<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Vanuatu IT Users Society</title>
	<atom:link href="http://vitus.org.vu/feed/" rel="self" type="application/rss+xml" />
	<link>http://vitus.org.vu</link>
	<description>Community Portal</description>
	<pubDate>Sun, 23 Aug 2009 04:28:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>GPRS USB Modem - Initial Impressions</title>
		<link>http://vitus.org.vu/2009/08/23/gprs-usb-modem-initial-impressions/</link>
		<comments>http://vitus.org.vu/2009/08/23/gprs-usb-modem-initial-impressions/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 03:03:39 +0000</pubDate>
		<dc:creator>Graham Crumb</dc:creator>
		
		<category><![CDATA[Article]]></category>

		<category><![CDATA[Networking]]></category>

		<category><![CDATA[Telecommunication]]></category>

		<category><![CDATA[digicel]]></category>

		<category><![CDATA[geek]]></category>

		<category><![CDATA[gprs]]></category>

		<category><![CDATA[Internet]]></category>

		<guid isPermaLink="false">http://vitus.org.vu/?p=27</guid>
		<description><![CDATA[I&#8217;ve been playing with a Digicel GPRS modem for the last few days, and thought I&#8217;d share some initial impressions.
To me, a computer without Internet access feels like a car without wheels. Trotting around town with my GPRS-enabled laptop has made me realise just how many ways the Internet supplements my daily existence. Technical disputes [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been playing with a Digicel GPRS modem for the last few days, and thought I&#8217;d share some initial impressions.</p>
<p>To me, a computer without Internet access feels like a car without wheels. Trotting around town with my GPRS-enabled laptop has made me realise just how many ways the Internet supplements my daily existence. Technical disputes with my kava-drinking buddies are resolved in a flash. (&#8221;Dude, railway ties <em>are</em> <em>so</em> treated with creosote. So there.&#8221;) My extended family can keep track on what their friends overseas are up to. The opportunities to learn are immense, too. (True story: someone asked me how tall a giraffe is. For the first time ever, I was able to say, &#8220;Hang on. I&#8217;ll show you.&#8221;)</p>
<p>That said, GPRS is far better suited to intermittent connectivity than staying online full-time. A quick facebook update here, an email there - that sort of thing. But compared to the amount of Internet available throughout most of the country (i.e. none) I&#8217;ve got to say it&#8217;s pretty darn cool to have it when you need it.</p>
<p>Read on for the geeky details.</p>
<p><strong>NOTE: Take everything I say with a grain of salt - I&#8217;ve only just started this evaluation, so I reserve the right to be very, very wrong on some or all what follows&#8230;.<br />
</strong></p>
<p><span id="more-27"></span></p>
<h3>1) Windows</h3>
<p>I had mixed results getting the Nokia GPRS USB dongle working on Windows. The dongle comes with all the software you need stored on it, so all I had to do was wait for it to mount itself as a CD device and let autorun do its magic. There are some obvious security issues here, but to its credit, the Nokia device did mount as read-only, so the odds of it getting infected (or passing on malware) is low.</p>
<p>The first machine I installed on - a Lenovo ThinkPad laptop - went smooth as silk, although the software complained about wanting Service Pack 3.</p>
<p>Installing on a VMWare virtual machine (SP2) ended up causing blue screens and never worked. I attribute this to the fact that the version of Windows I was installing on is not at all up-to-date (I normally run it sandboxed with no network connection at all).</p>
<p>A huge problem on Windows is that so many applications install updater services that automatically start downloading stuff the moment you&#8217;re online. I found that the laptop I tried kept transferring data at a more or less constant rate. If you leave the modem connected for any length of time that could get very pricy indeed.</p>
