Category: b.r.m.

The letter carrier is called 'Domain' ...

Without a clear address, no message reaches the recipient on the Internet; in this respect, 'virtual life' and 'real life' are similar. This address, called a 'domain', is a coherent sub-area within the Internet hierarchy that allows exact addressing. Network customers can freely choose the names of the domains - if not already assigned. They register the name with the responsible registry, the NIC (Network Information Center) of the respective top-level domain to which the endings on the far right of the Internet address refer (e.g. .de, .com or .org). In Germany, 'DENIC eG' registers all Internet addresses ending in .de.

The domain system resembles a widely ramified root system. At the top of the hierarchy is the root level, followed by the top-level domains and then the subordinate second- and third-level domains. In the address www.brm.de, for example, the 'www' is the root level that refers to the 'World Wide Web', the '.de' determines the German top-level domain, a 'brm' refers to our own domain in the second level, and possible further additions in the third and fourth levels allow precisely defined pages on our homepage to be accessed. The selection and registration of domains is a standard task, also for our for our IT service.

Impress - the page impressions

Page views - or page impressions - measure the number of page views of online content, i.e. clicks. It is primarily a commercial key figure that is determined monthly by the 'Gesellschaft für die Verbreitung von Werbeträgern e.V.' (IVW). Those who take part in the process are also subject to the IVW's regulations. To date, this includes around 1,000 fixed websites, 300 mobile offerings and 300 apps. The IVW figures are of particular interest to media providers, media agencies and other advertisers who are looking to use their customers' budgets as effectively as possible and are looking for suitable online advertising platforms to do so. Not every action counts as a 'call'. Automatic reloads, multiple visits by web robots or clicks when closing a page, for example, are not included in the figures.

It smells like quantum

Anyone who deals with quantum computers will soon find their head spinning. You will suddenly find yourself deep in the field of theoretical and atomic physics. Here is just this much: where 'traditional computers' are based on two voltage states that are either exceeded or fallen short of (the bits), a quantum computer uses the many different states that an electron can assume at molecular level (the qubits). Instead of the usual 'physical space', a quantum computer uses the 'complex space' of quantum mechanics. The computing power increases and completely new algorithms become possible. It is also clear that such computers will no longer run under Windows 10 or MacOS.

Quantum computers have not yet progressed beyond the experimental stage - up to a maximum of 1,000 qubits - even if there are occasional announcements of success, presumably to attract funding. Furthermore, quantum computers are unlikely to be suitable for commercial or private use because they generally require 'superconductivity', i.e. the loss-free transmission that only occurs near absolute zero. To put it bluntly: if you want to use a quantum computer, you first have to build your own power station. Nevertheless, quantum computers are of course extremely interesting for government and intelligence tasks: no conceivable encryption could withstand the attack of quantum-based computing power. This is what makes research in this field so interesting. We, on the other hand, assume that we will not need any knowledge of quantum mechanics for our IT service in the foreseeable future.

Sandbox: The data training ground

Almost everyone has had them in their folders: emails with dubious attachments. The 'sandbox' was created for such potential malware. Like generals who first play through the suspected course of a battle in a sandbox, the impact of the code is analyzed in a quarantine area. Some programs already have a (weak) sandbox function as a plug-in, e.g. the Java Runtime Environment (JRE). Other methods take a much more restrictive approach: the entire browser is executed in an isolation area, sealed off from all write access to the hard disk. Any attempted access is redirected to a separate subdirectory that can be easily deleted. Possible 'malware' does not reach its target. Others build a 'virtual machine' (VM). The computer is simulated on a software level, isolated from the real computer in every respect. Only a 'virtual prison' is then 'infected'. Attempts at system changes, the creation of new network connections or the unmotivated opening of files are always considered suspicious.

Excellent as a trainer

In the digital sector, many paths lead to ROM. There are career changers, online students and do-it-yourself experts. As one of the first regional IT companies, b.r.m. has now been recognized by the Oldenburg Chamber of Industry and Commerce for its "outstanding achievements in vocational training". We would like to thank you for this honor, also on behalf of the many partners with whose help we have been able to pave the way to a successful future for young people. You can find the certificate here ...

DSGVO: Business cards for the visit

A familiar picture: at the end of a customer meeting, the partners exchange their business cards. Both of them later enter the data contained on them into their respective customer databases, but they have already violated the new General Data Protection Regulation (GDPR) several times. At least if you take the wording of the law at its word. This is because the GDPR is primarily intended to create 'more data transparency'. Every partner would therefore have to be informed immediately about which personal business card data is processed and how, and which rights of objection this person has in the course of data processing.

How these information obligations are to be fulfilled is described in particular in Articles 13 and 14 of the GDPR. It also states that this information must be provided immediately. So if two people hand over their business cards to each other, for example at a trade fair, then both would have to inform each other about the reciprocal handling of the data in accordance with Art. 13 GDPR. However, a short sentence is by no means sufficient for this; the required data protection information would barely fit on an A4 page. In reality, compliance with the GDPR would therefore be more like a slapstick act, with both parties 'texting' each other for pages on end. It would also be far removed from reality to hand the other person a piece of paper with data protection information when handing over business cards. Combined with the request to confirm this in writing. Especially as this would pose a problem in terms of subsequent verifiability.

In view of the impracticability of the GDPR, politicians are already fiddling around, and not just on this point. A spokesperson for the Berlin supervisory authority said that the mere "receipt of the business card does not in itself trigger an obligation to provide information". This 'duty to inform' would only arise in cases where the data contained on the card is stored. Although this would make things easier, it would still contradict the intention of why business cards are exchanged in the first place. Companies store the data from business cards handed over in their customer data management program so that they can expand their own partner network in the business interests of both sides. Quite apart from this, the supervisory authority also fails to state the legal basis on which it arrived at its unusual opinion. This is because the statement by the above-mentioned employee contradicts the wording of the regulation. In other words, the GDPR is still in conflict with reality in many respects.

Bitkom Managing Director Dehmel recommends informing every person who has handed over a business card promptly afterwards about the mandatory information in accordance with Art. 13 GDPR in order to offer them the opportunity to object to the data processing at a later date. Such a solution would still contradict the direct wording of the law, but at least it seems more 'practicable'. What the GDPR lacks above all, however, are concrete and legally certain statements and assistance from the supervisory authorities. The GDPR urgently needs practical 'implementing provisions'.

The money is the mice

The opportunity to generate money online is in the hands of every computer user every day. Twenty years ago, nobody would have thought that a single click of the mouse would one day become the most important key figure on the Internet. The mouse click as a navigator not only guides users through the vast space of the Internet, it has also become the universally accepted 'currency' in e-commerce, because on the one hand it at least signals 'interest', and on the other hand it even enables purchases to be made. Almost every interface on the Internet is now operated intuitively with the mouse. This will continue to be the case until the further development of speech recognition software could even relieve us of this tedious manual work ...

Nothing works without a CPU

It is not without reason that the CPU is considered the 'heart' of every computer. This central processing unit (CPU) - or central processing unit (CPU) - is a miniaturized computing chip that can process defined computing tasks ('algorithms') due to its 'architecture' of semiconductors (or 'transistors'). Today, CPUs are not only found in computers, but also, for example, in washing machines, TV sets, cars and ticket machines.

The main components of such a computing core (or processor) are 'modules' that perform different tasks. At the center is always the arithmetic-logic unit (ALU). There is also the control unit, which primarily monitors the addresses, as well as several registers and a memory manager (memory management unit or MMU). Co-processors support the central unit in its tasks as 'service providers' - for example, by taking over computationally intensive floating point operations.

