>

Buy Microsoft Office Ultimate 2007!

August 31, 2007

Service Oriented Architecture (SOA)

A friend of mine pointed me to an interesting article on SOA called Service Oriented Architecture is your Ticket to Hell.

Its on a blog called "The War on Bullshit" It's a short, but good read on a few of the flaws of SOA

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

August 19, 2007

Things I hate about Vista, and How I fixed them.

I've been using Windows Vista off and on since the first release years ago and have watched it grow and turn into a pretty good OS. (yes some of you hate it, I know, I know...but I don't care) Durring this time I have found that there are things I love about Vista, things I like about Vista, and things that just irritate me about Vista. So instead of just dealing with the problems, I decided to fix them.


  1. The size of the icons on your desktop are freaking huge. Even at the smallest size they are way bigger than what I wanted. So I installed ObjectDock by Stardock and chose not to see desktop icons in my display settings. It's essentially a clone of the dock that the Mac OS comes with. I always liked that feature in OS X so now I have it on my PC and it got rid of the giant icons.

  2. The Log-in screen. I hate the way it shows the user image when you try to log in. And for security reasons I prefer it not to show the last user who logged in, so I altered the local security policy so when the computer turns on, you need to press CTRL-ALT-DEL then enter your user name and password. No user image, no pre-filled user name. To do this go to control panels --> Administrative Tools --> Local Security Policy --> Local Policies --> Security Options and then set "Interactive Log on: Do not require CTRL+ALT+DEL" to disabled. Also set "Interactive Log on: Do not display last user name" to Enabled.

  3. It's sluggish at times. Set page file to 2500MB (set, not variable or controlled by the computer. This prevents the drive from getting as fragmented) I also turned off the visual aspects I don't like (not all of them because I like Aero and Glass) and use ReadyBoost. Having 2Gb of RAM in my laptop doesn't hurt much either.

  4. Vista User Account Control: From a security standpoint this is a great feature, it doesn't allow the user to do anything requiring Administrative level privileges without checking first. Its similar to how even if you are logged into a admin account in a *nix environment you still need to specify that you want to run a task as an admin. From a usability standpoint, it sucks. So I turned it off. Id explain it how, but My Digital Life does a nicer job and give 6 ways to turn it off.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

August 18, 2007

Product Review: LogonStudio Vista

Being that I'm on a computer most of the day, I like to make them my own. I like every aspect to be just right, and big part of that is how it looks. Changing color schemes and desktop wallpapers are nice (and I do both) biut one feature that is a bit more difficult for the average user is changing the log in screen. Today I came across a program for Windows Vista that makes it effortless. The product is called LogonStudio Vista by Stardock

LogonStudio Vista by Stardock is a very simple specialized piece of software that allows you to change the log in screen on a Windows Vista computer. You simply install the software, and via a very clean and clear GUI pick the photo you want (either from a few that come with it or from your hard drive) and it will set it as the background for you log in screen. In all it took me about a minute to download, install, and then change my log in screen.

Stardock also offers several other tools for modifying your Windows user interface so go check them out.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

August 17, 2007

The "fix it" Button and tips to prevent using it.

OK, we all know that there is no magic "fix it" button when it comes to computer. (Trust me, I've built tons of them and have fixed even more, if it was there, I'd have found it). So I'm going to try and do the next best thing and offer some advice to help you find out what is causing the problem with your computer.

Restart the computer:

The first thing I always ask my clients/users to do when they are having trouble with their computer is to just restart it. whether it is the computer just acting sluggishly, a program not opening properly, a web page not loading properly, just go ahead and give the computer a restart. Restarting computers fixes so many problems it is ridiculous. It is the closest thing to a magic button there is.

The reason restarting fixes so many problems is because while you are running programs and opening files on a computer, the computer is storing them into temporary memory. If for some reason, one of these files get written incorrectly to that temporary memory or conflicts with a file that is already there, it can cause problems. Restarting the computer clears out that temporary memory.

(tech secret: having a user restart a computer does more than just clear the temporary memory on their computer. It also clears that mental block a user creates that makes them think "this computer is broken!" Once the computer reboots, the computer has done something so it changes the users mind state to again think the computer has the chance of working, and usually it does. This works especially well when users are mis-typing their passwords and refuse to believe that is the problem)

Think Back:

"But it was working earlier!" is one of the worst arguments ever made. Everything was working before it was broken, so your goal is to find out what happened at the point where the computer went from "working" to "not working". So think back. What were you doing the last time the computer was working? Did you install a new piece of software? Did you install a new piece of hardware? Did you attach any new peripheral (printers, scanners, mp3 Players, Digital Camera, etc).

