In what will most likely be my last posting for 2008, here is a bit of advice for all.
I read somewhere that news is never really all that useful. Its interesting. But its not useful. The stuff that you need to know about to go about your daily life is not going to make news.
To get some more perspective on this, I highly recommend that you visit The Onion online newspaper and browse a bit especially at the "Area" reports. (It is humour and is intended for 18+)
One of the interesting news stories of 2008 that I can think of the Dan Kamisky DNS issue that made headlines for all sorts of reasons. DLP made headlines. TJX made headlines.
What is more interesting is what didn't.
Here are some bits of news that you won't see:
"Company patches all servers"
"Awareness given at Company. Stronger passwords result"
"Good user management led to less options for Hackers"
"Antivirus updated led to viruses being blocked"
What did made the headlines today (thanks to Amrit and Dominic for alerting me to this... everyone will be talking about it soon) is the attack on MD5 certificates that makes trusting Web Certificates less of a good idea. The information is here, but this is a big deal so expect this to make the news.
The thing is, that this yields big rewards for the hackers but is also a lot of work. Social engineering methods such as bogus email, phishing, fake antivirus etc are so much easier to do and have big enough rewards as it is. So too do worms and the like that attack old vulnerabilities that should already be patched.
My though for the year is thus:
Hackers are mostly successful by exploiting the boring holes and really do not have to work hard at all. By using tools that are already available such as Firewalls, IPS, Antivirus and doing the boring bits such as choosing strong passwords, updating patches, updating antivirus patterns and being aware at what mails we should not open - we win 90% of the battle already.
I think next year will be very very interesting for us. I hope everyone reading this has a great 2009!
Showing posts with label 2008. Show all posts
Showing posts with label 2008. Show all posts
Wednesday, December 31, 2008
Friday, February 1, 2008
Prediction 3 - A major site gets hacked
I'm not so sure about this one and I have been thinking about it for too long. If I take much longer my predictions will be very accurate because it will be December and I'll have hindsight.
Online service providers (yahoo, gmail (google), hotmail (microsoft)) seem to take their security really seriously and that is great. I think that they are targets but they are aware of this and they realise that an attack could render them dead. Their business is all about trust and a loss of trust would break their business.
However, the web was never designed to be so secure and application based. It is meant to be static pages delivered non sequentially (images load up when they can). This is not a very good base to have for a service.
I see that the hackers are already playing with session keys and such. My prediction is that this year or in the foreseeable future malware (all kinds including bots) will try suck session keys from traffic and use them to steal information or do unauthorised actions on "behalf" of a user. This has happened in the past but I believe that it will become more widespread, targetted and automated.
Example possible attack scenario: "Bob logs onto Gmail from an infected PC. He logs into his account on gmail waking and wakes up the malware which either forwards the session key to the attacker or drafts an email to the attacker from Bob with a list of all his contacts. Attacker sells these good emails to spammer. Or malware downloads a preconfigured spam message and sends the message to all of Bob's contacts. All of this happens in a scripting environment and Bob is not aware of anything strange because windows don't pop up."
If this is happening already then I applogise for coming to the prediction party late.. and I'll just predict that it will increase until http is replaced with something else, new online standards are developed for services or it becomes as bad as spam is today.
Online service providers (yahoo, gmail (google), hotmail (microsoft)) seem to take their security really seriously and that is great. I think that they are targets but they are aware of this and they realise that an attack could render them dead. Their business is all about trust and a loss of trust would break their business.
However, the web was never designed to be so secure and application based. It is meant to be static pages delivered non sequentially (images load up when they can). This is not a very good base to have for a service.
I see that the hackers are already playing with session keys and such. My prediction is that this year or in the foreseeable future malware (all kinds including bots) will try suck session keys from traffic and use them to steal information or do unauthorised actions on "behalf" of a user. This has happened in the past but I believe that it will become more widespread, targetted and automated.
Example possible attack scenario: "Bob logs onto Gmail from an infected PC. He logs into his account on gmail waking and wakes up the malware which either forwards the session key to the attacker or drafts an email to the attacker from Bob with a list of all his contacts. Attacker sells these good emails to spammer. Or malware downloads a preconfigured spam message and sends the message to all of Bob's contacts. All of this happens in a scripting environment and Bob is not aware of anything strange because windows don't pop up."
