Blog

  • Why Responsive Web Design Matters More Than Ever

    The rise in the use of mobile devices (including iPhone, Smartphone, iPad and Android tablets) means more individuals tend to access the web via these devices. These devices have gradually replaced the use of PC (desktop/laptop computer) as the primary mode of accessing the web. This means that each individual today will need a responsive version of their site that could be operational on all devices (including desktop, mobile phones and tablets).
    A responsive web design is arguably one of the most powerful concepts in the web designing industry but the question is, why does it matter for your website? This article addresses several key reasons why responsive web design matters.

    Why Does Responsive Web Design Matter Than Ever?

    Responsive web design has been found to be vital to website owners due to the following reasons:

  • Difference Between Web Design and Web Development

    Many business owners search for both web design and web development without actually knowing the difference between these two. Well, although these two can be put under one hat called “web company” there is still a big difference between the services they offer. We are actually talking about two different approaches of website creation and the skills of those doing it are completely different. Do you really have to know the difference between them since you actually want to hire someone to build your company website? Let’s try to make things more clear.

    The Basics Difference between Web Design and Web Development:

    Basically, when we talk about web design we talk about the visual look of the website and its usability at the same time. Web designers use various programs intended for graphic design to create the website layout and add various visual elements to the website.
    Alternatively, web development means that those doing it will use the web design and turn it in a fully working website using different programming languages like CSS, PHP JavaScript and even HTML. They actually bring life to the design.

    A Brief Introduction to Web Development:

    Web developers, also known as programmers build a fully working website from the web design created by web designers. They break the complete design to small pieces and use programming languages to put them back together. With the help of web developers the static layout becomes a dynamic website. They can even use some CMS (Content Management Systems) like Joomla or WordPress to make it easier for their clients to update and maintain their website.

    A Brief Introduction to Web Design:

    Web designers generally start the work by talking to the client about the website’s objectives and purpose. After that they work on the Information Architecture and order the information given by the client. The next step would be to create a wireframe and continue with the design. There are some specific design principles that have to be followed when designing a website in order to create a great visual look of the website while taking care of the overall user experience.
    Learn More Aboutthe Basic Design Principles

    Conclusion Note:
    Knowing the difference between web design and web development will help the various companies choose the right one if they have to redesign their company website or make a brand new one.Of course, they can easily find people who are great at both design and programming, but most often companies hire a web design team first and after they are completely satisfied with the looks and feel of their company website they give the design files to the skilled programmer to connect all these elements in a fully working website.
    We hope we have made the difference between web design and web development a bit less confusing. So, now when you know more about the difference between these two you can continue searching for the right company or person to do the required work for you. We are sure you won’t hire a web developer to design your website now or contact a web designer to make some website modifications which are not related to web design.

  • How a website can improve your business

    Website are good for business and almost everyone know that it is but they have not taken time to think how the website can improve their business or services. We have listed some ways through which a good website can help your business survived in the 21st century.

    How a website can improve your business

    Your web site is open 24/7 so your customers can interact with your business when it’s convenient for them. Everyone is on a tight schedule these days. They may really appreciate the convenience of finding what they need without having to stop, call, and ask — filling in a form, signing up for a newsletter, reading your blog, getting a quick quote, booking online, downloading your e-book, or reading your case studies, all in their OWN time!

    People will keep you in mind if you keep in touch. It’s much easier to sell to customers who already know and trust you, so keep in touch and stay top of their mind. Regular email newsletters and updates to your website will help you better communicate with your customers. Additionally you should spend time setting up your online profiles on networks you belong to (eg Facebook, Twitter, LinkedIn, and Google+) – these are a low cost way to get more of YOU online!

    It’s not enough to provide just information about your products and services. Your expert advice may give you the edge over the competition and potentially even make the sale. Think of your website as an employee, presenting your customers with help and knowledge about your company’s area of expertise.

