Category: b.r.m.

Where elephants fight, the grass suffers

For most laypeople, the 'Secure Sockets Layer' (SSL) is just a Chinese IT term. The term actually refers to the network protocol for the secure transmission of data. Only those sites that have been certified in accordance with SSL are considered secure transmitters in global data traffic.

When an Internet giant like Google now distrusts an estimated tenth of all sites SSL distrust and no longer recognizes and no longer recognizes their certificates, then this is like a medium-sized earthquake in the IT world.

Officially, the Google browser 'Chrome' is withdrawing its trust from the affected Symantec sites because security is no longer guaranteed there. Unofficially, the issue is more likely to bethat Symantec is said to have distributed masses of SSL certificates without authorization. A battle of the giants - which in this country would also affect 'Spiegel Online', 'Golem' or 'Wechat', for example, and even 'amazon' would be in a tailspin from October 2018, i.e. from the next version of Chrome. After all, Google Chrome is the world's leading internet browser.

With the release of 'Chrome 66' in April 2018, the announced penalty will take effect worldwide. When accessing affected pages, Chrome users would then receive a warning that the content of the selected website is 'not trustworthy'.

Our IT service recommends that all website operators check the certified SSL security of their website with SSL-Labs to check the certified SSL security of their website. If you have any questions, just give us a call.

Bremen, February 22, 2018

Facebook: Return to Sugar Mountain

Since Facebook founder Marc Zuckerberg began to thoroughly 'clean out' his network, the platform has been getting closer to reality again. It was not only the American election campaign that showed everyone how easily Facebook could be misused as a 'fake news sling' under the old rules. The loss of advertising revenue and the increasing exodus of the younger generation probably also contributed to the major rethink.

We at b.r.m. are honoring these efforts on the social media platform and are returning to Facebook with our account and the range of IT services we offer. Interested parties can find our presence there at www.facebook.com/brmbremen/ .

Bremen, February 28, 2018

Green visit to Grüner IT

The fact that energy efficiency and climate protection also play an outstanding role in IT is not only demonstrated by the server farms of large digital companies, which are all located close to the Arctic Circle for cooling reasons. b.r.m. took a different approach here and now uses the waste heat from the servers to air-condition the offices.
We will be able to show our visitors these and many other measures in the field of practical sustainability when the Bremen Greens' state working group on economic and financial policy visits us on March 13, 2018 at 6:30 pm. We look forward to lively discussions about a contemporary IT service.

Bremen, March 7, 18

Nothing on the net is free

The major search engines only appear to work 'free of charge'. Every user pays to find information on the internet by disclosing their queries. This creates 'user profiles' that allow a customer to be presented with precisely the advertising that matches their interests.

Google's AdWord system dates back to the year 2000. 'AdWord' is an artificial word made up of 'advertising' and 'keywords'. Google's commercial customers pay for their advertising to appear on the side - or, more recently, below the search box - as a result, in the form of snippets with a link. And they do this precisely whenever the user of the search system calls up a specific keyword.

This is the IT service that Google offers its paying customers. Until 2008, the Adword system was billed as cost-per-click (see CPC). Since then, a complex model has emerged that also takes into account loading times, the quality of the ad and the type of device used (cell phone, PC). In the blog 'Inside AdWords' (also in German since 2008), Google provides continuous information about changes on this most important advertising platform worldwide.

Bremen, March 23, 2018

Order data processing (ADV) with hurdles

In Germany, Section 11 of the Federal Data Protection Act and Section 80 of the Tenth Book of the Social Security Act regulate 'commissioned data processing' or 'commissioned data processing (ADV)'. They provide the framework for the 'outsourcing' of data processing contracts to external third parties. Since 2009, the Federal Data Protection Act has referred to a ten-point rule that clarifies issues such as deletion, reporting obligations and control rights in a court of law.

Depending on the type of data collected, each client must first satisfy itself that the contractor is certified for the task in question and that it has also introduced and implemented a security concept. This information is usually provided in writing. Only after this confirmation may the client transmit personal data.

Under liability law, it is not primarily the service provider who is responsible for breaches, but still the client.

BCR: yesterday's news today

The term 'Binding Corporate Rules' (BCR) first appeared in the EU Data Protection Working Party in June 2003. The idea was to create a flexible instrument for data transfer that would also meet the requirements of data protection law. The result was a procedure that allows companies to individually structure data protection when transferring data to third countries, provided that the Binding Corporate Rules applied meet certain minimum standards.