If this is happening already then I applogise for coming to the prediction party late.. and I'll just predict that it will increase until http is replaced with something else, new online standards are developed for services or it becomes as bad as spam is today.
Friday, January 25, 2008
Prediction 2 for 2008 - Stealth "Hackers"
Wow.. that sounds like a good name for a movie "Coming to the big screen in 2008 - Stealth Hackers!"
This isn't really a new thing. Hackers as we know them (and I use the word hacker in the evyl-skript-kiddie-with-toyz way and not the kind-open-source-guru way) are slowly moving toward the idea that "cool, we can make good money from this!"
In the past hacking was really done for the cool stories hackers could tell their friends to get street cred. Events were big and done for the headlines. Hacking was like graffiti - it was out in the open and done so people could see. Hackers didn't want to get caught but they did want their work to get noticed.
I believe that these people are still out there and still trying to do big things. I think that their work is also being converted over to the new types of hackers.
The stealth hackers are not necessarily very computer literate. They take the research and exploits of the big-bang hackers and craft it into tools like malware, root kits etc. They don't want to get caught, obviously, but they don't want to be noticed either. These are the botmasters who want to use the world' s computers to gather information that they shouldn't have. They also want to use computers to send spam and the longer they can stay undetected, the more money they can get.
There are different levels of technical ability in the realm of the stealth hackers from those that write exploits to those that deploy bots to those that sell information and those that just buy credit card numbers.
I believe that both groups - traditional hackers and stealth hackers will grow in numbers but that stealth hackers will grow much quicker.
This isn't really a new thing. Hackers as we know them (and I use the word hacker in the evyl-skript-kiddie-with-toyz way and not the kind-open-source-guru way) are slowly moving toward the idea that "cool, we can make good money from this!"
In the past hacking was really done for the cool stories hackers could tell their friends to get street cred. Events were big and done for the headlines. Hacking was like graffiti - it was out in the open and done so people could see. Hackers didn't want to get caught but they did want their work to get noticed.
I believe that these people are still out there and still trying to do big things. I think that their work is also being converted over to the new types of hackers.
The stealth hackers are not necessarily very computer literate. They take the research and exploits of the big-bang hackers and craft it into tools like malware, root kits etc. They don't want to get caught, obviously, but they don't want to be noticed either. These are the botmasters who want to use the world' s computers to gather information that they shouldn't have. They also want to use computers to send spam and the longer they can stay undetected, the more money they can get.
There are different levels of technical ability in the realm of the stealth hackers from those that write exploits to those that deploy bots to those that sell information and those that just buy credit card numbers.
I believe that both groups - traditional hackers and stealth hackers will grow in numbers but that stealth hackers will grow much quicker.
Wednesday, January 23, 2008
Prediction 1 for 2008 - Facebook hacked
Ok, finally, here it is.
For the impatient - Facebook will be hacked. Alternatively, a major Facebook application will be hacked.
Right...the impatient can go now. The rest - read on.
[Personal note first]
I decided that my Blog was becoming too important. I have a host of blog posts that are just not quite as well written as I'd like and since my blog is somewhat a reflection of my writing skill (skillz?) I decided that I'd need to fix them up, when I have time.. well, I've changed my mind - my blog is now an indication of my thinking skills as it was always intended to be, hence the name. It is an indication of my quick writing skill and how I write under time constraints. So, ignore the strange terms, spelling and grammer. Read the content.
This is also the reason why I don't have a "my top 10 predictions for 2008". There is no list that I am working from - as I think them up, I wil blog about them.
[end personal note]
Last year when Facebook made their application language available I was very excited and signed up as an "application developer". I even wrote an application which is about the level of complexity of a "hello world" program. I think it is a box that greets the Facebook-er by name. Woopy-doo.
But what I found quite interesting is that the application runs on my server and my database but queries information from Facebook. This makes creating applications so much easier and is probably what led to the Facebook explosion in the first place. However, users may not be aware that every time they add an application they are increasing the risk that their Facebook information can be compromised.
