Category Archives: Security

Keep your SMART phone, Blackberry, or iPhone Safe!

SMARTphones, iPhones, and Blackberrys are in use everywhere on the HSPH campus.  As the functionality of these devices increases, it is important to be aware of potential security concerns with these devices. These security issues can have an impact on your computing at HSPH.

cnet.jpgCNET wrote an excellent article last week highlighting the areas of concern with recommendations. 

It may be found at: Using your smartphone safely (FAQ)

To help keep your phones safe, we recommend:

  • Resist the temptation to store any sensitive data on your phone for convenience sake (i.e., username/password combinations, account numbers)
  • Set a phone password.  Nearly all phones have method that requires entering a PIN after a period of inactivity
  • Keep your phone’s software up-to-date.  (i.e., iPhone and Blackberry have regular software updates that include important security patches.)

Computer Downtime Tonight: Thursday, January 14, 2010

UPDATE, January 15, 2010: All scheduled maintenance was successfuly completed.  All systems are fully operational.

On Thursday night, January 14, 2010, the network and server teams will be performing our normal monthly system maintenance to all servers and network equipment.

The downtime window will last from 7:00PM – 2:00AM.

The following services will have one or two small outages:
(You can continue to work, but may have brief pauses while services restart)

  • GroupWise Full Client and IMAP Clients
  • Novell File and Print services
  • NetStorage
  • ICF File and Print services
  • OASIS
  • ALICE
  • Powerfaids and NetPartner
  • Web Server (main www.hsph.harvard.edu site)
  • GroupWise WebAccess – NOTE – The new GroupWise WebAccess may require you to relogin, but you will not lose any work you have in a compose window. This new version has many new features, including an Auto-Save feature that is integrated with the “work-in-progress” folder.

The following services will not be affected:

  • HPCC system
  • HSPH Unix server

Laptop Encryption Update

In late-October, the Information Technology Department began an important project to provide full disk encryption for all Harvard-owned
laptops using McAfee Endpoint Encryption.

Our work continues in the new year. 

Laptop_Security.jpgIf you didn’t do so in the fall, we ask that all laptop owners fill out the brief form located at: https://webapps.sph.harvard.edu/internal/forms/laptop-encryption/

This greatly assists us with scheduling.

If there are any questions, please contact the User Service’s Helpdesk at 432-HELP.

Using Facebook and Twitter safely

With many in the HSPH community using Facebook or Twitter on a regular basis, there are potential security concerns to be aware of with either site. These security issues can have an impact on your computer at HSPH.

CNET wrote an excellent article prior to the winter recess highlighting the areas of concern with recommendations. 
cnet.jpgIt may be found at: Using Facebook and Twitter safely

The Department of Information Technology offers:

  • McAfee virus scanning products to the community free of charge. 
  • Additionally, automatic Windows updates are pushed out to the community for all users that utilize Novell. 

Please contact the Helpdesk at 432-HELP for further information.

Staff Promotion: Andy Ross

We are pleased to announce the promotion of Andy Ross from Unix Systems Administrator to HSPH Security Manager.  Andy has worked in the HSPH Department of Information Technology at HSPH for the past 9 years and has played a critical role in keeping our core servers, including email servers, operating smoothly 24-7-365.  

Andy’s extensive experience with both server and network administration will allow for a smooth transition to this new and
important role.  In preparation for the new role, Andy spent several months training with both top security vendors and with central
university security professionals.

andy.jpgAs security manager, Andy will oversee security technology and policies as well as work with the community to educate users on best practices.  His work will involve a variety of systems and processes including:

  • Email
  • Web and application servers
  • Confidential and high-risk information including student records, research data, financial and ecommerce information
  • Secure file transfer
  • Laptop and PC encryption
  • Remote computing
  • Community best practices
  • Auditing, risk assessment and compliance work with school and central university administration

Congratulations to Andy!

Interesting fact:
Prior to joining HSPH, Andy served our country for 8 years in the United States Army rising to the rank of sergeant

We are happy to have Andy on board providing security for HSPH!

army.jpg

Laptop Disk Encryption

Beginning in late-October, the Information Technology Department will begin an important project to provide full disk encryption for all Harvard-owned
laptops using McAfee Endpoint Encryption.

Full disk encryption is an important step in protecting confidential information and has now been mandated by Harvard University. Disk encryption provides valuable data protection for laptops that are lost or stolen.

There will be no charge to encrypt your laptop.
Laptop_Security.jpgWe ask that all laptop owners fill out the brief form located
at:

https://webapps.sph.harvard.edu/internal/forms/laptop-encryption/

Christopher Cahill, our desktop group leader, will be contacting department administrators and individual users in the coming weeks to schedule
the disk encryption. We are required to complete work by December 31, 2009. We have developed an FAQ about the product. It may be found at:

For more information on new University security policies or the product, please visit:

Phishing for Usernames and Passwords

Occasionally, an email message phishing for information finds its way through our spam filter.  Today, some users saw a message from a seemingly legitimate .edu address that read:

Your mailbox has exceeded the storage limit which is 20GB as set by your administrator,you are currently running on 20.9GB, you may not be able to send or receive new mail until you re-validate your mailbox. To re-validate your mailbox  please click the link below:

http://rpc.formmailhosting.com/showform.php?id=5833

Thanks
Raubicheck, Prof. Walter F
System Administrato

Another recent email said:

To ensure quick, responsive e-mail services, it is necessary to establish limits on the amount of e-mail each user may store on the system. The
volume of e-mail you are storing on the Central e-mail system is now exceeding your normal space allocation. To request for more storage
space on your webmail account, simply click here

Please note that the HSPH Helpdesk will never ask someone in the HSPH community for username and password information for any HSPH server or service via email.

Any messages received that are phishing for information should be deleted.  Protect your accounts!

Further reading on phishing:

Virus Warning: New York Times

There are a number of viruses/malware items that have been recently distributed via legitimate websites such as the New York Times through rogue advertisements.

If you are asked to purchase virus scanning software online through popup windows, please disregard the requests.  These are not legitimate anti-virus products.

Please contact the HSPH Helpdesk at 432-HELP for further information on this issue or on how to protect your computing environment with McAfee products provided by HSPH.

Read more: