Monday, 4 July 2016

Best practices for securing Desktop and Laptop Endpoints..


One of the most vulnerable parts of your infrastructure is the desktop and laptop computers that your end users use. These devices can be responsible for bringing in viruses or malware or causing your organization to lose sensitive data that can subject your organization to all sorts of headaches. In this guide, I’ll cover the practices I use when securing end user desktop and laptop systems.
Even in the age of BYOD (Bring Your Own Device) and things such as the Windows Store in Windows 8+ that give end users more control over their devices, maintaining some level of control over the endpoints that your organization owns is still important for security reasons. Following are some of the things I do as best practices when securing an organization’s desktop and laptop systems.
Be transparent to the End user : If you’re implementing any of the technologies in this article for the first time, I highly encourage you to communicate the changes to your end users and make sure they know how the changes will impact them. Letting them know about the changes and how they will benefit the organization will go a long way toward gaining acceptance.
You should also strive to keep the changes as unobtrusive to the end user as possible. You want users to know the changes are there, but the changes shouldn’t be so drastic that they impact the performance of the users’ computers and their ability to get their work done. The worst thing you can do is implement a security change that users circumvent because the change prevents them from doing their job.
Inventory Management and MDM :You can’t secure what you don’t know about. Running a product such as System Center Configuration Manager, LANDesk, Altiris, or some other systems management platform not only lets you inventory all of your assets but also gives you the ability to manage other aspects of your endpoints, such as software updates, antivirus, and firewalls. If a device walks away, either through loss or theft, having access to its model and serial number can be helpful to law enforcement and insurance companies if you insure your devices.
For your mobile devices, a Mobile Device Management (MDM) solution is a must for maintaining those devices that are on the go and not regularly connected to the corporate network. Products such as Microsoft's Intune are a great option for managing those systems and can also integrate with SCCM.
Antivirus/Anti malware : This is really a no-brainer, right? Sure, Windows 8 and 10 come with Windows Defender built in to the OS, but are end users going to call their IT person or the Help Desk every time they get a notice on their computer that the antivirus application has performed an action? My experience is that most end users won’t until it impacts their ability to work.
I highly recommend using an antivirus/anti malware product that allows you to manage the application on the endpoint rather than something like the built-in Windows Defender that doesn’t send feedback to IT.
Enterprise antivirus applications check in (usually through an agent) with a central server that IT can use to control the configuration, control updates, and monitor the solution. And, it’s really nice to set up email alerts for system infections. Who wants to have to run a report on a system every day when you can just have it emailed to you?
Firewall : Another no-brainer. Personally, I’m a fan of the built-in firewall in Windows 7+. It handles both inbound and outbound filtering and supported IPv6 before most of the third-party products out there did. Using the built-in firewall also gives you the benefit of being able to control it through either Group Policy or System Center Configuration Manager.
Disk Encryption : Disk encryption is no longer just for mobile devices. Encrypting the hard drives of your endpoints is a must now. Even if you’re using technologies such as Folder Redirection to keep data off computers, sensitive data can still end up in Offline Files, temp directories, and other non-standard locations for data storage, such as folders in the user’s profile.
File Explorer showing a BitLocker encrypted OS disk, data disk, and removable drive.
What if your users don’t have access to sensitive data? You should still seriously consider encrypting all devices regardless of form factor—even if the device is stationary and physically locked down. An attacker or malicious employee can use an offline attach to reset the local Administrator password and access the computer with that local Administrator account. Once after the system has been compromised, it can be used to steal the credentials of anyone logging in to the computer and all sorts of other malicious activity if it is connected to your corporate network.
Application Whitelisting / Blacklisting : One of my favorite new features that was included in Windows 7 when it was released is AppLocker . AppLocker is an application control service that allows IT to whitelist (allow) and/or blacklist (deny) executable, scripts, Windows Installers (MSI files), Windows Store /Universal apps (in Windows 8+), and even DLL files from running on endpoints.
With AppLocker (or other third-party solutions), you can allow only selected software to run based on criteria such as file location, digital signature, or file hash. Even if you set a policy that allows all software to run by default, you can still blacklist/block applications that your users shouldn’t be using with the same location, digital signature, or file hash settings.
AppLocker blocking an unauthorized application from running (program is blocked by group policy)
Windows and third-party updates : Even if you’ve locked down a computer to the point of being barely usable (which I don’t recommend), missing updates can still allow an attacker to compromise the computer. Smaller organizations can simply use Windows Update to automatically update systems. Larger organizations can use Windows Server Updae Services (WSUS) or systems management products such as System Center Configuration Manager for pushing out updates for Windows, Office, and other Microsoft products.
Third-party updates are just as important (if not more important!) than Windows and Office updates. Adobe Flash and Oracle Java both have a bad track record when it comes to security and usually need to be patched as soon as the updates are released to the public. Configuration Manager is capable of publishing third-party updates using the System Center Update Publisher or via plugins from third-party vendors.
Enhanced Mitigation Experience Toolkit (EMET) : Last, but certainly not least, is the Enhanced Mitigation Experience Toolkit. EMET is a utility from Microsoft that helps prevent an attacker or malicious user from exploiting vulnerabilities in applications.
EMET can enable Windows features such as Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), and other enhanced security features for applications that don’t specifically request them based on how the vendor or programmer designed them. This can act as an additional safety net to protect applications that may have unknown security issues or known security issues that, for whatever reason, can’t be patched.
Conclusion 
I hope this best practices guide can serve as a starting point for improving the security of your organization’s desktop and laptop endpoints.

