iSD in the Tech Age!



Net-self-defense, we spend an exorbitant amount of time on our physical defense training and then we forget that our lives are in just as much danger of "Grave Financial Harm" or Financial ruin (Death) as if we are attacked by a street predator. Research and studies show, from the security experts in this field, that Anti-virus and Firewall suites only catch about 5% of the threats out there and those same folks tell us that it is in all probability worse at the Enterprise levels.


My goal here is to educate myself, and by proxy, pass on what I learn to others so that each individual who is connected at any level can take steps to achieve some semblance of security in their electronic on-line lives. We are so deeply imbedded in modern technology that to not take appropriate actions to learn iSD or internet self-defense in the technological age is just foolishness.


My goal is to provide enough of a foundation that readers, like me, can take the appropriate actions, i.e., apply those fundamental principles of technological methodologies to safeguard one of the more important, actually critical, strategies and tactics to defend ourselves from grave economical harm or even economical/financial death or ruin from nefarious predatory hacking processes.


Nothing in this blog is definitive, it is meant to set a foundation of knowledge, understanding and awareness so that you are not one day blindsided by some effort to steal your very life out from underneath you so fast you feel like you have been hit behind the ear and knocked into a daze of confusion, fear and finally anger where your tech-life falls apart and ruins your real life utterly, completely and with no light in sight down that dark, empty and black hole.


Wednesday, April 13, 2016

Personal Internet Survival Actions

Steps you, as a user of networked devices like your computer, cell phone, iPads, etc., can take to reduce your exposure to criminal activity up to 85%. 
  • Application White List: allow only specifically authorized programs to run on your systems.
  • Block all unknown executable files and install routines.
  • Patch, patch and patch all devices automatically on a daily basis minimum.
  • Patch/update your Operating Systems automatically on a daily basis.
  • Restrict admin privileges on all your devices and spend your time as a basic user while emailing, surfing and shopping, etc.
  • Login as admin only you install new software or make system changes. 
  • Update frequently.
  • Make passwords long and complex.
  • Download from only known official sites. 
  • Use admin accounts with care.
  • Turn off your systems when you are not using them.
  • Encrypt your digital life. 
  • Protect your data both in storage and in transit across the web, encrypt.
  • Use common sense with all your e-mail. 
  • Don’t use USB from sources other than yourself.
  • Back up data frequently.
  • Cover up your camera features on your computers and other networked devices.
  • Sensitive browsing, i.e., do sensitive things like banking and shopping on computers that belong to you and avoid using wifi hotspots or unencrypted wifi at your home or work.
  • Think, before sharing on social media and networks. Think, before sharing on social media and networks. Think, before sharing on social media and networks.
  • Use the OS built in firewall. 
Bibliography (Click the link)
Goodman, Marc. “Future Crimes: Everything is Connected, Everyone is Vulnerable and What We Can Do About It.” Doubleday. New York. 24 February 2015. 

Surviving the Internet of Things

The list is partial and will grow but this is a good start. It will only come about when humans/users begin to realize, through eduction and understanding, the threat and grave losses all of us incur and will incur if we don’t take corrective actions very, very soon. 
  • Insist on secure software.
  • Require damages for non-compliance for secure software.
  • Reduce/Remove unsolicited data source storage and collection.
  • Secure those data sources with same damages for non-compliance.
  • Kill the password.
  • Encrypt code and apps by default and apply same damages for non-compliance.
  • Educate the users.
  • Required layered security involving technology and humans/users, apply damages for non-compliance.
  • Make cyber-security a lawful requirement with damages for non-compliance on all Internet Access, etc.
  • Make cyber-security a human-centered designed oriented thinking. 
  • Build more robust, responsive, and flexible defense methods for the internet, code, apps, programs, etc.
  • Practice good cyber hygiene by practicing safe tech, i.e., ways to teach, train and practice by users with reminders about practicing good computer skills.
  • Users take stewardship over their networks and devices, take personal responsibility and apply monetary fines when they fail.
  • Provide the public with proven methods of cyber hygiene to protect themselves.
  • Perform proactive network monitoring to detect infections and outbreaks of malware, etc. and apply damagers for non-compliance, etc.
  • Provide global incident responses by experts as required and coordinate globally efforts to isolate sources of criminal activity by Crime, inc. and the uVerse hacking predators then levy high monetary damages for failure to comply. 
  • Develop rapid-response systems for new dangers like a bioterrorism creating new biological viruses, etc. and apply monetary fines for non-compliance at levels commensurate to the business/systems funding, etc.
  • Create a worthwhile incentive program and competition for global security at a level at least commensurate to that of the criminal world. 
Return often to see additions to this list, mark it with a bookmark in your browser. 

