lunes, 21 de agosto de 2017

Make Your Online Identity Safe Again (1) - The Other CIA.

It is common to think on the U.S.A.'s Central Intelligence Agency when we hear the "CIA" name. It even makes more sense when we are talking security, but SURPRISE! There is another CIA!

I still don't know what format will I use for this series, so for this special ocassion I will talk about something that we all students from the Tec de Monterrey have suffered of: "Las Inscripciones" (a.k.a. that period of time where all the students have to make their schedules at the same time)

So, you may be wondering, "What does CIA mean to you?". When we are talking about computer and information security, one of the most important concepts is the CIA Triad, three components to measure how protected your information is. "C" stands for Condifentiality, "I" for Integrity, and "A" for Availability.

So let's talk class registrations. Why are they always a mess? Imagine that the Tec de Monterrey HAS to fulfill the Triad before you create your schedule. The first thing you have to do, is to enter to your account. By doing these, the ITESM can manage that ONLY YOU can see your information. You can manage your payment, insurances and courses to take there, this is an example of what confidentiality is.

By the way, here's a Top 10 list of words that shouldn't be your password:

  1. 123456
  2. password
  3. 12345
  4. 12345678
  5. football
  6. qwerty
  7. 1234567890
  8. 1234567
  9. princess
  10. 1234
So, please, if you have one of these on your bank account, make youself a favour and change it!

Going back to our subject, let's say you already chose your courses, and you are happy with your schedule (this has never happened to me, by the way), but suddenly, when you want to show it off to your friends, it looks nothing like the one you made, heck, you even had a course on Saturday. This would be a problem of Integrity, the information has to be protected so no one can alter it without supervision.

But the Tec is actually pretty good on the first two letters! Our information is confidential, and it has integrity. The problem is that it is so hard to access to the portal at the same time as the other 7000 students from Campus Guadalajara want to enter as well. When your turn to create your schedule is at 10 a.m. you're doomed because the site will not be available. Just when you need it the most, you'll find it very troubling to enter. Backing-up your information is normally a way to ensure daya availability, so, have your hard drives backed-up somewhere folks!

I heard that they are thinking on changing the name of the CIA Triad to the CAI Triad, but I think that would be a loss. How will everyone start talking about the Triad without an obvious reference to the Intelligence Agency?

miércoles, 16 de agosto de 2017

Make Your Online Identity Safe Again - Introduction to the Course.

Welcome to my blog for Computer and Information Security! You may remember me from such blog series as "Surviving at the Software Industry" and "On The Topic".

This semester I'm on a pilot program for the ISC semestre I at the Tec de Monterrey Campus Guadalajara. One of the courses I'm taking is Security with Ken Bauer. This is not the first time I have a course with him, neither the first time I write for one of his classes. I hope you all enjoy what I write and that it can be helpful for someone in the future.

I am not sure on what will my format be for this series, but stay tuned for more.