QuickBooks Desktop Enterprise 2024 Security Improvements: Now with 256-bit encryption

Intuit’s release of QuickBooks Enterprise and other desktop editions for 2024 have a variety of new features, and among them is an improved level of security for your business data. Upgrading from 128-bit encryption, QuickBooks Desktop 2024 now has AES 256-bit encryption.

256-bit encryption is the strongest and most robust encryption standard commercially available. It’s widely used because it’s virtually impenetrable to brute-force attacks. 256-bit encryption is an encryption technique that uses a 256-bit key to encrypt and decrypt data. Plain text is converted to a cipher, and the encryption key is required to decrypt the data and return it to readable plain text.

256-bit encryption is used in most modern encryption algorithms, protocols, and technologies, including AES in wireless security, processor security, file encryption, and SSL/TLS.

According to Intuit, “You can be confident your data is protected with our enhanced security using industry-leading AES 256-bit encryption. QuickBooks safeguards your reputation by protecting critical customer and vendor data, such as business financials, banking information, and credit card details.

This means we translate your information into a code that only we can read to make sure only you and Intuit have access to your information. The type of encryption we use is called AES-256 (Advanced Encryption Standard with 256-bit keys) and it ensures the highest level of cryptographic security.”

With a series of robust security steps and a complex 256-bit decryption key, AES 256-bit standard is nearly impossible to break using brute-force methods and has been approved for the handling of confidential data by the U.S. Government.

A brute force attack is when a hacker tries different combinations until they arrive at the correct combination – the key. The larger the key size, the more difficult it becomes to break the encryption. We’re talking about 256-bit keys. There are 984,665,640,564,039,457,584,007,913,129,639,936 (that’s 78 digits) possible combinations. Even if you use Tianhe-2 (MilkyWay-2), which was the 4th fastest supercomputer in the world in 2022, it will take millions of years to crack 256-bit AES encryption.

In case you’re interested: The fastest supercomputer in the world, ranked in June 2023, is Frontier, an HPE Cray EX system run by the US Department of Energy, Frontier incorporates 3rd Gen AMD EPYC™ CPUs representing 8,730,112 cores that have been optimized for high-performance computing (HPC) and AI with AMD Instinct™ 250X accelerators and Slingshot-11 interconnects. Its HPL benchmark was 1.194EFLOPS (EXA – 1 quintillion – floating point operations per second). (via networkworld.com). Frontier is faster than Tianhe-2, so breaking the key could take a little less time.

Breaking encryption with no known flaws is kind of like guessing a password. If you make enough guesses, you might eventually get the password right. With strong encryption, this can take a long time. AES-256 is the most secure version of AES and is virtually unbreakable by brute force based on current computing power. It’s also considered quantum-resistant, which means that quantum computers aren’t expected to crack the cipher.

How long would it take to crack 128-bit encryption using a brute force attack? Most security professionals would answer “1 billion years”, but that’s just an estimate. A machine that can crack a DES key in a second would take about 149 trillion years to crack a 128-bit AES key. According to researchers, with the right quantum computer, AES-128 would take about 2.6110^12 years to crack, while AES-256 would take 2.2910^32 years. For reference, the universe is currently about 1.38×10^10 years old, so cracking even an AES-128 encryption with a quantum computer could take hundreds of times longer than the universe is believed to have existed.

While Intuit is improving the security of the information it stores and transmits between its systems, your company should be equally concerned with the security and protection of all your business applications and data. Using strong password policies, multi-factor authentication, and SSL for secure web app access, Noobeh’s QBonAzure services provide layers of protection on top of the $20Bn in security investments made by Microsoft.

We take data security seriously, providing solutions to address access, security, privacy and protection for business applications and data. When your QuickBooks Enterprise deployment needs a solid foundation that offers agility and performance as well as strong platform security, we have that.

Visit MendelsonConsulting.com/cloud to learn more.

jm bunny feetMake Sense?

