<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paper Jammed &#187; Security</title>
	<atom:link href="http://paperjammed.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://paperjammed.com</link>
	<description>Has paper taken over your life?</description>
	<lastBuildDate>Wed, 30 Jun 2010 02:14:53 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Don&#8217;t let weak passwords take you down!</title>
		<link>http://paperjammed.com/2010/06/29/dont-let-weak-passwords-take-you-down/</link>
		<comments>http://paperjammed.com/2010/06/29/dont-let-weak-passwords-take-you-down/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 02:14:53 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Good Sites]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=1020</guid>
		<description><![CDATA[I was recently searching for some material related to password generation and stumbled on a blog post from a few years ago that contains some very candid and eye-opening discussion on password security.
How I&#8217;d Hack Your Weak Passwords (onemansblog.com)
The author starts off with a list of the top ten passwords, and how he would go [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1025" title="safe lock" src="http://paperjammed.com/wp-content/uploads/2010/06/iStock_000007608737XSmall-200x300.jpg" alt="iStockphoto" width="200" height="300" />I was recently searching for some material related to password generation and stumbled on a blog post from a few years ago that contains some very candid and eye-opening discussion on password security.</p>
<p><a href="http://onemansblog.com/2007/03/26/how-id-hack-your-weak-passwords/">How I&#8217;d Hack Your Weak Passwords</a> (onemansblog.com)</p>
<p>The author starts off with a list of the top ten passwords, and how he would go about finding the personal information needed. For example, number 1 is &#8220;Your partner, child, or pet’s name, possibly followed by a 0 or 1 (because they’re always making you use a number, aren’t they?)&#8221; and number 2 is &#8220;The last 4 digits of your social security number.&#8221;</p>
<p>The really interesting bits are when the author explains exactly how he would approach hacking your accounts, and how likely he would be to succeed. Unfortunately, the tools needed to engage in this kind of mischief are readily available and do not require great skill to employ.</p>
<p>Some key protection points include&#8230;</p>
<ul>
<li>Don&#8217;t use the same password for all of your online activities. Use different passwords for each site. That way, if your Facebook password is compromised, your Wachovia password is safe.</li>
<li>Never use dictionary words, names, or other common passwords.</li>
<li>Look for a trusted password management utility to help ease the pain of having a hundred different passwords.</li>
<li>Your email is one of the most important and critical passwords—a criminal can use the &#8220;reset my password&#8221; feature on many shopping sites once they have access to your email account.</li>
</ul>
<p>Take a look at the article and see if you can make some changes in the way you handle password security so that you don&#8217;t get hacked!</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/06/29/dont-let-weak-passwords-take-you-down/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is there anything interesting lingering on your clipboard?</title>
		<link>http://paperjammed.com/2010/01/28/is-there-anything-interesting-lingering-on-your-clipboard/</link>
		<comments>http://paperjammed.com/2010/01/28/is-there-anything-interesting-lingering-on-your-clipboard/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 04:40:19 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=867</guid>
		<description><![CDATA[A few weeks ago I pulled up a chair in front of an aging computer that is shared by many volunteers in order to log their work and do occasional web searches. After an hour or so of doing paperwork, I wanted to look something up on Google, so I selected the word and hit [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-868" title="www Search" src="http://paperjammed.com/wp-content/uploads/2010/01/iStock_000010018988XSmall-300x198.jpg" alt="" width="300" height="198" />A few weeks ago I pulled up a chair in front of an aging computer that is shared by many volunteers in order to log their work and do occasional web searches. After an hour or so of doing paperwork, I wanted to look something up on Google, so I selected the word and hit <strong>Control-C</strong> to copy it and quickly pasted it into the Google search bar, only to be greeted with an unusual error from Google saying that my search text was too long.</p>
<p>And the bits of the search string I saw had nothing to do with what I had copied. Clearly my <strong>Control-C</strong> did not “take” and I had pasted whatever stuff had been hanging around from the prior user.<br />
My curiosity got the better of me and I opened Notepad and did a quick <strong>Control-V</strong> and watched in amazement as a young girl’s secrets were exposed before my eyes.</p>
<p>She is clearly struggling in her relationship with her boyfriend, because she had listed about fifty bad points about him in detail—and some were pretty bad. She then listed a dozen or so good points at the bottom. And I must admit that I read the whole story…and felt a voyeuristic guilt with each word.</p>
<p>I then closed Notepad and purged the clipboard and felt much better.<br />
Of course, that doesn’t change the fact that I will feel uncomfortable the next time I see her. I feel like I snuck into her room and read her diary.</p>
<p>This is what she had done: She had written her personal note in Word or some other tool and then likely decided to email it to herself, so she copied and pasted the sordid details of her love life into Gmail, forgetting to purge the clipboard before going home.</p>
<p>And I, with no malice or intent, bumbled into her secrets.</p>
<p><strong>Learn from the mistakes of others!</strong></p>
<p>When was the last time you used a public computer at the library or worked on a common computer at school or work? Did you leave anything behind?</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/01/28/is-there-anything-interesting-lingering-on-your-clipboard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Could your family access your secrets in an emergency?</title>
		<link>http://paperjammed.com/2010/01/10/could-your-family-access-your-secrets-in-an-emergency/</link>
		<comments>http://paperjammed.com/2010/01/10/could-your-family-access-your-secrets-in-an-emergency/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 18:59:10 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Green Living]]></category>
		<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Knowledge Management]]></category>
		<category><![CDATA[Tips]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=851</guid>
		<description><![CDATA[Several weeks ago I was sitting at the dining room table with a family friend going through a stack of documents and letters. Her husband had passed away suddenly some weeks before, and I was doing the best I could to help her untangle the paperwork and understand what was what. This unfortunate scene made [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-853" title="Keys on a keyboard" src="http://paperjammed.com/wp-content/uploads/2010/01/iStock_000008796911XSmall-225x300.jpg" alt="" width="225" height="300" />Several weeks ago I was sitting at the dining room table with a family friend going through a stack of documents and letters. Her husband had passed away suddenly some weeks before, and I was doing the best I could to help her untangle the paperwork and understand what was what. This unfortunate scene made it clear to me that sudden illness or death of a family member may require us to access files that they have, for many reasons.</p>
<p>Imagine that you were to become temporarily incapacitated for whatever reason&#8230;</p>
<ul>
<li>Can a family member log in to your computer, as yourself, in order to access your files?</li>
<li>Can your spouse access your online banking details so the bills can be paid?</li>
<li>Can your family find your insurance information that you scanned and filed away?</li>
<li>Is there someone who can log in to any online accounts that need care and feeding?</li>
</ul>
<p>Not a pleasant subject, indeed, but one that worries me from time to time.</p>
<p>One way to address these needs is to keep all of your passwords and so forth in one special place, using a password safe application, and make sure someone else has the access code. For example, you can use a tool such as <a href="http://agilewebsolutions.com/products/1Password">1Password</a> or <a href="http://www.splashdata.com/splashid/index.asp">SplashId</a> to store hundreds of secret bits that you use all the time, and your family might need.</p>
<p>You might consider writing down the master passwords that control your life and sealing them in an envelope that you provide to a trusted family member. Since this is such a great security risk if found by the enemy, you might want to omit any identifying information from the note. Impress upon them the need to secure the document very well.</p>
<p>Perhaps you can choose the same master password with your spouse, with one relatively short password locking your computer and a long secure password locking your password safe application.</p>
<p>Regardless of how you address these issues, sit down with your better half (or trusted family member) and review where documents are and how to access them.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2010/01/10/could-your-family-access-your-secrets-in-an-emergency/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t worry if you didn&#8217;t sanitize your documents—even the TSA forgets occasionally</title>
		<link>http://paperjammed.com/2009/12/08/dont-worry-if-you-didnt-sanitize-your-documents%e2%80%94even-the-tsa-forgets-occasionally/</link>
		<comments>http://paperjammed.com/2009/12/08/dont-worry-if-you-didnt-sanitize-your-documents%e2%80%94even-the-tsa-forgets-occasionally/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 22:29:29 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Searching and Indexing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Shredding]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=796</guid>
		<description><![CDATA[It&#8217;s too comical to be true. A few months back, when I wrote an article warning about inadequate attempts at sanitizing PDF documents, I thought that any organization serious about censoring documents would not make such a basic error. Especially not a government agency, after the military had been caught by this pitfall.
