by Felicien | Sep 14, 2018 | Education
Microsoft’s Azure cloud service recently suffered a major disruption at one of its data centers in Texas. A truly epic lightning storm caused even the backup generators to go offline. Every time the center struggled back to a semblance of normal operations, another round of thunderbolts blew through and the center was offline again. It took about eight hours to fully restore service to the affected clients.
Cloud opponents will point to this and say that this proves the cloud is unreliable; no hospital can afford eight hours down. And Microsoft would rightly reply that, had those clients who were affected chosen to set up a redundant site in another region, their workload would have been seamlessly shifted over to a center out of harm’s way.
Microsoft would also note that eight hours a year of downtime is a miraculous figure compared to some hospitals that operate their own data centers. Virtually all of us have had the experience of having a health care provider tell us that they couldn’t do this or that because “the computers are down.”
What’s Coming in Cloud 2.0?
While some providers are waffling over whether to move anything to the cloud and if so, what, others are racing to get ahead of the coming tsunami of artificial intelligence (AI) products that are in the pipeline. Remember that Amazon, Microsoft, and Google are all working in collaboration to make medical records more uniform and permit rapid data exchange, where there is effectively “one patient, one chart,” no matter how many providers the patient sees.
This obvious step forward fills many providers with dread. Michael Robinson, the Vice President for healthcare at VMware, a Dell subsidiary, puts it like this: “A huge barrier to cloud adoption is that healthcare organizations want to run their own private environments and do not trust public cloud providers to secure their data.” (Robinson 2018.)
The consulting firm McKinsey sees a major divide coming between firms that adopt AI and those that don’t – to the great detriment of the latter (MIT Interview). The leaders will be so far ahead of the pack that the stragglers will never catch up.
What Is The Value Added?
AI will offer an enormous basket of goodies in the next five years. Virtual agents will enable replacing a lot of the legwork that providers’ employees do. But the big payoff for organizations in the near term will be in the realm of analysis. Data analysis becomes ever more important for all organizations.
Deep learning and similar techniques have been derided as “curve fitting,” but the point is that they are not only fitting lines to the curves, they are finding curves that no one suspected was there. And a lot of the patterns being discovered have to do with money. Hospitals often have no idea what they charge for a given procedure and why they are charging that amount. The prices are usually set in negotiations between payers and providers. AI can discover the real cost of procedures and show what is being overcharged and what is being undercharged. The latter, obviously, are revenue opportunities.
Of course, doing this kind of analytical work involves de-siloing financial and clinical data and making all of it available in one large data lake. Some level of data cleaning is a necessity. CMS, for example, spent over a billion dollars a year cleaning up Medicare and Medicaid data before doing analyses. You will not have to spend a billion, but you would be well-advised to spend something. It is also important to have good consultants to assist in the de-siloing and that data lake creation. Time spent on the front end will save a lot of frustration on the back end.
The value added will be understanding what’s going on in your organization at the deepest levels. Comprehension of this type enables rational actions towards critical business goals. Of course, if your organization has no goals that are stated in quantitative terms, then the analysis is of no use to you. If, on the other hand, you know what “good care” is in terms of costs, infection rates, lengths of stay, morbidity and mortality, and other operational parameters, you will be ahead of the game.
What Are The Risks Of Non-Adoption?
You can choose not to adopt the coming AI revolution. The risk you run there is being eclipsed by your competition, who will be enjoying the fruits of better, faster operations, and lowered personnel costs. You could find yourself in a negative business position from which you cannot recover.
For most healthcare organizations, the biggest worries are security, compliance, and privacy but the paradox here is that the security that cloud providers can give you is far better than you can provide for yourself. You may also fear the loss of control. Again, cloud providers will generally provide whatever level of security you ask for. You can ask for a private cloud and get utmost security there. If you take that direction, you lose the opportunity to reduce your IT staff, but that may be a price you are willing to pay.
In summary, the risks of not moving to cloud 2.0 are infinitesimal compared to the benefits. It’s a move you’ll eventually have to make so why not take the plunge now?
by Felicien | Sep 13, 2018 | Education
With a range of technology continuing to encompass upgrades and versions improving on previous ones, there are constantly new ways for people to improve their Wi-Fi speed. Considering the most recent developments, the below provides instructions for minimizing obstacles to your connection speed while optimizing it as much as possible.
Watch this great video from Steve Dotto below.
How Can I Use A Speed Test For Optimization?
