Showing posts with label donald burns. Show all posts
Showing posts with label donald burns. Show all posts

Wednesday, August 31, 2016

MiniLock: a program to keep your private files private

Image courtesy of  Yuri Samoilov at Flickr.com
The creator of an encryption program that wasn’t successful released another one with a renewed concept: making encryption so easy that anyone can do it, in order to stay protected from the prying eyes that spy on digital communications.

Espionage, a century ago, could be as simple as setting up a copper wire on an official telephone line and start eavesdropping. Today, one hundred years later, that way of spying is something to laugh at, and it may even seem endearing. Current espionage systems are so incredibly sophisticated that few words actually manage to escape the network of technological eyes that are constantly watching the digital messages circulating on the planet: SMS, emails, social networks, phone calls, and so on.

The world’s public opinion is divided between those who justify tracking and those who believe that a compulsively observed population will result in the most barbaric totalitarianism imaginable. Hackers and tech-savvy experts, though, were the first to denounce the machinery that states and governments were setting up to delve into any private space. The best known cases are those related to Julian Assange and Edward Snowden, but there are many more.

This community is also trying, with a lot more courage, to avoid an ultra-controlled future. For years, hackers have been creating encryption technologies to shield messages and making them only accessible to the person who sends and receives them. Many of them called themselves “cypherpunks”. People like Assange spent a lot of time creating free encryption systems for people to express themselves freely on the Internet. The identity and contents of a message are inaccessible except for the sender and the recipient.

For years there have been services that have been trying to stay out of this global espionage network consisting of governments and businesses. As an example we can find web browsers (Tor, Chrome’s incognito mode or Firefox’s private browsing), mail services (Lavabit, Riseup), instant messaging clients (Telegram) or search engines (DuckDuckGo).

But outside of those environments, for the average user, encryption remains a bit of a mystery. Software engineers and similar experts, however, work harder to make it easier and lighten the weight of this unprecedented network of espionage. One of those hard-working people is security consultant Nadim Kobeissi, who created and released a browser plugin that is capable of encrypting and decrypting files in just a few seconds, and was featured in an article from Wired magazine.

The program is called MiniLock. It is free and open source -you can find its source code in GitHub-, and it was presented for the first time in New York’s Hope X hacker conference in July of 2014. Kobeissi hopes to develop software so simple that anyone can use it. “It’s super simple, approachable, and it’s almost impossible to be confused using it”, said Kobeissi to the aforementioned magazine.

Image courtesy of Christiaan Colen at Flickr.com
MiniLock first appeared as a beta version and, according to its creator, it began still in an experimental phase. The extension is capable of encrypting virtually anything, ranging from videos embedded on an e-mail message to photos stored on a USB drive. These encrypted documents can also be stored, safely, on services like Dropbox or Google Drive.

In this desire for simplicity, MiniLock requires no registration or a signup process. The only thing the user has to enter is an extremely secure password, which means that it must be comprised of a combination of at least 30 letters and numbers.

Kobeissi has been working for quite a while on encryption systems. The consultant is probably better known for his Cryptocat chat program. But, according to Wired, that project had security flaws. In a pessimistic view this could mean that the hacker community can view MiniLock with a skeptical eye. An optimistic outlook may focus on something different. Kobeissi himself says that he has learned a lot from Cryptocat and he’ll avoid the mistakes he made back then. One example is the fact that he chose not to release the program right away via Google’s store. Instead, he posted the code on GitHub in order to allow other coders and experts to assess it, check it and correct it beforehand.

Information leaks have turned into a trending occurrence, an especially significant one when it comes to fighting corruption. Certain systems, such as the open-sourced SecureDrop, have allowed citizens to present documents and all kinds of complaints to major news outlets, in a secure and anonymous way, to protect the identities of the whistleblowers.

The controversy that came after Snowden’s revelations about the NSA encouraged the creation of platforms such as Trsst, a microblogging site similar to Twitter, which describes itself as “encrypted, anonymized and decentralized”.

Encrypting information will probably end up being a common practice. And maybe, hopefully before long, it will turn into something as simple as creating a zip file today.

Related contentRead Don Burns’ “Threema, a messaging app that cares about your privacy”

Tuesday, August 30, 2016

Did You Know Wireless Devices Were This Important in Today's World?

Image courtesy of Jope at Flickr.com
Telecommunication devices have come a long way from the time of smoke signals and notes on a pigeon's foot, but one of the most amazing advances has by far been the possibility of doing all of this without any of the traditional wires needed. Wireless communication does not only refer to smart-phones and Wi-Fi, it is every kind of possible communication where there is a transfer of information or power, but there is no connection whatsoever. The most common and known is the radio, which can be at short-wave and travel only a few meters, or as much as millions of kilometers for deep-space communication. You can find on the list great variety in the different types of communication like two-way radios, PDAs, GPS, garage door openers, wireless gadgets like headphones, keyboards and mice, broadcast and satellite television and of course cell phones and Wi-Fi. If you take a minute and start to really analyze how many of the devices you use on a regular basis are wireless, and not to mention which ones you’ll be using a year from now. Wireless is on the rise while offering consumers a more pleasurable experience without any of the hassle brought on by cables, and receiving the same service. 

We think wireless and of course we immediately think Wi-Fi and the advances there have been with 4G and now 5G communication, which you can read more about on the Don Burns Blogspot page, but it goes beyond that. Wireless communication, believe it or not, started off even before the 1900s when Guglielmo Marconi developed the first wireless telegraph, which started off a wave of other inventions including basic data compression, initial technology behind cellular phones, and radiotelephones during the early 1900s. From there, you could easily list the devices that started popping up in the 50s and 60s from microwave signals and satellites, which were launched into space. Around this time, some associations also started appearing with the purpose of controlling communication as it started to be implemented, among these were: The Federal Communications Commission (FCC), and the International Telecommunications Satellite Consortium (INTELSAT). In the 80s, you could definitely say there was a boom in technology and it can be said this was the birth of the cell phone, since this is when the technology we know today was refined, leading to the beginning of the “technological wars” that would establish the competition grounds for digital cellular standards in 1989. In the 90s, there’s no surprise when records are broken, and the 10 million milestone was surpassed by cell phone users and the size of the internet just continues to exponentially grow.

