Those of us that grew up in the Big Apple remember those obnoxious ads for 1-800-Mattress where the announcer told us to "leave off the last s for savings." The company is still selling bedding and still preying on the general public for its lack of spelling prowess. (They actually purchased the 800 numbers with the misspelled names because so many customers dialed them, but that is a story for another time.)
My point today is about that ending 's' but in another place that might have you losing sleep. I am reminded of their little ditty with an email from a reader who asks if there are many eCommerce sites that still don't use secure Web pages (where they use https: instead of just plain http:) for their shopping carts.
Sadly, they do still exist. I ask you all if you come across examples, to email them to me and I will add them to my strominator.com blog post and publicly shun them. It is time we put a stop to this shoddy practice. Come on people, this is the new millennium, we have better things to worry about, and this is not new technology or hard to do. Why just this week I purchased an SSL certificate - what you need to turn your Web server from http into https -- and it took all of about 10 minutes and less than $50. Godaddy makes it relatively easy to get one and get it setup, and if you don't want to use theirs, there are dozens of others who will take even more of your money for one.
Even Google's Gmail has gotten on board the https cluetrain: last week they turned on a very nice option that forces your browser to open a secure session when you are reading your Gmail account (go to Settings and scroll down to the "browser connection" choice and click the button to "always use https" and then click on save, it is that easy. If you use Gmail, go and do this now and you can thank me later.
Why is this important? Because someone can hijack your browser session and obtain personal information if you leave off the last 's'. This is especially the case when you are using a shared public computer, such as at an airport or library. But it can happen even if you are at work, if your work network has a wireless segment that anyone can see your traffic on just by sitting outside your building, or if someone brought an infected laptop into the office that is recording your sessions.
My correspondent wrote to the eCommerce vendor (in this case, it was the photo printing and sharing site Fotki.com) and asked why they did leave off the last 's.' This is what he got in a reply:
"Please don't worry about missing padlock, we no longer use HTTPS on our payment page, because web browsers tend to send warning messages about web page security and some users get confused with that. All credit card transactions are going through the secure network and properly encrypted by means of Java Scripting."
Yeah, and some users are still misspelling "mattress" too and dialing the wrong numbers. Steer clear of these Web sites that are trying to make it easier for others to steal your personal information. And don't leave off that last 's' unless you plan on spending some sleepless nights when your identity is compromised.
David Strom is a noted speaker, author, podcaster and consultant who has written two books and thousands of magazine articles for dozens of IT publications such as Computerworld, eWeek, Baseline Magazine, Information Week and Information Security magazine. His blog can be found at http://strominator.com, and he can be reached at david@strom.com
In these days of frequent business travel, working from home, and outsourcing work to independent contractors, you probably have some sort of remote access to your business networks. If your network is not properly secured and you do not implement appropriate remote access controls, you could discover that you have left the back door to your business open and allowed the wrong people to walk in.
Remote network access can be a wonderful thing. No matter where you are, you can log onto your network and access all the information stored there. It gives a great sense of freedom to know that by installing some remote access software and having access to the internet, you can manage your business at any time from any place. Remote network access also gives you the freedom to provide telecommuters and independent contractors access to your business information, enabling them to work for you from a remote location. Doing this is probably both efficient and economical for your business.
Stop for a moment, and think about the number of people who have remote access to your network:
" Employees using laptops and other devices when traveling
" Employees using home computers
" People in branch offices or retail locations
" Sales representatives
" Telecommuting employees
" Independent contractors to whom you outsource work
" Suppliers or vendors
" Business partners
" Customers or clients
To be sure, you almost certainly grant some groups of people only limited access to your network or access to only certain data. But, let's face it, you could be opening hundreds or even thousands of doors to your business.
Now consider that many of your most valuable company assets are probably stored on your network:
" Product information
" Legal and financial information
" Competitive analysis
" Customer profiles and sales history
" Research and development data
" Employee data
Inadequate remote access security can leave your business and the personal information of hundreds of individuals and companies at risk.
Every person who has remote access to your network has the ability to open the door to your business using some device. Whether that device is a home computer accessing your network through a phone line, cable or DSL, the device can be used to open a door. If you don't know how secure the device and the connection are, you are essentially leaving that door to your business unlocked. Once you leave a door unlocked, you no longer have control of who walks in or of what they can see or take without adequate security.
Consider the possibilities:
" An employee's child downloads a game to her home computer without realizing spyware has also been installed. When your employee downloads a file on your new product to that same home computer, your competitive advantage could be gone.
" You, the chief executive of your company, often work from home early in the morning. To save time, you tell your computer to "remember" your log-on and password. Your house is robbed and your home computer is stolen. The thief has full access to both your personal information and your business.
" The head of R&D for your company regularly takes a company laptop home in order to work on weekends. Without his knowledge, his son has downloaded a game, complete with a worm. When the head of R&D logs on to work, he introduces the worm and all those critical research files disappear.
How do you protect your business? You protect your business by closing and locking all of the doors. You establish policies and procedures about use of company equipment and about remote access to files. You build security for your network, and you build additional security for sensitive data. You restrict access by employees to certain websites from company equipment, and you prohibit placement of cookies and spyware on your system or your equipment. Then you layer the protection provided by your security system. Finally, you engage IT people to constantly monitor and update the security of your network.
The bottom line is this: Remote Access can open a back door to your network, putting your business at risk. You can, however, give people remote access to business data they need, and, at the same time, protect your business and your business data.
Copyright (c) 2007 Thomas Burns
Thomas Burns, founder and CEO of Intelligent Networks Services (INS) has been an industry expert in computer network and technology for over 20 years. Under his careful supervision, INS has become a leading, full service IT support company servicing small to mid-sized businesses in Silicon Valley. INS's goal is to save their client's money by focusing on preventative maintenance and intelligent network designs. For more information go to: [http://www.intelligentns.com/subscribe] and receive your complimentary network evaluation.