<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Practical Issues in InfoSec &#187; Backups</title>
	<atom:link href="http://www.dlstrom.com/category/backups/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dlstrom.com</link>
	<description>... putting information security within reach of everyone!</description>
	<lastBuildDate>Tue, 27 Jul 2010 13:26:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>He&#8217;s Dead, Jim&#8230;</title>
		<link>http://www.dlstrom.com/2010/05/24/hes-dead-jim/</link>
		<comments>http://www.dlstrom.com/2010/05/24/hes-dead-jim/#comments</comments>
		<pubDate>Mon, 24 May 2010 15:28:40 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Backups]]></category>
		<category><![CDATA[FlashDrive]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=313</guid>
		<description><![CDATA[Pay attention, everyone - You should never have the only copy of your important files be stored on your flash drive. It will die (or be lost or be stolen). If this is the case, you may be completely out of luck. I had a friend give me a flash drive this past weekend. The [...]]]></description>
			<content:encoded><![CDATA[<p>Pay attention, everyone -</p>
<p>You should never have the only copy of your important files be stored on your flash drive. It will die (or be lost or be stolen). If this is the case, you may be completely out of luck.</p>
<p>I had a friend give me a flash drive this past weekend. The flash drive is not recognized by any computer. Where there normally is a light that comes on when plugged in, now there is no longer a light.</p>
<p>If the problem is more that just a poor USB connector, then it will be pretty costly to recover the data, if it is possible at all&#8230; Usually the cost will outweigh the benefit of recovered files.</p>
<p>So, use the flash drive only as a working and portable storage device. Make sure they are encrypted. Copy the files back to your computer if they are important. That way they will be a part of  your normal backups. (You do have a backup system, right?)</p>
<p>If you don&#8217;t have a backup system in place, consider using something like LockYourData (<a href="http://www.lockyourdata.com/">www.lockyourdata.com</a>). It allows  you to manage both online and local backups as well as keeping multiple generations of files.</p>
<p>The last thing you want to hear is the words of Dr. McCoy as he looks up and says, &#8220;He&#8217;s dead, Jim.&#8221;</p>
<p> </p>
<p><object width="445" height="364"><param name="movie" value="http://www.youtube.com/v/qJQwHwP0ojI&#038;hl=en_US&#038;fs=1&#038;border=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/qJQwHwP0ojI&#038;hl=en_US&#038;fs=1&#038;border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="445" height="364"></embed></object></p>
<p> </p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2010/05/24/hes-dead-jim/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>InfoSec Tip: Are Your Backups Usable?</title>
		<link>http://www.dlstrom.com/2009/08/28/infosec-tip-are-your-backups-usable/</link>
		<comments>http://www.dlstrom.com/2009/08/28/infosec-tip-are-your-backups-usable/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 13:00:00 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Backups]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Planning]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://www.dlstrom.com/?p=280</guid>
		<description><![CDATA[&#8220;Backups are the disaster recover plan!&#8221;, he emphatically said. And so began the conversation&#8230; Of course, backups are a part of the disaster recovery, but not the complete plan. Just last night I found out about a local business whose server crashed. They had been dutifully performing backups. The backup subsystem reported that backups had [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Backups <strong><em>are</em></strong> the disaster recover plan!&#8221;, he emphatically said.</p>
<p>And so began the conversation&#8230;</p>
<p>Of course, backups are a part of the disaster recovery, but not the complete plan.</p>
<p>Just last night I found out about a local business whose server crashed. They had been dutifully performing backups. The backup subsystem reported that backups had been created. But&#8230; </p>
<p>It turns out that the backups are unreadable and now they are scrambling to determine the next steps to keep their business running.</p>
<p><strong>Tip: Periodically check your backups to make sure that (1) they are readable, and (2) that they contain the information you hope they do.</strong></p>
<p>Put this into your list of things to review on a monthly basis. As some point you <strong><em>will</em></strong> be glad that you did.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2009/08/28/infosec-tip-are-your-backups-usable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>End of Year Cleanup</title>
		<link>http://www.dlstrom.com/2008/12/08/end-of-year-cleanup/</link>
		<comments>http://www.dlstrom.com/2008/12/08/end-of-year-cleanup/#comments</comments>
		<pubDate>Mon, 08 Dec 2008 22:51:28 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Backups]]></category>
		<category><![CDATA[Data Integrity]]></category>
		<category><![CDATA[Planning]]></category>

		<guid isPermaLink="false">http://dlstrom.com/wp/?p=51</guid>
		<description><![CDATA[Do you know you data, computers and networks? I mean, really know them? The end of the year is a good time to take stock of your security measures and operational practices and do some maintenance. I like to ask the question Where are we? at the end of the year. What is being done [...]]]></description>
			<content:encoded><![CDATA[<p>Do you know you data, computers and networks? I mean, <em>really know</em> them?</p>
<p>The end of the year is a good time to take stock of your security measures and operational practices and do some maintenance. </p>
<p>I like to ask the question <strong>Where are we?</strong> at the end of the year. What is being done to protect the information assets of my company or myself and family? After I have a good grasp of this, then I like to ask myself the logical next question, which is <strong>Where do we want to be?</strong> Comparing the two gives some idea of where to focus my information security energies.</p>
<p>Yeah, I know that previous paragraph is pretty vague.</p>
<p>How about some specific ideas when asking that <strong>Where are we?</strong> question.</p>
<ul>
<li>Do I know where all the important data is being stored? Is it all on the hard drive of one notebook computer? Or, is some stored on my computer, some stored on my wife&#8217;s computer? Maybe it is stored on a file server on the network!</li>
<li>What am I doing to protect the data on my notebook computer? Am I doing backups? How do I know that the backups can be used?</li>
