Wednesday, October 16, 2019
Professionalism in Nursing Coursework Example | Topics and Well Written Essays - 6000 words
Professionalism in Nursing - Coursework Example From this report it is clear thatà clothing and conduct for students and practicing nurses were dictated strongly by dress codes and strict disciplinary protocols developed by hospital administrators in charge of nurses. Here, personality traits may have had negligible chance to emerge from the starch white uniforms and pulled back hair donned in a white cap. On the other hand, times have changed and most nursing students today are thrilled with the independence and career opportunities that have evolved for them at numerous levels, as well as those in advanced practice nursing. As the professional nursing arena expands and new roles develop, the professional nurse is expected to demonstrate respect for the faculty by continuing to don the traditional dress.à This study declares thatà there should be awareness to nurses that appearance makes a lasting impression on patients, contemporaries, and the general public. Although dress and appearance alone cannot guarantee success in a nursing job, they can at the same time assure letdown.à This is because patients do have their own expectations of a professional, including their personal preferences and generational influences. Since health care is a form of business, successful professionals must therefore attract a steady, growing patient population in order to survive. The professional nurse should therefore demonstrate respect for patients by developing relationships with them and projecting a positive public image that will help build a deep founded practice.... But these have become loosely adhered to. As a result, one finds nurses simply abandoning their traditional trade mark white uniform and substituting it with scrub suits and colorful jackets. Since nursing is becoming a professional practice, I will demonstrate respect to my peers by becoming more aware of how my appearance, behavior, and communication can influence the first impressions of others about me. I will therefore try to follow the dress code and the behavior expected of me as a professional nurse to the letter. Faculty In the past, clothing and conduct for students and practicing nurses were dictated strongly by dress codes and strict disciplinary protocols developed by hospital administrators in charge of nurses (Jacob, 1999). Here, personality traits may have had negligible chance to emerge from the starch white uniforms and pulled back hair donned in a white cap. On the other hand, times have changed and most nursing students today are thrilled with the independence and career opportunities that have evolved for them at numerous levels, as well as those in advanced practice nursing. As the professional nursing arena expands and new roles develop, the professional nurse is expected to demonstrate respect for the faculty by continuing to don the traditional dress. This is essentially because the professional dress and appearance continue to be very important facets of the nursing image especially within the faculty (Jacob, 1999). Patients As it has already been established, there should be awareness to nurses that appearance makes a lasting impression on patients, contemporaries, and the general public. Although dress and appearance alone cannot guarantee success in a nursing job, they can at the same time assure letdown
Tuesday, October 15, 2019
Essay assignment, inferencing Example | Topics and Well Written Essays - 750 words
Assignment, inferencing - Essay Example Set in the early twentieth century Ireland, the story is narrated from a third person point of view. The key conflicts that the plot of the story develops is that of Evelineââ¬â¢s current choices ââ¬â whether to stay at her home country and continue with her life as it is currently, or leave with her sailor boyfriend and chase the promises of a different, much rewarding but still uncertain future. James Joyce employs literary historicism to depict how life was in not only Ireland, but the entire Europe in the early twentieth centuries. The story is set in Ireland just immediately before the beginning of the first defining wars of that century. The country is characterized by a breakdown in social order which forms the core reason why the protagonist is trapped in the dilemma that she is in ââ¬â whether to leave her home and her country for the uncertain destination posed by the seas. The family as the foundational social pillar is in distress. It is for this reason that the protagonist wants to cut links with her immediate past by leaving behind her family in the hopes that a faraway place holds a much more promising future for her and her husband. The protagonist reflects on how his father treated his brothers and on the unenviable role that her mother played in the family. In a characteristic norm during that period, she results to blaming England and the Catholic Churc h for her current predicament. England had made unwelcomed advances into Ireland in the early twentieth century. It is also during this period that rebel groups like the Irish Republican Army to take arms against the excesses of the British. Two years after James Joyceââ¬â¢s fictional account in Eveline. The Irish mounted an armed uprising to force the British rule out of their country ââ¬â a timely response to the wishes of Eveline. The Catholic Church had also expanded its influence from Rome to
Learning Strategies and Information-Processing Development Essay Example for Free
Learning Strategies and Information-Processing Development Essay Learning can be simply defined as the process that leads to relatively permanent change in behavior or potential change in a personââ¬â¢s behavior. Learning makes one change the way they perceive the environment, react to stimuli and interact. Cognitive psychology is a very important branch of modern psychology. The main focus of this approach is the memory-how information is stored and retrieved. Several theories have been developed with regard to this subject such as the stage theory (Atkinson Shriffin, 1968). The stage theory model is widely accepted since it proposes that information is processed and stored in three sequential stages i.e. ââ¬Å"the sensory memory, short-term memory, and long-term memoryâ⬠(Atkinson Shriffin, 1968, p. 90). In addition to this model other accepted theories include levels-of-processing theory proposed by Craik and Lockhart (1972), the parallel-distributed processing model and the connectionistic model. This paper examines how attention, memory, recognition and knowledge are related to various learning strategies. In addition, the paper discusses how visual-perceptual, motor and language relate to information processing development. Information processing development As stated in the introduction above, cognitive psychology forms an integral part of the discipline of psychology. The most widely used theory is the stage theory whose focus is on how information is stored in memory. Information is processed in three stages and this is done in a serial and scholastic manner. Another important theory is the ââ¬Å"levels-of-processingâ⬠theory whose proposition is that the learner utilizes different levels of explanation as he or she processes in formation. A major advantage of the information-processing strategies is in their explicitness and accuracy in diving complex cognitive functions into distinct elements that can be easily studied. However, when it comes to analyzing cognition into its distinct parts; information processing fails to re-unite them into a general, comprehensive construct. In addition, most information processing tools such as computer models have lost touch with real-life learning experiences (Berk, 2009). Information processing approach towards cognition seeks to explain how the learner (children and adults) operate on the different types of information. Most scholars view the mind as a complex system (a type of computer) through which information flows and is manipulated. General models such as the store model by Atkinson and Shiffrin assume that information is stored in three parts of the brain for processing: ââ¬Å"the sensory register, short-term memory, and long-term memoryâ⬠(Berk, 2010, para.1). Craik and Lockhart (1972) level-of-processing model assumes that information is transferred from working memory to the long-term memory depending on the level processing. There exist several other information processing developmental models such as the Caseââ¬â¢s theory which is a reinterpretation of Piagetââ¬â¢s theory of information processing model. Case views cognitive development as the increase in information processing capacity as a result of brain development which can be linked to more efficient learning strategies. Connectionism on the other hand explains information processing development as a result of learning strategies such as computer-simulated strategies which enhance; inter-connectivity of processing units that are well stratified just like the neurological structure of the brain. Sieglerââ¬â¢s using his model of learning strategy choice argues that, learners always generate a number of strategies for problem solving, the more the experience, the more strategies are selected or discarded (Kail Cavanaugh, 2008). Attention is a critical factor when it comes to human thinking, it dictates the information that will be considered when undertaking a task. Attention is greatly enhanced during early and middle stages of childhood. Thus, improved attention makes one to be more adaptable, selective and organized. Enhanced cognitive reticence and efficacy of attentional learning strategies are pertinent to the fine-tuning of selective attention. The fine tuning of attentional learning strategies takes place in four stages: ââ¬Å"production deficiency, control deficiency, utilization deficiency, and effective strategy useâ⬠(para.2). Whenever there is a problem with attention students would develop learning disorders. The argument here is that, when a student is learning a new concept, their attention needs to be focused on the new concept.à If they fail to fully pay their attention, it means that they will have a serious problem with the learning of the new information (Kail Cavanaugh, 2008). Memory strategies are said to improve with age, as children continue to develop various methods such as, organization, and elaboration. This increases the likelihood of storing information in working memory and its consequential transfer to the long-term knowledge bank. Thus, over childhood stages and even in adolescence, studentsââ¬â¢ recall steadily improves as knowledge is continually amassed and its organization is improved effectively. Childrens metacognitive abilities usually change from passivity to activity. A more productive view of mental functioning increases with the increase in awareness of information processing strategies, cognitive aptitudes, and task variables. Self-regulation cognitively develops gradually during childhood and adolescence stages. Recently, scholars of information-processing have focused their attention towards academic learning of children (Berk, 2009). Visual-perceptual, motor and language relation to information processing development A visual-perceptual skill is simply the brainââ¬â¢s ability to process information as seen.