<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Reliable Networks</title>
	<atom:link href="http://www.reliablenetworks.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.reliablenetworks.com</link>
	<description>Things we have learned we thought would be helpful to others.</description>
	<lastBuildDate>Fri, 18 May 2012 19:18:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Client Update &#8211; Ch&#8230; Ch&#8230; Ch&#8230; Changes</title>
		<link>http://www.reliablenetworks.com/security/client-update-ch-ch-ch/</link>
		<comments>http://www.reliablenetworks.com/security/client-update-ch-ch-ch/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 15:26:01 +0000</pubDate>
		<dc:creator>L. Mark Stone</dc:creator>
				<category><![CDATA[Productivity]]></category>
		<category><![CDATA[Reliable Networks News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1683</guid>
		<description><![CDATA[Reliable Networks was born nine years ago as a vision of what, as a then CIO of a global corporate trading company, would comprise my ideal technology managed services provider. Over that time, as technology has changed, so has the makeup of our clients – but not what we accomplish for them. David Bowie&#8217;s song [...]]]></description>
			<content:encoded><![CDATA[<p>Reliable Networks was born nine years ago as a vision of what, as a then CIO of a global corporate trading company, would comprise my ideal technology managed services provider.</p>
<p>Over that time, as technology has changed, so has the makeup of our clients – but not what we accomplish for them. David Bowie&#8217;s song &#8220;Changes&#8221; instructs: <em>&#8220;Turn and face the strange&#8230; Changes.&#8221;</em> Certainly that is apt advice for our clients trying to maximize benefits from their technology investments.</p>
<p>So I thought it would be helpful to let everyone know some interesting news and recap a few core principles that comprise who we are and how we spend our days in this strange world of technology.</p>
<p><span style="color: #ff6600; font-size: small;"><strong>Core Values</strong></span><br />
The most important thing to us is our clients, who:</p>
<ol>
<li>Are smart. Wicked smart. So smart they force us to be our best every day.</li>
<li>Have as a core value leveraging technology to improve communication and collaboration between employees, customers, vendors, community, politicians, etc. – everyone whom they “touch” to get business done.</li>
<li>May, or may not (nor care to) understand all the technical bits of a particular solution, but require us to know our stuff and be free from conflict in recommending and implementing solutions – which is why we do not act as a reseller.</li>
<li>Demand an open, constructive dialog with their technology consultant and managed services provider to collaboratively architect, deploy, maintain and eventually life cycle mission-critical core systems on which the health of the business depends. One client called us the “<em>…constructive thorn in our side.</em>”. High praise that confirms we are successful in helping our clients obtain an appropriate balance between the sometimes-conflicting arts of business-expedient and technical-grace.</li>
</ol>
<p>Most of our newer clients (increasingly who are out-of-state) now rely on us for our private cloud expertise to architect, deploy and in many cases host their mission-critical applications. Whether that application be email-based (Zimbra or Exchange), an EHR/EMR, LAMP stack, database, image-rendering, ERP, accounting, or whatever, we have found that each application has its own peculiarities but a significant amount of commonality with others. Our trademarked <em>&#8220;Uptime. All the time.&#8221;</em>® is the standard our clients require and what we strive to provide.</p>
<p>Supporting mission-critical applications alone is hard; providing a first-class private cloud in which to host them is harder. We deployed our own private cloud last summer after first trying to outsource hosting to a separate private cloud provider – and finding no vendor who met our standards. And that gets us to some interesting news:</p>
<p><span style="font-size: small;"><strong><span style="color: #ff6600;">News</span></strong></span><br />
<strong>New SAN Storage.</strong> Already we are about to outgrow our private cloud’s SAN storage infrastructure (about a year sooner than our optimistic forecast) and will be placing an order for new storage within the week. We have also added to the compute head side of the farm three times since going live last summer.</p>
<p><strong>New Certification.</strong> Increasingly we find we are sought out by companies in regulated industries for whom an SSAE16 SOC 2 Type II is mandatory. Last year we successfully completed a third-party HIPAA/HITECH Act review and this year we engaged Moody, Famiglietti and Andronico, LLP in Massachusetts to help us get our SOC2 Type II report before the end of this year. We have been following ITIL processes for some time, so we have had no surprises getting ready for the actual SSAE16 audit.</p>
<p><strong>New Insurance.</strong> We have had $2.0 million of technology errors and omissions insurance for some years now, but we recently doubled our aggregate commercial general liability to $4.0 million to better meet the needs of some of our newer clients.</p>
<p><strong>New Offices.</strong> To provide room for our continued, albeit carefully measured, expansion, we will be moving offices early this summer and are evaluating our options currently.</p>
<p><span style="font-size: small;"><strong><span style="color: #ff6600;">Client Impacts</span></strong></span><br />
Hardly any. Other than an address change, we expect all of the above news items will help us to continue to provide the exceptional standard of work we demand of ourselves and which our clients demand of us.</p>
<p><span style="font-size: small; color: #ff6600;"><strong>The Future</strong></span><br />