The one with the grey lapto




I remember the first time I encountered the Internet. It was 1996. It was a sunny day. I was inside, in my father’s office, watching him hook up his grey laptop. It was the only device with a modem card installed. He opened the device, selected the modem connection window, pressed start and we listened to our phone line dialing. For the next half hour our family was unavailable to pick up the phone. The internet was using it.
The sounds stopped, my father double-clicked on the lighthouse icon and Netscape loaded steadily for the next 10 minutes. I forgot what we searched for or if we just stared at the browser screen, unable to grasp the singularity of that moment. All I remember is that it was a glorious day.
20 years later, the Internet has expanded beyond the boundaries of my imagination. Approximately 40% of the world population is connected and about 1.5 billion have an active Facebook account. And interestingly enough, there are still 50 million or so active MySpace users.
Sources vary but per minute about 640TB data is being transferred and 200 million emails are being sent. I can only estimate the number of likes and shares in that same minute. The sheer immensity of these numbers makes it impossible to grasp their true meaning and I have trouble relating to what these numbers mean emotionally or what they mean to society.
My brain seems naturally predisposed to think micro instead of macro. For instance, when it comes to memorization, the method of loci, used to memorize π to 67,000 digits, focuses on deconstructing a number and attributing each element to a certain object in, for instance, a building. In the end the number is no longer a number but has become part of a personal story. It is just one of many examples that strengthen my belief that faith in technology is just an expression of the human acknowledgement of its own fallibility.
Since the day my family sat around that small, heavy, grey laptop and watched the Internet load, the challenge of memorization has been overcome. Our collective memory is now in the cloud, yet scattered and often difficult to contextualize. The new challenge lies in improving our understanding, building a story that makes sense and closing the gap between data and knowledge. Google is probably working on it but until then it is up to us.

