Computer Security in Higher Ed.

One of our sister institutions, the University of Iowa, suffered a breach of their book store computer systems last month, potentially exposing the credit card info of 30,000 people. This follows the breach we had at our campus public radio station in March, affecting a smaller group on our own campus. As this article shows, this year, over half a million people have had their credit card numbers, social security numbers, and other personal data potentially stolen from universities with shoddy computer security. Oh, and the year is barely half over.

At this point, you've got to think (and I hope) a Congressional investigation or legislation is coming in the future. Many institutions, including my own, need to change their approach to computer security if they're going to reverse this trend.

One of the problems on many campuses is that the IT staff is distributed, because the IT dollars are distributed. There's usually not a single IT department, there are 50 of them, with varying practices, levels of skill, staffing, and funding. Some campus IT staff don't get near the level of training dollars spent on them that they need to do their jobs properly, due to declining tax revenues in many states. This distributed model also means that an institution's critical information is spread across dozens, if not hundreds, of computers spread throughout the campus network, with greatly varying degrees of security placed upon them. A spreadsheet containing social security numbers or other private information might be on the same computer that a student worker is installing spyware-infested games on to play when they're bored.

A lot of campuses have "open" computer networks, that allow most, if not all types of network traffic to flow to and from their borders, rather than just allowing certain types. This gives students, faculty, and staff the ability to use whatever types of software they like, so it's very flexible, but it also exposes them to a much greater risk.

As the ComputerWorld article says, this philosophy of openness is pervasive:

The most fundamental factor is the openness of the university. The free and open exchange of ideas has long been at the core of the university mission. As a result, the typical campus is physically open to all comers; no identification badge is needed. Its intellectual property is openly aired, and members of the college community interact in public forums online and off-line. Names of professors are public knowledge much more often than their middle-management counterparts in private industry, and rosters of students aren't hard to come by, either. The campus is like this because everyone there, except IT security, wants it that way.

I know it probably seems strange to hope that Congress intervenes in one's own profession, I think it can only improve the situation at this point. While we are working to improve our campus network security, I know it would happen a lot faster if there were tougher laws requiring us to do so...

Report from the WWDC Floor

One of the UNI IT staff is at the WWDC show, and here's what he just sent to us:

I just browsed the iTunes Music Store on a PowerMac running a 3.6 ghz Intel chip. They have several of them set up in the labs here at WWDC.

I wanted to see if I could see Rosetta working so I downloaded Cyberduck and ran it. Either Cyberduck is "universal" (not likely!) or Rosetta is pretty transparent. I couldn't find it in Top.

If you sit down at one of these machines you can see the difference. There is a menu item by the clock that lets you turn hyperthreading on and off. Also, there is a preference pane called "Processor" that allows you to set hyperthreading on or off by default.

This is all very strange. It's even stranger when I think about the fact that after this week, I may not see another Intel based Mac for another year.

So long Big Blue

Wow, Cnet is reporting that Apple is moving to Intel CPUs, and will announce it on Monday. I'm surprised, though I know the PowerPC hasn't been scaling like it was supposed to... It's a great move on the desktop, my iMac G5 runs hot and the fans that keep it cool add a great deal of noise. On the other hand, my 1.33Ghz 12" PowerBook is a great little machine, and relatively quiet, even when I'm pushing it to the limit. It gets a little warm on the left palm, but it's quieter than even the Pentium M laptops I've had in the past.

Gift Ideas

Since my 29th birthday is rapidly approaching, I'm going to take this opportunity to say that I'd like the set of grey rubber floormats from WeatherTech for our 1998 Ford Windstar, as well as their racksack for the luggage rack. If it asks, no, we don't have any entertainment system installed. Also, stuff from my Amazon wishlist, especially the Freaks and Geeks DVD set is appreciated, and there's always the cool stuff on my ThinkGeek wishlist as well.