The 2000s brought tons of new and interesting advances that now allowed users to interact more than ever. This tech had become such a part of everyday life that in 2009 it was registered that over 6.2 billion minutes were used by clients and more than 5 billion SMS messages were sent per day, all via wireless networks. During these years, was also the creation of the iTunes and the Android Play Store bringing about a brand new way of interacting. Apps on smart phones are now integrated into almost every part of our lives, and it seems that this is not the end of it. From here there was an even more advanced integration, which is the Internet of Things (IoT), allowing users to use the internet networks to communicate with devices around the home, office or city to carry out specific tasks.


Image courtesy of ollierb at Flickr.com
So, even though this was a brief timeline, you need to also realize that there are different types of wireless signals, which will be determined by the device being used. For instance, on a TV you are either using analog video or digital video, whereas on a cell phone you are using voice, be it via analog or digital, 3G, 4G or LTE, Bluetooth, or two-way radio. Satellites can carry all types of signals independent if they carry voice, audio, video or data, or even if they do so through analog or digital. The other consideration is the frequency of the signal, which are all supported by these satellites from 3400 MHz to 23 GHz, or others. Then you Wi-Fi and Bluetooth, and finally radio which synchronizes on AM and FM radio. In this whole mix you’ll find devices that could be transmitters, receivers, or transceivers. Each of these will take on a particular role in the wireless communication service: wireless clients (which are the stations that use the connection to interact), access points (which the host of the signal), and Ad-Hoc Nodes (which allow a network of devices to connect to a specific access point).

The list could go on about devices or wireless tech, but at the end of the day the purpose of all of this is maintaining communication as we have the possibility of going mobile. There’s now doubt that there will only continue to be advances in this field in the years to come.

Tuesday, August 23, 2016

Threema, a messaging app that cares about your privacy

Image courtesy of Dr. Motte at Flickr.com
Telegram is surely the app that we usually resort to in order to demonstrate how an app can offer a very high level of security and privacy to its users, with certain characteristics such as end-to-end encryption and secure chats that take to the next level the fact that we can feel safe when we take part in a conversation with sensitive information. The developers of Telegram have struck a chord with a need that came from millions of users after the events that took place with Edward Snowden and the NSA.

Now we have another application that follows this path and that presents itself as one of the most secure ones to stay out of reach from hackers, corporations and government agencies, and, once and for all, it can be used in a completely anonymous way.

The app is called Threema and we could say that it's the opposite to the ones that we use everyday -such as WhatsApp- in terms of security and privacy.


Security comes first


Telegram is a big bet, and so is Line with the implementation of end-to-end encryption. WhatsApp would later adopt this method, though a bit later than its competitors. If we want to jump to the next level, we’ll get to Threema. It's not a free app, something that some users may not like, but those who want to have access to certain privacy and security features will shortly find in it a great destination for completely anonymous conversations.

Threema is an app developed by a company in Switzerland that has been endorsed by the German government. The servers are located in Switzerland as well and we could say that it’s one of the countries that cares the most about users’ safety and privacy.


With that being said, these servers will only store the minimal amount of information, and the users’ devices will act as clients and servers. The Swiss servers will only act as intermediaries to transfer information from one device to the other. Said information, will be encrypted.


Anti-hacker encryption

Image courtesy of  Melina Sampaio Manfrinatti at Flickr.com

Without a doubt, announcing that it will be impossible for hackers to access your private information will be an attractive statement to them, but this is due to an encryption method based in the open-source library NACl (Networking and Cryptography library). This is why in order to impede copies of information or unauthorized backdoor accesses, the encryption keys are generated and stored securely in the devices of the users, as we mentioned before. 

Threema has stated that group subscriptions and contact lists are only managed from the user’s device. Once the messages have been delivered, they delete themselves so that the files that remain locally will stay, encrypted, within the smartphone or tablet.

The following are several of Threema’s features:

  • Text messages and voice messages 
  • Sending of all kinds of files: PDF, GIF, MP3, Doc, ZIP and so on.
  • Sending images and video and the ability to share your location.
  • Group chats in which new members can be deleted at any time.
  • ID verification of contacts through personal QR codes.
It’s also worth noting that Threema doesn't require the use of a phone number or an email address. Each user receives a random ID from Threema to identify themselves.

You may not find many of your contacts with it, but it's only a matter of time. It also has a specific function in terms of privacy which differentiates it completely from other apps.

The company that created Threema is made out of -you guessed it- three employees. The startup managed in just 24 hours to double the size of their user base and the app got to the first place in the charts of paid apps in Germany.

Threema combines components of social networking with some of them coming from messaging apps and, on the other hand, apps aimed towards customization. Anonymity is definitely a key factor around which the app revolves.

The German government endorsed the usage of alternative apps for private communications. The app also allows you to find other users by syncing your contacts, but this step is completely optional. You can also share information such as your location on a map, all without leaving the app. If you want, you can exclude individual contacts from the sync process, it features an internal image viewer, a contact list that can be classified according to your needs, blocking of individual contacts, quick switching between different chat conversations, custom nicknames for unknown contacts and several other useful features that will help you keep your conversations away from eavesdroppers.

Even though it doesn't feature the option of voice calling, users can send voice messages. It's available for iOS and Android, and it’s a little less expensive if you have a Windows phone.

Related content

Read Don Burns' "The importance of cryptography in points of sale"

Monday, August 22, 2016

Some 2016 communication trends you need to know

Image courtesy of  RL GNZLZ at Flickr.com
Etymologically, the words trend and “turn” are closely related: they derive from the same Old Norse root: trendr. Trends are new directions, transformations, changes. If our time could be described with a social phenomenon, the lot of increasingly, frequent and definite trends is the right one. The communications sector is an example of how these trends occur very quickly. Some of these trends, which have had prominence in the current year, will be analyzed in this post.

Related: Find Out What Happens When the Telecommunications Industry Discovers 3D Printing

According to Forbes, communication with Millennials is a priority, and one of the ways this will be achieved more efficiently is through human capital investments in call centers. It will certainly develop the necessary technology to achieve the necessary communication.

