¡Hola!
Solo 14 días han pasado desde que comenzó el 2017 y ya dos amigos míos han sido víctimas de accesos no autorizados a sus cuentas en linea: una amiga, a su cuenta de Facebook y el otro, a su cuenta de Skype.
Aunque nunca hayas pensado en tu seguridad digital o tal vez, ya lleves un tiempo pensando en tomar ciertas acciones; este comienzo de año es las excusa perfecta para hacerlo.
El pensar en tomar acciones para protegerte puede parecer abrumador y llevarte a abandonar el intento. No hay dudas que tomar las riendas de tu seguridad te va a generar trabajo extra; por eso voy a intentar mostrarte algunas medidas que exigen poco de esfuerzo pero generan mucho valor, el equivalente a "en vez de dejar tu bicicleta simplemente apoyada contra un árbol, asegurarla".
Estos son mis consejos:
Activen la autenticación de 2 pasos, también conocidos como aprobaciones de inicio de sesión
Esta medida que usualmente requiere que ingreses tu password y además, ciertos códigos que son enviados o generados en tu teléfono, te protege en el caso de que tu password sea obtenido por terceras personas.
No todos los servicios ofrecen esta opción, pero la mayoría lo hace, aunque los nombres pueden cambiar. Por ejemplo, en Twitter se llama "Verificación de inicio de sesión", y en Facebook es "Autorización de inicio de sesión".
Estos servicios no generan molestias en el día a día porque tienes la opción de marcar tus dispositivos personales (teléfono, PC) como confiables, y pare estos no necesitarás el código adicional. Claro que se pueden volver un poco molestos cuando estas apurado en iniciar sesión en un dispositivo que nunca antes has usado, o estas en un lugar donde no hay señal para recibir los códigos.
Aquí las instrucciones para los sitios más usados, te recomiendo comenzar por los sitios que tienen tu información financiera, por ejemplo Amazon:
Amazon -> ver aquí. Facebook -> ver aquí. Gmail -> ver aquí.
Usen un administrador de contraseñas
Todos tenemos un montón de cuentas en línea, y la idea de catalogarlas, cambiar las contraseñas de manera regular, usar contraseñas distintas para cada una de ellas, es enloquecedora. Precisamente por eso es que necesitas un administrador de contraseñas. Lo interesante de usar un administrador de contraseñas es que, una vez haya pasado por el proceso de alimentarlo hará tu vida más simple. No tendrás, nunca más, que pasar por el proceso de "olvidé mi contraseña" cada vez que quieras acceder un servicio que no accedes con frecuencia o sentarte a pensar qué poner como contraseña.
Aquí hay una lista de los mejores administrador de contraseñas pagos, y también existen algunos gratuitos.
Después de instalado, añade tus cuentas más usadas, y veras que en un par de semanas, con el uso regular de las otras cuentas, estas se añadirán automáticamente cada vez que inicies sesión.
Los administradores de contraseñas no son perfectos. Estos centralizan todos tus datos, y es posible que las compañías que los proveen sean infiltradas. Ya ha ocurrido antes.
Al menos que estés dispuesto a invertir mucho de tu tiempo en una estrategia, elaborada por ti mismo, para administrar tus contraseñas, los administradores de contraseñas son una manera viable de tener tus contraseñas bajo control. ¡Haz que el 2017 sea el año en que comenzaste a usar un administrador de contraseñas!
Realicen copias de seguridad periódicamente
Puedes hacer tus copias de seguridad en dispositivos externos (discos duros externos, flashs, etc.), o en servicios en la nube, o en ambos.
Las herramientas que aconsejo más abajo cifran tus datos antes de moverlos a los dispositivos externos o a la nube. Esto es muy importante en caso de que roben tu dispositivo externo, o el servicio en la nube se vea comprometido. Dado que tu información esta cifrada, no podrán verla.
Los servicios CrashPlan and Backblaze son algunas de mis recomendaciones. CrashPlan realiza tus copias de seguridad automáticamente a dispositivos externos y a la nube.
