Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts
Thursday, 26 July 2018
Not All Encryptions Are Created Equal
In today’s volatile digital security world, encryption has become a standard security measure to keep your data protected. Many in the security industry would even goes as far to say that it is one of the most important methods for providing data security, especially for end-to-end protection of data transmitted across networks. The core foundation of encryption focuses on converting information or data into a form unreadable by anyone except the intended recipient. Once a file or data piece is encrypted, it becomes difficult for external sources to get access/understand the encrypted information.
While highly touted, encryption is hardly a new strategy with the origins of hidden messages and cryptography dating back to the 19th century. Since then, it has evolved and there are many different types of encryption algorithms that are used. However, not all of these are created equal or are completely secure. Below are several types of today’s popular encryption algorithms all of which have security loopholes.
Homomorphic Encryption
Homomorphic encryption requires a public key to enable search. This also means it requires a keystore to hold the private key to enable the encryption. The person with access to the keystore has access to your data! This means you are putting your data at risk to internal misuse and in the hands of who owns the keystore. You don’t believe you would have an internal person who abuse this power? Nor did the CIA until Edward Snowden fled the country.
Data Masking
Data masking has generally been created as an intermediate layer between the data store and the user and is becoming more common as part of the GDPR regulations. The masking gateway accesses the data as an administrator and transforms (masks) the data on a user query. However, the stored data remains in clear text and is vulnerable. Simply put, this is really just application redaction.
TDE – Transparent Data Encryption
This technology encrypts the data file on disk, stopping anyone from reading it, while it is at rest on the disk drive. HOWEVER, as soon as it is loaded in to the database, it is decrypted and available to be viewed by all who have admin privileges. This puts the encrypted data at risk to internal misuse as admins have approved access to the keys and could decide to capitalize on this access to sensitive information.
Column Level Data Encryption
Column level data encryption is generally implemented with a keystore, which means that those with access to the store also have access to the data. However, just as importantly, if this is implemented post production, it requires whole-sale changes to the database and the calling applications, leading many implementations to remain incomplete, as well as expensive.
As you can see, many of these encryption tools are lacking in complete external and internal security.
At BOHH Labs, we believe that the parties at the two ends of a data message – the sender and requester – should be the only ones who have access to that data message. We believe encryption should be dynamic. In other words, your keystore should be dismantled and the encryption keys, IV’s Salts, should be created by the application based on different criteria at that moment in time. This means that each piece of data, each network message, or each file is encrypted to a unique key, so it doesn’t leave your data open on your key store and accessible to unauthorized employees. Dynamic key creation encryption that has no reliance on web security or keystores is a cornerstone of BOHH’s data security service. Every data request is isolated from the requestor and is encrypted using transient keys that are destroyed after each transaction. This means the original data request never has direct access to the company network or backend database and terminates intercepting party connections and renders partial data a third party may get access to useless, making it very difficult for to steal useable data (including a database admin). Further, by uniquely providing field level security, removing these fields from the source, storing the encrypted data and separately, without changing the underlying database structure or using a keystore to manage the encryption keys, which removes not only the hacker threat to the data, but also the more prominent insider threat.
As such, despite being popular in the security industry, it’s clear that many of the current encryption methods that have backdoors, especially for internal misuse. If you are interested in more about BOHH’s keystore-less encryption method that makes these security loopholes obsolete, reach out to learn more.
Tuesday, 19 June 2018
Why Every Company Needs A Proactive Plan to Secure their Proprietary and Sensitive Data
- Ted West, BOHH Labs Chairman
Companies store a massive amount of data which they want to liberate for new business applications, analytics and optimization. These data include everything about customers, suppliers, production and logistics operations, as well as financial transactions and results. All these data offer new value to companies looking at adding new business applications and analytics tools to help make better business decisions and remain competitive.
Many of these applications and tools reside on the cloud, outside of existing “firewalls” of security. And while the companies consider and procure more and more security solutions to harden the edges of the firewall, they remain reluctant to “let the data out” to the cloud due the risk of it being hacked, leaked, lost, or stolen. As a result, companies may be missing out on ways to better optimize their business.