For the majority of our clients, a near or fully virtualized SAN-backed application hosting environment deployed on premises or in a private cloud is the common theme. Consider the benefits:</p>
<ol>
<li>Desktop security concerns and support costs go down significantly when Desktops are virtualized.</li>
<li>Server maintenance is simplified, and patch testing risk, backup, disaster recovery and business continuity costs are reduced.</li>
<li>Storage management is similarly simplified and total storage costs reduced (over DASD).</li>
<li>Application and platform migrations (e.g. Exchange 2003 on Windows Server 2003 to Exchange 2010 on Windows Server 2008) are similarly simplified and costs reduced.</li>
</ol>
<p>In the same way that electronic medical records have created new kinds of medical errors, getting your applications properly hosted either in a private cloud or on premises in a SAN-backed virtualized infrastructure creates new kinds of exposures. By way of example, your virtualized server may move all by itself across physical hosts. Strange? Sure (thank you Mr. Bowie). And boy does it ever change your disaster recovery plans.</p>
<p>That’s where we can help. To learn more, give us a call (our phone number is not changing!) at (207) 772-5678.</p>
<p>All the best,<br />
Mark<br />
CIO</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/security/client-update-ch-ch-ch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SuSE Linux Enterpise Server 11 Service Pack 2 &#8211; Caution!</title>
		<link>http://www.reliablenetworks.com/uncategorized/suse-linux-enterpise-server-11-service-pack-2-caution/</link>
		<comments>http://www.reliablenetworks.com/uncategorized/suse-linux-enterpise-server-11-service-pack-2-caution/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 16:32:59 +0000</pubDate>
		<dc:creator>L. Mark Stone</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1671</guid>
		<description><![CDATA[Client Advisory Recently, Novell released the latest Service Pack (SP2) for SuSE Linux Enterprise Server 11. We urge great caution before upgrading your existing production SLES servers to this new Service Pack. &#160; Background Under SLES 9 and 10, it was very safe to apply newly released Service Packs to production systems.  SLES 11 however [...]]]></description>
			<content:encoded><![CDATA[<h3>Client Advisory</h3>
<p>Recently, Novell released the latest Service Pack (SP2) for SuSE Linux Enterprise Server 11. We urge great caution before upgrading your existing production SLES servers to this new Service Pack.</p>
<p>&nbsp;</p>
<h3>Background</h3>
<p>Under SLES 9 and 10, it was very safe to apply newly released Service Packs to production systems.  SLES 11 however broke with that trend (twice now) in a fairly major way.</p>
<p>SLES 11 SP1 introduced a new version of glibc (a major system library) that caused havoc for developers. Take <a title="Zimbra" href="http://www.zimbra.com/partners/zimbra_hosting.html" target="_blank">Zimbra</a> for example (we are a Zimbra hosting partner&#8230;); up to certain versions, Zimbra would run on SLES 11 only, but not on SP1.  After a certain Zimbra version, Zimbra would not run on SLES 11, just SLES 11 SP1. Ugh.</p>
<p>SLES 11 SP2 now introduces the 3.0 Linux kernel; historically SuSE <strong><em>never</em></strong> upgraded the major kernel version during the lifetime of a SLES product, though it did backport bug fixes and security updates from later kernel versions. This backporting of features, fixes and security patches provided the best of both worlds &#8211; a really stable enterprise Linux platform with a secure kernel containing modern features.  Indeed, IBM&#8217;s Linux distro of choice for Linux virtualized on their mainframes is SLES; RedHat is relegated primarily to lower-end x86 platforms by IBM.</p>
<p>&nbsp;</p>
<h3>Developers Won&#8217;t Support It Now</h3>
<p>We asked Zimbra what their plans were for supporting SLES 11 SP2 and were told that they will start supporting SP2 only on Zimbra 8, due to be released later this year.  In other words, <strong>don&#8217;t upgrade SLES 11 to SP2 on any existing Zimbra system.</strong></p>
<p>&nbsp;</p>
<h3>Now What?</h3>
<p>What happens if Zimbra delays the release of version 8 past the date that Novell provides fixes for SP1?  The short answer is we are stuck with a system which could contain security exposures and bugs at the operating system level.</p>
<p>Our Novell licensing is up for renewal this Summer. We have been testing Ubuntu Server LTS and will make a decision later as to whether to abandon SLES.  To date, we find administration takes longer with Ubuntu (and Red Hat too) because there is nothing comparable to SUSE&#8217;s YaST (Yet Another System [management] Tool) in any other distro.  And once you &#8220;get&#8221; YaST&#8217;s peculiarities, it is incredibly efficient and keeps the entire OS in a highly consistent state.</p>
<p>In the interim, before you upgrade your SLES 11 system to SP2, talk to your application developers and make sure their application has been tested on SP2.</p>
<p>Take care,<br />
Mark<br />
CIO</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/uncategorized/suse-linux-enterpise-server-11-service-pack-2-caution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zimbra vs. Dropbox and Evernote; Security and Privacy Policies</title>
		<link>http://www.reliablenetworks.com/security/zimbra-dropbox/</link>
		<comments>http://www.reliablenetworks.com/security/zimbra-dropbox/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 15:09:24 +0000</pubDate>
		<dc:creator>L. Mark Stone</dc:creator>
				<category><![CDATA[Productivity]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud Storage]]></category>
		<category><![CDATA[Cyberduck]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Dropbox]]></category>
		<category><![CDATA[Evernote]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[WebDAV]]></category>
		<category><![CDATA[Zimbra]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1654</guid>
