Hack The Planet

Because if you don't, who will?

Friday, December 12, 2008

Open Source is a great start, maybe MSSP is the finish

I am a big fan of open source software and have been using it for most of my career to do one thing or another. I find that it is just a starting point, not the end of the road. When using an open source solution you have to plan for some customizations to fit your environment, just like you would with a standard commerical product.

I have found that many individuals don’t have the security resources to really deploy any free open source solution or the budget to purchase a full blown commerical solution. This usually leads to them trying to use the open source tools but inevitably leaving themselves extremely vulnerable.

With the lack of security resources and budget I have found a lot of customers are looking towards MSSPs to bridge the gap. It will be interesting to see how this affects the security market among small businesses over the next few years.

posted by holliday at 1:15 pm  

Wednesday, December 3, 2008

Visibility

Thought for the day:

If I don’t know about an issue, it can’t hurt me.

This seems to be a major factor in many companies overall security policy. Management has a responsibility to keep costs down and one way to do that is ignore issues until something bad enough happens for them to open their wallets.

For the person in charge of securing the data and systems on the network this is a very big headache. How can this security person be able to perform their job adequately without the proper tools or people? The correct answer is that they can’t. This person has to make it clear to management what issues they are seeing and why it is critical that they get resolved.

To do this you need to have visibility into your network and the ability to present that to your management team. Where do you find the tools or resources to do this though? The internet of course.

www.secviz.org

www.nmap.org

www.nessus.org

www.stillsecure.org

www.snort.org

www.darknet.org.uk

All of these give you free options to help build visual evidence to deliver to the management team. It is hard to keep your head in the sand when someone keeps clearing it away.

posted by holliday at 12:52 pm  

Tuesday, November 11, 2008

I told you so

In an interview with Marcus Ranum, CSO online asked him what he sees as the weakest link in the network security chain. He said “Not knowing what’s on your network is going to continue to be the biggest problem for most security practitioners.”

All I have to say to that is, “Duh”.

posted by holliday at 2:33 pm  

Monday, November 10, 2008

Threat assessment, or how I met your mother

As a species we are hard wired to do threat assessment in our day to day lives. We do many forms of threat assessment without recognizing it as such. You do it when you are changing lanes, or commenting on your wife’s outfit or even when you take that first sip of hot coffee. How dangerous is this thing I am about to do?

There is something that we need to be good at threat assessment. I am going to call it Danger Awareness. If you are not aware of some impending danger then you will have no way to correctly assess your threat level. One example of not having danger awareness is when you are in a car and you don’t check your blind spot before merging or changing lanes. I am going to refer to it this way when I discuss danger awareness on the Internet. When you change lanes and a car is in your blind spot it can end very badly, the same is true when you use the Internet without being aware of what is waiting for you.

To really be able to do a true threat assessment you must be aware of all of the dangers (or as many as humanly possible as there are more than enough to keep us all busy for many life times) and then build a plan to help you avoid the dangers that you are aware of and even some you may not be.

posted by holliday at 12:24 pm  

Sunday, November 9, 2008

Teaching the next generation

I was invited to be a guest at the University of Colorado to teach a networking class about Network Security. It was interesting to see how diverse the class was. You had the different groups you expect to find in a normal college classroom. The people there to learn, the people who think they already know everything you are talking about, and the people that are just trying to get a credit. There was also someone’s wife who was just hanging out with her husband.

There is a lot to cover under the umbrella of Network Security so I had to slim down what I went over. I went over vulnerability assessment, intrusion detection, social engineering, network access control, 802.1x and then gave some war stories.

I think that the next time I teach a class I will just build out one large scenario and then go over the security you would need to protect each section. I think it would be easier for the students to see how it all comes together to form a secure network environment.

posted by holliday at 8:06 pm  

Tuesday, November 4, 2008

HOPE

I am not going to discuss politics in this forum but this is the first time in my life time that I have had hope for our nation.

posted by holliday at 10:17 pm  

Tuesday, November 4, 2008

When all else fails

The failing economy has obviously effected every market to a certain extent. The security market (which is the one I am in so it is the one I care most about) has been hit pretty hard. I did not believe that people could do without security but I was wrong. This comes down to lack of legislation forcing people to take responsibility for data breaches.

An interesting article over at Network World is a letter to the next President asking him to take a stand. The author makes a great statement about how there will be no change until there are real negative consequences for not being secure. CTO’s and CISO’s will continue to do the bare minimum until there is a reason for them to change their ways.

posted by holliday at 1:52 pm  

Tuesday, October 28, 2008

How do you define ROI?

Everywhere I look I see links talking about ROI and let our tool show you how we can get you more ROI. Well, what is ROI? I get that ROI stands for Return on Investment and that it defines what monetary value this product will give you or save you for purchasing said product. Well, that is great when the ROI tool is designed by the person trying to sell you the product. I have some swamp land in Florida at discount prices if you are interested.

Seriously though, how can you show true ROI on a security product when the reason to purchase the product is to limit your risk of losing money through losing critical data, being DOS’d or having your competitors get your secret formula for that super secret project you are working on? You are purchasing the product to alleviate risk, some of which is unknown. It is very difficult to show true ROI because it is an unknown quantity. How much will you be fined for losing those 1,000,000 customer accounts? How much is your next product worth if you get it out before the competitors do? It is easier to build a case if you know what you are protecting and why.

When the reason to buy security is specifically ROI you are buying it for the wrong reason. Yes you do want to show that your purchase saved you countless headaches and hours or days of work when you are trying to recover from an incident.

It just seems like people want to “buy” security but don’t care if they are actually securing their networks and endpoints or have secure practices in place.

When you start looking to secure your network don’t settle for some fancy ROI chart. Look at how it will affect your infrastructure and make sure that it actually works. If you don’t, then I still have that swampland for sale at a low, low price.

posted by holliday at 12:12 pm  

Tuesday, October 14, 2008

Hacking has changed…duh?

I was just reading an article that was talking about Mafiaboy and what he is doing now, 8 years after knocking Yahoo offline. It struck me that “hackers” have changed from tinkerers to mafia types.

Once upon a time Timmy, hackers were people that just wanted to see what would happen if they touched that button or changed this byte. Now they are going around mugging tourists and they don’t care how they do it. There is so little curiousity left in the next generation of hackers that when the previous generation dies off from vitamin D deficiency all the tools will be lost also. Or at least new iterations of them.

All of the new attacks and new vulnerabilities seem to be coming from the previous generation. How do you teach innovation? How do you teach curiousity? I don’t think you can.

posted by holliday at 1:33 pm  

Wednesday, August 27, 2008

iPhone is UrPhone

So one of the guys over at gizmodo created a video to show you how to get past the security password on the iPhone. As cool as Apple is the one thing they are definitely not is a security aware company.

posted by holliday at 10:10 am  
« Previous PageNext Page »

Powered by WordPress