Managing Chrome In Windows With Group Policy

Download the Chrome Group Policy Templates For Windows

Extract the files to a network share or local location

Open Group Policy Management editor or Run gpedit.msc for local install

Open or Create a new policy

Expand Computer Configurations

Right Click on Administrator Templates -> Then Add/Remove Templates -> Click Add

Navigate to the files you extracted and import the Chrome Template

Now under Administrator Templates, you will see a Google folder and a Chrome folder

If you go into the Chrome folder you will see hundreds of options to customize Chrome

Now link the Group Policy Object to a computer’s OU with the customizations you want.

Sh1mmer Exploit Mitigation

The Sh1mmer Exploit is a Chromebook unenrollment tool that allows users to unenroll Chromebooks from Google Enterprise Workspace. Google has not released an ETA on a patch for this they have released mitigation practices to help prevent this exploit from working.

  • Turn off enrollment permissions for most users. This will require users to identify themselves in order to properly re-enroll on a device that was unenrolled.
    1. Open your Admin Console at: https://admin.google.com/
    2. On the left panel, expand “Devices” > “Chrome” > “Settings”, then click on “Users & Browsers”.
    3. Select the organizational unit(s) of the users that you wish to remove enrollment permissions.
    4. Under “Enrollment Controls”, change the “Enrollment permissions” setting to “Do not allow users in this organization to enroll new or re-enroll existing devices”.
  • On managed Chromebooks, block access to chrome://net-export so that users cannot capture wireless credentials. This can be achieved with the URL blocklist policy.
  • Additionally, Block access to the following websites that have been used to spread exploit tools and information using URLBlocklist as well as via content filtering products:
    • sh1mmer.me
    • alicesworld.tech
    • luphoria.com
    • bypassi.com

Fix For Error Security settings do not allow external startup disk on Mac

If you are trying to reinstall macOS or trying to boot off an external hard drive on Mac for any reason and get the error “Security settings do not allow external startup disk on Mac” there is a way to fix this going forward. To start with this is a security feature to protect your machine called secure boot. Secure Boot is an important security feature designed to prevent malicious software from loading when your Mac starts up or boots. But at times you will need to boot off external media to do that follow the steps below.

Restart your Mac and press and hold Command + R as soon as you see the Apple logo.

You should now see the macOS Utilities window. Select Utilities > Startup Security Utility.

Now enter the macOS password, select an administrator account and enter its password.

In the External Boot section check the Allow booting from external media option.

external disk

Reboot and you will be able to boot off of external media.

Fix For Warning SSL Medium Strength Cipher Suites Supported (SWEET32)

I recently ran into an issue where users were getting “SSL Medium Strength Cipher Suites Supported (SWEET32)” looking into the issue I found the following on the Nessus support site.

The remote host supports the use of SSL ciphers that offer medium-strength encryption. Nessus regards medium strength as any encryption that uses key lengths at least 64 bits and less than 112 bits, or else that uses the 3DES encryption suite.

To disable the Three DES ciphers run

https://www.nartac.com/Products/IISCrypto/

Click on best Best Practices

Under Ciphers

Uncheck Triples DES 168

Check Reboot and Hit Apply

The server will reboot and disable this protocol.

You must reboot for the changes to take effect.

I would recommend disabling protocals TLS 1.0 and 1.1 on your devices if you can for security purposes.

Uncheck TLS 1.0 and TLS 1.1 under Server Protocols

Check Reboot and Hit Apply

This will reboot the server for the changes to take effect.

With these 2 protocols disabled and the 3DES ciphers disabled, this warning should go away when you do your next scan.

Reason For Secure Boot

Microsoft Secure Boot is a component of Microsoft’s Windows 8, 10, and 11 operating systems that relies on the UEFI (Unified Extensible Firmware Interface) specification’s secure boot functionality to help prevent malicious software applications and “unauthorized” operating systems from loading during the system start-up process. Mac computers that have the Apple T2 chip support secure boot options. Mac computers, unlike Windows, support three settings to make sure that your Mac always starts up from a legitimate, trusted Mac operating system.

