<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Securing Your Virtual Growth &#187; Security</title>
	<atom:link href="http://www.iowadatacenters.com/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iowadatacenters.com/blog</link>
	<description>A blog by Infrastructure Technology Solutions</description>
	<lastBuildDate>Thu, 07 Jul 2011 12:21:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Internet Explorer 6: Ticking time bomb</title>
		<link>http://www.iowadatacenters.com/blog/2010/08/internet-explorer-6-ticking-time-bomb/</link>
		<comments>http://www.iowadatacenters.com/blog/2010/08/internet-explorer-6-ticking-time-bomb/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 01:46:30 +0000</pubDate>
		<dc:creator>Leslie Althoff</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[discontinued]]></category>
		<category><![CDATA[internet explorer 6]]></category>
		<category><![CDATA[support]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.iowadatacenters.com/blog/?p=361</guid>
		<description><![CDATA[I logged into our internet banking portal this week to pay some bills and transfer funds within my personal accounts, and found this ominous warning:

My first reaction was to laugh and think, &#8220;Who uses Internet Explorer at all for online banking?&#8221;
Apparently people do, and people even still use Internet Explorer 6. (IE 6)  A post [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F" height="61" width="51" /></a></div><p>I logged into our internet banking portal this week to pay some bills and transfer funds within my personal accounts, and found this ominous warning:</p>
<p><img class="alignnone size-full wp-image-360" title="Picture 3" src="http://www.iowadatacenters.com/blog/wp-content/uploads/2010/08/Picture-3.png" alt="" width="367" height="139" /></p>
<p>My first reaction was to laugh and think, &#8220;Who uses Internet Explorer at all for online banking?&#8221;</p>
<p>Apparently people do, and people even still use Internet Explorer 6. (IE 6)  A p<a href="http://slashdot.org/story/10/07/31/0451207/UK-Government-Rejects-Calls-To-Upgrade-From-IE6" target="_blank">ost on Slashdot</a> revealed that the UK uses IE 6 for governmental affairs, including many applications related to finances and security.  Citizens of the UK recently circulated a <a href="http://petitions.number10.gov.uk/ie6upgrade/" target="_blank">petition</a>, gathering over 6,000 signatures, to persuade the Prime Minister to upgrade web browsers in government departments and preserve sensitive information.  Parliament politely refused, reasoning that the cost to upgrade would not be worth the effort.</p>
<p><a href="http://www.zdnet.com.au/ie6-used-as-facebook-blocker-microsoft-339303424.htm?omnRef=http%3A%2F%2Fwww.theregister.co.uk%2F2010%2F06%2F01%2Fie6_facebook_microsoft%2F" target="_blank">Other businesses embrace IE 6</a>, simply because facebook and other time-wasters are not fully functional with the outdated browser.</p>
<p>Google and Adobe both agree that the targeted hack on their systems in January were caused by <a href="http://www.wired.com/threatlevel/2010/01/hack-of-adob" target="_blank">exploiting the vulnerabilities of IE6</a>.</p>
<p>I understand that there are applications and situations where using IE 6 is warranted.  I even keep an ancient version of Firefox on my computer because Upromise doesn&#8217;t like Safari.  But, if you need to use IE 6 for specific applications, either install another browser for daily use or run IE 6 in a VM.  If you run IE 6 in a VM, you can configure your machine to roll back to your original settings (snapshot) upon reboot, thus keeping viruses and malware at bay.</p>
<p>Speaking of viruses and malware, make sure you are up to date on your patches &#8211; goodness knows that IE 6 isn&#8217;t!</p>
<div class="lightsocial_container"><a href="http://digg.com/submit?url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F&amp;title=Internet+Explorer+6%3A+Ticking+time+bomb"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F&amp;title=Internet+Explorer+6%3A+Ticking+time+bomb"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a href="http://www.facebook.com/sharer.php?t=Internet+Explorer+6%3A+Ticking+time+bomb&amp;u=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a href="http://delicious.com/save?title=Internet+Explorer+6%3A+Ticking+time+bomb&amp;url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F&amp;title=Internet+Explorer+6%3A+Ticking+time+bomb&amp;summary=&amp;source="><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a href="http://twitter.com/home?status=Reading+http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F08%2Finternet-explorer-6-ticking-time-bomb%2F"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;</div>]]></content:encoded>
			<wfw:commentRss>http://www.iowadatacenters.com/blog/2010/08/internet-explorer-6-ticking-time-bomb/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Annoyance of Encrypted Searches</title>
		<link>http://www.iowadatacenters.com/blog/2010/06/the-annoyance-of-encrypted-searches/</link>
		<comments>http://www.iowadatacenters.com/blog/2010/06/the-annoyance-of-encrypted-searches/#comments</comments>
		<pubDate>Tue, 29 Jun 2010 04:13:33 +0000</pubDate>
		<dc:creator>Joel Althoff</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cipa]]></category>
		<category><![CDATA[encrypted]]></category>
		<category><![CDATA[engine]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[schools]]></category>
		<category><![CDATA[search]]></category>

		<guid isPermaLink="false">http://www.iowadatacenters.com/blog/?p=271</guid>
		<description><![CDATA[A month ago, Google rolled out its encrypted search option, which allows users exploring through https://www.google.com to seemingly search in stealth mode.
