How to Block Access to a Particular Folder for a Guest User in Windows 7

If you have a guest over who would like to use your computer to access their email or Facebook or cruise the internet, you can ensure that they don’t accidentally  or intentionally breach your privacy. By activating a Guest account for them you can give your guest a safely limited account that won’t allow system changes. Additionally, you can protect the administrator’s account and any other account with a password.

Enabling a guest account helps draw a line between browser preferences, history and bookmarks, and personal files, and other system settings.

To activate the Guest account, Click the Start button, then Control Panel and find Users, User Accounts or, as in Windows 7, “User Accounts and Family Safety”.  Click on “Add or remove user accounts” and find the Guest account.  If it is off, click the icon to turn it on.

Now that you have an active Guest account, here is a very simple yet effective method to let your Guests access your computer without the fear of exposing your personal documents and files. Furthermore, this method could be used to limit access to folders for just about any user and not only the Guest users.

Step 1: Make sure you are logged in to an administrator account. Right-click on any folder you want to block from Guest users and open the Properties window.

Step 2: In the folder property window, open the Security tab and click on the Edit button to change the permission settings.

Step 3: You will see a list of groups and users of your system. As there’s no privilege level defined for Guest user here, click on the Add button to include the Guest user.

Step 4: In the Select Users or Groups window write down guest in the text box below enter the object names to select and click on the button Check Names. Windows will now check for the user or group name for its existence. Once the window has identified the user, click on the Ok button.

Step 5: Now select the Guest user in the list, and check deny on the permissions you want to revoke from the user and click Ok.

Step 6: Windows will ask you for your confirmation by a Security Warning dialog box. Click on Yes and wait for Windows to change attributes for the files.

From now on, if a guest user tries to access a folder, you’ve denied them permission to access the folder so they will be prompted to enter the admin password.

 

What Techies Will Be Watching on Capitol Hill

From piracy to privacy, and cybersecurity to spectrum, Congress this year will be wading into several potentially blockbuster issues that could affect a wide swath of the tech community.

Below are just a few of the major issues to watch for.

Online Piracy

When the House returns later this month, Judiciary Chairman Lamar Smith, R-Texas, has vowed to continue a markup he started before the holiday break on legislation that would provide new tools to curb piracy and counterfeiting on foreign websites.

The committee spent two days last month wading through dozens of amendments to legislation known as the Stop Online Piracy Act, or SOPA. The bill aims to cut off funding and U.S. access to foreign websites that offer pirated movies, music, counterfeit running shoes, luxury purses, prescription drugs, and other items. The amendments were offered by a bipartisan group of critics on the committee, and the bill is expected to now pass the committee.

Smith has said he would consider a request by some opponents to hold another hearing that would examine concerns that the legislation could interfere with efforts to bolster the security of the Internet’s domain-name system. But he plans to continue the markup regardless.

The Senate Judiciary Committee approved its own version of piracy legislation in May, but Sen. Ron Wyden, D-Ore., has been blocking it from moving to the Senate floor. Senate Majority Leader Harry Reid, D-Nev., has scheduled a vote for Jan. 24 on a motion to begin debate.

Cybersecurity

Leaders in both chambers have promised to move forward with wide-ranging cybersecurity legislation this year. While the intent may be clear, the details remain murky.

Reid plans to bring comprehensive cybersecurity legislation to the floor during the first month of work after the Senate returns on Jan. 23. Various draft legislation has been making the rounds.

Potential proposals include clarifying the role and authority of government agencies to tackle cyberthreats, defining what “critical infrastructure” may warrant additional government protection, and ways to increase information sharing between the government and corporations.

While the Senate plans to tackle cybersecurity in a comprehensive bill, the House may be taking a more roundabout approach. In October, the House Republican Cybersecurity Task Force proposed developing smaller pieces of legislation in the various standing committees that could be packaged into a larger bill.

“We are generally skeptical of large, ‘comprehensive’ bills on complex topics, at least as the bills are being written,” the task force wrote in its report. House members have proposed several bills, including one from House Intelligence Committee Chairman Mike Rogers, R-Mich., that aims to allow the government to share more information with businesses.