Aprendan a usar una VPN
Cuando estas conectado al internet, la VPN crea un canal de comunicación seguro entre tu dispositivo y un servidor seguro, para evitar el espionaje de la información en los lugares que visitas en internet. El uso de una VPN son casi obligatorio si sos alguien que se conecta a redes WiFi públicas. Una advertencia: el uso de una VPN reduce la velocidad de tu internet.
Uno de mis servicios de VPN favoritos es Freedome.
Haz que la seguridad digital no sea parte de tu ya extensa lista de preocupaciones diarias y sigue estos simples cuatro consejos.
sábado, 14 de enero de 2017
lunes, 14 de noviembre de 2016
Finally! SAP BW A Dynamic Star Schema!
For years, we (BW guys) have used the classical BW schema:
This model has worked for years, and was very robust and performant. But it always lacked:
- Multiple layers, and data is moved from layer to layer
- If you need something new (add a field, etc.), usually you have to touch all layers, and most probably do a reload
This model has worked for years, and was very robust and performant. But it always lacked:
- Flexibility and adaptability
- Support of modern federated DWH architecture
Finally with BW 7.5 this has changed, now we have the: SAP BW Dynamic Star Schema - Separating Star
Schema Modeling from Fact-Table Modeling
This is the new proposal from SAP, which give us: Flexibility and adaptability and Support of modern federated DWH architecture.
SAP has published this document which I strongly recommend you to check:
I recommend you to focus your attention on page 7 and onwards.
Enjoy Snowflaking!
Finally! SAP BW A Dynamic Star Schema!
For years, we (BW guys) have used the classical BW schema:
This model has worked for years, and was very robust and performant. But it always lacked:
- Multiple layers, and data is moved from layer to layer
- If you need something new (add a field, etc.), usually you have to touch all layers, and most probably do a reload
This model has worked for years, and was very robust and performant. But it always lacked:
- Flexibility and adaptability
- Support of modern federated DWH architecture
Finally with BW 7.5 this has changed, now we have the: SAP BW Dynamic Star Schema - Separating Star
Schema Modeling from Fact-Table Modeling
This is the new proposal from SAP, which give us: Flexibility and adaptability and Support of modern federated DWH architecture.
SAP has published this document which I strongly recommend you to check:
http://sapassets.edgesuite.net/sapcom/docs/2016/03/445ef806-647c-0010-82c7-eda71af511fa.pdf
I recommend you to focus your attention on page 7 an onwards.
Enjoy Snowflaking!
martes, 23 de agosto de 2016
Shadow IT: The new competitor
"Shadow IT is the proliferation of information technology (IT) that remains largely unknown and unseen by a company’s business IT department, which is concerning from both a security and a management perspective."
"When employees bypass IT and use their own, unsanctioned technology, we call it “shadow IT.” The cloud makes this really easy: all you need is a browser or a mobile device and you can connect to a virtually endless number of cloud apps for collaboration, file sharing, note taking, presentation building and just about every other tool you could ever want. The cost is minimal or even free. Who could resist?"
These 2 quotes from David Metcalfe define what shadow IT is.
What does this mean for us, external consultants?
Usually we try to develop a trust relationship with our customers' business areas and to achieve a perpetual honeymoon with the customers' IT department. We have to follow their rules and use the platforms they have chosen probably decades ago.
We deliver a product in X time and most probably with a not so appealing UI, since we were using IT’s approved platforms. Then, comes shadow IT and produces the same application in 1/3 X time and probably with a more appealing interface. Now, we have new a competitor: shadow IT.
Gartner is predicting that by 2016 35 percent of IT expenditure will go toward shadow IT.
The case for shadow IT is that it drives innovation and removes boundaries. The dark side is that it is uncontrolled, unmanaged and potentially not secure enough.
One area where us, external consultants, can contribute to IT departments is in the creation of change and configuration management for the shadow IT applications. By defining simple rules and processes we can help to avoid detrimental outages or security breaches.
For example, if the person from shadow IT decides to take a sabbatical year, we don’t want the business to become unable to do use their trendy forecast application.
Have you started a conversation about shadow IT with your customer?
viernes, 27 de mayo de 2016
Data visualisation tool + In memory Database in 10 minutes / Docker + Spark + Zeppelin
Hi,
Have you ever wanted to have an ultra fast in-memory database and a real time visualisation tool where you can create charts from your SQL query results?