I like to believe that Facebook is big enough to be able to throw money at security. I think that their product is simple enough to secure. So, there should not be too much opportunity to hack into Facebook. I could be wrong. Facebook certainly is a huge target for both those hackers who want to make some good money, those that want email addresses (to spam) and those that want to make a big bang and a name for themselves.
But my money is on a large Facebook application being hacked - its a way to get in through the back door.
For the impatient - Facebook will be hacked. Alternatively, a major Facebook application will be hacked.
Right...the impatient can go now. The rest - read on.
[Personal note first]
I decided that my Blog was becoming too important. I have a host of blog posts that are just not quite as well written as I'd like and since my blog is somewhat a reflection of my writing skill (skillz?) I decided that I'd need to fix them up, when I have time.. well, I've changed my mind - my blog is now an indication of my thinking skills as it was always intended to be, hence the name. It is an indication of my quick writing skill and how I write under time constraints. So, ignore the strange terms, spelling and grammer. Read the content.
This is also the reason why I don't have a "my top 10 predictions for 2008". There is no list that I am working from - as I think them up, I wil blog about them.
[end personal note]
Last year when Facebook made their application language available I was very excited and signed up as an "application developer". I even wrote an application which is about the level of complexity of a "hello world" program. I think it is a box that greets the Facebook-er by name. Woopy-doo.
But what I found quite interesting is that the application runs on my server and my database but queries information from Facebook. This makes creating applications so much easier and is probably what led to the Facebook explosion in the first place. However, users may not be aware that every time they add an application they are increasing the risk that their Facebook information can be compromised.
I like to believe that Facebook is big enough to be able to throw money at security. I think that their product is simple enough to secure. So, there should not be too much opportunity to hack into Facebook. I could be wrong. Facebook certainly is a huge target for both those hackers who want to make some good money, those that want email addresses (to spam) and those that want to make a big bang and a name for themselves.
But my money is on a large Facebook application being hacked - its a way to get in through the back door.
Thursday, January 17, 2008
2007
I have been trying to get the motivation together to blog about my predictions for 2008 but I'm not finding it. So, I've decided to break it up into smaller pieces and hopefully that will make it easier.
So, looking back...
2007 started with me being very motivated, excited and happy. It was going to be a great year with lots of promise. It ended with me feeling very down, de-motivated and depressed. But I am still optimistic for 2008 which either means I am hard to get down or just really naive. I guess time will tell.
My first prediction for 2008 is that I will be a very different person by this time next year. And I will be sitting in a very different place. If I am not - I will have failed.
I don't like to get too much into the personal aspects of my job but a lot of the energy I put into getting security to move forward has been in vain and I am feeling that I am now wasting my time trying to move forward. I have put myself into "cruise" mode while I work behind the scenes to improve myself and then with a big bang I'll be back.
There were some some really excellent moments in 2007. I think that the most important was when I started my blog. I highly recommend blogger. I also recommend feedburner. Both companies are owned by the big G.
A big thank you goes out to Alan from Still Secure who got me motivated and introduced me to the Security Bloggers Network.
While it helps that I am a member of the network and that drives some views to my blog, it has helped me more to explore and find people on the network. I have been able to populate my RSS feed list from a number of bloggers and I hope to add more. I just need the time.
So, who is honoured to be in my RSS feed?
First up is my brother-from-another-mother - Andy the IT guy. I call him that because he has a very similar job, a wife and two daughters and he has had a very similar career path to me. More importantly, I usually see eye-to-eye with him.
Next up is "Security Mike" - Mike Rothman. The daily incite is an amazing tool to get an idea of what is happening in the security blog world. How Mike can read so much still amazes me. One day I'll have saved up enough. The new Audio is also worthwhile.
Next is (this is the order I read my blogs in - obviously I'd want to get the best first) the Mogull. One can see from his postings just how much research he has done into the security field. They are well written and very useful.