 Spectrum

Congress will also continue work in the second session on legislation that would free up more spectrum to meet the public’s growing demand for wireless technologies.

The spectrum legislation is likely to be part of the larger debate over whether to pass a one-year extension of the payroll-tax holiday. The House included spectrum legislation in a payroll tax bill it passed last month. And some of the key players in the spectrum debate have been named as conferees to help negotiate with the Senate on the issue, including Energy and Commerce Chairman Fred Upton, R-Mich.; Energy and Commerce ranking member Henry Waxman, D-Calif.; and Rep. Greg Walden, R-Ore., chairman of the Communications and Technology Subcommittee.

 Privacy

Privacy will continue to make waves on the Hill and regulatory agencies, but the chances that lawmakers will actually pass a bill at this point appear remote. Nonetheless, the House Energy and Commerce Subcommittee on Manufacturing, Commerce and Trade is expected to hold more hearings. The panel’s chairwoman, Rep. Mary Bono Mack, R-Calif., has said she is still undecided on the need for legislation.

Her panel has approved legislation that would set national standards for how companies must respond to data breaches. The data-breach bill, however, is still awaiting action by the full committee.

In the Senate, a spokesman for Senate Commerce Chairman Jay Rockefeller, D-W.Va., said privacy remains a priority but the panel is still crafting its agenda for the second session.

 Cloud Computing

While the government has joined businesses in moving toward cloud computing, significant legislation on the issue has been delayed in Congress.

Cloud computing, in which data and programs are stored on remote servers and usually accessed online, offers ways to cut costs and increase efficiency but poses a range of concerns over privacy, security, and liability.

Many industry leaders say legislation is needed to clarify existing law and provide certainty to encourage investment in the new technology.

Sen. Amy Klobuchar’s Cloud Computing Act of 2011 generated a lot of buzz when the Minnesota Democrat announced it at a Best Buy store in her home state in April. But seven months later, the bill floundered after Sen. Orrin Hatch, R-Utah, who was originally floated as a cosponsor, bailed.

Late last year Klobuchar said she is working with new authors to introduce the bill.

Other issues that could emerge this session include debate over legislation that would require online retailers to collect sales taxes from out-of-state customers. Also on the Senate’s docket are two nominees to the Federal Communications Commission. They were approved by the Senate Commerce Committee but their final confirmation vote is on hold while Sen. Chuck Grassley, R-Iowa, spars with the FCC over the handling of the LightSquared proceeding.

Source: National Journal

Computer Clarity

 

Startpage Search Engine Scores another First: Encrypts ALL Searches

The World’s Most Private Search Engine now makes SSL encryption the default

Oct. 24, 2011

As of today, Startpage, by Ixquick, the “world’s most private search engine”, automatically encrypts ALL searches. Startpage was the first search engine to offer SSL encryption in 2009, and today it again breaks new ground by making SSL encryption the default.

SSL encryption, also known as secure socket layer encryption, is widely praised by security experts as the most secure way to surf the web. Startpage’s encryption prevents eavesdropping by Internet Service Providers (ISPs) who may become legally required to store massive amounts of personal information on you.

“In combination with the U.S. Patriot Act, snooping ISP’s pose an enormous, Orwellian privacy threat,” says Robert E.G. Beens, CEO of Ixquick and Startpage. “That’s why we’ve decided to change our website default to 100% SSL encryption, to further protect the privacy of our users’ Internet searches.”

All visitors to Startpage.com and its sister meta-search engine Ixquick.com will benefit from the new encryption service, which will automatically redirect them to the secure website. Users will see the letters “HTTPS” in the URL bar, indicating that all data will be transmitted in encrypted form. Any hacker or eavesdropper who accesses the connection will simply see gobbledygook.

Other search engines have begun to follow Startpage’s lead by offering SSL encryption. However, the privacy benefits of using SSL with other major search engines may be misleading, since those search engines themselves record users’ IP address and store extensive records of their searches.

“When you use Startpage, your IP address is not recorded, your visit is not logged, and no tracking cookies are placed on your browser,” explains Beens. “In fact, Startpage does not record any information about its users. Nothing. Nada. Zilch.”