à Previously, most scholars had assumed that a deficiency in visual-perceptual skills was directly linked to the malfunctioning of the eye.à That is having a poor physical vision or poor muscle control in the eye. However, the presence or absence of physical vision has nothing to do with visual perceptual. Instead, visual perceptual refers to the ability of the brain the receiving of visual information, its interpretation, organization, storage, and transmission Thus, if a studentââ¬â¢s brain is not properly storing information, recall will definitely be poor. This directly affects the studentââ¬â¢s ability to concentrate and read since he or she has a slow recall of words. The slowing down of recall can also have a negative impact on their mathematical abilities let alone their fluency in speech and reading (Smith 2004). Language and phonological processing abilities are affected by the studentââ¬â¢s ability to store, process, and retrieve information.à Usually language and phonological problems are rooted to reading disorders.à Many students with reading disorders have difficulty storing, processing, and retrieving information.à A normal studentââ¬â¢s left brain hemisphere becomes dominant when they are carrying out tasks involving language processing (Berk 2009). A studentââ¬â¢s motor skills are also an important factor when discussing about learning strategies.à Children will learn from their interaction with the environment; this ability is affected hindered by a childââ¬â¢s motor or verbal skills, a child will learn better when their motor skills are well developed.à This can be observed in a math class.à A conventional practice in the learning of fractions is the use of multiplication.à A student with a problem with their motor skills will have a problem with the use of manipulatives.à Thus they will definitely have it rough when it comes to the learning of fractions (Berk, 2010). Conclusion This paper argues that there exist several other information processing developmental models such as the Caseââ¬â¢s theory which is a reinterpretation of Piagetââ¬â¢s theory of information processing model. Case views cognitive development as the increase in information processing capacity as a result of brain development which can be linked to more efficient learning strategies. The most widely used theory is the stage theory whose focus is on how information is stored in memory. Learning strategies such as memory strategies are pertinent to the process of information development. Information processing approach towards cognition explains how the learner operates on various kinds of information. The mind is a complex system (a type of computer) through which information flows and is manipulated. Deficits in information processing skills have negative impacts on a studentââ¬â¢s ability to learn effectively. This is attributed to the reason that all learning is relatively cumulative.à Thus, problems in learning should be detected early in enough and solved otherwise; they would get worse with advancement of age.
Sunday, October 13, 2019
Presentation Of Iago In Othello English Literature Essay
Presentation Of Iago In Othello English Literature Essay The plot of the play Othello is that the Moorish soldier Othello and a young Venetian lady Desdemona secretly marry. Her father isnt happy by this secret ceremony and warns Othello that if she can deceive her own father she might some day do the same to him. Iago later uses Desdemona against Othello in the play. He does this because he is jealous of Othello who became promoted to the job he feels he should have got. To complete this plot of his, he speaks many lies and proceeds in many incidents to convince Othello that Desdemona is being disloyal to him by having an affair with another man-Cassio. In Act 1 Scene 2 Iago starts off speaking to Othello. He is trying to gain his trust by telling Othello all the things he has done wrong and all of his regrets. He speaks about him being with Desdemona and then he goes onto saying that he thinks she is betraying him. Iago is trying to make Othello suspect Desdemona for being unfaithful to him and gives Othello images he can picture in his head (which then relates back to when Othello saw Desdemona and Cassio dancing together). Cassio then walks in, this makes Iagos plan go even better for him even though it wasnt what he planned to happen. Cassio comes in asking Othello to go to Cyprus because the duke would like to have an appearance from him. Iago then says that Othello cannot go because he is married. Shakespeare has done this so Iago can make it look like Cassio is trying to send Othello away so he can be with Desdemona. In Act 1 Scene 3, Shakespeare has revealed Iagos entire plan. He is thinking aloud so the whole plot is revealed to us. It shows that Iago wants revenge on Othello because when he is speaking to Roderigo he says: I hate the Moor; Let us be conjunctive in our revenge against him. Then later in the scene he reveals his plan, saying that Desdemona is the love of his life and that she is his only weakness. So if she is made to seem that she is sleeping with Cassio then he will go to Iago and tell him he was right all along and thank him for realising it. If Iagos plan went to how he wanted, then this would mean that out of gratefulness for realising what he couldnt see, Othello would then do anything to repay him. In Act 2 Scene 1 Iago is again alone with Roderigo, they are speaking about Desdemona, and because Roderigo is so madly in love with her, Iago can still use this to his advantage. In this scene, Iago says first, I must tell thee this Desdemona is directly in love with him. Shakespeare is still showing how Iago can make things sound and how he can use the people he is manipulating. Iago then moves on to Othello and tries to gain his trust. He is trying to get Othello to trust him so he will later believe him about Desdemona sleeping with Cassio. In Act 2 Scene 3 Iago is with Cassio and Iago is trying to get Cassio drunk so he can make Cassio make stupid mistakes so his plan will be more convincing. Iago says If I can fasten but one cup upon him, with that which he hath drunk to-night already, hell be as full of quarrel and offence as my young mistress dog. Shakespeare has presented Iago in this way because he is discreetly making Cassio drink without him taking any notice of what he is doing. Iago has now given Cassio many cups of wine and Cassio becomes aggressive towards Montano, Iago then tells Roderigo to go and report to Othello of Cassios state, this is so Othello will loose all trust in Cassio for becoming so rowdy. Cassio says to Othello I pray you, pardon me; I cannot speak Othello now thinks that now he cannot trust him because he is easily persuaded. He now trusts Iago more because he was the one who supposedly stopped him getting out of control. Later in the scene, Iago is with Cassio, and Cassio is feeling like his life is a mess. Iago tells him to go and see Desdemona because she can sort out his life. Cassio has obviously gained Iagos trust because he takes his advice and goes to see her. He is desperate to sort his life out and will do anything to get it back in order. William Shakespeare has portrayed Iago as a scheming person who will do anything in order out of spite and jealousy. Iagos character can gain any persons trust in such a discreet way, he can give them advice and they will take it. This is why Iagos plan goes right because everyone believes him until last minute when it is too late to change things. The audience is prepared for Iagos character because you see his evil side, especially when he speaks his plan out aloud to the audience at the end of Act 1 Scene 3; he announces his jealousy and hate for Othello which makes you prepared for the ending.
Saturday, October 12, 2019
The Touch, The Feel Of Hemp-- The Fiber Of Our Lives :: essays research papers
The Touch, The Feel of Hemp-- The Fiber of Our Lives Imagine how useful a Swiss Army Knife with more than 2500 functions would be if it was compact enough to be manageable. And imagine that this ââ¬Å"knifeâ⬠could help solve some very important problems that plague our environment as well as our society. Now think if the production of this tool was to be banned by the government. There would have to be some very strong reasons for the government to deny this extremely useful product to the people it governs. If the reasons for this interdiction were not very strong it would be absurd to think that the ban would last for an extended period of time. Well some people will be surprised to know that this very injustice is happening as we speak right here in our wonderful United States of America. The injustice I am describing is our governments ban on the cultivation of the hemp plant in our country. In this article I hope to inform the uninformed and reinform the misinformed on the subject of the hemp plant and how it would benefit us to encourage its widespread production. Industrial hemp is only a cousin of the drug producing plant, marijuana, but as far as the government is concerned they are the same things. Even though there is no chance a person could get high from smoking hemp, the government still prohibits its growth. Hemp does contain some THC, the chemical in pot that makes you high, but only a trace amount. To get the same buzz that a person would get from smoking one marijuana cigarette you would have to smoke twenty or thirty rolled from hemp and you would have to do in about the same amount of time. Common sense tells us that smoking this much of anything in a short amount of time would make you sick. If you smoke some industrial hemp you will only get a headache, and if you smoke more you will only get a bigger headache. The government has the same reason for the banning marijuana as they do for the ban on hemp, when hemp only contains trace amounts of the intoxicants that makes it illegal. Hemp can be compared to non-alcoholic beer, nut meg, cough syrup and mouthwash. NA beer and mouthwash contain alcohol, but nobody drinks them to get drunk. Nutmeg and cough syrup contain some psychoactive substances, but nobody uses these common products to get high.