In today’s business environment, proprietary data can be an immensely valuable asset. It must be treated as such. It is no longer enough for companies to take a laissez-faire approach to securing proprietary data, reacting to a threat or breach and figuring out how to deal with it on the fly. Rather, companies must adopt a proactive approach and plan to secure their data before letting the data out.
Companies are responsible for holding massive amounts of data – much of which is sensitive customer and employee personal information such as PHI (Protected Health Information) or PII (Personal Identifiable Information), as well as sensitive proprietary and financial data. When a company experiences a breach and any of this sensitive data is leaked, companies are exposed to financial and brand damage, trust and loyalty degradation, and even lawsuits, financial penalties and fines.
That is why it is critical companies have plan to approach their data security. But, what does such a proactive data security plan look like? The first step is understanding your data and how it is already protected. Once these questions are addressed, data security protocols and policies will be better understood, and new security protocols and solutions can be reinforced, updated or added.
Questions you must address to start your data security plan when moving data outside the enterprise:
1. What company data from the inside is needed to move on the outside into new applications?
2. How is this data transported from on premise (inside the firewall) to the cloud?
3. Which of these data are truly sensitive, subject to privacy and confidentiality requirements?
4. How will user access to these data be provided once data is outside the firewall?
5. How will the truly sensitive data be transported and accessed with privacy and confidentiality?
When companies don’t have a plan in place to protect their proprietary data, it can’t be properly leveraged to optimize their business. The analytical value of data is enormous and can be applied to everywhere from improving sales cycles to helping organizations plan better marketing efforts that will help companies make more informed decisions on how to interact with its current and potential customers. However, if data is not properly protected or, even worse, if data is breached and stolen from bad actors, companies will lose the ability to apply this value to their business efforts.
Every company should have a well-thought out plan to protect their proprietary data at the root level to help minimize risk of data breach and loss, while taking advantage of the full use of their data.
Tuesday, 3 April 2018
Why Data Integrity is the Key to Protecting Corporate Data
It’s clear data is an asset to businesses and holds a lot of weight to how successful a business can be. That is why it is vital for companies to take a look at how they are protecting data across their entire network.
Traditionally, security professionals within an organization identify the most sensitive information and pick and choose what information should be protected and selectively give access privileges to certain individuals. However, this approach to security is incredibly dated and does not hold up to the new cloud and mobile services companies and users alike are using to access and store data. As such, with the massive amount and constantly changing data that is flowing through a company’s network from various users and applications, it makes it difficult to manage the security of all this data.
With the heavy reliance on an open and integrated cloud environment to access their data, it’s critical for us as security professionals and technologists to look at what security tools are put in place currently and ask ourselves if we are doing it right and providing enough trust and security to enable organizations to allow their customers to use that data correctly. It’s time to take an approach that assumes all data is at risk from internal and external threats and focus on making data security a priority by combining the approach to weave the access to data with security from the start. If we don’t, we are going to lose our data.
What Does This Mean?
To make data security a priority, the core focus must be on protecting the data itself at the foundation level. Regardless of the user, it is important not to assume that every data request that comes in is from a trusted source. As such, at BOHH Labs we use a process that separates out every request from the requestor, and then use a combination of unique keyless end-to-end encryption, Artificial Intelligence technology, Natural Language Processing, and In-Memory Distributed Blockchain Ledger technology, to ensure the request gets checked at all points of vulnerability: the request, processing and backend data stores. This means every data request must be validated at each of these three points before moving forward, and never has direct access to the backend system so anyone coming on to the system is not able to hack their way through. This will allow companies to protect data no matter where it is being stored, accessed or transacted such as on on-premise databases, cloud platforms, IoT devices, mobile services and more.
Data is increasingly a critical part of businesses and consumers’ lives; thus, it’s essential to protect it without hindering the ability to actually use it. As such, at BOHH we believe it is time to revaluate how companies are securing the interaction with their data and make data access and security of it a priority to ensure companies can securely deploy innovative enterprise applications and cloud services without opening them up to massive, widespread, and malicious security threats.
Friday, 30 March 2018
Weekly News Roundup
Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.