J

The Question You Never Want to Have to Ask

Why MFA Shouldn’t Be Optional

“Do you offer any help for decrypting files due to ransomware?”

This is a question we are asked with more frequency than ever before. And, sadly, it is often followed up with the information that their files were on “an internal server that was missed in the backup protocol by IT”.

Email phishing and brute force attacks are the most common methods cyber criminals use to get into your business network where they can set up to initiate ransomware attacks. The ransomware (malware) encrypts your data, which becomes unrecoverable without the decryption key. Usually, the only way to recover from a malware/ransomware attack is to rebuild systems and restore data from backups. If you have backups.

A “brute force” attack is typically used to get personal information such as passwords or passphrases, usernames, and Personal Identification Numbers (PINS). Scripts or specialized apps are used to carry out a string of continuous attempts to get the information desired. Cybersecurity researchers at Coveware analyzed ransomware attacks during the second quarter of 2021 and found that phishing and brute force attacks on unsecured desktops (remote and local) are among the most popular entry points for starting ransomware attacks. This is at least partly because it is relatively cheap and can be highly effective.

Phishing attacks are when cyber criminals send emails containing a malicious file attachment or hyperlink directing to a compromised website that delivers ransomware. Attacks against desktop logins include methods where cyber criminals use brute force to leverage weak or default usernames and passwords – or even get access because they got legitimate login credentials via a phishing email.

Software vulnerabilities and web-based application services are also among the popular vectors for delivering ransomware or exposing corporate networks to cyber criminals. While this type of attack is somewhat less frequent than the others, they are often leveraged by some of the most sophisticated and disruptive ransomware groups and nation/state bad actors.

  • Sodinokibi – also known as REvil – is responsible for some of the most high-profile ransomware attacks this year, including the massive ransomware attack on customers of Kaseya.
  • Contij – one of the most high-profile attacks by the group was the attack against the Irish healthcare system. Healthcare services across Ireland remained disrupted for months.
  • Avaddon – ransomware distributed via phishing emails.
  • Mespinoza and Hello Kitty are new forms of ransomware recently identified.

All of these have a common purpose in that they take advantage of weaknesses in security and exploit phishing tactics to lay the foundation for an attack on your network and possibly others.

Keeping systems updated, applying security patches and application software updates is an important aspect to keeping things secure. Known vulnerabilities can be exploited to gain access to the network, so keeping up with updates as the vendor supplies them has become more important than ever.

To help protect networks from being compromised, businesses should also apply multi-factor authentication (MFA) to desktop and applications.

MFA is an important tool to help stop intruders from breaching accounts and gaining access to the corporate network, and it can be the difference between keeping your data safe and working or discovering your files are digitally encrypted and completely unusable. Data encryption changes the data into code, and only the decryption key can read the code and return the data to a useable form. If you don’t have the key, the data typically cannot be decrypted.

Cyberattacks continue to evolve in their sophistication and frequency, and consequences of such attacks are growing. Private companies and public agencies alike must adapt their security techniques and embrace new security technologies while providing more end-user education and training.

Mendelson Consulting and NOOBEH Cloud Services take security very seriously and we have the experience and expertise to assist businesses with transforming their operations to be more efficient and effective. Our cloud team works exclusively with private tenant accounts on Microsoft Azure, and offers MFA security and other solutions to protect local and remote resources, helping keep your valuable information safe and available when you need it.

“How can we get started?” is the question you should be asking.

jm bunny feetMake Sense?
J

Windows Server 2012/R2 Not Aging Well, Loses Support for Microsoft 365 Apps

Lots of people loved (and continue to love and use) Windows Server 2012/R2. This Windows Server release introduced several new and improved features that made it a cornerstone of business and service provider networks worldwide. Notable improvements in virtualization with Hyper-V, along with improvements in storage, networking, remote access and server administration features, made 2012/R2 a necessary upgrade from the 2003 and 2008 versions still present in many networks.