Bibliography (Click the link)
Goodman, Marc. “Future Crimes: Everything is Connected, Everyone is Vulnerable and What We Can Do About It.” Doubleday. New York. 24 February 2015. 


Monday, April 11, 2016

So Little Effort

It used to be a predator had to assess their targets and would need to weigh the odds of whether they would have success or whether they would be caught.

All you had to do is use appropriate awareness, adequate knowledge and project an aura of competency, etc., that you are not an easy target and the predator would move on to easier pickings.

In our modern tech-crime era none of this applies. The ePredators just don't consider or care about the human equation, coding cannot see, hear, touch of FEEL the human conditions. There is no need to “other a target” because they already see thier efforts as a coding exercise and challenge and the humans behind those challenges in coding just don’t even exist in their minds. 

You can be a person of great skill, ability and experience in self-defense in our physical world and yet in the uVerse those traits mean nothing. The only challenge they face are getting caught and that is slim to none, in other words the rewards literally dwarf the chances of getting caught, prosecuted and jailed. 

It takes very, very little effort on a ePredator to build the code and make their move. They don’t even consider whether the protection is adequate or strong because it comes down to a matter of a few milliseconds of effort, in the code running that is no effort although it does require bandwidth and computing power, to a few seconds. 

Bibliography (Click the link)
Goodman, Marc. “Future Crimes: Everything is Connected, Everyone is Vulnerable and What We Can Do About It.” Doubleday. New York. 24 February 2015. 

Eagleman, David. “The Brain: The Story of You.” Pantheon Books. New York. 2015

Friday, April 8, 2016

Biometric Identification

Don’t be fooled by the ads saying biometric identifications are foolproof, that criminals cannot compromise them because it has been proven that you can compromise them, big time.

There are a variety of clever ways it can be done both tech-wise and sneaker-wise (using sneaker much like the old sneaker-mail meme, i.e., a non-tech method of copying and using your biometrics to circumvent security protocols for nefarious purposes. 

Hey, I wear hearing aids that use bluetooth to connect to iPhone apps to control how the function and guess what, bluetooth has poor security protocols and anyone with the appropriate software can turn on your bluetooth in the aids and hear everything you hear, talk about eavesdropping, yikes!

I won’t tell you how they bypass your own fingerprints, retina prints or other biometric venues used for security but remember, the moment you add the biometric function to any security model it is hackable. 

This brings me to how you can protect your biometrics, don’t allow them to be used in tech-security. But guess what, that won’t do the trick because, if they want you they will get you so the best security is to reduce the biometric recordings to a bare minimum. In my case, I have my phone locked down to the lowest security level possible and still be useful and I don’t use the biometric finger ID feature at all. 

This is one of those “Damned if you do, damned if you don’t,” things. You have to assess the threats you face and decide how far you are willing to go, to gamble your life from your money to your very life itself, it is that capable and bad. 

Bibliography (Click the link)
Goodman, Marc. “Future Crimes: Everything is Connected, Everyone is Vulnerable and What We Can Do About It.” Doubleday. New York. 24 February 2015. 



AT LEAST, BE INFORMED!

Thursday, March 31, 2016

Multiple vs. Singular Security Models

In a recent article one of the ads presented said, “Control the Chaos with a Single Security Solution.” Wow, that made me drop my bagel and choke on the drink of coffee I was partaking in when I saw the ad. 

It is a bit like the model the military started to take on when I was still the physical security person at a military installation, centralize their leadership into two “single” locations, one on the East Coast and one on the West Coast. I remember thinking about the art of war where to achieve a quick and decisive victory you cut the head off the chicken. In other words, put all your eggs in the East and/or West basket then let the enemy simply blow that leadership to hell and back. 

In the technological world a single source of security is convenient and easy but then the predators of the uVerse no longer have to spread out the attack to cover a variety of security models, they just focus o the one you just paid good money for - whalla, single point shopping for Crime, inc. What could be better.

It comes down to advertising to our laziness and comfort zone, to find just one way to supposedly have a “single” secure protection like that firewall and anti-virus program on your computer you think and “FEEL” is protecting your Internet presence. Guess what, according to some sources that firewall and AV barely protect us from about 5% or so of threats out there racing around our Internet searching, seeking and destroying our protections leaving us exposed and vulnerable. 