Apparently this is [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-797" title="20091208-redaction1" src="http://paperjammed.com/wp-content/uploads/2009/12/20091208-redaction1.gif" alt="20091208-redaction1" width="361" height="280" />It&#8217;s too comical to be true. A few months back, when I wrote an article <a href="http://paperjammed.com/2009/04/21/keeping-your-secrets-to-yourself—what-can-your-shared-documents-tell-others/">warning about inadequate attempts at sanitizing PDF documents</a>, I thought that any organization serious about censoring documents would not make such a basic error. Especially not a government agency, after the military <a href="http://www.schneier.com/blog/archives/2005/05/pdf_radacting_f.html">had been caught</a> by this pitfall.</p>
<p><a href="http://www.wanderingaramean.com/2009/12/tsa-makes-another-stupid-move.html">Apparently this is not the case</a></p>
<p>It seems that the TSA has leaked their official document of airport security guidelines. ABC News says <a href="http://abcnews.go.com/Blotter/massive-tsa-security-breach-agency-secrets/story?id=9280503">Online Posting Reveals a &#8220;How To&#8221; for Terrorists to Get Through Airport Security</a></p>
<p><a href="http://abcnews.go.com/Blotter/massive-tsa-security-breach-agency-secrets/story?id=9280503"></a><span id="more-796"></span></p>
<p><strong>A Rookie Mistake</strong></p>
<p>Look at the screenshot of the document at the top of this post. Even though a certain part of the document has been blacked out, it is possible to select the text and copy/paste to find out what is hidden behind the black text.</p>
<p>What kinds of things are listed in this document?</p>
<ul>
<li>Photographs of all kinds of official ID cards. Ever wondered what a U.S. Senator&#8217;s ID card looks like?</li>
<li>Procedures for calibrating equipment, such as where guns should be hidden for the testing and such.</li>
<li>Guidelines for who gets searched and who doesn&#8217;t.</li>
<li>Guidelines for what objects get searched and which don&#8217;t.</li>
<li>And much much more!</li>
</ul>
<p>In other words, this was a most unfortunate event.</p>
<p>See for yourself—ABC News (and others) have <a href="http://a.abcnews.go.com/images/Blotter/ht_tsa_screening_2_091208.pdf">posted the document with redactions removed</a>.</p>
<p><strong>Easy as Pie</strong></p>
<p>Here&#8217;s a screenshot of the original document, opened in Adobe Acrobat Professional.</p>
<p><img class="alignnone size-full wp-image-801" title="20091208-redaction2" src="http://paperjammed.com/wp-content/uploads/2009/12/20091208-redaction2.gif" alt="20091208-redaction2" width="500" height="197" /></p>
<p>As you can see, it was a trivial matter to use the <strong>TouchUp Object</strong> tool to gently slide the black rectangle off of the secret stuff (I have blurred the text here, though you can read it from ABC News if you wish).</p>
<p>If you are working with confidential documents that could potentially cause disaster if leaked, <em>please</em> learn how to redact your documents correctly!</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/12/08/dont-worry-if-you-didnt-sanitize-your-documents%e2%80%94even-the-tsa-forgets-occasionally/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keeping your secrets to yourself—old changes lingering in your PDF files</title>
		<link>http://paperjammed.com/2009/11/23/keeping-your-secrets-to-yourself-old-changes-lingering-in-your-pdf-files/</link>
		<comments>http://paperjammed.com/2009/11/23/keeping-your-secrets-to-yourself-old-changes-lingering-in-your-pdf-files/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 04:46:58 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Geeky]]></category>
		<category><![CDATA[PDF]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=781</guid>
		<description><![CDATA[A few months ago I wrote an article that touched upon the problems inherent in attempts to sanitize documents before sending them to the enemy—perhaps to remove competitor&#8217;s names or trade secrets.