Sadly, even though Release 2 (R2) for Server 2012 was largely a new OS due to its features and capabilities, it did not receive a new lifecycle end date and instead inherited the end dates for 2012 version. And an extended lifecycle end-date doesn’t guarantee extended usefulness or compatibility.

Windows Server 2012 began with mainstream support on October 30, 2012 and that mainstream support ended in January 2018, including for R2. Extended support for 2012/R2 goes through January 2023, but that is only if you are paying for Software Assurance for your licenses.

During this period where extended support may still be available for the OS, there is no guarantee that it will remain as a supported platform for your application software. An example of this is the Microsoft Office 365 Apps suite formerly known as ProPlus. The Office 365 apps, which include Outlook, Word, Excel, Powerpoint and more, are staples of business users worldwide. These applications are no longer supported on Windows Server 2012/R2.

Microsoft 365 Apps ended support on Windows Server 2012/R2 on January 14, 2020.

Innovative features and functionality continues to be released for the Microsoft 365 Apps and Microsoft needs to know that the platforms running the applications will work properly with those innovations. As the software is improved and new capabilities introduced, stability and performance issues can plague the install when it is running on older or unsupported operating systems.

Microsoft has pointed out that any Microsoft 365 Apps updated to version 2005 or later will result with functionality and stability problems because there are changes that are specifically not compatible with Windows 8 and Windows Server 2012.

The pace of change is increasing no matter what industry you are in. With technology adoption rates rising faster than ever in all sectors, business owners cannot rely upon outdated systems if their operations are to remain competitive. Application software as well as the operating system platforms it runs on must be regularly updated in order to provide the reliable performance and useful functionality demanded by today’s business users.

jmbunnyfeetMake Sense?

J

Are You Prepared for SQL Server 2008 End of Support?

 

Everything gets old eventually, and now it is official for SQL Server 2008.

03-2012sean-phone-328-e1377042261105On July 9, 2019, support for SQL Server 2008 and 2008 R2 will end. That means the end of regular security updates and general support for the product. Are you ready?

It took more than 10 years for Microsoft to end support for our beloved SQL 2005 and version 2008 has enjoyed a similarly long reign. But it’s over and you need to get used to the idea. Even more, you need to get upgraded to a new version of SQL so your systems can still be patched, updated and supported. With all the nasty exploits out there, letting your software get out of date is more of a business risk than ever.

With cyberattacks becoming more sophisticated and frequent, running apps and data on unsupported versions can create significant security and compliance risks. The 2008 family of products was great for its time, but we highly recommend upgrading to the most current versions for better performance, efficiency, and regular security updates.

Now is a Good Time to Consider Azure

Microsoft is giving a present to businesses that want to migrate their workloads to Azure. For those customers that elect to take this as an opportunity to move to the Azure cloud, extended security updates will be available for free in Azure for 2008 and 2008 R2 versions of SQL Server and Windows Server to help secure workloads for three more years after the end of support deadline. Moving existing systems to the Azure cloud is a natural step in modernizing the business infrastructure and makes the next step of upgrading to managed database services and/or migrating to new Azure servers a lot easier.

Upgrading isn’t simply a matter of maintaining status quo, either.

Moving to new versions can be a foundation for new strategic capability and increasing overall business potential, powering new decision-making processes fueled by analytics and business intelligence.

The Microsoft Lifecycle Policy offers 10 years of support (5 years of regular support and another 5 years of extended support) for the 2008 and 2008 R2 versions of SQL Server and Windows Server. When the extended support period ends, there will be no patches or security updates, which always creates security risk.

If your business is going to remain competitive, you can’t rely on outdated systems.

Your business is tough enough to manage without having your systems work against you.  Software that prevents you from keeping up with demand, creates risk in compliance and security, and reduces operational performance is not what you need. Collecting, storing and rationalizing data takes power and speed, and securing your growing information warehouse requires vigilance in security and update management.