If you did, uninstall them. There is a good chance that whatever you installed is causing the problem. Yes, even plugging in a simple peripheral can cause problems, because when you plug it in, your computer needs to install drivers (basically the set of instructions for your computer to use a device). These drivers sometimes can cause conflicts with other software/hardware on your computer. So the easiest way to test if this is the problem is to remove them (contact the manufacturer of the product for instruction on how to remove hardware drivers from your computer)

Tips to prevent problems:

  • Always follow the instructions that come with products you are installing. Some computer components are finicky about how you install them and doing steps out of order can cause unexpected results (and they usually aren't for the better)
  • Get some anti-virus software (especially if you use the Windows Operating System). It's not that expensive (or go with a free product like AVG) and it will help keep you computer running smoothly.
  • Make sure your software is up to date. All operating systems come with an updater, use them. (For windows users is called "windows update" or "Microsoft Update" and is located in the programs section of your start menu.) Software updates fix small bugs that you might not even notice are there but that can increase the performance of the software, they also fix critical issues that can affect the security of your computer.
  • In addition to software updates, be sure to occasionally check for Driver updates for your hardware as well. Using Microsoft Update will show most of these as well. Drivers are essentially instructions for your computer on how to use a piece of hardware. If better instructions are available, you should use them. Typically they increase stability, reliability, and occasionally will add more functionality.
  • Be smart. If you are surfing the internet and a window pops up that says "you just won a car!" don't click it. If something seems too good to be true, it typically isn't. Clicking on pop ups like this all but guarantee that you will start seeing more and more pop ups.
  • Don't download anything unless you know it is from a trusted source.
  • Be careful with Email. If you get a message from someone you have never heard of offering you something, delete it. Remember, if it sounds too good to be true, then it probably isn't. Also, don't download attachments from people you don't know, and NEVER give out personal information about yourself. A bank or credit card company, heck NO well run company will EVER ask you for personal info (i.e. social security number, password, address, etc) via email. The reason for this is because e-mail is not a secure form of data transfer. If you get an email requesting this information (even if it looks legitimate) call the company who is requesting the info and verify with them over the phone the information they want.
  • Do basic system maintenance. Operating systems come with tools for this. Use your disk defragmenter and disk clean up utilities. These tools will help your computer run smoothly and last longer.
  • Let a professional help you if you aren't sure how to do something. Stores like Best Buy and CompUSA get a really bad rep. and personally, I don't like either of them for various reasons (there are tons of complaint boards on the net about both if you need reasons) but look for a local computer repair shop, ask friends where they have had a good experience, and take your computer there.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

August 13, 2007

Balancing Security and Usability: The Human Factor

Social Engineering: n. the act of obtaining or attempting to obtain otherwise secure data by conning an individual into revealing secure information

One element of digital security that is typically over looked is the human element. People, for the most part, are trusting and want to help others in need. While this may be good for the human race in general, its not good for security, and thats what we are talking about.

Training staff members to recognize and protect sensitive data is imperative to keeping it a secret. In addition to recognizing what should be considered sensitive, a staff member must also recognize an attempt from a non authorized person to obtain that data.

For instance, most companies post the names of their executives or other prominent members of their organizations on their website. If a person were to call in to one of your smaller offices, or call someone low in the company answers the phone (we'll call her "Jen") and says they are the VP of sales, most employees probably wouldn't challenge that fact unless they happen to know the VP personally or have at least met enough times to recognize the difference in voice etc. Because of this Jen is probably going to be on her best behavior and want to help as much as possible. If the person calling says they are on a business trip and cant seem to find the number for the IT department or Help desk and needs his password reset, I'm sure Jen would happily turn over that information, because what harm could that do? Now the caller can call that inside phone number, but instead of saying they are the VP of some department, they say they are a new employee (with another phone call a person can obtain the name of an employee) and Jen told them to call here to get their password reset. This gives the caller some perceived credibility since they seem to know a person in the company and also because they are new, people want to help them. So the person taking the call, if not properly trained, or if no checks are put in place will reset their password for them and the intruder now has a user name and password to access company info.

This is a really simplified example, but unfortunately its not unrealistic. Without proper training, staff wont challenge someone the perceive to be their superior. So staff need to both know they should do this and also feel comfortable doing it. In the military soldiers are trained to challenge those who approach an area they are guarding, they are taught that they should respectfully demand proof of identification if one claims they are a superior. This is the thought process staff should be trained with. No one wants to inconvenience another person, especially one who is their superior, but for the sake of security and confidentiality, it is sometimes necessary.

So how do we prevent things like this from happening? There are a few things that can be done.

* Teach staff to identify sensitive information. And properly label items as "internal use only" or "confidential" to prevent any confusion.
* Be sure staff know never to share their password, not with anyone, not even the IT staff. Your IT department can reset the password if they need access to your account, its rare they will actually need your password.
* Put policies and procedures into effect that control how user names/passwords are controlled. Who can do password resets? Who can authorize them? and how do you verify the identity of the person who is requesting it?

But primarily what you need to do is educate you staff and have them understand the reason these things are considered sensitive. Saying "this is bad" doesn't mean much to a lot of people, explain why its bad, explain what can happen if that data is released to the wrong people, and be sure they understand it. Have consequences for when data is mistakenly released, but do not rely solely on the fear of consequences to get staff to follow these rules. And of course treat you staff well. People who feel appreciated, who are happy at their jobs, and who feel they are a part of the company will protect it's interests. A guy you yell at, who hates where he works, and doesn't really give a damn will probably give up what ever info is asked for just because it makes no difference to him.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google