Tuesday, June 19, 2007

"1 for the show... 2 for the money"


Yes, the title is right. And this is finally a post that is actually useful (as opposed to interesting and useful somewhere down the line, I hope).

If a friend of yours on MSN Messenger messages you to look at a site that looks something along the lines of messengerweb don't go. Or, go but know the risks.

The title - confusing as it may be reflects the change in attitudes of the "blackhat" or "hacker" community.

1 - it used to be for show - how many site can you hack in 24 hours?, how many machines can you bring down?, is Google invulnerable?
2 - now its for the money.

The site above is an excellent example of this. It is packed full of Google adverts. So each time someone visits the site the owner gets a (very) small amount of money. The way to make that into a big amount is to get a large amount of people to visit.

There is the way I do it which is try to make good content and hope that people find it useful but there is another way - the way that site does it.

The site offers a dubious service to the people that log into it. You need to log in with your MSN credentials (which also happen to be your MSN passport and hotmail password). The site does some checking in its database for you (thats the service) and (this is the genius bit) uses the recently acquired MSN username and password to send a message (as you) to all of your contacts telling them about this "really cool" site and so the networking effect goes on until a lot of visits happen and the site owner makes a load of cash.

You have to accept the terms and conditions before connecting where it is spelled out in no uncertain terms what the site will do.

I got "fake announcements" from a number of technical people who had obviously
not only visited the site but also entered in their usernames and passwords.

To the general public: don't give up your password ever! Even when asked to on websites. The MSN password is for MSN only - not for other websites like messengerweb. Ask yourself before you enter any information onto a site - how much do I trust this site? Rather close the window if you are not sure

To security people: it looks like we have failed again if people are so keen and eager to just give away their passwords. We have to focus on the principals - "Don't share your password! Know where to use them and where not to" and not the modus operandi - "watch out for emails asking for your password or directing you to a bank website" because the principals don't change but the modus operandi do.

Technorati

I have joined Technorati. They need me to do a silly post to prove I own this blog. So here goes. You can safely ignore this post. Technorati Profile

A tale of two CEOs..

A while back I went to a lecture that opened my eyes and inspired me. It is what I look back on when times are dark and enables me to think "Information Security is possible".

The talk was started by the CEO of a large financial institution which is also heavily involved in the medical industry. Alarm bells should be ringing... because the information they have floating around their network is so private - its scary.

The CEO of the company started the talk and told us how secure they are now and how they are working on getting more secure and more to the point - how come he knows.

It seems it wasn't always that way but they are working on getting more secure. They started with a framework, defined goals, worked out a plan and ways to measure their security posture.

And it is something they are very proud of. In fact, that the CEO can talk security already is something special. That he is aware at any one time how secure he is, is more special. Well done to them.

I also had a chance to talk to someone from their competition. I mentioned this inspiring talk and asked this person how secure they are - he told me about firewalls, VPNs and that they had a "full PKI installation with non-repudiation" but gave me no measurables - just product talk. In short, he doesn't know.

There are (apparently) 2 companies in South Africa that are fully ISO27001 certified. I'm not sure what these are but 2 is a very small number. Hopefully, companies will wake up to the realities and as South Africa does more business with overseas companies, hopefully information security will become a selling point.

Monday, June 18, 2007

Elucidate


This is not promotion for my business. Maybe if "blogging" (and other cool web 2.0 technologies)
had been so popular three years ago then my business would have survived.

No, it is much more important than that.

When I was trying to pick out a name for my (then) consulting business I literally picked up a dictionary and tried to find a cool name that had not been used. I also wanted to stay away from things that had strange placements of lowercase letters like "e" (e-security) and "i" (iSecureU) and "x" (x-pert consulting). I ended up with "elucidate" which is a lovely word that flows off the tongue.

When I gave up my business due to more pressing issues and rejoined the workforce as a normal lemming, I kept the term close to my heart.

Most of my time is spent on the cutting edge, I definitely don't "take up too much space" as the phrase goes. Hence, my time is spent in areas where I don't (yet) have a clue what I am doing but neither does the rest of the world. I like it here, its not too crowded and its interesting; like climbing up a steep cliff wall with no rope is "interesting".