Speed tests can be helpful to locate problems and potential in your Wi-Fi network. The two most fundamentally concerning or relevant aspects of your connection are the speeds by which it can upload or download data. This can affect aspects of your operations including:
How quickly you can send large files in your business
How quickly manual or automatic updates take to download
Media and a range of aspects of web browser speeds
Computer, internet of things (IoT) devices, and cloud file transfers
File attachments in emails
Sending live video streams
Uploading media such as images
Running a speed test allows you to view measurements of the ping, or the effective response time of the Wi-Fi connection, which is measured in milliseconds. Users naturally want to have a low number for their measurement. Many free speed tests are available online, such as Speedtest.net recommended by LinkSys, created and maintained by OOKLA, an online metrics business. The test offered through their organization has over eight billion tests of experience, and functions by using sample uploads and downloads analyzed through their program.
Before starting a test, users are recommended to ensure that their connection is maintained in a normal manner so that the reading is accurate. For example, if multiple family members are using hotspots, streaming, using online gaming, using downloads, etc., it is recommended that the user wait until the use of service ends so that ideal testing conditions are established. Additionally, users are recommended to ensure their router or routers are not obstructed in some way.
After testing, if you are not satisfied with the results, you can take some actions in an attempt to make improvements. You could also consider upgrading your router or changing Wi-Fi providers. Purchasing a superior router can also give you better security as you browse. Some users, especially those in large offices or homes use a range extender to improve performance.
Other options include resetting your router, then retesting to ensure that the low speed observed wasn’t simply random or a ‘fluke.’ Next, you can attempt to transfer your router or routers to a more open area of your building to be sure that electronics or building materials weren’t responsible for a reduced signal strength causing the speed drop.
Beyond this, check to see if your modem is outdated. If you have a dual-band router, you can enter into its settings to see if you can increase a common 2.4 GHz frequency set to a 5 GHz one, which will reduce signal congestion. Lastly, you can compare your ethernet to your Wi-Fi connection with an ethernet cable to determine the extent that your speeds are due to your internet service provider (ISP) or a device. Your ISP may not actually be providing the speeds that they advertise. If you determine that the ISP is the culprit here, contact them and explain that you’ve checked to make sure that your slow speeds are not due to any other thing and insist on them taking action on their end.
In addition to the link provided above, NetSpot recommends users consider their speed app or one of four others listed on their website: Wifiner, Network Speed Test, LAN Speed Test, or Google Speed Test. Click the link for details regarding these tests and other relevant information.
How Can I Begin To Take Steps To Increase Robustness And Reliability?
Beyond the basic steps listed here, you can begin to take more involved steps to optimize your connection. Firstly, you can update the firmware of your router. There may be a new version that has been created since your last install. Firmware updates are important because they involve better security or other speed related upgrades that can improve your service. The administration page of your router’s firmware generally has access to this.
In addition to building material interference and excessive use bogging, you may be experiencing interference from other devices you use. Home telephones, Bluetooth speakers, microwaves, baby monitors, and other devices, according to USA Today, can affect a Wi-Fi network. Creating a ‘heat’ map of potential issues using an application such as HeatMapper could assist you with finding them. You can also attempt to change the channel you established for your router, or use network settings and rules to limit the bandwidth or accessibility of other users to reduce their capacity to affect your speed.
The Quality of Service (QoS) feature available in some routers can also potentially help, as it allows users to prioritize their traffic in accordance to the nature of the information that is transferred in the process. Applications that are sensitive to latency, such as Skype, streamed media, and online games can have higher prioritization than other types of activity; this can be addressed for better results in practical use.
How Can I Further Optimize My Router?
Beyond changing the settings and updating the firmware, you can upgrade. If you navigate to the settings feature of your existing firmware, you should be able to enter into “Advanced Settings” and access channels. Changing the channel to a ‘clear’ one that no one else is using can help. LifeWire has more channel-related recommendations.
How Can I Use A Powerline Or Wi-Fi Signal Strength Increaser?
Wi-Fi extenders, which are devices made specifically for the purpose of improving your wireless power, can also be a worthwhile investment. According to TechRadar, such devices have been increasingly useful in helping people experience greater improvements to their network capacities. Relatively inexpensive, they significantly increase coverage without the extent of installation or restructuring required in implementing new network cables. The most effective use of them is their placement in areas where the signal in the network has been observed as weak. Specific devices that TechRadar recommends for this use include:
Netgear’s AC1200 EX6150 and EX6200 models
D-Link’s DAP-1520 Dual Band Range Extender model
TP-Link’s RE350 AC1200 model
Linksys’ RE6500 AC1200 and Velop models
D-Link’s DAP-1320 N300 and DAP-1650 AC1200 models
Trendnet’s 1200 AV2 model
How Can I Make The Most Of The Netgear Genie Program?