Why is this important? In an office environment, someone can again plugin or boot off unsecured media like a password manager or an operating system that’s on a jump drive or Live CD and gain access to the computer. This is probably not an issue in your home but in an office environment, it can be a major security hole for a network administrator to protect against.

A Windows password reset disk is a specially created disk or USB flash drive that can be used to gain access to Windows if you’ve forgotten your password. It’s a useful step to take if you tend to forget your password, and it’s easy to create; all you need is a USB flash drive or disk. Great for the home user who forgets their password no so good for a large company network to boot off of and reset a local administrator password.

A live CD is a complete bootable computer installation including an operating system that runs directly from a CD-ROM or USB Stick. Linux has been adapted to the needs of modern computer users by offering a live CD. This type of operating system type can be booted from a CD, DVD, or USB drive without actually being installed on the computer’s hard drive. Again, great for troubleshooting a computer issue and not so good for a secured network.

Microsoft Windows 11 even has a version that you can use to boot off a jump drive with preloaded tools to help you hack a secure network this is why secure boot is so important and is coming on by default on a lot of new computers.

Google Ecosystem And Privacy

I am not trying to scare anyone but I think that everyone needs to know when it comes to Google how their Ecosystem works. Let’s first talk about Google’s Nest. We have all seen the Google Nest in Home Depot. If you don’t know what a Google Nest is it’s an internet-connected thermostat connected to your Google account. So now Google has data on when and how you like the temperature of your home and what heating and cooling system you have.

Since Google Nest offers door locks now Google knows when you lock and unlock your doors if you have those locks installed. Since Google Nest offers key lending Google knows who you lent keys to and who you trust to enter your home.

Google offers as well Google Chromecast and Android TV devices. You guessed it these devices need to be connected to your Google account. So now Google knows what shows you watch and what services you use like Netflix, Hulu, Pandora, and any others you cast to the TV.

One of Google’s most popular services is Gmail. Gmail is by far one of the most popular email services in the world but like anything free, it comes with a cost of privacy. Google has always made it known that they read your email to target ads at you.

Encase you didn’t know YouTube is owned by Google since most people log in with Gmail and the accounts are connected to YouTube Google knows what kind of videos you are watching on YouTube and unless you have YouTube Premium they are going to target video ads on YouTube to you to get you to buy products. Google even ties music in now with YouTube Premium so they can make money on their subscription music service and see what kind of music you are listening to and when you are listening to that music.

YouTube has broken into the television market as of late with YouTubeTV. This is another way of Google collecting data knowing what TV and movies you watch and finding out your TV viewing habits. While YouTubeTV is a service you pay for they are still collecting your data since you need to again use your Gmail account to log in to use the service.

We all love Google Maps and Google places but every time you use your GPS to find a location in Google maps don’t think that information is not stored somewhere for later ad targeting by Google. Google has even admitted to using the speaker on your phone to listen to help improve their Google Assistant and AI programming but has never said they delete that information.

Google Drive or Google Photos is another issue to think about remembering everything you save in your Google drive is subject to Googles review so if you store all your photos and files on Google Drive it’s a good possibility you are building Google a repository of information to scan through at some time.

The Google picture data is rather concerning considering Google uses metadata from the picture and cell phone used to take the picture to determine where it was taken then uses facial recognition to find which Gmail users are in the picture.

Google Chrome is another great invention by Google, and I really mean that they have made the most secure browser with the best extension store. Google Chrome has even expanded its Chrome browser in recent years into a full-fledged operating system that can compete with Microsoft and Apple. Again, this very secure browser and operating system come at a cost as Google is collecting all internet traffic you are doing and using it to target ads at you since you must sign in to Chrome using you guessed it your Gmail account.

Part of the thing that’s concerning about all this information is Google uses this information to target Google Searches, News, Videos, and Ads. While the ads are for Google to make revenue on, and Google Searches are used to bring you the correct information to entice you to continue to use the service the issue becomes Google giving you the News, Searches, and Videos they think you would most likely enjoy keeping you on the platform longer.

