About Me

My photo
Experienced Information Technology leader, author, system administrator, and systems architect.

Sunday, May 4, 2014

"The Technology Manager's Survival Guide" Class at LOPSA East 2014

I had a blast this week teaching "The Technology Manager's Survival Guide" at LOPSA East 2014. The course was based on significant content out of "From Techie to Boss" and featured a lively conversation about the experiences of the technical managers in the audience.

If you were in the class, please feel free to contact me with any questions or comments.

I'll be presenting a similar class "Leader's Survival Guide," in Jacksonville, FL on July 16 and 23. Space for that class is limited; please contact me if you are interested in attending!

I am pursuing other opportunities to present the course; keep an eye on this space!

Saturday, March 1, 2014

Protection against WiFi Viruses and Attacks

Security researchers have designed a virus that spreads silently through WiFi networks. The "Chameleon" virus replaces access point firmware and masquerades the settings and administrative credentials, which makes it very difficult to detect this virus.

Fortunately, the virus can be blocked by following good WiFi security practices. Unfortunately, many WiFi networks are not set up in a secure way.

Fortunately, the steps to secure a home WiFi network are not particularly difficult:

Beyond securing your own routers, you need to keep in mind that public routers may also have been infected. There are some steps you can take to protect yourself when connecting to public WiFi routers. Be aware that public networks are by definition insecure, whether WiFi or wired. There is little or nothing to stop a miscreant from trying to snoop your connection.

  • Enable built-in firewall features on your computer, especially software firewalls. Deny all incoming connections.
  • Make sure file sharing is turned off.
  • Be aware that passwords may be sniffed by keyboard loggers, pulled from your computer's registry, or simply observed over your shoulder. By using a tool like LastPass or Password Safe, you can avoid having to type passwords while storing them in a secure, encrypted location.
  • Use a VPN if possible.
  • Use https (HTTP over SSL) to connect to vendor sites wherever possible.

Monday, February 24, 2014

Upcoming Events

I look forward to seeing some of you at an upcoming class.

My class, "Technology Manager's Survival Guide" is on the Friday afternoon training schedule at LOPSA-East on May 2 in New Brunswick, NJ.

And I'll be presenting a two-part class, "Leader's Survival Guide," in Jacksonville, FL on July 16 and 23.

Friday, February 7, 2014

Allowing Outside Vendors on Your Network

Recent revelations about the Target attack have re-focused attention on the dangers associated with allowing an outsider on your internal network. There are a few key lessons we can take from this episode:

Thursday, February 6, 2014

Bring Back Net Neutrality

In January, a federal appeals court struck down the FCC's regulations regarding net neutrality. In arguments in that case, Verizon indicated that it wanted to pursue "different pricing service models."

(In other words, they want to throttle traffic for content providers who don't pay up. In fact, they want it so badly that they stated it five separate times during arguments.)

In the wake of the ruling, it appears that Verizon is doing exactly that. Reportedly, Verizon reps are telling customers that the reason that services (such as Netflix) that run on Amazon's AWS platform run so slowly on Verizon's network is that they are being throttled.

(Verizon is clearly betraying its New Jersey roots. "That's a real nice service you're offering there. It would be a real shame if something happened to it." Who knew that they had hired Tony Soprano to plan their corporate strategy?)

Earlier this week, House and Senate Democrats introduced legislation to re-institute the former net neutrality rules. The legislation is known as the Open Internet Preservation Act.

Good luck to them. Given that most people have a very limited selection of broadband providers, I'm not sure how the FCC ever considered them anything other than common carriers.