Monday, August 23, 2021

Adityas-Origami-Art-2020-JAN




Origami Wedding One-piece-no-cut 









Birds of paradise One-piece-no-cut




One-piece-no-cut





One-piece-no-cut

One-piece-no-cut

One-piece-no-cut
































Tuesday, October 15, 2019

How to Protect Your Domain Name System From Hijacking

Large-scale domain name system hijackings — usually in the form of DNS spoofing or DDoS attacks — have been on a steady rise for years. But the unprecedented number of DNS hijackings in 2019 has prompted the U.K.’s National Cyber Security Centre to alert and advise organizations on the threat. Learn how to protect your domain name system from hijacking.
The DNS operates like the switchboard of the internet, connecting alphabetical characters typed into web browsers with correct numeric-based IP addresses on servers where the content resides. If a DNS connection is hijacked, unsuspecting user traffic can be redirected to dangerous websites.

Securing the Foundations of the Internet

DNS attacks, more so than others, damage the primary trust users have on the internet. With consequences ranging from data theft to financial fraud, anyone victimized by a DNS attack will be wary of the internet generally — and especially suspicious of the domain where the attack originated. Customers who have been hurt by DNS hijacking have been known to abandon the affected service in droves, damaging revenue and brand reputation simultaneously.

By hijacking a domain, hackers can effectively weaponize a company’s online presence.

DNS hijacking can have catastrophic consequences for an organization and its brand image. When a company falls victim to DNS hijacking, its customers are exposed to fraud, data theft, breach of privacy, and financial loss. The company’s brand reputation suffers, which leads to lost customers and revenue. Also, the company may be fined or otherwise penalized by regulatory authorities.

Individuals and enterprises can both fall prey to attack, but website owners face the worst consequences.

Internet users trust the websites they visit to be safe, secure, and encrypted to protect their online data.
Penalties from regulatory bodies like the General Data Protection Regulations also take their toll. British Airways was recently fined $230 million over a data breach involving a DNS hijack that redirected traffic to a fraudulent website. More than 400,000 customers were affected when they entered credit card data into what they thought was a legitimate British Airways website.
The loss of revenue, customers, and brand reputation that result from DNS hijacking go directly to a company’s bottom line and capital value.

Why the DNS Is Vulnerable

Given the scale of most organizations’ online presence and operations, it’s not surprising the DNS is a vast network filled with potential vulnerabilities. Abandoned domains, weak password controls, and burdensome management processes compound these weaknesses.

Hackers will often exploit expired or forgotten domains that companies neglect to manage.

A forgotten domain caused a compromise to Dell when it relinquished control over a domain that enabled users to back up their computers to an online service with one click. After hackers discovered the oversight, they appropriated the domain, redirecting Dell computer users worldwide to a website full of explicit content and dangerous downloads. The damage to Dell’s brand reputation was significant.

Unused, or “orphaned,” domains are another issue: When companies manage hundreds — even thousands — of domains, it’s easy to overlook a compromised domain.

In an attack known as “Spammy Bear,” hackers exploited GoDaddy’s DNS system to steal 4,000 orphaned domains from 600 owners, including ING Bank, Hilton, McDonald’s, and Mastercard. The domains were particularly vulnerable because they resided outside the respective owner’s primary DNS services, where they were forgotten and not actively managed.

Correctly operating domains and the DNS depends upon rules and settings such as “zone files,” also known as resource records.

Access to DNS control systems should be restricted to authorized personnel, yet they are often left vulnerable from poor password management. Unauthorized parties frequently gain access to corporate DNS control systems, hijack domains and the DNS, and even cover their tracks to evade detection. Because DNS controls can involve both the DNS owners’ and the DNS service providers’ operations, both systems require secure password control such as two-factor authentication.
Inefficient, ineffective change management processes also weaken DNS security. Small changes can put domains at risk, so administrators must diligently track when, where, why, and how changes are being made. This work is typically done manually, raising the risk of errors and oversights that compromise DNS security.

Inefficient change management can result in omitted or invalid DNS security settings.

Widely considered to be mandatory and essential security measures are settings such as Domain Name System Security Extensions for authenticating users and destinations, and Domain-based Message Authentication, Reporting & Conformance, and Sender Policy Framework to vet email users. Ongoing surveys of Fortune 1,000 companies show that these protections are either missing entirely or they have been deployed incorrectly, exposing the affected organizations’ DNS networks and customers to serious compromise.

Businesses have a responsibility to their customers and their bottom lines to manage the DNS far more effectively.