		<description><![CDATA[Challenges: Ease of Use vs. Security Dropbox and Evernote are very easy to use and have enjoyed fairly broad market adoption. Two issues we have with Dropbox are their security (all customer files were left open for several hours in Summer 2011 for anyone to see) and their Privacy Policy, which enables Dropbox to share [...]]]></description>
			<content:encoded><![CDATA[<h3>Challenges: Ease of Use vs. Security</h3>
<p>Dropbox and Evernote are very easy to use and have enjoyed fairly broad market adoption.</p>
<p>Two issues we have with Dropbox are their security (<a title="Dropbox Security Breach" href="http://www.informationweek.com/news/security/vulnerabilities/231000111" target="_blank">all customer files were left open for several hours in Summer 2011 for anyone to see</a>) and their Privacy Policy, which enables Dropbox to share your files with third-parties who provide support services to Dropbox.</p>
<p>Evernote&#8217;s Terms of Service have you granting Evernote a license to all of your Content that you post there. Similar to Dropbox, Evernote&#8217;s Privacy Policy also allows them to share your data with third parties. Worse, Evernote will drop cookies and tracking pixels on your devices.</p>
<p>For corporations in regulated industries (e.g. healthcare, financial services), employees who use such services for data covered by, say, HIPAA, may have created a defacto violation &#8211; Neither Dropbox nor Evernote to our knowledge execute Business Associate Agreements.</p>
<p>In unregulated industries, much corporate data is highly sensitive, so why would you want to allow a service provider to share it with third parties?</p>
<h3>Solution: Zimbra Briefcase and CyberDuck</h3>
<p>Zimbra already has a robust file-sharing, Google Docs-like offering in the form of the Briefcase. Until Zimbra releases Project Octupus in version 8, what is lacking in Zimbra now is the ability to synchronize easily the files in your Zimbra Briefcase with the files on your computer.</p>
<p>That functionality however is easily provided by a handy utility called Cyberduck, available for download at <a title="Cyberduck Home Page" href="http://cyberduck.ch/" target="_blank">http://cyberduck.ch/</a>. Historically, Cyberduck (and Filezilla, another favorite tool of ours) have been used for FTP transfers. As insecure plain-text FTP gave way to FTPS and SFTP, both Filezilla and Cyberduck expanded the number of transfer protocols supported.</p>
<p>But Cyberduck didn&#8217;t stop there. They saw that the future was in Cloud Storage, so they added even more secure transfer protocols to enable users to transfer files to Amazon S3 and indeed any storage repository which supports WebDAV over http &#8212; like Zimbra&#8217;s Briefcase.</p>
<p>So what we do ourselves and have configured for clients needing this functionality but are concerned about Dropbox&#8217;s past data breach history and Evernote&#8217;s content licensing, is to configure Cyberduck to talk directly to Zimbra&#8217;s Briefcase. Cyberduck you see, does Remote-Local Syncing of whole folders trees, so it&#8217;s a snap to keep your Zimbra Briefcase and your computer repositories in sync.</p>
<p>In the screenshot below, you can see in the upper right the Cyberduck window, looking at my Zimbra Briefcase.  In the upper left is the normal Zimbra web interface.  In the lower left is a local folder on my Mac, and in the lower right is the Cyberduck sync windoready to sync all of my Briefcase folders.</p>
<p><img class="aligncenter" style="vertical-align: middle;" title="Zimbra Briefcase Sync" src="http://www.reliablenetworks.com/wp-content/uploads/2012/02/Zimbra_Cyberduck_Briefcase_Sync1.png" alt="Zimbra Briefcase Sync" width="1024" height="640" /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The sync process to be fair takes two mouse clicks; you have to remember to actually do it.  But if you need to keep all your corporate documents on your corporate Zimbra system and your corporate laptops, the combination of Zimbra and Cyberduck is a win-win until Zimbra&#8217;s Project Octopus comes along later this year.</p>
<p>Hope that helps,</p>
<p>Mark</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/security/zimbra-dropbox/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Zoho Cloud Down Due To Power Outage at Equinix SV4 Data Center</title>
		<link>http://www.reliablenetworks.com/uncategorized/zoho-cloud-due-power-outage-equinix-sv4-data-center/</link>
		<comments>http://www.reliablenetworks.com/uncategorized/zoho-cloud-due-power-outage-equinix-sv4-data-center/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 20:54:53 +0000</pubDate>
		<dc:creator>L. Mark Stone</dc:creator>
				<category><![CDATA[Technology News]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1639</guid>
		<description><![CDATA[Earlier today Zoho, a leading cloud services provider whose CRM solution is known as a solid competitor to Salesforce.com, went off the air.  The root cause it turns out was a power outage at their colocation provider&#8217;s data center.  Their colo provider, Equinix, is considered to be a top-tier provider, and while power at the [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier today Zoho, a leading cloud services provider whose CRM solution is known as a solid competitor to Salesforce.com, went off the air.  The root cause it turns out was a power outage at their colocation provider&#8217;s data center.  Their colo provider, Equinix, is considered to be a top-tier provider, and while power at the data center has been restored, Zoho is still down hours later trying to fix all the data corruption from what was effectively pulling the power cords out of the back of the servers while the servers were still running.</p>
<p>Now, Zoho has several million users, including us, so fixing data corruption of that magnitude is not like letting Windows chkdsk just run for a few minutes after the server is rebooted. We&#8217;ll have to wait to see what the final outcome is, and for how long Zoho CRM (and SugarCRM and another 214 customers Equinix claims to host at that data center) remain down.</p>