Friday, October 11, 2019
Boyz in the Hood Essay
Boyz in the Hood is a vivid video representation of what life is like for those who live in the hood. There are two families that were the focus within the movie: The Styles and The Bakers. The director of the movie, John Singleton, wants his viewers to compare the lives of the individuals within the movie to their own lives so there could be a change in our society. He discretely expresses the importance of a good upbringing by a fatherly figure. I believe that this made the difference with the two families. It made all the difference to be brought up in the right circumstances. The two families were brought up in a lower class part of Los Angeles. The area is a low income neighborhood with the homes in need of much repair. In the movie there is un-cut grass and un-raked leaves cumbering the ground. The paint on the walls is chipped and dull. The movie shows Tre at a young age sent to his father Furious. Tre and the Bakers children, Doughboy and Ricky become good friends throughout their teen years. It is interesting that these kids would get into so much trouble by just trying to find things to keep them occupied. In one scene of the movie, Ricky took a football as they were walking around town. A group of teenagers eyed the ball and desired to take it. With a little contention they stole the ball. After a small conflict, they got the ball back. There were many differences between the two families. The Baker family did not have a male figure in the home. The mother, Brenda tended to take care of the kids on her own. In the Styles home there was no father because Treââ¬â¢s mom and dad, Reva and Furious separated. Even though Furious did not live with his family, he was around to help Tre become a man. When Treââ¬â¢ was in the middle years of elementary school, he made an agreement with his parents that if he got into trouble, he would be sent to live with his dad. Indeed that ended up happening and he lived with his father till he was around 20 years old. During these years, he learned many things that helped prepare him for life. There was one pivotal point within the move that helped illustrate this. On a clear, beautiful day Tre and Furious went fishing. There was an ulterior motive to spending that type of quality time. It gave Furious and Tre the opportunity to communicate. Furious could give insight and ask Tre questions. Furious states, ââ¬Å"Black man aint got no place in the army. â⬠He offers his fatherly council to impress Tre not to join the army. Also within the boat Furious asks Tre what he knows about sex. After a short remark from Tre, his dad says, ââ¬Å"Only a real man can raise children. â⬠This comment made a big influence on Tre whether he knew it or not. Through his teen years, he maintained his virtue. Doughboy and Ricky Styles on the other hand did not have the fatherly council that Furious offered to Tre. They were left to themselves to learn how to become men. Their mother, Brenda, was not the best example for them while they were children. She would call them names that I would never imagine would come out of a motherââ¬â¢s mouth. The lack of respect for women is a good indicator of the lack of fatherly influence for the Styles. Doughboy thought he was tough. He thought that he was superior to all around him. His attitude might have contributed to him being in jail. After getting out of jail, he had nothing going for him. He would hang around the porch with his thug buddies. Ricky was in a better frame of mind with regards to his future. He wanted to get an education while playing football for the University of California in Loa Angeles. I believe that Ricky turned out better because Tre became his fatherly figure. Ricky and Tre were best friends. They wanted each other to succeed in life and would do anything for each other. While Tre first moved in with his dad, Furious blurted a statement that came true many years later. He says, ââ¬Å"youââ¬â¢re gonna see how they end up too. â⬠He was referring to the Styles children who were young at the time. There is a fulfillment of this prophesy at the end of the movie. Both Ricky and Doughboy end up being tragically shot and killed. I really had a hard time with the fact that Ricky died. Despite his upbringing, he had things going for him. The examples that were set forth within the movie vividly gives food for thought of what we can do to make a difference. For Tre, he was fortunate to have well educated parents that showed good examples. The Styles children lacked these aspects and it played an important roll on how they turned out. Therefore, if the movie accurately portrays the outcome of such circumstances, then we need to make a difference in society by starting in the home. By raising children in an environment that will help them make wise critical decisions, I believe this will accomplish what director John Shingleton wanted to convey to his viewers.
Thursday, October 10, 2019
The Art of War
Sun-Tzu Wu is the reputed author of the Chinese classic Ping-fa (The Art of War), written approximately 475-221 B. C. Penned at a time when China was divided into six or seven states that often resorted to war with each other in their struggles for supremacy, it is a systematic guide to strategy and tactics for rulers and commanders. In doing business on the Internet during this time of rampant computer viruses and hacker attacks it may be wise for us to follow some of his tactical principles in order to insure the safety of ourselves and our future clients. Know your enemy and know yourself; in a hundred battles, you will never be defeated. When you are ignorant of the enemy but know yourself, your chances of winning or losing are equal. If ignorant both of your enemy and of yourself, you are sure to be defeated in every battle. In a chilling article entitled Big Brother is Watching Bob Sullivan of MSNBC recounts a tale during a recent visit to London: Only moments after stepping into the Webshack Internet cafe in Londonâ⬠s Soho neighborhood, ââ¬Å"Markâ⬠asked me what I thought of George W. Bush and Al Gore. ââ¬Å"I wouldnâ⬠t want Bush running things,â⬠he said. ââ¬Å"Because he canâ⬠t run his Web site.â⬠Then he showed me a variety of ways to hack Bushâ⬠s Web sites. That was just the beginning of a far-reaching chat during which the group nearly convinced me Big Brother is in fact here in London. ââ¬Å"I donâ⬠t know if he can run the free world,â⬠Mark said. ââ¬Å"He canâ⬠t keep the Texas banking system computers secure. So-called ââ¬Å"2600â⬠clubs are a kind of hacker ââ¬Å"boy scoutâ⬠organization ââ¬â there are local 2600 chapters all around the globe. It is in this environment, and this mindset, that Londonâ⬠s hackers do their work. They do not analyze computer systems and learn how to break them out of spite, or some childish need to destroy: Mark and friends see themselves as merely accumulating knowledge that could be used in self-defense if necessary. They are the citizenâ⬠s militia, the Freedom Fighters of the Information Age, trying to stay one step ahead of technology that could one day be turned against them. Jon-K Adams in his treatise entitled Hacker Ideology (aka Hacking Freedom) states that hackers have been called both techno-revolutionaries and heroes of the computer revolution. Hacking ââ¬Å"has become a cultural icon about decentralized power.â⬠But for all that, hackers are reluctant rebels. They prefer to fight with code than with words. And they would rather appear on the net than at a news conference. Status in the hacker world cannot be granted by the general public: it takes a hacker to know and appreciate a hacker. That's part of the hacker's revolutionary reluctance; the other part is the news media's slant toward sensationalism, such as, ââ¬Å"A cyberspace dragnet snared fugitive hacker.â⬠The public tends to think of hacking as synonymous with computer crime, with breaking into computers and stealing and destroying valuable data. As a result of this tabloid mentality, the hacker attempts to fade into the digital world, where he-and it is almost always he-has a place if not a! In his self-conception, the hacker is not a criminal, but rather a ââ¬Å"person who enjoys exploring the details of programmable systems and how to stretch their capabilities.â⬠Which means that he is not necessarily a computer geek. The hacker defines himself in terms that extend beyond the computer, as an ââ¬Å"expert or enthusiast of any kind. One might be an astronomy hackerâ⬠(Jargon File). So in the broadest sense of his self-conception, the hacker hacks knowledge; he wants to know how things work, and the computer-the prototypical programmable system-simply offers more complexity and possibility, and thus more fascination, than most other things. >From this perspective, hacking appears to be a harmless if nerdish enthusiasm. But at the same time, this seemingly innocent enthusiasm is animated by an ideology that leads to a conflict with civil authority. The hacker is motivated by the belief that the search for knowledge is an end in itself and should be unrestricted. But invariably, when a hacker explores programmable systems, he encounters barriers that bureaucracies impose in the name of security. For the hacker, these security measures become arbitrary limits placed on his exploration, or in cases that often lead to confrontation, they become the focus of further explorations: for the hacker, security measures simply represent a more challenging programmable system. As a result, when a hacker explores such systems, he hacks knowledge, but ideologically he hacks the freedom to access knowledge. Political hackers are another group considering themselves modern freedom fighters. ââ¬Å"Hacktivistsâ⬠have officially moved from nerdish extremists to become the political protest visionaries of the digital age, a meeting at the Institute of Contemporary Arts in London was told on Thursday. Paul Mobbs, an experienced Internet activist and anti-capitalist protestor, will tell attendees that the techniques used by politically minded computer hackers ââ¬â from jamming corporate networks and sending email viruses to defacing Web sites ââ¬â has moved into the realm of political