Now you can! It can all be achieved using open source software and the effort of setting it up is minimal.
In a nutshell:
Have you ever wanted to have an ultra fast in-memory database and a real time visualisation tool where you can create charts from your SQL query results?
Now you can! It can all be achieved using open source software and the effort of setting it up is minimal.
In a nutshell:
- Install Docker (https://www.docker.com)
- Download a Docker image that contains Spark + Zeppelin
- Execute the Zeppelin example
Install Docker
If you are in the IT world and you do not know what docker is; I recommend you to find out here.
The docker installation process is very straight forward. If you are using a MAC or Windows 10, I recommend you to install the beta version, which is much more efficient. The beta version requires Windows 10.
Download the Docker image
Once you have docker installed, download an image from: https://github.com/dylanmei/docker-zeppelin
As mentioned on the web page, you only need these two commands:
docker pull dylanmei/zeppelin
docker run --rm --name zeppelin -p 8080:8080 dylanmei/zeppelin
The first command can take from three to ?? minutes depending on your internet connection speed. In my case, it took four minutes.
Execute the Zeppelin example
After executing the second docker command which runs the image, you will see something like this:
Open your browser to this address: http://127.0.0.1:8080. Use Chrome or Firefox.
And you should see something like this:
Click on the Zeppelin Tutorial note.
Click save; this will cause the notebook to have the needed dependencies.
Then click the "play" icon for the first part or paragraph as it is called in Zeppelin.
As you can see, this will create a table called "bank" (1) from a text file located in (2).
Now you can start to explore the data:
Feel free to execute any of the charts, or alter the SQL statements to start exploring the data you just loaded.
In my next post I will write about using more advanced features.
viernes, 29 de enero de 2016
From IOT trough the cloud into analytics
I still remember the example from several years back telling us what the IOT is going to be about: "Your fridge will be connected to the internet and will order milk and eggs when you are running out". Sounded kind of appealing but, I thing IOT is much more interesting than that.
One nice example of what IOT can achieve is described in this article of Wired magazine.
I myself wanted to experience the topics IOT, Cloud, and analytics combined together, with a budget of 50€, during 5 days, at a rate of 1.5 hours per day.
The result of my experiment is this:
I've got an Onion Omega microcomputer (30 USD) that runs Linux and can be connected to any type of sensor, and connects to a Wi-Fi network. I originally wanted to use a Raspberry PI Zero (5 to 10 USD) but they were in Back Order.
In this case I decided to work with a temperature sensor (5 USD). So, inside the Onion I put a Python program (thanks Maria!) that reads the temperature from the sensor and send it to Microsoft Azure Cloud.
Then I used the newest Microsoft analytics services, called PowerBI to create some charts with the resulting data.
In a Nutshell, any small and cheap micro computer connected to a equally small and cheap sensor, and to a WI-FI network can send its reading to a server in the cloud. Then with any device (PC, Smart phone, tablet) connected to the Internet you can analyse and visualise this information. Great, isn't it?!
Right now I'm in the process of creating a platform which enables anybody to collect and analyse information from sensors (whatever sensor you can imagine) in a cheap and fast way. So, if you have an idea where you can use this, please contact me.
Some pictures:
One nice example of what IOT can achieve is described in this article of Wired magazine.
I myself wanted to experience the topics IOT, Cloud, and analytics combined together, with a budget of 50€, during 5 days, at a rate of 1.5 hours per day.
The result of my experiment is this:
I've got an Onion Omega microcomputer (30 USD) that runs Linux and can be connected to any type of sensor, and connects to a Wi-Fi network. I originally wanted to use a Raspberry PI Zero (5 to 10 USD) but they were in Back Order.
In this case I decided to work with a temperature sensor (5 USD). So, inside the Onion I put a Python program (thanks Maria!) that reads the temperature from the sensor and send it to Microsoft Azure Cloud.
Then I used the newest Microsoft analytics services, called PowerBI to create some charts with the resulting data.