<p>We suffered the same fate a few years ago at our former colocation host.  That and other issues caused us to move to a new colocation facility.  What happened at our former colocation host was that there was a power outage, the data center UPS (uninterruptible power supply) kicked in, and the system waited for the generator to start.  Only the generator didn&#8217;t start, and the UPS system had only a few minutes of juice in their batteries, so every server in the data center crashed, quite hard.  Fortunately, we had plans in place so we were able to recover quickly.</p>
<p>When we did a new colocation facility bakeoff, one of the detailed questions we asked was what happens if the power goes out and the generator fails to start?  Most data centers told us things like &#8220;We test the generator weekly! That won&#8217;t happen!&#8221; (which is what our former data center provider told us as well). Well, guess what?  You-know-what does happen periodically.</p>
<p>At the end of the day, we chose BayRing Communications, a New Hampshire-based phone company with two data centers at the old Pease Air Force base.  When we asked that same question of them, they laughed, literally, and said that in their experience gear fails all the time and so one needs to be prepared.  In their case, they bought a <em><strong>lot</strong></em> of batteries for their UPSs. When the power goes out, their UPS can run everything for several hours &#8211; plenty of time to either fix the generator or get a portable generator trucked in and hooked up.  They reminded us that, as a phone company, they get in big trouble if things like 911 don&#8217;t work for any length of time.</p>
<p>Indeed, at the end of the due diligence, we understood in more intimate detail what &#8220;carrier-grade&#8221; really means. And why, if you are running your own and hosting your clients&#8217; mission-critical applications (like electronic health records, and email for regulated companies for example), &#8220;carrier-grade&#8221; has to be the minimum standard.</p>
<p>Does that cost more? More than some and less than others.</p>
<p>Will we survive without access to our CRM application through Zoho for a few hours? Sure. For a few days would be a real problem though.</p>
<p>At the end of the day, the takeaway here is that, whether you are taking care of a few dozen customers or a few million, when you choose a data center provider you really need to do your due diligence carefully.  Something clearly went horribly wrong at Equinix, and as of this writing, though power has been restored for a few hours, they haven&#8217;t disclosed the root cause.  We&#8217;ll have to wait and see&#8230;</p>
<p>If you have mission-critical applications and you have concerns about their hosting, we&#8217;d be happy to help you through a due diligence process that we organized for ourselves and our clients who host with us. Just give us a call at (207) 772-5678.</p>
<p>Mark</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/uncategorized/zoho-cloud-due-power-outage-equinix-sv4-data-center/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Windows Malware &#8211; Five Easy Pieces</title>
		<link>http://www.reliablenetworks.com/uncategorized/windows-malware-easy-pieces/</link>
		<comments>http://www.reliablenetworks.com/uncategorized/windows-malware-easy-pieces/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 14:33:51 +0000</pubDate>
		<dc:creator>L. Mark Stone</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1616</guid>
		<description><![CDATA[We recently came a cross an interesting study released by international security firm CSIS, which concludes that &#8220;&#8230;as much as 99.8 % of all virus/malware infections caused by commercial exploit kits are a direct result of the lack of updating five specific software packages.&#8221; According to CSIS, &#8220;Up to 85 % of all virus infections [...]]]></description>
			<content:encoded><![CDATA[<p>We recently came a cross an interesting study released by international security firm CSIS, which concludes that &#8220;&#8230;as much as 99.8 % of all virus/malware infections caused by commercial exploit kits are a direct result of the lack of updating five specific software packages.&#8221;</p>
<p>According to CSIS, &#8220;Up to 85 % of all virus infections occur as a result of drive-by attacks automated via commercial exploit kits.&#8221;</p>
<p>Commercial exploit kits are used both by the Bad Guys as well as by legitimate security shops to perform penetration testing, security scans and other tests appropriate for regulated companies and unregulated companies with valuable intellectual property to protect. Like guns, how these tools are used is up to the person with their finger on the trigger.</p>
<p>We have always known that patching your systems is very important.  Unfortunately, even though Windows Update now patches Office and other Microsoft software in addition to the Windows operating system itself, that&#8217;s not enough.  And now CSIS has the facts to prove it.</p>
<p>The five software packages that accounted for that 99.8% of all infections as reported by CSIS comprise:</p>
<ol>
<li>Java JRE (which includes the browser plugin)</li>
<li>Adobe Reader</li>
<li>Adobe Acrobat</li>
<li>Adobe Flash and,</li>
<li>Microsoft Internet Explorer</li>
</ol>
<p>While Internet Explorer gets patched via Windows Update, the other software packages have their own update system that prompts the user to update each software package individually.</p>
<p>Regrettably, in our experience way too many end-users ignore and click away those update warnings.  Further, in in more locked-down corporate environments, end-users often do not have sufficient rights to install software updates and patches; those updates and patches are pushed out to the end users&#8217; machines via centralized system management software.  When the company&#8217;s system administrators do not push those patches out promptly enough, or the end users click away and defer updating those packages, a significant exposure is created.</p>