A better analogy is probably: my work life is like doing a puzzle without the box lid to help, with pieces that all fit together (even incorrectly) and some that don't even belong. Sometimes I'll find a few that just have to work together and I have a sense of enlightenment. I can then pass this on to others without them having to do the hard work.

Its a good feeling.

It is a total sense of clarity - lucid.

I should have probably posted this blog entry first because it gives the clearest insight into myself and what I strive for and how I do it.

Now, go back and read all my blog entries all over again. ;)

Thursday, June 14, 2007

Information security done wrong can kill!

...really.

This morning I took a look at an article in the New York Times about the Virginia Tech Report.

This report was requested by the American President after Seung Hui Cho shot 27 students and 5 faculty members to death at Virginia Tech’s Blacksburg campus on April 16.

His mental health was shown to be questionable and he had been ordered by a Judge to undergo a psychiatric evaluation. But due to privacy restrictions when he applied for a weapon there was no record of this and he was legally able to acquire one.

When I say "privacy restrictions" I actually mean "assumed privacy restrictions". According to the report (and as stated in an article on examiner.com) schools, doctors and police often do not share information about potentially dangerous students because they can't figure out complicated and overlapping privacy laws.

So, they would rather "fail safe" as such and not release any information. Even though, in this case it would have saved lives.

Rule number one when dealing with people who are trusted with information - they need to know what they can and can't do with it and rules have to be crystal clear.

Kudos to the American government for seeing the problem and reacting to it by proposing a Federal bill.

Tuesday, June 12, 2007

And Now for Some Bible Education (Part 3)

Finally, just a word of thanks to Jewishanswers.org who put me in contact with Rabbi Seinfeld (yes, really) who helped me find the information I needed for these posts.

A rabbi with a blog sounds like the start of a jewish joke but his blog is interesting and I have bookmarked it.

The actual article I used for my blog is here. And is from commentary on Exodus 18.

And Now for Some Bible Education (Part 2)

So.. how does that affect us?

I find in some cases it makes sense to take a hard line on something and not compromise. Sometimes you also just know the answer. You can't really be certain of your security posture if you have 20% of all passwords being "password", sometimes you have to compromise a bit - you have to allow some traffic through your firewall.

I like to think that I am more of an Aaron person - I find it easier to analyse, debate and discuss than research and enforce. Which makes me a pretty good Information Security consultant. I have different people, with different agendas all coming at me and I need to find a balance.

I fully expect those people to have the agendas that they do and while things can get heated when someone doesn't understand why I can't fully agree with them, I actually prefer them to have strong ideas. That way I can make a good decision.

Every InfoSec consultant will be stuck in the middle of a few factors, the CSO who wants everything perfectly secured (pull out the Internet cable and lock the doors), the CIO who wants everything up and running and the CEO who doesn't care as long as business gets done. You also have 1,000,001 vendors who all think that their product is perfect and does everything. You have the law makers who want to push laws that protect everyone. You have your wife and kids who want you at home all the time (or at least every night and weekend). Another example is ISACA who believe everything can be solved through risk analysis.

And the sad truth is that you can't make all of these people happy. You have to compromise.

Each of these people is a "moses" - they know their point exactly. They see the world in black and white. A technical salesperson (assuming they are trustworthy and their product is reasonably competent) will know all the good about his/her product. They know all the bad it can eradicate and the risks it can mitigate. They may know about competitors products and how choices were made - some companies decided to use agents, some use no agents. They will stand by their products. They will not budge and so they shouldn't.

I do have a bit of bias and where I can I push Open Source software but I am aware that it doesn't work for everything and that is where I take my Moses cap off and put on an Aaron cap. I know how good Check Point's firewall software is but when it comes time to do NAC I need to judge fairly.

Speaking of Open Source software - the community is made up of people who are Moses-types and Aaron types. Richard Stallman is very much a moses type. Linus Torlvalds is more of an Aaron-type when it comes to license issues but more of a Moses-type when it comes to some aspects of kernel programming.

They are both successful because they have managed to be the kinds of personality they need to be when they need to be that kind.