Thứ Sáu, 18 tháng 4, 2014

Microsoft Key Management Service (KMS) at the University of Michigan (S4362)

http://www.itcs.umich.edu/itcsdocs/s4362/

Microsoft Key Management Service (KMS)
at the University of Michigan

S4362 • November 2009

This document provides information for system administrators on the Microsoft Key Management Service (KMS) and the university's KMS server.

Table of Contents


What Is KMS?

Beginning with Windows Vista and Windows Server 2008 products, Microsoft implemented the Key Management Service (KMS) for validating its Enterprise software. Future Enterprise products will also be KMS-capable.

KMS offers many advantages — especially to computer lab administrators — and must be used on any machine capable of connecting to a U-M KMS-served network. In the rare circumstances where this is not possible, system administrators may request a Multiple Activation Key (MAK). There is only one situation where you should use an MAK: the machine is located off-campus and is unlikely to connect to the campus network — even through a Virtual Private Network (VPN) — for at least 6 months.

KMS Server at U-M

A university-wide KMS server is available at no charge for university-owned workstations and servers. Co-hosted by Information and Technology Services (ITS) and the University Library, this secure service is reliable and redundant.

FOR UNIVERSITY-OWNED MACHINES ONLY: U-M policy prohibits using KMS on a personally-owned computer, even if it is used for university business and is running university-licensed software.

The server's addresses are:

  • mskms.umich.edu

  • 141.211.175.165      141.213.143.150      141.213.238.150

We highly recommend U-M system administrators use this service to manage KMS-capable Microsoft Enterprise products deployed on university-owned computers. You should only consider running a separate KMS server under very rare circumstances.

Activating Products

  • AUTOMATIC: Microsoft KMS-capable products will automatically find the university-wide KMS server under either of the following conditions:

    • the machine is within the UMROOT domain.

    • uses a DNS server that includes an SRV record for the to-be-activated workstation.

  • MANUAL: You can manually set up KMS activation if the machine:

    • has an IP address within a university-owned subnet, including Virtual Private Network (VPN) connections

    • is able to use in- and outbound TCP port 1688 to access mskms.umich.edu.
      FIREWALL? You only need to provide access to the U-M's network using either mskms.umich.edu, university subnets, or the KMS server's IP addresses. For those who use Virtual Firewall, you should be covered by a Global Rule, but please check with the service owners.

Additional Resources

Visit ITS's Information System to obtain ITS computing documentation and other resources. A list of relevant documents follows:

Microsoft Documentation

ITS's IT Staff section provides a variety of help resources for its products and services.

The ITS Service Center provides a variety of computing help resources.

For further help with this or any other topic, call 734-764-HELP [4357] or submit an online service request.




Appendix A: Manually Activating Machines

If the machine cannot be set up for automatic activation but meets the manual activation criteria noted in Activating Products, follow these steps:

  1. From the Start menu, select All Programs then Accessories.

  2. RIGHT-click Command Prompt and select Run as administrator.

  3. In the User Account Control window, click Continue.

  4. In the Command Prompt window, enter the commands appropriate for your product.
    NOTE: The first command points the activation to the U-M KMS server. The second command activates the workstation or server.

    • Windows Vista and Server 2008 up to R1:

      %windir%\system32\cscript slmgr.vbs -skms mskms.umich.edu
      %windir%\system32\cscript slmgr.vbs -ato

    • Windows 7 and Server 2008 R2 and later:

      %windir%\system32\cscript slmgr.vbs /skms mskms.umich.edu
      %windir%\system32\cscript slmgr.vbs /ato

Appendix B: Creating an SRV Record

NOTE: In order for auto-discovery to work, the DNS domain corresponding to one or both of the following must contain the KMS SRV record:

  • The primary DNS suffix of the computer

  • The DNS domain name assigned by DHCP

To create an SRV record:

  1. In the DNS server, open the Bind zone file.

  2. Enter a line (SRV record) in the form of

    _vlmcs._tcp.[your subdomain].umich.edu. 3600 IN SRV 0 100 1688 mskms.umich.edu

    replacing [your subdomain] with the correct subdomain without the brackets. For example, at the School of Public Health, the line would look like

    _vlmcs._tcp.sph.umich.edu. 3600 IN SRV 0 100 1688 mskms.umich.edu

Appendix C: Troubleshooting

You can fix most failed KMS activations by re-registering the software and then manually activating the machine.

  1. From the Start menu, select All Programs then Accessories.

  2. RIGHT-click Command Prompt and select Run as administrator.

  3. In the User Account Control window, click Continue.

  4. In the Command Prompt window, enter the command appropriate for your operating system.

  5. Proceed with step 4 of Appendix A: Manually Activating Machines.

REDUCED FUNCTIONALITY MODE: If the machine you're attempting to recover is already in Reduced Functionality Mode, you'll need to use Internet Explorer to access the Command Prompt.

  1. In Internet Explorer's Address Bar, enter C: and press the Enter key.

  2. If you receive an Internet Explorer Security dialog box, click Allow.

  3. In the Windows Explorer window, navigate to C:\Windows\System32.

  4. RIGHT-click the cmd file and select Run as administrator.

  5. Proceed to step 4 (Command Prompt) at the beginning of this troubleshooting section.

Microsoft maintains a Knowledgebase article on troubleshooting Volume Activation error codes that you might find helpful. However — for error code 0x800706BA: The RPC server is unavailable — the Microsoft-provided solution is incorrect. You should instead follow the re-registering the UPK and manually configuring steps at the beginning of this troubleshooting section.