Just as wordy and usually more fun is the Hoff. The Hoff is worth reading because of how he pushes the boundaries of what security (or survivability) is all about. He does not pull his punches and is not afraid to sacrifice a few sacred cows along the way.
There are other bloggers that I respect and read too - Anton Chuvakin, Randy Armknecht, Richard Bejtlich, etc etc
I think that the best part of reading all of the above blogs is that the authors all read each others blogs too. This leads to debates, arguments but hopefully lessons learned.
2007 was also the year that I learned about the Security Catalyst Forums where more debate happens. This just proves how new our industry is and how much passion is being put into finding out the answers. This can only be a good thing.
Locally I've kept up with my visits to ISG Africa which has great presentations every month.
I completed almost 100 blog entries over the year, putting into word my thoughts about our exciting industry. My "70s" entries show where we went wrong in the 80s with our IT plans and how we are putting things right again. My 7 habits show how popular business and life philosophies can be used in InfoSec to move us in the right direction. I will hopefully finish those off shortly. (Prediction 2?)
Thank you everyone who has shared their views and hard work with me via their blogs and forums and I hope all that read this blog have learned something and will continue to follow my progress and read my thoughts.
Soon I will post my predictions for 2008.
So, looking back...
2007 started with me being very motivated, excited and happy. It was going to be a great year with lots of promise. It ended with me feeling very down, de-motivated and depressed. But I am still optimistic for 2008 which either means I am hard to get down or just really naive. I guess time will tell.
My first prediction for 2008 is that I will be a very different person by this time next year. And I will be sitting in a very different place. If I am not - I will have failed.
I don't like to get too much into the personal aspects of my job but a lot of the energy I put into getting security to move forward has been in vain and I am feeling that I am now wasting my time trying to move forward. I have put myself into "cruise" mode while I work behind the scenes to improve myself and then with a big bang I'll be back.
There were some some really excellent moments in 2007. I think that the most important was when I started my blog. I highly recommend blogger. I also recommend feedburner. Both companies are owned by the big G.
A big thank you goes out to Alan from Still Secure who got me motivated and introduced me to the Security Bloggers Network.
While it helps that I am a member of the network and that drives some views to my blog, it has helped me more to explore and find people on the network. I have been able to populate my RSS feed list from a number of bloggers and I hope to add more. I just need the time.
So, who is honoured to be in my RSS feed?
First up is my brother-from-another-mother - Andy the IT guy. I call him that because he has a very similar job, a wife and two daughters and he has had a very similar career path to me. More importantly, I usually see eye-to-eye with him.
Next up is "Security Mike" - Mike Rothman. The daily incite is an amazing tool to get an idea of what is happening in the security blog world. How Mike can read so much still amazes me. One day I'll have saved up enough. The new Audio is also worthwhile.
Next is (this is the order I read my blogs in - obviously I'd want to get the best first) the Mogull. One can see from his postings just how much research he has done into the security field. They are well written and very useful.
Just as wordy and usually more fun is the Hoff. The Hoff is worth reading because of how he pushes the boundaries of what security (or survivability) is all about. He does not pull his punches and is not afraid to sacrifice a few sacred cows along the way.
There are other bloggers that I respect and read too - Anton Chuvakin, Randy Armknecht, Richard Bejtlich, etc etc
I think that the best part of reading all of the above blogs is that the authors all read each others blogs too. This leads to debates, arguments but hopefully lessons learned.
2007 was also the year that I learned about the Security Catalyst Forums where more debate happens. This just proves how new our industry is and how much passion is being put into finding out the answers. This can only be a good thing.
Locally I've kept up with my visits to ISG Africa which has great presentations every month.
I completed almost 100 blog entries over the year, putting into word my thoughts about our exciting industry. My "70s" entries show where we went wrong in the 80s with our IT plans and how we are putting things right again. My 7 habits show how popular business and life philosophies can be used in InfoSec to move us in the right direction. I will hopefully finish those off shortly. (Prediction 2?)
Thank you everyone who has shared their views and hard work with me via their blogs and forums and I hope all that read this blog have learned something and will continue to follow my progress and read my thoughts.
Soon I will post my predictions for 2008.
Subscribe to:
Posts (Atom)