    A well designed website will add credibility to your business and strengthen your brand. On the other side of that, a poorly designed or outdated website may portray your business as amateur or disorganized. By providing customers with information in an organized and well-presented manner, you can show customers you anticipate their needs and set an excellent impression for all transactions to follow.

    There is no other way that provides the geographic reach of a website, and internet usage continues increase year after year. If you don’t have a well-placed website someone else will get your business. Your website puts your business out there to be found by anyone anywhere who is already looking for what you offer.

    With website content, you incur no printing, shipping, or postage expenses, and updates are quick and easy. It can be tailored to suit the size of your business and your budget.

  • Domain name, Its Importance and why you need to have your own

    Domain name, Its Importance and why you need to have your own

    A domain name is your unique identity on the internet. It is the address of your cyberspace. Owning a domain name gives you the same feeling that you get once you have in your hands the title deed for your newly purchased house. The sense of ownership is the most vital importance of domain name.
    Getting a domain name registered is like getting your own business card. A person makes a number of evaluations about you on reading your visitor’s card. Similarly your domain name reveals so much about you and your website, on the first look, that it is nothing short of your own personal visitor’s card. Get a right domain name and get a good first impression.
    If you are planning to create your presence felt on the internet, getting a domain name is perhaps the starting point. It opens the doorway to so many options on the internet which can only follow once you have a domain name registered under your name.

    IMPORTANCE OF A DOMAIN NAME

    Conclusively:
    There is vast importance of domain names. It helps build your reputation. Not having your own domain name gives an amateur look to your website. Get that all important professional look by having your own domain name.
    Earlier the domain names were costlier and only few companies had one for themselves. Nowadays it is so cheap to have a domain name for yourself that there is no reason not to buy one for your own use. With so much importance of domain name and with hardly any disadvantage, it makes sense to invest that paltry sum for a domain name that reflects your persona or caries your brand image to give further boost to your brand value and your online business.
    It is highly recommended that you too realize the importance of domain name and get your own domain name registered if you are serious about making a mark on the cyberspace.

  • Businesses and the future of eCommerce

    The future of e-commerce looks promising for businesses. Let’s take a closer look at how independent merchants can continue to sell more and stand out in competition with big-box retailers who also have moved online.
    Consumers are adopting new technologies quicker than ever. According to a recent study, a large amount of people now own a smartphone. That’s an increase in the owners of the smartphone in 2011 – and the market still has great potential for growth. A recent study also shows that millions of smartphone owners are using their smartphones to shop online.
    The major shortcoming with online shopping to date has been the instant gratification that comes with in-store shopping and the ease with which consumers can get their hands on products in real-time. As new technologies such as Near Field Communications emerge, that advantage for traditional retailing may shift.
    NFC is a smartphone technology that allows for easy communication and data transfer over short distances. By connecting NFC-enabled devices to a credit or debit card, paying for goods or services is simpler and faster than ever before. Imagine simply waving your phone over a product to purchase it online.
    That kind of transaction has the chance to be a real game-changer in the e-commerce space. By 2022, brick and mortar retail spaces will be little more than showrooms. Instead of loading up a cart with goods to purchase in-store, consumers will try on or sample the products in-store, quickly scan and purchase the items they desire, and have them delivered to their homes within 24 hours. The shopping mall as we know it today will be much different 10 years from now.
    Does this mean brick and mortar stores are dead or dying? No. They’re simply evolving as consumers find new technologies that simplify their lives. The challenge for businesses going forward, large or small, is adapting to this change in consumer behavior or even predict it.
    So where should businesses be focusing their efforts so they’re not tripped up by the next disruptive technology?