<p>And once one machine on a network is infected, many more are often subsequently infected.</p>
<p>So what does this all mean?</p>
<p>Well, first&#8230; this report reaffirms the importance of prompt patching.  Second, it documents that of the five top exposures, only one of them (Internet Explorer) is patched via Windows Update, so just turning on Windows Auto Update and thinking you are protected is at best fatuous.</p>
<p>At the end of the day, a comprehensive patching process is required; the proper execution of which is someone&#8217;s key responsibility.</p>
<p>If you have concerns about your company&#8217;s patching processes, please give us a call (207) 615-1529.</p>
<p>Mark</p>
<p>CIO</p>
<p>P.S.  You can read a summary of the study <a href="http://www.csis.dk/en/csis/news/3321/" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/uncategorized/windows-malware-easy-pieces/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Computing &#8211; State of the Union</title>
		<link>http://www.reliablenetworks.com/uncategorized/cloud-computing-state-union/</link>
		<comments>http://www.reliablenetworks.com/uncategorized/cloud-computing-state-union/#comments</comments>
		<pubDate>Mon, 22 Aug 2011 14:53:40 +0000</pubDate>
		<dc:creator>L. Mark Stone</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1330</guid>
		<description><![CDATA[We recently reviewed a Cloud Computing survey published by Cloud.com and it got us thinking.  Cloud.com is in a terrific position to have their finger on the pulse of the overall market; they make platform-independent Cloud Management software that in one console can mange multiple cloud deployments deployed on Amazon, VMware, XenServer etc.  They were [...]]]></description>
			<content:encoded><![CDATA[<p>We recently reviewed a Cloud Computing survey published by Cloud.com and it got us thinking.  Cloud.com is in a terrific position to have their finger on the pulse of the overall market; they make platform-independent Cloud Management software that in one console can mange multiple cloud deployments deployed on Amazon, VMware, XenServer etc.  They were recently purchased by Citrix, who have a solid track record of supplying both Open Source and Proprietary software. (Most larger cloud stacks, like Amazon, are built on Citrix&#8217;s Open Source version of XenServer.)</p>
<p>The survey pointed out that workloads currently on clouds are comprised primarily of web sites, shared data storage,  backups and prototyping/sandbox.  Although most companies nowadays have adopted virtualization for line-of-business applications, the survey pointed out that very few of these of line-of-business have been migrated to the cloud.</p>
<p>At first, that struck me as odd since the greatest benefits of cloud computing come with cloud-ified (is that a word?) line-of-business applications.  And then the brick of realization hit me: Doh!  Most cloud environments aren&#8217;t ready to host line-of-business applications. Most line-of-business applications rely on high-performance databases (&#8220;fast disk I/O&#8221; in techno-speak), and most cloud providers have pretty slow disks &#8212; it&#8217;s how they keep prices down.</p>
<p>We ourselves spent eight months trying to get out of the hardware business, unsuccessfully.  Our Zimbra hosting farm hardware was approaching end-of-life, we had multiple clients who wanted to break the expensive cycle of premises-based hosting and so we had a raft of servers ready to be cloud hosted.</p>
<p>What we found was that the inexpensive cloud hosting providers&#8217; infrastructure had nowhere-near-fast-enough disk I/O, and even very expensive private cloud hosting providers (at least the ones we talked to at the time) with very fast disk I/O had one or more &#8220;gotchas&#8221; that precluded us from going with them.</p>
<p>There are a lot of moving parts to successful cloud hosting. Not only do you have to be an expert at virtualization and eliminating single points of failure cost-effectively, but you have to be cognizant that most security standards are only a starting point. The most difficult challenge in moving clients to the cloud however is education/politics.  Cloud computing done well often requires business process improvements.</p>
<p>And then the second Brick &#8216;O Realization hit us (this was starting to hurt) that we have been doing virtualization for regulated companies, educating senior management and managing staff&#8217;s expectations for years.</p>
<p>So, we built our own private cloud, for our hosted Zimbra farm and for our clients. Architected explicitly for those database-intensive line-of-business applications requiring fast I/O. With 24 x 7 x 365 human client service. And priced appropriately, which is to say higher than Amazon (but not by as much as you think) and less than dedicated server hosting from the majors.</p>
<p>One client who runs SAS for healthcare analytics tested our private cloud and found it ran jobs anywhere from four to 10 times faster than their current blend of physical and virtual server infrastructure. Our own Zimbra hosting farm runs noticeably faster as well (and we do not overload our mailbox servers with the maximum amount of mailboxes either).</p>
<p>So in a nutshell, we think the big upcoming wave in Cloud Computing is migrating mission-critical, database-dependent line-of-business applications to private cloud service providers who &#8220;get&#8221; security, regulated environments and who can be relied on to manage, carefully and successfully, what can too often be a difficult transition to cloud computing.</p>
<p>And that&#8217;s why, after we had a chance to think about it, the survey from Cloud.com made sense and validated the investment we made in, and position of, our own private cloud environment.</p>