I was reading a post on a board I frequent where a person was describing exactly this kind of activity—removing sensitive information from PDF [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-791" title="Rusty trap" src="http://paperjammed.com/wp-content/uploads/2009/11/iStock_000011076402XSmall-300x225.jpg" alt="Rusty trap" width="300" height="225" />A few months ago I wrote an article that touched upon <a href="http://paperjammed.com/2009/04/21/keeping-your-secrets-to-yourself—what-can-your-shared-documents-tell-others/">the problems inherent in attempts to sanitize documents</a> before sending them to the enemy—perhaps to remove competitor&#8217;s names or trade secrets.</p>
<p>I was reading a post on a board I frequent where a person was describing exactly this kind of activity—removing sensitive information from PDF documents. Several suggestions were made, but one individual suggested opening the file in Acrobat Pro and replacing the sensitive text with good old <a href="http://www.lipsum.com/">Lorem Ipsum</a>.</p>
<p>It was at that moment that I recalled a peculiar feature of the PDF file format: it is designed to support nondestructive updates, allowing people to make vast changes to a PDF document while still retaining the original document, fully intact. I did a few experiments and was surprised with the results.<span id="more-781"></span></p>
<p><strong>A Brief Note on the PDF File Format</strong></p>
<p>For the geeky types among us, one place to begin is this article:</p>
<p><a href="http://www.mactech.com/articles/mactech/Vol.15/15.09/PDFIntro/">Portable Document Format: An Introduction for Programmers</a></p>
<p>The key points to get out of the article is this: A PDF document is comprised of several distinct sections, a <strong>Header</strong>, a <strong>Body</strong>, an <strong>&#8220;xref&#8221; Table</strong>, and a <strong>Trailer</strong>. At the very end of the file you will find the character sequence <strong>%%EOF</strong></p>
<p>The PDF standard was designed to allow multiple updates to a document, while retaining the original version. This is accomplished by appending anything new to the end of the document, after the original <strong>EOF</strong> tag. The document will now have two <strong>EOF</strong> tags: one indicating where the original document ended, and a new <strong>EOF</strong> tag indicating where the new changes end.</p>
<p>If we wish to revert PDF changes, it should be a simple matter of opening the PDF file in a binary editor, searching for the first <strong>EOF</strong> tag, and deleting everything following.</p>
<p><strong>A Simple Experiment</strong></p>
<p>Let&#8217;s start with a proper secret document containing missile plans&#8230;</p>
<p><img class="alignnone size-full wp-image-785" title="20091123-missile-plans-1" src="http://paperjammed.com/wp-content/uploads/2009/11/20091123-missile-plans-1.gif" alt="20091123-missile-plans-1" width="439" height="418" /></p>
<p>Suppose we want to obscure some special information in paragraph 37. We can open the file in Acrobat Professional and use its text editing features to swap in the venerable <em>Lorem Ipsum</em> text.</p>
<p>Here&#8217;s what it looks like after the switch:</p>
<p><img class="alignnone size-full wp-image-786" title="20091123-lorem-ipsum" src="http://paperjammed.com/wp-content/uploads/2009/11/20091123-lorem-ipsum.gif" alt="20091123-lorem-ipsum" width="598" height="243" /></p>
<p>You can see here that the first seven lines of text starting on paragraph 37 have been replaced with appropriate unreadable text.</p>
<p>Now, open the new PDF file in a binary editor (since PDF files contain a mix of text and binary, the editor must be a binary editor).</p>
<p><img class="alignnone size-full wp-image-787" title="20091123-binary-editor" src="http://paperjammed.com/wp-content/uploads/2009/11/20091123-binary-editor.gif" alt="20091123-binary-editor" width="693" height="633" /></p>
<p>Note the <strong>%%EOF</strong> character sequence embedded in the text. This is the first <strong>EOF</strong> tag, indicating where the original file ended. All we need to do is place the cursor to the right of the <strong>EOF</strong> and delete everything to the end of the file.</p>
<p>Once we have done so, it&#8217;s like magic:</p>
<p><img class="alignnone size-full wp-image-788" title="20091123-after-binary-editing" src="http://paperjammed.com/wp-content/uploads/2009/11/20091123-after-binary-editing.gif" alt="20091123-after-binary-editing" width="794" height="323" /></p>
<p>The edits that replaced lines of paragraph 37 with gibberish have neatly been undone!</p>
<p><strong>More Details</strong></p>
<p>From the <a href="http://www.mactech.com/articles/mactech/Vol.15/15.09/PDFIntro/">PDF Intro document</a> linked earlier:</p>
<p>&#8220;The trailer, it turns out, plays an important role in the way PDF implements incremental updating. The key concept to understand here is that a PDF file is never overwritten, only added to. That goes for all portions of the PDF file &#8211; even the trailer itself, and the end-of-file marker. In other words, a multiply-updated PDF document may contain multiple trailers &#8211; and multiple end-of-file markers! (There may be numerous occurrences of %%EOF.) Each time the file is edited, an addendum is written to the tail of the file, consisting of the content objects that have changed, a new xref section, and a new trailer containing all the information that was in the previous trailer, as well as a /Prev key specifying the byte offset (from the beginning of the file) of the previous xref section. The cross-reference info will then be distributed across more than one xref section. To access all of the cross-references, the reader must walk the list of /Prev keys in all the trailers, in reverse order.</p>
<p>Space doesn&#8217;t permit a detailed exploration of updates here, but you can find several examples in Appendix A of the PDF 1.3 specification (available at <a href="http://partners.adobe.com/asn/developer">http://partners.adobe.com/asn/developer</a>).&#8221;</p>
<p><strong>Summary</strong></p>
<p>It is important to understand that the PDF standard allows for appended updates to files that leave the original document intact, regardless of how drastic the changes are. If you are intent on redacting text from PDF documents, do not depend on simply deleting the secrets using a PDF editor—you must use a proper redaction tool that addresses these issues correctly.</p>
<p>That said, I did some experimenting with a few utilities (Apple Preview, PDFpen, and Adobe Acrobat Pro) and found that some write the file from scratch each time, with no lingering cruft from former versions, while others respect the original intent of the PDF standard. This means that you can&#8217;t trust that older revisions are being retained in your file and you can&#8217;t trust that they aren&#8217;t.</p>
<p>Be conservative: use a redaction tool for secrecy and proper backups for versioning.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/11/23/keeping-your-secrets-to-yourself-old-changes-lingering-in-your-pdf-files/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>HowStuffWorks — How Paperless Offices Work</title>
		<link>http://paperjammed.com/2009/07/03/howstuffworks-%e2%80%94-how-paperless-offices-work/</link>
		<comments>http://paperjammed.com/2009/07/03/howstuffworks-%e2%80%94-how-paperless-offices-work/#comments</comments>
		<pubDate>Sat, 04 Jul 2009 00:30:42 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Green Living]]></category>
		<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Workflow]]></category>
		<category><![CDATA[Good Sites]]></category>
		<category><![CDATA[Indexing]]></category>
		<category><![CDATA[Online Services]]></category>
		<category><![CDATA[Organization]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=594</guid>
		<description><![CDATA[
I have always been a big fan of HowStuffWorks, with their detailed in-depth articles describing such disparate topics as manual transmissions and money laundering.