Consumer privacy expert and Startpage spokesperson Dr. Katherine Albrecht concurs. “Now our users get the outstanding privacy of Startpage combined with the power of Google search results, and it’s all wrapped up with a tidy bow of encryption.”

“When you perform an encrypted web search through Startpage, we remove all identifying information from your query and submit it to Google anonymously through our own servers,” she explains. “We obtain Google’s search results and serve them to you in total privacy. Then we delete all records of your visit.”

Automatic SSL encryption is just the latest addition to the growing family of privacy features which combine to make Startpage the world’s most private search engine.
About Startpage “The World’s Most Private Search Engine”

Startpage by Ixquick is an award-winning search engine that is third-party certified and fully anonymous. It is the only search engine to offer a free proxy service, and the first to offer SSL encryption. Startpage has earned the coveted EuroPriSe “trust mark” for outstanding privacy and data handling practices. It is also certified by Certified Secure and registered with the Dutch Data Protection Authority.

https://www.startpage.com/

Original Source

Computer Clarity

How to Stop Telemarketing Calls to Your Mobile Phone

Many people are under the misguided perception that mobile phones are automatically off limits for telemarketing and solicitation calls.

Original Source

Everyone has encountered a telemarketing call. It may be a robocall directing you to vote for some political candidate, or perhaps some local organization seeking donations. But, most people are used to getting those calls on their home land line, not their mobile phones. Telemarketers are increasingly targeting mobile phone numbers, so here is what you need to do to stop–or at least minimize–those annoying calls.

There is a common misconception that mobile phones are somehow inherently protected against telemarketing solicitations. Unfortunately, that is not true.

PrivacyStar, an app available for Android and BlackBerry smart phones that lets users report violations of the Do Not Call list to the Federal Trade Commission (FTC) has compiled stats from the over 200,000 complaints it has logged to date. According to PrivacyStar, more than half of the users who have used the app to lodge complaints never registered for the Do Not Call List in the first place.

There are two easy ways to add you mobile phone number to the FTC Do Not Call registry:

• FTC Website: https://www.donotcall.gov/register/reg.aspx
• Call Directly: 1-888-382-1222

Of course, the Do Not Call list only works for organizations that play by the rules. I have had repeated calls for over a year from some company promising to lower my interest rates on credit cards. It is an automated call and every time I have pressed “1″ to speak with a representative and asked to be removed from the list, the rep has simply hung up and the calls have persisted.

I have also dealt with various entities trying to track down someone that I can only assume is the previous owner of my phone number. Apparently, he has a lot of collectors who are anxious to get in touch with him even though I  have had my phone number for five years.

The Do Not Call list may not work for situations like these, but it will stop the vast majority of the annoying solicitations and telemarketing calls. Don’t make the mistake of assuming that your mobile phone is somehow off limits.

Take the 30 seconds to visit the FTC site or call the Do Not Call registry number and get your mobile phone number added to the list.

Computer Clarity

The Mark of the Future – Personal Internet Number

The President had just signed the National Strategy for Trusted Identities in Cyberspace (NSTIC) to address two challenges that can affect economic growth online:  (1) the insecurity and inconvenience of static passwords and (2) the cost of transactional risks that arise from the inability of individuals to prove their true identity online. The solution proposed by NSTIC is a user-centric “Identity Ecosystem” built on the foundation of private-sector identity providers.

The Identity Ecosystem: Use Examples

The National Strategy for Trusted Identities in Cyberspace describes a vision of the future—an Identity Ecosystem—where individuals, businesses, and other organizations enjoy greater trust and security as they conduct sensitive transactions online. The Identity Ecosystem is a user-centric online environment, a set of technologies, policies, and agreed upon standards that securely supports transactions ranging from anonymous to fully authenticated and from low to high value.

Key attributes of the Identity Ecosystem include privacy, convenience, efficiency, ease-of-use, security, confidence, innovation, and choice.

Below are brief examples of how the Identity Ecosystem would work. More detailed versions of these and other examples are included in the Strategy.

Faster Online Errands—Mary is tired of memorizing dozens of passwords to conduct her personal online errands. She opts instead to get a smart card issued by her Internet service provider. She inserts the card into her computer and in a matter of minutes, with just clicks of her mouse, she is able to securely conduct business with her bank, mortgage company, and doctor, while also sending an email to her friend and checking her office calendar hosted by her employer.

