Almost to add on my previous (or a previous) post I think one of the big things stopping people from moving to a more secure OS or infrastructure is the desire to not learn. It is really easy to sit back in our ignorance and blame outside sources for our security faults. What would the insurance company say if your house was robbed and they found out you left the doors and windows open all the time, even when you weren’t there. Your answer better not be “Well I didn’t know better.” They may not reimburse much if it is.
In our technology filled world it is no different. Being ignorant is no longer acceptable. If people are unwilling take the time to learn how to “lock their doors” then they are going to have to come to grips with getting hacked. I don’t mean that the hacker is not to blame but if you leave the sandwich on the counter, there is a good chance the dog will eat it.
posted by holliday at 3:05 pm
Comments Off on Education isn’t just about teaching, you have to be able to learn and want to learn
I recently gave my parents a new computer and when I was installing it I couldn’t help but feel dread knowing that it was Windows. I have tried to move them over to Linux for the last few years but I have been unable to get them to switch. I think part of it has to do with their work computers being on Windows also. How do you show the value of change?
When I first tried to get them to switch it was because they had infected their computer beyond recovery. I installed Ubuntu as it is the most friendly Linux OS I have found. They gave up on it before they even logged in because it wasn’t Windows. Now they have Windows again and I can only imagine how long it will be before I have to rebuild the PC again.
There needs to be an easier way to get regular people to use a more secure OS.
posted by holliday at 7:35 pm
Comments Off on Security for the rest of us
I should have published this right after I got back from Defcon when it was all fresh in my mind. Sadly as things go I forgot to and now most of my memories of it have a shadow around them.
BlackHat this year was pretty good with some good talks this year. There are some very good presenters and there are some not so good ones. The information can be good but if you don’t know how to present it then a lot gets lost in translation. Not meaning dialect but meaning in what you mean and what the listener hears. One of the better speakers at the show was Jeremiah Grossman and also Dan Kaminsky who both know how to engage an audience.
Defcon was a bit more of the same old but I enjoyed the capture the flag as always. I don’t know why it interests me so much but it does. The parties were great also. The Freakshow went awesome. I think it was all about the contortionist though. She seemed to have a pretty captive audience for most the night.
The big thing I took away from this year was that you should spend your time looking into the easy solutions before you hammer away at the more difficult. So often we get caught up in the thing that looks coolest but is more likely to fail than trying to just walk in the front door. Low tech hacks are usually faster than a more complex (or even cooler) hack.
posted by holliday at 1:36 pm
Comments Off on Defcon 16
With the recent conflict between Russia and Georgia (not the US state although that would make things very, very interesting if it was) there is a lot of debate on what is cyber war. There is an article today on CNN.com that discusses potential cyberattacks on US infrastructure. There was another article somewhere, I forget where now, that talked about hackers as terrorists and DOS attacks as cyberwarfare. What constitutes a cyberattack? I mean, I know what should but what do government officials think cyberwarfare is? Defacing a website? Maybe throwing a few packets someones way? If we are so worried about hackers knocking out our power then why is the grid still open to those types of attacks? It seems like we as a country talk a lot about all of the ways we can be attacked and then we put in false security measures to make the masses feel safer. Airport security anyone?
posted by holliday at 1:27 pm
Comments Off on Is a DOS attack Cyberwar?
Security Engineers are in high demand and with the recent vulnerability found by Dan Kaminsky it is clear why there are just not enough of them out there. We can all patch our systems and keep them up to date with the latest hot fix or security update but the bigger issue is that patches only come out after a vulnerability or issue is found. How do you prepare for the unpublished vulnerabilities and unknown attacks? The answer is to build your environment with security in mind from the ground up, not as an after thought.
There are too many people who feel that security is an add-on or a nice to have so they don’t design it in to their environment. If more people would start with security in mind they would find that they had less risk and fewer incidents.
posted by holliday at 3:47 pm
Comments Off on When patching isn’t enough
I am not a fan of bumper sticker wisdom but this sticker “Ignore your rights and they will go away” really hit home. With all of the news recently about Congress trying to push legislation that will let telecoms get away with illegally wiretapping the public for the government I thought it was a good time to post about our rights.
In America we have many rights. Some of these include our freedom of speech, our right to bear arms and our right to vote. Our rights are slipping away because We the People are not interested in knowing what our rights are or defending them when they get trampled.
How many Americans feel that voting is useless? I know many of my friends don’t plan on voting in the presidential election because they believe their vote doesn’t count. This is because there are no classes in school that teach kids how much their votes do count at every level of government.
There are American history classes in our public education curriculum but how many of them really teach what it means to be an American? I would guess none. I know that my American history class didn’t fill me in on it. This is all intentional. If we all become cattle we will all be easier to herd. Please take it upon yourselves to educate your friends and family as to what it means to be a citizen of America and why fighting for our rights and knowing what they are is our duty.
“If a nation expects to be ignorant and free, in a state of civilization, it expects what never was and never will be.” Thomas Jefferson
posted by holliday at 12:59 pm
Comments Off on Ignore your rights and they will go away…
Chinese hackers destroy Earth…or they cause mass black outs…or it didn’t actually happen like that at all. The media is controlled by people that really want to make sure you hate the right people. For a long time it was Communists, then we went for a period without a common enemy, then it was terrorists (AKA Arabs), and when we figured out as a people that they weren’t the enemy China became the target of our fear. Sadly the majority of Americans are not willing to inform themselves so they will go on thinking the Chinese are the new enemy when in fact, it was many other factors that had nothing to do with the Chinese.
posted by holliday at 6:04 pm
Comments Off on and now for our media…
A buddy sent me this video of CSI NY knowing that it would break my brain. I don’t ask for much, just get a technical consultant if you don’t know what you are talking about.
posted by holliday at 9:42 am
Comments Off on This is what is wrong with America…
I have a horrible time breaking away to keep this updated so if my posts always seem 4 days late…well they are.
After doing a lot of research on the Phlashing attack that is being discussed I find it interesting that everyone discredits it not because it would not be wildly successful, but because there is no money in it. There is no more illusion as to what being a hacker is anymore. You are either paid by the mob/organized crime or you are working to stop those paid by the mob/organized crime.
There don’t seem to be a lot of mystery seekers out there anymore. People that would work all night to get something to work, or to find something new. No one wants to know about hacks or cracks that are not directly tied to the purse strings of whoever they report to. It feels dirty.
There needs to be a restart button on the internet.
posted by holliday at 6:43 am
Comments Off on Where have they gone?
This has been pretty publicly beaten to death but I just thought I would throw my thoughts in on the whole Debian SSL key issue. This is crazy. How does this not get noticed for as long as it has been out (any keys generated between 09/06 and 05/08)? Which makes me wonder how many people already knew about this and were using it without the community at large being aware of the problem?
I hate to be the one to ask but is this caused by open source testing? Are people more forgiving of faults in Linux so they over look glaring defects? There doesn’t seem to be as much animosity as there would be if this were an issue in Windows. Maybe I am just more questioning now that I am running a macbook and every where I go mac folks are blaming everything but the macbook. “It isn’t your mac, it is that you want to run encryption. Just don’t use encryption.” Hello? McFly?
posted by holliday at 11:52 am
Comments Off on Old news is still news