Anyway, author Diane Dannenfeldt has written a lengthy article on How Paperless Offices Work, giving ample coverage to myriad aspects of the topic:

Introduction to How Paperless Offices Work
Benefits of a Paperless Office
Transitioning [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-full wp-image-595 alignnone" src="http://paperjammed.com/wp-content/uploads/2009/07/20090703-howstuffworks.jpg" alt="20090703-howstuffworks" width="492" height="352" /></p>
<p>I have always been a big fan of HowStuffWorks, with their detailed in-depth articles describing such disparate topics as <a href="http://auto.howstuffworks.com/transmission.htm">manual transmissions</a> and <a href="http://money.howstuffworks.com/money-laundering.htm">money laundering</a>.</p>
<p>Anyway, author Diane Dannenfeldt has written a lengthy article on How Paperless Offices Work, giving ample coverage to myriad aspects of the topic:</p>
<ul>
<li>Introduction to How Paperless Offices Work</li>
<li>Benefits of a Paperless Office</li>
<li>Transitioning to a Paperless Office</li>
<li>Managing Digital Documents</li>
<li>Going Paperless at Home</li>
<li>Paperless Office Solutions</li>
</ul>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Introduction to HoPaperless Offices Work</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Benefits of a Paperless Office</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Transitioning to a Paperless Office</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Managing Digital Documents</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Going Paperless at Home</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Paperless Office Solutions</div>
<p>Take a look at the full article here: <a href="http://communication.howstuffworks.com/how-paperless-offices-work.htm">How Paperless Offices Work</a> (howstuffworks.com)</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/07/03/howstuffworks-%e2%80%94-how-paperless-offices-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Banish the kids to their own network!</title>
		<link>http://paperjammed.com/2009/06/02/banish-the-kids-to-their-own-network/</link>
		<comments>http://paperjammed.com/2009/06/02/banish-the-kids-to-their-own-network/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 00:16:43 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Geeky]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Portable Devices]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=557</guid>
		<description><![CDATA[A nastygram from my ISP let me know that I needed to take action to lock down my home network. In this article I discuss using a spare router in a somewhat unusual daisy chain configuration in order to banish the teenagers and all of their wifi devices to their own network.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-560" src="http://paperjammed.com/wp-content/uploads/2009/06/istock_000006562749xsmall-300x210.jpg" alt="" width="300" height="210" />A few weeks ago I received an unpleasant bit of email from my Internet provider. At first, I thought it was yet another lame spammer or phisher sending me some official-looking notice, but after a moment&#8217;s inspection I realized that this was a real <em>bona-fide </em>official notice.</p>
<p>Their network security department very kindly (and politely) informed me that they had received a &#8220;cease and desist&#8221; order from a particular game publisher. They had included the game publisher&#8217;s email, complete with the incriminating evidence.</p>
<p>There it was: logs showing the MAC address of my cable modem being involved in suspicious <a href="http://en.wikipedia.org/wiki/BitTorrent_(protocol)">BitTorrent</a> activities.</p>
<p>Considering that at any time during the week there can be from two to six or seven different teenagers hanging out in my humble abode, carrying virus-ridden machines, the message was clear: I had to get serious about locking down network access<span id="more-557"></span></p>
<p><strong>The Problem</strong></p>
<p>I would have liked to have bought some net filtering software to slap on the offending machine and been done with it, however I knew that this was insufficient.</p>
<p>Even if this one event could be traced to a youthful source, a more ominous danger comes from the inevitable malware and viruses that teenagers collect on their machines as they swap cool stuff with their friends.</p>
<p>Complicating things, there are many devices on our home network: Besides their school laptops, the kids have video game consoles and one has an iPod touch, all with wifi access. Think about how many different gadgets are on <em>your</em> home network.</p>
<p>And shutting off access altogether was not an option—there is still schoolwork to be done!</p>
<p><strong>The answer: A Private Network for the Kids</strong></p>
<p>My solution was to put together an unusual network configuration using a second wireless router; I wanted the ability to manage every single kid-owned device at the flip of a switch, while leaving the grownups untouched.</p>
<p><img class="aligncenter size-full wp-image-568" src="http://paperjammed.com/wp-content/uploads/2009/06/20090602-network-devices.gif" alt="" width="600" height="550" /></p>
<p>I hooked the cable modem (<strong>red</strong>) to the main router, shown in <strong>green</strong>. I then plugged a second wireless router, shown in <strong>blue</strong>, into the first.</p>
<p>By doing this, you can see that there is <em>one single wire</em> connecting the entire <strong>blue</strong> network (the kids) to the <strong>green</strong> network. It was trivial to then configure the green<em> </em>router with appropriate access control and filtering for that one single device: the blue router.</p>
<p><strong>Some quirky details</strong></p>
<p>Home routers like these are, by default, configured with a <a href="http://en.wikipedia.org/wiki/Network_address_translation">NAT</a> firewall. They work sort of like one-way mirrors: someone on the network can see out, but nobody can see in. As a result of this, the kids (<strong>blue</strong> devices) can see any device on the main router (<strong>green</strong> devices), such as our print server and the NAS device, but no one can see <em>into</em> the kids&#8217; network.</p>
<p>As paradoxical as it seems, this is exactly what I wanted. By making the kids&#8217; network a private network, it appears to the green router as a single device. When I am configuring access restrictions, I only need to control access for the blue router&#8217;s IP address or MAC address.</p>
<p>Many consumer-grade routers have flakey firmware that just doesn&#8217;t really behave well when you start doing things like turning on filtering for multiple machines. I simplified things by bringing down the number of controlled devices to <em>one</em>. In addition, if one were to try filtering on the IP addresses or MAC addresses of individual machines, this can be easily defeated by manually changing the IP address or MAC address. With my configuration, the MAC address being filtered is the blue router, locked away safely.</p>
<p><strong>The Finer Points</strong></p>
<p>If you want to set up a network like this, do the following:</p>
<ul>
<li>(Recommended) Reset the kids&#8217; router. Hold the hard reset button on the router in while you turn on power; hold the button for 15 seconds or so.</li>
<li>Hook the kids&#8217; router up to a spare laptop using an Ethernet cable. (Turn off the wireless of the laptop for the time being).</li>
<li>Use the laptop to navigate to the configuration web page (usually 192.168.1.1).</li>
<li>Set the router&#8217;s own address to a <em>different</em> network from the main network, such as 192.168.<strong>2</strong>.1. <em>This is critical</em>.</li>
<li>Configure the router&#8217;s gateway and DHCP server entries to all point to the <em>main</em> router (192.168.1.1). This tells the kids&#8217; router to use the main router as a source for its DHCP lookups and such, rather than going to cable modem.</li>
<li>Navigate to the configuration web page at the new address (192.168.2.1). You may need to close the browser and replug the Ethernet cable.</li>
<li>Set up your wireless security for the kids however you like. Make sure to choose a different channel and SSID from your main router.</li>