<li>What if my notebook computer gets stolen and my personal financial information (with bank account numbers and passwords) is stored on it? What am I doing to encrypt or adequately protect that data?</li>
<li>If you host your own web services, you should evaluate the access rules on your firewall. Do I really need to allow access on the ports that I have open?</li>
<li>Am I patching the OS on my servers? Do I test patches in a controlled environment before installing them on the production servers?What about the patch level of my workstations? Am I using Automatic Updates (on Windows) to keep them updated?</li>
<li>When was the last time I changed the WEP/WPA key on my wireless access? Am I using WEP or WPA or something else? Am I sure that only authorized people know what it is? Maybe the neighbors are leaching the signal!</li>
<li>Do I have any idea of what &#8220;normal&#8221; traffic looks like on my network? What applications are being used &#8211; P2P, chat, BitTorrent, webcams? What about filtering? Is my filtering functioning as desired?</li>
<li>When was the last time that I forced password changes for users? How about administrator/root accounts?</li>
</ul>
<p>Wow! That sounds like a lot of work! It&#8217;s not, really, but these things need to be considered periodically.</p>
<p>In the next entry, I will be discussing the <strong>Where do we want to be?</strong> question.</p>
<p>- Dan</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2008/12/08/end-of-year-cleanup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Data Storage with getdropbox.com</title>
		<link>http://www.dlstrom.com/2008/07/18/online-data-storage-with-getdropboxcom/</link>
		<comments>http://www.dlstrom.com/2008/07/18/online-data-storage-with-getdropboxcom/#comments</comments>
		<pubDate>Fri, 18 Jul 2008 23:41:02 +0000</pubDate>
		<dc:creator>d.strom, cissp, gsec, gsna</dc:creator>
				<category><![CDATA[Backups]]></category>
		<category><![CDATA[Data Integrity]]></category>
		<category><![CDATA[getdropbox.com]]></category>

		<guid isPermaLink="false">http://dlstrom.com/wp/?p=23</guid>
		<description><![CDATA[Small business is confronted with a significant decision when it comes to the backup of their important data. Should a local solution be implemented, or should an on-line service be used? I’ve just begun experimenting with a relatively new service called getdropbox.com. getdropbox.com is a relatively recent entry into the fray of on-line storage and [...]]]></description>
			<content:encoded><![CDATA[<p>Small business is confronted with a significant decision when it comes to the backup of their important data. Should a local solution be implemented, or should an on-line service be used? I’ve just begun experimenting with a relatively new service called getdropbox.com.</p>
<p>getdropbox.com is a relatively recent entry into the fray of on-line storage and is still in “beta” mode. Getting an account requires an invitation from someone who already has an account. This free account gives the beta-user 2GB of storage. Once an account has been set up, a bit of software is installed on the local computer. This software creates a new folder (dropbox) on the local computer. As files are moved into that folder, they are auto-magically uploaded to the folder on the getdropbox.com servers. These files are only accessible by you, or any other computer with the getdropbox software and and that is linked to your account. Pretty simple, eh?</p>
<p>getdropbox.com also allows you to make some of your files publicly accessible. A unique URL is provided for each file. Anyone who knows, or is lucky enough to guess, this URL can access this file. The file is readable, but changes cannot be written back to the servers.</p>
<p>The capability is also included to share a folder with other getdropbox.com users, but whose computer is not linked to your account. You just need to send them an invitation (via email) to the shared file. At this point they have full read/write access.</p>
<p>Now, how can this be used for an online backup? As mentioned earlier, the software watches the dropbox folder on your computer and automatically synchronizes with the on-line server. If you are using Mac OS X you can simply create a symbolic link in the dropbox folder pointing to any other folder you want automatically backed up. (Unfortunately, this capability is not available to Windows users at this time.) The developer indicates that they are internally testing a Linux client. Then, this should be available for LInux, also.</p>
<p>So, how secure is your data? According to the FAQ, the data transfer takes place over an SSL connection. I’ve not yet had the chance to examine the network traffic to verify this. But, and this is significant, does not state that the files are encrypted on their servers. According to the FAQ, “Files are encrypted with AES-256 before being stored on our backend.” They indicate that in the future users will be able to define their own private keys to encrypt the data, but this is not currently implemented. I would highly recommend that any confidential information be encrypted prior to putting it in the dropbox folder on your computer.</p>
<p>So, would I recommend that you use getdropbox.com for on-line data storage for your company? Yes, if the following conditions are met&#8230;</p>
<ol type="1" start="1">
<li>Sensitive data is encrypted before being put in the dropbox folder for synchronization</li>
<li>The total amount of data is less than the amount allocated to your account. Right now the maximum folder size is 2 GB</li>
<li>There is a need to share files with others trusted individuals outside the company</li>
<li>You business model allows for your company information to be stored outside of your control</li>
</ol>
<p>Ok, then, what about personal use? Pictures that need be shared with family would be fine to have stored. Likewise, other personal files may be fine. But, I sure wouldn’t put my Quicken data files up on a service like this unless I first encrypt it. (TrueCrypt would be a fine piece of software to use for encryption.)</p>
<p>Finally, the getdropbox.com privacy statement only speaks to personally identifiable information you submit as you create your account. Of course, they reserve the right to sell or disclose your information to service providers, business partners, and others. It is curious to note that they omit speaking to what they will do with the files you store on their site!</p>
<p>Disclaimer: The information in this post is current as of the date and time of the posting. The details of the getdropbox.com service are always subject to change.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.dlstrom.com/2008/07/18/online-data-storage-with-getdropboxcom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