<p>If you are as scared of cloud computing as we were, give us a call at (207) 772-5678. You might rightfully decide that cloud computing is not for your company, but you might find out some things you didn&#8217;t expect.</p>
<p>Safe computing,</p>
<p>Mark, CIO</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/uncategorized/cloud-computing-state-union/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reliable Networks Announces Private Cloud and Educational Series</title>
		<link>http://www.reliablenetworks.com/uncategorized/reliable-networks-announces-private-cloud-educational-series/</link>
		<comments>http://www.reliablenetworks.com/uncategorized/reliable-networks-announces-private-cloud-educational-series/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 17:24:06 +0000</pubDate>
		<dc:creator>Kristin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1289</guid>
		<description><![CDATA[Reliable Networks Announces Private Cloud and Educational Series Holiday Inn by the Bay – Wednesday, June 29th 5:00pm – 6:00pm &#160; PORTLAND, ME — June 13, 2011 — Reliable Networks, a network engineering and hosted services firm based in Portland, ME today announced its Private Cloud and Educational Series to help companies evaluate whether cloud [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.reliablenetworks.com/wp-content/uploads/2011/06/Clouds.jpg"><img class="alignleft size-thumbnail wp-image-1290" title="Clouds" src="http://www.reliablenetworks.com/wp-content/uploads/2011/06/Clouds-150x150.jpg" alt="" width="150" height="150" /></a>Reliable Networks Announces Private Cloud and Educational Series</strong></p>
<p><em>Holiday Inn by the Bay – Wednesday, June 29<sup>th</sup> 5:00pm – 6:00pm</em></p>
<p><em> </em></p>
<p>&nbsp;</p>
<p><strong>PORTLAND, ME — June 13, 2011</strong> — Reliable Networks, a network engineering and hosted services firm based in Portland, ME today announced its Private Cloud and Educational Series to help companies evaluate whether cloud hosting is at all appropriate for their business.</p>
<p>After nearly a decade of architecting and deploying private clouds for select clients, Reliable Networks has expanded the same successful formula to create the most secure and reliable cloud to hover over Maine.</p>
<p><strong>Public versus Private Clouds</strong></p>
<p>Outages and data breaches at large <em>public</em> cloud and service providers like Amazon EC2, Yahoo, Microsoft 360 and Gmail are reported with increasing frequency.  Niche private cloud providers like Reliable Networks however have been quietly providing secure, reliable services to clients for years.</p>
<p><strong>Appropriateness of Cloud Hosting</strong></p>
<p>Is the Cloud right for all businesses? Not necessarily. Businesses must evaluate whether cloud hosting is appropriate before even considering which type of cloud hosting is optimal, public, private, or hybrid. Reliable Networks has conducted a due diligence program to consider whether outsourcing this service would be in its clients’ best interests.  “Regrettably,” reports Reliable Networks President L. Mark Stone, “all of the private cloud providers we investigated had one or more areas of concern that made their offering inappropriate for our clients’ needs and for our own suite of hosted services.”</p>
<p><strong>Cloud Hosting Educational Series</strong></p>
<p>The temptation to move to the cloud is great, given the myraid benefits including cost savings, higher reliability and more efficient workflow processes.  “But as our own due diligence exposed, the road to Nirvana has a few IEDs buried along the shoulder.”  added Stone. “So we thought we should share the results of our cloud hosting due diligence with the community, to help others make better decisions about whether to, and if so, how to, host in the cloud.”</p>
<p>The first session in this Cloud Hosting Educational Series will be held on Wednesday, June 29<sup>th</sup> from  5:00pm to 6:00pm at the Holiday Inn By The Bay in Portland.  Pre-registration is required (no at-event signups can be admitted) at <a href="../events">www.reliablenetworks.com/events</a> and complimentary refreshments, sushi, beer and wine will be served.</p>
<p>&nbsp;</p>
<p><strong>For more information: </strong></p>
<p>Kristin Przybysz, (207) 772-5678, kristin@reliablenetworks.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/uncategorized/reliable-networks-announces-private-cloud-educational-series/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA SecureID Tokens Totally Compromised &#8211; All 40 Million Likely To Be Replaced</title>
		<link>http://www.reliablenetworks.com/security/rsa-secureid-tokens-totally-compromised-40-million-replaced/</link>
		<comments>http://www.reliablenetworks.com/security/rsa-secureid-tokens-totally-compromised-40-million-replaced/#comments</comments>
		<pubDate>Tue, 07 Jun 2011 13:51:16 +0000</pubDate>
		<dc:creator>L. Mark Stone</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology News]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1227</guid>
		<description><![CDATA[Yesterday the respected online news service Ars Technica and the Wall Street Journal reported what we had internally suspected for a while: that the March 2011 data breach at RSA has indeed rendered all of their SecureID tokens effectively useless. The articles point out that RSA will be replacing virtually all 40 million SecureID tokens [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday the respected online news service <a href="http://arstechnica.com/security/news/2011/06/rsa-finally-comes-clean-securid-is-compromised.ars" target="_blank">Ars Technica</a> and the <a href="http://online.wsj.com/article/SB10001424052702304906004576369990616694366.html?mod=djemalertTECH" target="_blank">Wall Street Journal</a> reported what we had internally suspected for a while: that the March 2011 data breach at RSA has indeed rendered all of their SecureID tokens effectively useless. The articles point out that <em><strong>RSA will be replacing virtually all 40 million SecureID tokens currently in circulation.</strong></em></p>