Several call centers have invested a considerable amount of money on improving communication technologies. The aim has been, for a long time, an effective agent management and a continuous improvement of customer service. Today, the focus of many investments in this sector is real-time communication with users through virtual channels (WebRTC and SMS, for instance), because the Millennials seek, above all, direct and immediate interaction with customer service for solving their problems quickly and efficiently.

Brands will be the new activists. It’s important to keep communities together, but we need to live the experience of living among them and to see them in action. Because of the new kind of consumers, who judge everything based on economic and social policies of brands, we continue to see how brands give more weight to those political and social issues that concern people, placing values at the heart of its communication strategy.

On the other hand, virtual reality as a channel of choice is another important trend this year. While consumers need more experiences and less linear communications, virtual reality will become a key trend in the current 2016. This system has been generally used in the gaming and adult entertainment community, but content creators and communications professionals will use this kind of platforms to help people to assimilate certain realities. Users ask for new experiences in real life every day (or something that closely resembles.) Virtual reality has been very useful in the education sector (driving and flight simulators, for example), to the point that in the future will be a need to impart knowledge of all kind. Since during 2015 the technological advances in this field of communications were tremendous, this year things will move faster. “Brands not only need to ensure that they understand the impact that technology may have on the strategy,” says Don Burns, leader in the telecom industry, “they also must know when to use it and where to turn it into work.”

Image courtesy of  Tyler Pruitt at Flickr.com
In addition, in the flowcharts of companies, Youtubers may have a significant presence to stream content to workers. Companies need to decode new cultural codes, just like Youtubers: a social phenomenon of a decade that started in 2006 and has revolutionized the way information is transmitted at present.

Large 2016 marketing campaigns don’t just make noise to catch attention: they provide a good service. IBM, for example, has protected people from the rain under their ads on the street, and Samsung has set up giant screens in the back of their trucks where they project an image of the traffic through a camera on the front of the vehicle, to show drivers a good view that the truck is blocking. Marketing campaigns will be increasingly active every day.

The traditional model of 'funnel' sales belongs to the past. Consumers go directly to the end point of purchase today. While large online retailers are always seeking the amplitude, brands must seek depth. They guide their ad contents and campaigns to create a good experience with the brand. It makes it possible for consumers not only back, but remember the brand anywhere when purchasing.

The Internet of Things (IoT) is changing the way the global society communicates with itself. This phenomenon of hyper-connectivity will produce a paradigm shift of huge proportions, difficult to foresee (almost like the invention of the steam engine or the discovery of electricity.) Every day, more devices and objects of daily use are connecting to internet and providing useful information for users and businesses. In ten years, the number of smart objects will exceed the fifty billion of units. This year, more and more brands want their products to use IoT technology to improve the user experience and their sales and services as well.

Finally, the Millennials are destroying advertising. iOS 9 has allowed ad blocking, but the market is not ready to react. In 2016, brands will need to improve native advertising, as well as exploring new ways to generate notoriety in the top of the funnel (from sponsored podcasts and agreements with bloggers who are influencers, vloggers and Instagrammers), to a renewed commitment to activities experiences.

Tuesday, August 16, 2016

The importance of cryptography in points of sale

Image courtesy of hrp_images now at Flickr.com
When we analyze the security of point of sale (PoS) applications, we must keep in mind the necessary presence of magnetic bands and the data of the owners of cards, which are extremely sensitive information, both for the owner as well as for the financial institution that provides them.

In any space in which there’s information that needs to be protected and safeguarded, there lies the imperious necessity of using cryptographic solutions, the ones that originated in battlefields and which today are capable of protecting the confidentiality and integrity of said data. It's not enough to use certain safe protocols, it is also necessary and imperative to make a correct and proper implementation at a software and hardware level.

As obvious as it may seem, cryptography is an essential part of a point of sale, as well as in any other digital forms of payment used today. Complementing the pillars of confidentiality and integrity, authentication and non-repudiation come into play, which means that an operation cannot let itself be unknown to the user.

In terminals, mainly three groups of cryptographic algorithms converge which are used in heterogeneous technologies, where they mix with one another and with many architectures within the point-of-sale devices. Each one of these groups has advantages and disadvantages in relation to one another.
The main point where we will be able to distinguish great differences are linked to resource consumption, speed and even the ease of implementation in the different sections that point-of-sale devices have. The way of storing a password, the way of encrypting the communication between two points or even the degree of safety needed will be the way in which either one of the following algorithms will be implemented.

Symmetric-key algorithms



The same password is shared for the encryption and decryption of information. This algorithm is very fast, but at the same time it is less secure and it definitely needs both parts to have already exchanged their key or password to begin the communication. A couple of examples of symmetric-key cryptography are the 3DES and AES algorithms.

Asymmetric-key algorithms

Image courtesy of MIKI Yoshihito at Flickr.com
They contain two keys: a public and a private one. This way, the same one cannot be used to encrypt and decrypt the information. Both keys are generated at the same time and the private one is safeguarded, which is the one that will be used to read; and the public one is distributed, which is the one that will write, encrypting the communication. Two extensively used examples of asymmetric-key cryptography or public key infrastructure (PKI) are email messages sent through PGP (Pretty Good Privacy), or the network traffic encrypted with SSL or TLS. These are widely used in transactional websites or those that require the user to enter a set of credentials.


One-way algorithm or hash


These functions capture a variable-length information and generate an output commonly called fixed-length hash, based on the input. These functions used in cryptography have the property of being easily calculated, which is why they're widely used to store passwords, since it is difficult -in many cases- to recreate the input if only the value of the hash is known.

When it comes to encryption algorithms, size does matter


A general rule for all encryption algorithms is: the bigger, the better. This is due to the fact that the most simple way of attacking encryption is a brute force attack, testing all the possible combinations of bits, until finally the desired string is found. With the data combination processing capacity of modern computers, it is possible to apply brute force techniques to obtain relatively long passwords made out of several bits or characters.

For instance, DES with a 56 bit combination password can be cracked in less than a day. However, the addition of more bits to the string will exponentially increase the time required for the cracking process to finish. The most widely used hash algorithms are MD5 (128 bits) and SHA1 (160 bits) which curiously are not very robust when it comes to security in comparison with Triple DES or AES, both of which are recommended by the NSA.