Netgear Genie is a desktop application program that can be configured to manage home routers for the purposes of:
Network speed tests
Live parent controls
SSID and password changes
Guest network controls
Viewing a connected device map
Most of these help users do what has already been discussed here more easily. The network map feature shows when connections are problematic.
What Should I Do?
Use these recommendations as a basic guideline. While you may not need to upgrade your hardware or even your software, it’s likely that you can take some action to increase your Wi-Fi performance.
by Felicien | Sep 13, 2018 | Education
What is ‘ZeroFont’ Phishing?
‘Phishing’ is where hackers attempt to get a user to willingly provide personal information, generally through posing to be someone else. It is one of the more threatening forms of hacking, as it is among the most difficult to protect against traditional security measures.
Hackers continue to find new ways to breach spam and other filters while representing authorities with practical reasons to request information. It is ultimately the user’s decision to trust the hacker which results in information misuse. Users must, therefore, be aware of the nature of phishing tactics and vulnerabilities to best protect themselves.
‘ZeroFont’ phishing attacks have been successful against Office 365 users. In this attack, hackers use a zero-sized font in order to hide identifying information while posing as a reputable account-hosting organization. Users are unable to view zero-sized fonts so they are easily tricked.
What’s Been Happening?
Attacks have been increasing as security researchers learn about this type of internet hacking. ZeroFont phishers have been bypassing Advanced Threat Protection (ATP) processes in popular email services, such as those provided with the commonly used Office 365. Although the advanced Microsoft software uses security processes with many AI and machine learning procedures for blacklisting and other forms of phishing defenses, the ZeroFont method is able to evade these. The use of zero font sizes has proven to be a clever method that allows hackers to sneak in and steal information from a wide range of users.
ZeroFont attacks are actually not new. They were used by hackers in the past but faded into the background for quite some time. For years, hackers have used simple phishing scams to trick users into visiting unsafe sites or giving up their log-in information. This basic method of exploiting internet users has been very successful but cybercriminals are always looking for new and easy ways to steal our money.
Microsoft’s natural language processing has made it more vulnerable to zero font attacks. One example of a hacker using this approach for a successful attack against an Office 365 user involves fraudulent email. The emails are created by a phisher who pretends to be a legitimate Microsoft representative. The email they send out says something about how Microsoft is attempting to notify them that they’ve reached a quota limit of some sort.
Assuming they’ve received an actual message from someone who is their subscription representative, and with the words ‘Microsoft Office 365,’ the email urges the user to divulge personal information. Because of the zero font size, the security program does not recognize relevant keywords and the email is not correctly identified as a ‘spoof’ or spam. Instead, users may choose to cooperate in providing personal information.
ZeroFont attackers can exploit an ability to display a message to users that cannot be properly read by anti-phishing filters. These emails can look as if they are being sent by Facebook, PayPal, Apple, or your financial institution. They urge users to give up sensitive personal information that can then be misused. Hackers have been able to take over Amazon, Facebook and eBay accounts.
While natural language processing is regarded as a powerful aspect of software, highly efficient and effective while safeguarding against email phishing, exploitations of its vulnerabilities have caused ongoing demands for security upgrades. Avanan has more information about the nature of ZeroFont, Punycode, Unicode, and Hexadecimal Escape Character attacks being used today.
Online sources explain that this form of attack has been common, if not rampant since the extent of certain vulnerabilities in Office 365 has been realized.
Security Affairs reported recent phishing ‘campaigns’ that have successfully used this approach, and The Hacker News also reported on a campaign that ‘wildly’ attempted to target a wide range of Office 365 users. The latter was reported to involve a representation of Microsoft while directing users, via a link, to a SharePoint document established to record sensitive information.
As the bodies of the emails sent made use of a zero font size to avoid anti-phishing filters, users were presented with messages that appeared to be legitimate. Imagine getting SharePoint invitations asking for your collaboration or cooperation from Microsoft. It can be tempting to follow the instructions that hackers provide and just do what they say.
Clicked links resulted in automatic openings of the SharePoint file, which hyperlinked the user to an unsafe URL. Therefore even users that did not log in were vulnerable to hacking through the hyperlink, while users that attempted a login also provided their account information to the phisher.