Modern CPUs are designed as multi-core units, which supports parallel processing and speed when solving tasks. Data lines ('buses') enable communication with other components of the computing system, in particular with the main memory. The 'caches' (intermediate memory) enable rapid further processing of partial results.

The choice of CPUs used in a company should be based on the tasks to be performed. The most expensive solution is by no means always the best or most efficient.

Hands off WhatsApp!

The WhatsApp messenger service is not compatible with the General Data Protection Regulation (GDPR). It should therefore not be used in the workplace. In the words of the Lower Saxony State Office for Data Protection: "The LfD Lower Saxony has already publicly emphasized several times that the use of WhatsApp by companies for business communication violates the General Data Protection Regulation (GDPR)."

The main reason for the infringement is the technical process used by Facebook subsidiary WhatsApp Inc. in California. A user registers there with their mobile phone number and the messenger service then reads the address book of users on their smartphones unnoticed. Ostensibly to locate other WhatsApp users. This comparison is repeated at regular intervals.

Despite all the data collection mania, the company is trying to keep a 'lean foot' on its own shoulders: Users alone are responsible for the legality of data transmission. In the event of a case, the criminal provisions of the GDPR would then also apply to the users alone. According to its 'Privacy Policy', WhatsApp also uses the data obtained for its own purposes: The company reserves the right to make extensive use of the information collected, for example for "measurement, analysis and other company services". In addition, WhatsApp generally shares information with other Facebook companies.

The conclusion of the German data protection experts: "The transmission of contact data from the address book to WhatsApp is regularly inadmissible." To make matters worse, possible sanctions under the GDPR would only affect the company that allowed the use of WhatsApp in its area of responsibility.

The advice to companies and organizations can therefore only be this: Ban the use of WhatsApp at all operational levels.

GDPR: Affected five times over

Compared to the German Federal Data Protection Act (BDSG), the GDPR brings little that is new in terms of 'data subject rights' - with the exception of the right to data portability. However, it often specifies the vague requirements of the BDSG considerably. The new data subject rights in detail:

1. The obligation to provide information (Art. 13 and 14 GDPR): This already exists in principle in the BDSG. However, it is no longer sufficient to simply state the identity of a data controller. In future, it will also be mandatory to provide contact details for both the processor and the responsible data protection officer. The legal basis on which data is collected and the intended duration of storage must also be stated. The biggest innovation is probably the fact that information must be provided unsolicited about every data transfer to a third country or an international organization. It must also be possible to withdraw consent at any time.

2. The right of access (Art. 15 GDPR): Every data provider has the right to know whether their personal data is being processed and to whom it is being forwarded. This corresponds roughly to Section 34 BDSG. However, the GDPR extends the scope of information. In principle, the duration of storage, the purpose of use and the origin of the data must be stated. The person whose data has been collected has the right to rectification, erasure and complaint. All information must be provided free of charge (Art. 12 para. 5 GDPR).

3. The 'right to be forgotten' (Art. 17 para. 2 GDPR): Individuals whose data has been collected can request the erasure of their data, unless statutory retention periods apply (e.g. in criminal records). It is not yet clear whether data collectors must also enforce erasure with the subsequent institutions to which data has been forwarded - or whether there is only an obligation to inform them of the request.

4. The right to data portability (Art. 20 GDPR): This is a provision that the BDSG was previously unaware of. Data collectors must make their collected data available to the data subject on request in a 'structured, commonly used and machine-readable format'. This paragraph is primarily aimed at 'social networks'. Anyone who wants to switch from Facebook to another provider, for example, must receive their collected 'data treasure trove' (photos, texts, etc.) in a readable form that is compatible with the technical conditions on the new platform. The popular excuse of 'technical hurdles' therefore no longer applies. How this will work in practice is still unclear.

5. The right to object (Art. 21 GDPR): Any person who provides their data must be able to object to any form of further processing, for example for advertising purposes. However, this provision can already be found in the BDSG (Section 28 (4)).