Modernizing Laptop Management


It’s been a busy—and incredibly exciting—summer for business mobility.
Over the past several months, I’ve been close to some of the biggest innovations and announcements in the business mobility space. I’ve spoken with customers about their mobility journeys over the past several years, but recently a striking new reality is surfacing to the top. We are witnessing major transformations in phone, laptop and tablet operating systems and hardware, and at the same time, a revolution in management and security is taking place. These shifts, combined with the innovations coming from an ecosystem of application developers, security and technology vendors, are ensuring that the way organizations manage their desktop and laptop footprints will never be the same.
Reimagining Imaging, Access & Management
I’ve been saying for years that we have to rethink mobile computing for both the user and IT, in a way that enables simple access, collaboration and sharing of information.
Your users just want to be able to pick up any device and get to work. They want single touch access to information regardless of the device or business policy. When enterprises fail to provide a great, consumer-like experience for accessing apps and data because of security, employees will invent new ways of working that are often less secure and put your business data at risk.
Conversely, IT managers are asked to do more with less, and they also want an elegant way to deploy, manage and secure users’ devices within a single management console. Until recently, we’ve seen the way organizations manage their mobile fleets contrast with how they oversee their pools of desktops and laptops. Organizations tend to use different systems from different vendors to meet different operational requirements with varying degrees of success.
The industry has been working towards a vision of a unified mobile device management experience across iOS, Android and Windows Phone, but unifying laptop and desktop management into that same paradigm has always been on the periphery—a completely different process and toolset. IT managers have to juggle multiple management consoles, lifecycles, user groups, contracts and app and software delivery processes. Additionally, the traditional desktop management environment often requires hours of redundant tasks, such as imaging, software updates, app installs and virus definition updates. And with locked-down desktops, the result is a flood of support calls. In fact, in talking with customers, it is not uncommon to see an average organization having one IT person for every ~250 desktops deployed. Compare that with the average organization with one administrator for every 3,000 mobile devices deployed via EMM.
All of this is about to change, thanks to recent innovations.
Two Transformational Leaps toward Unified Management
Since the entrance of desktops and mobile phones into the business world, there’s been a very clear line between “mobile” and “desktop.” Companies have both desktop managers and mobile managers. Laptops are managed via PC lifecycle management, while smartphones and tablets use EMM. These two different worlds require very different strategies, processes and people resources. Two important announcements this summer have changed everything.
Microsoft’s Windows 10 debut at the end of July now makes it possible for IT pros to make EMM the standard management for devices running on the new Windows operating system—and yes, this includes the desktops and laptops running Windows 10. As the first truly mobile operating system for both desktop and mobile devices, and with the concept of universal applications, Microsoft has helped make true unified endpoint management possible using solutions like AirWatch EMM. No longer will there be Windows desktop apps and Windows mobile apps; apps are just apps, regardless of the device on which end users access information.
Let me reiterate, since I’ve been asked about this a lot recently: Windows 10 makes it possible to manage Windows laptops just like you manage Windows mobile devices—one operating system with interchangeable apps for desktop and mobile. Because of this, you can now manage ALL of your Windows 10 devices with AirWatch EMM, right alongside your fleet of iOS and Android mobile devices. By unifying the Windows experience across the device ecosystem, Windows gets us tantalizingly closer to the transformation we’ve been innovating toward all these years. In fact,Microsoft took the stage for the first time at VMworld U.S. this year to talk about how we’re working together to make this EMM dream a reality. The vision of every device, one console is closer than ever before.
On the Apple front, APIs have enabled us to manage Mac OS X and iOS devices in a similar way for years, and we’ve been innovating quickly. So quickly, in fact, that we just announced support for Mac OS X El Capitan enrollment and management. The El Capitan capabilities (see the impressive listhere) make consolidated laptop management even more of a reality. But the key, most important aspect of this announcement is that these enterprise-ready features get us so much closer to achieving truly unified endpoint management.
One Vision. One Experience. One Console.
Our vision has always been to enable a user to be productive through a Digital Workspace of apps, data and services that enables a productive workforce across any device. Users don’t care “what type of app” it is; they just want them to work! They don’t care about certificates or authentication or secure cloud app delivery. They don’t care about the delineation between personal smartphone or work computer. They only want to access an application for work or create a spreadsheet in the office, and then access the updated version again on their iPad at home. So for years, IT teams, developers and technology innovators like us have been working unceasingly to superglue together the many pieces needed to provide that unified, seamless experience for users AND help companies protect their business-critical data to achieve their objectives. But now, the stars are aligning with EMM across every operating system, and thanks to the tireless work of AirWatch’s developers, we can finally treat laptops and desktops in the same way as mobile devices. Even better, we can unleash the full potential of our teams.
One console for both our desktops AND mobile devices. Finally, modern management has arrived.
Do you agree?

