<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SC Small Firm.com &#187; Security</title>
	<atom:link href="http://www.scsmallfirm.com/wordpress/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.scsmallfirm.com/wordpress</link>
	<description>law practice management and more</description>
	<lastBuildDate>Tue, 31 Aug 2010 15:32:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Old hard drives</title>
		<link>http://www.scsmallfirm.com/wordpress/2010/07/old-hard-drives/</link>
		<comments>http://www.scsmallfirm.com/wordpress/2010/07/old-hard-drives/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 21:05:27 +0000</pubDate>
		<dc:creator>ckennaday</dc:creator>
				<category><![CDATA[Disposing of old tech]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.scsmallfirm.com/wordpress/?p=277</guid>
		<description><![CDATA[A few years back, a professor at a well-known law school told me how his university dealt with old computer hard drives. “We used to pay students to smash them with sledge hammers,” he recalled, “until someone got a piece of metal in his eye. Then we stopped.” Around the same time I heard this [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2010%2F07%2Fold-hard-drives%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2010%2F07%2Fold-hard-drives%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>A few years back, a professor at a well-known law school told me how his university dealt with old computer <a href="http://en.wikipedia.org/wiki/Hard_disk_drive" target="_blank">hard drives</a>. “We used to pay students to smash them with sledge hammers,” he recalled, “until someone got a piece of metal in his eye. Then we stopped.” Around the same time I heard this tale, I discovered an <a href="http://web.mit.edu/newsoffice/2003/diskdrives.html" target="_blank">experiment </a>by <a href="http://web.mit.edu/" target="_blank">MIT </a>researchers. The students at the MIT Laboratory for Computer Science (I’m sure you have a visual of what they might have looked like) purchased used hard drives from eBay and other sources. Of the approximately 170 drives, they found only 12 that were properly sanitized. The rest all contained data, including credit card numbers and medical records. Doh! This study sparked another project, this one involving “<a href="http://driveslag.eecue.com/" target="_blank">drive slagging</a>.” If you know that slag relates to molten metals, you probably figured out that drive slagging means melting down your hard drive. If you’d like to see some neat pictures, check out the link. I think you will agree, there’s no way to rescue that data! <a href="http://driveslag.eecue.com/"><img class="alignright size-thumbnail wp-image-282" title="images_pic-medium-25219-green_flames_are_good" src="http://www.scsmallfirm.com/wordpress/wp-content/uploads/2010/07/images_pic-medium-25219-green_flames_are_good1-150x150.jpg" alt="" width="150" height="150" /></a></p>
<p>Aside from melting, foolproof ways of sanitizing a hard drive so that it can be disposed of are few and the techniques for rescuing data on hard drives have improved over the last few years. I’ve heard experts in <a href="http://en.wikipedia.org/wiki/Computer_forensics" target="_blank">computer forensics</a> state that data can be retrieved from hard drives that were submerged in sea water, burned, and otherwise abused. Such feats are not inexpensive, of course. Spending $1000 for one drive would not be unusual (which is why you’re glad you made that <a href="http://www.corevault.net/scb" target="_blank">backup</a>, right?).</p>
<p>So, what’s the best way to dispose of a hard drive? See my <a href="http://www.scsmallfirm.com/wordpress/2009/12/ecycle/" target="_self">eCycle </a>post from December 2009.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.scsmallfirm.com/wordpress/2010/07/old-hard-drives/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scams against lawyers</title>
		<link>http://www.scsmallfirm.com/wordpress/2010/03/scams-against-lawyers/</link>
		<comments>http://www.scsmallfirm.com/wordpress/2010/03/scams-against-lawyers/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 19:57:15 +0000</pubDate>
		<dc:creator>ckennaday</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Law Office Management]]></category>
		<category><![CDATA[Law firm accounting]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.scsmallfirm.com/wordpress/?p=229</guid>
