OSX Keyboard Shortcuts

Startup keyboard shortcuts

Press the key or key combination until the expected function occurs/appears (for example, hold Option during startup until Startup Manager appears, or Shift until “Safe Boot” appears). Tip: If a startup function doesn’t work and you use a third-party keyboard, connect an Apple keyboard and try again.

Key or key combination What it does
Option Display all bootable volumes (Startup Manager)
Shift Perform Safe Boot (start up in Safe Mode)
C Start from a bootable disc
T Start in FireWire target disk mode
N Start from NetBoot server
X Force Mac OS X startup (if non-Mac OS X startup volumes are present)
Command-V Start in Verbose Mode
Command-S Start in Single User Mode


Finder keyboard shortcuts

Key combination What it does
Command-A Select all items in the front Finder window (or desktop if no window is open)
Option-Command-A Deselect all items
Shift-Command-A Open the Applications folder
Command-C Copy selected item/text
Shift-Command-C Open the Computer window
Command-D Duplicate selected item
Shift-Command-D Open desktop folder
Command-E Eject
Command-F Find any matching Spotlight attribute
Shift-Command-F Find Spotlight file name matches
Option-Command-F Navigate to the search field in an already-open Spotlight window
Shift-Command-G Go to Folder
Shift-Command-H Open the Home folder of the currently logged-in user account
Command-I Get Info
Option-Command-I Show Inspector
Control-Command-I Get Summary Info
Shift-Command-I Open iDisk
Command-J Show View Options
Command-K Connect to Server
Shift-Command-K Open Network window
Command-L Make alias of the selected item
Command-M Minimize window
Option-Command-M Minimize all windows
Command-N New Finder window
Shift-Command-N New folder
Option-Command-N New Smart Folder
Command-O Open selected item
Shift-Command-Q Log Out
Option-Shift-Command-Q Log Out immediately
Command-R Show original (of alias)
Command-T Add to Sidebar
Shift-Command-T Add to Favorites
Option-Command-T Hide Toolbar / Show Toolbar in Finder windows
Shift-Command-U Open Utilities folder
Command-V Paste
Command-W Close window
Option-Command-W Close all windows
Command-X Cut
Option-Command-Y Slideshow (Mac OS X 10.5 or later)
Command-Z Undo / Redo
Command-1 View as Icon
Command-2 View as List
Command-3 View as Columns
Command-4 View as Cover Flow (Mac OS X 10.5 or later)
Command-, (Command and the comma key) Open Finder preferences
Command-` (the Grave accent key–above Tab key on a US English keyboard layout) Cycle through open Finder windows
Command-Shift-? Access Mac Help
Option-Shift-Command-esc Force Quit Finder
Command-[ Back
Command-] Forward
Command-Up Arrow Open enclosed folder
Control-Command-Up Arrow Open enclosed folder in a new window
Command-Down Arrow Open highlighted item
Command-Tab Switch application–cycle forward
Shift-Command-Tab Switch application–cycle backward
Command-Delete Move to Trash
Shift-Command-Delete Empty Trash
Option-Shift-Command-Delete Empty Trash without confirmation dialog
Spacebar (or Command-Y) Quick Look (Mac OS X 10.5 or later)
Command key while dragging Move dragged item to other volume/location (pointer icon changes while key is held–see this article)
Option key while dragging Copy dragged item (pointer icon changes while key is held–see this article)
Option-Command key combination while dragging Make alias of dragged item (pointer icon changes while key is held–see this article)


Application and other Mac OS X keyboard commands

Note: Some applications may not support all of the below application key combinations.

