m d3velopment a technical, development and security blog

6Oct/110

How to uninstall Tunnelblick

As with most Mac software, Tunnelblick lacks a "clean and easy" uninstall process.

To simplify the process, I've outlined the six recommended steps, below -

1. Drag the Tunnelblick program from your Applications folder to your Trash.

2. Click your hard disk icon on your desktop (or open your Finder).

3. Click on Library->Application Support, and Delete/Trash the "Tunnelblick" folder if it exists.

4. Click on Library->Preferences, and Delete/Trash the "com.tunnelblick.Tunnelblick.plist" file if it exists.

5. Empty your Trash.

6. Restart your computer.

For more information on Tunnelblick configuration and install/uninstall processes visit: http://code.google.com/p/tunnelblick/wiki/UsingTunnelblick

Filed under: Apple No Comments
31Aug/111

Roundcube Virtual Keyboard

Roundcube Webmail is a is a browser-based multilingual IMAP client with an application-like user interface. It provides the full functionality you would expect from an e-mail client, including MIME support, address book, folder manipulation, message searching, calendar, notes and spell checking.

There are an array of plugins available for Roundcube but to date, there is no "Virtual Keyboard" plugin. A virtual keyboard is a software application which allows a user to enter characters via an onscreen keyboard. Unlike typing a password using a hardware keyboard, a virtual keyboard cannot be logged using a keystroke logger. This provides an additional layer of security and is particularly useful when using web mail from an Internet Cafe or other untrusted location.

I've compiled a package which includes a virtual keyboard interface and is available for download here. Installation instructions are included in the ZIP file.

You can view a demo of the virtual keyboard on Aorta's Secure Email website at www.aorta.me.

21Aug/110

Plesk PCI Compliance

To reduce the risk of compromising sensitive data hosted on your server, you might want to implement special security measures that comply with the Payment Card Industry Data Security Standard (PCI DSS). The standard is intended to help organizations protect customer account data and enhance system security.

Parallels has released a comprehensive PCI Compliance guide for the Plesk hosting panel for both Windows and Linux. A full PDF copy is available here and an online version is available here.

I recommend using Parallels guide as it is maintained inline with industry standards.

21Aug/110

Thai Cyber Law Compliance

I often receive question from customers and partners regarding Thai Cyber Law Compliance.

Thailand's Computer Crime Act of 2007 requires any company or organization that provides Internet access to their employees, customers or visitors (that includes hotels providing broadband to their guests and staff) to retain certain header information for various types of internet activity (email, web surfing, instant messenger chat, FTP downloads) for 90 days as well as maintain a log of the users' identities. Thailand's full Computer Crimes Act (B.E. 2550 / 2007) is available in English here.

Thailand has a history of media censorship including printed news, TV, videos (DVD, VHS), satellite TV and has taken a number of steps to address Internet censorship in the past five years. The Thai Computer Crime Act is a component of this in providing Internet access history, records and tracking capabilities at end user sites.

There are a number of open source based Internet firewall solutions which include authentication and logging capabilities such as Untangle, IP Cop and Smoothwall.

A number of school's and organizations in Bangkok and Chiang Mai which have been investigated by the Thai Police (Section 5) for failing to meet the compliance requirements so Thai based organizations should take the laws seriously.

Filed under: News, Security No Comments
14Aug/111

Recommended Data Center Temperature & Humidity

Monitoring the environment conditions in a computer room or data center is critical to ensuring uptime and system reliability. A report from the Gartner Group in late 2003 estimated that the average hourly cost of downtime for a computer network at that time was $42,000 (1,260,000 baht). In the year 2011, it has likely gone up dramatically. At these high costs, even companies with 99.9% up-time lose hundreds of thousands of dollars each year in unplanned downtime. Maintaining recommended temperature and humidity levels in the data center can reduce unplanned downtime caused by environment conditions and save companies thousands or even millions of dollars per year.

Recommended Computer Room Temperature

Operating expensive IT computer equipment for extended periods of time at high temperatures greatly reduces reliability, longevity of components and will likely cause unplanned downtime. Maintaining an ambient temperature range of 68° to 75°F (20° to 24°C) is optimal for system reliability. This temperature range provides a safe buffer for equipment to operate in the event of air conditioning or HVAC equipment failure while making it easier to maintain a safe relative humidity level.

It is a generally agreed upon standard in the computer industry that expensive IT equipment should not be operated in a computer room or data center where the ambient room temperature has exceeded 85°F (30°C).