Use this opportunity to review your platforms and applications, and consider moving your on-premises or co-located systems to the cloud. The upcoming milestone is a great opportunity to transform applications and infrastructure to take advantage of cloud computing and the latest versions of SQL Server and Windows Server.

jmbunnyfeetMake Sense?

J

Contrary to What You Learned in Grade School… Sharing is Bad, Okay?

There is a place and time for sharing. Share your color crayons, share your toys… share your feelings with those you love. But when it comes to business technology and infrastructure, sharing isn’t always the best approach. Some things you should just keep for yourself… like the servers you use for hosting business desktops, desktop applications and business data.

When we first began the journey of bringing small business desktops and applications like QuickBooks to the Internet, the “cloud” was not yet a thing. Hosting providers put up servers in racks in data centers, installed software and stored data on behalf of customers, and did their best to find ways of making the service affordable. Elastic resources, massive scalability and built-in redundancy (which are benefits of a real cloud fabric) were not generally available nor were they even remotely affordable. Because the hardware, networking and other resources that make up the hosting infrastructure is costly, it is important for the hosting service provider to be able to spread those costs across the entire customer base.

In most cases, this meant creating shared servers where many customers run their applications and store their data. Even when a provider suggests that a customer has a “private” server, there is still a good chance the server is using shared storage and/or networking resources made accessible in the environment.

Sharing can be a good thing or a bad thing, and it often depends on the behavior of those involved. In shared application hosting environments, particularly desktop hosting environments, there is a lot of potential for intentionally and unintentionally causing problems that can and will impact other users and customers on the platform.

A simple provisioning error might allow a user to see data belonging to another company or have access to applications or services they should not.

With shared resources, bad actors and intruders can often escape permission boundaries, attaching to network shares and other computers on the platform.

Malware accidentally introduced by an innocent user from one company could easily penetrate the entire system, following paths to data storage locations and other servers, spreading the problem to many customers and systems and even data centers.

If you are operating on the compromised system you are at risk, even if the compromise wasn’t initiated by one of  your users or from within one of your applications.

In the realm of QuickBooks hosting providers, the issues around sharing infrastructure and resources have created some very difficult situations for hosts and for their customers alike – especially when it comes to dealing with computer viruses, malware and ransomware. A few high-profile events, as well as numerous incidents which have flown under the radar, have revealed just how damaging the shared approach can be.

With the IRS, AICPA and other agencies issuing increasingly strong guidance for tax and accounting professionals to protect client information, finance professionals should strongly consider the risk introduced through shared hosting service arrangements and evaluate if it is greater than the costs of having a more private system.

Cloud platforms available today are fully matured, delivering scalability and agility at price levels that are affordable even for very small businesses.  No longer solely for enterprise enjoyment, real cloud solutions and delivery models can be used by small businesses for desktop and application hosting without compromise. Every business deserves their own cloud, and we know how to make that affordable.

Cooper Mann works with teams deploying on the Microsoft Azure platform, offering an agility in design not previously available with legacy computing approaches. Because every delivery is absolutely private to each customer, the solution can be scaled up (or down!) on demand to suit the specific needs of the individual business. More important is the fact that each customer operates separately, so any bad behavior the system may suffer from is their own.

jmbunnyfeetMake Sense?

J

4 Rules of Thumb Regarding Passwords and Authentication

Many people believe passwords are dumb.  They store their credentials for easy login, or maybe even leave the password blank if the app allows. For IT managers, forcing users to come up with a strong, unique password is definitely not an easy task.  Resting on convenience over security, many people would prefer to use familiar names and dates or simple phrases they can remember.  Even when IT departments try to enforce best practices there is often a struggle between honoring those standards and influencing user behavior.

Relaxed password standards allow users to set passwords that may be as easy to guess as they are to remember, and very strict requirements for strong and complex passwords often results with users storing passwords in document files or on post-it notes on the monitor. Setting password standards and managing the policy implementation requires a balance between usability and security, but more often than not the balance skews toward simplicity. Yet passwords aren’t going away any time soon, even while biometrics and multi-factor authentication methods grow in prominence.