Key combination What it does
Command-Space Show or hide the Spotlight search field (if multiple languages are installed, may rotate through enabled script systems)
Option-Command-Space Show the Spotlight search results window (if multiple languages are installed, may rotate through keyboard layouts and input methods within a script)
Command-Tab Move forward to the next most recently used application in a list of open applications
Shift-Command-Tab Move backward through a list of open applications (sorted by recent use)
Shift-Tab Navigate through controls in a reverse direction
Control-Tab Move focus to the next grouping of controls in a dialog or the next table (when Tab moves to the next cell)
Shift-Control-Tab Move focus to the previous grouping of controls
Command-esc Open Front Row (if installed)
Option-Eject Eject from secondary optical media drive (if one is installed)
Control-Eject Show shutdown dialog
Option-Command-Eject Put the computer to sleep
Control-Command-Eject Quit all applications (after giving you a chance to save changes to open documents), then restart the computer
Control Option-Command-Eject Quit all applications (after giving you a chance to save changes to open documents), then shut down the computer
fn-Delete Forward Delete (on portable Macs’ built-in keyboard)
Control-F1 Toggle full keyboard access on or off
Control-F2 Move focus to the menu bar
Control-F3 Move focus to the Dock
Control-F4 Move focus to the active (or next) window
Shift-Control-F4 Move focus to the previously active window
Control-F5 Move focus to the toolbar.
Control-F6 Move focus to the first (or next) panel
Shift-Control-F6 Move focus to the previous panel
Control-F7 Temporarily override the current keyboard access mode in windows and dialogs
F9 Tile or untile all open windows
F10 Tile or untile all open windows in the currently active application
F11 Hide or show all open windows
F12 Hide or display Dashboard
Command-` Activate the next open window in the frontmost application
Shift-Command-` Activate the previous open window in the frontmost application
Option-Command-` Move focus to the window drawer
Command- – (minus) Decrease the size of the selected item
Command-{ Left-align a selection
Command-} Right-align a selection
Command-| Center-align a selection
Command-: Display the Spelling window
Command-; Find misspelled words in the document
Command-, Open the front application’s preferences window (if it supports this keyboard shortcut)
Option-Control-Command-, Decrease screen contrast
Option-Control-Command-. Increase screen contrast
Command-? Open the application’s help in Help Viewer
Option-Command-/ Turn font smoothing on or off
Shift-Command-= Increase the size of the selected item
Shift-Command-3 Capture the screen to a file
Shift-Control-Command-3 Capture the screen to the Clipboard
Shift-Command-4 Capture a selection to a file
Shift-Control-Command-4 Capture a selection to the Clipboard
Command-A Highlight every item in a document or window, or all characters in a text field
Command-B Boldface the selected text or toggle boldfaced text on and off
Command-C Duplicate the selected data and store on the Clipboard
Shift-Command-C Display the Colors window
Option-Command-C Copy the style of the selected text
Control-Command-C Copy the formatting settings of the selected item and store on the Clipboard
Option-Command-D Show or hide the Dock
Command-Control D Display the definition of the selected word in the Dictionary application
Command-E Use the selection for a find
Command-F Open a Find window
Option-Command-F Move to the search field control
Command-G Find the next occurrence of the selection
Shift-Command-G Find the previous occurrence of the selection
Command-H Hide the windows of the currently running application
Option-Command-H Hide the windows of all other running applications
Command-I Italicize the selected text or toggle italic text on or off
Option-Command-I Display an inspector window
Command-J Scroll to a selection
Command-M Minimize the active window to the Dock
Option-Command-M Minimize all windows of the active application to the Dock
Command-N Create a new document in the frontmost application
Command-O Display a dialog for choosing a document to open in the frontmost application
Command-P Display the Print dialog
Shift-Command-P Display a dialog for specifying printing parameters (Page Setup)
Command-Q Quit the frontmost application
Command-S Save the active document
Shift-Command-S Display the Save As dialog
Command-T Display the Fonts window
Option-Command-T Show or hide a toolbar
Command-U Underline the selected text or turn underlining on or off
Command-V Paste the Clipboard contents at the insertion point
Option-Command-V Apply the style of one object to the selected object (Paste Style)
Option-Shift-Command-V Apply the style of the surrounding text to the inserted object (Paste and Match Style)
Control-Command-V Apply formatting settings to the selected object (Paste Ruler Command)
Command-W Close the frontmost window
Shift-Command-W Close a file and its associated windows
Option-Command-W Close all windows in the application without quitting it
Command-X Remove the selection and store in the Clipboard
Command-Z Undo previous command (some applications allow for multiple Undos)
Shift-Command-Z Redo previous command (some applications allow for multiple Redos)
Control-Right Arrow Move focus to another value or cell within a view, such as a table
Control-Left Arrow Move focus to another value or cell within a view, such as a table
Control-Down Arrow Move focus to another value or cell within a view, such as a table
Control-Up Arrow Move focus to another value or cell within a view, such as a table
Shift-Command-Right Arrow Select text between the insertion point and the end of the current line (*)
Shift-Command-Left Arrow Select text between the insertion point and the beginning of the current line (*)
Shift-Right Arrow Extend text selection one character to the right (*)
Shift-Left Arrow Extend text selection one character to the left (*)
Shift-Command-Up Arrow Select text between the insertion point and the beginning of the document (*)
Shift-Command-Down Arrow Select text between the insertion point and the end of the document (*)
Shift-Up Arrow Extend text selection to the line above, to the nearest character boundary at the same horizontal location (*)
Shift-Down Arrow Extend text selection to the line below, to the nearest character boundary at the same horizontal location (*)
Shift-Option-Right Arrow Extend text selection to the end of the current word, then to the end of the following word if pressed again (*)
Shift-Option-Left Arrow Extend text selection to the beginning of the current word, then to the beginning of the following word if pressed again (*)
Shift-Option-Down Arrow Extend text selection to the end of the current paragraph, then to the end of the following paragraph if pressed again (*)
Shift-Option-Up Arrow Extend text selection to the beginning of the current paragraph, then to the beginning of the following paragraph if pressed again (*)
Control-Space Toggle between the current and previous input sources
Option-Control-Space Toggle through all enabled input sources
Command-Left Arrow Change the keyboard layout to current layout of system script
Command-Right Arrow Change the keyboard layout to current layout of Roman script
Option-Command-esc Force Quit