In a Nutshell, any small and cheap micro computer connected to a equally small and cheap sensor, and to a WI-FI network can send its reading to a server in the cloud. Then with any device (PC, Smart phone, tablet) connected to the Internet you can analyse and visualise this information. Great, isn't it?!
Right now I'm in the process of creating a platform which enables anybody to collect and analyse information from sensors (whatever sensor you can imagine) in a cheap and fast way. So, if you have an idea where you can use this, please contact me.
Some pictures:
1. The Onion with an USB stick (A) and the temperature sensor (B). The Onion is on top a pack of cigarettes so you can guess its size.
2. A simple dashboard (running on my iPad) that shows the temperature of the last 30 mins, the current temperature, and the average of the last 5 days. I created a couple of artificial temperature variations by putting some ice near the sensor.
domingo, 27 de septiembre de 2015
The new world of analytics and BI. From a text file to the iPad in a couple of hours.
The world has changed in many ways in the last 5 years. It has changed in analytics and business intelligence too.
A friend of mine is running a web proxy, a program that monitors which web pages are visited and by whom from inside his company. This proxy generates a log file in text format which contains the username, the page visited, the amount of bytes, etc. The file looks like this:
192.168.15.63 user2 [15/Sep/2015:09:10:09 -0400] "GET http://api.new.livestream.com/accounts/8665913/events/4253600/broadcasts/99302610/availability HTTP/1.1" 304 342 TCP_MISS HIER_DIRECT
192.168.15.150 user1 [15/Sep/2015:09:10:16 -0400] "CONNECT ci3.googleusercontent.com:443 HTTP/1.1" 200 5917 TCP_MISS HIER_DIRECT
192.168.15.150 user1 [15/Sep/2015:09:10:16 -0400] "CONNECT ci5.googleusercontent.com:443 HTTP/1.1" 200 11657 TCP_MISS HIER_DIRECT
192.168.15.150 user1 [15/Sep/2015:09:10:16 -0400] "CONNECT ci6.googleusercontent.com:443 HTTP/1.1" 200 17674 TCP_MISS HIER_DIRECT
192.168.15.63 user2 [15/Sep/2015:09:10:25 -0400] "POST http://livestream.com/analytics/api/track HTTP/1.1" 204 484 TCP_MISS HIER_DIRECT
192.168.15.150 user1 [15/Sep/2015:09:10:16 -0400] "CONNECT ci3.googleusercontent.com:443 HTTP/1.1" 200 5917 TCP_MISS HIER_DIRECT
192.168.15.150 user1 [15/Sep/2015:09:10:16 -0400] "CONNECT ci5.googleusercontent.com:443 HTTP/1.1" 200 11657 TCP_MISS HIER_DIRECT
192.168.15.150 user1 [15/Sep/2015:09:10:16 -0400] "CONNECT ci6.googleusercontent.com:443 HTTP/1.1" 200 17674 TCP_MISS HIER_DIRECT
192.168.15.63 user2 [15/Sep/2015:09:10:25 -0400] "POST http://livestream.com/analytics/api/track HTTP/1.1" 204 484 TCP_MISS HIER_DIRECT
Based on the contents of the log file, my friend wants to know which are the top 10 internet users, the top 10 visited sites, or the peak hours of daily internet use. And he asks me to process the file and get this information for him. There are many ways to achieve it, but the one I tested is the following:
I loaded the log file to a Hadoop-based platform (Microsoft Azure HDinsight) and gave it a queryable structure. For achieving this I had to write only two lines of code.
Now I have the file loaded and I want to give my friend a familiar tool to query the logged data. It could be Excel (there are ODBC drivers for Excel to connect to HDinsight), but why not something more mobile? For example Microsoft PowerBI, it has has the ability to connect to HDInsight and you can run PowerBI in your iPad.
Now, I have a log file from a web proxy loaded into a Hadoop-based tool, and my friend can query its contents from his iPad, amazing isn't it?
I used technologies like cloud and big data for a trivial task like this, and I did it without installing any tools locally. My point here is: The way we process and make information available has changed a lot in the last 5 years, and we (IT professionals) have to adapt to those changes, and more importantly, we must take advantage of them!
Suscribirse a:
Entradas (Atom)