<p>To its credit, the Nokia software has an always-on-top bandwidth usage monitor. It calculates the total download and upload volume, as well as the total (this is what you get billed on). There&#8217;s also a rather rudimentary usage history chart available as well which shows you a summary of all your recent sessions, but unfortunately doesn&#8217;t offer summary totals.</p>
<p>While the session monitoring applet claimed speeds in excess of 40 Kilobits/second, I found that the modem <em>felt</em> slower than my 128Kbps DSL line at home. (More on this below&#8230;.)</p>
<p>Nonetheless, I became very popular indeed when I was able to wander around the Freswota and Namburu neighbourhoods, laptop in tow, and download photos of all my family and friends on demand. (Strictly speaking it would have been vastly less expensive and much more efficient to put them on a USB stick, but that wasn&#8217;t the point of the exercise.)</p>
<h3>2) Linux</h3>
<p>Getting the modem working on Linux was a little more challenging. The Modem took the same approach as it did on Windows, opening itself as a CD device and featuring a clear instruction sheet accompanied by a simple install script.</p>
<p>The only problem was that whoever developed the install routine just assumed that the correct kernel modules would be loaded already. It took a few hours of digging around to find out why my modem just sat there doing nothing. I&#8217;ll be submitting a bug report to Nokia to fix this.</p>
<p>BUT, once the kernel module issue was addressed, using the modem was actually easier in Ubuntu (9.04) than in Windows. As with so many things these days, it <em>just worked</em>. I plugged in the modem and Ubuntu&#8217;s Network Manager found it within seconds, dialed the connection and established a session with a single click. Very cool.</p>
<p>I used my conky desktop monitor script to measure total bandwidth as well as download and upload rates. I did see a very brief peak of 14Kbps at one point, but longer downloads seem to peg at about 4-6 Kpbs (much slower than dial-up). Of course, if you&#8217;re using GPRS to download large files, you&#8217;ll have other fish to fry. The costs alone might kill you.</p>
<h3>3) Mac</h3>
<p>Once again, the Nokia&#8217;s install routine was about as easy as it could reasonably be made. I opened a Finder window, found the USB modem already mounted. Double-clicked on the installer package, and followed the instructions. Easy Peasy.</p>
<p>The software interface, as with many things on the Mac, is much more polished, albeit with fewer features than the Windows version. I could always geek right out and install the same monitoring tools as I used on Linux. But even without those deep forensics, I found the experience (and performance) was much the same as on Windows and Linux, with the exception of a brief failure to finish loading one web page (probably purely coincidental, but it was the Skype.com home page). </p>
<p>All in all, there&#8217;s a definite case to be made for the convenience of being able to check email more or less from anywhere, and it&#8217;s nice to be able to look up information at the drop of a hat.</p>
<p>I won&#8217;t comment on the costs just yet, but let me assure you that this will not be a replacement for a full-time, dedicated Internet account any time soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://vitus.org.vu/2009/08/23/gprs-usb-modem-initial-impressions/feed/</wfw:commentRss>
		</item>
		<item>
		<title>TVL reduces Internet prices</title>
		<link>http://vitus.org.vu/2008/09/26/tvl-reduces-internet-prices/</link>
		<comments>http://vitus.org.vu/2008/09/26/tvl-reduces-internet-prices/#comments</comments>
		<pubDate>Fri, 26 Sep 2008 07:20:27 +0000</pubDate>
		<dc:creator>Daryl Moon</dc:creator>
		