Appendix D: Running Your Own KMS Server

The university provides — at no charge — a secure, reliable and redundant KMS server. We highly recommend you use this service.

In the following rare events, you may need to provide your own KMS server.

  1. The cluster you want to activate:

    1. is not located within the U-M networks.

    2. cannot use the university's VPN.

  2. A local firewall restricts access to mskms.umich.edu through in- and out-bound TCP port 1688.

CAVEATS

  • You must fully understand the terms and conditions of the university's Microsoft Enterprise Agreement.

  • Your KMS service must absolutely prevent machines and virtual machines not owned by the university to validate.

  • You must be prepared to accept personal legal liability and for that of U-M in the event your KMS service permits even one machine not owned by the university to illegally validate.

Appendix E: KMS-Capable Products with Universal Product Keys (UPK)

Windows 7  
Enterprise 33PXH-7Y6KF-2VJC9-XBBR8-HVTHH
Enterprise N YDRBP-3D83W-TY26F-D46B2-XCKRJ
Enterprise E C29WB-22CC8-VJ326-GHFJW-H9DH4
Professional FJ82H-XT6CR-J8D7P-XQJJ2-GPDD4
Professional N MRPKT-YTG23-K7D7T-X2JMM-QY7MG
Vista  
Business YFKBB-PQJJV-G996G-VWGXY-2V3X8
Business N HMBQG-8H2RH-C77VX-27R82-VMQBT
Enterprise VKK3X-68KWM-X2YGT-QR4M6-4BWMV
Enterprise N VTC42-BM838-43QHV-84HX6-XJXKV
Windows Server 2008 (see also R2 product keys)
Standard w/ Hyper-V TM24T-X9RMF-VWXK6-X8JC9-BFGM2
Enterprise w/ Hyper-V YQGMW-MPWTJ-34KDK-48M3W-X4Q6V
Datacenter 7M67G-PC374-GR742-YH8V4-TCBY3
Datacenter w/ Hyper-V 22XQ2-VRXRG-P8D42-K34TD-G3QQC
for Itanium 4DWFP-JF3DJ-B7DTH-78FJB-PDRHK
Web Server WYR28-R7TFJ-3X2YQ-YCY4H-M249D
Windows Server 2008 R2
Standard R2 YC6KT-GKW9T-YTKYR-T4X34-R7VHC
Enterprise R2 489J6-VHDMP-X63PK-3K798-CPX3Y
Datacenter R2 74YFP-3QFB3-KQT8W-PMXWJ-7M648
R2 for Itanium GT63C-RJFQ3-4GMB6-BRFB9-CB83V
R2 HPC Edition FKJQ8-TMCVP-FRMR7-4WR42-3JCD7
Web Server R2 6TPJF-RBVHG-WBW2R-86QPH-6RTM4

Thứ Tư, 16 tháng 4, 2014

Print a customized legend or title - Project

http://office.microsoft.com/en-ca/project-help/print-a-customized-legend-or-title-HA102809399.aspx

Print a customized legend or title

Sometimes the items in a print preview are what you want, but if not, you can customize them. You can even remove the project title or legend.

Here's how you can change which items, like a project title or legend, are included when you print a Gantt chart or Diagram view.

  1. In the Gantt chart view, click Gantt Chart Tools Format > Format > Bar Styles.

  1. To include a bar name in the printed legend, delete the asterisk in front of the name. And if you don't want to print a bar name, just add an asterisk in front the bar's name.

  1. Click File > Print and preview before printing.
  2. To change things like the page orientation, margins, header, footer, legend, or include other items click, File > Print > Page Setup.

For more on setting printing options, see Print a project schedule.

Don't print the legend and title

If you'd rather not include the legend in print, here's how you can hide it:

  1. Click File > Print > Page Setup.
  2. Click Legend, and under Legend on click None.

If you have a header or title but don't want it to print it:

  1. Click File > Print > Page Setup.
  2. Click Header and delete the text.

 Tip   If you want the header but in a different position, you can edit the text, position or change the format.

 Note   Remember that the header you set will be the same on every page, and you can't customize or specify on which page it's included.

Read more about setting up your page for print.

Hướng dẫn sử dụng BitLocker để mã hóa dữ liệu trong Win 7

http://vnreview.vn/tu-van-may-tinh/-/view_content/content/244779/huong-dan-su-dung-bitlocker-de-ma-hoa-du-lieu-trong-win-7

Hướng dẫn sử dụng BitLocker để mã hóa dữ liệu trong Win 7

Nếu bạn có một số dữ liệu quan trọng cần lưu trong ổ cứng máy tính hoặc ổ USB flash, Microsoft cung cấp cho bạn công cụ mã hóa BitLocker để đảm bảo dữ liệu của bạn được bảo vệ với mức cao nhất. VnReview hướng dẫn bạn cách thực hiện mã hóa dữ liệu bằng công cụ này trên Windows 7.

Bài liên quan:

Kích hoạt tính năng BitLocker bị lỗi

Bảo mật ổ đĩa bằng BitLocker trên WinXP

BitLocker Drive Encryption là gì?

