Tuesday, July 7, 2009

[OT] Men are chickens**t.

If you walk into (any) Exclusive Books book store and go to the counter you will be confronted by a whole bunch of gifts.

There are bookmarks, pens, little torches etc. And there are little gift-books. Some are small, some are sentimental, some are silly but they are all intended to be gifts.

So, on the counter at the EB in Cresta shopping centre are two boxes that hold books. One is called "Don'ts For Husbands" with a blue cover and one is called "Don'ts For Wives" with a pink cover.

Now remember, these are by the gift books, not on the shelves where you'd go to browse and buy a book for yourself. So, the intention of these books is for a husband to buy for his wife and vice-versa.

All the "Don't For Husbands" were snapped up by wives and given. The "Don'ts For Wives" were still on the shelf. The one copy that was purchased was apparently buried with the husband the next day.

You've got to love married bliss.

(This whole article is true - except for the bit about the one copy of "Don'ts For Wives" missing.)



(The pic above is not such great quality but take my word for it - there are no copies in the left box and the box on the right is almost full.)

Thursday, June 25, 2009

[OT] Open Question to Nokia

So, I have a Nokia E71.

It is absolutely amazing. There is very little in the way of hardware that I can fault.

My wife has a Nokia too and its camera is so good that our regular camera is now collecting dust.

Bottom line - we love our Nokias.

But, Nokia fail on one aspect which I would hope that they can sort out.

According to this Vodacom page, a Blackberry subscription with Vodacom costs R60 and includes email, all on-device-browsing and most importantly - turn-by-turn navigation.

Nokia offer an email service which is "free for now". My browsing is pretty much covered by my contract and I try not to browse from my phone if I can help it.

But... navigation is R100 a month. That is truly mad. It is almost double the Blackberry deal and doesn't include the email, browsing, etc etc.

If Noka want to compete in the new cellphone world then they need to realise that there is more to a cellphone than just the device. There is a service now and Nokia need to make the price realistic. I wouldn't swap my Nokia for Blackberry any day but Nokia needs to come to the party and bring services that are not ridiculously priced.

So, Nokia, what can you do?

Monday, June 8, 2009

The most important security advice for home users!

[Make backups of your important information. Totally erase all devices with storage before you give them away]

So, because I manage Information Security for a large organization people ask me for advice on how to protect themselves.

The first thing I tell them (stuck record time) is to do backups.

The most important thing that home users can do is backup their information. That includes photographs.

Its like smokers - the people in a restaurant most likely to complain about smoke are the ex-smokers. The people who are most likely to make good backups are those that have lost information.

Except for the fact that my wife does scrapbooking, we would have precious few printed pictures of my younger daughter. They all reside digitally. If my wife's harddrive had to crash then we (potentially) would lose every photograph of our daughter ever taken.

The thing is that hard-drives are built like everything else - to fail. So, all your precious information (and every household has some) is sitting on a device built to fail. (Read that sentence again and again until you totally understand the implication.

Now, consider that most modern PCs have CD/DVD writers and the disks can be bought quite cheaply. What are you waiting for? Disaster?

Having said all of that, my SD card in my phone was corrupted. There was nothing really important on it (and what is important has been backed up) but I thought I'd try recover what I could from the device. I found a tool called PC inspector File Recovery. It is freeware and will analyse a drive and try to restore files which can be saved onto another drive. It is very easy to use and the price is right (free).

It managed to restore files that non-free software was not able to. I highly recommend this tool.

So, yes, it is possible to get files after a drive has crashed but it is not 100% and Murphy will come to the party by making all files restorable except the one you really want. Backup!

On the other hand, delete is not as permanent as it sounds. So, if you have private information on any device (including PCs, cellphones, USBs etc) assume that the information on them is readable by whoever you sell/give the device to when you are done with it. Another good free tool is Eraser .This tool will erase everything on the disk so it can't be undeleted.

One last thing on this topic. Some malicious software (eg viruses) puts fake file recovery software on your PC, encrypts files and tells you that the files are corrupted, asking you to buy the software so it can "repair" the files. Don't fall for this trick, you will just be making the cyber-criminals rich.

Tuesday, June 2, 2009

Quick Tought - The Pelzman Effect

I was reading about Ralph Nader on Wikipedia, and came across something called the Pelzman Effect.

