IT Management Tools

News Commentary: One Webcam Per Child

On Sundays I offer comments on some of the most interesting information technology stories that I have found on the web that week.  Please feel free to join in the discussion or suggest other stories.

image

Well I think that we can all agree that using webcams on school provided computers to spy on students without parental consent is a really bad idea.  I also think that attempting to cover it up and denying it when caught with your hand in the cookie jar is a far worse one.  Nevertheless, this story will shape the landscape of information technology and mobile computing for years to come, so all Information Technology Professionals need to be conversant on both the facts and the implications.

hothardware.com – Laptop Monitoring: It’s Not Just In Pennsylvania

“One of the major news stories of the past week has focused on the Lower Merion school district in Philadelphia and the furor created when the school admitted it could remotely activate student webcams and observe them remotely. One clip from an episode of Frontline that aired in June 2009, however, proves that Lower Merion’s Harriton High School is not the only place where students’ rights are potentially being violated.”

There was so much written about this topic that there is no single news story to cover all bases.  I recommend that you review Google News’ aggregation site for this topic.  You can find all angles, opinions, and levels of engagement there.

At its essence, this is a great cautionary tale for IT Pros… just because you can do something does not mean that you should.  Also, it is a story of the best of intentions being carried out in the worst possible ways.  Also, the great ends that were realized by this program have now been completely erased by the means that were used to obtain them.  Really a sad tale… imagine how well this all could have gone if they had simply sent home a permission slip.  My kids’ school sends them home for everything from zoo trips to in-class videos.  How did these school administrators miss the boat by so much?

Well, as they say, knowing is half the battle.  Be warned….

What do you think about this topic?  Do you agree or disagree with me? Do you have a recommended news story for next week? Please share your ideas below.

That is my Information Technology Thought of the Day (ITTOD) for February 28, 2010  by Scott Coughlin.

 

Image Credit: xomba.com

Single Sign-On

The Information Technology (IT) Vocabulary Builder series aims to deliver a very concise summary of a currently relevant topic to Information Professionals.  It is done mostly by collecting a small number of highly relevant web links to save you the time of combing through search results yourself.  It differs from sites such as Wikipedia because it includes opinions, forecasts, and detractions in addition to just facts.

image

Today’s term is Single Sign-On.  This is how Wikipedia defines the it:

“Single sign-on (SSO) is a property of access control of multiple, related, but independent software systems. With this property a user logs in once and gains access to all systems without being prompted to log in again at each of them. Single sign-off is the reverse property whereby a single action of signing out terminates access to multiple software systems.

As different applications and resources support different authentication mechanisms, single sign-on has to internally translate to and store different credentials compared to what is used for initial authentication.”

Essentially, it is the practice of setting up one, very-high security fence for your users to cross.   Once they pass this tough security check-point, then they have ability to use all of the system resources without having to deal with another user-intrusive validation procedure.  If your information system is a castle, then the single sign-on is the main gate and the computing resources are all of the shops in the castle market that is inside the walls and moat.  The opposing model is one, very similar to the Internet, where users get asked for differing usernames, passwords, and security tokens before they get access to individual pages, databases, and programs.

Single Sign-On protocols usually invoke very hard security requirements to make sure that users are authenticated, validated, and properly approved for access at that once check.  Solutions usually involve some or all of the following:

  • Usernames
  • Strong passwords or Personal Identification Numbers (PINs)
  • Hardware Tokens
  • Random number generators
  • Digital certificates
  • Access Control Lists
  • Smart cards

Here are some of the reasons why one might be interested in instituting a single sign-on solution:

  • Users are more willing to be inconvenienced with complicated security protocols once and actually follow them.  This means that you can really come up with a high-powered “lock” and they will be willing to use it.  This prevents the “writing the password on a sticky” problem as well as the one password for many places challenge.
  • Having a single repository protocol for security services permits less vulnerabilities due to software or hardware faults.
  • Troubleshooting of security processes is significantly simplified when only one system is in use.
  • Vendors can develop products for your system and evoke security as a service.
  • Disavowing a user is simplified for human resources because they only have to expunge them from one service vice many.
  • You can use completely open source services to maximize forward looking compatibility.
  • Alternatively, you can use completely proprietary systems to employ “security through obscurity” concepts and be comfortable that you can replace the entire single-sign on component at a future date if desired or required.