To sum up, the diversity in the different types of point of sale devices, both in modular and compact machines, will keep rising and the telecommunication technologies will also accompany this constant evolution, generating greater indices of speed and availability. However, cryptographic algorithms in many cases don't go hand-in-hand with the development of point of sale devices from the initial stage of the design, which leaves an open window through which cyber criminals are able to break into systems and extract different types of information.

Malicious codes are able to sort these cryptographic processes in payment terminals or point of sale devices, applied in certain specific layers with the intention of capturing sensitive information.

Recent contents

Read Don Burns' "What Is Encryption And How Can It Work For Me?"

Thursday, August 11, 2016

What Is Encryption And How Can It Work For Me?


Image courtesy of Intel Free Press at Flickr.com
We truly live in an era where information has become one of the most traded commodities available. Is it possible to ensure that the information we send, receive, create and store in our devices stays safe and accessible only to those you want to share it with?

The use of encryption software has been associated with paranoid conspiracy-theory enthusiasts who believe the government is out to get them and wants to steal their information. However, as ridiculous as it may sound, they are not entirely wrong. Your information can be at risk but not exactly the way you think. Identity theft, hacking, state-sponsored snooping and even advanced steps of social hacking may take place by violating your electronic privacy accessing your files, pictures and personal computer content.

You’ve probably heard the word “encryption” many times before but are unsure of what it means exactly, how it works and what can you do to take advantage of its benefits.

First of all, encryption is a method of protecting information in a way so that only those intended by you are able to access it. Using encryption is not something new, and the basic concept of it remains the same even if the tools available to encrypt have changed. Rudimentary forms of encryption have existed since the times of the Old Kingdom of Egypt when non-standard hieroglyphics were carved in monuments. It wasn’t until around 800 AD when Al-Kindi invented a frequency-analysis technique for breaking mono-alphabetic substitution ciphers, something that proved to be the most fundamental cryptanalytic advanced until WWII.

Encryption uses algorithms to jumble data into a string of code that is complete gibberish to those who do not have permissions to see the information. Those permissions come in the form of an encryption key that decodes the information and rearranges characters and code so it can be read the way it was meant to and without the key it is impossible to decrypt the data.
Data can be encrypted in transit, meaning when the information is traveling towards its destination; or at rest, when the data is stored at a terminal or server. End-to-end encryption for communication platforms is considered the most secure. If messages are end-to-end encrypted, only the people who are having the conversation have the keys to decrypt what’s being sent.

Software for encryption is very easy to use nowadays and it doesn’t take much to get started. Here you can see a very easy info-graphic showing you all the necessary steps to do basic encryption for folders in different operative systems. 

It is important to choose an encryption key length that is strong enough to withstand any attacks or attempts to decrypt your data. An AES 128-bit encryption key is considered suitable for your security needs as it can have more than 300,000,000,000,000,000,000,000,000,000,000,000 key combinations.  
Encryption software gathers random data before encrypting your files, also known as entropy. The password you use will be part of this random data gathered to cipher the files, this is why it is very important that you choose a long passphrase, in addition, you should not use any dictionary words to avoid brute force attacks. A brute force attack consists of an automatic process where all of the dictionary words are quickly input at the password login window. As computers have become increasingly faster this can be done in a matter of hours or less using cloud computing.

Here are some tips to follow:
Image courtesy of Kevin Spencer at Flickr.com
  • Always choose an encryption program that uses a standard cipher that has been approved and tested by experts, like AES for example.
  • Do not use common dictionary words as your password, use a long passphrase made up of capital and small letters with punctuation signs and numbers that will remember and try not to write it down anywhere
  • Do not use the passphrase you use to encrypt your data for anything else like your email, Facebook or any other computer password.
  • Never trust a third party service to store your encryption keys or carry out the encryption implementation, if you store data online encrypt it yourself in your computer before uploading it.
  • Watch out for key-loggers and malware in your computer that could capture your keystrokes and your secret passphrase, use an antivirus and firewall and always keep it up to date.
  • Never reveal to anyone your password, not even to a support department whose staff could be outsourced overseas or could be impersonating someone else. Always verify personnel before giving out any of your information over the phone
All of your information is valuable and should be protected, so take the necessary steps and get in the positive habit of encrypting your files and your communicated over the web.

If you want to learn more about encrypted communications and more advances in telecommunication technologies, be sure to check out our many articles at our blog at Don Burns’ Blogspot.

Monday, August 8, 2016

Anonymity on the Internet: which is better, VPN or Tor?


Image courtesy of Blue Coat Photos at Flickr.com
Complete anonymity on the Internet is impossible and, in the best of cases, a particular phenomenon unfeasible of being maintained for extended periods of time. However, both the VPN and Tor networks help hide the user's identity from third parties. But which one of them is better? Let’s take a look at the similarities, differences, advantages and disadvantages of using VPN and Tor.

Online privacy has become a growing concern for millions of users worldwide, either due to the fact that they’re sharing all kinds of personal information with third parties such as Facebook, Google or Twitter; or to prevent possible attacks by cybercriminals; monitoring by government agencies like the NSA or to limit access to certain websites.

Even though some still believe that surfing the Internet is an anonymous activity, reality is stubborn. The incognito mode or private browsing offered by browsers like Google Chrome, Mozilla Firefox and others is not an effective method of maintaining your anonymity on the Internet, which is why more users are choosing to use a VPN or connecting through Tor.

Both are two methods of transport to surf the Internet. However, the differences between Tor and VPN networks are considerable: a VPN could be likened to an ultralight aircraft, pretty fast but also expensive; whereas Tor, could be compared with a bus, available to anyone, but much slower.


Advantages of using Tor


The purpose of Tor (The Onion Router) is anonymity when surfing the Internet. To do this, the user’s information bounces between different nodes before reaching its destination, so the last server is unable to know the location and private information such as the IP address of the source.

We said at the beginning that there’s no such thing as complete anonymity, and Tor is no exception. Although it’s one of the best systems to surf anonymously, the network’s end node decrypts the data to access the required destination by the initial user, opening the door to possible vulnerabilities. It is hard, but not impossible.

If you browse via Tor, it is essential for you to be aware of the fact that it is not a bullet-proof system. The security level is very high if you use secure connections (HTTPS), but otherwise it’s low.