In a truly secure environment be it in the physical world, the inner brain world and the Internet electronic world, you need to have multiple layers of security to achieve some semblance of protection and safety and security. 

In the physical security world in which I worked you had to analyze and asses the threats you face and the value of loss toward your business, etc., to create a layered security that would not protect but rather make the effort to breach the security long and ardarous leaving the nefarious folks trying to break in wanting to move on to easier targets. Yes, I said not protect but slow the effort down because in truth there is not absolute protective security model, there is only creating a long delay to either redirect the thief’s efforts or to delay them enough that the models detection and alarms would give responders time to - respond effectively. 

Putting all my physical security into one central solution is foolishness nonsense. In my more high secure needs I had alarms, CCTV’s, Fencing, Human Security patrols (armed and authorized deadly force), human access controls, etc. to cause a great enough delay in attempts to circumvent so that armed security could respond, apprehend, detain and lock up criminals who attempted to gain access. 

Heck, even authorized access by employees had security layers beginning with background investigations, personal and professional references checks, legal investigations as to criminal records and activities then a dual badge system with entrapment areas for both human and vehicles, a badge verification and exchange by armed security and so on just to get to work. 

So, layered multiple security measures along with knowing who is maintaining and enforcing those security measures and an access control system to ensure that nefarious types are not allowed in. Yet, we will pay good money to have this unknown and completely strange human controlled SINGLE security solution to first, have the connection and social belief that will protect you as if you were family or a valued tribal member; second, who will exercise every possible way to protect you as if they were protecting themselves; third, whose agenda is not about money or company profit or board member profit margins, etc., and make you their sole reason for existence. 

So, we are going to pay strangers, complete and utter strangers who are selling a product for profit and strangers whose sole purpose is to sell the product at any costs maintaining profits, etc. regardless. Just send me five thousand dollars and I will personally guarantee it will remain safe and protected until you ask for it back. Now, just wait and see if you ever get that money back. 

It has been proven time and again that a single software program, like one very famous operating system, will protect you computer and data yet time and again the hackers of the world demonstrate, in short time (literally hours and minutes), that the so called secure OS can and is vulnerable and easily hacked. 

Isn’t that a single security source?

We want things simple, we want an easy solution and we don’t want to have to exert any real effort to achieve our security. We want others to do it for us yet we don’t want those others to have a close social and familia type relationship. We don’t want the effort and especially the responsibility, but we do want a disinterested and detached group of others to provide us protection and for little to nothing. 

We have to get real, we have to accept our responsibility and we have to take the actions necessary to achieve a layered security model and guess what, that begins with each and every one of us as individuals. We have to take responsibility for our actions as to what we do and how we do it or they are just going to clean us out and leave us broke and destitute. You cannot make others protect us with laws for those laws will simply make them angry and resentful, do you think they will go the distance for you - a complete and total stranger? 

Take a close look at what you do and how you do it using all those wonderful devices that make life so easy, because it is easy that gets us in trouble every single time. 

Nuff said … pull your head out of the sand and get layered!

Bibliography (Click the link)

p.s. there is a reason why software development needs a group to program over just one person; one person and even a group of persons cannot adequately program security all by themselves. 


Multiple vs. Singular Security Models

In a recent article one of the ads presented said, “Control the Chaos with a Single Security Solution.” Wow, that made me drop my bagel and choke on the drink of coffee I was partaking in when I saw the ad. 

It is a bit like the model the military started to take on when I was still the physical security person at a military installation, centralize their leadership into two “single” locations, one on the East Coast and one on the West Coast. I remember thinking about the art of war where to achieve a quick and decisive victory you cut the head off the chicken. In other words, put all your eggs in the East and/or West basket then let the enemy simply blow that leadership to hell and back. 

In the technological world a single source of security is convenient and easy but then the predators of the uVerse no longer have to spread out the attack to cover a variety of security models, they just focus o the one you just paid good money for - whalla, single point shopping for Crime, inc. What could be better.

It comes down to advertising to our laziness and comfort zone, to find just one way to supposedly have a “single” secure protection like that firewall and anti-virus program on your computer you think and “FEEL” is protecting your Internet presence. Guess what, according to some sources that firewall and AV barely protect us from about 5% or so of threats out there racing around our Internet searching, seeking and destroying our protections leaving us exposed and vulnerable. 