As you can see there are potentially many reasons to consider a cross grade.

What are some of the disadvantages?

  • Complexity.  These solutions are rarely easy, simple, or straight forward.
  • Installation Expense.  Good solutions require investments in people, products, and training.  This is not the place to short change.
  • Recurring Expense.  If you choose solutions that require hardware tokens or third-party certificates, then you will be stuck purchasing them forever.
  • People.  If you only have one gate, then you had better make sure that your gate guards know what they are doing and how it works.  If you choose an obscure or complicated system then you need to be ready to pay for the right people here.
  • Fault Tolerance.  If you have one gate and it gets stuck up then you entire system is out of commission.  You need to have back-up plans that don’t remove all of the security advantages of the Single Sign-On system by creating back doors.

Here are some of the best links on the subject that I found in my search of the web:

  • Wikipedia – Single Sign-On.  Contains a great pros and cons as well as resources section.
  • The Open Group – Single Sign-On.  Contains open source specifications, solutions, and white papers.
  • IBM – Build and implement a single sign-on solution. Industry best practices, Java implementation guide, and commercial products to achieve goals.
  • Novell – Secure Login Solutions.  Includes ROI calculators, product comparisons, implementation guides, and white papers.

I have used many Single Sign-On solutions.  Overall, I think that if you properly procure the solution after a formal process of defining your requirements, manning for success, and training your people the benefits of these solutions far outweigh their costs.  I am a big proponent of their employment.

Hopefully, this introduction to the vocabulary word was valuable for you.  Considering all the options for optimizing knowledge management is a core competency of all Information Technology Professionals.

That is my Information Technology Thought of the Day (ITTOD) for February 11, 2010 by Scott Coughlin.

Image Credit: Positiv-it

Best Information Technology Websites: CIO.com

Today, I continue our series on my favorite websites for Information Technology Professionals. I either read these daily or subscribe to them via my RSS reader.  I recommend them all to you.

image

Today, I wish to feature CIO.comCIO.com is an enterprise Information Technology focused site that is targeted at well… Chief Information Officers (CIOs).  It is presented in a magazine blog style and features daily, weekly, and monthly columns, along with news and special features.  It tends to stay aimed at items that would interest mid to large size organizations and has a very nice mix of human resources type stories – hiring, certifications, management, etc. – and technology implementation and utilization articles.  I especially like it because they do an excellent job of linking to unfamiliar terms and writing at an appropriately mature, but not academic level.  They also feature continuing series on topics of interest such as smart phones, Blackberries, virtualization, and management practices.

CIO.com is free.  It has a very clean interface that while featuring ads, does so in a standard vice flashy manner.  It looks good in all the major browsers, including ones featured by large enterprises, but outmoded in general use, such as IE 6.  I find it very usable and direct.

What is CIO.com?  I cannot describe it better than they do… From their own about page:

“Serving chief information officers and other IT leaders, CIO.com, CIO magazine, CIO Executive Programs, CIO Custom Solutions Group and the CIO Executive Council are produced by CXO Media, an award-winning business unit of International Data Group. CXO Media also produces sister publications CSO magazine and CSOonline.com, for chief security officers and other security executives.”

This site is one that all Information Technology  Professionals should be following.  If not on the web, then at least on Twitter where they have a very good news casting service.  Please check this great site out.

What do you think about this topic?  Do you agree or disagree with me? Do you have a recommended website for next week? Please share your ideas below.

That is my Information Technology Thought of the Day (ITTOD) for February 9, 2010 by Scott Coughlin.

Image Credit: fastcompany.com

Special thanks to the team at CIO.com I really appreciate your work at putting out such a terrific resource for the Information Technology Professional community.