campaigning. Mobbs says that the term ââ¬Å"Hacktivismâ⬠has been adopted by so many different groups, from peaceful Net campaigners to Internet hate groups, that it is essentially meaningless, but claims that Internet protest is here to stay. ââ¬Å"It has a place, whether people like it or not,â⬠says Mobbs. Steve Mizrach in his 1997 dissertation entitled Is there a Hacker Ethic for 90s Hackers? delves into this subject in great detail. He describes the divergent groups of hackers and explains their modus operandi: I define the computer underground as members of the following six groups. Sometimes I refer to the CU as ââ¬Å"90s hackersâ⬠or ââ¬Å"new hackers,â⬠as opposed to old hackers, who are hackers (old sense of the term) from the 60s who subscribed to the original Hacker Ethic. à § Hackers (Crackers, system intruders) ââ¬â These are people who attempt to penetrate security systems on remote computers. This is the new sense of the term, whereas the old sense of the term simply referred to a person who was capable of creating hacks, or elegant, unusual, and unexpected uses of technology. Typical magazines (both print and online) read by hackers include 2600 and Iron Feather Journal. à § Phreaks (Phone Phreakers, Blue Boxers) ââ¬â These are people who attempt to use technology to explore and/or control the telephone system. Originally, this involved the use of ââ¬Å"blue boxesâ⬠or tone generators, but as the phone company began using digital instead of electro-mechanical switches, the phreaks became more like hackers. Typical magazines read by Phreaks include Phrack, Line Noize, and New Fone Express. à § Virus writers (also, creators of Trojans, worms, logic bombs) ââ¬â These are people who write code which attempts to a) reproduce itself on other systems without authorization and b) often has a side effect, whether that be to display a message, play a prank, or trash a hard drive. Agents and spiders are essentially ââ¬Ëbenevolent' virii, raising the question of how underground this activity really is. Typical magazines read by Virus writers include 40HEX. à § Pirates ââ¬â Piracy is sort of a non-technical matter. Originally, it involved breaking copy protection on software, and this activity was called ââ¬Å"cracking.â⬠Nowadays, few software vendors use copy protection, but there are still various minor measures used to prevent the unauthorized duplication of software. Pirates devote themselves to thwarting these things and sharing commercial software freely with their friends. They usually read Pirate Newsletter and Pirate magazine. à § Cypherpunks (cryptoanarchists) ââ¬â Cypherpunks freely distribute the tools and methods for making use of strong encryption, which is basically unbreakable except by massive supercomputers. Because the NSA and FBI cannot break strong encryption (which is the basis of the PGP or Pretty Good Privacy), programs that employ it are classified as munitions, and distribution of algorithms that make use of it is a felony. Some cryptoanarchists advocate strong encryption as a tool to completely evade the State, by preventing any access whatsoever to financial or personal information. They typically read the Cypherpunks mailing list. à § Anarchists ââ¬â are committed to distributing illegal (or at least morally suspect) information, including but not limited to data on bombmaking, lockpicking, pornography, drug manufacturing, pirate radio, and cable and satellite TV piracy. In this parlance of the computer underground, anarchists are less likely to advocate the overthrow of government than the simple refusal to obey restrictions on distributing information. They tend to read Cult of the Dead Cow (CDC) and Activist Times Incorporated (ATI). à § Cyberpunk ââ¬â usually some combination of the above, plus interest in technological self-modification, science fiction of the Neuromancer genre, and interest in hardware hacking and ââ¬Å"street tech.â⬠A youth subculture in its own right, with some overlaps with the ââ¬Å"modern primitiveâ⬠and ââ¬Å"raverâ⬠subcultures. So should we fear these geeky little mischief-makers? The New York Post revealed recently that a busboy allegedly managed to steal millions of dollars from the worldâ⬠s richest people by stealing their identities and tricking credit agencies and brokerage firms. In his article describing this event Bob Sullivan says, ââ¬Å"Abraham Abdallah, I think, did us all a favor, for he has exposed as a sham the security at the worldâ⬠s most important financial institutions.â⬠The same two free e-mail addresses were used to request financial transfers for six different wealthy Merrill Lynch clients, according to the Post story. Merrill Lynch didnâ⬠t notice? Why would Merrill accept any transfer requests, indeed take any financial communication seriously at all, from a free, obviously unverified anonymous e-mail account? Iâ⬠m alarmed by the checks and balances that must be in place at big New York brokerage firms. Rather than being a story about a genius who almost got away, this is simply one more story of easy identity theft amid a tidal wave of similar crimes. The Federal Trade Commission has received 40,000 complaints of identity theft since it started keeping track two years ago, but the agency is certain that represents only a fraction of real victims. This is a serious problem, long ignored by the industry. If fact, just last year the credit industry beat back a congressional bill known as The Identity Theft Protection Act, claiming it would be too expensive for them. ââ¬Å"Clearly there has to be more leveling of the playing field. We have to hold banks and credit unions accountable.â⬠Last month the U.S. Federal Bureau of Investigation (FBI) was again warning electronic-commerce Web sites to patch their Windows-based systems to protect their data against hackers. The FBI's National Infrastructure Protection Center (NIPC) has coordinated investigations over the past several months into organized hacker activities targeting e-commerce sites. More than 40 victims in 20 states have been identified in the ongoing investigations, which have included law enforcement agencies outside the United States and private sector officials. The investigations have uncovered several organized hacker groups from Russia, the Ukraine, and elsewhere in Eastern Europe that have penetrated U.S. e-commerce and online banking computer systems by exploiting vulnerabilities in the Windows NT operating system, the statement said. Microsoft has released patches for these vulnerabilities, which can be downloaded from Microsoft's Web site for free. Once the hackers gain access, they download proprietary information, customer databases, and credit card information, according to the FBI. The hackers subsequently contact the company and attempt to extort money by offering to patch the system and by offering to protect the company's systems from exploitation by other hackers. The hackers tell the victim that without their services they cannot guarantee that other hackers will not access their networks and post stolen credit card information and details about the site's security vulnerability on the Internet. If the company does not pay or hire the group for its security services, the threats escalate, the FBI said. Investigators also believe that in some instances the credit card information is being sold to organized crime groups. Defend yourself when you cannot defeat the enemy, and attack the enemy when you can. Scott Culp in a detailed list of security precautions on Microsoftâ⬠s Web page suggests that there are ten immutable laws of security. Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore. It's an unfortunate fact of computer science: when a computer program runs, it will do what it's programmed to do, even if it's programmed to be harmful. When you choose to run a program, you are making a decision to turn over control of your computer to it. That's why it's important to never run, or even download, a program from an untrusted source ââ¬â and by ââ¬Å"sourceâ⬠, I mean the person who wrote it, not the person who gave it to you. Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore. In the end, an operating system is just a series of ones and zeroes that, when interpreted by the processor, cause the machine to do certain things. Change the ones and zeroes, and it will do something different. To understand why, consider that operating system files are among the most trusted ones on the computer, and they generally run with system-level privileges. That is, they can do absolutely anything. Among other things, they're trusted to manage user accounts, handle password changes, and enforce the rules governing who can do what on the computer. If a bad guy can change them, the now-untrustworthy files will do his bidding, and there's no limit to what he can do. He can steal passwords, make himself an administrator on the machine, or add entirely new functions to the operating system. To prevent this type of attack, make sure that the system files (and the registry! , for that matter) are well protected. Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore. He could mount the ultimate low-tech denial of service attack, and smash your computer with a sledgehammer. à § He could unplug the computer, haul it out of your building, and hold it for ransom. à § He could boot the computer from a floppy disk, and reformat your hard drive. But wait, you say, I've configured the BIOS on my computer to prompt for a password when I turn the power on. No problem ââ¬â if he can open the case and get his hands on the system hardware, he could just replace the BIOS chips. (Actually, there are even easier ways). à § He could remove the hard drive from your computer, install it into his computer, and read it. à § He could make a duplicate of your hard drive and take it back his lair. Once there, he'd have all the time in the world to conduct brute-force attacks, such as trying every possible logon password. Programs are available to automate this and, given enough time, it's almost certain that he would succeed. Once that happens, Laws #1 and #2 above apply à § He could replace your keyboard with one that contains a radio transmitter. He could then monitor everything you type, including your password. Always make sure that a computer is physically protected in a way that's consistent with its value ââ¬â and remember that the value of a machine includes not only the value of the hardware itself, but the value of the data on it, and the value of the access to your network that a bad guy could gain. At a minimum, business-critical machines like domain controllers, database servers, and print/file servers should always be in a locked room that only people charged with administration and maintenance can access. But you may want to consider protecting other machines as well, and potentially using additional protective measures. If you travel with a laptop, it's absolutely critical that you protect it. The same features that make laptops great to travel with ââ¬â small size, light weight, and so forth ââ¬â also make them easy to steal. There are a variety of locks and alarms available for laptops, and some models let you remove the hard drive and carry it with you. You also can use features like the Encrypting File System in Windows 2000 to mitigate the damage if someone succeeded in stealing the computer. But the only way you can know with 100% certainty that your data is safe and the hardware hasn't been tampered with is to keep the laptop on your person at all times while traveling. Law #4: If you allow a bad guy to upload programs to your web site, it's not your web site any more. This is basically Law #1 in reverse. In that scenario, the bad guy tricks his victim into downloading a harmful program onto his machine and running it. In this one, the bad guy uploads a harmful program to a machine and runs it himself. Although this scenario is a danger anytime you allow strangers to connect to your machine, web sites are involved in the overwhelming majority of these cases. Many people who operate web sites are too hospitable for their own good, and allow visitors to upload programs to the site and run them. As we've seen above, unpleasant things can happen if a bad guy's program can run on your machine. If you run a web site, you need to limit what visitors can do. You should only allow a program on your site if you wrote it yourself, or if you trust the developer who wrote it. But that may not be enough. If your web site is one of several hosted on a shared server, you need to be extra careful. If a bad guy can compromise one of the other sites on the server, it's possible he could extend his control to the server itself, in which case he could control all of the sites on it ââ¬â including yours. If you're on a shared server, it's important to find out what the server administrator's policies are. Law #5: Weak passwords trump strong security. The purpose of having a logon process is to establish who you are. Once the operating system knows who you are, it can grant or deny requests for system resources appropriately. If a bad guy learns your password, he can log on as you. In fact, as far as the operating system is concerned, he is you. Whatever you can do on the system, he can do as well, because he's you. Maybe he wants to read sensitive information you've stored on your computer, like your email. Maybe you have more privileges on the network than he does, and being you will let him do things he normally couldn't. Or maybe he just wants to do something malicious and blame it on you. In any case, it's worth protecting your credentials. Always use a password ââ¬â it's amazing how many accounts have blank passwords. And choose a complex one. Don't use your dog's name, your anniversary date, or the name of the local football team. And don't use the word ââ¬Å"passwordâ⬠! Pick a password that has a mix of upper- and lower-case letters, number, punctuation marks, and so forth. Make it as long as possible. And change it often. Once you've picked a strong password, handle it appropriately. Don't write it down. If you absolutely must write it down, at the very least keep it in a safe or a locked drawer ââ¬â the first thing a bad guy who's hunting for passwords will do is check for a yellow sticky note on the side of your screen, or in the top desk drawer. Don't tell anyone what your password is. Remember what Ben Franklin said: two people can keep a secret, but only if one of them is dead. Finally, consider using something stronger than passwords to identify yourself to the system. Windows 2000, for instance, supports the use of smart cards, which significantly strengthens the identity checking the system can perform. You may also want to consider biometric products like fingerprint and retina scanners. Law #6: A machine is only as secure as the administrator is trustworthy. Every computer must have an administrator: someone who can install software, configure the operating system, add and manage user accounts, establish security policies, and handle all the other management tasks associated with keeping a computer up and running. By definition, these tasks require that he have control over the machine. This puts the administrator in a position of unequalled power. An untrustworthy administrator can negate every other security measure you've taken. He can change the permissions on the machine, modify the system security policies, install malicious software, add bogus users, or do any of a million other things. He can subvert virtually any protective measure in the operating system, because he controls it. Worst of all, he can cover his tracks. If you have an untrustworthy administrator, you have absolutely no security. When hiring a system administrator, recognize the position of trust that administrators occupy, and only hire people who warrant that trust. Call his references, and ask them about his previous work record, especially with regard to any security incidents at previous employers. If appropriate for your organization, you may also consider taking a step that banks and other security-conscious companies do, and require that your administrators pass a complete background check at hiring time, and at periodic intervals afterward. Whatever criteria you select, apply them across the board. Don't give anyone administrative privileges on your network unless they've been vetted ââ¬â and this includes temporary employees and contractors, too. Next, take steps to help keep honest people honest. Use sign-in/sign-out sheets to track who's been in the server room. (You do have a server room with a locked door, right? If not, re-read Law #3). Implement a ââ¬Å"two personâ⬠rule when installing or upgrading software. Diversify management tasks as much as possible, as a way of minimizing how much power any one administrator has. Also, don't use the Administrator account ââ¬â instead, give each administrator a separate account with administrative privileges, so you can tell who's doing what. Finally, consider taking steps to make it more difficult for a rogue administrator to cover his tracks. For instance, store audit data on write-only media, or house System A's audit data on System B, and make sure that the two systems have different administrators. The more accountable your administrators are, the less likely you are to have problems. Law #7: Encrypted data is only as secure as the decryption key. Suppose you installed the biggest, strongest, most secure lock in the world on your front door, but you put the key under the front door mat. It wouldn't really matter how strong the lock is, would it? The critical factor would be the poor way the key was protected, because if a burglar could find it, he'd have everything he needed to open the lock. Encrypted data works the same way ââ¬â no matter how strong the cryptoalgorithm is, the data is only as safe as the key that can decrypt it. Many operating systems and cryptographic software products give you an option to store cryptographic keys on the computer. The advantage is convenience ââ¬â you don't have to handle the key ââ¬â but it comes at the cost of security. The keys are usually obfuscated (that is, hidden), and some of the obfuscation methods are quite good. But in the end, no matter how well-hidden the key is, if it's on the machine it can be found. It has to be ââ¬â after all, the software can find it, so a sufficiently-motivated bad guy could find it, too. Whenever possible, use offline storage for keys. If the key is a word or phrase, memorize it. If not, export it to a floppy disk, make a backup copy, and store the copies in separate, secure locations. Law #8: An out of date virus scanner is only marginally better than no virus scanner at all. Virus scanners work by comparing the data on your computer against a collection of virus ââ¬Å"signaturesâ⬠. Each signature is characteristic of a particular virus, and when the scanner finds data in a file, email, or elsewhere that matches the signature, it concludes that it's found a virus. However, a virus scanner can only scan for the viruses it knows about. It's vital that you keep your virus scanner's signature file up to date, as new viruses are created every day. The problem actually goes a bit deeper than this, though. Typically, a new virus will do the greatest amount of damage during the early stages of its life, precisely because few people will be able to detect it. Once word gets around that a new virus is on the loose and people update their virus signatures, the spread of the virus falls off drastically. The key is to get ahead of the curve, and have updated signature files on your machine before the virus hits. Virtually every maker of anti-virus software provides a way to get free updated signature files from their web site. In fact, many have ââ¬Å"pushâ⬠services, in which they'll send notification every time a new signature file is released. Use these services. Also, keep the virus scanner itself ââ¬â that is, the scanning software ââ¬â updated as well. Virus writers periodically develop new techniques that require that the scanners change how they do their work. Law #9: Absolute anonymity isn't practical, in real life or on the web. All human interaction involves exchanging data of some kind. If someone weaves enough of that data together, they can identify you. Think about all the information that a person can glean in just