To maintain your anonymity it’s essential that you avoid sending unencrypted personal information such as your email address, location or mobile phone.


Advantages of using a VPN

Image courtesy of PhOtOnQuAnTiQuE at Flickr.com
In simple terms, VPNs (Virtual Private Networks) add a private network -tunnel- on the main network of the user. Basically, a VPN grabs your connection, encrypts it and sends it to another server. Instead of your computer going directly to Google, it first accesses an intermediate server and, from there, it goes to Google.

Using a VPN is recommended, for example, when browsing within a public Wi-Fi network because otherwise you’ll be at risk of third parties seeing everything you do online. When using a tunnel, only your connection to the intermediate server will be visible, which is the one that actually makes the requests to Google, Facebook and other sites.

Another advantage of using a VPN versus the usual navigation is that you can “fool” the rest of the world about your location: if you are in New York and the VPN server you use is in London, all of the websites that you visit will believe that you are a user from England, which opens the possibility of skipping geographical limitations in all types of content.


When is it best to use Tor? And a VPN?


Although there are some providers of free services like Hola, most VPN services -the most powerful ones- are paid. By contrast, the Tor network is free by definition, because it employs the user’s connections to establish the nodes.

Anonymity in a VPN network is in any case relative, given the fact that even though they promise not to store information about their users, it is difficult to think that they can keep their promise if a court order comes.

Tor guarantees a higher level of online anonymity, as long as the the user takes some precautions, but it’s not as impenetrable as the NSA has tried to show in recent years. The biggest disadvantage of Tor is that browsing speed is very limited.

When to use a VPN? If you are an intermediate user concerned about online privacy and the use of your data by third parties the recommended option is a VPN. You will have a considerable latency, but the speed of your connection will be enough to play HD videos on sites like YouTube or Netflix.

When to use a Tor network? This system is used in situations that require a high level of anonymity, especially with the threat of governments or intelligence agencies. It’s reliable, for instance, for journalists working with sensitive documents and leaks, but the biggest disadvantage is that the connection speed is quite slow.
Recent contents

Read Don Burns’ “How The Evolution of Sensors On Smartphones Makes Life Easier”

Monday, June 20, 2016

10 Most Popular Uses For The Internet Of Things

Image courtesy of CODE_n at Flickr.com
Wikipedia defines the internet of things (IoT) as “the network of physical devices, vehicles, buildings and other items—embedded with electronics, software, sensors, and network connectivity that enables these objects to collect and exchange data.” But what does that really mean? How does it affect me? 

Think about it this way; anything that can be connected will be connected in the near future. It means devices that have an on and off switch will be able to communicate with each other and be controlled and monitored from anywhere in the world as long as they are part of the network. This type of advances will greatly change the way we live and interact with other in social, financial and personal aspects.

Here we have, some of the most popular uses we are seeing today, for the Internet of Things.

1. At home


Smart homes are some of the most common examples of innovative technology using the IoT today. Houses that are connected, allow users to control everything from how the access the home, temperature, lighting, entertainment and home appliances. Systems can be as simple or as complex as users want, and there are a lot of big companies out there making sure they can offer users the latest gadgets to fit their smart home set up.


2. Wearable technologies


Smartwatches and fitness trackers are just a couple example of this category. There are also wearables for pets that allow owners to track their activity, sleep cycles an overall health with the help of monitors the animal can wear easily. Clothing off course is another obvious choice for developers of wearable devices made for athletes and fitness enthusiasts. These garments can measure muscle activity, vital signs and GPS location among other things.

3. City Management


Smart cities in the future will use technologies like the Smart Belly, a device that communicates with municipal services to let them know that a certain trash can needs to be emptied. There are also apps that can communicate to drivers the number of parking spots available in different city blocks with the use of infrared sensors located next to the curb or in parking garages connected to the system. Other uses that are already available include lighting regulators to use energy more efficiently as well as monitoring stations for pollution and noise levels.

4. Security


Close circuit security systems that can be accesses from your mobile phone as well as better alarm systems installed at homes that can be connected to emergency services. Another aspect of security that is of great importance is the need for better encryption in communication protocols due to being in an environment of enhanced connectivity.

5. Analytics


Understanding customer needs and processing feedback and suggestions will always be of great relevance in the future of telecommunications. The IoT allows delivering services, improving products, identifying and intercepting business moments.

6. Health


Health in general is another area greatly benefited. This can go from preventive medicine as it is in the case of sensors that track your health, all the way to emergency services and devices. It is worth also mentioning monitors for babies and for elderly members of the family that can help you be vigilant of their health as well as of possible hazards.

7. Retail Applications


Retail solutions can help to make the customer experience a lot better, as well as aiding with restock, reorder, tracking and product information. There are apps that also help human resources monitor staff activities and creates an internal network of instant communication between different areas of the business.

8. Farming

Image courtesy of joinash at Flickr.com

These applications can be used to track the health of livestock as well as help farmers monitor crucial vitals like humidity, air temperature and soil quality using remote sensors on their crops. Individual monitoring of plants and animals can help the industry be more productive and to minimize losses due to disease and detrimental conditions suffered due to different conditions.

9. Maintenance and repair


Moving components, vehicles and machinery in general need constant monitoring and inspection of parts and maintenance. Most of this is done manually and takes a lot of manpower. Making these processes automatic ensures that resources are used more effectively and only when needed, ensuring the safety of operators and reducing costs in a responsible way.


10. Advanced warning for disasters


The University of Loughborough’s has developed an Acoustic Landslide Detection system called ALARMS (Assessment of Landslides using Acoustic Real-time Monitoring Systems). It detects waves produced by soil movement and it relays information that can be used to issue early warnings to communities that could possibly be affected by natural disasters like earthquakes for example.

For more information in home networks and its advancement, check out this article at Don Burns Blogspot.

