Monday, November 30, 2015

IRS Releases First in a Series of Tax Security Tips

The Internal Revenue Service (IRS) has released the first in a series of tips intended to increase public awareness of how to protect personal and financial data online and at home. A new tip will be available each Monday through the start of the tax season in January, and will continue through the April tax deadline.


The first tip focuses on seven simple steps to secure your computer when conducting business online. US-CERT encourages users and administrators to review IRS Security Awareness Tax Tip Number 1 for additional information.

Sunday, November 29, 2015

Handmade Music Lovers Pens

Stunning Detail

These Music Lovers Pens are remarkable. The head is a drum, the clip is the neck of a guitar, keyboard keys for the center ring and a musical score for the tip.

I can custom make these in just about any color, a wide assortment of woods with Chrome or 24ct Gold.

Take a look!!! Old Mill Pens Music Collection

Old Mill Pens Music Collection

Sunday, November 22, 2015

Shop Handmade Pens

Old Mill Pens

Executive Pen for Sale

Saturday, July 4, 2015

Big Changes in Overtime Pay, Big Challenges for Companies | Corporate Counsel

This is a game-changer……

In a long-awaited announcement this week, the U.S. Department of Labor released new regulations requiring companies to give overtime pay to a whole new group of formerly exempt workers. Under these revisions to the Fair Labor Standards Act, it’s estimated that the rules will lead to time-and-a-half pay for all hours logged over the 40-hour workweek for nearly 5 million additional members of the U.S. workforce.

Big Changes in Overtime Pay, Big Challenges for Companies | Corporate Counsel

Thursday, July 2, 2015

Lax Network Administration: OPM hackers tapped the mother lode of espionage data | Ars Technica

Yet another lackadaisical network administrator has given ColdFusion a black-eye.
 
According to many published articles (link below) the Federal Office of Personnel Management (OPM) was a ColdFusion based application managing the data that was stolen by hackers. They were able to obtain the records of 14 million people who work for, applied for or provided services to the US Federal Government.
 
That is 5% of the adult population of the US. One out of twenty people (to keep this massive breach in perspective).
 
The cracked system was operating an older version of ColdFusion, one which used the Adobe JRun engine.
 
Adobe stopped using JRun over eight years ago moving to Apache Tomcat.
 
Eight years…. Amy Winehouse won a Grammy, Barack Obama was running for president, before Bernie Madoff was busted.
 
Yet the headline you will all see in computer security stories is how it is the fault of Adobe’s ColdFusion.
 
The story should not focus on the mark-up language of the application, but the underlining platform.
The server itself was not kept up-to-date.
 
If it had, the information of those fourteen-million of our neighbors and fellow Americans would not have fallen into the hands of the CHINEESE GOVERNMENT.
 
This information should have those who have purview over server farms and have been given the responsibility to keep them up-to-date a wake-up call.
 
Software companies and those who are creating the applications can only do so much to provide secure code. The servers and the supporting infrastructure is just as important as data encryption and session management.
 
“EPIC” fail—how OPM hackers tapped the mother lode of espionage data | Ars Technica

Wednesday, June 17, 2015

Encryption “would not have helped” at OPM, says DHS official | Ars Technica

 

I occurs to me that the individuals on the news channels and those in our government asking questions about the large data breach at OPM are asking the wrong questions.

One of the news channels was interviewing a guy who’s data had been stolen. He hadn’t worked for the federal government since 1992. What was obtained was his initial resume and the paperwork associated with hiring him along with security background check documents and subsequent work evaluations.

Since the data about this person hadn’t been relevant well over ten years that data should have been recognized as not vital to the current needs of the government and been put in an ‘At Rest’.

“Data At Rest” is a term that is sometimes used to refer to all data in computer storage while excluding data that is traversing a network or temporarily residing in computer memory to be read or updated. [REF: http://searchstorage.techtarget.com/definition/data-at-rest ]

With the reported amount of data that was taken we need to ask two things:

  1. How much of the data taken was actively being used for day-to-day operations of OPM (Office of Personnel Management).
  2. Of the data that was not being used to meet the immediate (or imitate) needs of OPM why was it still available on an accessible network?

The long-and-the-short of it is the information that was taken should not have been that readily available in the first place.

Encryption “would not have helped” at OPM, says DHS official | Ars Technica