In a truly secure environment be it in the physical world, the inner brain world and the Internet electronic world, you need to have multiple layers of security to achieve some semblance of protection and safety and security. 

In the physical security world in which I worked you had to analyze and asses the threats you face and the value of loss toward your business, etc., to create a layered security that would not protect but rather make the effort to breach the security long and ardarous leaving the nefarious folks trying to break in wanting to move on to easier targets. Yes, I said not protect but slow the effort down because in truth there is not absolute protective security model, there is only creating a long delay to either redirect the thief’s efforts or to delay them enough that the models detection and alarms would give responders time to - respond effectively. 

Putting all my physical security into one central solution is foolishness nonsense. In my more high secure needs I had alarms, CCTV’s, Fencing, Human Security patrols (armed and authorized deadly force), human access controls, etc. to cause a great enough delay in attempts to circumvent so that armed security could respond, apprehend, detain and lock up criminals who attempted to gain access. 

Heck, even authorized access by employees had security layers beginning with background investigations, personal and professional references checks, legal investigations as to criminal records and activities then a dual badge system with entrapment areas for both human and vehicles, a badge verification and exchange by armed security and so on just to get to work. 

So, layered multiple security measures along with knowing who is maintaining and enforcing those security measures and an access control system to ensure that nefarious types are not allowed in. Yet, we will pay good money to have this unknown and completely strange human controlled SINGLE security solution to first, have the connection and social belief that will protect you as if you were family or a valued tribal member; second, who will exercise every possible way to protect you as if they were protecting themselves; third, whose agenda is not about money or company profit or board member profit margins, etc., and make you their sole reason for existence. 

So, we are going to pay strangers, complete and utter strangers who are selling a product for profit and strangers whose sole purpose is to sell the product at any costs maintaining profits, etc. regardless. Just send me five thousand dollars and I will personally guarantee it will remain safe and protected until you ask for it back. Now, just wait and see if you ever get that money back. 

It has been proven time and again that a single software program, like one very famous operating system, will protect you computer and data yet time and again the hackers of the world demonstrate, in short time (literally hours and minutes), that the so called secure OS can and is vulnerable and easily hacked. 

Isn’t that a single security source?

We want things simple, we want an easy solution and we don’t want to have to exert any real effort to achieve our security. We want others to do it for us yet we don’t want those others to have a close social and familia type relationship. We don’t want the effort and especially the responsibility, but we do want a disinterested and detached group of others to provide us protection and for little to nothing. 

We have to get real, we have to accept our responsibility and we have to take the actions necessary to achieve a layered security model and guess what, that begins with each and every one of us as individuals. We have to take responsibility for our actions as to what we do and how we do it or they are just going to clean us out and leave us broke and destitute. You cannot make others protect us with laws for those laws will simply make them angry and resentful, do you think they will go the distance for you - a complete and total stranger? 

Take a close look at what you do and how you do it using all those wonderful devices that make life so easy, because it is easy that gets us in trouble every single time. 

Nuff said … pull your head out of the sand and get layered!

Bibliography (Click the link)

Goodman, Marc. “Future Crimes: Everything is Connected, Everyone is Vulnerable and What We Can Do About It.” Doubleday. New York. 24 February 2015. 

p.s. there is a reason why software development needs a group to program over just one person; one person and even a group of persons cannot adequately program security all by themselves. 

Focus on the Real Threat

It seems the professionals are being misdirected toward things that are not all that critical to our security on the Internet/uVerse. It is not truly about the legal system although the legal system needs to get a grip on what they are asking. It’s about keeping the real threat out of our personal and financial businesses. The threat from the proverbial uVerse’s Crime, inc., that is where we need to focus our efforts in regard to iSD.

I’m not saying we can’t take a proactive posture toward terrorism and terrorists but in the overall scheme of things those guys, so far, are not as big a threat as the predator criminals building a huge billion dollar business using technology to fleece the masses of their identities and monies. Consider this, failing to protects everyone from the threat and repercussions of using technology to commit terrorism is huge, they make end of the world movies out of this stuff and it is closer to reality than you think. 

To those who hack, steal and cause mayhem using technology, remember there is a finite amount of money you can steal and if you go to far the whole system collapses and then your accumulated money and effort will also hit the wall. 


Bibliography (Click the link)

Goodman, Marc. “Future Crimes: Everything is Connected, Everyone is Vulnerable and What We Can Do About It.” Doubleday. New York. 24 February 2015.