Sunday, June 19, 2016

Internet of things: controversial changes for the future of the world

Image courtesy of Marcus Brown at Flickr.com
The next major trend that will impact telecommunications is the boom of connected devices. This internet of things, or “Thingification”, will add billions if not trillions of new connected data sources globally by 2020. Objects throughout our lives will become connected, aware and chatty, constantly transmitting information across our global networks. The upswing of all of these devices will be an astronomical growth in data volumes; we will quickly push through Exabyte volumes and enter the world of Zettabytes per year, as sensors are added to everything, and everything starts sending out signals, the trunk lines of our networks will have to carry this crushing load of information. The “Thingification” begins for example with a light bulb, which is not particularly smart and it doesn´t have a lot to say, it's either "on" or "not on”. The challenge grows as millions and then billions of bulbs and toothbrushes and microwaves all start pushing more and more information, all of the time. The aggregated traffic from all of these devices will be enormous, and will stress our networks to the max.

The internet of things (IoT) is the network of physical devices, like said light bulbs, plus vehicles, buildings and other items, embedded with electronics, software, sensors, and network connectivity that enables these objects to collect and exchange data. The IoT allows objects to be sensed and controlled remotely across existing network infrastructure, creating opportunities for more direct integration of the physical world into computer based systems, and resulting in improved efficiency, accuracy and economic benefit. The result of this begins with smart homes, intelligent transportation, and then smart cities. Each thing is uniquely identifiable through its embedded computing system but is able to interoperate within the existing Internet infrastructure. By 2020, the Internet of Things probably will consist of almost 50 billion objects. But what actually is this 'Internet of Things'? Basically, it's the combination of low-cost, low-power processors with 'real-world' electronic sensors and wireless network connectivity increasingly being added to a wide range of electrical devices. These sensors can measure everything from temperature and humidity to pressure, proximity, sound, light, gravity, movement, feedback and through on-board software, devices can record and action those measurements over the internet.

Imagine you wake up in the morning and the fitness tracker on your wrist has recorded how well you slept, uploading the results to your Twitter account. Your coffee machine reads your Twitter feed and knowing you're awake, begins brewing your first coffee of the day. Lights automatically turn on and off as you walk down the hall to the kitchen where your coffee is now waiting. As you leave for work, the robotic vacuum cleaner begins and updates its cleaning progress map to your phone. This is the world envisioned by tech giants powered by Internet of Things that promises to change the world we live in.

Today, there are already devices that work with the principle of IoT. In Denmark's a company named Scanomat has developed the TopBrewer, which lets you choose your coffee type from your Android or iOS phone or tablet. In Copenhagen, in TopBrewer Café, you can enjoy the service without queues, just your coffee ordered, brewed and paid for by your phone.

Image courtesy of Pierre Metivier at Flickr.com

This is definite frontier technology right now and the more we understand how it works, the data it generates and how that data is stored and used, the more we'll all be aware of the potential pitfalls and benefits the Internet of Things will bring. But there are two initial problems and a possible controversial third.

First, the IoT is beginning to suffer from the lack of consistent standards. Right now, the pace of IoT development is such that there's as much pressure to get product to market as there is to develop consistent standards to ensure we don't just see a bunch of devices that can't talk to each other. Everything from hardware interoperability to how recorded data is stored in the cloud is coming under scrutiny, with growing calls for standards to be set before the market progresses too far.
Image courtesy of Schneider Electric España at Flickr.com


Second, there is a battle going on, and that's for the platform. Not a day goes by without a new player claiming that their cloud hosted platform is best, from Apple's HomeKit, Google's Brillo and Intel's IoTivity to Qualcomm's AllJoyn, the UPnP Forum and ARM mbed, and the list goes on.

And third, there is no doubt Internet of Things could clash with our privacy ideals as the internet permeates its way into areas of our lives we probably never imagined.

This issue has been debated for years now. If you want to read more about it, go to: are we creating an insecure internet of things? And to know learn about facing the challenges in communications, follow this Link provided by Don Burns.

Monday, June 6, 2016

Silent Circle, the company that turns your privacy into a business

Image courtesy of Maurizio Pesce at Flickr.com
There is no more to it. Privacy and security in communications has to be included within the public and private security plans of organizations and individuals. Silent Circle is a company founded from the need for a new form of digital privacy. It was created in 2011 when Mike Janke, former member of the US Navy; and Phil Zimmerman, creator of PGP (Pretty Good Privacy), met with the idea of developing a new, safer version of Skype.

From this they summoned the other co-founders: Jon Callas, creator of Apple's encryption software, and Vincent Moscaritolo to found the company, in 2014, with the launch of the first phone designed to protect the privacy and digital safety of users. Its name: the BlackPhone.

To reinforce their commitment to the privacy of information, in 2014 they moved their headquarters to Geneva (Switzerland) since this is considered one of the countries with a stronger legislation to protect the privacy of information and, therefore, its customers’.

After four years of operation in Europe and the US, the company committed to emerging markets, targeting Mexico and the rest of Latin America. This is a region that has all elements at play when it comes to security, but there is still work to be done regarding the awareness of risks that exist and how much of the users contributions play a part in being at risk.

Privacy and security in communications must be included within the security plan of organizations and individuals. This initial phase should provoke a cultural and organizational change. Prevention is always the best tool when it comes to crises. The lack of privacy and security can bring financial and reputational losses to both organisations and individuals.

Silent Circle wants to work for the privacy of Latin American markets and their people. They will focus in carrying their message to CEOs or CTOs, as well as the whole society by talking about the risks that exist today in mobile environments. And at the operational level, within organizations, for them to understand the current severity of implementing these policies.

Over the past few years, losses have been reported due to leakages or theft of information equivalent to more than 156 billion dollars. But we should keep in mind that this risk is for companies, organizations and the end consumer. It's not about restricting, but raising awareness and giving people the right tools for them to have a professional and personal balance without losing connectivity or sacrificing functionality.
Image courtesy of Jon Callas at Flickr.com

In this scenario, Silent Circle offers the first platform designed for the privacy of individuals, which is composed of their mobile device, the BlackPhone 2 and the software Silent OS, and the Silent Phone, along with services that add value such as the Silent Manager. The purpose of each of the components of this platform is to provide private and secure communications to the users.

Silent OS the operating system which is exclusive to the BlackPhone 2. It is based on Android but it's designed to address the current concerns about the privacy and safety of users. This means there won't be any leakages of information. The operating system gives users control of their personal, work and family privacy without sacrificing their lifestyles.

Blackphone 2 is the device that provides extra levels of security, such as the Security Center to give absolute control over the personal information that apps request on the mobile device.