Under Armour Says 150 Million MyFitnessPal Accounts Hacked
Under Armour Inc., joining a growing list of corporate victims of hacker attacks, said about 150 million user accounts tied to its MyFitnessPal nutrition-tracking app were breached earlier this year. An unauthorized party stole data from the accounts in late February, Under Armour said on Thursday. It became aware of the breach earlier this week and took steps to alert users about the incident, the company said. Read more…
Boeing hit and recovering from possible WannaCry attack
Aerospace manufacturer Boeing is reporting that the company has mitigated what may have been a small outbreak of WannaCry ransomware that hit one of its manufacturing facilities on March 28. Read more…
As Atlanta Seeks To Restore Services, Ransomware Attacks Are On The Rise
Atlanta city officials are not saying whether they were strong-armed into paying the $51,000 ransom to hackers holding many of the municipality's online services hostage, but they did announce progress in restoring networks on Thursday. Read more…
Facebook Could Be Fined Millions for Violating Consent Deal
Former Federal Trade Commission officials say that Facebook Inc. appears to have breached a 2011 consent agreement to safeguard users’ personal information and may be facing hundreds of millions of dollars in fines. The agency could fine Facebook up to $40,000 per violation per day -- which could add up quickly with millions of users involved -- if it finds the social media giant broke its earlier promises to protect user data, they say. Read more…
Thursday, 22 March 2018
The Security Blame Game: From the Past to Now, Who Takes Ownership When Things Go Wrong?
- Dr. Peter Courtney, BOHH Labs Director
Today security threats seem to be inescapable, with companies dodging attacks on an hourly basis and breaches being revealed daily. As such, the practices, technologies and management of security threats have seen a dramatic shift over the past couple of decades, especially in how breaches are accounted for and who takes ownership when things go wrong.
Before we can address where we are today, we first must look at the past and where we’ve come from. In the past, security flaws in a company amounted to losing a ledger-book, a cash box or a roller-deck. While the competitor might steal some customers if they obtained your roller-deck, the impact was modest compared to having an electronic customer file stolen, that might then be sold on, mined automatically or even put up on public display to embarrass the company, as is happening today. Additionally, the complexity of IT errors was much simpler in the past. For example, IT errors might have involved a functional code bug that only caused a problem under rare circumstances. In these instances, the impact on the company was relatively low, typically affecting a specific area of the company. It was relatively easy to identify the culprit and move forward with a solution. Security breaches were dealt with in a similar manner to a project failing, the CEO would identify the accountable executive and either censure, discipline or fire them depending on the severity of the issue. Typically, the executive to blame was either the CIO or CSO, as security was their focus area and it was clear that they carried the accountability.
Today, more often than not, IT errors are deliberate attacks that target systems such as payments or CRM, they can invade the core processes of the company and may broadcast sensitive customer information to the public web. Unlike in the past, this means that the impact can stretch across the entire company, not just the area that is initially targeted. The company can be damaged internally and potentially cause reputational and financial damage in the public domain. Because of this, the impact of the breach spreads across the company and accountability flows far beyond the IT/security department. It may be judged that the CFO, CSO, COO or even CEO should have exerted greater control over the company, its processes and its decisions. Today, it is much more difficult to clearly assign blame. Unlike in the past, the perpetrators of the breach may never be identified or the case proven with any hard evidence, making it difficult to hold any single person accountable. In addition many of the suppliers of systems and security are now external rather than having been developed in-house as was the norm. Indeed, the external party may have been selected by a Board decision rather than simply the CIO or CSO, making it even more difficult to assign individual accountability.
Because the nature of security threats are becoming more complex and the impact a breach can have on the company is more widespread, the risk that accountability may not be contained to an expendable CIO or CSO is making security a priority for the whole executive and even non-executive Boards. We are seeing more executives politically positioning themselves both in demanding scrutiny on security decisions in advance of them being made and also in positioning accountability away from themselves where that is possible.
The current IT world has been unable to prevent breaches from occurring and many institutions simply consider it a cost of doing business. As we are seeing, if the threat is inescapable, then so too is the blame. We now see companies spending huge sums on technology solutions that may not work but enable the company to say that they followed the process and did what they were supposed to do, so they should not be penalized. For now, companies are simply skirting around the accountability game when it comes to breaches, but if we are to move forward as an industry overall, we must come up with a better way. Surely it is time to find security solutions that actually fix the risks and solve the problems rather than waste political energy and money on avoiding blame when the inevitable breach occurs.