Securing Your Laptop


I wanted to provide some simple tips that would allow you to secure your laptop that goes beyond the obvious physical security. It is quite possible that your laptop sits at work where you feel it is secure, but it is more likely that you travel with your laptop and take it with you wherever you go.
Today, no matter the operating system you use, there are tools integrated with your laptop and many more tools that are available free of charge on the internet that can increase the security of your laptop. I wanted to take this time to introduce you to some of these tools and how they can be best used.
1. Use your BIOS settings to Disable booting your machine using a USB or a CD/DVD. What does this mean? Well, in simple terms, your system BIOS can dictate many aspects of how your system's hardware behaves and one of the important components of BIOS settings is allowing your machine to be started or restarted using a USB (externally connected on your laptop) or a CD/DVD drive. You can enter your BIOS settings by restarting your machine, pressing a key (such as F2, F10, etc.) during the bootup process, and changing the setting. You can also assign a BIOS password so that an unauthorized user cannot enter the BIOS setting and change your system's' behavior without your permission.
2. Encrypting all of your drives, whether it's a hard drive or a USB (flash/thumb) driveis a practice that many organizations employ to secure their data, but it is something that is rarely used on personal laptops. If you are separated from your laptop, and someone manages to gain access to your hard drive, what is going to prevent them from putting that hard drive into their own machine and accessing your data? If there is any personal data on your hard drive you wish to protect, you should definitely encrypt your hard drive. Tools such as Bitlocker Drive Encryption (BDE) in Windows and freely available tool for other operating systems including Mac OS X is calledTrueCrypt can help accomplish drive security.
3. Use and frequently change Complex Password for all of your applications and to your laptop. Complex password implies that you have a password that is a minimum of 8 characters in length, contains at least one uppercase letter, one lowercase letter, a number, a symbol, and does not contain a dictionary word. So, instead of using 'ComplexPassword' you would change it to 'C0mpl3xP@ssw0rd!' and by doing so, you would make it monumentally more difficult for a password cracking system to unlock your computer and the sensitive documents on it. You can go to many websites that will generate a complex password for you. Websites such as Strong Password Generator will do just that.
4. If you travel for work and are often in hotels or other insecure locations, you should think about investing in a Travel Router that will secure all of the traffic that is going to and from your machine. If you have a mobile phone with a data plan that will support your normal network usage, use your phone as a mobile hotspot instead of a public hotspot. Be warned that if your data plan on your mobile phone is not high enough you will end up paying immense fees on data overage charges. Study your plan carefully before you decide to use your mobile hotspot to connect your laptop and stream any type of data. Mobile hotspots are perfectly fine to send and receive emails along with browsing the web.
5. If you travel a great deal and are at airports all over the world as I am, you may want to invest in an inexpensive device that will send an alert to your mobile phone if you have moved more than a few feet away from your laptop. Examples of such devices include Kensington Proximo or a hipKey from Hippih.
I hope that this article has made you aware of what is available for you to help secure your laptop. 
Until next time, this is Rafiq Wayani signing out!