For public library and internet cafe users, bored private sector employees, and non-American Googlers, this news was heralded with great excitement and a flurry of key presses; nobody can see what we are Googling [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F" height="61" width="51" /></a></div><p>A month ago, Google rolled out its encrypted search option, which allows users exploring through <a href="https://www.google.com/" target="_blank">https://www.google.com</a> to seemingly search in stealth mode.</p>
<p>For public library and internet cafe users, bored private sector employees, and non-American Googlers, this news was heralded with great excitement and a flurry of key presses; nobody can see what we are Googling anymore!  (To be fair, I must also mention that <a href="http://www.eweek.com/c/a/Security/Firefox-Extension-Brings-Encryption-to-Facebook-Twitter-395091/" target="_blank">Firefox also rolled out an extension</a> last week called <em>HTTPS Everywhere </em>that encrypts data between users and sites whenever possible, but I haven&#8217;t had a chance to read more on the release.)</p>
<p>For many other users and network administrators, encrypted searches are a minor annoyance.</p>
<p>For example, our K-12 Education clients that rely on federal E-rate funding for bandwidth and internet related hardware must comply with the <a href="http://www.fcc.gov/cgb/consumerfacts/cipa.html" target="_blank">Children’s Internet Protection Act (CIPA)</a>.  Adherence to CIPA policies requires that schools design and implement a policy that monitors the online activity of minors.  Allowing students to use encrypted searches, whether through Google or elsewhere, violates CIPA and a school&#8217;s qualifications for E-rate funding.  <a href="http://googleenterprise.blogspot.com/2010/06/update-on-encrypted-web-search-in.html" target="_blank">Google is aware of the issue</a>, and recently changed the url of their encrypted search to <a href="https://encrypted.google.com" target="_blank">https://encrypted.google.com</a>.  Schools looking to block access to Google&#8217;s encrypted search engine should be able to do so within their URL filters or by blocking access to the above hostname.</p>
<p>Earlier I said that nobody could see what you were Googling when you used the encrypted search, but that isn&#8217;t exactly true.  Google still tracks and compiles that data, but webmasters and others that rely on analytics and search engine data to judge the effectiveness of their sites, products and marketing campaigns <a href="http://www.theregister.co.uk/2010/05/25/google_ssl_search_and_web_analytics/" target="_blank">will no longer see what keywords led viewers to a specific webpage</a> when using an encrypted search.  For many of our web hosting clients, this is dismal news.  Small- and medium- businesses typically depend on their website as the hub of their marketing presence.  If consumers are led to a site through an encrypted search, businesses will see the same statistics as if the consumer had simply typed the address in the browser without using Google&#8217;s encrypted search.</p>
<p>Many businesses will also find that encrypted searches are not allowed in their company Internet access/privacy policy.  We typically recommend that a privacy policy read something like this:</p>
<blockquote><p><em>NO EXPECTATION OF PRIVACY- </em><em>Employees are given computers and Internet access to assist them in the performance of their jobs. Employees should have no expectation of privacy in anything they create, store, send or receive using the company&#8217;s computer equipment. The computer network is the property of the Company and may be used only for Company purposes.  WAIVER OF PRIVACY RIGHTS- User expressly waives any right of privacy in anything they create, store, send or receive using the company&#8217;s computer equipment or Internet access. User consents to allow company personnel access to and review of all materials created, stored, sent or received by User through any Company network or Internet connection.  MONITORING OF COMPUTER AND INTERNET USAGE &#8211; The Company has the right to monitor and log any and all aspects of its Computer system including, but not limited to, monitoring Internet sites visited by Users, monitoring chat and newsgroups, monitoring file downloads, and all communications sent and received by users. Failure to monitor in specific situations is not a waiver of the Company’s right to monitor.  BLOCKING SITES WITH INAPPROPRIATE CONTENT-  The Company has the right to utilize software that makes it possible to identify and block access to Internet sites containing sexually explicit or other material deemed inappropriate in the workplace.</em></p></blockquote>
<p>If Google&#8217;s encrypted search remains an optional tool, it will remain just a minor annoyance for IT staff.  But, if Google favors the encrypted search for its sole search engine, schools, webmasters and businesses may be Googling for a new search engine.</p>
<div class="lightsocial_container"><a href="http://digg.com/submit?url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F&amp;title=The+Annoyance+of+Encrypted+Searches"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/digg.png" alt="Digg This" title="Digg This" /></a>&nbsp;&nbsp;<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F&amp;title=The+Annoyance+of+Encrypted+Searches"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/stumbleupon.png" alt="Stumble Now!" title="Stumble Now!" /></a>&nbsp;&nbsp;<a href="http://www.facebook.com/sharer.php?t=The+Annoyance+of+Encrypted+Searches&amp;u=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/facebook.png" alt="Share on Facebook" title="Share on Facebook" /></a>&nbsp;&nbsp;<a href="http://delicious.com/save?title=The+Annoyance+of+Encrypted+Searches&amp;url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/delicious.png" alt="Bookmark this on Delicious" title="Bookmark this on Delicious" /></a>&nbsp;&nbsp;<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F&amp;title=The+Annoyance+of+Encrypted+Searches&amp;summary=&amp;source="><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/linkedin.png" alt="Share on LinkedIn" title="Share on LinkedIn" /></a>&nbsp;&nbsp;<a href="http://www.technorati.com/faves?add=http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/technorati.png" alt="Bookmark this on Technorati" title="Bookmark this on Technorati" /></a>&nbsp;&nbsp;<a href="http://twitter.com/home?status=Reading+http%3A%2F%2Fwww.iowadatacenters.com%2Fblog%2F2010%2F06%2Fthe-annoyance-of-encrypted-searches%2F"><img src="http://www.iowadatacenters.com/blog/wp-content/plugins/light-social/twitter.png" alt="Post on Twitter" title="Post on Twitter" /></a>&nbsp;&nbsp;</div>]]></content:encoded>
			<wfw:commentRss>http://www.iowadatacenters.com/blog/2010/06/the-annoyance-of-encrypted-searches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

