Monday, August 29, 2016

Don't Mix Personal and Business Email

Don't Mix Personal and Business Email

Those of you in business know about the best practice of keeping separate personal and business bank accounts and credit cards. Any accountant will tell you this is a no-no for several reasons. 

It's best to follow this no-mix approach for email too. Limiting our business email accounts to business matters only, including creating spam and filter lists that black-list all non-business correspondence, will reduce the threats of malware and hacking.   

Will-nilly email sending
Why? Because of the willy-nilly approach many users take to opening, sending, and forwarding potentially unsafe emails (I'm guilty too!), you increase your risk of mixing those types of missives in your in-box with important business email. Some malware and hacks that gain a foothold on your computer via email can wipe out data, take over the email account, and infect the email program or browser. 

I'm not suggesting the business, professional, and governmental world does not bat around junk email and infected messages. But the variety and exposure is generally more limited. This is partly because many institutions have strict email use policies and stringent filtering of inbound and outbound email. This is largely not true for the personal email user. 

How to un-mix the accounts
The easiest remedy to un-mix your email - if you don't already have a personal email address - is to create a free gmail account. Choose a non-identifying address, one that doesn't include your name or pointers to who you are. For example, you can refer to a hobby (passion) like fishing: live.to.fish808@gmail.com. (It's easy to add a gmail account to your phone or tablet after set up in a web browser on a computer.)

Once you create the new email, notify all friends and family to send email only there. Re-route any subscription or online shopping accounts to that address too, or create a new email for that type of thing.

Filter your business mail
Then in your business email account/program, set up a filter to block anyone not in your business contacts list.  

The joy of a smaller inbox
One joy you will notice from doing this is your business email in-box will shrink dramatically. And you'll not be distracted by the noise of non-business messages. 

Personal email browser
As for your personal email, you can keep it handy in a browser window, which you can flip to when you like. If using gmail for your personal email, I recommend using Google Chrome. If you're already using Chrome for your business email, then I suggest using Firefox for the personal account. A better practice is to not access personal email on a work computer; use a personal laptop, tablet, or phone. 

Related article
You may also like to read my post about segregated web browsing, which dovetails with this article


Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Monday, August 15, 2016

Disable Third-Party Cookies to Protect Against Threat

Disable Third-Party Cookies to Protect Against Threat

Hackers are trying by every hook and crook to access our private information. A newly reported vulnerability in https, the protocol that encrypts our web surfing, may now be exploited. I have provided a link the news story at the bottom.
This is a very technical, sophisticated exploit called HEIST. The best way to reduce your risk from this attack is to disable third-party cookies in your web browsers.

What are cookies?
Here’s a nice explanation from howtogeek.com:
“Most cookies exist for the sake of persistence. When you visit a website such as Facebook or Twitter, cookies let you stay logged until you log out again. This means that every time you visit that site, you will still be logged in, which saves you the time and effort of re-entering your password.
If you clear you cookies, then you will be logged out (or rather, the browser will think you’re logged out because it will have no memory of you every visiting the site in the first place).

Third-party cookies
Third-party cookies are cookies placed on your device by a website other than the one you’re visiting. For example, say you visit a website and their advertiser(s) set a cookie–this allows that advertiser to track your visits to other websites. You probably don’t want this to happen.

Cookies off, errors possible
For example, you might try to view streaming video on a website, but the video originates from another source. In this case, you will likely see an error telling you that the video cannot be viewed. Often, the error message will provide little clue as to what the problem may be, but if you have third-party cookies disabled, that is most likely the culprit.”

Howtogeek.com gives clear instructions how to disable third-party cookies here:


News story on HEIST exploit:
http://uproxx.com/life/https-heist-exploit/

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Friday, July 15, 2016

Which Browser is Best?

Which Browser is Best?

I get asked this loaded question frequently. It's loaded because there is no one right answer, and because whichever one I propose will soon likely have some flaw reported that smears its good name. 

So instead of pointing to one, I usually answer like a psychotherapist, tossing a question back: What do you use the browser for? 

Because practically speaking, that's what matters most. For example, some of my clients found Internet Explorer worked best when viewing certain sites they liked. So there it is: use that browser for that purpose. 

Here are some more specific tips:

Google Chrome
For users of Google's Gmail and Google Docs, I recommend Google Chrome. It seems to work best for that purpose.

Mozilla Firefox
For general browsing, I recommend Firefox. It's mostly stable and Mozilla is intent on keeping it as secure as possible. 

Microsoft IE (Internet Explorer) 
I have always found Internet Explorer kind of clunky; but that's just me. If it works well for you, then use it. It's pretty much built-in to Windows. 

Microsoft Edge
This comes with Windows 10. It's sleeker than IE and many users report liking it once they get used to it. 

Update and Refresh
The most important aspect of using any browser these days is keeping it updated. This provides protection against the known exploits that target a specific browser's weak points. You can also refresh/reset browsers when they get buggy. You may lose some of your customization afterwards, but the performance boost is worth it. 

