Over the past few weeks, the technology press has focused on a new wave of investments in online learning.  (It's interesting, those of us in the field moved from using the term online learning to e-learning in 2000; investors have remained with the term online learning.  But that's another discussion.)For example, the Chronicle of HIgher Education has been running a series on new educational technology startups and the New York Times has run a series of similar features. Its series highlights a variety of startups, including one that helps professors manage e-mail from students.  (See Students Endlessly E-Mail Professors for Help. A New Service Hopes to Organize the Answers at http://chronicle.com/article/Students-Endlessly-E-Mail/131390/).Many of the features in the Times focus on services providing online courses, like a feature on a series of online services that provide training on various languages for writing Internet applications (see A Surge in Learning the Language of the Internet at  http://www.nytimes.com/2012/03/28/technology/for-an-edge-on-the-internet-computer-code-gains-a-following.html?_r=2&ref=business&pagewanted=all).   In today's edition, the New York Times reports on a large investment in Coursera, a company founded by some professors at Stanford and that provides university-based courses for free online (see Online Education Venture Lures Cash Infusion and Deals With 5 Top Universities at http://www.nytimes.com/2012/04/18/technology/coursera-plans-to-announce-university-partners-for-online-classes.html?ref=business).Nestled between the enthusiastic reporting for these new ventures are some troubling details:The founder of the e-mail company has"no plans to generate revenue—the service is free and does not carry advertisements. Ms. Sankar said that she didn't write a business plan for the site, because she doesn't believe in them, and that she believes that once a critical mass of students and professors are signed up, revenue models can emerges" (quote from the article from the Chronicle cited above).  Isn't that how the tech bubble burst the last time?The quality of the free and low-cost courses for writing Internet applications mentioned in the New York Times article sounds pretty poor. An expert acknowledged that most students who complete these courses still cannot write applications.  One company quoted in the article admitted publicly that its courses could be improved.  If one reads the fine print, the free university courses offered by Coursera and its competitors don't fully compete with those from universities. If students want feedback, they only receive it from other students. Sounds like a good plan but the article never explores the participation rates of students in these students-evaluate-students programs. Avoiding teaching assistants reduces costs, but if participation rates of students in evaluating one another are low, then many students might go wanting for feedback. (This is a real concern; the courses are voluntary, after all.)Students also do not receive university credit; they receive certificates of completion.The courses have no measures to protect against cheating.And, most significantly, when the article cites the impact of courses on students, they have no figures to report. They provide qualitative data.  That's fine, because it provides insights into whom and how the courses affect students.  But both of the students mentioned are working professionals, rather than degree-seeking students.Perhaps, then, these services are not really meant to replace universities; they're the beginnings of an online system for continuing professional education.  The only problem is, it doesn't sound like the founders of these companies have figured that out yet and, even if they have, the courses might need extensive rework before they can help workers really develop the skills and knowledge they need to succeed on the job.  