To protect everyone’s interests, companies must tighten up DNS security by managing the DNS comprehensively and efficiently.

Defending the DNS from All Angles

Preventing DNS attacks is mainly about managing the ever-increasing scale of DNS network operations. Hackers exploit confusion and complexity to their advantage. Simplification is the antidote. Avoid hijacking and secure the DNS using with these strategies:

1. Consolidate to one platform 

Consolidate all domain registrars and DNS service providers to a single enterprise-grade registrar and DNS service. Working on one platform makes it easier to control access, implement stronger password protections, and manage all processes using the same best practices. Single platforms also enable users to activate “auto-renew” and “registrar lock” features to reduce the chance of failed domain renewals and unauthorized DNS changes.

2. Eliminate unwanted domains

All domains, including unused domains, should be managed with the same care and attention as premium domains. Become proactive about eliminating orphaned domains and managing DNS settings that could be vulnerable to misuse, such as unused IP addresses and domains that lack the start of authority (SoA).

3. Integrate change management

Implement a systems-based change management platform that relies on automation rather than manual inputs. Automation will block unauthorized changes, notify administrators of authorized changes, and create a tamper-proof audit of all activity within the system. Ideally, the platform integrates all DNS-related management tasks, including TLS certificates for encryption and security settings like DNSSEC.

4. Automate DNS security

Overcome the complexity of important DNS security features by automating processes. DNSSEC, DMARC, and SPF are challenging to manage and costly to administer, making them economically unsustainable for many companies. Automating DNS security makes it financially viable and administratively easy while ensuring full compliance.

Employees can be Your Greatest Defense Against Security Threats

Employees can be your greatest defense against security threats. These security threats abound because it is our nature to trust many different people with sensitive information. A security threat even has a loophole into our employee logins. There will always be human error, which is something companies must take into account when strategizing security. All business security studies will tell you that your employees are your biggest security weakness. But businesses and companies should also observe that your employees can be your greatest defense against security threats.

Educate your employees about the nature of security threats — so they can be a line of defense.

Help your employees be your most important defense against security threats. They are often your greatest asset when it comes to protecting your company’s vital information and avoiding breaches. What issues can you teach your employees about?
  •  Falling victim to phishing emails.
  • Careless management of sensitive data.
  • Losing physical equipment with company information.
  • Sensitive information.
  • Digital identities.
  • Trusting too much.
  • Employee logins.
  • Human error.
  • Employees must help you strategize for security.
  • What is the vital information?
  • Device security.

Educate your employees about phishing attacks as security threats.

It’s common knowledge at this point, but best practices for security involve training your employees to recognize phishing emails and report them. It’s also a good idea for your IT department to send out a false phishing email to reinforce how easy it is to get tricked (although doing this more than once doesn’t tend to increase its effectiveness).
Falling victim to a phishing attack is surprisingly easy. Shaming or punishing employees who might not be able to immediately recognize these tactics is counterproductive. Instead, institute mandatory education sessions, and let employees know what they should and shouldn’t expect from their company email. For example, they should know that no one in the company will email them asking for their password or payment information and that they should type in web addresses into their browsers, rather than clicking on in-email links.

Instill good password habits to limit security threats in your employees.

Many larger companies are transitioning to SSO for security purposes, which is a powerful tool. But not all sites are compatible with SSO, and it can leave gaps in security during implementation. That’s where a password manager comes in.
password manager can improve your company’s security immediately upon rollout. It’s a simple solution to the problem of sharing passwords: Remember one password, share passwords securely among teams, and make sure that people who don’t need access to passwords don’t have it.
One of the biggest strengths of a password manager is that it can teach your employees that having good password habits can be just as simple as having terrible ones. A good password manager will integrate seamlessly into your employees’ work-life, making it easier to do their jobs well.
The issue, though, is that instilling good password habits at work often isn’t enough to fully protect your company. If employees want to find workarounds for password managers, they can and will. That’s why we think it’s a good idea to give employees free personal password management as well. Free personal password management encourages them to implement a password manager across their personal and professional lives. It’s also why all 1Password Business accounts come with free family accounts for any individual at the organization.

Make sure your employees know they are valued.