(*) Note: If no text is selected, the extension begins at the insertion point. If text is selected by dragging, then the extension begins at the selection boundary. Reversing the direction of the selection deselects the appropriate unit.


Universal Access – VoiceOver keyboard commands

Key combination What it does
Command-F5 or
fn Command-F5
Turn VoiceOver on or off
Control Option-F8 or
fn Control Option-F8
Open VoiceOver Utility
Control Option-F7 or
fn Control Option-F7
Display VoiceOver menu
Control Option-;
or fn Control Option-;
Enable/disable VoiceOver Control Option-lock
Option-Command-8 or
fn Command-F11
Turn on Zoom
Option-Command-+ Zoom In
Option-Command- – (minus) Zoom Out
Option-Control-Command-8 Invert/revert the screen colors
Control Option-Command-, Reduce contrast
Control Option-Command-. Increase contrast

Note: You may need to enable “Use all F1, F2, etc. keys as standard keys” in Keyboard preferences for the VoiceOver menu and utility to work.


Universal Access – Mouse Keys

When Mouse Keys is turned on in Universal Access preferences, you can use the keyboard or numeric keypad keys to move the mouse pointer. If your computer doesn’t have a numeric keypad, use the Fn (function) key.

Key combination What it does
8 Move Up
2 Move Down
4 Move Left
6 Move Right
1 Move Diagonally Bottom Left
3 Move Diagonally Bottom Right
7 Move Diagonally Top Left
9 Move Diagonally Top Right
5 Press Mouse Button
0 Hold Mouse Button
. (period on number pad) Release Hold Mouse Button

Leave a Reply

LinkedIn DNS hijacked, site offline

Agentless Backup is Not a Myth

LinkedIn is working on its right-on-the-ball-with-security reputation, this time letting slip its domain details.

According to this App.net post:


“LinkedIn just got DNS hijacked, and for the last hour or so, all of your traffic has been sent to a network hosted by this company [confluence-networks.com]. And they don’t require SSL, so if you tried to visit, your browser sent your long-lived session cookies in plaintext.” (User @berg)

The Register hasn’t yet confirmed that Confluence Networks is receiving the traffic as asserted by Berg, but LinkedIn.com was delivering a big white nothing at Vulture South around 03:15 GMT on 20 June 2013.