    So what does the future of e-commerce look like for businesses? Smarter, faster and more promising and that’s why we are introducing BOS(Business Owner Solutions)  which will provide you all the needed tools to better sell your goods and services and catch your prospective customers which will drive traffic to your business.
    To view, all the tools contained in BOS, Visit http://digitalbesltd.mydigitalbeshost.com/business-owner-solutions

  • Who gain, Who loses out: The internet of things

    Employees of a software company in Sweden had implanted chips in their wrists that activated the company photocopier. Yes, you read that right. Having minor surgery instead of just remembering a four-digit PIN is a pretty daft idea. You’d have to be a tech utopian to want to do it.
    But this news story wasn’t just about privacy and new technologies, and how “we’ll all soon be doing it”. This story was about power: who has it, who doesn’t, how it is used. And the internet of things, too, is about power.
    The internet of things connects objects to networks and exploits the data that is generated. Most of this information is machine-to-machine. For example, a Boeing 777 may generate 20 terabytes of data per engine per hour. Most of the “things” in the internet of things are focused on supply chains and on machine and system performance, not on consumers. But that is changing.
    By 2020, it’s claimed that up to 100 billion devices will be connected to private networks or to the internet. The data this creates is crunched by secret algorithms analysing how machines and systems work, how economies function and, increasingly, how humans live .
    On one end of the scale we have sensor networks, proprietary and open-source protocols and standards, and a Hobbesian war of all against all between commercial behemoths like Apple, Google, Cisco, Oracle, SAP, GE and others you have never heard of. On the other end, there’s the T-shirt that can talk to your washing machine, the ubiquitous ads that just know you’re re-thinking your summer wardrobe, the self-driving car, the smart city.
    Sure, the set of hardware, software, platforms and business models shooting up around the internet of things have the potential to do good. But they do not come innocent into a world of plenty. The internet of things will be be as much determined by its own revenue imperatives and ownership structures as our society is by inequality, consumerism and the politics of fear. The internet of things is a set of heavily invested capabilities in search of long and deep profit. Where it meets individuals, its goal is to hoover up information about us, use that to optimise processes, nudge us to earn more, consume more, depend on each other less.
    Unlike those enthusiastic and well-rewarded Scandinavian programmers, you and I don’t generally opt into the internet of things. The “trade-off” of consumers sacrificing privacy for convenience or lower prices is a myth. Faced with pages of legalese and all-or-nothing terms and conditions, US research found that individuals accept online and physical tracking by businesses because they believe that if they refuse it will happen anyway:

