Tuesday, November 10, 2020

Georgia Public Library Service Tech Boot Camp 2020

 Georgia Public Library Service Tech Boot Camp 2020: The Cyber Edition

GPLS's Tech Boot Camp was held from 10/27 to 10/30 this year. This year's conference was conducted virtually using the Whova platform and everything went fairly smoothly, especially considering the COVID situation and the Hurricane Zeta-induced power outages. The conference featured speakers from the FBI, USG, GPLS, and a number of Georgia libraries.

 

I focused on attending the cybersecurity events and the events covering G Suite/Google Workspace and Chrome OS Administration. Judging by what I saw at Boot Camp, I think that the administration options for Chromebooks are simple, straightforward, and powerful. I did not realize that you can remotely lock down Chromebooks that you administer and display a custom message, even when these devices are outside of your network. Several library systems are using this feature to force patrons to bring back Chromebooks if they keep these devices past the allowed lending period.

 

The first cybersecurity event was a talk from Dr. Todd Watson, the Information Security Officer for the Board of Regents. As with most security presentations, there were several alarming statistics about all kinds of security risks and compromises. Ransomware was a hot topic, as it continues to be a very common form of attack and remains popular among criminals due to the potential for money making. Ransomware continues to be a scourge for public sector entities like local governments and public universities and will likely continue to keep your humble network administrator up late at night. The most common Ransomware infection vector is a malicious email message or attachment, so please be careful when clicking on things in your email and do not be afraid to contact IT with any questions regarding suspicious email messages.

 

The next cybersecurity event featured two special agents from the FBI’s Atlanta field office. Their presentation focused on how the FBI partners with public and private sector organizations to help combat cybercrime and mitigate the impact of crippling events like Ransomware. Regarding Ransomware, the FBI’s official advice is still not to pay the ransom. Parts of the U.S. Treasury department also recently came out to advise against paying Ransomware ransoms, more details for those interested here: https://www.natlawreview.com/article/ransomware-payments-can-lead-to-sanctions-and-reporting-obligations-financial

However, Dr. Watson’s presentation indicated that for many companies it is often cheaper and faster to just pay, and many companies and public sector entities do pay. So Ransomware is not going anywhere soon.

 

The other two cybersecurity events I attended were hosted by David Teston from GPLS. One focused on general cybersecurity tips and tricks. I did learn that GPLS is hoping to provide general cybersecurity training courses for end users (in other words, non-IT people) through Niche Academy. They also have a special cybersecurity resource page dedicated to COVID-19: https://galibtech.georgialibraries.org/cybersecurity/security-measures-during-covid-19

 

The second event was more technical and focused on firewall strategies and in particular deploying and managing your own pfSense firewall. pfSense is a popular FOSS (that stands for Free and Open Source Software) firewall solution, and while there is a bit of a learning curve, it is quite powerful, especially considering the price (free, you just have to supply the hardware to run it). It could be useful to us for future projects that involve expanding our network.

 

There was also an update from Galileo on their Open Athens project. This project is a mammoth effort to completely redo the way Galileo authentication is managed, with the goal of getting rid of the passwords and instead using an SSO (Single Sign-On) process where users will authenticate with their library card and PIN for access to all Galileo resources. The primary focus so far has been on universities and public schools, but attention is increasingly turning to public library systems now that many of the schools have already been converted to the new sign-on method. A few non-PINES libraries are already working with Galileo on this project, and we have submitted some preliminary information to Galileo, so stay tuned.

  

And that’s all for Tech Boot Camp 2020. I always appreciate the chance to hear from GPLS, Galileo, and IT staff from other Georgia Library Systems.

-Nicholas

No comments:

Post a Comment