Thursday, May 28, 2009

Official Google Blog: Went Walkabout. Brought back Google Wave.

Official Google Blog: Went Walkabout. Brought back Google Wave.

This is an interesting development on collaboration. As I understand, Google Wave is a realtime collaborative (as in online) tool that mixes collaborative document management (ie, creating, editing, sharing and publishing) and communication. It is like (to my limited understanding) having a whole page of your instant messenger where you also display your online documents, videos, images and other digital content.

I am very interested in how this can be applied to education. Expect me to blog about this after I use it. If you are interested, try going to the website at http://wave.google.com.

Wednesday, May 27, 2009

Using your mobile phone as a high speed modem - Part 2

Previously, I have blogged about my intent of using the mobile phone as a high speed modem. I indicated there that I will try it so that I can post about it.

Well, I got myself a Samsung SGH-U800 phone, a relatively affordable (ie, cheap) phone which, among other things, is HSDPA-capable. I was afraid that it would not work (considering I gave up my dual-active China mobile phone with television and I paid for the Samsung phone 7+++.++), but I am so thankful when I tried it and it worked.

How fast was it?
I used Azureus Torrent client and it came to a high of 220 kbps (3G speed) at 10 am. It was fast (faster than the connection at UP Manila at peak times), and I was mobile. (I have used only for fifteen minutes because I need to go back to admin work.)

Click here to see what HSDPA promises (Globe website).

System Requirements
Before continuing, let's check the requirements:
  • A 3G/HSDPA mobile phone. How will you know? Check the features list of your mobile phone. If it says it has 3G but has no HSDPA, then it does not have HSDPA. It is fast, but not as fast as HSDPA.
  • Software for your mobile phone (particularly if you have Windows)
  • Computer with USB port (some mobile phones allow Bluetooth)
  • Credit (load) on your mobile service (3G/HSDPA is a paid service.
  • A browser or any Internet software.
How to Connect
So, how did I do it?

For Windows: It consists of three parts: 1) Enable your mobile phone and your SIM for 3G/HSDPA; 2) Install the mobile phone software on your computer; and, 3) Connect to the internet using the mobile phone as modem.

For Ubuntu: It consists of 2 parts: 1) Enable your mobile phone and your SIM for 3G/HSDPA; and, 2) Connect to the internet using your mobile phone as modem.

For the first part, it is best that you contact the customer service representative of your mobile service provider (ie, Globe, Smart, Sun, Red). If you are a Globe postpaid subscriber, as far as I know, your SIM is pre-activated for 3G (together with HSDPA*). If not, send GO to 2951. You will then be sent instructions on how to do it. For Smart and Sun, no idea, contact your CSR.

*Please note that having a 3G phone does not mean you also have HSDPA. HSDPA runs on top of the 3G technology. Check the features of your phone to see if it indeed has HSDPA functionality.

Once that is done (you have confirmed that your phone has 3G/HSDPA enabled), you now install your mobile phone software. If your phone has a CD with it, now is the time to install it (if you have Windows). If you use Ubuntu Linux, skip this part. If you have Mac, check if the CD with your mobile phone also is applicable for your Mac.

After installing the software, connect the phone to your PC (in my case, a laptop). Usually, there is a USB data cable for 3G/HSDPA-capable phones.

If you use Ubuntu 9.04, it practically ends here. A pop-up would appear at the upper-right hand of your screen saying it detected a USB modem. It will show you a list of networks (Globe, Globe WAP, Smart Telecom, etc.). Select your network of course. For me, I selected "Globe Telecom" (without the "WAP").

It will then show a pop-up sign saying that if you want to connect, click there. In my case, I missed it, so I just clicked the network icon (the four vertical bars indicating wireless signal strength), then selected Globe Telecom. It will ask for username and password. Just leave them blank and select "Dial" or "Connect." Once it finishes the handshake, it should say that you are now connected to the Globe Telecom network.

I opened my Firefox and Pidgin, and I got connected!

If you use Windows (XP in my case), open the mobile phone software, connect the mobile phone to the laptop. Wait for the process to finish detecting the phone (In my case, the software indicated it detected the SGH-U800 phone), then click the option for networking.

It may prompt you for username and password. As in Ubuntu, leave them blank. Windows would tell you something about using sending username and password on unencrypted network. Basically, you ignore this since there is no username and password. Click "Dial" or "Connect," wait for the handshake, and the pop-up should appear at the lower righthand side of your screen indicating the speed of your connection. When you receive this, that means you are connected already.

The next time you want to connect with your mobile phone and you use Windows, you just connect your mobile phone to your computer, and then double-click the dial-up connection icon with the symbol of your mobile phone.