Age Appropriate Access—Antonio, age 13, loves to visit online chat rooms to talk to other students his age. His parents give him permission to get an identity credential, stored on a keychain fob, from his school. The credential verifies his age so that he can visit chat rooms for adolescents, but it does not reveal his birth date, name, or other information. Nor does it inform the school about his online activities.

Smart Phone Transactions—Parvati does most of her online transactions using her smart phone. She downloads a “digital certificate” from an ID provider that resides as an application on her phone. Used with a single, short PIN or password, the phone’s application is used to prove her identity. She can do all her sensitive transactions, even pay her taxes, through her smart phone without remembering complex passwords whenever and wherever it is convenient for her.

Efficient and Secure Business Operations—Juan owns a small business and is setting up a new online storefront. Without making large investments, he wants customers to know that his small firm can provide the same safety and privacy for their transactions as sites for larger companies. He agrees to follow the Identity Ecosystem privacy and security requirements, earning a “trustmark” logo for his Web site. To reduce his risk of fraud, he needs to know that his customers’ credit cards or other payment mechanisms are valid and where to ship his merchandise. There are a number of different ID providers that can issue credentials that validate this information. Millions of individuals can now use his Web site without having to share extra personal information or even set up accounts with Juan’s company. This saves his customers time, increases their confidence, and saves Juan money.

Enhanced Public Safety—Joel is a doctor. A devastating hurricane occurs close to his home. Using his interoperable ID credential embedded in his cell phone and issued by his employer, he logs in to a Web portal maintained by a federal agency. The site tells him that his medical specialty is urgently needed at a triage center nearby. When he arrives, officials at the center use his credential to verify that he is a licensed doctor, and Joel is able to provide medical attention for victims.

COMPUTER CLARITY

Cyber Security Alert – Apple Updates!!!

Apple Updates for Multiple Vulnerabilities

Original release date: October 13, 2011
Last revised: –
Source: US-CERT

National Cyber Alert System
Cyber Security Alert SA11-286A

 

Apple has released security updates for Apple iOS, Safari 5.1.1, OS X Lion v10.7.2, iWork 09, and Apple TV 4.4 to address multiple vulnerabilities. Exploitation of these vulnerabilities may allow an attacker to execute arbitrary code, cause a denial-of-service condition, obtain sensitive information, and bypass security restrictions.

 

Systems Affected

  • Mac OS X 10.6.8
  • Mac OS X Server 10.6.8
  • Mac OS X 10.7, 10.7.1
  • Mac OS X Server 10.7, 10.7.1

Overview

There are multiple vulnerabilities in Mac OS X 10.6.8, 10.7, and 10.7.1 and Mac OS X Server 10.6.8, 10.7, and 10.7.1. Apple has released updates to address these vulnerabilities.

Solution

Install updates

The updates to address these vulnerabilities are available through the Mac OS X Software Update feature. Apple support article Mac OS X: Updating your software describes how to install these updates.

Description

The Apple Security Advisory for OS X Lion v10.7.2 and Security Update 2011-006 describes multiple vulnerabilities in Mac OS X and Mac OS X Server. Apple has released updates to address these vulnerabilities.

References

Is Your Business Vulnerable to Cybercrime?

It only happens to the big companies, right? While that may have been the conventional thinking in the past, cyber crime is finding large businesses, government institutions, and even individuals as its victims and as the Internet becomes increasingly integrated in to our daily lives, cyber crime continues to become more widespread.

Business is often about timing. Each day you have deadlines and if they aren’t met, you lose money. If you can’t get to your data for any reason, your day and the future of your business may be at risk. With data being so important to businesses of all sizes, it would be reasonable to believe that much like liability insurance, businesses are protected but that’s far from true.

A recent survey concluded that 52% of all business doesn’t have an IT security policy. Their data simply isn’t held under cyber lock and key like it should be and their employees are free to practice internet usage while at work in any way that they see fit.

If your business is in the 52% crowd, something has to change and it has to change today. What can you do to decrease your risk of cyber attack?

