TECH SERVICE: Monster’s Security Breach Larger

Saturday, September 1, 2007

http://mashable.com/2007/08/29/monster-security-breech/

Monster’s Security Breach Larger than Thought
August 29, 2007 — 10:56 PM PDT — by Kristen Nicole

***Begin Quote***

The 1.3 million individuals whose data, including financial information, was stolen from Monster’s database may be larger than initially reported.

During the investigation regarding the theft, it was discovered that the website had been previously hacked. The exact number is still unknown, but could reportedly be in the millions. Monster has indicated that users should assume their information has been taken. As this wasn’t an isolated incident, the illegal activity has been impossible to pinpoint. Monster has lost between 200 and 300 job seekers and some employers’ accounts due to the issue.

***End Quote***

Like I said. Lot of blame there.

# # # # #

text


TECHNOLOGY: More from the Ebenezer Scrooge School of Overseer Management

Saturday, September 1, 2007

>Network World’s Security Strategies Newsletter, 08/28/07
>Hacker tips published in Wall Street Journal
>By M. E. Kabay
>On July 30, Vauhini Vara published an article in the _Wall Street Journal_ entitled, “Ten Things Your IT Department Won’t Tell You.”
>The author explains that office
>workers like to use corporate-supplied equipment to “keep up with our lives. … …

Don’t forget that corporations are INTENTIONALLY blurring the lines between work / play / home. As an IT executive, I have seen:
* The corporate honchos with different sets of rules for themselves and the serfs.
* IT troops are expected to answer “problems” at all hours of the day or night. And, then turn to in the morning on time as if nothing happened.
* Projects scheduled with a “forced march” ethic in human resources. AND
* The deliberate planning of “human resources” to avoid payment of overtime and giving comp time.
So let’s not kid around that people are just goofing off all the time, watching YouTube, and playing online poker. Work has to get done. And it does get done. If you are going to fudge the margins, then you can’t get all uppity when the letter of some policy or standard is not met.

If I’m waiting for a phone conference call to assemble and begin, usually because some required honcho is “late”, don’t scream like Mayor Bloomberg if there’s a solitaire screen up. If I’m working on a holiday weekend installing a new IT system and don’t get anything other than maybe “thanks” or keep getting my regular paycheck, don’t gripe when the “big” football game is on one of the monitors or everyone’s watching a movie while the big update is ruining. At least on Wall Street, when they make absurd demands, they pay obscene bonuses.

The AFL/CIO is dumb not trying to unionize the IT workers. It’s the new sweat shop. I am astonished that some one hasn’t sued about these type of issues already.

>her “safety” measures for violating appropriate-use policies include this advice for attempting to wipe audit trails:
> “Clear your private data as often as possible.
>Better yet, don’t use your work computer to do anything you wouldn’t want your boss to know about.”

I agree that one should have your own ethical standards. A good Nun once told me that my standard should be “don’t do anything you would want to have to tell your Mother”. Works for me.

BUT!

Let’s not imbue Acceptable Use Policies as if they come down from some Olympic mountain.

For example, once upon a time, there was a corporate policy not to use AOL IM. (Why I have no idea? Pinging someone to join a conference call may tell some hacker … what?) But the corporate IT group (aka the shills for Microsoft) had no solution. Yet the executives used AOLIM, and wanted their people to use it. It was efficient. Talk about mixed messages. But piously, they made people sign annual acceptances of the corporate policies. Like Stossel says “gimme a break”. In my past executive coaching practice, as well as my stints as an ITA/BPR consultant, I counseled against sending mixed messages. People, like little children, learn by watching carefully what you do. Not what you say.

>I invite readers to read Vara’s article for themselves and then to join me in a short series of columns
>as I analyze her work from an ethical standpoint.

Having been brought up in the Ebenezer Scrooge school of employee training, where the motto was “You pretend to pay me; I’ll pretend to work”, I suggest that it’s time for everyone to grow up.

The world has changed.

Unlike KMart, there’s no Blue Light to turn on. No PA system over which we can make the announcement. No clap of thunder or bolt of lightening to get everyone’s attention. Nor any formal demarcation point, like when the calendar changes. We can’t afford to play silly games. In the global competitive environment, we need to develop our thinking.