Tuesday, 20 March 2018
Web Development Tools You Should be Using to Protect Your Data
- Greg Gray, BOHH Senior Software Engineer
At the core is your server’s software. Keeping it up-to-date should be a primary concern. Bugs and security holes can quickly compromise your systems if you don’t keep the software patched with the latest fixes. If you are maintaining your own server network environment, you also need to pay attention to firmware updates for your network infrastructure, as exemplified by the recently revealed exploits (e.g., Slingshot) that can compromise your network routers.
Managing the configuration of your servers is also important. Restricting incoming traffic to just a few ports is a common practice, but it’s also important that other software, such as the database is also protected. Data breaches are regularly reported where the exploit is using the default root password on a system exposed to the Internet. Some database installation processes will suggest the changing of root passwords and will initially limit access to the network, but it’s up to you to ensure that these safeguards are maintained and not compromised for convenience. An even better practice is to not expose the database to the Internet at all, relying instead on application server access via internal network paths.
Additionally, all web servers should be configured with SSL certificates. Sorry, but the days of worrying about the loss of the extra CPU cycles to process secure requests are over. HTTP (insecure) access should be limited to allowing a redirect to the HTTPS (secure) processes. Browsers will soon be warning users when they are accessing sites that aren’t protected by SSL certificates. Lock them down and keep the SSL software up-to-date.
Most of the responsibility for data security is in the hands of the developer. I am constantly amazed that there continues to be reports of SQL Injection exploits when the simple practice of parameterized queries can solve the problem. Many databases can now be encrypted or use custom encryption routines on specific tables and fields. Password fields need to be stored with one-way hashing functions, preferably using per-user salts.
But encrypted databases won’t protect against an application that has been compromised. The application will, by design, have the mechanisms or permissions to decrypt the data. The application should only be allowed to do the tasks on the database that are required. For example, most end-user applications probably don’t need to drop tables or create scripts. If they don’t need a permission, they shouldn’t have it. If the app can’t do a particular function on the data, neither can someone attacking the data via the app.
Almost everything running at the web browser has the potential to be compromised. Those wonderful browser-based user experiences come at a cost by delivering the software to the browser in a human-readable form, ready for exploitation. Make sure your code doesn’t contain account names and passwords, or any other information that can be used to compromise your back-end server.
Form input validation should take place at both the browser and the server. Browser-based validation speeds the response to the user (a convenience) but server-based validation is needed to ensure the browser’s process hasn’t be compromised (a necessity).
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) exploits have many attack vectors but mitigation is possible with the appropriate server checks in place. XSS exploits can occur anywhere your web application uses input from a browser within the output it generates without validating or encoding it. You must validate and escape/encode all input that comes from the wild. CSRF prevention begins with checking standard headers to verify that the request is “same origin” and using CSRF tokens. Developers will often disable the “same origin” checks during testing, and sometimes they forget to turn them back on. See the Useful References from the Open Web Application Security Project (www.owasp.org) at the bottom of this post for an overview of XSS and CSRF.
At the end of the day, how do you know if your carefully crafted best practices are actually being used and providing full coverage? Code reviews by staff not involved in the project are one solution. External audits of common and uncommon exploits are another solution and might be best done by third party software and service companies. Some good examples of such services include: Netsparker, SecurityHeaders, and Xenotix.
Website security cannot be taken lightly. Breaches have operational and legal ramifications. Good security design practices and a little help from outside agents can ensure a healthy web experience for your customers and your business.
Useful References
XSS (Cross Site Scripting) Prevention Cheat Sheet https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet
Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet
https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet
Labels:
data,
data protection,
database,
HHTPS,
server,
SQL,
web,
web development,
web tools
Thursday, 1 March 2018
Confessions of a Marketer: Data Is Everything, But I Won’t Share Mine Until I know It’s Securely Protected
You might think that as a marketing professional, I would be fascinated by loyalty programs and their power to grow revenue by creating repeat sales and building customer relationships. (I am!) So logically you might expect me to sign up for every loyalty program possible where I regularly spend $, to both experience it as a marketer, as well as reap the benefits of being a member. (Free makeup samples at Sephora! Special discounts at Rite Aid! Birthday bonuses from Anthropogie!) The truth? I avoid Loyalty Programs like a middle seat on a 6-hour flight.
