Posts

Showing posts with the label Privacy

This Week I Learned - Week #52 2019

Image
This Week I Learned - * In a GigaOm study comparing throughput performance between SQL Server on Azure Virtual Machines and SQL Server on AWS EC2. Azure emerged as the clear leader across both Windows and Linux for mission-critical workloads, up to 3.4 times faster and up to 87 percent less expensive than AWS EC2.  A key reason why Azure price-performance is superior to AWS is Azure BlobCache, which provides free reads . Given that most online transaction processing (OLTP) workloads today come with a ten-to-one read-to-write ratio, this provides customers with significant savings. * AzureCharts.com provides a visual digest of vital info related to Azure Services. It can answer these questions faster than if you had to look it up in the Azure documentation  - >> Is a particular VM instance type available in all regions? >> Is a service Generally Available or in Preview mode? In how many regions is it available? >> What are all the Azure servi...

This Week I Learned - Week #51 2019

Image
This Week I Learned - *  Network security groups are associated to subnets or network interfaces in the Resource Manager deployment model . Unless you have a specific reason to, Microsoft recommends that you associate a network security group to a subnet, or a network interface, but not both. Since rules in a network security group associated to a subnet can conflict with rules in a network security group associated to a network interface, you can have unexpected communication problems that require troubleshooting. *  Certain services also impose restrictions on the subnet they are deployed in , limiting the application of policies, routes or combining VMs and service resources within the same subnet. Check with each service on the specific restrictions as they may change over time. Examples of such services are Azure NetApp Files, Dedicated HSM, Azure Container Instances, App Service. *  Service endpoints allow service resources to be secured to the virtual netwo...

This Week I Learned - Week #213

Image
This Week I Learned - * Q. Does Azure Backup deduplicate data across VMs? A. No. Azure Backup does not deduplicate across VMs in the Azure Backup vault. Azure Backup works by only sending and storing the modified blocks of protected data which means only the delta change is stored for each backup optimizing space used. *  The Azure SQL Database has a DNS name which by default is blocked for access through its firewall and access has to be enabled for IP addresses utilizing (from the Internet) and/or from all services in Azure itself. * When an Azure SQL Database instance is accessed from an Azure service the access is through the internal Azure network and not via the Internet. * All new Azure SQL databases will be encrypted with transparent data encryption by default, thereby having encryption at rest. * Amazon is releasing new software updates every 11 seconds * Whatsapp has a billion active users and 57 engineers to keep it running *  LinkedIn to auto-sugge...

This Week I Learned - Week #168

This Week I Learned - *  Microsoft Azure Machine Learning Algorithm Cheat Sheet helps you choose the right algorithm for a predictive analytics model. * Microsoft Data Science Virtual Machine (DSVM) is an operating system image available in the Azure Marketplace with a host of popular data science tools pre-installed and pre-configured. *  Azure SQL Data Warehouse can connect to Microsoft’s Azure Machine Learning libraries and Azure Data Lake. *  Mark Zuckerberg covers his laptop camera. The taped-over camera and microphone jack are usually a signal that someone is concerned, perhaps only vaguely, about hackers’ gaining access to his or her devices by using remote-access trojans — a process called “ratting.” (Remote access is not limited to ratters: According to a cache of National Security Agency documents leaked by Edward J. Snowden, at least two government-designed programs were devised to take over computer cameras and microphones .) - NY Times ...

Browsers give away device name through user agent - Et tu Browser!

Image
My mobile browser has been letting the websites I visit know what handset I use and I wouldn't have known this until I saw this targeted ad - an ad for case for Lumia 530 I knew about browser user-agent strings, but today I learnt that browsers give away device model name as well, through the user agent they expose - Mozilla/5.0 (Windows Phone 8.1; ARM; Trident/7.0; Touch; rv:11.0; IEMobile/11.0; NOKIA; Lumia 530 Dual SIM) like Gecko Cookies , prying sites like Google , Facebook , apps like TrueCaller know more about me than my friends and family . Good-bye privacy !