LinkedIn says it is working on the issue:

Meanwhile, it requests patience, a commodity that may be in short supply for those who last year had their passwords for the service perused by pilferers. ®

Steps to Take Before Choosing a Business Continuity Partner

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/20/linkedin_dns_hijacked/

LinkedIn DNS hijacked, site offline

Agentless Backup is Not a Myth

LinkedIn is working on its right-on-the-ball-with-security reputation, this time letting slip its domain details.

According to this App.net post:


“LinkedIn just got DNS hijacked, and for the last hour or so, all of your traffic has been sent to a network hosted by this company [confluence-networks.com]. And they don’t require SSL, so if you tried to visit, your browser sent your long-lived session cookies in plaintext.” (User @berg)

The Register hasn’t yet confirmed that Confluence Networks is receiving the traffic as asserted by Berg, but LinkedIn.com was delivering a big white nothing at Vulture South around 03:15 GMT on 20 June 2013.

LinkedIn says it is working on the issue:

Meanwhile, it requests patience, a commodity that may be in short supply for those who last year had their passwords for the service perused by pilferers. ®

Steps to Take Before Choosing a Business Continuity Partner

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/20/linkedin_dns_hijacked/

LinkedIn DNS hijacked, site offline

Agentless Backup is Not a Myth

LinkedIn is working on its right-on-the-ball-with-security reputation, this time letting slip its domain details.

According to this App.net post:


“LinkedIn just got DNS hijacked, and for the last hour or so, all of your traffic has been sent to a network hosted by this company [confluence-networks.com]. And they don’t require SSL, so if you tried to visit, your browser sent your long-lived session cookies in plaintext.” (User @berg)

The Register hasn’t yet confirmed that Confluence Networks is receiving the traffic as asserted by Berg, but LinkedIn.com was delivering a big white nothing at Vulture South around 03:15 GMT on 20 June 2013.

LinkedIn says it is working on the issue:

Meanwhile, it requests patience, a commodity that may be in short supply for those who last year had their passwords for the service perused by pilferers. ®

Steps to Take Before Choosing a Business Continuity Partner

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/20/linkedin_dns_hijacked/

LinkedIn DNS hijacked, site offline

Agentless Backup is Not a Myth

LinkedIn is working on its right-on-the-ball-with-security reputation, this time letting slip its domain details.

According to this App.net post:


“LinkedIn just got DNS hijacked, and for the last hour or so, all of your traffic has been sent to a network hosted by this company [confluence-networks.com]. And they don’t require SSL, so if you tried to visit, your browser sent your long-lived session cookies in plaintext.” (User @berg)

The Register hasn’t yet confirmed that Confluence Networks is receiving the traffic as asserted by Berg, but LinkedIn.com was delivering a big white nothing at Vulture South around 03:15 GMT on 20 June 2013.

LinkedIn says it is working on the issue:

Meanwhile, it requests patience, a commodity that may be in short supply for those who last year had their passwords for the service perused by pilferers. ®

Steps to Take Before Choosing a Business Continuity Partner

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/20/linkedin_dns_hijacked/

LinkedIn DNS hijacked, site offline

Agentless Backup is Not a Myth

LinkedIn is working on its right-on-the-ball-with-security reputation, this time letting slip its domain details.

According to this App.net post:


“LinkedIn just got DNS hijacked, and for the last hour or so, all of your traffic has been sent to a network hosted by this company [confluence-networks.com]. And they don’t require SSL, so if you tried to visit, your browser sent your long-lived session cookies in plaintext.” (User @berg)

The Register hasn’t yet confirmed that Confluence Networks is receiving the traffic as asserted by Berg, but LinkedIn.com was delivering a big white nothing at Vulture South around 03:15 GMT on 20 June 2013.

LinkedIn says it is working on the issue:

Meanwhile, it requests patience, a commodity that may be in short supply for those who last year had their passwords for the service perused by pilferers. ®

Steps to Take Before Choosing a Business Continuity Partner

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/20/linkedin_dns_hijacked/

Microsoft breaks bug-bounty virginity in $100,000 contest

Agentless Backup is Not a Myth

Microsoft is breaking its long-standing tradition of not paying for security vulnerabilities by offering a $100,000 cash prize for the first penetration tester to crack Windows 8.1 and a $50,000 bonus to explain how they did it.