I avoid all manner of giving away personal info to companies, even ones where I regularly spend my cash. My privacy is worth more to me than free mascara samples and 20% off coupons. I know how valuable my personal details are to the marketing team at a company, but its security is far more valuable to me than any incentive a company has ever dangled in front of me. I’m not giving it away just for a discount on a new spring skirt or some cute espadrilles. I’d rather spend the extra $ and keep my personal info secure. Why? For one, it is clear by the breaches that happen almost daily now, that companies are struggling to protect customers’ data. Just look at some of the more recent breaches from top-name companies: Equifax – exposed data of 143 million customers; Uber – over 56 million customers affected by a data breach, and there is still aftermath from the Yahoo data breach that happened years ago with it being revealed last year that the number of people affected jumped from 1 billion to 3 billion. Secondly, working in the security industry, I just know too much know about data security to feel confident my data will be secure. The risk of accidental or intentional exposure of my data is far too high in today’s world.
There is not always a lot of control users have when it comes to data breaches, but one small line of defense I can take is to control how much of my information I share with the companies and services I am using.
As a customer, I would never sell my personal info and my purchase history for some free samples or a birthday discount because I don’t think we fully understand the implication of privacy breaches in our data driven economy yet, other than of course the direct impact of our credit card being stolen or our social security number being compromised. I don’t think I’ll ever participate in loyalty programs unless laws are enacted to protect our privacy, but beyond that, I would need to know how companies protect my privacy.
As a user, before giving away my personal information to a company, I want to know how that company will keep my data protected and give me secure access to my data. Currently, I believe there is too much focus from companies on figuring out how to collect and analyze customer data to apply toward marketing and audience targeting strategies and not enough focus on keeping that customer data they interact with safe. At BOHH Labs, we believe that data is invaluable and we are focused on re-evaluating how customers can have access to their data, yet keep it safe when sharing it with companies and services.
We believe that the parties at the two ends of a data message – the sender and requester – should be the only ones to have access to that data message. As such, our security approach focuses on ensuring a secure transport of data between all users, applications, and the end database services. We use a powerful combination of keyless encryption that keeps data protected both in transit and at rest and Artificial Intelligence technology, Natural Language Processing, and In-Memory Distributed Blockchain Ledger to ensure that your data stays protected, no matter where it is stored or accessed from. And until I know that the companies I do business with protect my data with the same care, I guess I’ll be paying more for my moisturizer and melatonin. But I wont be losing sleep over who has access to my private info.
Tuesday, 27 February 2018
Why Is BOHH Labs The Data Security Standout?
BOHH Labs is a company that believes security is paramount to success, but at the same time we think it should not get in the way of data access. After all, while data protection is invaluable to companies and users alike, it also serves no benefit to keep it protected if it is not accessible for anyone. Let’s be honest, users want to know their data is secure without worrying where it is coming from or impacting their usability and convenience. If they have issues accessing their data or the process means jumping through hoops to get to it, users are going to find a different way of getting it, and this is what opens the door to big security threats like we have seen weekly over the last several years.
We believe that it’s critical for us as technologists to look at what security tools are put in place currently and ask ourselves if we are doing it right and providing enough trust and security to enable organizations to allow their customers to use that data correctly. If we don’t put security in place, we are all going to lose our data.
That’s why at BOHH, our security solution is built on making data security a priority by taking the approach to weave the access to data with security from the start. What makes our approach unique is that we ensure a secure transport of data between all users, applications, and the end database services by validating access at each stage of the journey. Our process separates out every request from the requestor, and then using a combination of patented security IP of unique keyless end-to-end encryption, Artificial Intelligence (AI) technology, Natural Language Processing (NLP), and In-Memory Distributed Blockchain Ledger technology, the request gets checked at all points of vulnerability: the request, processing and backend data stores. This means every data request must be validated at each of these three points before moving forward, and data only interacts with the BOHH secure server, removing direct access to the backend system so anyone coming on to the system is not able to hack their way through.
This process enables our core focus to be on protecting the data itself, so this allows BOHH to protect data no matter where it is being stored, accessed or transacted from, such as on on-premise databases, cloud platforms, IoT devices, mobile services and more.
