Tuesday, September 29, 2009

Available services for online discussions

Just today, Professor Anna Theresa Santiago tweeted that Vice Chancellor Josefina Tayag encourages professors to assign activities to students and/or conduct online discussions. In this line, I will talk shortly about available services for online discussions.

While there are many online services available, each has its strength. Let's take a look at some:
  • Instant Messaging
Using the Conference feature of your IM client (eg, Yahoo! Messenger, Google Chat, AIM, etc.), you can talk to many participants in a conference in near real-time.

Yahoo! Messenger or IM-only software
Strength: Number of participants almost limitless
Weakness: Text only. Sharing files available but participants need to download. Participants need to use the same system.
How to use: Assuming all your students use the same system, you ask them prior to logging in that you will be available online at a particular time. Once all of them are online, you invite them to join the online conference. You may want to set "house rules" in that particular conference as an online conference can be very unstructured.
  • Blogs
The good thing about blog is that you can talk at length about a topic (like a lecture), and then ask your students to give their comments.

Strength: Allows non-realtime interaction. Participants can respond to other participants even at different times. Allows posting of other online resources, such as online video from YouTube or online slideshows.
Weakness: Interaction not as dynamic as IM. You maybe typing a comment that someone else has already entered, so you are not able to support or respond to one another.
How to use: You create your blog. You share the particular post you want them to read, and then ask them to post their comments. Most blogs ask participants to register before leaving a comment.
  • Online forums
Also called message boards (eg, Proboards.com), Online forums allow one to post a comment/issue, then all other interested participants can respond. Your participants need to be registered (ie, like a member of an organization) to respond and leave a comment. Your participants are relatively permanent.

Strength: Captures your audience
Weakness: Not realtime.
How to use: You create a message board, and then invite your students to register. After they register, you create your first thread/topic, and students respond.
  • Online Presentations
If you use Google Docs or the UPM Post Mail (http://post.upm.edu.ph) you can upload your presentations or documents, have others read it, while you talk about it, in the same screen. People can also interact with you like in IM, also in the same screen.

Strengths: Multi-channel (text, visual and other available online resources) near-realtime communication
Weaknesses: People have to have Google Mail or UPM Post Mail.
How to use: You upload your presentation (or document) to Google Docs, then invite your participants by sharing them. People will need to log in or register using the link you send them.

Of course, you can use any combination of these.

If you have questions, just IM me.

Friday, September 25, 2009

How email service providers tag spam

As a former technical support representative for two big Internet Service Providers (ISPs) in the United States, I have come to understand how their mail servers work in reducing spam. Of course, the one I would like to discuss is just the basic manner of recognizing spam. Providers may have other means of identifying spam.

First: For definition, we will work on "spam" as unsolicited email--be it business, advocacy or commercial email. I will not talk about IM spam or SMS spam or gaming spam. I will discuss spamming in emails.

Spam identification is the key to spam reduction, so ISPs actually focus on that aspect. As soon as they determine that an email is spam, what they do with that spam is just a matter of creativity on the email address owner or the email service provider.

There are two key strategies in spam identification: Keyword monitoring and Spam tagging.

Keyword monitoring is (of course) monitoring key words in the email's subject line. Based on the ISP's pre-studied list of words that are most likely to contain spam, ISPs control the distribution of messages that have these words. Instead of going to the recipients' Inbox, they go to the Junk or Bulk mail folder.

This means that if you send email with words such as "tits" or "dicks" in your email, this will probably be sent to the Spam folder of the recipient if the email server has that approach in spam detection.

While this seems logical, the downside of this is not supported by certain groups as this same rule may be applied to the words such as "breasts" or "penis" which may be required in medical professions. Useful emails may be forwarded to the spam folder without knowledge of the recipient (obviously) even though they intend to receive it.

Spam tagging refers to the use of the "Report Spam" or "This is spam" feature of your email service provider to report that the email you are reading is actually a spam. Most of the email service providers have this feature, but the level of effect of the feature varies.

With this feature, what happens usually is that the email you use is transferred to your Spam folder. What you may not know, however, is that what you actually do is not just tag the email as spam, but tag the sender as a spammer.

This indicates that if a certain number of users tag that email sender as a spammer, the email server of the recipient will automatically tag it as spam, resulting to the future emails of that sender to be forwarded to the Spam folder, even for other receivers.

Spam identification focus on two parts of the communication model: the message (Email subject line)b and the sender (Email sender / address), with the channel (email service provider) processing also the setting of rules in spam identification.

The implication of these technologies is simply discretionary use of spam identification. Spam costs a lot of money for organizations as they have to deal with wasted resources (bandwidth) and time (for deleting spam), not to mention privacy and other security issues, so proper identification of spam is really useful. On other hand, be careful with tagging an email as "spam" if you are in an organization where the sender is sending relevant information that only you do not appreciate receiving. You may be costing the inconvenience not just to the sender but to the other recipients.

Resolution for recipients who have discovered they have received an email but it is in the Spam folder when it is actually not spam:
  1. Use the "Unmark as spam" or similar feature
  2. Add the recipient's email address to your address book. This adds a rule to your email that the sender is a valid contact.

Thursday, September 10, 2009

What is cloud computing?

Wikipedia defines "cloud computing" as a "paradigm of computing in which dynamically scalable and often virtualized resources are provided as a service over the Internet." For me, it is just a way of computing (or doing your work with your computer) with your data or your applications--or both--on the Internet.

To concretize, look at Google Docs, or Zoho, or ThinkFree. Also, previously, when one conceives of a website, you use either your Notepad or Microsoft Frontpage. Now, you can do so with Google Sites, which reduces your need to learn HTML or similar languages. Further, Google Sites allows collaboration, multiple types of access, and easy addition of content. Imagine if you will have to write all these in code, and you are not a computer science graduate.