Minimize plug-in use
Another rule of thumb is to minimize the plug-ins you install in a browser, such as the Adobe Flash Player plug in. These are also exploited when not kept current. (I do recommend the Privacy Badger and HTTPS Everywhere plug-ins.)

A Brave new browser
Recently I've been test driving a new browser called Brave. It is a cleanly designed browser with easy-to use privacy and security settings. 

Brave is open source and blocks online ads and other trackers. Unlike traditional browsers where ad-blocking takes place via a third-party add-on or extension, Brave’s browser has this technology built in, which should offer users more privacy and increased speed and performance.

Segmented browsing
My current approach to using browsers is to limit what I do with each one. As mentioned above, I use Chrome primarily for Gmail and Google Docs, and a few other business-only sites. I use Firefox for my personal email, calendar, and personal banking.

I use Edge and Explorer for some other personal Gmail accounts.

I use Brave for all other browsing, web research etc.

Why segment? For one, it keeps me focused on the kind of tasks I'm doing based on which browser I'm in. Chrome=work. IE=youtube watching. Brave=websurfing. 

Also, if I visit a poisoned site which infects my browser, the damage may be limited to that browser, so I can sanitize the infection more easily. (A counter argument could pose that using several browsers enlarges the "attack surface" for malware and hackers, as having more software means more attention to keeping it current.)

A separate tablet or laptop
Another type of "segmenting" I recommend for professionals like doctors, lawyers, etc. is to dedicate one computer to work-related web use. Then use either a tablet or a small laptop, like a Chromebook, for personal websurfing and email while on the office network. The Chromebook is less likely to get infected or hacked due to its operating system, and even if it were, there would be minimal data on it. Plus it can easily be "power washed" to remove any infections.  

Use what works best and is safest
With the rapid evolution of a variety of web services as well as rampant hacking and malware distribution, browser makers are hustling to keep pace by providing sound software products. We users just gotta keep up with what works best and is safest for our purposes. There's no one best solution. 


Thanks for reading.
Sam


p.s. if you're hungry for more detailed info on the browsers mentioned in this article and the many others omitted, check this wikipedia link.

---


If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Wednesday, June 15, 2016

Use System Restore to Fix Your Windows Computer

Use System Restore to Fix Your Windows Computer

There are plenty of glitches that can plague our Windows computers, malware being just one. Programs break, drivers break, we users make unhelpful changes, etc. 

System Restore - the magic undo
The good news? There is a magic “undo” feature in Microsoft Windows – it’s called System Restore. It’s bailed me and my clients out of difficulties many times. And when you've been hit by malware you can use this to repair your computer before removing the infections with a security scanner. 

If you’ve used System Restore, you may recall your delight when it did its magic. If it’s new to you, let me explain.

A simple approach
Of course there are more detailed ways of diagnosing and remedying hardware and software problems, including malware infections. But if things were fine one day, and the next they’re not - and you don’t recall changing anything - System Restore is a handy tool.

To use it, locate the Run box after clicking your Start button (Windows 7), or type Run in the Windows search box (Windows 8 or 10). Then in the Run box type rstrui.exe, then click OK.

No change to data - but back up anyway
System Restore will launch. Click Next, then locate a recent restore point prior to the day you started having issues. Note: any programs or updates you installed after that date will be removed, but none of your data will be changed. (Nonetheless, it’s best to back up important data before running System Restore.)

Before running System Restore, close all open programs and save all work. Allow anywhere from 5-15 minutes for the Restore process.  

The computer will reboot and present your Windows login screen, and report whether System Restore succeeded or failed.

Creating a Restore Point
A proactive approach to take with System Restore is to set a Restore Point when things are working well. Open the Control Panel, then type Restore in the Search box. Then select Create a restore point. Choose your Windows drive (usually C). Then click Create and name the Restore Point.

Once this Point is created, you can roll back to this in the future should your computer be throwing a fit. (If it’s throwing a big fit, you may have to run System Restore from the command prompt in Safe Mode, but that’s another story.)

Deeper malware removal
If you're running System Restore to aid in malware removal, after Restore is done, go to your Programs in the Control Panel and remove any suspicious characters, sorting by date - a clue being programs you didn't intend to install. 

Then run malware removal scans by using programs like Malwarebytes. 

Restore doesn’t fix all problems, but it’s an easy “go-to” when you want a quick return to smoothing sailing after rough waters.   

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 



Sunday, May 15, 2016

Where's Your Data Stored?

Where's Your Data stored?

I'd like to pose a question we should be asking ourselves often in this modern digital world: Where's my data?

Where is your data?
These days a person may own a computer, a smartphone, a tablet, and other Internet-connecting gadgets like a smartwatch. Each of these devices collects data we put into them, and data they gather about us. Here I'll focus on one set of important data we input: Personally Identifying Information (PII).

What is Personally Identifying Information (PII)?
PII can include your name, social security number (SSN), date and place of birth, mother's maiden name, etc. It can also relate to your unique medical, educational, financial, or employment information. PII can be exploited for identity theft and other crimes.