While I do not see an issue with this Google has been known to co-operate will law enforcement on issues. While I have nothing to hide Google turns over these records and of who has done what in a certain area it does technically violate some of our privacy rights. Even though the law in enforcement not looking for me just because I was in that area at a certain time now, they have my files and access to certain data.

Source Code: Open-Source Vs Proprietary

I get asked by people all the time. What is the source code? Source code contains everything a program needs to run including coding functions like variable declarations, instructions, functions, loops, and other statements that tell the program how to function.

Beyond providing the foundation for software creation, the source code has other important purposes, as well. Developers can use the source code to create similar programs for other operating platforms for example if a program that was designed for Windows needs to now run on a Mac. Access to source code also allows programmers to contribute to their community, either through sharing the code for learning purposes or by recycling portions of it for other applications like the old saying goes why reinvent the wheel.

Typically, proprietary software vendors like Microsoft don’t share source code with customers for two reasons: to protect intellectual property and to prevent the customer from making changes to source code in a way that might break the program. Proprietary software licenses often prohibit any attempt to discover or modify the source code.

Open-source software, on the other hand, is purposely designed with the idea that source code should be made available because the collaborative effort of many developers working to enhance the software can, presumably, help make it more robust and secure. Users can freely take open-source code under public licenses, such as the GNU General Public License.  The security issues come into play when hackers use source code to find vulnerabilities in the software to attack, steal trade secrets, or reverse engineer code to avoid paying for software.

The other security issues with source code are programmers may also add comments to their source code that explain sections of the code. These comments help other programmers gain at least some idea of what the source code does without requiring hours to decipher it. Comments can be helpful to the original programmer as well if many months or years have gone by since the code was written. You can see how these comments can be an issue because they explain how the software works and makes the hacker’s life much easier.

Source Code is a valuable thing since you can compile it and use the software for free that you would normally get charged for using. For hackers, it tells them how the software works behind the scene making it much easier to find and create vulnerabilities.  Back in 2012 VMWare Got Source Code Stolen. In 2017 Microsoft fell victim to having source code stolen as well.  

Open-sourcing code makes it less of a target since it’s free and anyone can read it and find bugs. Offering bug bounties is a great way to get hackers to report bugs to you. A bug bounty is a sum of money offered by the software manufacturer to hackers to report bugs to them instead of selling them on the black market. Businesses like HackerOne have perfected the bug bounty business by offering a platform for manufacturers and bug bounty hunters to interact.

The issue is proprietary code as you would not want to open that up to hackers even in a bug bounty program cause some hackers would join the bug bounty program just to look at the code. I think this is an issue was can do our best to combat but since we can’t release all software openly we will always have issues like this going forward.

Access Control

Access Control is defined as “any mechanism by which a system grants or revokes the right to access some data, or perform some action.”  Physical access by a person may be allowed depending on payment, authorization, etc.

Physical security access control refers to the practice of restricting entrance to a property, a building, or a room to authorized persons.  Restriction to physical access control can be achieved by a human (a guard, bouncer, or receptionist) or through mechanical means.  Historically this was partially accomplished through keys and locks.

When a door is locked only someone with a key can enter through the door depending on how the lock is configured.  Mechanical locks and keys do not allow restriction of the key holder to specific times or dates. Mechanical locks and keys do not provide records of the key used on any specific door and the keys can be easily copied or transferred to an unauthorized person.  Physical key management is a nightmare to control due to the ease of copying keys at local hardware stores and if keys are lost the lock must be rekeyed.

Physical access control is a matter of whom, where, and when.  An access control system determines who is allowed to enter or exit, where they are allowed to exit or enter, and when they are allowed to enter or exit.

Electronic access control uses computers to solve the limitations of mechanical locks and keys. A wide range of credentials can be used to replace mechanical keys. The electronic access control system grants access based on the credential presented. When access is granted, the door is unlocked for a predetermined time and the transaction is recorded. When access is refused, the door remains locked and the attempted access is recorded. The system will also monitor the door and alarm if the door is forced open or held open too long after being unlocked.