Why "cloud compute?" As Eric Knorr and Galen Gruman say, it "comes into focus only when you think about what IT always needs: a way to increase capacity or add capabilities on the fly without investing in new infrastructure, training new personnel, or licensing new software."

The previous paragraph summarizes the benefits. What are the costs? As I see it, it is minimal. Access to the Internet and necessary software for connecting to the internet (which can be free, considering open source solutions), which are all being used anyway.

I will stop here. But I hope this short post stimulates your creativity--focusing on your own interest while expanding your capability at minimal if no cost.

Friday, July 17, 2009

Understanding Patches

Cyber Security Tip ST04-006

When vendors become aware of vulnerabilities in their products, they often
issue patches to fix the problem. Make sure to apply relevant patches to
your computer as soon as possible so that your system is protected.

What are patches?

Similar to the way fabric patches are used to repair holes in clothing,
software patches repair holes in software programs. Patches are updates that
fix a particular problem or vulnerability within a program. Sometimes,
instead of just releasing a patch, vendors will release an upgraded version
of their software, although they may refer to the upgrade as a patch.

How do you find out what patches you need to install?

When patches are available, vendors usually put them on their websites for
users to download. It is important to install a patch as soon as possible to
protect your computer from attackers who would take advantage of the
vulnerability. Attackers may target vulnerabilities for months or even years
after patches are available. Some software will automatically check for
updates, and many vendors offer users the option to receive automatic
notification of updates through a mailing list. If these automatic options
are available, we recommend that you take advantage of them. If they are not
available, check your vendors' websites periodically for updates.

Make sure that you only download software or patches from websites that you
trust. Do not trust a link in an email message—attackers have used email
messages to direct users to malicious websites where users install viruses
disguised as patches. Also, beware of email messages that claim that they
have attached the patch to the message—these attachments are often viruses
(see Using Caution with Email Attachments for more information).
______________________________
___________________________________

Both the National Cyber Security Alliance and US-CERT have identified this
topic as one of the top tips for home users.
_________________________________________________________________

Author: Mindi McDowell
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed
to increase awareness.

Originally Published at: http//www.us-cert.gov/cas/tips/ST04-006.html

Wednesday, July 1, 2009

Understanding Anti-Virus Software

Cyber Security Tip ST04-005


Anti-virus software can identify and block many viruses before they can
infect your computer. Once you install anti-virus software, it is important
to keep it up to date.

What does anti-virus software do?

Although details may vary between packages, anti-virus software scans files
or your computer's memory for certain patterns that may indicate an
infection. The patterns it looks for are based on the signatures, or
definitions, of known viruses. Virus authors are continually releasing new
and updated viruses, so it is important that you have the latest definitions
installed on your computer.

Once you have installed an anti-virus package, you should scan your entire
computer periodically.
* Automatic scans - Depending what software you choose, you may be able to
configure it to automatically scan specific files or directories and
prompt you at set intervals to perform complete scans.
* Manual scans - It is also a good idea to manually scan files you receive
from an outside source before opening them. This includes

* saving and scanning email attachments or web downloads rather than
selecting the option to open them directly from the source
* scanning media, including CDs and DVDs, for viruses before opening any
of the files

What happens if the software finds a virus?

Each package has its own method of response when it locates a virus, and the
response may differ according to whether the software locates the virus
during an automatic or a manual scan. Sometimes the software will produce a
dialog box alerting you that it has found a virus and asking whether you
want it to "clean" the file (to remove the virus). In other cases, the
software may attempt to remove the virus without asking you first. When you
select an anti-virus package, familiarize yourself with its features so you
know what to expect.

Which software should you use?

There are many vendors who produce anti-virus software, and deciding which
one to choose can be confusing. All anti-virus software performs the same
function, so your decision may be driven by recommendations, particular
features, availability, or price.

Installing any anti-virus software, regardless of which package you choose,
increases your level of protection. Be careful, though, of email messages
claiming to include anti-virus software. These messages, supposedly from
your ISP's technical support department, contain an attachment that claims
to be anti-virus software. However, the attachment itself is in fact a
virus, so you could become infected by opening it (see Using Caution with
Email Attachments
for more information).

How do you get the current virus information?

This process may differ depending what product you choose, so find out what
your anti-virus software requires. Many anti-virus packages include an
option to automatically receive updated virus definitions. Because new
information is added frequently, it is a good idea to take advantage of this
option. Resist believing email chain letters that claim that a well-known
anti-virus vendor has recently detected the "worst virus in history" that
will destroy your computer's hard drive. These emails are usually hoaxes
(see Identifying Hoaxes and Urban Legends for more information). You can
confirm virus information through your anti-virus vendor or through
resources offered by other anti-virus vendors.

While installing anti-virus software is one of the easiest and most
effective ways to protect your computer, it has its limitations. Because it
relies on signatures, anti-virus software can only detect viruses that have
signatures installed on your computer, so it is important to keep these
signatures up to date. You will still be susceptible to viruses that
circulate before the anti-virus vendors add their signatures, so continue to
take other safety precautions as well.
______________________________
___________________________________

Both the National Cyber Security Alliance and US-CERT have identified this
topic as one of the top tips for home users.
_________________________________________________________________

Authors: Mindi McDowell, Allen Householder
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Note: This tip was previously published and is being re-distributed to
increase awareness.

Terms of use

http//www.us-cert.gov/legal.html

This document can also be found at

http//www.us-cert.gov/cas/tips/ST04-005.html