		<category><![CDATA[Telecommunication]]></category>

		<category><![CDATA[ADSL]]></category>

		<category><![CDATA[Internet]]></category>

		<category><![CDATA[TVL]]></category>

		<category><![CDATA[WiMax]]></category>

		<guid isPermaLink="false">http://vitus.org.vu/?p=23</guid>
		<description><![CDATA[TVL last night announced significant reductions in the price of ADSL and WiMax services.
The most significant reduction is the Internet Home 128 kb service that was reduced from 16,800 vt/month to 5,950 vt per month.
See the attached file(s) for details.
TVL New Internet Pricing ENGLISH (PDF File)
TVL New Internet Pricing FRENCH (PDF File)
]]></description>
			<content:encoded><![CDATA[<p>TVL last night announced significant reductions in the price of ADSL and WiMax services.</p>
<p>The most significant reduction is the Internet Home 128 kb service that was reduced from 16,800 vt/month to 5,950 vt per month.</p>
<p>See the attached file(s) for details.</p>
<p><a href="http://vitus.org.vu/files/2008/09/tvl-new-net-pricing.pdf">TVL New Internet Pricing ENGLISH (PDF File)</a></p>
<p><a href="http://vitus.org.vu/files/2008/09/tvl-new-net-pricing-french.pdf">TVL New Internet Pricing FRENCH (PDF File)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://vitus.org.vu/2008/09/26/tvl-reduces-internet-prices/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Results of Telecoms Survey and VITUS Submission</title>
		<link>http://vitus.org.vu/2008/09/17/results-of-telecoms-survey-and-vitus-submission/</link>
		<comments>http://vitus.org.vu/2008/09/17/results-of-telecoms-survey-and-vitus-submission/#comments</comments>
		<pubDate>Wed, 17 Sep 2008 07:16:59 +0000</pubDate>
		<dc:creator>Daryl Moon</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://vitus.org.vu/?p=20</guid>
		<description><![CDATA[The VITUS submission to the DRAFT Telecommunications Licences and the results of the survey that 27 members completed has now been submitted to the Ministry of Infrastructure and Public Utilities.  Thanks to all members that contributed to the discussion and completed the survey.  You can read our submission below and view the results of the [...]]]></description>
			<content:encoded><![CDATA[<p>The VITUS submission to the DRAFT Telecommunications Licences and the results of the survey that 27 members completed has now been submitted to the Ministry of Infrastructure and Public Utilities.  Thanks to all members that contributed to the discussion and completed the survey.  You can read our submission below and view the results of the survey.</p>
<p><a href="http://vitus.org.vu/files/2008/09/vitus-submission-telecoms-licences.pdf">vitus-submission-telecoms-licences</a></p>
<p><a href="http://vitus.org.vu/files/2008/09/vitus-surveyresults.pdf">vitus-surveyresults</a></p>
]]></content:encoded>
			<wfw:commentRss>http://vitus.org.vu/2008/09/17/results-of-telecoms-survey-and-vitus-submission/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Survey on DRAFT Telecommunication Licences</title>
		<link>http://vitus.org.vu/2008/09/14/survey-on-draft-telecommunication-licences/</link>
		<comments>http://vitus.org.vu/2008/09/14/survey-on-draft-telecommunication-licences/#comments</comments>
		<pubDate>Sun, 14 Sep 2008 10:30:54 +0000</pubDate>
		<dc:creator>Daryl Moon</dc:creator>
		
		<category><![CDATA[Government Policy]]></category>

		<category><![CDATA[Telecommunication]]></category>

		<category><![CDATA[telecommunication survey]]></category>

		<guid isPermaLink="false">http://vitus.org.vu/?p=19</guid>
		<description><![CDATA[Following discussions on VIGNET since 8 September, the main points raised in the discussions have been formed into a survey.  Please have your say on these issues by completing the survey.  We will use the results of this survey to help with the VITUS submission to the Ministry of Infrastructure and Public Utilities.  Submissions close [...]]]></description>
			<content:encoded><![CDATA[<p>Following discussions on VIGNET since 8 September, the main points raised in the discussions have been formed into a survey.  Please have your say on these issues by completing the survey.  We will use the results of this survey to help with the VITUS submission to the Ministry of Infrastructure and Public Utilities.  Submissions close on Wednesday 17th September so we will close the survey at 12 midday on that day to allow time to add the survey responses to our submission.</p>
<p>Survey link: <a id="lnkWebLaunchURL" class="bodytext" href="http://www.surveymethods.com/EndUser.aspx?E4C0ACB4EDA6B8B5">http://www.surveymethods.com/EndUser.aspx?E4C0ACB4EDA6B8B5</a></p>
]]></content:encoded>
			<wfw:commentRss>http://vitus.org.vu/2008/09/14/survey-on-draft-telecommunication-licences/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Draft Telecommunications Licensing Policy</title>
		<link>http://vitus.org.vu/2008/09/08/draft-telecommunications-licensing-policy/</link>
		<comments>http://vitus.org.vu/2008/09/08/draft-telecommunications-licensing-policy/#comments</comments>
		<pubDate>Sun, 07 Sep 2008 23:05:14 +0000</pubDate>
		<dc:creator>Graham Crumb</dc:creator>
		
		<category><![CDATA[Article]]></category>

		<category><![CDATA[license]]></category>

		<category><![CDATA[MIPU]]></category>

		<category><![CDATA[telecommunications]]></category>

		<guid isPermaLink="false">http://vitus.org.vu/?p=15</guid>
		<description><![CDATA[The Ministry of Infrastructure and Public Utilities is inviting comments on the following:

Draft telecommunications licensing policy (Download here)
 Draft standard telecommunications licence (Download here)
Draft application for licence (Download here)