Beware of Mobile Apps which misuse access requirements

Image
An excellent article by Shadma Shaikh  in The Economic Times, highlights the dangers of Mobile Apps which misuse access requirements. Excerpts - As India becomes a mobile app-economy, it is important for users to understand if apps indeed require access to so much of their data and device tools.  Even if .. not paranoid about online security, you ought to be more careful about something else--mobile applications.Apps that read your contact list and your messages--including the ones about your bank transactions and one-time passwords, and access your pictures, screenshots and messenger images. Permissions by themselves are harmless and even useful to provide users a good mobile experience. But since the list of permissions required is long and doesn't explain its effect, an immediate reaction is to treat it the way you would a `Terms and conditions' agreement--accept without reading the list and move to the next step. Skipping over these permissions could m...

HOW TO completely get rid of everything you ever posted on Facebook?

Image
Based on this forum post on StackExchange Also see:  What do you give someone who already owns a lot of gadgets?

Cookie usage notification

Image
For quite a while now, I've wondered why websites all of a sudden have been bothering to put a prominent notice that reads something like - " This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. " I've learnt that websites HAVE to do so because they are mandated by European and US Internet privacy laws.  The law applies to European companies even if their website is hosted overseas. This explains why google.nl has the cookie usage notification for that domain but not for google.co.in - Indian laws probably don't ask for it. (This kind of differentiation by country exists on other Google properties as well.  For political correctness , Google serves one map of India from its Indian domain & a different one when viewed from Google Map's HK TLD ) Did you know, a visit to a page on the Guardian's website may generate the following types of cookies : - Site performance cookies - Anonymous analytics c...

List of online services that offer 2-Step Verification

Image
".. all you data from “smart” devices could be accessible from internet,which is the  place of  anarchy .." Apple has acknowledged that computer hackers broke into the accounts of several celebrities and advises all users to always use a strong password and enable two-step verification.  It turns out two-factor authentication may have not entirely protected anyone in this case. The criminals apparently used ElcomSoft, a law enforcement tool(!), to expedite the extraction of information from iCloud backups, not protected by two-factor.   Being paranoid is probably a good thing to get used to . As the Internet evolves, there will probably be a security hack for every deterrent that the good guys enforce. Two-step verification can be one of many checks that regular users can make use of to ward off evil hackers. Josh Davis maintains a list of websites that offer 2-Step Verification  that you should check if you don't want to lose critical informat...

HOW TO let Google watch over your web activity

When we get onto the Internet, we trade our privacy for convenience. Everyone from marketers, ISPs to Governments can watch our activities on the Internet. I chuckled when I saw a question on Stack Exchange from an enquirer wanting to find how he can get Google to save not just his search queries but track every URL he types browsers across multiple machines he uses. When we are already giving away so much information, why not leverage these services to the fullest? Google Web History can be set up to track things other than just search. If you're using Internet Explorer, install the Google Toolbar (only available for Internet Explorer) which will then submit all the URLs you access to Google Web History. If you're using Chrome, all of the features of Google Toolbar are already built into it. Signing in to Chrome brings your bookmarks, history, and other settings to all your devices . Anything you update on one device instantly updates everywhere else, and your Chrome ...

Big Data and Machine Learning make protecting your online privacy even more challenging

Image
Your personal details are safe only if the people you've shared it with also realize the importance. With the cost of computing power and storage drastically coming down, it's getting cheaper & easier for social media to entice you and your connected circle into revealing personal information to forward their commercial interests by breaching your trust. image from Google Play TrueCaller is a mobile app that will show you the name of a caller that's not already on your mobile contact list. The app's website claims that it is a collaborative  global phone directory with over 700 million numbers. Don't be surprised if your carefully guarded phone number is in their database. The novelty of finding the identity of an unknown caller may have suckered someone known to you to give away their contact list that includes your number. Thanks to Big Data and Machine Learning, the individual datapoints (phone number, date of birth etc) can be aggregated to pain...

Carefully review apps that provide Facebook Login

Image
Facebook Login makes it easy for a website's users to connect with that app or website without having to create a new set of credentials and instead reuse your Facebook account details. It came as a surprise to me that a shopping site implementing OAuth with Facebook as a provider could receive many more personal details than required for a regular e-commerce transaction. The shopping site places a condition that I should allow it to access my "basic info". I was shocked to find that to Facebook, "basic info" means all of these: Name Profile picture Gender Networks User ID List of friends Any other info you made public Except my name & possibly my email address, the shopping site had no business to know any other details. In addition, it informed that app can make posts on your behalf on your Facebook timeline and the visibility of those posts was set to Friends by default. The onus is on the subscriber to set it to "Only Me"...