<li>Remove the laptop and plug the WAN port of the kids&#8217; router into one of the LAN ports of the main router. Restart everything.</li>
<li>Test both networks to make sure things work the way you think they should.</li>
<li>(Optional) You might want to connect to the kids&#8217; router and set it&#8217;s external IP address statically. Make sure that this is set to a number on the home network (e.g. 192.168.1.2).</li>
</ul>
<p>Some notes:</p>
<ul>
<li>You can only maintain the kids&#8217; router from a machine connected to the kids&#8217; network; the home network cannot see the management screens. If you wish, you could enable remote management for the kids&#8217; network only, since the main home router is still protecting the whole network from intruders.</li>
<li>Computers on the kids&#8217; network can see all devices, but they aren&#8217;t on the same network. This means that network printers and NAS devices are accessible, but you will have to attach to them using IP addresses. I was able to easily set up the machines on the 192.168.2.1 network to use a print server on 192.168.1.100.</li>
<li>For machines that should have full access (a.k.a. <em>yours</em>), make sure that you either set the <strong>green</strong> network to be a higher priority or remove the <strong>blue</strong> network SSID entry altogether. I found out the hard way that my iMac would randomly pick the green or the blue depending on which one it saw first when it woke up.</li>
<li>This does <em>not</em> wall off your main network; it simply provides a single point of control to the entire kids&#8217; network. In other words, don&#8217;t depend on this setup to prevent malware on the kids machines from seeing your machine. You can, however, set up your PC to not trust the kids&#8217; network.</li>
</ul>
<p><strong>Wireless Network Security</strong></p>
<p>Regardless of how you set up your network, make sure you use at least WPA encryption (Never use WEP!). Make sure your passwords are solid.</p>
<p><strong>Using DD-WRT on my new wireless router</strong></p>
<p>In addition to the new network configuration, I went one step further and chose a main router that lends itself well to installation of open-source firmware. I ordered a <a href="http://www.amazon.com/Linksys-Cisco-WRT54GL-Wireless-G-Broadband-Compatible/dp/B000BTL0OA/ref=sr_1_1?ie=UTF8&amp;s=electronics&amp;qid=1243905597&amp;sr=8-1">Linksys WRT54GL</a> from Amazon for a little over fifty bucks. I chose this one because, as a direct descendent of the venerable <a href="http://en.wikipedia.org/wiki/WRT54G">WRT54G</a>, this router is very well suited for running alternative firmware such as <a href="http://en.wikipedia.org/wiki/Dd-wrt">DD-WRT</a>, giving substantial control over things like, say, access control&#8230;</p>
<p>Within a half hour after my new router arrived, I had gone to the <a href="http://www.dd-wrt.com/dd-wrtv3/dd-wrt/hardware.html">Supported Hardware</a> page, obtained the latest build of DD-WRT, and replaced the Linksys firmware with the far-better open source code.</p>
<p>I won&#8217;t go into the specifics of installation here, but it isn&#8217;t very challenging. Check out the <a href="http://www.dd-wrt.com/dd-wrtv3/index.php">DD-WRT site</a> for details.</p>
<p><strong>Closing Thoughts</strong></p>
<p>Make no mistake: we are responsible for whatever goes on our home networks. Just like your home telephone; if someone dials up some 900 number and rings up a thousand-dollar phone bill, the phone company won&#8217;t care a whit who did it, you will still pay. Likewise, regardless of who did the BitTorrent download, there is a certain degree of responsibility of the homeowner to lock down the network.</p>
<p>Another point: Without some degree of personal responsibility on the part of the kids in the house, this sort of activity would simply be an arms race of filtering and blocking versus hacking. My goal is to help keep the honest people honest and to make life more difficult for the viruses and malware.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/06/02/banish-the-kids-to-their-own-network/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>A cheap and cheerful way to reduce Internet surprises</title>
		<link>http://paperjammed.com/2009/05/26/a-cheap-and-cheerful-way-to-reduce-internet-surprises/</link>
		<comments>http://paperjammed.com/2009/05/26/a-cheap-and-cheerful-way-to-reduce-internet-surprises/#comments</comments>
		<pubDate>Tue, 26 May 2009 21:51:14 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Geeky]]></category>
		<category><![CDATA[Good Sites]]></category>
		<category><![CDATA[Online Services]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Reviews]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=539</guid>
		<description><![CDATA[Anyone who has kids in their home worries about how easy it is to access the seamier side of the Internet, even if by accident. Indeed, it is thrust upon us in our email in-boxes daily in the form of misspelled spam with links that only a fool would click.
Another issue altogether is the spam [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-542" src="http://paperjammed.com/wp-content/uploads/2009/05/istock_000000230827xsmall-300x199.jpg" alt="" width="300" height="199" />Anyone who has kids in their home worries about how easy it is to access the seamier side of the Internet, even if by accident. Indeed, it is thrust upon us in our email in-boxes daily in the form of misspelled spam with links that only a fool would click.</p>
<p>Another issue altogether is the spam email that is carefully crafted to appear as if it has come from your bank, saying cheerfully &#8220;Your statement for May is available online, just click here to access!&#8221; &#8230; but whoever clicks will inevitably be providing their secrets to some ne&#8217;er-do-well in New Zealand who will promptly empty their accounts.</p>
<p>Here is a simple, quick, and free way to avoid phishing attacks as well as casual/accidental exposure to unwanted adult content.<span id="more-539"></span></p>
<p><strong>OpenDNS</strong></p>
<p>The service I am referring to is <a href="http://www.opendns.com/">OpenDNS</a>, a free domain name lookup service that you can use in lieu of your Internet Service Provider&#8217;s own DNS servers.</p>
<p>When your computer goes to a web site, the name of the web site must be converted to a numeric address, in much the same way that you use a telephone directory to look up a friend&#8217;s number.</p>
<p>This lookup service is typically provided by a server owned by your Internet Service Provider. The address to this server is automatically configured when your cable modem connects to the network the first time.</p>
<p>The way OpenDNS works is you change the Domain Name Server (DNS) setting in your router to now point to the OpenDNS servers instead of your ISP servers. By doing this, you have changed the default telephone directory used by your home network.</p>
<p><strong>A Phone book with the Bad Numbers Missing</strong></p>
<p>To take the phone book analogy further, imagine that in your new phone book, all of the phone numbers for shady businesses such as escort services and massage parlors have been replaced with a special number. When you dial that number, a pleasant older woman gives you a gentle scolding for trying to call such a business.</p>
<p>This is pretty much what happens with OpenDNS: when your browser asks for a page from www.naughtystuff.com, the OpenDNS server points you to a different place, a nice page from OpenDNS that says that the page is blocked and explains why.</p>
<p><strong>One fix for your Entire Network</strong></p>
<p>There are many options available for &#8220;net nanny&#8221; style software that can be installed on individual machines, such as the kids&#8217; machine. These features are also embedded in modern versions of Windows and OS X. But, what about all of the little portable devices that find themselves into kids&#8217; hands? How about their gaming consoles?</p>
<p>Since you configure OpenDNS at the network entry point to your home, the router, any device attached to your network is automatically covered.</p>