Saul Carliner   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:17am</span>
Matthew Ferrari posted a blog postTales from the Disaster Recovery FrontIn a previous post I wrote about the importance of a) being able to test your disaster recovery (DR) plan and b) actually performing the test on a regular basis. But that discussion presumes there is already a DR plan in place. That may not be the case.Take the healthcare industry. A recent survey of health IT executives showed that the majority (70%) did not have a data centers DR plan in place. If something happened, their "strategy" was to sit tight and wait until the problem that took the data center down was fixed. That’s a huge gamble to take, especially with how much of all business today relies on the IT infrastructure.Perhaps the best way to illustrate the importance of having a DR plan in place (and tested) is to look at two real-world examples of what can happen - one a costly failure and the other a textbook example of a good DR plan in action.Let’s start with the failure, which involves the flooding in New York City in 2012 during Hurricane Sandy. An entire data center that served clients in the financial services industry went dark when the backup generators in the building’s basement were submerged in water. With no other recourse, the data center provider had to scramble to find space in other data centers that hadn’t been affected by the flooding. When it did, the provider had to physically pull the servers out of its racks and drive them to a data center it didn’t own in another city to restore functionality for its most important customers. Those customers went without their data for 4.5 days, while others were down for a week and a half before main power could be restored.Ask yourself - could your organization survive without access to data for more than four days? Especially given that 24 percent of organizations that suffer an outage of 24 hours or more close within two years? Or that 68 percent of organizations down for a week or more close within one year?Now let’s look at the benefits of preparing properly for disasters. A hospital in the Utah mountains built its DR plan to include replication of data to the cloud over a dedicated MPLS connection and quarterly tests to ensure performance. When a huge snowstorm threatened to shut down the power to their local data center, the hospital proactively failed over production to the cloud environment with a recovery time objective (RTO) and recovery point objective (RPO) of less than an hour - with no loss of performance or security. The replication process meant the data was available immediately after the failover - no need to go through a lengthy restore process from tape or disk, no need to ship SQL logs. Most importantly, the hospital was able to operate as though the data was still being held locally. In fact, it was so successful the hospital is now considering permanently moving all of its production to the cloud.The reality is today’s enterprises (as well as small to medium-size businesses) are heavily reliant on data and technology. This makes them far more vulnerable than they realize. Even something as simple as pulling the wrong cable can create potentially devastating disruptions.A well-designed, well-tested DR plan is no longer a "nice to have." It is a must for every organization.Matt Ferrari is CTO of ClearDATA.See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:16am</span>
Check out, The Three Approaches to Professionalization in Technical Communication, one of the articles in the special issues on professionalization in the journal, Technical Communication.    The article explores internal divisions within the profession by exploring a spectrum of attitudes towards professionalization.  At one of the spectrum is professionalization, which seeks to formalize the practice and preparation for the profession. At the other end of the spectrum is contra-professionalization, which actively resists efforts to professionalize.  Here is the abstract of the article:Purpose:  Explores internal divisions within our profession by exploring one particular type of tension that exists: that technical communicators do not have a unified view of professionalization for the field. Methods:  Proposes that prevailing approaches to professionalization are rooted in theories of occupations, the exclusive right to perform a job. True occupations have such rights legally; aspiring occupations like ours are professions.  Common components of an infrastructure for occupations includes professional organizations, bodies of knowledge, education, professional activities, and certification.Results:   Professions often establish these in anticipation of becoming an occupation, but some practicing professionals interpret and use them differently, resulting in a spectrum of approaches to professionalization.At one end of the spectrum is formal professionalism, which views professionalization as a stepping stone to full occupational status. It is rooted in a worldview that values expertise and sees the infrastructure of an occupation supporting the development of expertise and controlling access to the profession. In the center of the spectrum is quasi-professionalization, in which individuals participate in the activities of the occupational infrastructure but without the expectation of exclusive rights to perform the work. Quasi- professionalization is rooted in professional identity. At the other end of the spectrum is contra-professionalization, which refers to initiatives that offer or promote professional services outside of parts or all of the infrastructure, sometimes circumventing it completely. This world view is rooted in market theory and characterized by  concepts like Do-It-Yourself (DIY), user-generated and Subject Matter Expert (SME)-provided documentation.Conclusions:  The differing views suggest tensions regarding support for specific efforts to professionalize technical communication, including formal branding of the profession, establishment of certification, and support for professional organizations.To see the complete article, visit http://www.ingentaconnect.com/content/stc/tc.  (Note: Only free to members of the Society for Techincal Communication and to those entering through university libraries with a subscription to IngentaConnect.)