		<description><![CDATA[As a lawyer, what would you do if a prospective client contacted you by email and asked for your help collecting a large debt? What if you were sent a retainer check from a new client who contacted you through email? Would the answer be different if the client were a well-known foreign corporation? Lawyers [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2010%2F03%2Fscams-against-lawyers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2010%2F03%2Fscams-against-lawyers%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>As a lawyer, what would you do if a prospective client contacted you by email and asked for your help collecting a large debt? What if you were sent a retainer check from a new client who contacted you through email? Would the answer be different if the client were a well-known foreign corporation? Lawyers around the country and around the world have been falling victim to well-executed fraudulent schemes involving phony checks (or cheques). Though the scam varies, there’s always a phony check and a request for some of the funds to be wired by the attorney.</p>
<p><a href="http://jimcalloway.typepad.com/lawpracticetips/">Jim Calloway</a> recently blogged about scams against lawyers and linked to an article I recommend: <a href="http://www.okbar.org/news/front/2010/03/12-scams-targeting-lawyers.htm">Check Scams That Target Lawyers</a>. Another article I recommend is <a href="http://www.abanet.org/lpm/magazine/articles/v34/is5/pg58.shtml">How Not to Get Stung by Promises of Easy Offshore Work</a> by my colleagues <a href="http://asblastword.wordpress.com/">Laura Calloway</a> and <a href="http://thoughtfullaw.com/">David Bilinsky</a>. You might think it couldn’t happen to you, but the perpetrators are very sophisticated. A Houston attorney recently shared <a href="http://www.khou.com/news/Texas-Lawyers-Conned-by-check-scam-87422092.html">his story</a> of being taken for $182,500.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.scsmallfirm.com/wordpress/2010/03/scams-against-lawyers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>eCycle</title>
		<link>http://www.scsmallfirm.com/wordpress/2009/12/ecycle/</link>
		<comments>http://www.scsmallfirm.com/wordpress/2009/12/ecycle/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 20:24:50 +0000</pubDate>
		<dc:creator>ckennaday</dc:creator>
				<category><![CDATA[Disposing of old tech]]></category>
		<category><![CDATA[Law Office Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.scsmallfirm.com/wordpress/?p=217</guid>
		<description><![CDATA[Did Santa Claus bring you a new electronic item? Or did you purchase new hardware as a year-end capital expense? Whatever the reason, if you find yourself with old computers or electronics that are too old to benefit anyone (even the National Cristina Foundation won’t take Pentium II computers anymore), you need to responsibly dispose [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2009%2F12%2Fecycle%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2009%2F12%2Fecycle%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Did Santa Claus bring you a new electronic item? Or did you purchase new hardware as a year-end capital expense? Whatever the reason, if you find yourself with old computers or electronics that are too old to benefit anyone (even the <a href="http://www.cristina.org/rethink.html" target="_blank">National Cristina Foundation</a> won’t take Pentium II computers anymore), you need to <strong>responsibly</strong> dispose of the old clunker.</p>
<p>Being responsible means taking or shipping it to a government or private recycling center. It means doing a little research on the Internet to find out where to go and which location accepts what.  It means sanitizing hard drives and other storage media so that you don’t breach your ethical and legal duties to safeguard your client’s property (not to mention your own personal data). This can be done using software like <a href="http://www.dban.org/" target="_blank">Darik&#8217;s Boot And Nuke</a>, <a href="http://www.diskwipe.org/" target="_blank">Disk Wipe</a> or <a href="http://eraser.heidi.ie/" target="_blank">Eraser </a>.</p>
<p>You can also use a physical device to erase, like <a href="http://www.wiebetech.com/products/Drive_eRazer.php" target="_blank">Drive eRazer</a>, which works well if you have miscellaneous hard drives without the computer case. CD’s, DVD’s, floppies and tapes are the <a href="http://en.wikipedia.org/wiki/Tribble_(Star_Trek)" target="_blank">Tribbles</a> of the law office – they have a way of self-proliferating. Most new paper shredders can shred CD’s and old floppies.</p>