a short conversation with you. In one glance, they can gauge your height, weight, and approximate age. Your accent will probably tell them what country you're from, and may even tell them what region of the country. If you talk about anything other than the weather, you'll probably tell them something about your family, your interests, where you live, and what you do for a living. It doesn't take long for someone to collect enough information to figure out who you are. If you crave absolute anonymity, your best bet is to live in a cave and shun all human contact. The same thing is true of the Internet. If you visit a web site, the owner can, if he's sufficiently motivated, find out who you are. After all, the ones and zeroes that make up the web session have be able to find their way to the right place, and that place is your computer. There are a lot of measures you can take to disguise the bits, and the more of them you use, the more thoroughly the bits will be disguised. For instance, you could use network address translation to mask your actual IP address, subscribe to an anonymizing service that launders the bits by relaying them from one end of the ether to the other, use a different ISP account for different purposes, surf certain sites only from public kiosks, and so on. All of these make it more difficult to determine who you are, but none of them make it impossible. Do you know for certain who operates the anonymizing service? Maybe it's the same person who owns the web site you just visited! Or what about that innocuous web ! site you visited yesterday, that offered to mail you a free $10 off coupon? Maybe the owner is willing to share information with other web site owners. If so, the second web site owner may be able to correlate the information from the two sites and determine who you are. Does this mean that privacy on the web is a lost cause? Not at all. What it means is that the best way to protect your privacy on the Internet is the same as the way you protect your privacy in normal life ââ¬â through your behavior. Read the privacy statements on the web sites you visit, and only do business with ones whose practices you agree with. If you're worried about cookies, disable them. Most importantly, avoid indiscriminate web surfing ââ¬â recognize that just as most cities have a bad side of town that's best avoided, the Internet does too. But if it's complete and total anonymity you want, better start looking for that cave. The Art of War Sun-Tzu Wu is the reputed author of the Chinese classic Ping-fa (The Art of War), written approximately 475-221 B. C. Penned at a time when China was divided into six or seven states that often resorted to war with each other in their struggles for supremacy, it is a systematic guide to strategy and tactics for rulers and commanders. In doing business on the Internet during this time of rampant computer viruses and hacker attacks it may be wise for us to follow some of his tactical principles in order to insure the safety of ourselves and our future clients. Know your enemy and know yourself; in a hundred battles, you will never be defeated. When you are ignorant of the enemy but know yourself, your chances of winning or losing are equal. If ignorant both of your enemy and of yourself, you are sure to be defeated in every battle. In a chilling article entitled Big Brother is Watching Bob Sullivan of MSNBC recounts a tale during a recent visit to London: Only moments after stepping into the Webshack Internet cafe in Londonâ⬠s Soho neighborhood, ââ¬Å"Markâ⬠asked me what I thought of George W. Bush and Al Gore. ââ¬Å"I wouldnâ⬠t want Bush running things,â⬠he said. ââ¬Å"Because he canâ⬠t run his Web site.â⬠Then he showed me a variety of ways to hack Bushâ⬠s Web sites. That was just the beginning of a far-reaching chat during which the group nearly convinced me Big Brother is in fact here in London. ââ¬Å"I donâ⬠t know if he can run the free world,â⬠Mark said. ââ¬Å"He canâ⬠t keep the Texas banking system computers secure. So-called ââ¬Å"2600â⬠clubs are a kind of hacker ââ¬Å"boy scoutâ⬠organization ââ¬â there are local 2600 chapters all around the globe. It is in this environment, and this mindset, that Londonâ⬠s hackers do their work. They do not analyze computer systems and learn how to break them out of spite, or some childish need to destroy: Mark and friends see themselves as merely accumulating knowledge that could be used in self-defense if necessary. They are the citizenâ⬠s militia, the Freedom Fighters of the Information Age, trying to stay one step ahead of technology that could one day be turned against them. Jon-K Adams in his treatise entitled Hacker Ideology (aka Hacking Freedom) states that hackers have been called both techno-revolutionaries and heroes of the computer revolution. Hacking ââ¬Å"has become a cultural icon about decentralized power.â⬠But for all that, hackers are reluctant rebels. They prefer to fight with code than with words. And they would rather appear on the net than at a news conference. Status in the hacker world cannot be granted by the general public: it takes a hacker to know and appreciate a hacker. That's part of the hacker's revolutionary reluctance; the other part is the news media's slant toward sensationalism, such as, ââ¬Å"A cyberspace dragnet snared fugitive hacker.â⬠The public tends to think of hacking as synonymous with computer crime, with breaking into computers and stealing and destroying valuable data. As a result of this tabloid mentality, the hacker attempts to fade into the digital world, where he-and it is almost always he-has a place if not a! In his self-conception, the hacker is not a criminal, but rather a ââ¬Å"person who enjoys exploring the details of programmable systems and how to stretch their capabilities.â⬠Which means that he is not necessarily a computer geek. The hacker defines himself in terms that extend beyond the computer, as an ââ¬Å"expert or enthusiast of any kind. One might be an astronomy hackerâ⬠(Jargon File). So in the broadest sense of his self-conception, the hacker hacks knowledge; he wants to know how things work, and the computer-the prototypical programmable system-simply offers more complexity and possibility, and thus more fascination, than most other things. >From this perspective, hacking appears to be a harmless if nerdish enthusiasm. But at the same time, this seemingly innocent enthusiasm is animated by an ideology that leads to a conflict with civil authority. The hacker is motivated by the belief that the search for knowledge is an end in itself and should be unrestricted. But invariably, when a hacker explores programmable systems, he encounters barriers that bureaucracies impose in the name of security. For the hacker, these security measures become arbitrary limits placed on his exploration, or in cases that often lead to confrontation, they become the focus of further explorations: for the hacker, security measures simply represent a more challenging programmable system. As a result, when a hacker explores such systems, he hacks knowledge, but ideologically he hacks the freedom to access knowledge. Political hackers are another group considering themselves modern freedom fighters. ââ¬Å"Hacktivistsâ⬠have officially moved from nerdish extremists to become the political protest visionaries of the digital age, a meeting at the Institute of Contemporary Arts in London was told on Thursday. Paul Mobbs, an experienced Internet activist and anti-capitalist protestor, will tell attendees that the techniques used by politically minded computer hackers ââ¬â from jamming corporate networks and sending email viruses to defacing Web sites ââ¬â has moved into the realm of political campaigning. Mobbs says that the term ââ¬Å"Hacktivismâ⬠has been adopted by so many different groups, from peaceful Net campaigners to Internet hate groups, that it is essentially meaningless, but claims that Internet protest is here to stay. ââ¬Å"It has a place, whether people like it or not,â⬠says Mobbs. Steve Mizrach in his 1997 dissertation entitled Is there a Hacker Ethic for 90s Hackers? delves into this subject in great detail. He describes the divergent groups of hackers and explains their modus operandi: I define the computer underground as members of the following six groups. Sometimes I refer to the CU as ââ¬Å"90s hackersâ⬠or ââ¬Å"new hackers,â⬠as opposed to old hackers, who are hackers (old sense of the term) from the 60s who subscribed to the original Hacker Ethic. à § Hackers (Crackers, system intruders) ââ¬â These are people who attempt to penetrate security systems on remote computers. This is the new sense of the term, whereas the old sense of the term simply referred to a person who was capable of creating hacks, or elegant, unusual, and unexpected uses of technology. Typical magazines (both print and online) read by hackers include 2600 and Iron Feather Journal. à § Phreaks (Phone Phreakers, Blue Boxers) ââ¬â These are people who attempt to use technology to explore and/or control the telephone system. Originally, this involved the use of ââ¬Å"blue boxesâ⬠or tone generators, but as the phone company began using digital instead of electro-mechanical switches, the phreaks became more like hackers. Typical magazines read by Phreaks include Phrack, Line Noize, and New Fone Express. à § Virus writers (also, creators of Trojans, worms, logic bombs) ââ¬â These are people who write code which attempts to a) reproduce itself on other systems without authorization and b) often has a side effect, whether that be to display a message, play a prank, or trash a hard drive. Agents and spiders are essentially ââ¬Ëbenevolent' virii, raising the question of how underground this activity really is. Typical magazines read by Virus writers include 40HEX. à § Pirates ââ¬â Piracy is sort of a non-technical matter. Originally, it involved breaking copy protection on software, and this activity was called ââ¬Å"cracking.