At this year’s Black Hat USA conference – held at the end of July in the sweaty hell that is Las Vegas at that time of year – Microsoft will offer $100,000 (and a laptop) to the hacker who can demonstrate a critical vulnerability in Windows 8.1, either at the conference or afterwards.


Any successful hacker can earn an additional $50,000 “BlueHat Bonus” if they can tell Redmond how to fix a major flaw in the operating system. In addition, there’s an $11,000 bounty on Internet Explorer 11 Preview Edition vulnerabilities – but with a 30 day time limit – presumably so that any new problems can be fixed in time for the final release.

The market for software vulnerabilities is a contentious issue. Proponents point out that cash payouts are the only way for independent security researchers to make a living and that the resulting disclosures have immense benefits for end users. Opponents suggest that hackers should disclose responsibly as a matter of morality. Meanwhile, there’s a thriving black market for software flaws, especially zero-day vulnerabilities.

Many software companies, including Google, Paypal, and Facebook, offer bug bounties of varying amounts, and security researchers have reaped millions of dollars and built successful businesses as a result. Redmond has held off from similar policies until now.

Part of the reason for change at Microsoft is the appointment of Katie Moussouris to Redmond’s team senior security strategist. She has championed the rights of researchers to disclose flaws without fear of prosecution and pushed for Microsoft to share vulnerability data with third parties at the earliest opportunity. Now she appears to have helped Redmond cross the final frontier.

“Speaking with Katie Moussouris of Microsoft, this has been something that’s been hotly debated and discussed internally and externally at Microsoft for a long time,” Trey Ford, general manager of Black Hat told The Register. “It took her, I think, three years ago to help get this through the ranks and I’m really excited, this is a really great move I’m hoping to see Apple follow suit.”

Apple is still holding out against paying for vulnerability disclosures, and its debut Black Hat briefing last year was a disappointment. It wasn’t too long ago that Apple’s minions were breaking down journalists’ doors in the pursuit of intellectual property, and Cupertino is making a few mistakes of its own on the security front in the meantime.

Getting Microsoft online has been a major coup for the Black Hat conference, but Ford said this year’s jamboree (with DEFCON afterwards) covers sessions on security issues in 18 different security areas – a long way from the first conference in 1997, where the two-day event was dominated by enterprise server, ActiveX, and UNIX issues.

Since their inception, Black Hat and DEFCON have provided a forum where the suits of corporate culture and the freer spirits of the security research world can mingle and exchange ideas. As a result, we’ve seen major flaws patched in the internet’s backbone and useful insight into the current security landscape. Long may it continue. ®

Steps to Take Before Choosing a Business Continuity Partner

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/19/microsoft_bug_bounty_black_hat/

Thousands of fingered crims, informants spaffed in web security COCK-UP

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Exclusive An IT blunder splashed photos of suspected criminals and details of Brits who reported them over the internet, The Register can reveal.

The Facewatch website, which allows police and businesses to upload and share evidence of alleged petty crimes, was left wide open thanks to a web-server misconfiguration. The schoolboy error allowed anyone to easily access a huge cache of CCTV footage, photos and information about companies that sign up to the service.


El Reg was able to look through almost 5,000 records containing images and films of suspects dating back to March 2011.

We saw shoplifters pilfering from department stores, a man brandishing a stick inside a bookies, and people looking shifty in packed pubs presumably just before a crime took place. Some of the images even had names on them, which would be legally problematic if those pictured turned out to be innocent.

We also saw long lists of shops around Britain which have signed up to Facewatch, along with the names and contact details of their security guards and managers. This could come in handy for any crook wishing to intimidate a witness or exact revenge on the person who reported them to the police.

Big high-street names whose staff details were available for anyone to look at include the Carphone Warehouse, Lloyds Bank and Ladbrokes, which runs a nationwide chain of betting shops. There were also extensive lists of small businesses.

Publicly distributing images of suspected criminals could cause a legal headache due to strict rules on defamation and contempt of court: publishing evidence of a person apparently committing a crime risks prejudicing a jury, should the case ever come to trial, or could ruin their reputation.