Facebook Privacy Settings - important to review but generally ignored

Image
A depiction of the Padmavyuha or  Chakravyuha formation, from Wikipedia Not understanding Facebook privacy settings before getting into it is like Abhimanyu landing into the Chakravyuh trap in the Mahabharata battle of Kurukshetra - it can lead to unsavory social consequences. Like most teenagers of the previous generation who anxiously yearned to get a driving license when they turned 18, these days driven by peer pressure, teenagers eagerly look forward to turn 13 so that they can legally subscribe to Facebook. The privacy settings are too many and in my opinion, purposely defined in a complicated way so that users don't bother with them and accept the default settings which are not in their best interest. So for Facebook users, a little time spent reading about the Facebook Privacy Settings  & implementing them can go a long way in protecting their online social reputation. Also see:  Don't let Chrome & Firefox remember your pa...

4 practical ways to protect your privacy online

Image
A recent Wall Street Journal article reveals that companies today are increasingly tying people's real-life identities to their online browsing habits. WSJ also provides these startling privacy insights among others - Americans' license plates are now being tracked not only by the government, but also by repo men who hope to profit from the information. The government follows the movements of thousands of Americans a year by secretly monitoring their cellphone records .  One of the fastest growing online businesses is that of spying on Americans as they browse the Web. Here are some ways drawn from online resources , to protect your privacy online  - 1. Log Out of Social Networks When Browsing and Clear Cookies All those little “Like” buttons and other social-networking technologies across the Web can inform the parent company of your browsing habits whenever you encounter them. This is true even if you don’t actually click the button. Did you notice, m...

DuckDuckGo shows why Google may not be good for you

Image
To show that DuckDuckGo, a search engine site winning rave reviews, doesn't " filter bubble " or track you, they have illustrated guides to demonstrate how Google may not be as saintly or good as it may appear. The facts they present are something to ponder on. On a different note, DuckDuckGo provides a great API alongwith other goodies like the easily configurable Karma Widget  that displays your online karma (e.g. twitter follower count, facebook fans, etc.), for your blog, profiles or other Web sites. Here's how a sample Karma Widget looks - Related: Say Goodbye to Privacy

Are you building a WikiLeaks of your own life?

New York Times reports that there are now several people database websites that can aggregate personal information & present a dossier with  your age, home value, marital status, phone number and your home address, even a photo of your front door.  Snoops who take the time to troll further online may also find in blog posts or Facebook comments evidence of your political views, health challenges, office tribulations and party indiscretions, any of which could hurt your chances of admission to school, getting or keeping a job or landing a date. Many privacy experts worry that companies will use this data against users, perhaps to deny insurance coverage or assign a higher interest rate on a loan. Like the way some weight loss clinics charge for each pound lost, there are sites that charge a price ($75-$99) for removing personal information from the top online databases! Also see: Say Goodbye to Privacy Impact of online reputation on job recruitments

Impact of online reputation on job recruitments

Image
Did you know, while only 7% of U.S. consumers surveyed believed information about them online affected their job search, 70% of responding recruiters and HR professionals have rejected candidates based on information they found online.  86% of human resources professionals surveyed stated that a positive online reputation influences hiring. (Microsoft Online Reputation Research, 2010) A Microsoft Privacy & Safety blog post  offers these tips for individuals to protect their online reputations: Monitor your reputation by searching for information about yourself on the Internet. Apply appropriate privacy settings on social networking services. Enhance your reputation by posting positive information in your online profiles. Defend your reputation by correcting online information about yourself that is untrue.

Say Goodbye to Privacy

Don't take yourself so seriously. No one else does. Regina Brett Danny Dover makes an interesting point on privacy - The privacy conflicts .. encountered in the offline world are nothing compared to those .. in the online world. With a story & hard facts he illustrates how our private details are tracked by popular websites - Google is storing hundreds of .. metrics about it's users . Apple is rumored to be building a $1 billion data center .. In total, 25 Terabytes of user activity data is stored daily by Facebook. AT&T reportedly has 20,268 servers . This is infantile compared to Google's estimated 1,000,000 servers. Twitter recently peaked at 5,000 messages a second following Michael Jackson's death. Odds are one of them was yours. Digg says that only about half of its server load is from visitors to its website . The other half is a mix of Digg buttons and API calls. This means a non-trivial amount of information that Digg collects is from ...