Digital Security for the 2017 Lawyer
cameronhuff.com
cameronhuff.com
https://techsolidarity.org/resources/basic_security.htm
We've used this as the basis for training we're doing with NGOs, the press, and some legal groups.
Also, is there a similar list for small companies focused on remote working?
Companies with minimally or ad-hoc supported environments are nearly always dealing with various outbreaks (I mean literally daily), and yet the one thing they are always doing for security is buying McAfee or SEP because it's the one thing an auditor from an accounting firm told them to do.
Have a look at actual detection logs across several thousand machines. You'll see silly things like "tracking cookies" show up ("glad we bought that antivirus!!"), but blocked malware will be far more rare than actual outbreaks.
This will leave you with the view that they are not effective.
Then, talk to the sales team there. Often the only thing they can tell you about AV is that, aside from Office 365, it's the only guaranteed subscription service a client will sign up to. So now you know why having AV is a big deal.
Then look at how many hours get burned on things like "slow servers", where you find your Linux PostgreSQL server is configured with its database being scanned on write. And politically, it's easier to upgrade RAM and CPU than to try and exclude the database. So now you're just totally jaded on AV wish the whole industry didn't exist.
I've never seen a bad Defender update nuke a running Windows installation, which I cannot say for any popular product. Look at last week's Webroot meltdown.
If you know exactly what you're doing, and you're using a Google phone, you might be able to get approximately the same security out of an Android device as an iOS device. But ordinary users have no chance.
Can you help me to understand the validity of this statement [0]?
> When used with the best practices for web security, the Chromebook is secure against most direct attacks on the local hardware and the Chrome browser, but its dependence on a web-based backend where US courts have already ruled there's less of an expectation of privacy is something no amount of end-point security is going to fix.
[0] https://arstechnica.com/information-technology/2013/09/why-t...
Is my statement false? Please, explain why you think so.
I expect an intelligent interaction here in HN.
What we don't know for sure is if they're still doing it after being caught.
[0] https://www.washingtonpost.com/world/national-security/nsa-i...
My personal wishlist would include an equivalent of iOS's ability to encrypt new files to a public key while the phone is locked, as pointed out by Matt Green in "The limitations of Android N Encryption", but I'm interested in your perspective.
* Pair locking [1]
* Updates for longer than 18 months [2]
1: https://www.zdziarski.com/blog/?p=2589 - There was a more up to date guide but I can't find it.
2: https://www.businessinsider.com.au/apple-ios-10-iphone-softw...
I've been interested in perhaps using Evernote given its popularity but haven't done much research into it. Do you have a quick summary to share, or perhaps a preferred reference for more reading on this?
Why should I trust this vendor specifically with my specific data?
Then again, I don't see cause to trust any businesses by default. Perhaps I'm missing something.
If you follow all recommendations you're way ahead of the curve compared to what I've seen, but I've mostly seen small IT shops.
I do recall passworded ZIPs being easy to crack, that might be better replaced with a PGP-based alternative.
Don't use password-protected ZIPs.
It's almost worth a HN post in itself, but I can't find a good reference to link to.
1: http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.49.2... (PDF maybe available via FTP?)
2: https://security.stackexchange.com/questions/5447/how-secure...
This isn't a list of the best things to do, it's a list of some practical steps that can make things better. But ultimately the right level of security depends on the importance of the client communications. Some things are fine to do as Google Docs and other things you'll want to do with in-person meetings where no phones are allowed.
And if you like the slides, there will be a free video of the actual presentation online soon.
- pictures of the office opening party
- clients addresses
- employee contracts + data
- written warnings to employees
- ALL communication to/from clients
- INCLUDING stuff like stalking Protective Orders
Additionally, one CEO saved data from his other company on the server. His company dealt with medical stuff. The company was eventually sold for an undisclosed amount of money - but the server also contains correspondence to investors and board of directors....
The data is almost 10 years old, but some employees are still in business. Please always teach basic security when talking to anyone who handles 3rd party data. Lawyers must be aware of the value of their data. No victim of stalking wants to have their case correspondence public.
Instead of learning more about server hardware, I'll probably use this data to learn more about data/document analysis and use it as a simple example when talking about the boring topic of computer/data security.