We all know our employees are valuable; after all, our companies wouldn’t function without them. But do they feel valued? That’s an important distinction. Employees that are invested in your company, and that feel trusted, will be quicker to protect your business. They will recognize you are invested in them and will, in turn, invest in you and take security more seriously.
Frankly, it is very hard to fake authentic care. You are going to have to actually feel something for your employees — and you both deserve this effort. Employees can tell when companies are genuinely invested in them versus just trying to make them feel that way.  To make people feel valued is one of the most security-conscious strategies you can do for your company. It is a strategy that starts at the ground up — and is fundamental to the way you run your company and treat your employees.
If you’re not sure about how your employees feel, consider asking for feedback or bringing in an outside firm to run a focus group (employees may be reluctant to be honest if they fear reprisals for their comments). Take their comments seriously and implement policies to improve employee satisfaction.
The bottom line is that when employees are happy, are valued and feel valued, and are invested in your company’s success; they will become your front line of defense for security threats. It’s time to stop seeing employees as security threats and instead treat them like the strengths that they are.

Tuesday, September 24, 2019

If the J.P. Morgan Chase Amazon marriage succeeds, the two entities will gain access to a wealth of consumer data.





If the J.P. Morgan Chase Amazon marriage succeeds, the two entities will gain access to a wealth of consumer data.


Amazon is entering the finance market at the perfect time to take advantage of an industry that’s adjusting to a tech-first orientation.

Today, technology gives consumers more control over their finances and more personalized banking experience. If Amazon goes forward with his plans to enter finance, it could once again revolutionize an entire industry. Most relatively recent finance disruptors have had to build their enterprises from the ground up. Amazon, however, has the benefit of experience, market share, and hefty coffers.

http://feedproxy.google.com/~r/readwriteweb/~3/HQ_Ao7C-s0w/

Monday, September 23, 2019

Fujifilm SonoSite Wants to Bring AI to Ultrasound

Have you ever needed an IV and had to undergo multiple pricks before the nurse could find a vein? Technology to avoid that painful trial and error is in the works. Fujifilm’s ultrasound diagnostics arm SonoSite announced yesterday that it had partnered with a startup company to develop artificial intelligence that can interpret ultrasound images on a mobile phone.
The companies say the first target for their AI-enabled ultrasound will be finding veins for IV (intravenous) needle insertion. The technology would enable technicians to hold a simple ultrasound wand over the skin while software on a connected mobile device locates the vein for them.
For this project, Fujifilm SonoSite tapped the Allen Institute for Artificial Intelligence (AI2), which has an incubator for AI startup companies. “Not only do we have to come up with a very accurate model to analyze the ultrasound videos, but on top of that, we have to make sure the model is working effectively on the limited resources of an android tablet or phone,” says Vu Ha, technical director of the AI2 Incubator.


http://feedproxy.google.com/~r/IeeeSpectrum/~3/Cx40E6I8rjQ/fujifilm-sonosite-wants-to-bring-ai-to-ultrasound

1Password Unveils 1Password Advanced Protection

http://feedproxy.google.com/~r/readwriteweb/~3/d4JqdUZ8YeY/



1Password unveils 1Password advanced protection: additional security controls for enterprise.

Known for their private, secure, and user-friendly password manager, 1Password protects the data businesses all over the world. The new features will help businesses fortify their defenses against 89 percent of breaches that result from outside attacks.
“Large, complex organizations use 1Password Business, and many of them have specialist security and governance requirements. With 1Password Advanced Protection, these businesses can create custom rules to determine how their employees can access the information stored in 1Password, and protect their most important data,” says 1Password CEO Jeff Shiner.
This latest release comes as 1Password celebrates reaching 50,000 paying business accounts, just three years after launching 1Password Business.

What does 1Password Advanced Protection include?

The new features make it easy for businesses to create and enforce security policies, prevent threats, and monitor their team’s access.
  • Enforce two-factor authentication.

Enforce two-factor authentication company-wide, and choose which second factors your team can use when they add 1Password to a new device.
  • Restrict access with firewall rules.

Create rules to allow, report, or deny sign-in attempts from specific locations, IP addresses, and more. Review recent sign-in attempts and take any action required to protect your team.
  • Set complex Master Password policies.

Define requirements employees must adhere to when they choose their Master Password.
  • Require modern app usage.

Check which version of 1Password your employees are using to ensure they have the latest security and feature updates.

Guard against breaches and unauthorized access.

Data breaches are getting more significant and more costly. According to a report by IBM, the average cost of a data breach has risen from $3.50 million in 2014 to $3.86 million in 2018 — representing nearly 10 percent net increase over the past five years of the study.
With high-profile breaches hitting the headlines weekly, and stricter data protection laws like the GDPR coming into action, businesses are looking for security solutions that are scalable, compliant, quick to deploy, and make an immediate difference.

Wednesday, April 25, 2012