The only way Microsoft can identify such attempts is to scan links within shared documents for URLs that appear to be created for the sake of phishing. Hackers have now become well aware of this. Even if all links are correctly identified, the software would have to blacklist links to all SharePoint files to blacklist the bad URL. This is not a practical fix for the problem.
The Hacker News reported that approximately 10 percent of registered Office 365 users had been targeted by a phishing campaign within just a two week time window.
What Should I Do?
Microsoft recommends, in addition to following best practices for trusting a claim of authority in an email, to:
Ensure the best ATP anti-phishing software and updates are installed.
Use all applicable anti-phishing features.
Use the Security & Compliance Center for more information and system- or software-specific instructions and optimization.
by Felicien | Sep 13, 2018 | Education
To date, Excel and similar apps deal primarily with text and numbers as data types. However, that tradition is about to be a thing of the past as Microsoft is adding two new data types to Excel. These data types allow cells to contain rich, intelligent data that can better represent more real-world data types.
Limitations and Possibilities
Suppose you are putting together a spreadsheet that will plot the relationship between a company’s sales and population in South America. The sales data is easy enough to find, but tracking down the latest population for each South American country might be a bit time consuming and error-prone. At the last minute, someone asks for data that shows sales related to the size of the country, which means another session of hunting down the right information.
What if you could have all that information for a country — population, square miles, map, gross national product, average minimum wage and more – all contained in a single cell within your worksheet? Believe it or not, those days are not too far away.
Excel’s New Intelligent Data Types
There are two new intelligent data types available in Excel: Geography and Stocks. That means that cells in your Excel workbook are no longer limited to holding flat information like text, numbers, or dates. Cells can now house an incredible amount of information related to geography and stocks. Not only can you access this information easily, you can even work with it when you are offline. Both of these data types can be found under the Data tab in Excel, and converting existing data to either of these types is very simple.
Working with the New Geography Data Type
Let’s suppose we have a worksheet that contains a single-column table. The table contains strings that represent countries. To convert this data to the new Geography data type, highlight the country names, then go to the Data tab and click on Geography. This takes care of the conversion.
You’ll notice that an icon appears in the cells next to each country name. It resembles a map that has been unfolded. If you click on that icon, you’ll see a data card that contains tons of information about that country. Now that cell is no longer just a string of characters, but a rich data type with much deeper meaning. All of the data from the data card is actually contained in that cell, and you don’t need an internet connection to access that data.
You will notice that a widget appears to the right at the top of the table. If you click on it, it offers to add another column. You can select from a list of available fields based on the data contained in the card you just looked at.
Stock Data Type
The Stock Data type works in a similar manner to the Geography data type but provides access to data involving stocks. Let’s say you have a table with a single column that contains some company names and some ticker names. You highlight that data, then go to the Data tab and select Stocks. That converts the string data into the new Stock data type, and all the names are switched to company names. You’ll notice that an icon appears by each company name, allowing you to access the data card for that company.
Stock data changes quickly, unlike the Geography data. Because of the dynamic nature of Stock data, the data is refreshable. Some of it is available in almost real-time, while other data will be delayed. If you want to do calculations with cells that contain either the Geography or Stock data type, type in a formula referencing the cell number and then use the . (dot operator) to select the correct member of that geography object. Anything you can do with normal data, you can do with these new data types.
Intelligent Data Types
The Microsoft Knowledge Graph, the intelligent service that also powers Bing, is what provides the data. When someone points out that the Stock and Geography data types are intelligent, that means far more than fixing typos or spelling errors. For example, these intelligent data types can interpret data requests in context. It may ask for more specifics if you enter a city name and convert it to the Geography data type because it wants to make sure what city you mean. However, if a city is listed with other city names in a particular geographical region, then Excel will select a city in that particular region (context).
Accessing It
Not all Excel 365 users can access these new AI data types just yet. According to Microsoft,
“The new data types are being released as preview to Office 365 subscribers enrolled in the Office Insiders program, in the English language only, starting in April 2018. “
However, it will eventually be rolled out for all Office 365 users. And other AI data types will also be added to Microsoft Excel’s repertoire. These developments mean that in Excel you can do even more, even faster.
by Felicien | Sep 12, 2018 | Education
Schools and libraries applying for E-rate technology funding discounts must be CIPA Compliant. CIPA stands for the Children’s Internet Protection Act and mandates that if an institution is receiving a discount for network and network-adjacent services, then it must develop a protocol for use of these services by minors. Further, CIPA stipulates that the public must be notified that the district, school, or library is going to be developing an internet safety protocol, and offer a public hearing before developing the protocol (again with adequate notice to the public ahead of time).