    The unholy alliance of CCTV, face recognition, mobile phones, fitness trackers and other wearable technologies, data brokerage and analytics, private ownership and control of previously public spaces like city squares, and increasingly wide-ranging policing powers mean we live in an urban world of ambient surveillance we never voted for. We are no longer citizens enjoying civic space; we are crops to be harvested, we are potential risks to be controlled. The internet of things does all that for us and more.
    With its insecure devices with multiple points of data access, user applications that routinely exfiltrate our sensor data, activity logs and personal contacts, and a Sisyphean uphill struggle required to exert any control over who knows what about us, the internet of things does more than create whole new cyber-security attack surfaces. It is so riddled with metastasising points of vulnerability that you begin to sense that these are not bugs, but features. As we walk around our increasingly “smart cities”, we are haemorrhaging data; but we will not be the ones to primarily benefit from mopping it up.
    Think about it.
    Who benefits from a car that transmits vast amounts of data about its use (and therefore its user) back to the manufacturer and potentially on to third parties like insurers? Who is the “you” who’ll enjoy a supposedly better-designed successor vehicle, the “you” who might be offered lower premiums? Who is the “you” the energy company (or the online retailer, or the bank) will data-mine and offer a better rate to, and the “you” that will be offered the worst cash-only deals or simply cut off?
    Advertisement
    The entire point of combining sensor and object data with individualised behavioural data sets is to create ever richer profiles that more efficiently segregate the marketplace into winners and losers. Anyone who has spent more than five minutes studying the US credit-rating agencies knows they rack up the costs of being poor (and Black), amplify inequality and disappear down a rabbit hole of proprietary methods and non-disclosure agreements the moment you try to figure out why one bad datum means you suddenly can’t get credit, an apartment lease or even a job interview. Systems go wrong. Proprietary and unaccountable systems go horribly wrong and inherently lack the ability to fix themselves.
    But while individuals are increasingly and with less choice living their lives out in the open, the companies and governments making money and decisions about us are not. Freedom of Information about public policy-making is being systematically rolled back. Companies increasingly obscure their actions behind a fog of NDAs, complex ownership structures and “proprietary information and processes”. Show me the sensor network that tells us anything useful about the private companies running our prisons or large chunks of the welfare system. Show me the big data set being mined to reduce the class ceiling.
    The internet of things is a multi-billion pound industry set for 10 percent compound growth rates every year until 2020. But it is also what Frank Pasquale calls a one-way mirror. We are visible, not to say naked, in front of it; and behind it lies … who knows?
    On that BBC programme, I tried to point out that privacy is something you have a lot less of the less powerful you are, especially in an employment relationship. It is supposed to be a right, not a luxury good. But the employees subjected to the tracking, data-gathering and zero-hours coercion the internet of things makes possible and profitable will not be the well-educated geeks who can jump to the next start-up when they tire of the free coffee (and realise they need a new chip implanted for the new photocopier). They will be the hotel cleaners, the retail warehouse pickers, the security guards and the harried carers.
    Surveillance capitalism is not the only way. Let’s stop thinking of privacy as something to do with data protection, as a set of information rights that can be banished by the magic spell of “consent”. Privacy is just another name for autonomy, for the ability to use a little intelligence and independence in our work – however “lowly” – for the right to simply be in a public space without needing an excuse or a credit card, for the ability to look through that one-way mirror and see who is looking back at us.
    Con el marcado láser se tiene una libertad absoluta para la realización de marcas, logotipos, gráficos, códigos de barras y números de serie, sobre cualquier tipo de material plástico.

  • ALWAYS –ON SSL (AOSSL), AN IMPORTANT SECURITY TO CONSIDER BY COMPANY AND THOSE WHO HAVE FUNCTIONAL WEBSITE.

    In the past many company shied away from the use of always-on SSL (AOSSL) but right now there is a growing interest in adopting AOSSL due to the increased threat from evolving cyber-attacks and the rising impact of breaches on organizations, companies and some personal website. We are encouraging companies, organizations and individual with functional websites to start using AOSSL because this will not only secure their website but will also drive a lot of business benefit to their businesses.
    The Benefits of AOSSL to companies, organizations and individuals with functional websites