Đây là chương trình được Microsoft tích hợp trên Win 7 phiên bản Enterprise, Win 7 Ultimate và Win Server 2008 nhằm giúp người sử dụng mã hóa ổ cứng và ổ USB flash để bảo vệ dữ liệu cá nhân. Lưu ý: các phiên bản Windows 7 khác không được hỗ trợ tính năng này.

Bật BitLocker mã hóa ổ USB flash (ổ cứng trong máy cũng tương tự)

1) Cắm USB muốn mã hóa vào máy

Vào Control Panel > System and Security > BitLocker Drive Encryption > mở ra bảng chứa các ổ cứng và ổ USB trên máy > chọn ổ USB muốn mã hóa > Turn On BitLocker

Cách khác: vào My computer > chuột phải vào ổ USB muốn mã hóa > chọn Turn On BitLocker

2) Hộp thoại mới hiện ra với hai lựa chọn để check vào:

Use a password to unlock the drive: Lựa chọn này cho phép bạn sử dụng mật khẩu để mở ổ mã hóa, bạn cần nhập chính xác mật khẩu vào hai ô trống bên dưới. Chú ý mật khẩu phải ít nhất có 7 ký tự và bạn cần bảo vệ mật khẩu của mình.

Use my smart card to unlock the drive: sử dụng thẻ thông minh để mở ổ mã hóa. Bạn cần cắm thẻ vào máy để xác nhận.

Sau khi lựa chọn phương thức sử dụng khẩu bạn nhấn Next để tiếp tục

3) Hộp thoại khác hiện ra yêu cầu bạn chọn "lưu giữ key phục hồi" hoặc "in key phục hồi" này để trong trường hợp bạn quên mật khẩu hoặc mất thẻ thông minh thì bạn dùng key này để truy xuất được vào ổ mã hóa. Bước này là bắt buộc nếu không nút Next sẽ không sáng lên. Sau đó ấn Next để tiếp tục.

4) Hộp thoại mới hiện ra hỏi bạn có sẵn sàng để mã hóa ổ này > bấm Start Encrypting để bắt đầu

5) Quá trình mã hóa

6) Mã hóa xong > ấn nút Close.

Sử dụng ổ đã được mã hóa

Khi cắm ổ USB đã được mã hóa vào máy tính (sử dụng Win 7) ta sẽ thấy trên ổ đĩa có biểu tượng một chiếc khóa màu đồng đang đóng. Kích vào để truy cập thì có một hộp thoại yêu cầu nhập mật khẩu hiện lên, nhập mật khẩu xong bấm Unlock (mở khóa) thì biểu tượng cái khóa lúc này thay đổi thành đã được mở, có màu xám và ta có thể làm việc với dữ liệu trong ổ.

Nếu đưa ổ USB này sang máy sử dụng WinXP thì không thấy có biểu tượng hình ổ khóa. Truy cập vào ổ này thấy hiện ra các file dữ liệu đã được mã hóa có đuôi .NG và những file cần thiết của chương trình BitLockerToGo đã được cài vào để giúp truy xuất dữ liệu ổ USB khi chạy trong WinXP. Bạn cần nhập chính xác mật khẩu (đã được đặt khi mã hóa) khi chương trình này hỏi, chú ý là ổ cứng lúc này vẫn ở dạng chỉ được đọc / copy dữ liệu ra chứ không được sửa hoặc thêm dữ liệu vào. Nếu muốn thêm bớt / chỉnh sửa dữ liệu thì bạn cần sử dụng trên Win 7.

Các file được mã hóa có đuôi .NG

Nếu muốn quản lý ổ đã được mã hóa, bạn bấm chuột phải vào ổ đó, chọn Manage BitLocker. Bảng hiện ra cho phép bạn thay đổi mật khẩu, xóa mật khẩu, thêm tính năng sử dụng thẻ thông minh để mở khóa, lưu hoặc in key khôi phục hoặc tự động mở khóa ổ đĩa đối với máy đang sử dụng.

Tắt BitLocker

1) Cắm ổ USB đã mã hóa vào máy

2) Nhập mật khẩu BitLocker rồi ấn Unlock

3) Vào Control Panel > System and Security > BitLocker Drive Encryption > mở ra bảng chứa các ổ cứng và ổ USB trên máy > chọn ổ USB trước đó đã Unlock > Turn Off BitLocker

4) Hộp thoại hiện ra xác nhận có bỏ mã hóa không:

5) Quá trình bỏ mã hóa

6) Ấn Close sau khi hoàn thành.

Khóa và bảo vệ dữ liệu với Bitlocker của Windows 7

http://dantri.com.vn/suc-manh-so/khoa-va-bao-ve-du-lieu-voi-bitlocker-cua-windows-7-335024.htm
Thứ Bẩy, 04/07/2009 - 08:06      

Khóa và bảo vệ dữ liệu với Bitlocker của Windows 7

(Dân trí)-USB là thiết bị hữu ích để mang dữ liệu bên mình đi bất cứ đâu. Tuy nhiên nhược điểm của nó là khá nhỏ, dễ rơi hoặc đánh cắp. Khi đó, có thể dữ liệu sẽ bị truy cập trái phép. Mã hóa và bảo vệ dữ liệu trên USB là vấn đề đáng lưu tâm.