So for example, just like I don’t expect my employer to buy me my pens, I buy my own technology. Sure I’ll use theirs for their stuff if they insist. (Mine’s better.) But, if your trash is not working, you can’t hold me accountable for the “shortfall”. Can’t have it both ways. If you want me to do 24×7 support or some other outrageous demand, then it’s OK for me to use my home computer, policies be darned, for which you don’t pay. That’s OK, but heaven forbid I answer an email from work? (Note: My personal information NEVER goes near their hardware.) Now I realize I’m a little bit of an odd ball. I’ve been a consultant, and in my own business several times. But I can see the hypocrisy in some “policies”.

New times require new rules.

It’s about generating value. Some of that value belongs to the employer and some I am allowed to retain. It’s a team sport. I need them and they need me. 50/50.

(Actually the company needs the employees more. Some wag once said “Each night, all of our intellectual capital walks out the door.” I had an old boss who use to extend that with “It’s my job to make you want to come back.” With the aging of the work force, that’s even more true today than it was then.)

Leadership and management must forget the lessons of Ebenezer Scrooge and Frederick Winslow Taylor. You manage things and lead people. Throw all the policy manuals out the window. Lead people. Teach them why you should NOT put corporate secrets into email unencrypted or waste time when your supposed to be earning value for the team. Deploy tools that make it unnecessary to “bend” rules. Share the monetary value such that unpaid OT or unreasonable demands aren’t made. Hold leadership accountable for their decisions and policies.

This line of inquiry is based on an old paradigm and is coming from the meme of “unwilling worker”. In today’s new world, the new team-shared meme must be that there is value produced which is shared by all who produced it.

We have to evolve our memes because there are a lots of very smart very hungry people in India and China that are going to eat us for breakfast if we stay stuck in “Detroit thinking” with respect to the roles of employer and employee.

In my not so humble opinion, I believe that these large corporations are going to self-destruct. The new meme will be small team size agile organizations, that can do a better job of delivering and sharing value, while “outsourcing” all non-core competency functions (i.e., HR, finance, IT). The economies of scale that allowed the IBMs, AT&Ts, GMs, and such to evolve and flourish are no longer there.

Small ‘n’ agile will outperform big ‘n’ bureaucratic every time.

And, don’t get me started on the “gooferment”.

imho,
fjohn

P.S.: I hope that’s the type of input your were looking for. My current employer is very enlightened and doesn’t have these problems that I know of.

# # # # #


TECH SERVICE: BLOGLINESBETA missing a feature from the old version

Friday, August 31, 2007

FROM: Bloglines Customer Service

*** begin quote ***

Thank you for contacting us. Please refer to the discussion thread below for our response. If you need further assistance with this issue, please reply to this message describing the issue in more detail.

Thank you for allowing us to be of service to you.


Subject
Web Form: [Suggestions]

Discussion Thread
Response (C.D.) 08/31/2007 08:12 PM
Hello,

Your suggestion is much appreciated, and we have forwarded your note to the Bloglines Beta team.

Over the years we have modified our site based on feedback like yours and from other Blogliners. Look for changes in the upcoming weeks and months, as we continue to build-out Bloglines Beta. We welcome your thoughts about Bloglines.

Please let us know if we can be of further assistance.

Customer 08/30/2007 02:41 PM

Old Bloglines allows me to “keep as new”. So if I am whizzing thru and see something that I’d like to spend more time on I just check it. Beta Bloglines doesn’t do that. Or, I don’t see it. And, it doesn’t honor the oldblogline’s setting. This was the reason I move from Google to Bloglines. Hate to have to move again.

*** end quote ***

# # #

Sigh! Why bother?

# # # # #


TECHNOLOGY: from the Ebenezer Scrooge School of Overseer Management

Friday, August 31, 2007

Network World’s Security Strategies Newsletter, 08/30/07
Ethical decision-making: Identifying the ethical issue
By Mark Gibbs

***Begin Quote***

Let’s assume for the sake of this discussion that an employee, Bob, has signed an appropriate-use agreement with his employer and that he’s not supposed to use his company computer for non-work-related Web surfing.

*** end quote ***

It’s all too black and white. Cut and dried. Either or. The real world is much more gray!