Saul Carliner   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:16am</span>
As 2013 draws to a close, it’s seductive to make declarations about how things (including ourselves) will be different in the coming year. Daily exercise Kind words to the crotchety co-worker No sugar The list goes on. The problem is that too frequently we jump to these resolutions prematurely. They end up operating in a vacuum and without context… more like challenges than congruent, integrated intentions. They capture our intention for a few weeks; but they fail to capture our imaginations and hearts sufficiently to carry them further. And it’s all because we skip an important step: we look forward before looking backward. The new year inspires new energy… but that energy can be more constructively and productively focused if we spend even a few minutes reflecting on the past twelve months: What activities generated the greatest sense of accomplishment? (Note: This is different from ‘what did you accomplish?’ This is about the activities that got you there.) When did you feel most alive? Who inspired you and why? What were you doing when you were happiest? What came easily to you? What were the greatest struggles? What did you learn… about yourself… about others… about life? Your answers to these questions are fodder for resolutions that will mean something… that will stick with you beyond the first few weeks of January…. that will direct your attention and action in ways that are meaningful and fulfilling. Allowing resolutions to emerge from this reflection yields an emotional pull toward what matters versus a punitive push toward a bunch of ‘shoulds’ that might not. So, before toasting the New Year and looking forward to 2014, take a few pre-solution moments to look backward then set some genuine intentions and resolutions that will stick with you and propel you forward into the life you envision. The post Pre-solution: The Forgotten Step Before Resolutions Can Take Hold appeared first on Julie Winkle Giulioni.
Julie Winkle Giulioni   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:16am</span>
Per Buer posted a blog postThe State of Entrepreneurship in the NordicsAt the end of January, the analyst James Governor invited me to present at his Monki Gras developer’s conference in London. This year’s theme was "Nordic Craft Culture and Tech" and my company, Varnish Software, is based in Norway.As James put it, "the web runs on Nordic inventions" and most web inventions are built on open source. Varnish Software began life as an open source project and the Nordic region is rich with open source inventions like Linux, MySQL and PHP.James wanted to explore further "what makes Nordic Culture so productive" during the conference. To outsiders there are many factors that would appear to be working against Nordic entrepreneurs, for example the high taxes - of which I am all too familiar! Other things like difficulty in raising capital and less sophisticated VCs also work against us.So here’s something that will probably come as a surprise. In 2013 when we won a Red Herring award, I made a quick count of how the various Nordic countries were represented. I found that the Nordics were massively over-represented per capita, when compared to other countries in Europe. I suspected lots of different reasons for this - let me share a few..Tech startups have flat organizations. The boss doesn’t have as much authority as in other companies. Startups hire bright people and they are expected to provide guidance on various parts of the business even though it might be slightly outside their job description. This makes perfect sense as the boss doesn’t have all the answers. This attitude is pretty common in the Nordics. As other speakers explained , the cultural concepts of Dugnad (Norway) or Talkoot (Finland), both of which refer to voluntary community work, or Lagom (Sweden) which describes the gravity towards the average as positive, are strong cultural values that favor such a flat organization. Countries with more hierarchical cultures are less naturally included towards these flat, collaborative structures.Another factor that probably comes into play is the region’s strong social security net, mitigating risks for entrepreneurs. Trusted governments and low levels of corruption also make a startup more likely to succeed. There are probably other aspects as well, such as individuals’ need for self-realization. The relatively high median income in the Nordics make self-realization a stronger motivational force compared to countries with lower incomes.Earlier this year I looked at the last 500 Red Herring awards given in Europe and how the various countries were doing.The Y axis shows the number of people in each country per Red Herring winner. Norway is doing pretty bad compared to Denmark and Sweden. This didn’t really surprise me much. Sweden has done a spectacular job of turning its tech startups like MySQL, Spotify, iZettle and Mojang into global successes.Denmark, which is pretty close behind, also has a strong entrepreneurial spirit. Having spent quite a few vacations in