I think that VIGNET should see if we can do a response that represents the thoughts of all members.
Responses are required by 5:00pm on Wed 17th September [...]]]></description>
			<content:encoded><![CDATA[<p>The Ministry of Infrastructure and Public Utilities is inviting comments on the following:</p>
<ol>
<li>Draft telecommunications licensing policy (<a href="http://vitus.org.vu/?attachment_id=16">Download here</a>)</li>
<li> Draft standard telecommunications licence (<a href="http://vitus.org.vu/?attachment_id=17">Download here</a>)</li>
<li>Draft application for licence (<a href="http://vitus.org.vu/files/2008/09/draft-application-for-license.pdf">Download here</a>)</li>
</ol>
<p>I think that VIGNET should see if we can do a response that represents the thoughts of all members.</p>
<p>Responses are required by 5:00pm on Wed 17th September so there is not much time to prepare responses.</p>
]]></content:encoded>
			<wfw:commentRss>http://vitus.org.vu/2008/09/08/draft-telecommunications-licensing-policy/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Digicel Seek Technical Operations Manager, Vanuatu</title>
		<link>http://vitus.org.vu/2008/08/20/digicel-seek-technical-operations-manager-vanuatu/</link>
		<comments>http://vitus.org.vu/2008/08/20/digicel-seek-technical-operations-manager-vanuatu/#comments</comments>
		<pubDate>Tue, 19 Aug 2008 23:24:05 +0000</pubDate>
		<dc:creator>Graham Crumb</dc:creator>
		
		<category><![CDATA[Employment]]></category>

		<category><![CDATA[digicel]]></category>

		<guid isPermaLink="false">http://vitus.org.vu/?p=13</guid>
		<description><![CDATA[I met with Digicel management a little while ago to do some research for my column, and they mentioned that they&#8217;d posted an advertisement for the position of Technical Operations Manager.
This is a senior technical position with the company, with significant responsibility.
You can get a copy of the job description here.
Contact Douglas Creevey, CTO of [...]]]></description>
			<content:encoded><![CDATA[<p>I met with Digicel management a little while ago to do some research for my column, and they mentioned that they&#8217;d posted an advertisement for the position of Technical Operations Manager.</p>
<p>This is a senior technical position with the company, with significant responsibility.</p>
<p><a href="http://vitus.org.vu/files/2008/08/technical-manager-digicel.pdf">You can get a copy of the job description here</a>.</p>
<p>Contact Douglas Creevey, CTO of Digicel Vanuatu, for further information:</p>
<p><strong>PMB 9103, Ellouk Plateau, Port Vila, Vanuatu </strong></p>
<p><strong>Mob +(678) 555 5008 | Fax +(678) 27865 </strong></p>
<p><em>This advertisement is offered as a public service. All employers seeking skilled technical staff and/or management are encouraged to contact VITUS. We will be happy to offer whatever assistance we can.<br />
</em></p>
]]></content:encoded>
			<wfw:commentRss>http://vitus.org.vu/2008/08/20/digicel-seek-technical-operations-manager-vanuatu/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Network Security</title>
		<link>http://vitus.org.vu/2008/08/11/network-security/</link>
		<comments>http://vitus.org.vu/2008/08/11/network-security/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 07:29:49 +0000</pubDate>
		<dc:creator>jtoara</dc:creator>
		
		<category><![CDATA[Networking]]></category>

		<category><![CDATA[Network]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://vitus.org.vu/?p=9</guid>
		<description><![CDATA[This online document was authored by IT professionals in Vanuatu at the IT Best Practices Works, held June 24 2005 at the Freswota Computer Resource Center (CRC) 

