ALKHOBAR, 26 November 2002 — I’ve got an entire inbox packed with messages screaming, “Where are you?” As all of you can read, I’m back after a brief two-week vacation out of cyberspace. Why was such an interlude necessary? Well, it happened like this. You see, I travel a lot for work and after getting on and off what seemed like a million flights in one year, I was exhausted. Toward the middle of October, I stayed at the Emirates Towers Hotel where the mouthwash was green and the shower gel was blue. The next week I camped out at Le Meridien, where the mouthwash was blue and the shower gel was green. As I was almost in a coma, I did not register the switch in the colors of the hygiene products. Thus, the first morning that week I found myself gargling with shower gel. Even worse, for about two minutes I didn’t realize I’d made any sort of error — until I started aspirating soap foam. That’s when I decided to log off.

Anyway, I’m back online now and I’ve got a whole bunch of stuff for everyone to do — immediately. Come on folks, move it. I understand that you’ve all been sleeping Ramadan away. The first item of business is to click to dmaconsumers.org and register your e-mail address to have it added to the Direct Marketing Association’s Opt-Out List. You simply type your e-mail address into the empty blank and click “submit.” Then, when an e-mail from DMA appears in your inbox, you reply back to it to confirm that the mail is correct. DMA requires that their member companies not send mail to any e-mail address on the opt-out list. The organization claims that within two months after an address is added to the opt-out list, the user of that mailbox will see a decrease in the amount of commercial e-mail received.

Next up, as all regular readers know, I hate my bank’s credit services. The entire civilized world is moving to plastic cards instead of paper currency, but here in the Kingdom, the banks are doing everything possible to penalize those of us who want to transition into the 21st century. Last year I paid SR225 to my bank for one high-limit uninsured credit card and another SR100 for an insured low-limit credit card to use online. I had to pay SR325 in annual fees for credit cards, despite the fact that I have an investment account with that bank.

This is why I am delighted that a new challenger has come into the market to shake things up a bit. American Express launched its American Express Blue credit card on Oct. 19. According to Mazin Khoury, CEO, American Express Saudi Arabia, the “Blue” card has been well received.

“American Express Blue comes with an Online Fraud Guarantee and we give back to the card holder 1 percent of the value of purchases made on the card yearly,” explained Khoury. “The annual fee is just SR200 and supplementary cards for family members are free. For those individuals who are already customers of American Express, the annual fee is waived for the blue card. The American Express Blue is different than our original green card in that we assign a credit limit and the card balance may be paid in installments.”

Basically the American Express Blue is fully insured against fraud, whether it is being used in the real world or off in cyberspace. The full available balance can be accessed anywhere. The card is being issued in the Kingdom by American Express to both Saudis and expatriates. To qualify, total income, which includes salary and all allowances, must be at least SR7,000. For further information go to americanexpress.com.sa.

The third order of business on today’s agenda is my role in refereeing arguments between teenagers and parents. Every journalist has a responsibility to be available for use as a community resource. That is how I frequently find myself in the middle of major squabbles between geezers, who won’t get online, and their respective offspring who never log off. I received a desperate e-mail from a young man who explained that he was in his junior year of high school and his father had just decreed that he should become a chemical engineer. The teen in the hot seat, named Hisham, explained that he hated the idea of working as a chemical engineer and urgently needed to convince his father that there were other jobs that could bring higher potential financial rewards and success than his father’s choice. Time for a little online research.

Eventually, I discovered just the thing to bring daddy around. It is necessary to point out here that Hisham will most probably be spending his adulthood in North America. At the website of the US Department of Labor, Bureau of Labor Statistics, there is an excellent report, “The 2000-2010 job outlook,” (www.bls.gov/opub/ ooq/2002/spring/art01.htm). The report should be recommended reading for all high school students and their parents, as many of its recommendations apply globally.

It’s excellent that Hisham shouted for help before he got trapped in a career choice he hated. Even worse, chemical engineering in the United States is expected to have slower than average growth, and competition for starting positions will be tough. Where are the good jobs? Actually, it appears that anything having to do with computers or data management is where the money and opportunities will be. Hot career picks include: Computer and information systems managers, computer software engineers, computer support specialists and systems administrators, systems analysts, computer scientists, database administrators and computer hardware engineers. Outside the computer field, biomedical engineers, environmental engineers and registered nurses will do well. With the fortune most parents will pay for higher education, it seems silly not to use the wealth of information available online to investigate the future employment market in order to help teenagers select careers that will be rewarding in every way.

