Server administrators, web-application programmers, web site designers, help desk support, software companies, technology providers, government officials, and yes, even end-users — we are all responsible for information security on the internet. We need to not fall for knee-jerk, and ineffective solutions — i.e. strong passwords — or assume that certain technologies will keep us safe — i.e. “I use a mac and they don’t get viruses”. What can we do? I am not a security expert with specific prescriptions to give — but remember, easy prescriptions don’t exist. What is needed is an ongoing conversation — at my workplace the CIO recently held the first of a series of campus-wide forums to provide technology staff with information, and to gather ideas from all of us. This is a good first step. Here are a couple of other ideas: Read the rest of this entry »