Reminders:
  • If you are used to connecting your laptop to the UP Manila network, remember to disable the proxy settings.
  • If you use an Acer laptop with webcam, you would experience the webcam being disabled. I don't know why it happened, but it did. I know it is because of the Samsung software because when I uninstalled the software, the webcam worked again.
Using your mobile phone as a high speed modem is a viable and cost-effective alternative to getting USB devices (eg, Globe Broadband Tattoo and Smart Bro Prepaid) which requires you to get another number. Since you do not use your mobile phone 24 hours a day, you could use it at night, during the day or on the road (with your laptop), to connect to the internet where there is 3G/HSDPA signal.

To know if you have 3G signal at your location, try this site: Globe. Click Item number 16, "LOCAL COVERAGE."

Other considerations
Please note that since you will install another software in your computer, this software which will run will consume memory (or affect speed of your computer). While the speed of your computer may not noticeably change, the presence of another software running means programs may react slower than without that program.

Please note also that service providers have different billing schemes (time-based or KB-based). Make sure to take note which one is enabled in your SIM or you might get surprised with the bill.

Concluding Remark
HSDPA by Globe or any service provider is subject to certain technical limitations. Since I have no use for them I have not tried using Globe HSDPA for SSH, VPN, or other highly technical modes. For basic browsing, chat, email and content downloading and uploading, as far as I know, it works.

If you need assistance, ask me. I appreciate your feedback.

Disclaimer: I am not promoting Globe. I use it as an example because that is the one I have.
Update: I'll see if I can update this to include screenshots from Windows XP and Ubuntu.

Thursday, May 21, 2009

Choosing and Protecting Passwords

Cyber Security Tip ST04-002

Introduction

Passwords are a common form of authentication and are often the only barrier
between a user and your personal information. There are several programs
attackers can use to help guess or "crack" passwords, but by choosing good
passwords and keeping them confidential, you can make it more difficult for
an unauthorized person to access your information.

Why do you need a password?

Think about the number of personal identification numbers (PINs), passwords,
or passphrases you use every day: getting money from the ATM or using your
debit card in a store, logging on to your computer or email, signing in to
an online bank account or shopping cart...the list seems to just keep
getting longer. Keeping track of all of the number, letter, and word
combinations may be frustrating at times, and maybe you've wondered if all
of the fuss is worth it. After all, what attacker cares about your personal
email account, right? Or why would someone bother with your practically
empty bank account when there are others with much more money? Often, an
attack is not specifically about your account but about using the access to
your information to launch a larger attack. And while having someone gain
access to your personal email might not seem like much more than an
inconvenience and threat to your privacy, think of the implications of an
attacker gaining access to your social security number or your medical
records.

One of the best ways to protect information or physical property is to
ensure that only authorized people have access to it. Verifying that someone
is the person they claim to be is the next step, and this authentication
process is even more important, and more difficult, in the cyber world.
Passwords are the most common means of authentication, but if you don't
choose good passwords or keep them confidential, they're almost as
ineffective as not having any password at all. Many systems and services
have been successfully broken into due to the use of insecure and inadequate
passwords, and some viruses and worms have exploited systems by guessing
weak passwords.

How do you choose a good password?

Most people use passwords that are based on personal information and are
easy to remember. However, that also makes it easier for an attacker to
guess or "crack" them. Consider a four-digit PIN number. Is yours a
combination of the month, day, or year of your birthday? Or the last four
digits of your social security number? Or your address or phone number?
Think about how easily it is to find this information out about somebody.
What about your email password—is it a word that can be found in the
dictionary? If so, it may be susceptible to "dictionary" attacks, which
attempt to guess passwords based on words in the dictionary.

Although intentionally misspelling a word ("daytt" instead of "date") may
offer some protection against dictionary attacks, an even better method is
to rely on a series of words and use memory techniques, or mnemonics, to
help you remember how to decode it. For example, instead of the password
"hoops," use "IlTpbb" for "[I] [l]ike [T]o [p]lay [b]asket[b]all." Using
both lowercase and capital letters adds another layer of obscurity. Your
best defense, though, is to use a combination of numbers, special
characters, and both lowercase and capital letters. Change the same example
we used above to "Il!2pBb." and see how much more complicated it has become
just by adding numbers and special characters.

Longer passwords are more secure than shorter ones because there are more
characters to guess, so consider using passphrases when you can. For
example, "This passwd is 4 my email!" would be a strong password because it
has many characters and includes lowercase and capital letters, numbers, and
special characters. You may need to try different variations of a
passphrase—many applications limit the length of passwords, and some do not
accept spaces. Avoid common phrases, famous quotations, and song lyrics.