<p>Lockheed and Northrop the articles further point out have already suffered intrusion attempts, with Northrop reportedly going so far as to shut down all remote access.</p>
<p>It&#8217;s not just defense contractors, Sony, VMware, Amazon, Google, and the State of Texas who suffer data breaches increasingly measured in the millions of records. We see typically half a dozen or so very professional intrusion attempts every day on our home firewalls; our data center firewalls see about the same.</p>
<p>SecureID, combined with a personal password known only to the user creates what is called a &#8220;two-factor authentication&#8221; authorization scheme.  Described as &#8220;something you have, plus something you know&#8221;, it works just like an ATM card (something you have) with your PIN (something you know). The two-factor authentication provided (past tense&#8230;) by SecureID often lulls users into a false sense of security and the temptation to use weak passwords; how many of us have 10-digit ATM card passcodes?  I used to have an 8-digit passcode but found it didn&#8217;t work on about half of all store credit card swipe pinpads.  Not terrific security&#8230;</p>
<p>And what happens when we lose our ATM card?  We cancel the card and get a new PIN.  Well&#8230; RSA just &#8220;cancelled&#8221; some 40 million SecureID cards.</p>
<p>With our without SecureID or some other two-factor authentication scheme, there is no substitute for good, basic password policies. We recommend strongly that our clients adopt password complexity, reuse and rotation policies, at least as follows:</p>
<ol>
<li>Passwords should be a minimum of eight characters long and contain at least one each of:
<ol>
<li>Uppercase character</li>
<li>Lowercase character</li>
<li>Number</li>
<li>Punctuation mark or symbol (e.g. semi-colon, underscore, hyphen, parenthesis, etc.)</li>
</ol>
</li>
<li>Passwords should be changed no less frequently than every 120 days (one company we know requires weekly password changes)</li>
<li>Passwords should not contain dictionary words or derivatives, or be based on personal information like birth dates or anniversaries.</li>
<li>Passwords once used should not be able to be reused for at least a year.</li>
<li>Lastly, the log files need to be parsed routinely for intrusion attempts (this can be automated) and a human alerted ASAP when something looks wonky.</li>
</ol>
<p>&nbsp;</p>
<p>Consider the costs to a company when a user&#8217;s email password is compromised and a hacker starts using that account to send out thousands and thousands of spam emails.  In short order, the company&#8217;s email server becomes blacklisted, no one in the company can send email anywhere, and business comes to a grinding halt.  It can take a few days to get off all the blacklists, so we advise clients to consider the costs of a few days of email downtime against the complaints from a vocal few users who don&#8217;t like changing their passwords three times a year.  It&#8217;s all about tradeoffs and risk management at the end of the day.</p>
<p>If you would like an objective review of your company&#8217;s security, remote access, password and related policies, give us a call at (207) 772-5678.</p>
<p>Take care!</p>
<p>Mark</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/security/rsa-secureid-tokens-totally-compromised-40-million-replaced/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health Care Data Breach? Surprise! Your Insurance May Not Cover It.</title>
		<link>http://www.reliablenetworks.com/uncategorized/health-care-data-breach-surprise-insurance-cover/</link>
		<comments>http://www.reliablenetworks.com/uncategorized/health-care-data-breach-surprise-insurance-cover/#comments</comments>
		<pubDate>Wed, 30 Mar 2011 19:32:40 +0000</pubDate>
		<dc:creator>Kristin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cyber insurance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[insurance]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1052</guid>
		<description><![CDATA[Featured in this month&#8217;s MaineAhead Magazine is an article we wrote about the tragic risks and consequences associated with a data breach. Reliable Networks founder, L. Mark Stone, recounts a speaking engagement at an October health care conference, MIMS2010. Physicians there were alarmed to learn that neither general liability insurance nor malpractice insurance typically covers [...]]]></description>
			<content:encoded><![CDATA[<p>Featured in this month&#8217;s <a href="http://www.maineahead.com/j-doe-data-breach-denial/">MaineAhead Magazine is an article</a> we wrote about the tragic risks and consequences associated with a data breach. Reliable Networks founder, L. Mark Stone, recounts a speaking engagement at an October health care conference, <a href="http://www.mims2010.com/">MIMS2010</a>. Physicians there were alarmed to learn that neither general liability insurance nor malpractice insurance typically covers a medical data breach, even if they were HIPAA compliant at the time of the breach.</p>
<p>The reasons for this coverage gap are several:  First, property and casualty insurance policies are written to cover tangible items and data isn&#8217;t tangible. Medical malpractice insurance policies don&#8217;t consider a data breach a medical error and so don&#8217;t usually cover the costs from data breaches. Even General Liability policies rarely include data breaches in the specific list of liabilities covered.</p>