<p>Once your computer is sanitized and free of data, you need to find someone who will accept it for proper disposal. It is <strong>not </strong>proper to put a computer in a landfill!  For a list of e-cycling websites, go to the <a href="http://www.scbar.org/pmap" target="_blank">PMAP</a> pages of <a href="http://www.scbar.org">SC Bar.org</a> and find “<a href="http://www.scbar.org/member_resources/practice_management_pmap/technology/old_computers/" target="_blank">old computers</a>.”  Be sure to read the article there on disposing of computers responsibly &#8211;  by yours truly and <a href="http://rossipsa.com/" target="_blank">Ross Kodner</a>: “<a href="http://www.scbar.org/public/files/docs/PMAP/Dumpster.pdf" target="_blank">Dumpster Disasters</a>.”  Good luck and happy e-cycling!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.scsmallfirm.com/wordpress/2009/12/ecycle/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Metadata</title>
		<link>http://www.scsmallfirm.com/wordpress/2009/12/metadata/</link>
		<comments>http://www.scsmallfirm.com/wordpress/2009/12/metadata/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 21:37:01 +0000</pubDate>
		<dc:creator>ckennaday</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Word Processing]]></category>

		<guid isPermaLink="false">http://www.scsmallfirm.com/wordpress/?p=214</guid>
		<description><![CDATA[The most important thing to know about metadata is that it exists ]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2009%2F12%2Fmetadata%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2009%2F12%2Fmetadata%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Maybe you’ve heard about a thing called “metadata.” Say what? Usually, dropping buzzwords and using plain English is helpful, but not here – since <em>metadata</em> means “data about data” or “information about information.” Gee, thanks.</p>
<p>Metadata is actually the code or words contained in electronic documents that help the document function better somehow; for example, making it easier to search for the document on the computer. According to Catherine Sanders Reach, Director of the ABA Legal Technology Resource Center, “Metadata helps users save and retrieve documents more readily, by capturing information such as author, editor, &#8220;date created&#8221; and &#8220;date revised&#8221; in the hidden part of the document.</p>
<p>“However, other information about the document is also captured, such as additions, deletions, revisions, versions, comments, and other information about the document that an attorney may not want to share with others”</p>
<p>So, while metadata is useful, it can also be dangerous. Anyone with the inclination and a little know-how can look at metadata. Unfortunately, well-publicized stories of metadata embarrassments abound. Usually, they involve an electronic copy of Microsoft Word emailed or otherwise transmitted (intentionally or otherwise) to another person who exploits the information contained in the metadata to suit his or her own ends.</p>
<p>It’s not difficult to see that this could be particularly dangerous for lawyers, whose ethical duties to clients could be breached as well. Although South Carolina has not weighed in with an ethics opinion, the majority of states with opinions held that lawyers have a duty to exercise reasonable care to avoid disclosing confidential information via metadata when transmitting electronic files. To see all existing opinions, visit the ABA Legal Technology Resource Center&#8217;s metadata ethics opinion <a href="http://www.abanet.org/tech/ltrc/fyidocs/metadatachart.html" target="_blank">comparison chart</a>.</p>
<p>The question then is “how do I get rid of metadata?” (I wish to clarify that we are discussing the metadata in documents the attorney creates, not metadata which may be present in electronic evidence in a lawsuit, which may be subject to the federal and state rules or laws.)</p>
<p>Many “solutions” to the metadata problem aren’t practical – such as not transferring electronic files; scanning documents and saving in a new format; or copying and pasting into a plain text editor. A more realistic solution is to clean the documents before you share them. Microsoft attempted to address the issue with Office 2003 by releasing an add-in removal <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=144E54ED-D43E-42CA-BC7B-5446D34E5360&amp;displaylang=en" target="_blank">patch</a> for Word, Excel and PowerPoint files. In the year since it was released, there have been many reports of it failing to do a complete job of metadata removal, so I do not recommend relying on it.</p>
<p>Office 2007 comes with more built-in metadata removal tools, including Document Inspector. For a more in-depth discussion and instructions on metadata removal in Office 2007, see <a href="http://bit.ly/1pS6OM" target="_blank">http://bit.ly/1pS6OM</a>.</p>
<p>For most lawyers, third party software remains the best means of removing or minimizing metadata. Two products to consider are <a href="http://www.payneconsulting.com" target="_blank">Metadata Assistant</a> by Payne Consulting  (priced from $80.00 for single workstation and more for enterprise-wide versions) and <a href="http://www.workshare.com/" target="_blank">Workshare Protect</a> (starting at $29.95).</p>
<p>While most of the problems with metadata arise from Microsoft software, to a lesser degree metadata is in other products as well, such as WordPerfect and PDF files. For pointers on dealing with WordPerfect, see <a href="http://www.corel.com/">www.corel.com</a> and search for metadata in the knowledgebase.</p>
<p>Adobe Acrobat (PDF) is usually a secure format for transferring documents electronically if the document is secured or restricted. For more on securing Acrobat PDF files, see <a href="http://www.adobe.com/support/security/" target="_blank">http://www.adobe.com/support/security/</a>.</p>
<p>The most important thing to know about metadata is that it exists and to exercise caution when transferring electronic files, utilizing removal tools when necessary.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.scsmallfirm.com/wordpress/2009/12/metadata/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hurricanes</title>
		<link>http://www.scsmallfirm.com/wordpress/2009/09/hurricanes/</link>
		<comments>http://www.scsmallfirm.com/wordpress/2009/09/hurricanes/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 15:12:42 +0000</pubDate>
		<dc:creator>ckennaday</dc:creator>
				<category><![CDATA[Backups]]></category>
		<category><![CDATA[Disaster Prep]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[disasters]]></category>
		<category><![CDATA[Hurricanes]]></category>
		<category><![CDATA[preparedness]]></category>

		<guid isPermaLink="false">http://www.scsmallfirm.com/wordpress/?p=160</guid>
		<description><![CDATA[Hurricane Hugo was our big one.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2009%2F09%2Fhurricanes%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.scsmallfirm.com%2Fwordpress%2F2009%2F09%2Fhurricanes%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>To the people of Mississippi and Louisiana, Katrina is the big one. For south Florida, it is Andrew. But for the people of South Carolina, Hugo is our big hurricane. Hugo was the most intense hurricane ever to strike the US coast north of Florida<a href="http://www.geocities.com/hurricanene/hurricanehugo.htm" target="_blank">*</a>.  It killed 35 people in the U.S. and caused billions of dollars in damage.<a href="http://www.geocities.com/hurricanene/hurricanehugo.htm" target="_blank">*</a> Everyone who lived through that hurricane has a story to tell and most of us will never forget it. One of the things that made Hugo so unforgettable was that it wasn’t limited to only the coastal communities. Hugo roared inland, cutting a huge swath across South Carolina. Even Charlotte suffered, with parts of the city without power for nearly two weeks.</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-159" title="Hurricane Hugo" src="http://www.scsmallfirm.com/wordpress/wp-content/uploads/2009/09/hurhugo-440x292.gif" alt="hurhugo" width="440" height="292" /></p>
<p>Today, September 21, is the twenty year anniversary of Hurricane Hugo.  (Since the eye of Hugo actually made landfall near midnight on the 21<sup>st</sup>, we officially remember both the 21<sup>st</sup> and 22<sup>nd</sup> as the Hugo anniversary.)  If you don’t remember Hugo, or you want to reflect on it after the passage of twenty years, the Charleston Post and Courier has posted photos, stories, videos and more <a href="http://www.postandcourier.com/stories/2009/sep/16/remembering-hugo2/" target="_blank">online</a>. You can also find links to helpful hurricane preparedness resources there. The SC Bar <a href="http://www.scbar.org/member_resources/practice_management_pmap/office_management/prepare/" target="_blank">disaster and emergency preparedness page</a> contains even more links to other resources. Be sure to click the link to request a free copy of the Bar disaster preparedness handbook, <em><a href="mailto:prepare@scbar.org">Prepare</a></em>, while you are there (or follow this link).</p>
<p>Perhaps we should set aside September 21 every year to review and update our firm’s disaster procedures. Even solos should do this, particularly where technology is concerned. Everyone should be able to answer this question with certainty: “If something happened to my computer today (theft, hard drive failure, flood, fire) can I be up and running on another computer – with all my previous work and programs – quickly and simply?”  If you can’t answer this question in the affirmative, <a href="mailto:pmap@scbar.org">contact me</a>.</p>
<p>If you were practicing law during Hugo, please comment below and share your memories and tips &#8212; they may benefit other lawyers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.scsmallfirm.com/wordpress/2009/09/hurricanes/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