Our last order of business today is a little matter known as cybersecurity. The US government would like everyone to start taking this issue seriously on both a personal and corporate level. The President’s Critical Infrastructure Protection Board, a group directly overseen by the White House, is currently working to create a final version of a document titled, “The National Strategy to Secure Cyberspace.” The draft of the document was released in September and all relevant comments on the document were submitted by last week in order to create a definitive National US Cyberspace Security Strategy. Why is this document important to us here in the Kingdom? Mostly because the US is emphasizing that security in cyberspace depends on everyone working together globally to implement best practices in this area.

The report pointed out the following:

“The US interest in promoting cybersecurity extends well beyond its borders. Critical domestic information infrastructures are directly linked with Canada, Mexico, Europe, Asia, and South America. The nation’s economy and security depend on far-flung US corporations, military forces, and foreign trading partners that, in turn, require secure and reliable global information networks to function. The vast majority of cyber attacks originate or pass through systems abroad, cross several borders, and require international cooperation to stop.

“In 1998, the United States received a wake-up call to the national security dimensions of the threat. Eventually dubbed ‘Solar Sunrise,’ this incident found US military systems under electronic assault, with computer systems in the United Arab Emirates the apparent source. Unclassified logistics, administrative, and accounting systems essential to the management and deployment of military forces were penetrated at a time that military action was being considered against Iraq due to its failure to comply with UN inspection teams trying to uncover evidence of weapons of mass destruction. The timing of the attacks raised US suspicion that this was the first wave of a major cyber attack by a hostile nation.

“It was eventually learned that two California teenagers under the guidance and direction of a sophisticated Israeli hacker, himself a teenager, had orchestrated the attacks using hacker tools readily available on the Internet. They had attempted to hide their involvement by connecting through overseas computers. Even cybercrimes committed by Americans against US computers often have an international component.”

The report insists that home users and small businesses must recognize that they have an important role to play in securing cyberspace. In a cyber attack, home users and small businesses can be severely damaged and in some instances their resources can be used to damage others.

Due to automated tools, cyber attacks are becoming increasingly common. Reaching each and every Internet user is much easier than before. For example, the “Honeynet Project” uses “dummy” systems attached to the Internet to measure actual computer attacks. According to the project’s most recent results, a random computer on the Internet is scanned, meaning it is checked for its presence, setup or weaknesses, dozens of times a day. A common home user setup the project created was hacked five times in four days. In some cases, insecure servers were hacked 15 minutes after connecting to the Internet.

The report asserts that using the Internet in a secure manner does not just happen. Rather it is the purposeful result of both awareness and the availability of services and tools, which facilitate secure Internet use. Research for the report found that it is often difficult for home users and small businesses to access the Internet securely. Many home users and small businesses do not use firewalls to protect their computers from unauthorized intrusions. DSL is increasing in popularity but often individual users are unaware of the security implications of an “always-on-connection.” For example, these connections generally mean that larger amounts of data can be sent at any time and the data can be sent continuously. These two factors can be exploited and used to attack other systems, possibly even resulting in nationally significant damage.

The report made five recommendations to be carried out by all individual and small business computer users.

1. Because automated hacking programs scan the Internet for unprotected broadband connections to exploit, those home users and small businesses planning to install a DSL or cable modem should consider installing firewall software first. Once firewall software is installed, it is important to regularly update it by going to the vendor’s website.

2. Because new computer viruses are introduced every week, home users and small businesses should regularly ensure that they are running an up-to-date “antivirus system.”

3. Because new viruses often come as e-mail, home users should use caution when opening e-mail from unknown senders, particularly those with attachments. To reduce the number of unknown senders, home users should consider using software that controls unsolicited advertisements, called “spam.”

4. Home users should also regularly update their personal computer’s operating systems (such as Microsoft Windows, Macintosh, Linux) and major applications (software that browses the Internet or creates documents, charts, tables, etc.) for security enhancements by going to the vendors’ websites.

5. Internet service providers, antivirus software companies, and operating system/application software developers should consider joint efforts to make it easier for the home user and small businesses to obtain security software and updates automatically and in a timely manner, including warning messages to home users about updates and new software patches.

Individuals and small business users can find more information on cybersecurity best practices at websites such as staysafeonline.info, infragard.net and crsc.nist.gov. Children and teenagers spend more hours online than most adults. Parents and teachers have an important role to play in helping young people learn about cybersecurity. The “CyberSmart School Program” is a free resource, which provides a complete curriculum that can be downloaded over the Internet from cybersmartcurriculum.org. Another website, netsmartz.org, is designed to teach children directly about what to watch out for when surfing the Net. Helping teens understand ethics online and the risks of cybercrime is the purpose of cybercitizenship.org.

The “The National Strategy to Secure Cyberspace” report is extremely comprehensive at all levels, from individual cybersecurity through to national issues. Download a copy from whitehouse.gov/pcipb/.

***

(Comments to [email protected].)