<p>Worse, breaches are expensive! The estimated cost for a data breach  spans $220 &#8211; $330 per record. Consider a primary care physician with a panel (i.e. patient base) of 4,000 patients. The practitioner&#8217;s cash out-of-pocket costs to remedy a typical data  breach could exceed $1.0 million. Almost all states mandate some form of data breach reporting, and a quick search on <a href="http://www.datalossdb.org/">DatalossDB.org</a> shows health care providers are reporting data breaches frequently. Fail to report appropriately and your out-of-pocket costs go up; Stanford was recently <a href="http://www.esecurityplanet.com/trends/article.php/3905721/Protecting-Your-Business-Cyber-Liability-Insurance.htm" target="_blank">fined $250,000</a> for failing to report a breach on a timely basis.</p>
<p>As businesses convert to electronic records or migrate to the cloud, increasingly more insurance companies offer cyber liability and data breach insurances. Rates vary depending on the risk within the practice. But it&#8217;s not easy obtaining cyber liability and data breach insurance. The vetting process is very thorough and time-consuming. We tell clients that the process is not unlike going through an actual security review &#8212; not a bad thing to do in any event since being &#8220;compliant&#8221; doesn&#8217;t necessarily mean you are &#8220;secure&#8221;!</p>
<p>The good news is that, with a combination of properly trained personnel and a secure network (not anywhere as expensive a proposition as you might think), any company can reduce the likelihood of  these tragic and unexpected costs.</p>
<p>If you would like to see how your network security configurations compare with others, please feel free to call us at 207-772-5678.</p>
<p>Kristin Przybysz<br />
Business Development</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/uncategorized/health-care-data-breach-surprise-insurance-cover/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Best Practices From the Tenth Fleet</title>
		<link>http://www.reliablenetworks.com/security/security-practices-tenth-fleet/</link>
		<comments>http://www.reliablenetworks.com/security/security-practices-tenth-fleet/#comments</comments>
		<pubDate>Wed, 09 Mar 2011 16:07:48 +0000</pubDate>
		<dc:creator>L. Mark Stone</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.reliablenetworks.com/?p=1040</guid>
		<description><![CDATA[Rear Admiral Bill Leigher was the guest speaker at this morning&#8217;s University of Southern Maine Corporate Partner&#8217;s breakfast, and while we didn&#8217;t learn anything new at a presentation geared to lay persons, it was reassuring to see someone so senior as knowledgeably up to date on cyber security. He should be: The Tenth Fleet has [...]]]></description>
			<content:encoded><![CDATA[<p>Rear Admiral Bill Leigher was the guest speaker at this morning&#8217;s University of Southern Maine Corporate Partner&#8217;s breakfast, and while we didn&#8217;t learn anything new at a presentation geared to lay persons, it was reassuring to see someone so senior as knowledgeably up to date on cyber security.</p>
<p>He should be: The Tenth Fleet has no ships, but is responsible for the cyber security (defensive) and cyber capabilities (offensive) of our Navy.</p>
<p>There were two key takeaways for me from this presentation.</p>
<p>We in the industry understand how easy it is for countries like Egypt to have &#8220;turned off&#8221; the wired Internet to their whole country so quickly, but it was interesting to see that the majority of the audience believes the Internet to be much more persistent and secure than it really is. The Internet is <em>much</em> more fragile than that.  We as engineers know that Border Gateway Protocol (&#8220;BGP&#8221;) is the glue that connects the Internet together and controls routing of Internet traffic.  Manipulation of BGP by malicious entities is often used for industrial and political espionage as one can, often with surprising ease, reroute selected Internet traffic through one&#8217;s own routers to analyze the entire flow of Internet traffic to a target.  A good presentation on the fundamental security issues with BGP can be found on Renesys&#8217;s website <a href="http://www.renesys.com/tech/presentations/pdf/blackhat-09.pdf">here</a>. (PDF Download.)</p>
<p>The second and more important takeaway for end users and our clients was the acknowledgment that malware these days is very professional (there is a very efficient global market for criminals and nation-states in malware and support services), well-hidden, and like StuxNet, very destructive and difficult to remediate.</p>
<p>The Admiral pointed out that good standard security practices, firewalls, security software and end-user training, though still very important, aren&#8217;t enough to defend a rich target.  The Admiral cited Apple as an example of a company which has taken defense against industrial espionage seriously, and whose track record is yards better than most.</p>
<p>According to the Admiral, Apple uses software that collects data from server access logs, swipe card systems and a number of other systems and creates &#8220;profiles&#8221; of &#8220;normal&#8221; user activity.  When a user&#8217;s activity deviates from normal, an alarm is triggered. This is a high-tech version of someone asking: &#8220;Why has Bobby been photocopying the new product design plans late each night?&#8221; and is similar to systems used in my former industry (investment banking) to track rogue traders and others potentially acting on inside information.</p>
<p>I can also tell you that we see on our data center and office firewalls at least a half-dozen professional intrusion attempts every day, most frequently from IP addresses registered in China, near Asia and Eastern Europe.  Frankly, anyone who thinks that just because they are in Maine or outside of a large metro area that they are off the bad guys&#8217; radar is deluding themselves; the Internet knows no boundaries.</p>
<p>If you have something valuable to protect and would like to benefit from our best practices, please do not hesitate to call us at (207) 772-5678.</p>
<p>Mark<br />
CIO</p>
]]></content:encoded>
			<wfw:commentRss>http://www.reliablenetworks.com/security/security-practices-tenth-fleet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