<p><strong>Customizable Blocking</strong></p>
<p>You can use OpenDNS without an account, just by pointing your router to their servers, but the real power comes when you register with them (for free) and make your own choices about what you want to see.</p>
<p>You can choose which parts of the Internet you don&#8217;t want to see using their online configuration tool. You can either use their &#8220;High/Moderate/Medium/Low/Minimal&#8221; options or you can pick and choose individual bits of stuff to allow or block.</p>
<p><img class="aligncenter size-full wp-image-545" src="http://paperjammed.com/wp-content/uploads/2009/05/20090526-opendns1.gif" alt="" width="583" height="589" /></p>
<p>Here&#8217;s a look at the categories available when you choose the custom blocking level:</p>
<p><img class="aligncenter size-full wp-image-546" src="http://paperjammed.com/wp-content/uploads/2009/05/20090526-opendns2.gif" alt="" width="393" height="337" /></p>
<p><strong>Basic Setup (about 20 minutes)</strong></p>
<ul>
<li><a href="https://www.opendns.com/start/">Configure your router</a> to use the OpenDNS servers for DNS lookups.</li>
<li>Create a free <a href="https://www.opendns.com/start/create_account/">OpenDNS account</a>.</li>
<li>Install their <a href="http://www.opendns.com/support/article/90">small updater program</a> on one machine on your network.</li>
<li>Log in to your <a href="https://www.opendns.com/dashboard/">OpenDNS Dashboard </a>on the web and configure your blocking settings to taste.</li>
</ul>
<p><strong>Why do you need the updater utility?</strong></p>
<p>In order to provide the custom blocking, the OpenDNS servers need to know your main IP address assigned by your Internet Server Provider. The desktop utility simply informs OpenDNS of your new IP address if it ever changes.</p>
<p><strong>What do users see if they go to a blocked page?</strong></p>
<p>They see a page that indicates the site that was blocked, along with a short reason and a link they can click if they want access to the page. If they click that link and fill out the short form, you will get an email from OpenDNS with the user&#8217;s request.</p>
<p>The remainder of the &#8220;blocked&#8221; page is a search form with some sponsored links.</p>
<p>You can customize the message as well as the image shown on the web page. When someone reaches a blocked page in my network, they are greeted by a picture of our calico cat, Roxy.</p>
<p><img class="aligncenter size-full wp-image-547" src="http://paperjammed.com/wp-content/uploads/2009/05/20090526-opendns3.gif" alt="" width="531" height="556" /></p>
<p><strong>Keeping the Honest People Honest</strong></p>
<p>This approach to blocking unwanted web sites is not a complete solution for keeping your kids from where they shouldn&#8217;t go; it is more like a simple padlock: it keeps the honest people honest. A determined individual can easily get around this product using various techniques, but they have to make a conscious effort to do so.</p>
<p>The real strength of OpenDNS is that it helps avoid accidental exposure to unwanted web content and phishing sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/05/26/a-cheap-and-cheerful-way-to-reduce-internet-surprises/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Keeping your secrets to yourself—what can your shared documents tell others?</title>
		<link>http://paperjammed.com/2009/04/21/keeping-your-secrets-to-yourself%e2%80%94what-can-your-shared-documents-tell-others/</link>
		<comments>http://paperjammed.com/2009/04/21/keeping-your-secrets-to-yourself%e2%80%94what-can-your-shared-documents-tell-others/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 02:23:16 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Paperless Life]]></category>
		<category><![CDATA[Scanning]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Good Sites]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=505</guid>
		<description><![CDATA[Do you ever send documents to other people that might have &#8230; sensitive information embedded in them?
Not everyone who works with documents in the home will run into this problem, but sooner or later you are probably going to find yourself in a situation where you would like to email someone a useful document that [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-507" src="http://paperjammed.com/wp-content/uploads/2009/04/istock_000004573310xsmall-300x199.jpg" alt="" width="300" height="199" />Do you ever send documents to other people that might have &#8230; sensitive information embedded in them?</p>
<p>Not everyone who works with documents in the home will run into this problem, but sooner or later you are probably going to find yourself in a situation where you would like to email someone a useful document that just happens to have your social security number embedded in it, or your full name and address, or some other info that you would rather keep private.</p>
<p>This process of editing documents to remove sensitive content is referred to as <em>redaction</em>—that&#8217;s the keyword you probably want to be searching for as you tip toe through Google for guidance.</p>
<p>In this article I discuss the obvious problems we face using the most naïve approach toward document redaction, and provide some resources for better options.<span id="more-505"></span></p>
<p><strong>The only sure way</strong></p>
<p>The only absolutely certain way of guaranteeing that you cut out secret information would be to print the document, physically cut out the bad bits, scan in the document, and send the scanned PDF to your colleague. This may seem a bit extreme, but if you were an anonymous tipster sending the media a document full of mob-related evidence, containing <em>your name</em>, you might go this route (You probably don&#8217;t want to send the email from your personal account. Try a throwaway email account at the library.)</p>
<p><strong>Other options&#8230; Microsoft Word</strong></p>
<p>Don&#8217;t even think about sending a raw MS Word document to your recipient. There&#8217;s <a href="http://www.usatoday.com/tech/columnist/kimkomando/2006-01-19-hidden-msword-data_x.htm">loads of hidden stuff</a> within those documents that you might forget. If you really must, you can look into some <a href="http://support.microsoft.com/kb/223396">recommendations from Microsoft</a>, and consider tools such as Microsoft&#8217;s <a href="http://www.microsoft.com/downloads/details.aspx?familyid=144e54ed-d43e-42ca-bc7b-5446d34e5360&amp;displaylang=en">free Office add-in</a> for removing hidden data.</p>
<p><strong>Danger lurking in PDF documents</strong></p>
<p>Since my paperless life really revolves around PDF documents, this is the most likely kind of document that I would be sending via email. Unfortunately, PDF documents have even more hidden data within than MS Office documents. Many people have been burned when they tried simple attempts at obscuring parts of a PDF.</p>
<p><strong>A Simple Demonstration</strong></p>
<p>I started with a nice PDF of the Declaration of Independence.</p>
<p><img class="alignnone size-full wp-image-508" src="http://paperjammed.com/wp-content/uploads/2009/04/20090421-independence1.gif" alt="" width="403" height="210" /></p>
<p>Now, supposing that we needed to send this document to a colleague, but we must not reveal the name of the original signer, we might try opening up the PDF in our favorite PDF markup tool and slapping a big fat rectangle over the sensitive information.</p>
<p><img class="alignnone size-full wp-image-509" src="http://paperjammed.com/wp-content/uploads/2009/04/20090421-independence2.gif" alt="" width="448" height="330" /></p>
<p>Now, all is good. But the enemy is crafty and they exploit the huge flaw in our thinking: the information never left the document. All they need to do is copy and paste:</p>
<p><img class="alignnone size-full wp-image-510" src="http://paperjammed.com/wp-content/uploads/2009/04/20090421-independence3.gif" alt="" width="673" height="448" /></p>
<p>A quick copy/paste from the PDF viewer application to Microsoft Word lets the whole world see that John Hancock is to blame! Better let him know we slipped up so he can take appropriate actions.</p>
<p>This sounds trivial, right?</p>