â⬠Nowadays, few software vendors use copy protection, but there are still various minor measures used to prevent the unauthorized duplication of software. Pirates devote themselves to thwarting these things and sharing commercial software freely with their friends. They usually read Pirate Newsletter and Pirate magazine. à § Cypherpunks (cryptoanarchists) ââ¬â Cypherpunks freely distribute the tools and methods for making use of strong encryption, which is basically unbreakable except by massive supercomputers. Because the NSA and FBI cannot break strong encryption (which is the basis of the PGP or Pretty Good Privacy), programs that employ it are classified as munitions, and distribution of algorithms that make use of it is a felony. Some cryptoanarchists advocate strong encryption as a tool to completely evade the State, by preventing any access whatsoever to financial or personal information. They typically read the Cypherpunks mailing list. à § Anarchists ââ¬â are committed to distributing illegal (or at least morally suspect) information, including but not limited to data on bombmaking, lockpicking, pornography, drug manufacturing, pirate radio, and cable and satellite TV piracy. In this parlance of the computer underground, anarchists are less likely to advocate the overthrow of government than the simple refusal to obey restrictions on distributing information. They tend to read Cult of the Dead Cow (CDC) and Activist Times Incorporated (ATI). à § Cyberpunk ââ¬â usually some combination of the above, plus interest in technological self-modification, science fiction of the Neuromancer genre, and interest in hardware hacking and ââ¬Å"street tech.â⬠A youth subculture in its own right, with some overlaps with the ââ¬Å"modern primitiveâ⬠and ââ¬Å"raverâ⬠subcultures. So should we fear these geeky little mischief-makers? The New York Post revealed recently that a busboy allegedly managed to steal millions of dollars from the worldâ⬠s richest people by stealing their identities and tricking credit agencies and brokerage firms. In his article describing this event Bob Sullivan says, ââ¬Å"Abraham Abdallah, I think, did us all a favor, for he has exposed as a sham the security at the worldâ⬠s most important financial institutions.â⬠The same two free e-mail addresses were used to request financial transfers for six different wealthy Merrill Lynch clients, according to the Post story. Merrill Lynch didnâ⬠t notice? Why would Merrill accept any transfer requests, indeed take any financial communication seriously at all, from a free, obviously unverified anonymous e-mail account? Iâ⬠m alarmed by the checks and balances that must be in place at big New York brokerage firms. Rather than being a story about a genius who almost got away, this is simply one more story of easy identity theft amid a tidal wave of similar crimes. The Federal Trade Commission has received 40,000 complaints of identity theft since it started keeping track two years ago, but the agency is certain that represents only a fraction of real victims. This is a serious problem, long ignored by the industry. If fact, just last year the credit industry beat back a congressional bill known as The Identity Theft Protection Act, claiming it would be too expensive for them. ââ¬Å"Clearly there has to be more leveling of the playing field. We have to hold banks and credit unions accountable.â⬠Last month the U.S. Federal Bureau of Investigation (FBI) was again warning electronic-commerce Web sites to patch their Windows-based systems to protect their data against hackers. The FBI's National Infrastructure Protection Center (NIPC) has coordinated investigations over the past several months into organized hacker activities targeting e-commerce sites. More than 40 victims in 20 states have been identified in the ongoing investigations, which have included law enforcement agencies outside the United States and private sector officials. The investigations have uncovered several organized hacker groups from Russia, the Ukraine, and elsewhere in Eastern Europe that have penetrated U.S. e-commerce and online banking computer systems by exploiting vulnerabilities in the Windows NT operating system, the statement said. Microsoft has released patches for these vulnerabilities, which can be downloaded from Microsoft's Web site for free. Once the hackers gain access, they download proprietary information, customer databases, and credit card information, according to the FBI. The hackers subsequently contact the company and attempt to extort money by offering to patch the system and by offering to protect the company's systems from exploitation by other hackers. The hackers tell the victim that without their services they cannot guarantee that other hackers will not access their networks and post stolen credit card information and details about the site's security vulnerability on the Internet. If the company does not pay or hire the group for its security services, the threats escalate, the FBI said. Investigators also believe that in some instances the credit card information is being sold to organized crime groups. Defend yourself when you cannot defeat the enemy, and attack the enemy when you can. Scott Culp in a detailed list of security precautions on Microsoftâ⬠s Web page suggests that there are ten immutable laws of security. Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore. It's an unfortunate fact of computer science: when a computer program runs, it will do what it's programmed to do, even if it's programmed to be harmful. When you choose to run a program, you are making a decision to turn over control of your computer to it. That's why it's important to never run, or even download, a program from an untrusted source ââ¬â and by ââ¬Å"sourceâ⬠, I mean the person who wrote it, not the person who gave it to you. Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore. In the end, an operating system is just a series of ones and zeroes that, when interpreted by the processor, cause the machine to do certain things. Change the ones and zeroes, and it will do something different. To understand why, consider that operating system files are among the most trusted ones on the computer, and they generally run with system-level privileges. That is, they can do absolutely anything. Among other things, they're trusted to manage user accounts, handle password changes, and enforce the rules governing who can do what on the computer. If a bad guy can change them, the now-untrustworthy files will do his bidding, and there's no limit to what he can do. He can steal passwords, make himself an administrator on the machine, or add entirely new functions to the operating system. To prevent this type of attack, make sure that the system files (and the registry! , for that matter) are well protected. Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore. He could mount the ultimate low-tech denial of service attack, and smash your computer with a sledgehammer. à § He could unplug the computer, haul it out of your building, and hold it for ransom. à § He could boot the computer from a floppy disk, and reformat your hard drive. But wait, you say, I've configured the BIOS on my computer to prompt for a password when I turn the power on. No problem ââ¬â if he can open the case and get his hands on the system hardware, he could just replace the BIOS chips. (Actually, there are even easier ways). à § He could remove the hard drive from your computer, install it into his computer, and read it. à § He could make a duplicate of your hard drive and take it back his lair. Once there, he'd have all the time in the world to conduct brute-force attacks, such as trying every possible logon password. Programs are available to automate this and, given enough time, it's almost certain that he would succeed. Once that happens, Laws #1 and #2 above apply à § He could replace your keyboard with one that contains a radio transmitter. He could then monitor everything you type, including your password. Always make sure that a computer is physically protected in a way that's consistent with its value ââ¬â and remember that the value of a machine includes not only the value of the hardware itself, but the value of the data on it, and the value of the access to your network that a bad guy could gain. At a minimum, business-critical machines like domain controllers, database servers, and print/file servers should always be in a locked room that only people charged with administration and maintenance can access. But you may want to consider protecting other machines as well, and potentially using additional protective measures. If you travel with a laptop, it's absolutely critical that you protect it. The same features that make laptops great to travel with ââ¬â small size, light weight, and so forth ââ¬â also make them easy to steal. There are a variety of locks and alarms available for laptops, and some models let you remove the hard drive and carry it with you. You also can use features like the Encrypting File System in Windows 2000 to mitigate the damage if someone succeeded in stealing the computer. But the only way you can know with 100% certainty that your data is safe and the hardware hasn't been tampered with is to keep the laptop on your person at all times while traveling. Law #4: If you allow a bad guy to upload programs to your web site, it's not your web site any more. This is basically Law #1 in reverse. In that scenario, the bad guy tricks his victim into downloading a harmful program onto his machine and running it. In this one, the bad guy uploads a harmful program to a machine and runs it himself. Although this scenario is a danger anytime you allow strangers to connect to your machine, web sites are involved in the overwhelming majority of these cases. Many people who operate web sites are too hospitable for their own good, and allow visitors to upload programs to the site and run them. As we've seen above, unpleasant things can happen if a bad guy's program can run on your machine. If you run a web site, you need to limit what visitors can do. You should only allow a program on your site if you wrote it yourself, or if you trust the developer who wrote it. But that may not be enough. If your web site is one of several hosted on a shared server, you need to be extra careful. If a bad guy can compromise one of the other sites on the server, it's possible he could extend his control to the server itself, in