Denmark I know that it is hard to drive more than a couple of hundred meters without running into a tiny business trying to sell you something. If a Dane has a few unused square meters in his backyard he likely to use the area to grow some vegetables or set up a tiny ceramics shop, selling his wares to whomever drives past. This entrepreneurial reflex is unique and leads to a vast number of small startups. Companies such as Zendesk and Endomondo are good examples of successful start-ups. These companies aren’t growing as quickly as the their Swedish counterparts but the sheer amount of them is pretty staggering.Norway has fewer start-ups and the reasons behind this are pretty complex. It seems pretty hard to compete with the offshore endeavours that dominate Norwegian business. The offshore oil business is hugely profitable and dominant. These companies get government subsidies and invest heavily in R&D and attract some of Norway’s best developers. This makes it impossible for start-ups to recruit on a level playing field. ForgeRock is notable exceptions, that has managed to overcome this and made a fantastic success in the enterprise world. And overall Norway isn’t doing too bad compared to the rest of Europe.All in all Scandinavia averages around 0.83 Red Herring award winners per one million population. The UK averages around 0.19, Germany 0.10, France 0.20 Spain 0.08 and Italy 0.04. But wait, what about Finland? The results are pretty surprising. Finland has on average 1.8 Red Herring awards per million people. While Finland is part of the Nordics, its culture is quite different, both in terms of language and culture.The Finnish entrepreneurs presenting at Monki Gras put a lot of emphasis on Sisu, the ability to persevere suffering. The best examples of massive amounts of Sisu can be found in history books describing the Finnish resistance to Soviet aggression. The idea of Sisu goes directly against ideas such as "fail fast" and "pivot quickly". As one speaker said, any Finnish entrepreneur would keep banging their head against the wall long after any sensible person would have given up. And sometimes, all a startup needs to succeed is another six months and just a few more head bangs!Per Buer is founder of Varnish Software.See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:16am</span>
Because of low enrolment, the Integrative Literature Workshop that was scheduled to begin this Thursday has been canceled. I hope to offer a section at a later time.  
Saul Carliner   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:16am</span>
Marin Perez's blog post was featuredHow Customer Success Can Supercharge AdvocacyDiving head-deep into the Customer Success space has been an eye-opening experience for me. In particular, the connections between Customer Success and advocacy have been illuminating. I've already covered how Marketing and Customer Success can partner to drive advocacy but I'd love to share some more insights I've learned.In the B2B world, I’ve noticed people tend to refer to relationships between vendors and customers as "partnerships." This isn’t a good thing because it paints all of these different types of relationships with the same brush. In reality, vendor-customer relationships exist on a spectrum. Some relationships are irrelevant while others are made up of honest, fully committed teamwork. The latter is a true partnership, and a true partnership is worth striving for with your customers. Why? Because it means they place a high value on your relationship. It also increases retention rates, broadens awareness of your brand within customers’ organizations, and builds true advocates. True advocates are worth their weight in gold because no matter how much marketing and branding you do, new potential customers are going to trust their peers more. Trust is the best form of advertising.Growing advocates is extremely important for any successful business. Advocates lead to more referrals, they lead to upsells and cross-sells, and if you’re using them correctly, advocates can also result in lead-generation and customer conversions. Venture Capitalist Tomasz Tunguz also points out that Advocacy can lead to a significant lowering of the cost to acquire new customers. That’s why Customer Success exists: we build partnerships by incentivizing customers to engage with our brand. This requires identifying the right people and opportunities. And those, in turn, require a lot of proactive communication and ongoing candor. Let’s do a deep dive into some specific tasks Customer Success orgs can do to help build these partnerships that eventually lead to advocates. Identify Hidden AdvocatesWithout a doubt, some of your current customers can make for great advocates but it’s up to Customer Success to find them. Having a keen understanding of your customers’ usage data is a good way to be able to spot power users who may eventually become advocates.A lot of companies get excited about how advocacy can advance their needs but that’s not how an advocacy partnership should work. After you’ve identified potential advocates, the next steps include