Dữ liệu riêng tư và quan trọng luôn được người dùng quan tâm và tìm cách che giấu hòng tránh những sự truy cập trái phép. Dân trí đã từng giới thiệu "5 tiện ích miễn phí bảo vệ dữ liệu trên máy tính". USB là thiết bị ngày càng thông dụng đối với mọi người, và lẽ dĩ nhiên, dữ liệu quan trọng trên đó cũng cần phải mã hóa để đảm bảo rằng không bị rơi vào tay người khác trong trường hợp nó bị đánh cắp hoặc thất lạc.

 

Windows 7, sản phẩm mới nhất của Microsoft mang đến cho người dùng chức năng Bitlocker, cho phép bạn mã hóa để bảo vệ giữ liệu trên USB (chỉ phiên bản Ultimate và Enterprise là có chức năng này). Nếu chưa cài đặt Windows 7, bạn có thể thực hiện các bước để "cài đặt Windows 7 song song với hệ điều hành sẵn có" hoặc "nâng cấp từ hệ điều hành trước đó" đã được Dân trí giới thiệu trước đây.

 

Sau đây là các bước thực hiện để mã hóa USB:
 
- Bước 1: Đầu tiên, cắm USB vào hệ thống. Tiếp theo, click Start, chọn Control Panel, chọn tiếp System and Security -> Bitlocker Drive Encryption. Click vào tùy chọn Turn On Bitlocker tại phân vùng ổ đĩa đại diện cho USB của bạn. (Cụ thể ở đây là ổ đĩa F)
 



 

- Bước 2: tiếp theo, bạn sẽ được hỏi cách thức bạn muốn để mở khóa ổ đĩa (sau khi đã mã hóa). Tại đây có 2 cách thức để lựa chọn: Sử dụng Password (mật khẩu) hoặc Smart Card. Mật khẩu là cách thức dễ dàng thực hiện hơn, nhưng lại không mạnh bừng sử dụng Smart Card. Trong ví dụ này, chúng ta lựa chọn cách sử dụng Password.
 



 

- Bước 3: Sau khi thiết lập mật khẩu, bạn sẽ được cung cấp một "khóa khôi phục" (Recovery key), giúp bạn khôi phục lại mật khẩu trong trường hợp quên mất mật khẩu để giải mã. Bạn có thể chọn Print the Recovery key để  in "khóa khôi phục" này hoặc chọn Save the Recovery key to a file để nó lưu vào đâu đó trên ổ cứng.
 


 

- Tiếp theo, bạn nhấn Next để bắt đầu quá trình mã hóa ổ đĩa USB. Quá trình sẽ mất một khoản thời gian, tùy thuộc vào dung lượng cũng như dữ liệu chứa trên USB.
 



 

- Sau khi quá trình mã hóa kết thúc, một hộp thoại sẽ xuất hiện như bên dưới để thông báo cho bạn biết.
 



 

Để kiểm tra xem ổ đĩa USB của bạn đã thực sự được mã hóa hay chưa, bạn tiến hành rút và cắm USB lại vào hệ thống. Nếu quá trình mã hóa thành công, khi truy cập vào USB, một hộp thoại sẽ xuất hiện yêu cầu bạn điền mật khẩu đã thiết lập từ trước.
 



 

Nhấn vào I forgot Password ở hộp thoại này và sử dụng "khóa khôi phục" ở trên để khôi phục lại mật khẩu trong trường hợp bạn quên mất mật khẩu đã thiết lập.

 

Để gỡ bỏ chức năng mã hóa Bitlocker, bạn thực hiện lại bước 1 ở trên, nhưng thay vào đó, chọn Turn Off Bitlocker ở trên ổ đĩa tương ứng.
 



 

Ngoài chức năng mã hóa để bảo vệ dữ liệu trên USB, bạn cũng có thể tiến hành mã hóa để bảo vệ dữ liệu trên các phân vùng của ổ cứng để đảm bảo rằng không ai có thể truy cập và cài đặt trái phép dữ liệu trên ổ cứng của bạn.

Protect Your Files in Windows 7 Using BitLocker To Go – Part 2

http://blog.pluralsight.com/windows-7-bitlocker-to-go
February 11, 2010  				

Protect Your Files in Windows 7 Using BitLocker To Go – Part 2

By

BitLocker To Go is the mobile version of BitLocker Drive Encryption that allows you to do essentially the same thing as BitLocker, but on mobile drives such as External Hard Drives, Flash Drives and Thumb Drives.

BitLocker To Go provides a powerful method of encrypting all of your mobile media and documents.

Using BitLocker To Go

Using BitLocker To Go is an extremely straightforward process, and provides powerful encryption in very little time. Just connect your mobile drive, type in your password, and enjoy.

Remember, while you must be on a premium version of Windows 7 (Ultimate of Enterprise) to encrypt BitLocker drives, you can use any version of Windows to unlock the drive, including older generations like Windows Vista and Windows XP.

When a mobile drive is encrypted with BitLocker To Go, it is accessible using a password chosen during setup. This works on all versions of Windows 7. On Windows Vista and XP, you can use the BitLocker To Go Viewer to unlock the drive and view files within.

 

Setting Up BitLocker To Go in Windows 7

Setting up BitLocker To Go is also a fairly simple process. Just connect your mobile drive, for example, a flash drive, right click, and choose Turn On BitLocker… — then follow the setup steps, choose your password, and encrypt the drive.

While encryption speed greatly depends on the speed of the drive, encryption should take about 30 seconds for a standard 2GB flash drive, depending on how much data is on the drive. You can also choose to automatically unlock the drive when logged into your Windows account.