     
    AOSSL is an approach to web design and implementation that uses HTTPS for all web pages, beginning with the home page. AOSSL provides the enhanced security needed in today’s cyber threat world, and in many cases delivers additional business benefits.
    Organizations such as Google, Facebook, Twitter, and others have led the charge. Such companies were early adopters of AOSSL, and by their example other organizations have followed.
    Using AOSSL is a change from past web design practices. Most companies use SSL only when sensitive information is transmitted to and from their sites. For example, it is quite common to use SSL when banking customers enter user names and passwords to sign onto their accounts or when shoppers enter their credit card information on a commerce site.
    Many companies also utilize SSL to secure internal communications but may not secure every page. A user may pass between SSL-secured and non-secured pages in a single session. For example, if a user decides to continue shopping once he has entered the checked out stage of an online purchase, browsing the site’s online catalog may result in visiting pages that are not SSL-protected. During this process the transmission protocol shifts from HTTPS to normal HTTP. So while a user’s login credentials are protected, the session ID in the cookie is transmitted in plain text when the client browser makes new requests to the domain.
    This can leave the client’s session vulnerable to hijacking and man-in-the-middle attacks. The consequences of these attacks are quite significant. The majority of financial institutions in numerous surveys considered these attacks to be the greatest threat to online banking.  For online merchants, account takeover fraud that results in hijacking of customer information is on the rise, leading to the loss of $5 billion globally each year for the past several years.
    Unfortunately, the situation is likely to get worse. Hackers increasingly have access to widely available and easy to use tools. These tools and others can steal insecure cookies and impersonate the user to steal personal information or intercept and reroute a user’s session traffic so it is converted to HTTP (thus “stripping” the SSL protection).
    These exploits take advantage of weaknesses either in the transition from HTTP to HTTPS or during the handshake stage when an SSL session is being established. AOSSL prevents these attacks using several techniques. For example, AOSSL uses HTTP Strict Transport Security (HSTS), which allows websites to pre-designate that all communications must be over HTTPS.
    From a business perspective, AOSSL offers several benefits. To start, savvy users today are looking for the extra safeguards of having their sessions on any site protected with end-to-end encryption. Those concerned with the growing problem of identity theft want stronger security. A company that employs AOSSL on its sites can tout the additional security it delivers as a differentiator. When clients or customers have a choice, they might decide that competitors that do not support AOSSL are a less favorable option.
    In some ways, the use of AOSSL reflects a shift in the way many companies use SSL. For some years, SSL was employed for its encryption capabilities to ensure confidentiality of the information exchanged between a user’s browser and a server. But increasingly, SSL is relied on to enhance a user’s trust in a company’s security practices and to verify its identity. In particular, SSL conveys a message to users that the company is a legitimate organization and its identity has been vetted by an external authority.
    A secondary business benefit of using AOSSL is its potential to get customers to a site in the first place. Google now boosts the rank of SSLsecured sites in its search algorithms. This is part of a broader Google effort calling for “HTTPS everywhere.”
    AOSSL is one of many factors that can be used by a business in its search engine optimization (SEO) efforts. If the decision has already been made to use AOSSL for security reasons, the SEO rankings boost is a bonus that comes at no extra expense.
    Currently, AOSSL has only a very lightweight impact on ranking, carrying less weight than other factors such as high-quality content. But this is likely to change. Google is keeping the impact on SEO rankings small to give companies time to switch to HTTPS, but it has indicated that over time, it may strengthen the impact to encourage all website owners to switch from HTTP to HTTPS to keep everyone safe on the web.
    Why have companies avoided AOSSL all along?
    Even with these security and business benefits, most companies have not used AOSSL in the past for several reasons. Perhaps the leading cause has been the perception that SSL needs to be applied only when secure information is being passed. As noted above, this is clearly not the case. The increased sophistication of today’s cyber-attacks and the growing use of these attacks to commit fraud are raising awareness for the use of AOSSL.
    A second reason many companies have not used AOSSL has to do with the perception that AOSSL is computationally intensive, requiring much more powerful systems to host websites. In particular, there has been a perception that running AOSSL would greatly increase CAPEX and OPEX costs related to operating a website. On a high-volume website, the assumption has been that the additional computation muscle needed to perform the associated encryption/decryption on AOSSL would require investment in new hardware.
    Fortunately, perception does equal reality. Google researchers testing the impact of SSL on system performance found that it increased the CPU workload on its systems by less than a 1 percent.
    An additional reason companies have not used AOSSL is the potential site performance impact it would have due to network latency. The latency comes in by virtue of the additional complexity of the SSL and Transport Layer Security (TLS) handshake. The back and forth exchange required to establish and maintain a secure session is dependent on network performance. A poor connection, low bandwidth link, or congested hub could lead to delays that slow the overall user experience when interacting with a site. However, in most cases, the delays are minimal.
    Furthermore, the performance penalty often can be managed with proper planning. For example, a heavily trafficked site using AOSSL could use higher bandwidth access lines or prioritize SSL session traffic.
    Selecting the right solution
    Once the decision has been made to implement AOSSL, the main priority is selecting an SSL Certificate.
    SSL Certificates are used to secure communications between a website, host, or server and end users connected to that server. An SSL Certificate confirms the identity of the domain name that is operating the website, encrypts all information between the server and the visitor, and ensures the integrity of the transmitted information.
    There are several general types of SSL Certificates, each offering different levels of assurance to end users. Certificate Authorities (CA) that issue the certificates typically have their own naming convention for the various certificates; however, the general classes of certificates can be categorized as follows:

  • The Impossible Mission of HTML5 – Leading to The Death Of Flash

    From Flash To HTML5

    At previous time we we create eLearning software, we have used this platform to deliver high end, award winning content wrapped in our own custom framework. The platform has vast adoption given its thriving developer community, user friendly audio visual tools, powerful scripting language, and cross browser support for desktop. But that’s all changed.

    When Flash Started Loosing

    It became clear during the release of the first iPhone and subsequent Android devices that Flash just wasn’t going to cut it. Android tried to maintain Flash player support, but performance issues coupled with battery usage really killed its chances. For a while making mobile courses required expert level web development skills, primarily to navigate the array of unique platform requirements.
    Creating a mobile course that was also available on Internet Explorer, without sacrificing production value, was challenging. Eventually in September 2012, with the announcement of new recommendations for HTML5, the W3C sealed the Flash player’s fate. It was obvious that HTML5 was the way forward and we would need to build a new course framework from the ground up. We began development with a few things in mind.
    First we needed the ability to run content across the widest distribution of browsers possible, everything from Internet Explorer, Chrome, Firefox, and across any device with modern standards.
    Second, it would have to allow us to produce courses with the same rich content as Flash; custom user interface, scripted interactions, animations, video, and audio. Finally, provide a way to convert older Flash content for mobile devices.
    I’m proud to say we managed to reach all of these goals and we have been using (and refining) this framework for the past 2 years.

    How To Convert Flash To HTML5

    After an extensive amount of research and testing we decided to use CreateJS as a base for our framework. CreateJS is officially supported by Adobe and includes a very powerful set of API’s similar to the AS3 language. We were able to leverage this to produce the three modular libraries; a course controller, flash layer and canvas layer. They allow us to use component based detection to determine if we are able to operate using HTML5 canvas (with 2d context) or Flash.
    In concert with our course software we have also refined our process by building a set of custom publishing tools. Built as standalone applications our tools use JSFL to interact with and manipulate normal flash files. They have allowed us to fully automate mobile optimization, and mitigate common HTML5 conversion issues.
    Our tools allow us to build content in Adobe Flash, and output directly to both Flash player (as a backup for older devices) and HTML5. Meaning we are able to produce courses that work on legacy browsers, and mobile devices. It also means we are able to recycle existing content (given source files) and convert it into something your users can view anywhere.