which case he could control all of the sites on it ââ¬â including yours. If you're on a shared server, it's important to find out what the server administrator's policies are. Law #5: Weak passwords trump strong security. The purpose of having a logon process is to establish who you are. Once the operating system knows who you are, it can grant or deny requests for system resources appropriately. If a bad guy learns your password, he can log on as you. In fact, as far as the operating system is concerned, he is you. Whatever you can do on the system, he can do as well, because he's you. Maybe he wants to read sensitive information you've stored on your computer, like your email. Maybe you have more privileges on the network than he does, and being you will let him do things he normally couldn't. Or maybe he just wants to do something malicious and blame it on you. In any case, it's worth protecting your credentials. Always use a password ââ¬â it's amazing how many accounts have blank passwords. And choose a complex one. Don't use your dog's name, your anniversary date, or the name of the local football team. And don't use the word ââ¬Å"passwordâ⬠! Pick a password that has a mix of upper- and lower-case letters, number, punctuation marks, and so forth. Make it as long as possible. And change it often. Once you've picked a strong password, handle it appropriately. Don't write it down. If you absolutely must write it down, at the very least keep it in a safe or a locked drawer ââ¬â the first thing a bad guy who's hunting for passwords will do is check for a yellow sticky note on the side of your screen, or in the top desk drawer. Don't tell anyone what your password is. Remember what Ben Franklin said: two people can keep a secret, but only if one of them is dead. Finally, consider using something stronger than passwords to identify yourself to the system. Windows 2000, for instance, supports the use of smart cards, which significantly strengthens the identity checking the system can perform. You may also want to consider biometric products like fingerprint and retina scanners. Law #6: A machine is only as secure as the administrator is trustworthy. Every computer must have an administrator: someone who can install software, configure the operating system, add and manage user accounts, establish security policies, and handle all the other management tasks associated with keeping a computer up and running. By definition, these tasks require that he have control over the machine. This puts the administrator in a position of unequalled power. An untrustworthy administrator can negate every other security measure you've taken. He can change the permissions on the machine, modify the system security policies, install malicious software, add bogus users, or do any of a million other things. He can subvert virtually any protective measure in the operating system, because he controls it. Worst of all, he can cover his tracks. If you have an untrustworthy administrator, you have absolutely no security. When hiring a system administrator, recognize the position of trust that administrators occupy, and only hire people who warrant that trust. Call his references, and ask them about his previous work record, especially with regard to any security incidents at previous employers. If appropriate for your organization, you may also consider taking a step that banks and other security-conscious companies do, and require that your administrators pass a complete background check at hiring time, and at periodic intervals afterward. Whatever criteria you select, apply them across the board. Don't give anyone administrative privileges on your network unless they've been vetted ââ¬â and this includes temporary employees and contractors, too. Next, take steps to help keep honest people honest. Use sign-in/sign-out sheets to track who's been in the server room. (You do have a server room with a locked door, right? If not, re-read Law #3). Implement a ââ¬Å"two personâ⬠rule when installing or upgrading software. Diversify management tasks as much as possible, as a way of minimizing how much power any one administrator has. Also, don't use the Administrator account ââ¬â instead, give each administrator a separate account with administrative privileges, so you can tell who's doing what. Finally, consider taking steps to make it more difficult for a rogue administrator to cover his tracks. For instance, store audit data on write-only media, or house System A's audit data on System B, and make sure that the two systems have different administrators. The more accountable your administrators are, the less likely you are to have problems. Law #7: Encrypted data is only as secure as the decryption key. Suppose you installed the biggest, strongest, most secure lock in the world on your front door, but you put the key under the front door mat. It wouldn't really matter how strong the lock is, would it? The critical factor would be the poor way the key was protected, because if a burglar could find it, he'd have everything he needed to open the lock. Encrypted data works the same way ââ¬â no matter how strong the cryptoalgorithm is, the data is only as safe as the key that can decrypt it. Many operating systems and cryptographic software products give you an option to store cryptographic keys on the computer. The advantage is convenience ââ¬â you don't have to handle the key ââ¬â but it comes at the cost of security. The keys are usually obfuscated (that is, hidden), and some of the obfuscation methods are quite good. But in the end, no matter how well-hidden the key is, if it's on the machine it can be found. It has to be ââ¬â after all, the software can find it, so a sufficiently-motivated bad guy could find it, too. Whenever possible, use offline storage for keys. If the key is a word or phrase, memorize it. If not, export it to a floppy disk, make a backup copy, and store the copies in separate, secure locations. Law #8: An out of date virus scanner is only marginally better than no virus scanner at all. Virus scanners work by comparing the data on your computer against a collection of virus ââ¬Å"signaturesâ⬠. Each signature is characteristic of a particular virus, and when the scanner finds data in a file, email, or elsewhere that matches the signature, it concludes that it's found a virus. However, a virus scanner can only scan for the viruses it knows about. It's vital that you keep your virus scanner's signature file up to date, as new viruses are created every day. The problem actually goes a bit deeper than this, though. Typically, a new virus will do the greatest amount of damage during the early stages of its life, precisely because few people will be able to detect it. Once word gets around that a new virus is on the loose and people update their virus signatures, the spread of the virus falls off drastically. The key is to get ahead of the curve, and have updated signature files on your machine before the virus hits. Virtually every maker of anti-virus software provides a way to get free updated signature files from their web site. In fact, many have ââ¬Å"pushâ⬠services, in which they'll send notification every time a new signature file is released. Use these services. Also, keep the virus scanner itself ââ¬â that is, the scanning software ââ¬â updated as well. Virus writers periodically develop new techniques that require that the scanners change how they do their work. Law #9: Absolute anonymity isn't practical, in real life or on the web. All human interaction involves exchanging data of some kind. If someone weaves enough of that data together, they can identify you. Think about all the information that a person can glean in just a short conversation with you. In one glance, they can gauge your height, weight, and approximate age. Your accent will probably tell them what country you're from, and may even tell them what region of the country. If you talk about anything other than the weather, you'll probably tell them something about your family, your interests, where you live, and what you do for a living. It doesn't take long for someone to collect enough information to figure out who you are. If you crave absolute anonymity, your best bet is to live in a cave and shun all human contact. The same thing is true of the Internet. If you visit a web site, the owner can, if he's sufficiently motivated, find out who you are. After all, the ones and zeroes that make up the web session have be able to find their way to the right place, and that place is your computer. There are a lot of measures you can take to disguise the bits, and the more of them you use, the more thoroughly the bits will be disguised. For instance, you could use network address translation to mask your actual IP address, subscribe to an anonymizing service that launders the bits by relaying them from one end of the ether to the other, use a different ISP account for different purposes, surf certain sites only from public kiosks, and so on. All of these make it more difficult to determine who you are, but none of them make it impossible. Do you know for certain who operates the anonymizing service? Maybe it's the same person who owns the web site you just visited! Or what about that innocuous web ! site you visited yesterday, that offered to mail you a free $10 off coupon? Maybe the owner is willing to share information with other web site owners. If so, the second web site owner may be able to correlate the information from the two sites and determine who you are. Does this mean that privacy on the web is a lost cause? Not at all. What it means is that the best way to protect your privacy on the Internet is the same as the way you protect your privacy in normal life ââ¬â through your behavior. Read the privacy statements on the web sites you visit, and only do business with ones whose practices you agree with. If you're worried about cookies, disable them. Most importantly, avoid indiscriminate web surfing ââ¬â recognize that just as most cities have a bad side of town that's best avoided, the Internet does too. But if it's complete and total anonymity you want, better start looking for that cave.
Subscribe to:
Posts (Atom)