An important step to remember when setting up your BitLocker To Go encryption is the Recovery Key. You will be prompted to save a recovery key on your hard drive. It is important not to forget this step.

If you ever forget your password, you can use this file to unlock your drive and gain access to your files again. You are offered the option of either saving this key, or printing it. I would recommend doing both just in case.

 

Configuring BitLocker To Go

While there isn't much in the front end in terms of configuring BitLocker To Go, there are some great functions when editing Local Group Policies that can help enterprise management and security. Here is an overview of the settings which you can configure from within the Local Group Policy Editor.

First, navigate to the following from within the Local Group Policy Editor:

Local Computer Policy -> Computer Configuration -> Administrative Templates -> Windows Components -> BitLocker Drive Encryption -> Removable Data Drives

  • Control use of BitLocker on removable drives — Choose to allow users the ability to apply or suspend protection on BitLocker drives.
  • Configure use of smart cards on removable data drives — Choose to make the use of smart cards a requirement.
  • Deny write access to removable drives not protected by BitLocker — This is a great security measure. For example, if someone tried to copy over contents to their own personal unencrypted drive.
  • Allow access to BitLocker-protected removable data drives from earlier versions of Windows.
  • Configure use of passwords for removable data drives — this configuration is also very useful. You can add an extra layer of security by configuring the complexity and minimum password length for BitLocker To Go drives being set up.
  • Choose how BitLocker-protected removable drives can be protected — This allows you to choose how a user will be allowed to recover locked drives if they forget their passwords. Disabling these may lock users out of their drives, but adds a powerful layer of security.

 

Turning Off BitLocker To Go

You can turn off or temporarily suspend BitLocker To Go as quickly as setting it up.

To temporarily suspend BitLocker To Go, visit your Control Panel, search for and go to the BitLocker Drive Encryption page and click Suspend protection and then choose Yes. Your drive will be temporarily open for all usage, unprotected until you follow the same steps to unsuspend it.

To turn off BitLocker To Go completely, visit the BitLocker Drive Encryption page in your Control Panel and choose Turn Off Bitlocker. You will be prompted to decrypt your drive, continue and your drive will be completely unencrypted and open. To secure your drive again, just track back and follow the steps outlined above.

 

The Downside of BitLocker To Go

The main problem with BitLocker To Go, is while it is a great encryption solution for Windows 7, older generations of Windows like Vista and XP can only view files using the BitLocker To Go Viewer, and cannot add or edit files on the encrypted drive. You must use the BitLocker To Go Viewer to copy files to your desktop before being allowed to edit them.

I don't completely understand why BitLocker To Go, a native Microsoft program, does not work with older generations of Windows. Other solutions such as the encryption applications that come with some thumb drives work across all versions of Windows. I can only hope that in the future, Microsoft provides more support for older versions of Windows, especially in BitLocker To Go, considering thumb drives are made to be moved between many different computer systems.

I feel that this feature should have come standard with BitLocker To Go. While this is definitely a downside for standard use across multiple systems that include older generations of Windows, those who are using Windows 7 exclusively will find BitLocker To Go a valuable asset to their system and drives data security.

 

Is BitLocker To Go Right For You?

BitLocker To Go is an awesome choice for encrypting your mobile drives, but not in all circumstances. Its ease of use and powerful protection makes this a great choice for enterprise users running the Windows 7 operating system on all drives they plan to use the drive on.

However, for those who are looking to use their drive on computers with varying operating systems including older generations of Windows, BitLocker To Go may not be right for you.

About the Author

is a computer technician with over 8 years of experience in the IT field. He has completed training in CompTIA A+, Network+, Computer Business Applications (Microsoft Specialist), Web Page Design and Graphic Design, and is working on completing his CompTIA A+ and CCNA certifications. Mike has experience working as a computer technician for two local school districts, as well as freelance computer repair work with AlisalTech.com, which Mike owns. Music is another one of Mike's callings. Using his technical experience, Mike promotes local musicians in Salinas California through his website SalinasRadio.com where local musicians and businesses can gain promotion to a worldwide audience.

Author's Website: http://alisaltech.com

Is it time to setup my own personal cloud instead of using Dropbox?

http://www.bit.com.au/Guide/365066,is-it-time-to-setup-my-own-personal-cloud-instead-of-using-dropbox.aspx

Is it time to setup my own personal cloud instead of using Dropbox?

With all the security concerns about the cloud and Dropbox, is it worth ditching Dropbox and setting up your own personal cloud?

Millions of people are putting their files into cloud storage so they can access them wherever they go, or as a backup. But at the same time, security concerns about cloud services like Dropbox continue, whether they be government spying, hackers, or weaknesses in security.

So it's interesting to see that many major brands of Network Attached Storage (NAS) boxes let you create your own "personal cloud" or "private cloud". In particular, Western Digital launched its My Cloud personal storage by asking the question "Who wants to keep their precious content in some mysterious location?"

Similarly, Seagate has teamed with Tappit to offer a similar service with some of their NAS units and DLink has the mydlink portal for remotely accessing documents stored on NAS devices.

While many of these services are pitched at home use, the advertising sometimes shows them being used for business - for example, opening a presentation when you're out of the office

Seagate says that the Seagate Business Storage NAS lets you create a "private cloud", with an "easy ten minute setup". According to the web site, "It helps protect your business-critical data and centralizes your files in a single location you can access from anywhere."