Don't assume that now that you've developed a strong password you should use
it for every system or program you log into. If an attacker does guess it,
he would have access to all of your accounts. You should use these
techniques to develop unique passwords for each of your accounts.

Here is a review of tactics to use when choosing a password:
* Don't use passwords that are based on personal information that can be
easily accessed or guessed.
* Don't use words that can be found in any dictionary of any language.
* Develop a mnemonic for remembering complex passwords.
* Use both lowercase and capital letters.
* Use a combination of letters, numbers, and special characters.
* Use passphrases when you can.
* Use different passwords on different systems.

How can you protect your password?

Now that you've chosen a password that's difficult to guess, you have to
make sure not to leave it someplace for people to find. Writing it down and
leaving it in your desk, next to your computer, or, worse, taped to your
computer, is just making it easy for someone who has physical access to your
office. Don't tell anyone your passwords, and watch for attackers trying to
trick you through phone calls or email messages requesting that you reveal
your passwords (see Avoiding Social Engineering and Phishing Attacks for
more information).

If your internet service provider (ISP) offers choices of authentication
systems, look for ones that use Kerberos, challenge/response, or public key
encryption rather than simple passwords (see Understanding ISPs and
Supplementing Passwords for more information). Consider challenging service
providers that only use passwords to adopt more secure methods.

Also, many programs offer the option of "remembering" your password, but
these programs have varying degrees of security protecting that information.
Some programs, such as email clients, store the information in clear text in
a file on your computer. This means that anyone with access to your computer
can discover all of your passwords and can gain access to your information.
For this reason, always remember to log out when you are using a public
computer (at the library, an internet cafe, or even a shared computer at
your office). Other programs, such as Apple's Keychain and Palm's Secure
Desktop, use strong encryption to protect the information. These types of
programs may be viable options for managing your passwords if you find you
have too many to remember.

There's no guarantee that these techniques will prevent an attacker from
learning your password, but they will make it more difficult.
________________________________________________________________

Authors: Mindi McDowell, Jason Rafail, Shawn Hernan
_________________________________________________________________

Produced 2004 by US-CERT, a government organization.

Source: http://www.us-cert.gov/cas/tips/ST04-002.html

Monday, May 18, 2009

Official Gmail Blog: Tasks, now in Calendar too

Official Gmail Blog: Tasks, now in Calendar too

This new feature in Google Calendar makes listing tasks related to events easier to manage. This is particularly useful to managing numerous tasks related to an event, instead of listing the tasks as numerous events in your Google Calendar.

If you read my previous post about "Free SMS Pre-Event Reminder?" you would already be familiar with the creative and useful feature of Google Calendar and in using it as a reminder. With this additional feature of Tasks, it will help event managers (be it a big event such as a conference or small event as in committee meeting) in preparing by having the option to identify specific tasks with identifiable outcomes or outputs.

Go to the readable blog post here.

Friday, May 15, 2009

Online Journal Options

The Office of the Dean is currently looking into the feasibility of setting of up an online journal. It might be an online version of the UP Manila Journal or a college-based peer-reviewed journal.

An online journal is not that difficult to implement--thanks to open source systems. And the idea is not that too alien, either. UP Diliman and UP Los Banos both have online journals using the system provided by the Public Knowledge Project.

There are two ways to implementing the Open Journal System (OJS):
  • You can set up the journal which INASP will host (easier to maintain--if at all--but may be a bit long to initiate due to legal requirements, but not so much).
  • Download the OJS code to the organization's server and implement it from their end (might need a bit of technical know-how, but is faster as the code is available at the site).
Either way, the system allows the journal organization to publish articles and share knowledge to a wider audience (talk about the world) without investing a lot. Further, if the journal is added to the online directory of online journals (eg Open Science Directory and Directory of Open Access Journals), the journal is connected to a global network of knowledge seekers. This helps the journal (and the supporting or host organization) highlight (if not promote) the expertise of its members or researchers, and--more importantly--the knowledge is shared with those who need it. Hopefully, this knowledge-sharing attitude will result in more effective and efficient ways of resolving concerns the journal organization seeks to address.

The online journal promises many benefits that the printed version cannot give. It even reduces the required library space for journals, and the journal is accessible anytime (no need to have the library open 24 hours). Of course, I like reading from a piece of paper or book, but you can always print the online journal (reducing the cost of printing for the organization).

Sources:
Public Knowledge Project
International Network for the Availability of Scientific Publications or INASP
Open Science Directory
Directory of Open Access Journals
UP Diliman Journals Online
UPLB Journals Online

Acquiring and Managing Electronic Journals. ERIC Digest.
"Electronic Journal Frequently Asked Questions" Prifysgol Aberystwyth University.

All links accessed May 16, 2009.