  • The future of PayPal as the operating system for eCommerce said the future CEO

    The chief executive of the soon-to-be-public company talks Venmo, bricks-and-mortar retail, and Apple Pay.
    As PayPal prepares to become an independent company in the next few months—it’ll trade under the old stock ticker PYPL—future company CEO Dan Schulman gave the media a glimpse at what the future will look like for the payment giant at a San Francisco event on Thursday.
    eBay  EBAY 1.00%  of course decided to spin-off PayPal as a public company, the company it acquired more than a decade ago, under pressure from activist investor Carl Icahn.
    Schulman cited PayPal’s continued strength as growing payments provider to both merchants and consumers. In eBay’s first quarter earnings report in April, it was revealed that PayPal’s revenue had surpassed that of its parent company for the first time, with revenue growing 14% to $2.1 billion. With $8 billion in revenue in 2014, PayPal could be in the elite group of Fortune 500 companies, he added.
    “This growth rate is all about mobile,” said Schulman. “Online commerce is being replaced by mobile.” Mobile payments through PayPal are up 40% year-over-year and now represent 30% of all transactions.
    He cited particular strength in PayPal’s peer to peer payments app, Venmo, which allows people to send each other money from debit accounts, effectively replacing checks and cash transactions. In the first quarter of 2014, Venmo did $300 million in transactions. That grew to $1.3 billion in payments volume in Q1 2015.
    The next chapter, however, said Schulman is that PayPal is going to “be more than just a button on someone’s website.” He envisions PayPal to be the operating system, similar to Apple’s iOS or Google Android, for commerce. Part of that plan is to a full suite of services that allows consumers and merchants to access any type of funding, whether that be a cash advance, credit, or payment from another person.
    The vision itself sounds like the modern version of a bank. Schulman alluded to this, explaining that PayPal’s technology could offer consumers easier simpler way to manage and move money, especially people who “live on the margins,” of traditional banks. “We want to democratize the management and movement of money.” Financial inclusion will be a theme around how PayPal is approaching engaging a new set of younger users in the future, he added.
    Growing payments abroad is also going to be a continued focus for the company. PayPal recently inked a deal with Chinese telecom giant China Mobile to allow PayPal merchants to accept payments from users who want to pay using China Mobile carrier billing. PayPal also struck a similar deal with the State Bank of India to allow card holders to have easier access to merchants that use and accept PayPal.
    What was less cogent in the vision statement was PayPal’s ambition to be present in brick-and-mortar stores. PayPal has previously made efforts to carve out a spot in the physical retail world with its Square competitor PayPal Here, as well as integrations at point of sale registers at large retailers like Home Depot. But both efforts haven’t really drawn much adoption and success. In fact, PayPal’sin-store divisions were the hardest hit with the company’s layoffs earlier this year.
    In an interview with Fortune, Schulman said the reason these ventures had troubles is that PayPal “tried to do things in bespoke way” that carried a lot of risk because the ambition was to change consumer behavior.
    In the future, PayPal will be focused on entering the physical world from where it is already a leader—mobile, he said: “This plays into our strengths.”
    With the PayPal’s $280 million acquisition of Paydiant, the company behind mobile wallet technology CurrentC (and Apple Pay competitor), PayPal is betting that consumers will use their mobile phones as a wallet that includes ways to pay, loyalty rewards, coupons, and more.
    But Schulman also said during the event PayPal would be open to working with Apple Pay, and Android’s payment services as an effort to more of an open platform. He didn’t share any further details on how these relationship will evolve in the future.
    Fast growing payments unicorn Stripe was recently picked as a provider to process payments for Apple’s fledgling payments service–at the time Braintree was missing from the list, but has since been added. Google is also focusing on powering mobile payments with its newly debuted Android Pay, a way for developers to integrate payments into their Android apps.

  • Security Advice You Can Count on when it come to your computer and the internet

    I couldn’t put my finger on what was nagging at me the last few months. When I finally sorted it out, it was the realization that most computer security advice is an absolute waste of time — and most of what isn’t is barely useful.
    Even I’m guilty. Statements I’ve spouted in the past, like using long and complex passwords or hardening your computer system, don’t really deliver much value. Disable weak password hashes? That was good advice 15 years ago. Use an up-to-date antivirus program? If that worked, we would have solved the problem decades ago.
    When I look at the data of how people and computers are compromised, those previous recommendations didn’t effectively address the attack vectors that make malicious hackers so successful. Instead of giving you dozens to hundreds of truly ineffective recommendations, I’m going to give you a few basic defenses that really work.
    Forget every past computer security advice you’ve ever read — even from me. This is the real deal. Everything else is wasted cycles.

    Bank robbers rob banks because that’s where the money is. Malicious hackers and malware concentrate on exploiting the most popular programs because those are the ones most likely to be on the computers they want to compromise.
    If you look at how most computers are compromised, it’s through unpatched software. Usually, the exploited unpatched software is the popular software used by everyone. Today, client-side, Oracle Java leads the pack, followed by Adobe Flash and Acrobat Reader. Server-side it’s unpatched admin or remote access tools. The most popular programs change over time. What doesn’t change is that those programs are the ones most often exploited.
    You’re going to get far more bang for your buck by patching the most commonly exploited programs and doing that perfectly than patching almost all of your programs with less rigor (which is the case in most organizations). If you can’t patch or mitigate the most exploited programs, the rest of your efforts aren’t worth much.