The potential markets

The company got to Mexico with an aggressive plan. Seeking to consolidate in that country and then opening to other markets in order to meet the needs of digital privacy and security of the region, it includes staffing and business partners that allows them to develop and effectively execute their operations, which in turn directly affects job creation.

Thanks to their portfolio, the company works hand in hand with the constant needs of private entities, government or whoever handles sensitive information in a more frequent way that has an impact on their organizations. In addition, at the moment, they believe they have an offer and a solution that penetrates different niches and contemplates the growing need for privacy and security of communications and the information in society. This allows them to position themselves in the various Latin American markets and consumer preferences.

How will the BlackPhone be marketed?

The company started operations in its first phase with just one mobile carrier, but it will subsequently do it with the rest of the carriers. The phone is intended for all users, not just businesses, as it provides all the functionality of the best smartphones in the industry and it adds an important piece of privacy and information security and communications. This gives them a very broad spectrum of consumers and they are not limiting functionality or connectivity to their daily lives, but they protect them through the Silent OS and their communications platform, Silent Phone, at the highest level, both information management and communications.

Saturday, June 4, 2016

Telecommunication trends: what you need to know to make profit

Image courtesy of Peter Harrison at Flickr.com
The modern world is propelled by the power of Telecommunications, which is the exchange of information over significant distances by electronic means. A complete, single telecommunications circuit consists of two stations, each equipped with a transmitter and a receiver. The transmitter and receiver at any station may be combined into a single device called a transceiver. The medium of signal transmission can be electrical wire or cable (also known as "copper"), optical fiber or electromagnetic fields. The free-space transmission and reception of data by means of electromagnetic fields is called wireless.
To better understand this wide concept, lets analyze the simplest form of telecommunication, which takes place between two stations. However, it is common for multiple transmitting and receiving stations to exchange data among themselves. Such an arrangement is called a telecommunications network. The Internet is the largest example. On a smaller scale, examples include: Corporate and academic wide-area networks (WANs), Telephone networks, Police and fire communications systems, Taxicab dispatch networks, and Groups of amateur radio operators.

For businesses to remain competitive, they must monitor the latest telecommunications developments and adapt their products and services to meet marketplace demands. Small and medium businesses phone service buyers can find significant cost savings and employee productivity gains when choosing suppliers and technologies. Associated advances in technology, make telecommunications even more critical for SMBs. Global spending on cloud, mobile, social and big data technologies and solutions in 2016 will be growing to more than $3.8 trillion by 2019.

In order to remain competitive in their industries, SMBs need to consider four telecommunication trends that will allow them to make profit and take advantage of the changing technologies.


Information Technology and Telecommunications Convergence

Telecommunications convergence is the way distinct services are merged into single networks. For example, devices such as smartphones that offer voice calls, web access, video, productivity applications and more. In this, Internet is the way information is relayed across networks, and the cloud storage and computing services the massive deluge of data have spawned, foundational for businesses today. Cloud computing is the one with more increasing relevance because the cloud enables the use of all web based tools and applications, from smartphone apps to business basics, such as video conferencing. The cloud is third party, offsite storage and processing of data, in massive. SMBs can purchase their data storage and processing, from a “cloud” provider, avoiding huge capital costs and ensuring access to the latest storage and processing technologies.


The Rise of the App Economy

In the last year alone, an estimated 180 billion applications were downloaded globally. But what originated as an Information Technology catchphrase for smartphone tools has a much deeper meaning for business productivity. Business intelligence applications delivered through telecom systems, such as video conferencing and unified communications, help employees work collaboratively, increase their efficiency and optimize overall business processes. The potential payoffs are huge. Thanks to Business Intelligence, applications are growing in importance and have the biggest impact on a company’s telecommunications needs. Cloud based voice over Internet Protocol calls, and associated applications let small and medium business reap the benefits of applications that allow unified communications through virtually every business application imaginable. Unified communications applications bring productivity improvements for mobile employees, they can also favorably change ways in which all employees communicate as well as reduce the necessity of travel. And, with the right service partner, these solutions to complex business needs, can be implemented simply and cost effectively.


Cyber Security

Image courtesy of Christiaan Colen at Flickr.com
Cyber security ceased to be optional. Everything from banking and healthcare to education and government, is protecting these digitized networks and the data they hold is critical. Cybercrime is crime that involves a computer and a network, with the computer being used in the commission of a crime, or being be the target Cybercrime costs are projected to reach $2 trillion by 2019. 

Regulations to protect this sensitive data are substantially increasing and are becoming increasingly complex. This creates a dilemma for SMBs, for whom these expectations may be the same as large companies’ with substantially greater resources: to remain competitive; do they incur the huge costs of self-implementing every possible security protection; or do they just take the risk? Fortunately, SMBs have another choice: obtaining data and network security as a service from a provider with third-party data security certifications, covering the key risk areas and regulatory requirements.


Large telecommunication providers

The fourth trend is that large telecommunication providers are shifting their focus away from small and medium businesses. This market segment requires a greater level of customer service than consumer markets, leaving them out of the sweet spot of most large telecom providers. Selling and servicing SMBs involves a greater number of stakeholders and requires higher and more frequent degrees of touch.

Wednesday, June 1, 2016

All you need to know about Encrypted Communication basics

Image courtesy of Intel Free Press at Flickr.com
Nearly every computing device we interact with on a daily basis utilizes some form of encryption technology. From smartphones (which can often have their data encrypted), to tablets, desktop, laptops or even your trusty Kindle, encryption is everywhere and it is a good idea to have some notions about this technology and know how to use it in case of need. Let's analyze the basic concepts:

We can define Encryption as the process of encoding messages or information in such a way that only authorized parties can read it. Encryption does not of itself prevent interception, but denies the message content to the interceptor. In an encryption scheme, the intended communication information or message is encrypted using an encryption algorithm. For technical reasons, an encryption scheme usually uses a pseudo-random encryption key generated by an algorithm. It is in principle possible to decrypt the message without possessing the key, but, for a well-designed encryption scheme, large computational resources and skill are required. An authorized recipient can easily decrypt the message with the key provided by the originator to recipients.