The Laptop is The New Factory


Even before world war I, the economy of most western countries was moving toward manufacturing. Farming was still important, but people left the farm to work in the new factories in hope of a better income. This trend was happening prior to WWI and WWII, but each war – with it’s emphasis on mechanised warfare – hastened the move to industrialisation.
In a manufacturing economy, people go to where the tools are. And a factory is a giant tool. So people moved to cities, started using mass transit (and eventually the automobile) to get to work. That was not always the case. Once upon a time, people woke up at work. Framers lived on their farm. Hunter/gathers went out to the hunting grounds, but they carried their tools with them.
Today, if you have a laptop, you can login to a company website, an external website, or create content on the laptop. That changes the economy back to how it was. But the infrastructure is set for a factory mentality. We drive to work, we sit in cubes … but work on a computer to produce our labour. Increasingly we work on a computer to provide the value to our organisation. Yet the computer, does not need to be “at work.” And so this changes how society supports it’s workers.
If someone has a laptop, they can create. About 30% of people in the United States work as freelancers. In the UK, this particular work forces are on the rise at 14% increase per year since 2011. And the trend in the EU, is a 45% rise. And a lot of freelance work is completed with a computer. Think web design, graphic design, writing … the list goes on.
This means that companies can allow workers to work from home, or hire from an increasingly large pool of freelance talent. Coffee shops like StarBucks, Costa and Nero in the UK, offer freelancers the feeling of working with other people, yet working on their project – all for the cost of a coffee. I wrote this post from Costa Coffee central London.
It makes no difference if a person works from home or office, the energy to run their computer is the same. But getting to the office, for many workers, is a massive waste, summing up: 1h morning / evening commute, time 4 week, times 11 month (1 month break)… equal 440 hours or 55 days ! This changes the economics of how society works. And as a result, many people are moving to walking communities. It may be downtown, it may be into cities that are walkable.
This remote work force has generated new needs and new services. I particularly like the work of Lisette Sutherland. Lisette is a specialist in creating online collaborative communities with over 10 years experience with web-based collaboration tools and online community management. Her goal is to get the best people working together regardless of location. She recently co-authored “Engagement Management: a step-by-step guide to building a thriving social network“, and helped over 40 organisations and businesses setup and run online communities.
This also means that computer savvy workers have employment options. At the same time, workers in other countries can compete for jobs, like web design, graphic design, and writing. As the laptop becomes the new factory, workers are at work, where ever they are.
When people needed the factory, companies had a lot of power over workers. If the laptop is the new factory, some power moves back to the worker. This trend will reshape society.
Have laptop – will travel.
More on my blog http://outofoffice.today
My recent post:

Why Microsoft's Surface Pro 3 is the most important "laptop" for laptops right now

Yes, I’m typing this on a Surface Pro 3 (SP3), but this is NOT a review. This is not a propaganda piece, either. This is about recognizing the roles a certain product and company play in the tech space. Now that expectations have been set…
Are you familiar with the terms “category manager” or “category management”? In the marketing world, they’re often used in the context of consumer packaged goods to describe the role that product group (think: a segment of similar products e.g. toothpaste or cereal or cold beverages) leaders play for their retailers. Bear with me, here’s a quick, arbitrary yet explanatory example: Walmart buys Philadelphia cream cheese from Kraft. Let’s say Philadelphia is the cream cheese innovator and best seller in the cream cheese category. Walmart asks Kraft and its Philadelphia brand managers to be “category managers” for cream cheese store-wide. Kraft’s brand managers are now responsible for boosting not only the sales of the Philly brand at Walmart, but also the sales of all other cream cheese brands on Walmart shelves. What’s good for the goose must be good for the gander, am I right? I contend that, whether requested to do so by the ailing PC/laptop market or not, Microsoft is playing the role of category manager right now.
And, its playing the category manager quite effectively. Although, it is not the best-selling or most popular laptop out there, it could be argued that the SP3 is the most innovative. The SP3 was released under the boisterous claim that it could replace your tablet and your laptop. Oh, who am I kidding? It claimed that it could replace your iPad and your MacBook Air! Those two Apple products are the most popular, best selling items in their categories. What a wild and machismo claim to make! Several internetbloggers and journalists have weighed in onwhether this comparison is based in logic or fact. Some were on the fence, some laughed and some kind of respected Microsoft’s gumption. At the end of the day, it doesn’t matter if the SP3 replaces your iPad and MacBook Air. It doesn’t matter if the SP3 ranks higher on Consumer Reports or Engadget. What does matter? The SP3 has started a dialogue among consumers about what computing could be. Here are the type of questions I’ve seen consumers and bloggers pose recently (along with some of my own answers):
  • Why can’t our computers be slim AND powerful? The SP3 easily out-specs the MacBook Air and Sony Vaio Tap 11. And…
  • Why can’t our tablet hybrids be light AND still be made from high quality materials? The Sony Vaio Tap 11 is light, but frighteningly flimsy. The ASUS Transformer Book line is clothed in polycarbonate and still heavy. And…
  • Why can’t we get a screen that’s sharp and bright? In every square inch of SP3 screen, there are 216 pixels. Macbook Air boasts 135 pixels per inch. That can’t be found on the Apple website. Yes, the Macbook Pro has a higher pixel count, but it’s not a direct competitor to the SP3. And…
  • Why can’t we have a touchscreen, too? You know, if we wanted it? Apple is the last major brand without a touchscreen laptop. And…
  • Why can’t we have a real computer in tablet form? Lenovo has two options: one is 4 pounds with its keyboard and the other uses an Atom processor. Office for iPad doesn’t make the iPad right for the office.
There are trade-offs to every machine. Sure, there are enough areas where the SP3 falls to its competitors to prevent it from flying off of every shelf everywhere, but Microsoft has started a conversation and a comparison war that will surely boost laptop/ultrabook/PC innovation in the years to come. Let’s face it, Microsoft has earned its role as a category manager once again.
*image from mashable.com