Not only does our technology solution protect data at the foundation level, but our AI and NLP technologies also give users the ability to securely, quickly, and easily convert real-world conversations into computer commands with voice-controlled access to the data needed in real-time. This enables BOHH to offer instant access to complex data, no matter where it is stored or accessed from, while making sure it is accessed through a secure process.
Data is increasingly a critical part of businesses and consumers’ lives; thus, it’s essential to protect it without hindering the ability to actually use it. At BOHH, we will continue to make data access and security of it a priority, and empower enterprise and users to securely interact with it, without opening them up to massive, widespread, and malicious security threats.
That is why BOHH Labs is the data security standout. If you would like more information on our adaptive security solution, then please visit https://bohh.io/ or reach out to us at info@bohh.io.
Monday, 26 February 2018
End Users: Data Protection Is Your Responsibility Too
- Becca Bauer, Director of Marketing & PR at BOHH Labs
In a recent post we addressed how it is time for enterprises to take data security seriously and view it as a legal responsibility to their users and customers. While enterprises who interact with user data must have accountability and responsibility on how its protected, this is not a one-way street.
As an end user, you do have some control over security of your data, and more importantly, you should exert that control over both your data and within your relationship with your cloud provider. What does this mean?
On a corporate level, this means not allowing a cloud provider to hold encryption keys. If you pass your security to a third party, and they own and store your encryption keys, then you have lost control of your information. For example, let’s say an unhappy employee, an ex-employee who was recently sacked, or an employee who has an axe to grind uses inside knowledge to share a virus, share documents with rivals, or misuse company and personnel data. If this organization is a cloud store or service provider that also holds and owns your encryption keys, then in any one of these cases your information is far from safe.
While these scenarios may seem far-fetched, many breaches have occurred this way. As such, it is imperative that you own and store these separately from your cloud suppliers. If you do not, then your information can be stolen or even subpoenaed without your knowledge.
On a personal level, end user accountability means being careful about what information is placed in a cloud store or social media network, or about how you behave regarding services that interact with sensitive data, such as online banking or e-commerce.
The truth is not all enterprises and cloud services are the same, so you should not assume they all have the same stance and protocols on protecting your data. It is important to treat each company and/or service you share your information with on a case-by-case basis, especially depending on the sensitivity of the data.
There are many ways for users to take control of keeping their data better protected:
- Set data permissions: You ultimately have responsibility for your data. If your bank account is hacked, you may need to prove your password was protected and you did what was necessary to guard against a breach. You must also be careful of the apps you download and if these apps do require a password, where else have you used the same one? Cognizant of this, we decide to pick a new password and check “Remember Me.” This makes it easier for us but doing so gives the site or application a cookie that is open to misappropriation.
- Less is more: Keep your most sensitive information on the fewest number of different computers or cloud-based tools as possible. Having fewer copies of your most sensitive documents helps keep it more protected. While the cloud provides convenience and ability to access information from multiple devices, are you really going to need to access all your bills, bank accounts, investment statements from anywhere? Disable Remote Desktop (RDP) unless you require these features. Additionally, it is best not to enable remote connections to your PC unless needed at the time. Instead, enable the remote connections when needed, and disable them when you're finished.
- Be conscious of where you access your data: Online tools and mobile device give us anywhere, anytime accessibility, but far too often, we don’t think too much about where we are accessing our data from. For example, by using public Wi-Fi, it's rather simple for someone to intercept your data in a man-in-the-middle attack by first setting up a network and naming it "Free Wi-Fi;" Instead of simply connecting on, ask the restaurant or airport staff what the name of their network is. Better yet, learn how to tether your phone and turn it in to your personal hotspot to keep other prying people out. Also keep in mind when traveling —if you sync your phone to rental car system, did you remember to wipe it before returning the car rather than trusting that the rental company will do it?
What we forget with living in an online world is that our data, everything from personal to financial, lives online and we often hand it off to others without a second thought. As our world becomes increasingly mobile, is it time to re-evaluate the value our data holds and start taking accountability for the care of it, like we do of our physical things, and not just rely on the organizations we hand it off to to keep it protected.
Subscribe to:
Posts (Atom)