Attendees/Authors:
Dan McGarry 
Ken Henjo (VIT) 
Tom Nako (VIT) 
Jack Nato (CRC Staff) 
George Keithson (CRC Staff) 
Simon Hilton (AYA - Vanuatu Financial Service Commission) 
Noeline Bule (Save the [...]]]></description>
			<content:encoded><![CDATA[<p><span>This online document was authored by IT professionals in Vanuatu at the IT Best Practices Works, held June 24 2005 at the Freswota Computer Resource Center (CRC) </span></p>
<p><span id="more-9"></span></p>
<p>Attendees/Authors:</p>
<p class="MsoNormal"><span>Dan McGarry </span></p>
<p class="MsoNormal"><span>Ken Henjo (VIT) </span></p>
<p class="MsoNormal"><span>Tom Nako (VIT) </span></p>
<p class="MsoNormal"><span>Jack Nato (CRC Staff) </span></p>
<p class="MsoNormal"><span>George Keithson (CRC Staff) </span></p>
<p class="MsoNormal"><span>Simon Hilton (AYA - Vanuatu Financial Service Commission) </span></p>
<p class="MsoNormal"><span>Noeline Bule (Save the Children) </span></p>
<p class="MsoNormal"><span>Andrew Moli (Vanuatu Financial Service Commission) </span></p>
<p class="MsoNormal"><span>George Petro (Wan Smolbag) </span></p>
<p class="MsoNormal"><span>Marianne Berukilukilu (Laho Ltd.) </span></p>
<p class="MsoNormal"><span>Craine (CRC Staff) </span></p>
<p class="MsoNormal"><span>Dan Ken Hinge (Habitat for Humanity Vanuatu) </span></p>
<p class="MsoNormal"><span>David Otto (Customs) </span></p>
<p class="MsoNormal"><span>Alex Nganga (National Bank of Vanuatu) </span></p>
<p class="MsoNormal"><span>Jackson Miake (National Bank of Vanuatu) </span></p>
<p class="MsoNormal"><span>THE Vignetenator (?) </span></p>
<h2>What is security?</h2>
<p class="MsoNormal"><span>* Protection against unauthorised access </span></p>
<p class="MsoNormal"><span>* This includes access to <strong>all</strong> important information (including documents, email, databases etc.) </span></p>
<p class="MsoNormal"><span>* This includes protection against internal and external threats </span></p>
<p class="MsoNormal"><span>* Threats can come from a number of places: Environment, Automated threats (like viruses, trojans, spyware), Direct human threats (hacking/cracking), </span></p>
<p class="MsoNormal"><span>* Ensuring a safe computing environment includes making sure that equipment is not likely to fail, or if it is, a plan exists to ensure that data is lost. This is known as Fault Tolerance. </span></p>
<p class="MsoNormal"><span>* <strong>Security is a (wholistic) process</strong> </span></p>
<h2>Who is responsible for security?</h2>
<ul type="disc">
<li class="MsoNormal"><span>Everyone      is responsible for security. Everybody needs to understand their role in      ensuring security. This includes backups, system maintenance, information      management and site security. All the good planning in the world doesn&#8217;t      help if the cleaner pulls the server&#8217;s plug out to run the vacuum! </span></li>
</ul>
<h2>How do we approach security?</h2>
<p>Security needs to be approached methodically, but it requires a wholistic view. It&#8217;s not safe, for example, to decide on an anti-virus software package in isolation. Does it work with the firewall? Is it easy to use? What are the staff training requirements?</p>
<h2>Reference Materials</h2>
<p class="MsoNormal"><span>The best way to stay secure is to stay informed. Here are a few sites that offer useful information on computer-related security issues. </span></p>
<ul type="disc">
<li class="MsoNormal"><span><a href="http://slashdot.org/">http://slashdot.org/</a> - Lots of talk and      analysis on all kinds of tech-related news </span></li>
<li class="MsoNormal"><span><a href="http://isc.sans.org/">http://isc.sans.org/</a> - The Internet Storm      Center is one of the best sources of breaking news on new Internet-based      security threats. </span></li>
<li class="MsoNormal"><span><a href="http://www.securityfocus.com/">http://www.securityfocus.com/</a> -      Home of the bugtraq mailing list, this is often the first place where important      security issues are reported. </span></li>
<li class="MsoNormal"><span><a href="http://www.ntbugtraq.com/">http://www.ntbugtraq.com/</a> - A bugtraq      devoted entirely to Windows exploits. </span></li>
<li class="MsoNormal"><span><a href="http://www.cert.org/">http://www.cert.org/</a> - Home of the      Computer Emergency Response Team, this website is a compendium of      important security-related information. Recently, they&#8217;ve been rather slow      to issue reports, however. They&#8217;ve become better known as a source of      vendor-specific information about existing exploits. </span></li>
</ul>
<h2>Network Security</h2>
<p class="MsoNormal"><span>This section deals with network-specific security issues. It covers both the physical and logical aspects of network configuration. </span></p>
<h3><span>Threats</span></h3>
<ul type="disc">
<li class="MsoNormal"><strong><span>Planning</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Poor planning can cause significant problems in implementation. This is especially true in terms of the logical layout of a network. Sometimes, planners don&#8217;t anticipate ways in which the network could be breached or abused. For example, a decent firewall might not stop someone from connecting a modem to their computer and gaining access to the Internet through it. USB drives and CDs are also vectors that is often forgotten when looking at information flow. </span></p>
<p class="MsoNormal"><span>Planning requires research and consultation. The Internet community (and VIGNET!) can be very valuable in helping to anticipate problems and take advantage of features that you might not have been aware of. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Unauthorised      access</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Access levels can cause problems if they&#8217;re not set properly. See also comments below on understanding and formulating a Trust Model </span></p>
<p class="MsoNormal"><span>File systems have permissions that can be set. This needs to be done very carefully, as it can block people from accessing resources that they need, as well. Through testing is critical in this regard. </span></p>