<p>In February, <a href="http://www.techcrunch.com/2009/02/11/the-ap-reveals-details-of-facebookconnectu-settlement-with-best-hack-ever/">the Associated Press was able to uncover the secret details of the Facebook/ConnectU settlement</a> using this same technique.</p>
<p>Apparently, the U.S. military has been <a href="http://www.schneier.com/blog/archives/2005/05/pdf_radacting_f.html">caught in the same trap</a>.</p>
<p>Last year, Google founder Larry Page&#8217;s home address info was <a href="http://hackaday.com/2008/08/01/exposing-poorly-redacted-pdfs/">leaked in a similar fashion</a>.</p>
<p><strong>How about Scanned Documents?</strong></p>
<p>Up to this point I was working with a document that had been printed to PDF, thereby preserving the document text perfectly.</p>
<p>What about a document that we scan in?</p>
<p>Here&#8217;s some honest-to-goodness missile plans&#8230;</p>
<p><img class="alignnone size-full wp-image-511" src="http://paperjammed.com/wp-content/uploads/2009/04/20090421-missile-plans1.gif" alt="" width="547" height="448" /></p>
<p>This is an excerpt from a scanned copy of the U.S. patent for the venerable Sidewinder Missile, complete with a black square that I have added to obscure some special information.</p>
<p><img class="alignnone size-full wp-image-512" src="http://paperjammed.com/wp-content/uploads/2009/04/20090421-missile-plans2.gif" alt="" width="616" height="237" /></p>
<p>As seen here, the copy/paste trick still worked.</p>
<p>But why does it still work? Because the document had OCR run on it in the past.</p>
<p>A brief look at Acrobat&#8217;s document inspector tool shows the hidden secrets:</p>
<p><img class="alignnone size-full wp-image-513" src="http://paperjammed.com/wp-content/uploads/2009/04/20090421-hidden-text.gif" alt="" width="588" height="364" /></p>
<p>All of the red text above is hidden text. The actual hidden text is displayed by itself in the box on the right side of the screen above. It isn&#8217;t very pretty, but it has all of the details.</p>
<p><strong>Proper Redaction</strong></p>
<p>If you are concerned about keeping your secrets secret, do a bit of research into the tools available. You want to be absolutely certain that you don&#8217;t pass along any more information than you intend to.</p>
<p>Adobe Acrobat Professional comes with tools to do just this, and I show their use here:</p>
<p><img class="alignnone size-full wp-image-514" src="http://paperjammed.com/wp-content/uploads/2009/04/20090421-redaction2.gif" alt="20090421-redaction2" width="477" height="175" /></p>
<p>You can see that I have used a redaction tool to select scanned text. Acrobat is selecting the hidden text as well as the bitmap image of the page. Once I apply the redaction, you can see the result below:</p>
<p><img class="alignnone size-full wp-image-515" src="http://paperjammed.com/wp-content/uploads/2009/04/20090421-redaction3.gif" alt="" width="609" height="175" /></p>
<p>Now when my enemy tries the old copy/paste trick, the stuff between <strong>38</strong> and <strong>said means</strong> is totally blank, as intended.</p>
<p><strong>Summary</strong></p>
<p>I covered a very simplistic form of redaction here as well as a very simple way of getting around someone&#8217;s naïve censoring. Don&#8217;t stop here. You should use your PDF editor to search the metadata and hidden text for any terms you don&#8217;t want made public. You may wish to strip all metadata from your documents.</p>
<p>This is a topic that has been covered in depth by many, particularly in the legal field. Here&#8217;s a few articles worth reading on the topic:</p>
<p><a href="http://office.microsoft.com/en-us/help/HA011400341033.aspx">Control metadata in your legal documents</a> (Microsoft)</p>
<p><a href="http://seminars.adobe.acrobat.com/p95867520">Redaction and Metadata Removal eSeminar</a> (<a href="http://blogs.adobe.com/acrolaw/2009/02/acrobat_legal_training_movies.html">Acrobat for Legal Professionals</a>)</p>
<p><a href="http://www.acrobatusers.com/articles/2006/10/redacting_pdf">Redacting PDF files with Acrobat 8</a> (AcrobatUsers.com)</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/04/21/keeping-your-secrets-to-yourself%e2%80%94what-can-your-shared-documents-tell-others/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>What would you do if you lost your cell phone?</title>
		<link>http://paperjammed.com/2009/03/16/what-would-you-do-if-you-lost-your-cell-phone/</link>
		<comments>http://paperjammed.com/2009/03/16/what-would-you-do-if-you-lost-your-cell-phone/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 02:20:07 +0000</pubDate>
		<dc:creator>Tad</dc:creator>
				<category><![CDATA[Backups]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Cell Phones]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Portable Devices]]></category>

		<guid isPermaLink="false">http://paperjammed.com/?p=370</guid>
		<description><![CDATA[Many of us have smartphones these days that hold substantial quantities and varieties of data. What happens to that data and how you replace it are two key questions to consider in the event that a mobile telephone is lost.
If you haven’t thought about it much before, why not take a few moments to consider the factors involved and any changes you might want to make to help minimize the stress from such an event.]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-372" src="http://paperjammed.com/wp-content/uploads/2009/03/istock_000003230350xsmall.jpg" alt="" width="226" height="339" />For some this would be a “oh well… it was getting old anyway” moment, while for others this would rate somewhere between “trouble with the in-laws” and “dismissal from work” on the <a href="http://en.wikipedia.org/wiki/Holmes_and_Rahe_stress_scale">Holmes and Rahe stress scale</a>.</p>
<p><strong>But what <em>would</em> you do?</strong></p>
<p>Many of us have smartphones these days that hold substantial quantities and varieties of data. What happens to that data and how you replace it are two key questions to consider in the event that a mobile telephone is lost.</p>
<p>If you haven’t thought about it much before, why not take a few moments to consider the factors involved and any changes you might want to make to help minimize the stress from such an event.<span id="more-370"></span></p>
<p><strong>What’s the problem?</strong></p>
<blockquote><p>There are really three basic areas of concern when you lose a portable phone:</p>
<ul>
<li>Someone else can make calls on your phone and bill them to you.</li>
<li>You just lost all of your pictures, contacts, and text messages.</li>
<li>Some bad dude has access to all of your pictures, contacts, and text messages.</li>
</ul>
</blockquote>
<p><strong>Problem 1: Some Bad Dude has your Telephone</strong><br />
Most people take care of the first problem right away, and you should do so as well.</p>
<p><strong>Take Immediate Action</strong><br />
You must contact your provider ASAP and let them know your phone was lost before some ne’er-do-well starts dialing up 900 numbers or making overseas calls to some see-no-evil third-world country that gladly charges you thousands of dollars per minute.</p>
<p>Even if you don’t have the provider’s number with you, it’s important enough to make a dash for the nearest computer to do a quick Google search. Call them up; it should be sufficient to give your name and mobile number.</p>
<p>Once you have reported the phone as lost or stolen, make sure you change the passwords for any email accounts you had configured on your phone. This will shut off any routes open to bad guys to send messages in your name.</p>
<p><strong>Take Preventative Measures</strong><br />
There are a few measures that you can take up front while you still have your phone. Note that these all fall under the category of &#8220;closing the barn door after the animals have left,&#8221; so you want to do them before you lose your phone.</p>
<p>You can minimize the risk of costly bills ahead of time by asking your provider to block 900 number service and block overseas calls. Of course, when you are packing for your trip to Paris, you might want to call your cellular provider to let them know so that you don’t block yourself. </p>
