If you have worked in security or just read articles on security for any length of time you will realize that all you are trying to do is provide risk avoidance. To this this you have to be good at assessing risk and then working to minimize it. I am constantly bombarded by sites discussing how we as humans are awful at risk assessment. Maybe this is what makes a good security professional, the ability to see through the false positives and find the real threat.
Tuesday, January 12, 2010
Friday, January 8, 2010
Bruce Schneier posted today about the cracking of a FIPS certified encrypted USB key. The attack from the original article:
“During a successful authorisation procedure the program will, irrespective of the password, always send the same character string to the drive after performing various crypto operations — and this is the case for all USB Flash drives of this type.”
Bruce calls out that “FIPS 104-2 Level 2 certification only means that certain good algorithms are used, and that there is some level of tamper resistance and tamper evidence.”
Does it really matter that these USB keys have been cracked? The reason I ask is that everyone cares so much about the Cloud and having their data secured in the Cloud that it seems like securing removable media is taking a back seat. If the person who has the encrypted USB key also copies their files to the Cloud will they care that the USB is crackable or will they focus on how to protect that data in the Cloud.
Sunday, November 8, 2009
So it was just a matter of time until the iPhone got it’s first worm. This is what happens when you have a very large user base with the belief that nothing can ever hurt them. Apple’s marketing team has done its job.
Wednesday, October 21, 2009
The CIA has recently invested in Visible Technologies which is a company that specializes in monitoring social networks. These include online forums, Flickr, YouTube, Twitter and Amazon.
Privacy has gone by the way side in hopes that your internet friends will know that you “are going clubbing.” They aren’t the only ones that can see this though. It is easy to find out when people will be home and where they are going. A wily thief could use this information to relieve you of any of your valuables you have left at home.
Your friends are not the only people watching you or your actions. Your future employers, in-laws or law enforcement can all find out more about you than you think from your internet profile. Be careful what you put out on the internet because it is who you are to the world.
Wednesday, October 14, 2009
In recent weeks Brian Krebs of The Washington Post has been covering a lot of bank account heists that have been done using the Zeus Trojan that steals credentials of authorized users. In a more recent article he goes on to say that you should use a Linux LiveUSB when doing your online banking. It great to see a major newspaper run this story. If you are going to bank online and you use Windows you may as well accept that your credentials are in the wild. Download Ubuntu, and then never go back to Windows. Your life will be much easier (and you bank account more safe).
Monday, October 12, 2009
Recently there was a server outage at Microsoft subsidiary Danger which has ended in a lot of user’s losing their personal data. This is what happens when you don’t do your own backups and leave all of your data in the cloud (internet). There is a discussion about this on Slashdot but what it really comes down to is responsibility. Your data is your responsibility. If you give it to someone else then it is your fault when they fail to keep it safe or even to keep it at all.
Sunday, October 11, 2009
I couldn’t have said it better myself so I won’t. Richard Bejtlich wrote “If a file is only readable once it has been decrypted in front of a user, that is where the intruder will attack once his other options have been exhausted. This means that the only way to completely “protect data” is to make it unusable.” The job of your Information Security team is to make it more expensive to get your data than what your data is worth.
Thursday, October 1, 2009
So MSE was released and has received a decent amount of press. It was reviewed and found to be about the same as other free services which I think we all expected. I didn’t really see the need to comment until I saw this post and thought it highly relevant….and funny.
Wednesday, September 30, 2009
I have heard a lot of discussion around Signature based security systems and Behavior based systems. There doesn’t seem to be a lot of benefit to either without the other though. One of the nastier trojans, Zeus, is still evading most AV products on the market. I need to look into this more but it seems like companies either lean towards heavy signature and light behavior or light signature and heavy behavior. It shouldn’t be a religious debate. Companies should focus on strong signatures and strong behavior anomalies to determine if a machine is infected. I am very curious to see how Microsoft’s entry in the market will affect it.
Saturday, September 12, 2009
I think anyone in the security profession has to be a little paranoid to be any good at their job. You have to be a little paranoid to be able to see risk everywhere and assess what you can solve, what you can’t and the most important piece; the difference between the two.
As a parent you are constantly reminded by your children that no matter how hard you try, they will find a way to hurt themselves. The best you can do is minimize the risk and make sure you have an escalation plan. The same thing is true in security. Limit your risk and be aware of the steps to take when something does happen. One of the most difficult things for me to do is tell the difference between what I can do and what I should do (ie no kennels for the kids to keep them safe).
Now as far as security goes it is the same thing, find what you can do to best secure your data but also make sure that the people who need access to that data still can be productive. I find that too often I get into the mind set of “locking it down” instead of the business mindset of how to make it as secure as possible without affecting productivity.
Just because you can make something more secure doesn’t mean you should. You need to take a step back and think about what the extra security will affect and weigh the consequences. Sometimes being a little paranoid is okay, but not turning on your computer so that you never get a virus may be going to far….or maybe it isn’t.