    Social engineering is a fancy name for a con, accomplished over the phone, via email, or on the Web, where the con artist manages to extract some vital piece of information or convince the victim to install malware. The only way to guard against social engineering is to keep your user training up to date to combat the most prevalent threats, which most companies fail to do.
    Test your employees, and if you can successfully socially engineer them, do a better job at education. If you have an excellent user education program and employees still fail the test, redouble your efforts.
    Make sure your user education material tells people they’re more likely to be exploited by trusted websites than strange or new websites. Tell users not to be tricked into installing new programs. Let them know that popular, free software, is often full of unwanted programs and malware

    Although the security of 2FA (two-factor authentication) is often oversold, its effectiveness often depends on which risks you think you’re mitigating. For example, 2FA can’t stop most of today’s APTs (advanced persistent threats) once they have full control of your PC — but 2FA is great at preventing phishing attacks (which often precede the ultimate compromise).
    If you can be strict enough to allow only 2FA when users log on to company resources, then there’s no logon name and password combination to steal. When the fake phishing email arrives asking for the user’s logon credentials — sorry, bad guy, you’re out of luck. This works well only if you use 2FA everywhere on the corporate network, and you don’t need a logon name and password for some websites.

    After phishing, the most common way hackers obtain your password is from other systems and sites. Many users have been successfully phished for their Facebook or Twitter logon and the attackers use the same password for the user’s corporate logon. It works all the time.
    Make sure your corporate passwords never match any password you use off the corporate network — and don’t use the same passwords on multiple websites. Even on the corporate network, local admin and service/daemon accounts should never share passwords on different systems — it allows a credential theft attacker to leverage a single compromise into a network-wide compromise in minutes. Not sharing local passwords is one of the best measures you can take to slow down attackers and minimize the damage.

    Malicious hackers always escalate their privileges to obtain the highest security credentials in the network. Once they have those, it’s game over. Want to frustrate a hacker? Don’t have any permanent members of any elevated group, and monitor and alert on unexpected member additions. There are ways around this defense, but most hackers are stymied when their go-to methodologies fail. Frustrate a hacker today!

    If you’re collecting a bazillion events a day, you’re doing it wrong. Instead, focus on defining only events that indicate maliciousness, and only alert on those. Everything else is trying to find needles in a haystack. If you want to know what events to monitor, email me.

    Today’s attackers gain a regular user’s credentials, then begin moving around the network accessing servers and sites the user’s logon credentials can access. Or they are using memory-only resident software that’s really hard to detect. But no matter what they use, bad guys move around networks in illegitimate ways. Use a network flow analysis tool, define what is normal, and alert on the abnormal.

    If everyone used a whitelisting application control program it would make everyone’s life easier. Whitelisting programs can prevent previously undefined programs from executing. That’s a terrific way to stop previously unknown malware. But even if you can’t use it in enforcement mode, turn on your application control program in audit-only mode. Then you can alert on and respond to new suspicious programs without interrupting normal operations.

    Lastly, learn how badness breaks into your network and put less focus on names. The name of the malware program on an exploited computer isn’t nearly as useful as how it got in (through unpatched software, social engineering, and so on). Learn those modalities and focus on mitigating those types of threats; then you have a real computer security defense plan in the works.
    After every major public hacking attack I read article after article offering absolutely useless advice. Those writers aren’t thought leaders. They are parroting the unoriginal, unsupported dogma they’ve read. They haven’t spent years looking at the data and interacting with hacked customer after hacked customer. I have. This advice is the real deal. Follow it, and you’ll be better off than anyone else.
    Orinally writen by Roger A. Grimes