Secure you Network Infrastructure

A company that is PCI Compliant passes a stringent test of potential security breach scenarios. PCI Compliance makes sure that all data stored or transmitted in the network is secured.

Secure your Computer

Up to date antivirus and operating system with a cookie-free clean computer are the crucial steps to secure your computer. Scheduling automatic updates and frequent cleanings keeps the computer up to date. Most of the security breaches happen when a computer user isn’t paying attention.

Back up Your Data

Just like in our real lives, not being a victim of theft often starts with common sense. Your data is too important to only be in one place.  Copy your data and place it someplace secure. If you can fit it all on to a portable hard drive or some other piece of hardware that isn’t connected to the internet, do that once per week. If you can’t, find an online backup service that will automatically do this for you

Invest in a Computer Service Warranty

Most manufacturers ONLY offer warranties for hardware defects. Computer Service Warranties what the manufacturers do not; computer maintenance, operating system problems and any virus attack and damage. This supplemental “Insurance”  protects the computer user from sudden “break and fix” repair expenses.

Find out more about Computer Service Warranty.

Computer Clarity | Colorado Springs

Steve Jobs death exploited by Facebook scammers

It’s impossible to express how sad many people in the technology world feel at the news of the death of Steve Jobs.

Sickeningly, as with the deaths of other figures in the public eye, there are scammers waiting to take advantage of bad news.

Here’s a scam we have seen on Facebook, claiming that free iPads are being given away “in memory of Steve Jobs”.

In memory of Steve, a company is giving out 50 ipads tonight. R.I.P. Steve Jobs [LINK]

The cool-sounding link sucks you in, tricking you into believing that you may get a free iPad but then goes on to get you to complete online surveys to “qualify”.

The link goes through the bit.ly short url service (we have asked our friends at bit.ly to shut the link down) and we can see that over 15,000 people have already clicked on the link which was set up within hours of Steve Jobs’s death first being announced.

Of course, if you were one of those people who clicked on the link you may be wondering what the chances are that you will receive a free iPad. I hate to disappoint you, but it’s pretty unlikely.

The webpage you are taken to is very similar to ones we have seen pointed to by other scammers. Here’s what I saw:

I am writing this article from the Virus Bulletin conference in Barcelona, and you can see that the page has auto-magically determined where I am in the world and adjusted its language and wording as appropriate.

Below you’ll see how the survey pages look if you visit them from Sydney, Australia, for instance.

Survey site visited from Australia

If you don’t click through within a few seconds, it plays an audio message urging you to do so:

You’ll notice that the audio message spectacularly fails to mention the 50 free iPads, which have by this time been reduced to the promise of “an exclusive reward”, whatever that might be.

My colleague Paul Ducklin captured the audio and – being a fountain of interesting but not always entirely relevant information – tells me that the speaker is an Australian who grew up in South Africa.

When Duck visited the page a second time from Sydney, this is what he saw:

Casino website

How do the scammers make money? Well, they are earning affiliate cash – in a nutshell, they make more money the more traffic they can direct to websites, driving more people to become customers, or take online surveys and competitions.

Cynically, they exploited the death of Steve Jobs in the hope of driving large numbers of internet users to websites offering content such as contests, surveys and online gambling. The fact is, of course, that they could just as easily have taken those users to a webpage containing malicious code or a phishing page designed to steal credentials.

Chances are that this won’t be the only scam we see regarding the untimely death of Steve Jobs. It wouldn’t be a surprise, for instance, to see scams which might try to take advantage of those moved by the loss of Apple’s founder with lures like “Donate to Steve’s favorite charities as a tribute”.

If you do want to pay tribute to Steve Jobs, the most appropriate place it seems to me would be Apple’s website itself.

The truth is that the scammers are not geniuses like Jobs, and they don’t contribute anything to the world of technology or wider society as Steve Jobs did. It’s a shame that they can’t be inspired by speeches like the one Jobs gave at Stanford University in 2005, and make something better of their lives.

Steve Jobs’ 2005 Stanford Commencement Speech

I think that’s how we should remember Steve Jobs today.

