Georgia Public Library Service Tech Boot Camp 2020: The Cyber Edition
GPLS's Tech Boot Camp was held from 10/27 to
10/30 this year. This year's conference was conducted virtually using the Whova
platform and everything went fairly smoothly, especially considering the COVID
situation and the Hurricane Zeta-induced power outages. The conference featured
speakers from the FBI, USG, GPLS, and a number of Georgia libraries.
I focused on attending the cybersecurity events
and the events covering G Suite/Google Workspace and Chrome OS Administration.
Judging by what I saw at Boot Camp, I think that the administration options for
Chromebooks are simple, straightforward, and powerful. I did not realize that
you can remotely lock down Chromebooks that you administer and display a custom
message, even when these devices are outside of your network. Several library systems are using this feature to force patrons to
bring back Chromebooks if they keep these devices past the allowed lending
period.
The first cybersecurity event was a talk from Dr.
Todd Watson, the Information Security Officer for the Board of Regents. As with
most security presentations, there were several alarming statistics about all
kinds of security risks and compromises. Ransomware was a hot topic, as it
continues to be a very common form of attack and remains popular among criminals due to the
potential for money making. Ransomware continues to be a scourge for
public sector entities like local governments and public universities and will
likely continue to keep your humble network administrator up late at night. The
most common Ransomware infection vector is a malicious email message or
attachment, so please be careful when clicking on things in your email and do not be afraid to contact IT with any
questions regarding suspicious email messages.
The next cybersecurity event featured two special
agents from the FBI’s Atlanta field office. Their presentation focused on how
the FBI partners with public and private sector organizations to help combat
cybercrime and mitigate the impact of crippling events like Ransomware.
Regarding Ransomware, the FBI’s official advice is still not to pay the ransom.
Parts of the U.S. Treasury department also recently came out to advise against
paying Ransomware ransoms, more details for those interested here: https://www.natlawreview.com/article/ransomware-payments-can-lead-to-sanctions-and-reporting-obligations-financial
However, Dr. Watson’s presentation indicated that
for many companies it is often cheaper and faster to just pay, and many
companies and public sector entities do pay. So Ransomware is not going
anywhere soon.
The other two cybersecurity events I attended
were hosted by David Teston from GPLS. One focused on general cybersecurity
tips and tricks. I did learn that GPLS is hoping to provide general
cybersecurity training courses for end users (in other words, non-IT people)
through Niche Academy. They also have a special cybersecurity resource page dedicated to
COVID-19: https://galibtech.georgialibraries.org/cybersecurity/security-measures-during-covid-19
The second event was more technical and focused
on firewall strategies and in particular deploying and managing your own
pfSense firewall. pfSense is a popular FOSS (that stands for Free and Open
Source Software) firewall solution, and while there is a bit of a learning
curve, it is quite powerful, especially considering the price (free, you just have to supply the hardware to run it). It could be
useful to us for future projects that involve expanding our network.
There was also an update from Galileo on their Open Athens project. This project is a mammoth effort to completely redo the way Galileo authentication is managed, with the goal of getting rid of the passwords and instead using an SSO (Single Sign-On) process where users will authenticate with their library card and PIN for access to all Galileo resources. The primary focus so far has been on universities and public schools, but attention is increasingly turning to public library systems now that many of the schools have already been converted to the new sign-on method. A few non-PINES libraries are already working with Galileo on this project, and we have submitted some preliminary information to Galileo, so stay tuned.
And that’s all for Tech Boot Camp 2020. I always
appreciate the chance to hear from GPLS, Galileo, and IT staff from other
Georgia Library Systems.
-Nicholas

No comments:
Post a Comment