When we use the Internet, we're not always just clicking around and passively taking in information, such as reading news articles or blog posts, a great deal of our time online involves sending others our own information. Ordering something over the Internet from an online vendor, or signing up for an online account, requires entering in a good deal of sensitive personal information. A typical transaction might include not only our names, email addresses and physical address and phone number, but also passwords and personal identification numbers. The incredible growth of the Internet has excited businesses and consumers alike with its promise of changing the way we live and work. It's extremely easy to buy and sell goods all over the world while sitting in front of a laptop. But security is a major concern on the Internet, especially when you're using it to send sensitive information between parties.

There is a whole lot of information that we don't want other people to see, such as Credit card information, Social Security numbers, Private correspondence, Personal details, Sensitive company information and Bank account information.

Information security is provided on computers and over the Internet by a variety of methods. A simple but straightforward security method is to only keep sensitive information on removable storage media like portable flash memory drives or external hard drives. But the most popular forms of security all rely on encryption, the process of encoding information in such a way that only the person with the key can decode it.


How does it works?

Encryption is a modern form of cryptography that allows a user to hide information from others. Encryption uses a complex algorithm called a cipher in order to turn normalized data (plaintext) into a series of seemingly random characters (ciphertext) that is unreadable by those without a special key in which to decrypt it. Those that possess the key can decrypt the data in order to view the plaintext again rather than the random character string of ciphertext.

Two of the most widely used encryption methods are Public key (asymmetric) encryption and Private Key (symmetric) encryption.

The Public Key Encryption uses the recipient’s public key as well as a (mathematically) matching private key. With the public key you could enter new information to the storage but you wouldn’t be able to view items already in there, nor would he be able to retrieve anything. The private key is used for encrypting cipher text. On the other hand, with the private key you could open the storage and view all items inside as well as removing them as you see fit by using the matching private key. However you could not add things to the box without having an additional public key.

Image courtesy of Karl Baron at Flickr.com
The Private Key Encryption or symmetric encryption differs from Public Key encryption is in the purpose of the keys themselves. There are still two keys needed to communicate, but each of these keys is now essentially the same. Two users need two different keys, but with them, they both are allowed to encrypt a message as well as decryption it, so they are both allowed to add or remove things from the storage.

We can conclude that Encryption is safe. The amount of time, energy usage and computational cost to crack most modern cryptographic technologies makes the act of attempting to break an encryption (without the key) an expensive exercise that is, relatively speaking, futile. That said, encryption does have vulnerabilities that rest largely outside of the power of the technology. But no matter how secure the encryption, a backdoor could potentially provide access to the private key. This access provides the means necessary to decrypt the message without ever breaking the encryption.

Monday, May 30, 2016

How to encrypt communications to have secure Android calls and text messaging


Image courtesy of Steve Crane at Flickr.com
In the digital age, maintaining your privacy seems to be a never ending battle sometimes. All kinds of companies and organizations have access to your personal data and information, and a few of them can spy on almost all methods of modern communication. 

In an effort to fight this trend, Open Whisper Systems has been at the forefront of encrypted mobile communications for quite some time. Their apps TextSecure and RedPhone, originally an exclusive feature in the CyanogenMod ROM, have brought secure and fully encrypted calls and text messages to smartphone users from all over the world.

With the aim of consolidating both options, Open Whisper Systems combined those two applications for secure communications into a single one, Signal. As a result, your calls and text messages can now take place away from prying eyes by installing a simple application, so we’ll take a look at how to achieve this:

1. Install the Signal app


All of TextSecure and RedPhone’s functionalities have been grouped into a single, open sourced application, called Signal. In order to start having encrypted communications that no one can eavesdrop, open the following link from your Android device to install the application:
https://play.google.com/store/apps/details?id=org.thoughtcrime.securesms

The installation of Signal can be performed, free of charge, from the Google Play Store. If you were previously a user of TextSecure or RedPhone, you'll notice that Signal will be installed as an upgrade to your existing TextSecure application. Basically, the only difference is that Signal provides all of the functionalities of RedPhone plus encrypted SMS, so, if you wish, you can uninstall the RedPhone app once you’re done. Signal is also available on iOS, so your friends and family members who own an iPhone can also use the app on their devices.

2. Activate Signal and import messages


Once you’ve installed Signal for the first time, you will be prompted to register the device. Make sure the phone number is correct, then tap the “Register” button and click “Continue”. From here, an encrypted text message will be sent to your device to automatically complete the registration process. Once you have registered, you will be prompted to set Signal as your default SMS app. Tap the banner at the top of the screen to do this, then press “Yes” in the pop-up. From here, you’ll see a second banner that lets you import existing SMS messages, so touch it if you’d like to have all of your text messages brought to Signal.

3. Invite your friends to join


At this point, app itself is all set, but before you start making calls and sending text messages, you should familiarize yourself with how the system works. Signal can only fully encrypt calls and text messages if both parties in a conversation are using the app. Otherwise, all communications will be carried out via standard connections. To start a secure conversation, press the action button in the lower right corner, then select a contact from the list. If the user you selected doesn’t have the app installed, you’ll be notified and will have the chance to invite him or her to do so. The other party will receive a link to download the Signal app for iOS or Android.

4. Make encrypted calls and send encrypted text messages

Image courtesy of Mister G.C at Flickr.com
Once you have made sure that the other party has installed the Signal app on their device, the text box on the bottom of the screen will say “Send Signal message”. This means that the messages you send to this person will be encrypted end to end, so there is no way for anyone to spy on the conversation. If you wish to make an encrypted call, just find the phone icon at the top of the chat window and make sure it has a small padlock icon superimposed on top of it. If so, simply press the button and the call interface should appear, and the banner at the top of the screen will read “Signal call”, which means that the conversation will be fully encrypted. The little padlock icon may not be displayed on top of the call button on all devices. In some cases, even when both parties have the application installed, the call button might have the lock icon missing and the system’s stock dialer interface is launched instead of Signal’s calling interface. So apparently there are still some rough edges in the app, but these issues should be resolved soon.

Do you feel more comfortable knowing that all of your Android communications can now be encrypted? Hopefully this app will continue to grow, in order to restore people’s peace of mind when it comes to regaining their privacy and the right to protect their personal information and conversations.