infrastructure must comply.

The following is taken directly from the PCI DSS 2.0 and PA-DSS 2.0 Summary of Changes – Highlights document.

image

image

And so begins the new 3 year lifecycle for standards development but minor revisions can be added, if necessary, during that time.  While the temptation is to wait until you absolutely have to comply or just test against the old standard, it’s better to get going on two-dot-oh sooner than later.  You really don’t want to be worried about implementing PCI updates when the 2011 holiday shopping season is in full swing or when staff is limited due to the holidays.  If you need to comply, do yourself a favor and get it done early.

ps

Resources:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet, cybercrime, holiday shopping, identity theft,

Tuesday, January 4, 2011

In 5 Minutes or Less Video - F5's iHealth System

Maintaining your system and troubleshooting issues can be time-consuming and tedious.  Whether you want to fix a problem, improve performance, or view your system’s running configuration, F5 BIG-IP iHealth™ can help you accomplish your task quickly and accurately. BIG-IP iHealth consists of BIG-IP iHealth Diagnostics and BIG-IP iHealth Viewer.  BIG-IP iHealth Diagnostics identifies issues, including common configuration problems and known software issues. It also provides solutions and links to more information.  With BIG-IP iHealth Viewer, you can see the status of your system at-a-glance, drill down for details, and view your network configuration.

F5 iHealth system, an exclusive online support service available to F5 customers and partners, is designed to proactively improve the performance of application delivery infrastructures.  iHealth is a web-based application that provides insight into BIG-IP product deployments through performance monitoring and automated analysis.  iHealth gives users a succinct description of identified issues along with F5's recommendations for addressing them.  This comprehensive analysis validates current product configurations against best practices, and displays heuristics data in an easy-to-understand format based on the familiar BIG-IP interface.  In offering a proactive approach to troubleshooting, iHealth significantly decreases the time and effort necessary to diagnose and address technical issues.

F5’s iHealth System

ps

Resources:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

 

Technorati Tags: F5, infrastructure 2.0, integration, big-ip, Pete Silva, security, business, education, technology, application delivery, diagnostics, cloud, context-aware, support, automation, web, video, blog, F5 iHealth

Monday, January 3, 2011

Audio White Paper - Application Delivery Hardware A Critical Component

Application Delivery Controllers (ADCs) come in a variety of hardware and software combinations, but mission-critical application delivery demands mission-critical ADC hardware.  Running Time: 17:58  Read full white paper here.  And click here for more F5 Audio.

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, security, hardware, audio, whitepaper,

Posted via email from psilva's prophecies