<p><strong> </strong>In addition, many phones come with a “lock” option, where a PIN is required to unlock the device. I wouldn’t trust my Swiss bank account number to such a PIN, as <a href="http://www.engadgetmobile.com/2008/08/27/iphone-security-flaw-bypasses-passcode-lock/">there have been known bugs in these</a>, but it’s better than nothing.</p>
<p>There exists a class of utilities for smartphones that allow you to remotely lock and erase your device. I used one of these utilities for a while when I was a Treo user, but it always seemed a little too quirky to depend on as my only defense.</p>
<p>You might consider handset insurance from your provider—for a few bucks a month, you can have your handset replaced if it is lost, stolen, or destroyed. Make sure you read the restrictions first!</p>
<p><strong>Problem 2: You lost your Data<br />
</strong> Have you ever considered what kind of data you would lose if the phone were lost?</p>
<p>Here’s a short list of possibilities:</p>
<ul>
<li>All of your contacts</li>
<li>Pictures you took with the camera</li>
<li>Calendar events</li>
<li>Text messages</li>
<li>Email messages</li>
<li>Music</li>
<li>Software</li>
<li>Special notes (A shopping list? A list of passwords?)</li>
</ul>
<p><strong>Synchronize with your Desktop</strong><br />
<img class="alignright size-full wp-image-396" src="http://paperjammed.com/wp-content/uploads/2009/03/20090316-itunes.gif" alt="" width="357" height="211" />Many phones come with desktop synchronization software that can be used to protect you to some extent. For example, the iPhone synchronizes with iTunes whenever you plug it in, and in the process the contacts and photos are copied between desktop and phone (only if you have this enabled, of course).</p>
<p>This kind of synchronization is pretty good, but it is implemented imperfectly for many devices, and it does you no good if the only time you synchronized was when you bought the phone.</p>
<p>Worse still, many phones don’t provide software data utilities out of the box. When my wife purchased a Motorola Razr 2, I was disappointed to find out that Motorola phones require a software package called <a href="http://direct.motorola.com/hellomoto/phonetools/">Motorola Phone Tools</a> which costs $35.</p>
<p>Take some moments and consider how many contacts you carry with you on your telephone. If it is a couple dozen, you can probably just keep a list on your desktop machine and keep them both up to date.<br />
But once you get into the realm of hundreds of contacts, you have no choice: to avoid a catastrophic loss of your social sphere, you had better back up that list somewhere.</p>
<p><strong>Consider the impact of losing Text messages and Email</strong><br />
Think about the text messages and email on your phone: would you shed a tear if you lost these? I couldn’t care a lick about losing old text messages, since I use SMS strictly for need-to-know-now information that loses relevance quickly. I imagine that folks who buy the “unlimited text message” option may have some special ones that they don’t want to lose.</p>
<p>With a bit of luck, and planning, you might be able to keep from losing important emails. One option is to use the mobile web versions of various online email services to handle your mail. This way, you never have any messages on your device.</p>
<p>I like Gmail because they offer a free service called <a href="http://mail.google.com/support/bin/answer.py?hl=en&amp;answer=75725">IMAP email</a>, where your emails are retained on their servers and your device simply shows what is available on the servers, kind of like webmail, but nicer.</p>
<p>Get to know what your device supports and what services are out there.</p>
<p><strong>Google Sync to the Rescue!</strong><br />
<img class="alignright size-full wp-image-374" src="http://paperjammed.com/wp-content/uploads/2009/03/20090316-google-sync.gif" alt="" width="214" height="247" />For the smartphone set, Google recently introduced a great calendar/contact syncing service, where you can set your phone to connect to your <a href="http://www.google.com/intl/en/googlecalendar/tour.html">Google Calendars</a> via a new tool called <a href="http://www.google.com/mobile/default/sync.html">Google Sync for your Mobile Phone</a>.</p>
<p>The screenshot on the right shows the phones that they support as of the time of this writing.</p>
<p>By using Google Sync, you can manage your contacts online or on your phone, and the changes are immediately mirrored.</p>
<p><strong>Problem 3: Bad Dudes have your Data</strong><br />
I don’t even want to consider the possibility of some creepy dude sifting through my contacts, looking at the pictures that I have carefully added, choosing people to stalk, and then going to their homes to slit their throats in their sleep.</p>
<p>Wow, what a horrible thought!</p>
<p>The reality is, that’s probably not going to happen. The odds of your lost or stolen phone ending up in the hands of a serial killer are in your favor.</p>
<p>But a thief sure can have fun with your data!</p>
<ul>
<li>Do you keep any of your sensitive personal data in notes?</li>
<li>Perhaps you have one note where you keep passwords for your online banking site?</li>
<li>Can a villain gain anything by sending text messages in your name?</li>
<li>Are your email messages all locally stored on the phone?</li>
</ul>
<p><strong>Protect your Secrets</strong><br />
If you are like me, you have tons of passwords and secret things that you can’t possibly remember. In my opinion, one of the essential applications for a portable device is a Password Manager application.</p>
<p>These applications provide a simple list of sites and passwords, protected by strong encryption. You provide a single main password to access the data within.</p>
<p>I have used two, and they are both excellent applications: <a href="http://www.splashdata.com/splashid/index.asp">SplashID</a> and <a href="http://agilewebsolutions.com/products/1Password">1Password</a>. There are <a href="http://www.google.com/search?q=smartphone+password+managers">others out there</a>.</p>
<p><img class="alignnone size-full wp-image-375" src="http://paperjammed.com/wp-content/uploads/2009/03/20090816-splashid.gif" alt="" width="438" height="324" /></p>
<p><strong>Recognize the Danger of Email in Enemy Hands</strong><br />
If you used the same email account for registering for any online services, then it is paramount that you prevent the bad guys from accessing your email. All a thief has to do is go to your online shopping sites and say “I forgot my password” and they will kindly send the password to the phone, in the hands of the enemy.</p>
<p>You would think that as soon as your provider blacklists the phone, nobody should be able to use its email; however, if your phone is Wi-Fi enabled, or if someone slips in a different SIM card, it is conceivable that the email client of the phone can still access your email service. </p>
<p><strong>Use IMAP Email or Webmail</strong><br />
If you use IMAP access to your email and contacts, such as with the Gmail IMAP and Google Sync options discussed earlier, you can very easily limit the access anyone has to existing data by changing your email password. Once your Gmail password has been changed, your purloined device will no longer be able to access your email.</p>
<p>It goes without saying that if you are using webmail alone, as soon as you change the email password, the bad guys have zero access to your existing email, but you most likely still have contacts on your phone.</p>
<p>It’s worth experimenting a little to see exactly what the “user experience” would be for a thief if you were to change your password.</p>
<p><strong>Summary</strong><br />
Losing a cellular phone can possibly be an expensive proposition, especially if you are not aware of the factors involved.</p>
<p>Ask yourself &#8220;What could I lose without being sad about it?&#8221;</p>
<p>Ask yourself &#8220;What is the worst thing somebody could accomplish with my data?&#8221;</p>
<p>Weigh the risks carefully and take any action that you feel is sufficient, and sustainable, on your part.</p>
]]></content:encoded>
			<wfw:commentRss>http://paperjammed.com/2009/03/16/what-would-you-do-if-you-lost-your-cell-phone/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