<p class="MsoNormal"><span>Folders and files should also be organised carefully. Unless you are a single user on an unconnected computer, My Documents is probably <strong>&#8216;not</strong>&#8216; the best place to store your files. Input is required from management and staff to create a proper file and folder structure. </span></p>
<p class="MsoNormal"><span>Users should be organised into groups, and permissions assigned on the group level. This is very important. Managing individual user accounts is time-consuming, prone to error, and can result in problems accessing critical information. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Viruses,      Spyware, Spam, Trojan Horses (Malware)</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>External mail and net-based sources of damage, unauthorised access and abuse of computer infrastructure. </span></p>
<p class="MsoNormal"><span>Words of Wisdom: <strong>There Ain&#8217;t No Such Thing As A Free Lunch</strong> Educate your users that if something looks too good to be true, it probably is. </span></p>
<p class="MsoNormal"><span>Consider a policy which does not allow <strong>&#8216;anyone</strong>&#8216; to install software from the Internet, unless it&#8217;s been checked by and approved IT staff and management. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Standards-compliance</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Sometimes people make decisions based on features or performance, without considering whether the product they have chosen conforms to accepted standards. This can cause problems with interoperability - that is, the ability of different systems to communicate effectively and efficiently. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Fault      tolerance</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Choosing reliable, standards-compliant equipment to protect against and hardware and software failure. </span></p>
<p class="MsoNormal"><span>It would be good if VIGNET users could compile a list of reliable hardware products available in Vanuatu. </span></p>
<h3><span>Network Security Measures</span></h3>
<ul type="disc">
<li class="MsoNormal"><strong><span>Planning</span></strong><span> </span></li>
<li class="MsoNormal"><strong><span>Consistent      and Workable Network Topology</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Networks have two aspects: the <strong>physical</strong> collection of wires, devices and computers that connect computers together, and the <strong>logical</strong> collection of pathways and storage points where information flows. We therefore refer to physical and logical network topologies. Both must be designed together - it&#8217;s important to understand how the one affects the other. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Network      Acceptable Use Policy</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>As far as we know, there&#8217;s no AUP in use anywhere in Vanuatu (with the possible exception of the TVL client agreement). VIGNET should consider drafting one example for its members. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Security      Software Tools</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Being able to view and interact with the network is a critical ability for systems admins. We&#8217;ll update this section with a list of useful tools and links in the future. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Physical      Network Security</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>If you can, put critical network apparatus into a locked &#8216;box&#8217;, off the ground and out of the way. It can save innumerable headaches. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Systems      and hardware backup</span></strong><span> </span></li>
<li class="MsoNormal"><strong><span>Maintenance      and Repair</span></strong><span> </span></li>
</ul>
<h2>Software Security</h2>
<h3><span>Threats</span></h3>
<ul type="disc">
<li class="MsoNormal"><strong><span>Pirate      software</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Only install software from trusted sources. This is a particular challenge here in Vanuatu where licensed software is hard to find and pay for. VIGNET should consider helping to build and maintain a trusted software &#8216;library&#8217;. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Unpatched/insecure      software</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Software that starts secure often becomes insecure with time. It&#8217;s important to remain up-to-date with patches and fixes. </span></p>
<p class="MsoNormal"><span>Some software needs to be updated regularly. It&#8217;s not enough to simply install anti-virus and/or anti-spyware software. You must keep it up-to-date. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Restricted      software</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Some software can be a powerful systems admin tool and a threat at the same time. It depends on who is running it and for what reason. Access control is important. In Linux and Unix, this is accomplished by storing certain program files in areas that are not accessible to all users. In Windows, access rights are defined on a file-by-file basis using the security tab accessed through the context menu. Right-click on the program file itself, choose properties, then click on the security tab. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Buggy      Software</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Software needs to be tested before it&#8217;s deployed. Small problem can become big ones when they happen often, or damage valuable data. </span></p>
<p class="MsoNormal"><span>Buggy software that has access to the Internet is especially dangerous. Examine your web browser, email client, music player, chat software and anything else that gets access to the Internet. If it&#8217;s a vector for viruses or exploits, consider choosing another one. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Malicious      Software</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Some kinds of malware (especially spyware) often pretends to be nice, or funny or sexy. It&#8217;s not. Users need to be educated about the dangers of running software. Consider insisting that users log in to accounts that do not have the right to install software at all. </span></p>
<p class="MsoNormal"><span>See also Network security above. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Bloatware      (software that is too resource-intensive)</span></strong><span> </span></li>