If the employee we are talking about is an hourly employee — the IT equivalent of a burger flipper — then the case presented makes some amount of sense. But, I am hard pressed why they have a fully functional browser, and expensive hardware.

I think the more interesting case is when you apply this to what I will classify as “knowledge workers”. They present a tougher case in what’s acceptable use. Proper leadership would know when the people were being productive and then trying to micro mange what people do by AUPs — which never work — would be unnecessary.

While we are talking about following rules, the rule maker’s hands are not always that clean. Sometimes there are different AUPs for the AUP-makers. AND, then we have many organizations, who want knowledge workers to provide off hour support from home without compensation, wanting to enforce an AUP. Seems like the rules are used when they are convenient.

Bottom line: Everyone must tread very carefully. And, keep notes on what is “current practice”. They’ll be useful when you negotiate your severance or can be used as evidence at your trial. AUPs are another gotcha from the Ebenezer Scrooge School of Overseer Management!

# # # # #


TECH SOFTWARE: ROBOFORM (Highly Recommended — Essential Software)

Wednesday, August 29, 2007

http://www.roboform.com

Have a few situations where I think roboform2go could do a little better.

(1) When I resume, the roboform2go can’t remember where the fob was. even though it never left its place in the usb slot. Rerunning roboform2go fixes it.

(2) When I reboot, roboform2go restarts but the little icon — that gives me access easily to all the functions — gets “lost”. Rerunning roboform2go restores to its proper place.

(3) On resume, if I put the fob in too early in the boot process, then roboform2go never triggers to start.

I just think that it could be handled a little better.

For example, when roboform2go “loses” its fob, there should be a pick from the little icon to “look around for it”.

For example, when the little roboform2go icon goes “mia”, (Note: roboform2go is running and will supply data), there should be a secret key combo to restore the icon.

Just some kvetches that have been building up and I thought I’d mention them.

# # # # #


TECH SERVICE: CollectiveX’s Groupsites (RECOMMENDED)

Tuesday, August 28, 2007

http://www.groupsites.com/

CollectiveX’s Groupsites

***Begin Quote***

What are Groupsites?

Groupsites make it easy for groups to share, communicate and network. They combine the best
features of:

– Discussion forums
– Email lists
– Calendars
– Social networks

Groupsites are powered by CollectiveX; are FREE to setup; and can be public, semi-public or private.

***End Quote***

Interesting concept. You’re own social network. I’d suggest that it has a fragment of the solution. Jibber Jobber has a part. Yahoo Groups has a part. LinkedIn has a part.

Hmmm! Maybe I’ll create something for my fellow Turkeys, or just me?

# # # # #


TECH SERVICE: Google Web Accelerator off

Tuesday, August 28, 2007

Any one else having the problem? Any one know why? Help?

# # # # #


TECH SERVICE: FACEBOOK has flaws

Sunday, August 26, 2007

Interesting that it would let you look up just one email address. You have to create a file that it can import and check. And, it doesn’t always do that correctly!

# # # # #


TECH SOFTWARE: OUTLOOK

Friday, August 24, 2007

Does anyone know how to work with Look Out (aka Outlook2003sp2) rule in any other way than the cruddy microsnooze user interface?

For example, when junk gets caught by LookOut or spam gets caught by CloudMark and I say “It’s OK”, they put it back in the inbox. Well my inbox is empty by design. I have rules that sort my inbound mail extensively. For example, if it’s coming from a known address, or to certain secret addresses, or has a secret word in the subject line, it gets sorted automagically to a specific folder. It allows me to allocate my time in priority order. But, when LookOut or Cloudmark just drop in the INBOX folder, the rules never execute against it. Argh! Help?

# # # # #


TECH SERVICE:COLLECTIVE GROUPSITES for your own free social network

Friday, August 24, 2007

http://www.collectivex.com/intro

***Begin Quote***

What are Groupsites?

Groupsites make it easy for groups to share, communicate and network, by combining the best features of discussion forums, email lists, calendars and social networks.

Groupsites are powered by the CollectiveX platform; are FREE to set up; and can be configured to be public, semi-public, or private and secure.

***End Quote***

FREE social network?

# # # # #