identifying co-marketing opportunities and tailoring them for the interest of the customer. Customer Success Managers should make the co-marketing opportunities aligned with the customer’s agenda for the quarter (or year) because this makes participating a seamless experience for the client.Maximize Business ReviewsWe know that quarterly business reviews are great moments to convey how much business value the customer is receiving but business reviews can also be used as a way to build advocates. Because these often have wider audiences than the day-to-day interactions of Customer Success Managers, use this as an opportunity to highlight the successes of your connections at the company.Anything that can boost their reputation in front of their company increases the odds of them becoming an advocate. There’s a difference between building up your customer’s confidence and inflating them for the sake of inflating them, so make sure that you’re utilizing relevant data which places the customer’s achievements in proper context.Keep Advocacy In Line With Actual SuccessIt’s very easy to get carried away with co-marketing and leaning on your advocates but it’s important to have honest depictions of what’s going on with your customers. In other words, make sure your advocacy material is in line with the actual success of your clients.Doing case studies or co-marketing assets simply for the sake of hitting predefined Marketing goals can ultimately undermine your efforts. While it’s important to maintain a strong cadence of advocacy material, if what you’re publishing doesn’t match up with what people in the field are hearing, it’s going to bring down your credibility.When it comes to selling this to skeptical internal teams that may have their own advocacy goals, really break it down into "How does this really benefit your customer?" Tailor the goals to make sense to your customers. Otherwise, you can find yourself going to the same few customers over and over, which can lead to advocacy burnout.One way Customer Success can help in this area is by bubbling up the best existing advocate sources so that Marketing can make the most with what they actually have. This can mean going deeper with existing advocates, as opposed to stretching to include multiple sources where there may be no substance - three in-depth, honest advocacy pieces are going to resonate more than five fluffy pieces. Focus on the People  It’s vital to remember that advocacy has to go both ways, as your organization should also be trumpeting your customers’ successes and the individual actors within it. We discussed how you could tailor the co-marketing efforts to help your customers hit their agendas, but Customer Success can take a variety of actions to ensure advocates are gaining value.Make sure that you’re connecting your advocates with individuals and companies that can be useful for their networking. You really want these partners to feel like being your advocate is advantageous for them … you’re not just trying to send them out there with a sandwich board advertising your brand. Marin Perez is a former tech journalist who's joined a B2B startup on the content side.See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:15am</span>
I finally got around to reading Before Happiness by Shawn Achor over the holidays. It’s an insightful book that describes how we must learn to see the world through a more positive lens which allows us to summon the motivation, emotion, and intelligence necessary to achieve happiness and success. The reading prompted me to begin considering the precursors of other fundamental success-driving factors… like competence. Competence is essential to workplace (or any-place) success. The ability to perform well and efficiently, proficiency, mastery, and expertise - it all lays a solid foundation for accomplishment and results. But competence doesn’t spontaneously appear; it unfolds in the presence of something even more powerful: confidence. Based upon my field research and 20+ years of experience helping leaders and employees build new skills to improve their effectiveness, confidence is the precursor of competence. Certainly there are times when we’ve all surprised ourselves by being able to do something we never thought possible. But, in the vast majority of cases, that achievement is preceded by a belief, trust, or faith that it could be done. In the vast majority of cases, confidence comes before competence. As a result, building worker confidence may be today’s most under-rated leadership priority. What steps do we take to inspire sufficient faith in one’s ability to perform well? Try any combination of this dynamic dozen of confidence-coaxing strategies. Feedback: Regular, balanced feedback provides a safety net, allowing others to try new things and act more boldly because they know they can count on you to offer constructive observations that will help them calibrate their efforts. Strengths: Tapping into areas of strength naturally activates confidence. So, find ways to encourage others to leverage what they are already good at to discover new abilities. Goals: Confidence is harder to muster if the endgame is unclear. If one’s not sure what success looks like, it’s hard to believe that it’s possible. So make the future less foggy by supporting others in clarifying their goals. Once we paint a picture of success, we can start to paint ourselves into it. Coaching: Engage in facilitative conversations that help others consider their methods, processes, and results. Ask about what’s motivating, challenging, confusing. If you stick to the questions, they must come up with the answers. And the mere act of doing that, builds confidence. Learning: Provide the training or development experiences required to be successful. Rehearsal: And give others a chance to practice and hone new abilities in a safe setting before ‘going live’ under greater performance pressure. Whether it’s working out the kinks of new skills in a workshop or role-playing a challenging interaction, success in these artificial settings builds confidence in one’s ability to excel. Accountability: Conferring responsibility to others communicates your confidence in their ability to perform well while providing the opportunity for them to take their own confidence-building actions. Recognition: Catch others doing things right. Provide on-the-spot acknowledgement of skills and abilities. Express appreciation. And, don’t forget to spotlight effort as well as results… since the road to achievement can sometimes be quite long. This supports persistence, which in turn supports greater confidence. Network: Encourage those around you to connect with others. Build strong bridges among individuals. Engineer collaboration and cooperation. A broader network provides greater perspective and support which make trying new things less risky and more comfortable. Reflection: Be a sounding board and offer opportunities for those around you to give serious thought and consideration to topics important to their success. Insightful, juicy, significant questions about what’s most important, past successes and failures, new lessons, concerns, and stumbling blocks (both internal and external) allow others to become grounded, better understand who they are and what they’re capable of… and tap that inner confidence. New experiences: Offering novel opportunities telegraphs your confidence in the abilities of others while providing a playground in which to apply strengths and skills in new ways… more or less successfully. But either way, simply taking action and trying builds grit and greater comfort stepping into new realms. Mistakes: Allow them. Encourage them. Cherish them. Genuine confidence comes from the deep inner belief that one is capable of dealing with the outcomes of their efforts… good and not so good. So, create the space where people can fail. Help them reframe errors and opportunities to generate new awarenesses. Facilitate conversations that allow others to milk their mistakes for all they’re worth. There’s nothing quite like surviving (and even thriving in the face of) failure to build a very profound and abiding sense of confidence. So, before competence, there’s confidence. But before confidence, there’s frequently a leader who understands the connection between the two and is willing and able to take steps to help others build trust, faith, and belief in their ability to succeed. It all comes down to coaxing confidence then watching competence unfold. Image: istockphoto.com The post Before Competence appeared first on Julie Winkle Giulioni.
Julie Winkle Giulioni   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:15am</span>
Informal Learning Basicse-Learning Handbook  Training Design BasicsAdvanced Web-based TrainingDesigning E-Learning  Techniques for Technical CommunicatorsInformation And Document Design: Varieties on Recent Research (2nd edition)An Overview of Online Learning (2nd edition)
Saul Carliner   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:15am</span>
Nathan Drier's blog post was featuredHow I Break Into Businesses (With Permission, of Course)As an ethical hacker, my job is to see the future. How would a real-life criminal break into "X" business? What security weakness would he exploit? What information would he steal and what would he do with it? Like a game of Chess, if I can predict my opponents’ next moves, I can align my attacks to make sure they fail.Social engineering encompasses that kind of forward-thinking. With a business’s permission of course, ethical hackers mimic real-life criminals to identify and remediate security weaknesses within their environment. To infiltrate successfully, the ethical hacker, a.k.a. security tester, uses a variety of strategies from physically breaking into the building without employees noticing to virtually gaining a foothold by luring unsuspecting employees to click on a link or open an attachment.Here are six of the most common social engineering tactics my team has used to get inside:Tricky Emails. Phishing emails have a high success rate. Pretending to be on the IT team or a trusted third party vendor, we send an email asking the end user to open an attached file or visit a website