</ul>
<h3><span>Software Opportunities</span></h3>
<ul type="disc">
<li class="MsoNormal"><strong><span>Security      Software</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Software firewalls, anti-virus, encryption tools all enhance data security. </span></p>
<p class="MsoNormal"><span>We should include a list of software that VIGNET users have found useful and reliable here in Vanuatu. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Efficiency      - Automation Tools</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>The single biggest benefit of software is its ability to automate processes that would otherwise be time-consuming and expensive. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Information      Management Tools</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Properly organised information gives greater efficiency than a new processor, a bigger hard disk or a more power server. The tools that we use to manage our information need to be well understood. </span></p>
<p>(Joseph Toara is running an iManage workshop tomorrow (Monday 27 June 2005) Hopefully he will add some useful information about the software here. In the mean time, you can check out <a href="http://www.imanage.com/">http://www.imanage.com</a>)</p>
<p><strong>Note that where software is concerned, there is a direct relationship between ease-of-use and security. There are some things which should *not* be easy to use - or at least not easily accessible. In software, one person&#8217;s opportunity is another person&#8217;s threat.</strong></p>
<h2>Human Security</h2>
<h3><span>Threats</span></h3>
<ul type="disc">
<li class="MsoNormal"><strong><span>Physical      Threats</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>People can steal or damage unprotected computers and devices - especially laptops! Access needs to be balanced with physical security. </span></p>
<p class="MsoNormal"><span>Consider creating a secure space for storing laptops, external CD drives, backup disks/tapes, projectors etc. </span></p>
<p class="MsoNormal"><span>Also, store at least one backup <strong>offsite</strong>. Remember: Data that doesn&#8217;t exist in two places&#8230; doesn&#8217;t exist. </span></p>
<p class="MsoNormal"><span>Remember that physical threats include environment as well. Ask yourself, will my equipment be damaged by earthquake, cyclone, volcano? How about rats? You may laugh, but consider this: </span></p>
<p><a href="http://slashdot.org/article.pl?sid=05/06/24/0249231&amp;tid=95&amp;tid=133">http://slashdot.org/article.pl?sid=05/06/24/0249231&amp;tid=95&amp;tid=133</a> - Rats &#8216;Cripple&#8217; NZ Web Access</p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Hacking/Cracking</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Many of the major incidents related to network security are caused by &#8216;inside jobs&#8217; - that is, staff and/or people with physical access to computer systems are responsible for security-related incidents. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Carelessness</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Failures have been caused by things as simple as pressing the wrong button. It sounds amusing, until it happens to you. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Computer      Literacy</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Ignorance of how computers and networks work can often cause significant problems. </span></p>
<h3><span>Opportunities</span></h3>
<ul type="disc">
<li class="MsoNormal"><strong><span>Create      a safe working environment for people and equipment</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Keep the place neat and orderly. It benefits both staff and equipment. </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Create      and enforce strong security policies</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>It&#8217;s not sufficient to write a password once. Passwords must be changed regularly, and they should be unique to each person. </span></p>
<p class="MsoNormal"><span>Consider using keys instead of passwords (i.e. PGP, SSH) </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Training</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Training is not a one-time event. Staff should conduct regular training as their work environment requires. </span></p>
<p class="MsoNormal"><span>If your organisation has full-time Internet access, consider using online training. There&#8217;s a ton of material available, and it&#8217;s there when you have time, so you don&#8217;t have to change your schedule or plan down-time just to use it. </span></p>
<p class="MsoNormal"><span>One good example: <a href="http://www.itrainonline.org/">http://www.itrainonline.org/</a> </span></p>
<ul type="disc">
<li class="MsoNormal"><strong><span>Trust      Model</span></strong><span> </span></li>
</ul>
<p class="MsoNormal"><span>Before any new system is put in place (no matter how small or simple) you should be able to clearly describe the trust model - that is: </span></p>
<p class="MsoNormal"><strong><span>&#8216;Who</span></strong><span>&#8216; has access to <strong>&#8216;What</strong>&#8216; data, at <strong>&#8216;What</strong>&#8216; times and for <strong>&#8216;What</strong> reasons. <strong>&#8216;How</strong>&#8216; will they access the data? </span></p>
<p class="MsoNormal"><span> </span></p>
<h2>Network Protocols</h2>
<ul type="disc">
<li class="MsoNormal"><strong><span>HTTP      and CGI Explained</span></strong><span> - <a href="http://www.garshol.priv.no/download/text/http-tut.html">http://www.garshol.priv.no/download/text/http-tut.html</a> </span></li>
</ul>
<p class="MsoNormal"><span>A clear, simple explanation of how web servers actually work. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://vitus.org.vu/2008/08/11/network-security/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Ultimate Boot CD for Windows</title>
		<link>http://vitus.org.vu/2008/07/29/the-ultimate-boot-cd-for-windows/</link>
		<comments>http://vitus.org.vu/2008/07/29/the-ultimate-boot-cd-for-windows/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 08:45:25 +0000</pubDate>
		<dc:creator>Daryl Moon</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[boot CD]]></category>