The E-Rate discount applies to:
Data Transmission Services and Internet Access
Voice Services
Internal Connections
Managed Internal Broadband Services
Basic Maintenance of Internal Connections
It does not apply to funding the actual computers, VoIP phones, software, or any other devices that use the above telecommunication services.
Eligible institutions or educational consortiums accepted into the program will receive need-based discounts of between 20-90% off of the costs for the above-mentioned services.
CIPA Compliance Overview
Before implementing an internet use policy, schools, and libraries have to provide reasonable notice to their learning communities that they’re going to be putting one together. Additionally, they must hold at least one public hearing where citizens may ask questions or register concerns.
Lastly, the policy must include two certification requirements: online protection of minors such as filters that can block out objectionable content, and they must include a plan to educate minors on internet safety, cyberbullying, “Netiquette” and more.
The 2011 update also notes that public libraries are not subject to CIPA compliance.
Additionally, schools and libraries have to put into their policy:
Education on safe direct-link contacts such as email or chat.
Unauthorized access like hacking perpetrated by minors and other unlawful acts committed by minors using school devices or using internet services on school property.
Unauthorized access, dissemination of, or use of minors’ personal information including grades, addresses, medical alerts, etc.
Restrict minor children’s ability to access potentially harmful material.
Here is an example of a CIPA Compliance Contractor used by Walled Lake Consolidated Schools in Walled Lake, Michigan.
Adults on Campus
Adults using the internet for appropriate, necessary means are permitted to remove filters blocking access to necessary websites and programs. Adults are also not subject to internet tracking.
Who Determines What Materials Are Appropriate?
Local and state authorities determine what content is appropriate or inappropriate. Further, the blocking of entire social networking sites such as Facebook is not required per CIPA, though individual instances of objectionable or mature content should be filtered out.
Important Additions to CIPA as of 2011
E-rate finding discount recipients must develop and implement a workable strategy for protecting minors and their information, and for educating minor students in how to properly present and protect themselves online.
Schools must provide lessons in “Netiquette” and direct communication (e.g., chat sessions, email) safety education for minors using the internet on school property or with school devices.
What About BYOT/BYOD?
The biggest wrench in the works after funding issues is the BYOD/BYOT phenomenon. It’s natural to allow students to bring in their own devices. It takes care of a few problems regarding access and funding. Plus it reduces the amount of class time needed to train students on an unfamiliar device since they are using their own devices. However, the problems that Bring Your Own Device programs include far outweigh the benefits.
What Is Due Diligence On The Educator’s Part?
Really, the same tried-and-true methods that caught kids with comics or Playboys behind their textbooks still work today. Move around the room as you would for any other group activity or quiet study time, and make your presence known.
Screen mirroring works too and has the added bonus of allowing you to pretend that you’re a TSA agent or mall security officer. It does not allow for classroom management best practices, however, since the instructor may be glued to the screen too closely. It also opens teachers up to liability regarding students’ privacy since a distracted teacher may leave a mirrored workspace screen unattended, giving someone else an opportunity to access student work.
Going back to BYOD, which almost certainly would not be mirrored, students may use a personal broadband or other mobile networks to get around filters. Of course, it would be a violation of not only CIPA-related policies but likely policies already on the books in just about every school district. The best protection is to have a clear, promulgated policy in place that spells out expectations as well as consequences for violations of the policy.
Personal use on a private network also does not currently fall under CIPA’s scope, nor is there any reason to think that it ever would, since CIPA compliance relates to use of school network services and devices. Making the access to restricted materials difficult, expensive, or extremely inconvenient will naturally cut down on the number of people trying to do so.
Last Word – “The Spirit Of CIPA”
Due to the nature of technological innovation today, there are going to be instances of uncertainty. If you “keep in the spirit of CIPA,” you should be all right. Districts developing their policies should make it clear that students and educators failing to make a good faith effort to remain in compliance put funding and the safety of minors at risk, therefore violations will have consequences. It should not be too difficult to uphold the spirit of the CIPA since CIPA guidelines line up faithfully with the goals of all educators: to provide a secure learning environment for students.
The next E-Rate training webinar is Wednesday September 19, 2018 and it takes educators through the invoicing process.