It is most likely that new technologies and standards will be combined with passwords to protect critical data. Using only a password to protect information may not be the ultimate in security, but it is important to recognize that passwords remain as a key element in any security model. For now, passwords should be as strong and unguessable as possible.  As technologies and standards rise up to meet the demands of users as well as enterprises, there are likely to be changes in how passwords are used. Here are 4 rules of thumb to consider regarding passwords and where authentication technologies are going.

1. Your face might be your password.

Biometrics won’t fully replace passwords right away, but the use of biometric data for authentication is growing rapidly. Face recognition, fingerprinting and voice identification are all being employed as authentication mechanisms and users are embracing the technology because it is easier to use than a remembered password.  Smartphones and PCs have sensors for reading fingerprints and cameras for seeing faces, and microphones for hearing your voice.  Many systems are also now able to use geodata with the biometric data (matching person to place), making it harder to compromise an identity while also being less disruptive to the user. While the technology isn’t foolproof, it represents a major step towards creating more secure systems without placing the responsibility strictly on the user.

2. Two pieces of ID are better than one.

The point of multi-factor authentication is that there are two different pieces of evidence a user must present in order to gain access. For example, a password may be the first piece of evidence presented, with a pass code sent to a mobile device as a second. Even as biometric authentication grows in prominence, industry participants recognize that no single method covers all the bases all the time. Multi-factor authentication is gaining in prominence as users become more familiar with the methods and the implementations become less intrusive. AI may also influence how these systems are applied. As user behavior and transaction parameters are “learned”, systems can identify activities that fall outside of normal routines and additionally prompt users for single-use pins or passwords sent to their mobile device.

3. Businesses should learn from past mistakes.

With news of hacking, ransomware and malware being daily fare, companies and their users are realizing that password security really is important and are stepping up their security efforts. The information is available to help prevent businesses from making the same mistakes that others have, offering worst case scenarios a’plenty to learn from.  Using default passwords and recycling passwords across work and personal accounts, using unsecured network connections, not encrypting files that contain password information and failing to patch or update systems and software are entirely preventable situations that put information at risk. Taking the reports seriously and identifying mistakes to avoid is highly useful in designing security for the business.

4. There’s a growing ecosystem for authentication.

With the number and type of systems requiring authentication – from industrial control systems to dating websites – there is a great and growing need to find highly secure methods of authentication that are actually usable for the user. Even in the world of blockchain there is a need for “identity assurance” and confirmation when documents or biometrics are captured via smartphone. Fast IDentity Online (FIDO) is a set of security specifications for strong multi-factor authentication, developed by the FIDO Alliance. The FIDO Alliance includes members such as Google, Aetna, Amazon, Microsoft, Bank of America and Samsung, and developed the spec as an initial basis for standardizing authentication across platforms and systems at the client and protocol layers.  

Technology is changing rapidly and solutions once reserved for government and large enterprise are now entering mainstream consumer use. You’ve probably already noticed that banking and other apps are employing the use of fingerprint and other biometric data with increased frequency as users demand easier access to applications and features from their smartphones and other mobile devices.

These technologies sometimes replace traditional password entry as the primary means of authentication or augment password use in some manner. Even MasterCard has announced a component in its payment card solutions that allows users of next-gen payment cards to register their fingerprint data on their credit card.

The push is to allow users to interact with their tasks without putting up barriers to access.

A combination of usability and enhanced protection, the new standards are developing to address not just system security but identity verification for various purposes. Corporate information must be secured and so must personal identity information; simply read the news to understand what can happen when digital identity information gets compromised.

Whether the data is business or personal, keeping hackers and bad actors away from it isn’t easy, so strengthening the most basic first layer of protection – the password – is the best place to start.

Make Sense?

J