Cloud storage is really pooled storage in a central location that can be accessed across the Internet from almost any device. In theory, it's not really all that difficult from a technical point of view.

So are these private/personal clouds all they're cracked up to be, and is it worth setting one up for your files?

We decided to put one of the market leaders in storage to the test. We set up a Seagate Business Storage 4-bay NAS equipped with four 4TB drives configured in a RAID5 configuration. This gave us about 12TB of usable space with redundancy in case a drive fails. It took us about an hour to get everything up and running with a laptop, smartphone and tablet all accessing the device with different user accounts.

Each separate user we created had access to a private folder and a shared folder that everyone could access. This gave us a similar set up to many small businesses.

What can my private cloud do?

The best way to consider what a private cloud solution can achieve is to compare it with some of the more popular services that are already out there such as Dropbox, Google Drive and Microsoft SkyDrive. These three services allow you, while you are working on your computer, to store files in a specific location. When you switch to another computer, smartphone or tablet you can access the same files with all the changes automatically synchronised.

What about a private cloud? With Seagate's Global Access feature you can save files to a shared folder on the NAS. You can access those files over the Internet wherever you go, just like Dropbox, but unlike Dropbox, this system won't automatically keep up-to-date copies of those files on your computers as it doesn't do file syncing. It's like a file server - unless you're connected to it, you can't access the files. If you sit down at your laptop to do some work in a hotel room and you aren't online, you won't have access to the files. With Dropbox, often you will already have a copy of the file on your laptop (although on a phone, Dropbox only downloads a file when you want to view that file).

There is something to be aware of. To use this personal cloud feature to access your files remotely, you'll most likely need to do some more complex configuration on your network router. For example, you'll need to change router settings to allow remote access to the shared folder. This might mean editing firewall rules, routing rules for incoming connections or putting the NAS in a demilitarised zone – a part of your network that sits outside the secure "inner sanctum" that's protected by your router's firewall. In that regard, the established public cloud services like Dropbox are far easier to use.

There is also an app so you can access the files in your private cloud using your phone or tablet.  We found this was very easy. We did this using an iPhone and an iPad and there is also an app for Android phones. Keep in mind it's not easy to edit any files on a phone or tablet this way - whether you are using Dropbox or Seagate's app. That's because the iPhone and iPad don't make it easy to open files stored remotely in locally installed apps.

If you need to upload files to your private cloud, you can do this using a web browser on your laptop, or the phone app. All we needed to do was go to https://seagate.tappin.com/ and enter the email address and password used to create our Global Access account. We could then upload files to our personal or shared folders.

So does your own private cloud have the same remote access capabilities as the likes of Microsoft SkyDrive, Dropbox and Google Drive? In our view it gets close, but lacks some of the polish. If Seagate included a utility that allowed us to sync a local folder on our laptop to the NAS automatically, then it would be a much closer match to the leading cloud storage services.

How much does this cost?

A NAS device can cost you hundreds of dollars, but the big advantage is that you can have a lot of storage this way.

For example, the Seagate Business Storage 4-Bay 16TB NAS we tested has a street price of around $1,700 (the recommended retail price is closer to $2,250). You don't have to spend this much - you could spend around $700 on a 4TB unit. Other NAS devices start at just a couple of hundred dollars but you then need to add hard drives to that cost (some NAS boxes don't come with the drives included).

Adding storage to a NAS is relatively easy and, in most cases, can be done without even turning the NAS off. For example, if you start with a four 1TB drives you can remove one of the drives and replace it with a 2TB drive. Once the RAID updates itself with the new drive  (this is an automatic process) you can then remove another 1TB and replace it with a 2TB drive. You repeat this until all of the disks are replaced. You need to do this one drive at a time so that all your data is safely updated to the new drives.

If your business is growing and you're likely to have more than a couple of users, then a NAS starts to get more attractive because you can add lots more storage (as long as you have enough drive bays).

In contrast, the likes of Dropbox and others give you between 2GB and 15GB of storage at no charge. In the case of Dropbox, you can increase this substantially by referring friends to the service.

The NAS sounds expensive by comparison, but the costs can add up quickly with cloud-based services like Dropbox once you need more data storage. For example, Dropbox charges businesses $795 per year for 5 users and $125 for each additional user per year. This gives unlimited storage capacity.

Although that may sound attractive, it's worth considering how you might move large volumes of data to that online facility. If you want to store large files that are many hundreds of megabytes in size, such as video or images, then your Internet connection's upload capacity might be a problem. When it comes to storing your files on a NAS that sits in your building, you're only limited by the speed of your internal network, not your Internet connection.

What about accessing the files? If you're in the same building, you don't have to be connected to the Internet to access your files - the box is in your building. That means you avoid the risk of your cloud provider going offline for some reason. Mind you, if you're accessing your files remotely, you won't be able to if your Internet connection connecting the NAS box to the outside world goes down.

Is this easy or hard to do?

How tricky is it to make this sort of system work? The good news is that NAS manufacturers have, over the years, made huge leaps forward when it comes to making it easier to set up their devices and access advanced features. But it does require some background knowledge and understanding of the terminology they use.

The key terms you need to get your head around are

Volume: a storage area on the NAS. In our case, the Seagate Business Storage NAS we used had four hard drives installed. These were set up to look like one large drive or volume.