Blighty’s privacy watchdog – the Office of the Information Commissioner – told us it was beginning inquiries that could lead to a formal investigation.

A spokesman said: “We have recently been made aware of a possible data breach which appears to involve the Facewatch website.

“We will be making enquiries into the potential breach of the Data Protection Act before deciding what action, if any, needs to be taken.”

‘Secured by design’

The website boasts it was declared “secured by design” by a police-run body that recognises products or business that meet the “Police Preferred Specification” on security. This badge of honour is normally given to secure buildings or products, such as window locks and burglar alarms, but Facewatch was awarded the online equivalent.

But with a gaping security hole in its website, this could make businesses think again about how stringent this standard actually is.

You didn’t have to be a light-fingered thief nor an elite hacker to get into the sensitive files: all that was required was changing “http” to “https” in the website’s address and all the information was there to be accessed.

Specifically, the Nginx software running the HTTPS site was incorrectly configured to list the contents of file directories on the web server rather than serving the intended web pages. Visiting http://facewatch.co.uk/ redirects to http://facewatch.co.uk/cms/ but this did not happen on the HTTPS site, which instead revealed the index of the server root directory, which could be explored to find website code, databases of users and folders packed with images.

We were told about the security hole by a source who was trying to report a crime. While trying to find the address of a HTTPS-encrypted server to send the images to, he found https://facewatch.co.uk/ gave him full read-only access to Facewatch’s file tree.

Our source said: “A novice who runs a church website would know not to allow directory browsing.”

We reported the security flaw to Facewatch, which closed the hole immediately.

The organisation’s chairman Simon Gordon told us the “accessible code related to a previous version” of its website software. And he argued the long lists of email addresses we saw were in the public domain already and could be “accessed by the public in order for people reporting crime to contact those who reported a crime on their behalf”.

The chairman admitted that contact details of security staff were left visible but they were people who took “all necessary precautions to protect their personal safety”. He continued:

We have undertaken penetration testing to ensure that the information stored in the Facewatch systems is secure and can confirm that all personal data are secure and that our systems are secure. The URL to which you referred us has been closed as this is no longer in use.

Facewatch takes the security of the information which it holds very seriously and works with its clients, including the UK police services, and the data protection regulators to ensure that all data is secure when it is being transmitted to the police or held on behalf of our clients.

The crimes which are reported through the Facewatch system do not relate to crimes against the person or which include violence and those using the system are aware that their business email addresses are made available to a variety of people, both by their own organisations and third parties.

Therefore, any risks in the publication of the email addresses are very unlikely. Our clients are required to post signs confirming that they are using CCTV and that images will be disclosed, many of our clients advertise that they are using the Facewatch system through such signs and by using other means. Therefore, the images of those that the police wish to contact are published with the full knowledge of the individuals concerned.

No names of any crime victims were hosted on the site due to ICO rules that state they should be deleted within 36 hours of recording them.

Some 63,000 people have downloaded Facewatch’s smartphone app and its images have been viewed nine million times, we’re told. As well as allowing officers and shop bosses to upload files, Facewatch allows Brits to use their mobiles to view CCTV stills and other photos of people wanted for questioning by cops.

Facewatch’s Gordon claimed some of the images we found on the server were part of that public mug-shot gallery.

“Some residual images of individuals that the police would like to contact in relation to certain reported crimes were available, these images had been made available to see if members of the public would be able to help with their identification,” Gordon said.

The scheme was first tested in London, before being rolled out across the UK. It is operated by a private company called FaceWatch Limited, based in Ipswich. ®

Agentless Backup is Not a Myth

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/19/facewatch_https_directory_index_error/

AXE-WAVING BIKER GANG SMASHES into swanky Apple UK store

Damage to the Apple Store window

Agentless Backup is Not a Myth

Pic Cops have arrested two men following a failed “smash and grab” robbery at Apple’s flagship store on Regent Street, London.

Detectives want to hear from anyone who may have witnessed the incident, which took place at 1am on Tuesday morning.