Electronic access allows for temporary keys for one-day access or room.  There are time limitations so if you would a person to only be able to access a room from 1 pm – 3 pm on Monday and Tuesday that is possible.  This is a great idea where a physical key would allow for 24/7 access.

There are MANY types of access control devices for your home and business.

  • Access badge
  • Biometrics
  • Card reader
  • Electronic lock
  • ID Cards
  • Key cards
  • Magnetic stripe card
  • Optical turnstile
  • Photo identification
  • Proximity card
  • Smart card
  • Swipe card
  • Finger Print

Access control is a very important part of business and personal life protecting your information and assets is one of the most important things you can do.  There are relatively low-cost solutions for homes and businesses.  There are high-cost solutions it all depends on how seriously you would like to take your access control.

Pycharm CE Vs Pycharm Professional

I recently have been working on a Python programming project and I wanted to point out the differences between the Pycharm community edition vs the paid addition. I want to start out by saying that I think Pycharm is the best Python editor on the market. While I like VSCode, Pycharm makes the virtual environment for you and loads the plugins for you rather than having to do all that manually in VSCode. But VSCode has one advantage over Pycharm it’s entirely free and while the Pycharm community edition is free it’s not totally functional.

Pycharm community edition lets you code apps using PyQT, PyGTK, and Tkinter so basically any kind of desktop app for free but if you want to code anything using web frameworks like Django or Flask you need to have Pycharm Professional. Pycharm community edition does not include any web framework platform editing.

Pycharm Community Edition as far as web development only supports HTML, XML, YAML, JSON, and RelaxNG while Pycharm Professional supports many others including remote development tools like Docker, SSH, and FTP. Both versions are free and paid support Github.

One of the things that really personally annoyed me was the support for SQL. You can use SQLite which is supported by Python but to use other free database tools like PostgreSQL or MySQL you need Pycharm Professional. I could understand that for Microsoft SQL Server or Oracle SQL but not PostgreSQL or MySQL which are free and open-source for everyone. Even Microsoft and Oracle offer express versions that are free why do you need the pro version to access and modify free databases.

If you are just learning Python I think Pycharm Community edition is great it’s fast and creates a Virtual Environment for you every time it makes it easy. While I do think that the community edition is great if you are going to be doing any real project work I strongly recommend buying the Pycharm Professional at 8 dollars a month it’s worth the cost for anyone who is serious about development it’s a great tool and I recommend it to anyone working with Python.

Background Checks Are A Must For All

Background checks are one of the most important things you can do when hiring someone, especially when hiring anyone who works with kids.

It drives me nuts when I see ads on craigslist for people needing a nanny or sitter ASAP. I just hope those parents do their best and get background checks from one of the companies like Enanny. I always recommend that you go and get a background check yourself. I tell everyone never to let someone bring you background check paperwork because this can be doctored up so easily.

Anyone who works with kids should have an FBI Federal Criminal History Check, Child Abuse Clearance check, and a drug test. I know that might be a little overkill and at times might make it hard to get volunteers for events but to me, it’s better to be safe than sorry when it comes to kids. Most schools now require these three clearances since 2016.

These clearances are important not just for schools but for anyone working with kids Scout leaders, coaches, or anyone working with kids. Never assume that just because someone has kids of their own they are ok they should still have clearances. Remember most issues with kids come from people that you would not expect. Close friends and family members are most of the time the ones arrested for inappropriate behavior with children.

Anyone working with the elderly should get FBI Federal Criminal History Check and Abuse Clearance. While the elderly are adults some cannot report issues of neglect or abuse. If you are taking a loved one to a private nursing home be sure to ask to see the staff clearance policy. Make sure people like janitors, maintenance, and kitchen staff have clearances. Just because they do not work with the elderly directly does not mean they cannot be an issue.

I would like to say not everyone with a record is not an issue and sometimes people with a record can be trusted but sometimes in certain situations better to be safe then sorry in the long run when dealing with children and elderly.