These included, among others:

1. development and implementation of a security concept 2. data protection training for employees 3. mandatory participation in an audit program 4. payment of compensation in the event of violations 5. regulated complaints procedure 6. assurance of transparency 7. definition of the scope of application.

The advantage of the introduction of 'corporate binding rules' seemed to be the possibility of individually structuring data transfers to 'unsafe third countries'. The main disadvantage was the high organizational effort and the lengthy review process. However, as data protection was subsequently not guaranteed even in the 'safe third countries' (see, for example, the Facebook scandal and Cambridge Analytica), a European General Data Protection Regulation (GDPR) has now replaced a European General Data Protection Regulation (GDPR) the BCR. The new regulation provides for unexpectedly high penalties for companies that do not handle data protection responsibly.

CPU: The smaller, the bigger

The 'heart' of every computer is the CPU. This Central Processing Unit (CPU) is a miniaturized computing chip that processes defined computing processes ('algorithms') according to its 'architecture' of semiconductors (or 'transistors'). CPUs are no longer only found in computers, but nowadays also in washing machines, cars and ticket machines, for example.

A CPU consists of several components. The arithmetic-logic unit (ALU) forms the center. It is supplemented by the control unit, which primarily manages addresses. Registers and a memory manager (Memory Management Unit or MMU) complete the core of the chip.

Small 'helpers' - or co-processors - support the central processing unit in its tasks, for example by performing floating point operations. Today's CPUs are designed as multi-core units, which increases parallel processing and the speed at which tasks are solved. The data lines ('buses') ensure communication with the other components of the computing system, especially with the main memory. 'Caches' (intermediate memory) enable rapid further processing of partial results.

The choice of processors used in a company should be based on the tasks to be performed. The most expensive solution is by no means always the best or most efficient. Just ask us ...

Ransomware - ransomware solves nothing

The number of cases where a 'ransom' is to be extorted by blocking the computer is increasing. The user of a computer sees a 'demand' from the attackers on the monitor instead of the usual working environment, but their data is encrypted. The perfidious thing about this is that the method itself is increasingly becoming a hindrance: If the victim responds to such a demand, their computer usually remains blocked anyway. Only very rarely can you 'buy your way out' with Bitcoins. Whoever pays therefore looks just as stupid as the person who refuses to pay. Which increasingly takes away any 'business character' from the use of 'ransomware' ...

Ransomware has long worked independently of the operating system. Whether Linux, Mac OS or Windows, all users are affected by this digital form of highway robbery. The instructions for building the ransomware, the so-called 'CrimeWare kits', are circulating on the DarkNet. The program often does not encrypt the entire computer, but mainly the data that is important to the user, such as the 'My Documents' folder under Windows.

Protection against ransomware is very similar to protection against other viruses or Trojans. For example, a user receives an email with the attachment of an unpaid invoice, with a threat of punishment from the Federal Criminal Police Office, or with alleged usage violations by GEMA. Anyone who opens such an attachment has already handed the blackmailers the 'house key'.

You should therefore NEVER open an e-mail attachment that does not come from an absolutely trustworthy source. GEMA and the BKA still use good old snail mail. It is also important to regularly back up all relevant data on external data carriers, as this keeps it out of reach of the blackmailers. Browsers can be protected against the execution of critical Java commands by installing applications such as 'NoScript', and even ad blockers offer increased protection.

All right - that's how good we are!

From the very beginning, the IT service provider b.r.m. has been a member of the Bremen-based 'Partnerschaft Umwelt Unternehmen'. The aim here has always been - and still is - to find the best possible solution for both employees and the environment. The technical term for this is 'work ecology'. In the university-affiliated working group 'NaGut - sustainable good work', this work ecology approach is tested in practice - with the help of advice, research and training. This working group has now published a brochure in which particularly successful models of implemented work ecology are presented. On pages 8 and 9 you will also find a company portrait of us ...

Healthy digitalization?

The introduction of e-files, digital business models, new software functions, documentation, project planning 'on the run', constant availability - the rapid pace of digitalization is not only overwhelming employees, but has also long since overwhelmed many employers. The pressure to implement is increasing, while at the same time there is a growing fear that one's own skills and job security could be automated tomorrow. This fear is no longer limited to 'simple tasks', but also extends to the 'carpeted floors' - for example, in accounting as well as with lawyers and notaries.

As a result, the number of mental illnesses is rising and rising: psychological stress, burn-out, depression. No technical revolution in the history of mankind has taken place at such a speed as digitalization. One of the reasons why this change should be accompanied by psychosocial support ...