Damage to the shop window

Officers told The Register that up to eight people may have been involved in the attempted burglary. Cops said the gang used an axe to smash through a glass door, but were chased off by the fruity firm’s security team.

The gang then sped off on a number of scooters, forcing the police to scramble a helicopter to find them.

Two men, aged 21 and 18, were later cuffed in the fashionable North London borough of Islington: the pair are still being quizzed by the plod.

They were both arrested on suspicion of aggravated attempted burglary and dangerous driving, although the two have not yet been charged with any offence.

Anyone with any infomation on the attempted break-in should call the Westminster division of the Metropolitan Police’s Serious Acquisitive Crime Unit via 101. Anonymous tipsters can ring the confidential Crimestoppers hotline on 0800 555 111 instead. ®

Customer Success Testimonial: Recovery is Everything

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/19/two_detained_after_apple_store_raid_attempt/

Six nations ask Google for answers on Glass privacy

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

36 Privacy Commissioners from around the world have written to Google to ask, in the polite-but-firm language of international diplomacy, for some details about Google Glass.

The letter, signed by Privacy Commissioners or their equivalents from Canada, Australia, New Zealand, Mexico, Switzerland and Israel, plus several Canadian provinces.


The authors’ beef is simple: it looks like Glass could invade privacy in dozens of ways, but Google has told the world almost nothing about how the device works. That observation produced the following list of questions the Commissioners want answered:

  • What are the privacy safeguards Google and application developers are putting in place?
  • What information does Google collect via Glass and what information is shared with third parties, including application developers?
  • How does Google intend to use this information?
  • While we understand that Google has decided not to include facial recognition in Glass, how does Google intend to address the specific issues around facial recognition in the future?
  • Is Google doing anything about the broader social and ethical issues raised by such a product, for example, the surreptitious collection of information about other individuals?
  • Has Google undertaken any privacy risk assessment the outcomes of which it would be willing to share?
  • Would Google be willing to demonstrate the device to our offices and allow any interested data protection authorities to test it?

At the time of writing Google has not responded to the letter, which is addressed to Larry Page himself.

“We would be very interested in hearing about the privacy implications of this new product and the steps you are taking to ensure that, as you move forward with Google Glass, individuals’ privacy rights are respected around the world,” the authors say. “We look forward to responses to these questions and to a meeting to discuss the privacy issues raised by Google Glass.”

As do we all. ®

Agentless Backup is Not a Myth

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/19/six_nations_ask_google_for_answers_on_glass_privacy/

Spear phish your boss to win more security cash

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Despite weekly news of successful and nasty online attacks damaging organisations of every stripe, executive types remain blasé about security and don’t pay it enough attention, says Jason Clark, chief security officer at Websense, who recommends fighting back by phishing CEOs and board members.

Clark’s suggested attacks are controlled fakes, run by dedicated white hat outfits, and are designed to ensure suits get a brief jolt of fear rather than having to ask their personal assistants to arrange delivery of new platinum cards. Clark feels the experience of being phished is sobering because its delivery by email demonstrates how anyone in an organisation can be attacked.


Once suits understand that, Clark’s hope is it becomes easier for security professionals to have meaningful conversations with business decision makers and those who hold the purse-strings.

Such discussions need to get deeper and more frequent, he feels, because today too few executives pay more than lip service to security. When they do, they ask for assurance that the organisations they lead are complying with legislation and can demonstrate they have appropriate security controls.

Once suits are properly scared, they’ll be more interested in learning more about security, will ask more and more probing questions of their IT departments and eventually lead their organisations to a security regime that gives them the protection they need.

Clark’s advice is otherwise mundane: he suggests organisations ensure they have advance malware repulsion tools, spear phishing blockers and data protection tools to ensure valuable documents can’t leave the building. Few organisations he visits – Clark claims to meet 400 CSOs or CEOs a year – have all three in place. Around ten per cent of organisations he visits have used phake phishing.

Fewer still perform comprehensive threat modelling, a practice he recommends as the best route to understanding appropriate security investments. ®

Agentless Backup is Not a Myth

Article source: http://go.theregister.com/feed/www.theregister.co.uk/2013/06/19/spear_phish_your_boss_to_win_more_security_cash/