This is something I see a lot and I spend a lot of time in my induction meetings trying to work against.

The Pelzman Effect (named after Sam Peltzman, a professor of Economics) is when you are aware of safety controls.

Knowing that you are fairly well protected, you take more risky behavior. This essentially makes all the controls less valuable, worthless or actually creates more risk than if the controls were not in place.

Two of these controls (Firewalls and Antivirus) are important but they do not cover 100% of all risk and users need to know that they must not assume total protection but need to take some of their own precautions.

Backups are even worse.. they are not magical but they are assumed to be.

Friday, May 29, 2009

ITWeb Security Summit - Day 1 Keynote Reflections

Bruce Whitfield did an excellent job of chairing the morning sessions. He managed to gather enough knowledge to challenge the speakers and get the audience involved in the round table. His question about the $1 trillion to Greg Day will go down in history. Craig Rosewarne asked Bruce the question that was on the tip of my tongue too. Bruce, as a Business Radio Presenter, has access to all of the top C level executives in South Africa and we wanted to know just how much they were concerned about Information Security. His feelings were "not so much" but he would follow this up on air.

Phil Zimmerman did punt his new product but leading on from that was an interesting talk about privacy. According to one of the delegates, South Africa is about to be flooded with video cameras all with the latest and greatest facial recognition systems. The government will use the "combating crime" and "stopping terrorism" excuses to do the roll out. While these are important in times of massive risk (such as the World Cup 2010), the equipment will stay. Phil is not from South Africa so he wasn't aware of the whole Mbeki, Zuma wiretapping tapdance but his talk largely was about how VOIP is less secure than normal phones but with encryption can be more secure.

Jeremiah Grossman
. Well.. a speech about how to hack free pizza.. what more can one say - amazing. I think the key takeaway from this speech is that technology is not everything. Hackers can use the technology in the correct way but exploit bad business plans. Jeremiah is very much at ease in front of a large audience and his speech is very polished and nice use of humor.

Greg Day made the fatal mistake of quoting the $1 trillion dollar figure for how big cybercrime is. This is maybe what his keynote will be remembered for. But. I think the key take-away from his speech is that trojans are so easy to compile and send out that signature anti-virus products are lagging. McAfee are trying to fix this by speeding up their signature system. They have also invested in an application white-listing product. Greg refered to this in passing but without going into details. I referred to the proliferation of trojans in my own speech, stating that the insider threat/ outsider threat is no longer up for debate. The point is that hackers are in your internal network. Its a given. Now, what are you going to do?

ITWeb Security Summit - Reflections (Part 1)

So,

The ITWeb Security Summit has come to a close and it was amazing.

Unfortunately, being stuck in South Africa, I really don't have anything to compare it to but I thoroughly enjoyed to conference and look forward already to next years' event.

I highly recommend it to all business people, security professionals and technical security people.

(I was involved in the conference as a speaker but, really, honestly, truly, I would say this even if I wasn't involved.)

The only major criticism I have (as a speaker and delegate) is that the Management breakaway sessions were held in the main conference room which meant that you had a smaller number of people spread out in a large area which was rather dark. This meant that the speakers of the management stream were quite separated from their audience.

And, to nitpick - the breakfasts were not great. However, the lunches were amazing and the coffee was great.

Generally, everything moved well. The audio-visual systems worked fine. The microphones worked very well and the clicky things (to move slides) worked.

Registration was a breeze and the venue was perfect. (Aside from the Midrand early morning traffic, yuck!)

The speakers were very interesting, especially the ones from overseas and it was a treat to be able to understand what is happening elsewhere in the world.

Well done ITWeb!

Friday, May 22, 2009

Happy Birthday Important Blog Post

I just realised that its been a year since I posted a blog post - Information-centric Security is Dead.

Ironically enough, next week I am presenting at a Security Summit on, well, Information-centric Security.

The article, I believe is one of my most important ones. Information-centric security is not really dead. But it is a stepping stone. Read my last blog post and the one linked above together and you will see what I believe is the most exciting and important development in our industry, probably since Firewalls.

If you aren't busy next week Tuesday then maybe come see me talk. It'll be fun, I'll make jokes. Promise.