		<category><![CDATA[spyware]]></category>

		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://vitus.org.vu/?p=5</guid>
		<description><![CDATA[Ultimate Boot CD for Windows
This is one of the most useful tools I have come across in ages.  It has several main benefits:

As it is a write protected CD, nothing can infect it or comprimise it.
As you boot from the CD, any spyware or viruses on the hard disk do not run.
There are lots [...]]]></description>
			<content:encoded><![CDATA[<h1><strong>Ultimate Boot CD for Windows</strong></h1>
<p>This is one of the most useful tools I have come across in ages.  It has several main benefits:</p>
<ul>
<li>As it is a write protected CD, nothing can infect it or comprimise it.</li>
<li>As you boot from the CD, any spyware or viruses on the hard disk do not run.</li>
<li>There are lots of useful tools on the CD apart from some good antivirus and antispyware tools.</li>
<li>It uses the Windows PXE Environment (same as during the windows install stage before the first reboot) so it is easy and familiar to Windows users.</li>
<li>It supports network access (I&#8217;ve not had any luck with wireless but wired LAN connections work fine).</li>
<li>The network access allows you to connect to the Internet and upgrade the virus scanner and spyware tools.  It does this by creating a RAM disk (as drive B:) and can download new virus definitions to there.  Of course they get lost when you reboot.  I don&#8217;t use that method as I disconnect and clean the machine before it is allowed to connect to the Internet.</li>
</ul>
<p>Some of the disadvantages are:</p>
<ul>
<li>You cannot download a CD image (.iso file) of the Ultimate Boot CD for Windows.  You have to build it yourself because it contains files from your XP CD and MS wouldn&#8217;t like them being distributed.</li>
<li>Building the CD is a bit a hassle as it is a 230MB download and then a couple of hours to get to know how to build and configure it.  After that you have to upgrade each package (using the config option) and wait for each package to download it&#8217;s virus/spyware signatures.</li>
<li>Finally you get to build the package and at the end you have a .iso file that you can write to CD.  You can even chhose whether you save the .iso file to burn later or just burn direct to the CD.  I always save the .iso in case I want to make another copy later.</li>
<li>If you use it regularly (as I do) then you will probably want to run the updates every month and write a new CD.  This is the safest way to use it.</li>
</ul>
<p><em>Some of the other tools include:</em></p>
<ul>
<li>Disk partitioning tools</li>
<li>Disk imaging tools</li>
<li>Disk defrag tools</li>
<li>Disk testing/diagnostic tools</li>
<li>Secure disk wiping tools</li>
<li>Web browsers</li>
<li>Registry editing tools</li>
<li>Network tools - sniffers/scanners etc</li>
<li>Password tools</li>
<li>Benchmarking tools</li>
<li>etc</li>
</ul>
<p><strong>Where can I download it?</strong></p>
<ul>
<li><a href="http://www.ubcd4win.com/">http://www.ubcd4win.com/</a></li>
</ul>
<p><span style="color: #ff0000"><em>If enough people are interested then I may be able to run a short workshop one afternoon and demonstrate how to use it.  email me at: <a href="mailto:daryl@datec.com.vu">daryl@datec.com.vu</a> if you are interested.</em></span></p>
]]></content:encoded>
			<wfw:commentRss>http://vitus.org.vu/2008/07/29/the-ultimate-boot-cd-for-windows/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
