Affichage des articles dont le libellé est security. Afficher tous les articles
Affichage des articles dont le libellé est security. Afficher tous les articles

25 novembre 2010

De la sécurité...

On aura beau mettre tous les outils de sécurité en place... On aura beau former les utilisateurs sur les risques...
Voici la petite aventure qui m'est arrivée à une conférence dans un hôtel parisien.



Je suis à une conférence entre soit disant experts IT. Les thèmes abordés sont le cloud-computing  et les écueils de sécurité, comment y penser, comment les contourner...

Vers 10:30  la pause et tout le monde sort pour le café proposé par les intervenants.

Dans les travées je remarque, posé à même le sol, juste relié à la prise par son chargeur un BlackBerry avec la messagerie ouverte...Je m'approche, le prends en main (persuadé que son propriétaire rode pas loin) et... RIEN... je clique un mail qui s'ouvre... toujours RIEN... c'est apparemment un mail pro vu l'adresse de l'expéditeur et le contenu ! Je repose le tout et pars au café abasourdi...

     Au retour de la pose, l'utilisateur se plonge dans le mail que j'ai ouvert, regarde un peu paniqué autour de lui... puis repose le téléphone à ses pieds dans la travée... où arrivent maintenant les autres intervenants !

Pas de mot de passe ? Le câble d'alimentation qui traine ? Pas de veille ? La messagerie ouverte...

Parlez-moi de confidentialité, de sécurité !... Au fait, je vous ai dit que les invitations étaient pour des DSI  et responsables Informatiques  ?


PS : la conférence était passionnante, je vous en reparlerai

26 novembre 2009

What else ?...

Today (thanks to lifehacker web site) I discovered a curious list :

61 Free Apps We're Most Thankful For

I have to admit I already used most of the top ten ones, for private or professional use... Most of daily use of IT tasks are covered here. So for a company, specially on these hard times, the question is : what else ? Why to pay more !

I suggest here some questions IT Manager should ask before switching to free app :









  • Is there any return on investment ? 





  • are thezy reliable ? 





  • what about security ?

    what about the long term developpments ?  

    is there a support available ?
    does this soft needs long term training ?


    We were used to ask these when buying software. We should not forget them wimply because it's free.



    Last but not least, never forget to test a free app (on key platform with key users)before company launch !




     Question : are you using professionaly one of these ? why and how ?

    PS : I trend to work more and more on web application or services , but this is another question





  • 09 octobre 2009

    Of basic security reminder...

    Sometime security depends on end users in the company ! This concerns all employee with a mail address whatever the system is.

    Ask them do not leave emails (webmail or pop mail with local client) containing : password, login, (mot de passe, profil, identifiant mot de passe en Français) and all other account information. These emails can come from eCommerce websites, bank website (poor security there!) or web 2.0 sites ...  Please just kill these emails once noticed login and password... and empty email trashbin.

    Also kill the ones requesting a login to reset password...



    Do it NOW : there is obviously one or two pending...

    PS Don't keep this information on an excel or word file saved on the desktop with name 'passwords'! or worth on a postit! over your screen or keyboard.

    11 septembre 2008

    Of risky Win XP SP3...

    To avoid anoyance with Win XP:

    A little warning about auto-update your computer with Windows XP SP3... as one of my friend had to remove it ! It seems in some case this update makes computer to permanently reboot.

    So except if you are working on a test platform, may I suggest to urgently wait before autoinstalling it .

    If you're facing some problems, it is simple as a program to remove it !...back to reliable SP2.

    Now to be honest , I installed it at work on a new fresh install without any problem since days... but was a virtual computer !

    PS : please no comment about MAc or Linux here ;-)

    28 juillet 2008

    Of remembering password after vacation

    As IT expert you have a backup of your data, you have checked all systems with last security patches and upddated your antivirus program. You have stopped all modifications on application and or system since a week or two...

    Did you save a list of your daily used passwords and keys ?

    You may have given some of admin passwords to the team in charge of the support during your vacation. But if not ?

    I already see comments like 'no, never write down any password, never !" I did not ask you to create an spreadsheet with all your password, and leave it under your keyboard (I saw that today from a supposed high lebel user ) But keep the paper version at home for example then delete the file.

    My better choice : I've only one to remind the database key one of my keepass programm ! I've writen it inside my mobile phone contacts. I can now go on vacation ! I have a backup of this database file on my computer @ home... without keepass installed on it.

    PS : another good tip for your users : ask them to change their passwords once back from vacation, not just before going to sea side for three weeks !!!...

    What is your paswword policy , to keeep them in mind during vacation ?