Know where your PII is stored. For example, do you keep your SSN, or those of family members, on your phone in the Contacts or in a notes app? This may be convenient, but it's risky. If someone steals your phone, or hacks it, the PII is exploitable.

So after answering the "Where's my data?" question, the follow up should be: "Is it safe there?"

Is your data safe there?
In the example of a smartphone, is yours password protected? Is it encrypted? If the answer is no, no, then do not store PII on the phone. If you are using an app like Lastpass on your phone to store PII, this app's vault encrypts the data. This is good protection, but still password-protect and encrypt your phone. Nothing is 100% secure.   

What if… your phone is lost or stolen?
The third data risk question to ask is: "What if?" For example, ask yourself, "What if my phone is lost or stolen?" Have a protocol you can follow quickly to minimize the potential for information theft, the first step being locating the phone and trying a remote wipe. 

If that isn't effective, then consider all apps and accounts you save on the phone that are password-linked and change those passwords on the website for those apps and accounts immediately! (If you haven’t done so already, make complex and unique passwords for each of those accounts.)

Don't keep any PII on a portable device
To err on the side of paranoia, don't keep any PII on a portable device, or for that matter any info that you don't want going public. Take measures to protect what’s most precious. 

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 


Friday, April 15, 2016

3 Steps to Reduce Computer Crisis Stress

3 Steps to Reduce Computer Crisis Stress

There are 3 steps you can take to reduce stress related to a computer crisis. 

By computer crisis I mean a situation where the computer is running very poorly, or may be infected by malware (annoying popups), or may have a hardware part failing (odd noises), or worse yet has crashed and won't restart. 

Be proactive! 

Do these 3 things to reduce your stress when the inevitable happens... 

  • Make regular backups of critical data - locally and offsite. For local backup you can use a USB drive. For offsite, I recommend Mozy.com. Worst case, if your computer fails or is hit by damaging malware (such as ransomware), at least you will have your data available to restore when the crisis is resolved. Note: You will need an offsite backup solution to recover from a ransomware attack because this kind of attack can encrypt even your local backup. 
  • Deal with the problem promptly. When the computer starts to act up, if you can't fix it, get help asap. Putting it off usually only makes things worse. It's the same as was when you hear an odd noise coming from your car's engine compartment. Better not ignore that one!
  • Do regular maintenance. This means installing important updates for all software, and doing tune-ups and clean-ups. Also run security software scans regularly. For businesses, I recommend scheduling maintenance at least quarterly, or having someone in-house be tasked to do it. For home users, do maintenance at least 2x/year. 
As the old adage goes, an ounce of prevention is worth a pound of cure. 

It's also a risk tolerance issue: ask yourself how comfortable you are risking a computer failure that could ruin your day. 

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Monday, March 14, 2016

Do Not Run Your Computer as Administrator

Do Not Run Your Computer as Administrator

I came across a recent study that reinforced why I recommend to my clients that they not use their computer logged in with administrator privileges. 

The study revealed that of the 251 vulnerabilities in Microsoft's Patch
Tuesday security bulletins in 2015 with a critical rating, 85% were concluded to be mitigated by removing administrator privileges.

The primary benefit of running in Standard user-level privilege instead is that programs which try to install without your permission/involvement cannot do so unless you provide the administrator password. This includes malware. 

This approach is also beneficial if you're sharing a home computer with kids - the last thing you want is them installing programs without your supervision. (And it's best to have parental controls running on their accounts too.)

The administrator account does not need to be named Administrator. It can be named whatever you like: Master, Admin, Big Kahuna, Sky Lord, whatever. But it needs to be the only account on the computer with administrator privileges. 

When setting this account up, choose a password that only you or another trusted person knows. 

After creating the new administrator-level account, log off the computer and try to log in with that account. Verify in Settings or the Control Panel that the account in fact has administrator privileges. This is very important! 

It's critical because in the next step you will demote any other administrator-level accounts. Once you do so, they will no longer have administrator control. If you didn't give the new account administrator privileges, you won't be able to "administrate" your computer. Not good!

The next step is to demote all other users to Standard user level. I've provided links at the bottom for Widows 7, 8, and 10. Select a desired user and change to Standard. Then log off the computer and log in again as that user, just to test the user can still log in.

You will notice a change on the computer after doing this: If you try to install software or make system-wide changes as a Standard user, you'll be prompted for the administrator password. 

Again, this is a best practice for computer security. It applies to Windows computers, Apple computers, and Linux (in Linux, administrator is called root.)

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Thanks for reading.
Sam

---

Links for changing account types

Windows 7
http://www.sevenforums.com/tutorials/103538-user-account-type-change.html

Windows 8
http://www.eightforums.com/tutorials/5518-user-account-type-change-windows-8-a.html

Windows 10
http://www.tenforums.com/tutorials/6917-account-type-change-windows-10-a.html