That Newbie Feeling - Your laptop should have been ready by now.


When I started my first proper job in 1988 the induction process was simple. I met my manager and he wrote down a list of things in his book that I could probably have a go at. Then I was introduced to an INTEL Development station and left to teach myself the CORAL66 programming language. Maybe a paper memo was also distributed around the office telling everyone that I had arrived.
It's not like this any more. Being the newbie is now a trial by all kinds of strange and wonderful ordeals - on the pilgrimage whose prize is termed "getting your IDs". Yet even before you can embark on this journey towards this nirvana of "login" there are so many things to accomplish.
The first test will be to attain the sacred key known as the "ID badge". Without this piece of rectangular plastic no doors will open for you and turnstiles will simply embed themselves in your thighs. Toilet trips will be impossible and going outside for a smoke will inevitably become a one way journey. Obtaining this talisman involves collecting signatures on a form and a visit to a dingy security office. Here you will be photographed by a camera, held aggressively inside your personal space. The picture of you in this anxious state will subsequently go everywhere with you. The ID badge will have to be collected about 1-5 days later depending on how you handled the necessary small talk.
So you are ready for the next stage. Being introduced. You shake the hands of many people whose names you will never be able to remember (because you are now rapidly decaffeinating and focusing only on where the loo might be). Some people are going to be key to your daily work; most of these you wont meet at this time. Now you are plonked at a temporary desk some distance away from those that you just met and left to make friends with workers around you.
As you sit abandoned there, it's time to start considering some of the big questions.
What things do people find funny here? Do you have to buy cakes if it's your birthday? How does the coffee round work? Is it 8-4 or 9-5? When is lunch? How do I charge my phone? How do I login to the wireless network? Would now be a good time to pop a picture of my "new job" shoes on Facebook?
After marinading for a while you will be handed a scrap of paper by your overloaded manager. This has a user name and password on it. These will not log you into the workstation in front of you, despite many attempts. A 30 minute call to the oracle known as "the helpdesk" will be needed. This eventually reveals it's an "0" not a "o" in your user name.
Once you have got past the login screen ordeal, your neighbours will ask you if you are OK with crisips? A quick glance across at the snack machine and you nod the affirmative. Only later on do you discover that CRISPS is the Central Request for Information Systems Provisioning System and without access to this the road to enlightenment is truly blocked.
So the days will pass and with continuous help from CRISPS and the help desk you make good progress. That is of course until the time they call "the coming of the laptop". Near to the much feared security office is another place where you will have to go. It's the desktop support team; here they will have a laptop for you. Don't expect to just march in and exit with your machine. It will be confined to a rucksack that weighs about a hundred kilogrammes - Kensington, Mouse, Power Supply and all sorts of other unfathomable ironmongery will slow your progress. Expect also to have to sign in triplicate for these things.
Everything that previously worked on the desktop computer will not work on this laptop. You wont of course be able to return to that computer to find out why because you are now officially "hot desking". It's back to scratch with the help desk - obviously after you have made friends with a whole lot of new people in your new location.
Then before you know it, there comes that holy day - the day it all makes sense and the higher state of WFH is achieved.
I write all this though as a tribute to that special person in every team; the knight in shining armour. There is always one individual who will take pity on you in your quest, They will go out of their way to sit down and explain how everything works and answer every silly question. To you all, past and present I offer my eternal thanks.
Thanks for reading, I'm back off to my INTEL Development station.