 

Computer Clarity

Data security expert: Sony knew it was using obsolete software months in advance

In congressional testimony this morning, Dr. Gene Spafford of Purdue University said that Sony was using outdated software on its servers—and knew about it months in advance of the recent security breaches that allowed hackers to get private information from over 100 million user accounts.

According to Spafford, security experts monitoring open Internet forums learned months ago that Sony was using outdated versions of the Apache Web server software, which “was unpatched and had no firewall installed.” The issue was “reported in an open forum monitored by Sony employees” two to three months prior to the recent security breaches, said Spafford.

Spafford made his comments in a hearing convened by the House Subcommittee on Commerce, Manufacturing, and Trade. Sony was invited to participate in the hearing, but declined to attend. In a letter to the committee, Sony said it has added automated software monitoring and enhanced data security and encryption to its systems in the wake of the recent security breaches.

“If Dr. Spafford’s assessment is accurate, it’s inexcusable that Sony not only ran obsolete software on servers containing confidential data, but also that the company continued to do so after this information was publicly disclosed,” said Jeff Fox, Consumer Reports Technology Editor.

Original Source

Computer Clarity

HEARING: The Threat of Data Theft to American Consumers

Original Source

Summary

On Wednesday, May 4, 2011, at 9:30 a.m., the Subcommittee on Commerce, Manufacturing and Trade will hold a hearing entitled, “The Threat of Data Theft to American Consumers” in 2322 Rayburn House Office Building. Witnesses are by invitation only.

The purpose of this hearing is to examine risks related to data breaches, the state of ongoing investigations, current industry data security practices, and available technology.

Background

Since this issue of data breach became a common household term in 2005 when hackers gained access to 160,000 consumer records in the ChoicePoint data breach, American consumers have been inundated with reports of data breaches on a regular basis. According to the Privacy Rights Clearinghouse, over 2,500 data breaches implicating nearly 600 million records have been made public since 2005.1,2 In April 2011 alone, the Clearinghouse reports over 30 data breaches occurred at hospitals and medical provider offices; universities; insurance companies; airlines; technology companies; banks; and at the municipal, State, and Federal government levels. These breaches occurred via phishing, theft of computer or other devices, and hacking, impacting a minimum of 99 million records (a number of these breaches impacted an “unknown” number of records).

These records involve various pieces of information that can be used alone or in conjunction with other pieces of information to wreak havoc on a consumer’s financial well-being by using existing lines of credit or establishing new lines of credit, to gain unlawful access to bank accounts, to acquire jobs or government benefits for which they are otherwise not eligible, seek medical care, or use another’s identification in a law enforcement situation. Data breaches often involve unauthorized access to a person’s name, birth date, Social Security number, driver’s license number, credit account numbers, financial account numbers, usernames and passwords, or PIN numbers.

Whether the breach occurs inadvertently through the accidental release of information, in the offline world by loss of a laptop or stolen records, or online via hacking, the results can be disastrous for consumers. The FTC estimates nearly 9 million Americans fall victim to identity theft annually, costing both consumers and businesses tens of billions of dollars each year. While the Identity Theft Resource Center reports that both the cost to consumers has fallen as has the number of hours lost in resolving identity thefts, consumers still lose hundreds of dollars out of pocket and spend dozens of hours on cleanup efforts.

May 4, 2011

The Subcommittee on Commerce, Manufacturing, and Trade subcommittee scheduled hearing on Wednesday, May 4, 2011, at 9:30 a.m. in 2322 Rayburn House Office Building entitled, “The Threat of Data Theft to American Consumers.”

Background Memo

Watch the Archived Webcast

Opening Statements

Opening statement from Commerce, Manufacturing, and Trade Subcommittee Chairman Mary Bono Mack

Witness List

Panel One

David Vladeck
Director Bureau of Consumer Protection
Federal Trade Commission
Written Testimony (Truth in Testimony Form)

Pablo Martinez
Deputy Special Agent in Charge
Criminal Investigative Division, U.S. Secret Service
Written Testimony (Truth in Testimony Form)

Panel Two

Justin Brookman
Director Consumer Privacy Project
Center for Democracy and Technology
Written Testimony (Truth in Testimony Form)

Dr. Gene Spafford
Executive Director
Purdue University
Written Testimony (Truth in Testimony Form)