06Jun

Shadow IT is one of the (many) things that keep system admins awake at night.

Right now, someone in every organization with more than a handful of workers is using an app they got from the internet that the IT department knows nothing about.

Unapproved technical tools – apps, cloud services like Dropbox or Google Drive, and personal devices – present potential and very real security concerns. They also come with not insignificant costs when multiple business groups buy duplicate solutions. By some estimates, 40% of spending on software and tech services occurs outside the IT department.

So common is it for a computer user to use a cloud service or download an app or tool to help them do their job that Microsoft says the average number of apps being used in an organization is around 1,000.

“80% of employees use non-sanctioned apps that no one has reviewed, and may not be compliant with your security and compliance policies,” Microsoft says, introducing a tutorial for using one of its products “to discover which apps are being used, explore the risk of these apps, configure policies to identify new risky apps that are being used, and to unsanction these apps.”

Hunting down and shutting off these apps and unapproved services does help with the security risk. But relying entirely on that approach is a never-ending policing effort that only contributes to the “Department of No” perception of IT.

A recent CompTIA article on the subject says imposing ever greater restrictions may even be counterproductive. “Enhanced rules may cause workers to venture outside of approved IT more, rather than less — especially if they feel their pain points are being ignored.”

The article suggests a more benign approach that actually allows some types of shadow IT uses while also educating workers about the risks and providing them with the functionality they want.

The latter is the approach the US Department of Veteran’s Affairs is taking.

“You have to give your customers options. If they don’t feel like they’re getting serviced properly from the central IT function, they’ll go find their own way, because they’ve got a mission to execute,” Dominic Cussatt, the agency’s principal deputy chief information officer, says.

He explained that the VA is developing portfolios of services from which customers can shop.

Reporting on Cusatt’s comments at a conference, FedScoop reported, “The idea is that these portfolios are ready to deploy, checked out from a security standpoint and with buys already in place.

“Said Cusatt, ’That ease of access helps them and helps them avoid seeking other options.’”

Photo by Christina @ wocintechchat.com

[bdp_post_carousel]

World’s Most Popular Software Hacked in 5 Minutes

Here’s news guaranteed to keep a CTO up at night: Chinese hackers successfully launched new exploits against some of the most widely used programs in the world.

And it took them 5 minutes or less to do it.

Fortunately, the successful hackers were part of the 15 teams competing in this year’s Tianfu Cup — China’s largest and most prestigious hacking competition. Using new, never before seen exploits, they were able to successfully hack the web browsers Chrome, Firefox and Safari.

They were also successful against Windows 10, Ubuntu, iOS 14 running on an iPhone 11 Pro, Docker (Community Edition), VMWare EXSi (hypervisor), QEMU (emulator & virtualizer), TP-Link and ASUS router firmware. And Adobe Reader.

Each team got three, 5 minute tries to successfully hack their target with an original exploit.

“Many mature and hard targets have been pwned (compromised) on this year’s contest,” organizers said last week, announcing the results of the competition. The winning team from Chinese tech giant Qihoo 360 earned $744,500, with the balance of the $1.21 million prize spread among 7 other teams.

The software providers were informed of the exploits. ZDNet says patches for all the bugs will be provided in the coming days and weeks, “as it usually happens after every TianfuCup and Pwn2Own (the west’s version).”

Pointing out that teams were able to hack so many widely used programs and applications, Tech Times commented, “The Chinese hacking competition shows powerful and new hacking systems that are never before seen by the technology security industry. The talented computer youngsters showcased how easily and rapidly they hacked into the world’s popular operating systems.”

Photo by Setyaki Irham on Unsplash

[bdp_post_carousel]

Boston to Become a Major Amazon Tech Hub

Bucking a tech trend to going remote, Amazon announced last week it was expanding its already sizable presence in Boston.

The company said it would be adding 3,000 more in the next few years in a new office tower to be built adjacent to its existing site.

In a statement, Amazon said the new jobs include technology roles in software development, artificial intelligence and machine learning, along with non-tech corporate roles in product management, HR, finance, and more.

“Much of the technology that makes Alexa smarter every day is invented in Boston. Our teams here play a key role in driving Amazon’s innovations – from Alexa to AWS to Amazon Pharmacy,” said Rohit Prasad, vice president & head scientist for Alexa at Amazon.

Amazon already has some 3,700 employees at its Boston Tech Hub, most of whom are working remotely because of the pandemic. The new building, now under construction, will be completed later this year and will accommodate 2,000 Amazon employees. It will be Amazon’s second full-building lease in Boston’s Seaport.

The giant ecommerce company has been on a hiring spree, adding 400,000 new workers in the last year. Most of the jobs have been in logistics, with Amazon bringing on tens of thousands of warehouse workers, delivery drivers and others. In September, Amazon held a one-day virtual career fair to fill 33,000 positions around the country.

After the company’s headquarters in Seattle, where it has 80,000 workers, and a “second headquarters” being developed in Crystal City, VA, Boston will become one of the largest of the company’s tech hubs. Others are in Dallas, Detroit, Denver, New York, Phoenix, and San Diego.

New York City, which the company initially selected as the home of its East Coast headquarters until it ran into opposition from activists and city leaders, has more than 8,000 Amazon workers. Over the summer, the company said it would add 2,000 more jobs there.

Photo by Christian Wiediger

[bdp_post_carousel]