Share: A folder created on the volume that we would assign specific access to. In our system, we had a public share that anyone on our network could access and private shares that could only be accessed by specific users.

User: This is a really an account (a combination of a username and password) that could access a share. You can also create groups that are collections of users. This makes it easy to assign access to a share as you can assign a group permission to access a share without having to enter lots of users.

When you set up a NAS, you create the volume first, the shares next and then the users. You then assign users their access to the shares.

Once you get your head around this, the actual set up process is reasonably easy.

Configuring the private cloud access will depend on the NAS you've chosen. With the Seagate unit I used, I needed to enable the Global Access option and then decide which users would be allowed to use the service.

This was easy – far easier than other NAS systems I've used in the past where none of this process was automated.

In my view, you will need to set some time aside and plan what you're going to do. But you don't need to be a network engineer or technical guru to make this work.

How secure is this?

When you're considering whether or not to make your data accessible when you're out of the office, the first thing we think you need to consider is the risk and reward. Whenever you make data accessible outside your network you open up a potential risk - whether it's via your own personal cloud, or a public cloud service. Even large service providers like Amazon, Dropbox and Sony have seen data that they thought was secured, accessed by unauthorised parties.

We want to make this very clear - there are security risks to your data with both approaches. Weigh up this risk against the benefits of making your data accessible (assuming you take all possible security precautions). For example, if you travel, then being able to easily access your documents from a tablet or smartphone could be useful.

With Seagate's private cloud there are two ways your data is protected:

  • The drive is encrypted, so if someone steals drive they can't read the data.
  • An SSL certificate is used to encrypt the data when you're accessing it remotely.

We found that by default, the data stored in a share on the Seagate NAS we used was not encrypted but it could be by ticking a checkbox in the configuration screen. If you're going to share or access data online we'd strongly recommend turning encryption on.

Also note that we'd recommend against using public hotspots for accessing critical, private data. Most public hotspots offer no security - all of the data sent and received over the public hotspot is in the clear and can be easily intercepted.

Also remember, like any online service, your security is only as strong as your weakest password. Make sure that every user's password is strong. Some good rules of thumb for creating a strong password are:

            •           use a combination of uppercase and lower case letters

            •           include some numbers

            •           include symbols such as punctuation

            •           don't use a word from the dictionary as the basis of your password

Dropbox, on the other hand, offers 256-bit AES encryption to store your data. SSL is used to create a secure tunnel for data transfers. In that sense, it offer similar security to the Seagate NAS we tested.

Also remember there are several dimensions to consider when thinking about security. The most obvious is whether an unwanted party can access your data remotely without you knowing. But there's also the risk of not being able to access your data when you most need it.

Almost every major cloud storage provider has suffered an unscheduled outage or technical fault that has resulted in either a potential security breach or a loss of access to data for customers. Just because some of these businesses are large and well resource it doesn't mean they are immune from outages and human error.

Also keep in mind the security implications of sharing sensitive data online. This introduces all sorts of risks, whether it's people sharing files with people they shouldn't, or accidentally sharing a file without realising it contains sensitive information. Read this article for more on this.

Is this personal cloud giving me offsite backup, or not?

A good backup strategy has at least one copy of your important data stored offsite – away from your main workplace. So, does creating your own cloud give you this?

In a word – no.

Creating a private cloud solution using your NAS offers the ability to remotely access your files wherever you are. But it doesn't reduce the risk of a disaster that might happen in the building where the NAS is kept. If you're looking at using a NAS as part of your back up arrangement, I'd suggest making an agreement with a friend to house an offsite backup for each other.

It could work like this. You both purchase NAS units and agree to host them for each other. That way, you both get the benefit of offsite backup and remote file access.

This is also where the established cloud-based storage services can still be useful.

Dropbox, for example, lets you easily retrieve past versions of your files. If you accidentally delete or overwrite a file, you can restore a previous version of the file. If you use the free version of Dropbox, you can retrieve up to 30 days of file history and there is no limit on what can be retrieved if you have a paid Dropbox account.

One of the benefits that a public cloud service like Dropbox offers is that your files are saved offsite. Although there are some risks and considerations that you need to consider when your data is held offshore, it's something to keep in mind.

Is this actually worth doing?

Given the effort required, the need for some technical know-how and how easy it is to use services like Dropbox, it's not easy to justify setting up your own private cloud solution.

Services like Dropbox, Google Drive and Microsoft SkyDrive are built upon millions of dollars of infrastructure by experts in storage, networking and security. Very few businesses are able to put those sorts of resources together to create that sort of service.

Let's look at a few of the key functions I'd expect from a cloud storage solution and see if a personal cloud using a NAS stacks up.

File Syncing

Being able to shift from a laptop to a desktop to a tablet and see a consistent view that's up to date of all my files is critical. The big, public cloud storage solutions all do this. Working with a NAS requires that I install another tool that synchronises my files from a folder on my computer to the NAS (Is this some capability/way of doing it you haven't mentioned earlier? Up till now I've been reading this as "syncing not possible"). It's not impossible but it means more fiddling.

Offsite Backups

Unless I keep my NAS at a friend or colleague's place, creating a private storage cloud doesn't satisfy my business need to keep critical data offsite.