that we control. Once the user clicks the link or opens the document, the damage has been done. We’ve silently collected the employee’s domain username and password, and possibly obtained shell access to his/her workstation. From there, we setup shop on the victim’s computer and use it as a launch pad to attack the rest of the corporate network.One time we sent out emails telling all employees that we upgraded them to a newer version of their external webmail service. Everyone started logging in - but instead of getting access to their email, we were collecting their usernames and passwords. One of those users happened to also have VPN access, which allowed us to VPN into the corporate network.Media Drops. People love free stuff including a new, shiny USB thumb drive in the parking lot on their way to work. Little do they know, we have spent all week custom-coding a piece of hidden malicious software. The second they plug it in, it runs code that takes over their computer and gives us remote access to it. From there, we can begin attacking other internal systems with minimal risk.For even greater success, we put the thumb drives in a trusted location. For example, we may fill up a small basket with the drives and write ‘FREE’ on it. While schmoozing with the receptionist, we drop off the basket somewhere in the lobby. A couple hours later, all 30 drives are gone and beginning to phone home.Tailgating. People are busy, too busy to notice me walking behind them on their way into the office. I don’t have a badge and they haven’t seen me around before - but the office is large and I look like I belong. I’m typing an important email or talking on my phone, and I seem to know where I’m going. The majority of the time, I will smile and they will hold the door open for me…I must have forgotten my badge.Once inside, I scout and find an empty cubicle off in the corner. I crawl under the desk and plug in a wireless access point. My cohorts in the minivan outside see the wireless network pop-up and begin using it to map out the internal network.Dumpster Diving. A company’s trash is a goldmine of information. From vendor information, passwords, usernames, schematics, network information - it’s all there. Dumpsters are rarely locked (or easily picked). Early in the morning, when the building is empty, we search through the dumpsters, grabbing bags full of papers, and running back to a home base for analysis.One time we found payroll data for employees including more than 10,000 social security numbers -all in the dumpster.Face to Face. Having confidence and looking the part gets us into places. For example, I was working on an ethical hacking assignment for a business with a large public office area and stumbled on one of their unlocked workstations on the main floor. The machine was obviously for employees-only. I slid up to the keyboard and got to work escalating my privileges and installing a backdoor. A couple minutes in, an employee walked over and asked me what I was doing. Before I could answer, she said, ‘Oh, they finally sent someone to fix my computer. I’ve been telling them it has been dog-slow for months!’I confirmed I was there to solve the problem for her. She left, and I got back to work. Minutes later, a security guard came hustling my way. I tried to finish installing my backdoor before he reached me - but to my surprise that first employee cut him off and said, ‘You leave him be, he is from IT and is fixing my computer.’She continued to distract the security guard just long enough for me to finish up my work and disappear.Phone Calls. The most direct way to get sensitive information from people is to call and ask. I like to pretend I’m interested in a technical job they posted, and use that guise to get additional information from human resources or wherever I happen to land. I can usually get them to ask for a resume, which makes for an excellent prelude for sending a phishing email.During one engagement, we had a target on the phone who thought we were from IT. We were helping her ‘fix’ her computer, and during that process she had to change her password to a known value (letting us compromise her account). Once we were finished, she mentioned that everyone else in her department was experiencing the same problem and she could help by having all her coworkers change their password to the same value. It was a huge help…for us.Security testing is critical in helping businesses defend against the latest threats and stay ahead of the criminals however it’s only one layer of data protection. Automated vulnerability scanning across all businesses’ assets is another key element. Scanning and testing should be performed continuously throughout the year so that whenever there’s a change in the business’s environment, it can identify new security vulnerabilities that arise and fix them before it’s too late.Nathan Drier is Principal Security Consultant at Trustwave.See More
Jeff Fissel   .   Blog   .   <span class='date ' tip=''><i class='icon-time'></i>&nbsp;Jul 14, 2015 09:14am</span>
Displaying 42521 - 42530 of 43689 total records
No Resources were found.