Security

This is a hard question to answer. On one hand, there's a big psychological factor that comes from being able to see where my data is stored. Having my data close by also means I don't have to worry about the implications of data privacy laws about storing data overseas and whether an overseas authority can access my data (the PATRIOT Act gives some very wide-reaching powers to authorities in the United States for example).

However, data that is remotely accessed ought to be encrypted when stored and accessed. The Seagate Business Storage NAS we tested allowed us to encrypt both the contents of the device's hard drives and the data communications. While this was not hard to do, it was another set of steps.

Turning on encryption for the storage was simply a matter of ticking a checkbox but encrypting communications required the creation of an encryption key. It wasn't difficult but it was yet another thing we needed to do, and would ultimately need to maintain.

Cost

Cloud storage is very cheap. We can now access enough capacity to store thousands of documents or images. Even though the free version of Dropbox delivers just 2GB that's enough for thousands of files. For example, I work for several clients where I provide documentation and images. I can hold more than a year's data in the free storage. If I need more, I can pay for more capacity as I need it without the need to spend hundreds of dollars in equipment.  In other words, there's no need to engage in a round of significant capital investment.

On the other hand, a decent NAS with capacity for four drives, so that you can configure it with some hardware redundancy, will cost several hundreds of dollars just to get started. And then you have to factor in the time it takes to set it up, maintain it and operate it.

When I weigh up those factors, it's hard to justify the cost of a NAS if I'm looking to it as an alternative to cloud-based storage. 

Conclusion

We started this article by assuming that you have weighed up factors like security and you have decided you do want remote access to your files. So, if that's the case, is it worth setting up a personal cloud?

Personally, I can't see why I would use a NAS as an alternative to public cloud-based storage for my business. Dropbox, Google Drive and Microsoft SkyDrive make it very easy and their costs are very manageable.

As we said, there are risks with public cloud solutions, and there are also risks doing it yourself with a NAS like the Seagate Business Storage. With Dropbox, experts in storage security handle all of the security settings automatically. With the NAS, you need to configure and maintain the security yourself. Cloud services keep a copy of your data offsite, whereas with a NAS your data is stored in your building which could be a less physically secure environment (unless you organise to keep another copy offsite).

Where a NAS such as Seagate's Business Storage excels is in giving you lots of local storage capacity that can be locally accessed and, assuming you've enabled at the security settings correctly, the ability to remotely access your files from a wide variety of devices. If you need lots of local storage, then this could be the way to go. But if all you want is remote data access, we'd suggest that public cloud services make file syncing to multiple devices easier than with a NAS.

As we've already flagged this is a big topic, so we'll have more coverage on this. If you have questions or comments they're more than welcome - let us know what followup articles you wat us to do by adding your comments below.

Thủy thủ chiến hạm Mỹ ở Biển Đen “sợ hãi” Su-24 Nga

http://kienthuc.net.vn/the-gioi/thuy-thu-chien-ham-my-o-bien-den-so-hai-su24-nga-331738.html

Thủy thủ chiến hạm Mỹ ở Biển Đen "sợ hãi" Su-24 Nga

(Kienthuc.net.vn) - 27 thủy thủ tàu khu trục USS Donald Cook đang triển khai ở Biển Đen đã xin thôi việc vì lo sợ máy bay chiến đấu Nga.
Báo Độc Lập dẫn nguồn tin Reuters cho biết, việc máy bay ném bom không quân Nga nhiều lần tiếp cận tàu khu trục USS Donald Cook trong khu vực Biển Đen khiến thủy thủ Mỹ lo ngại và buộc họ phải viết báo cáo xin thôi việc.
Theo phát ngôn viên của Lầu Năm Góc Stephen Warren, hôm thứ 7 (12/4), máy bay ném bom Su-24 của Nga đã nhiều lần bay gần tàu khu trục của Hải quân Mỹ USS Donald Cook ở Biển Đen, mô phỏng cuộc tấn công chiến đấu.
 Tàu khu trục USS Donald Cook (DDG 75) trang bị hệ thống Aegis và kho vũ khí cực mạnh gồm tên lửa Tomahawk.
"Các thành viên thủy thủ đoàn đã phải gặp nhà tâm lý học sau khi bị căng thẳng, và đã có 27 thuyền viên của tàu khu trục nộp đơn từ chức. Bình luận về hành động này, họ nói rằng không có ý định mạo hiểm với tính mạng của mình", người phát ngôn cho biết.
Tàu khu trục USS Donald Cook vào Biển Đen ngày 10/4, theo công ước hàng hải quốc tế tàu Mỹ không thể ở Biển Đen quá 14 ngày. Nếu quá thời gian này cho phép, Nga có quyền hợp pháp để thực hiện cuộc tấn công tên lửa và phá hủy dữ liệu của tàu mà không tuyên chiến với Mỹ.
Sukhoi Su-24 là máy bay cường kích cánh cụp cánh xòe được thiết kế chế tạo và đưa vào phục vụ từ những năm 1970. Trên chiếc máy bay này được trang bị kho vũ khí đủ sức vô hiệu hóa tàu chiến Mỹ bằng tên lửa chống tàu siêu thanh, bom có điều khiển.

(Chơi cho vui) AIRDROP CHAINGE FINANCE - dự án xây dựng ứng dụng ngân hàng số cho mọi người

 Không hiểu lắm về cái này, tuy nhiên thấy quảng cáo khá nhiều, lại chỉ cung cấp vài thông tin cá nhân (mà mấy ông lớn như facebook với goog...