Tuesday, April 24, 2012

Why the Privacy Bill is important to you!

[Almost every country in the world protects its citizens' person information. Almost.]


This is an example of a Membership Application form that I needed to fill in to be able to rent a video. You'll notice that besides all the usual stuff, they have asked for my date of birth, ID number, employer. They need to know my next of kin which is interesting.. in case I die while hiring a video, at least they can get their video back. Not sure what it helps having my car registration number. I can just picture driving through a roadblock - "Mr Baranov... do you realise that your copy of Twilight is overdue by two days. For that I will give you a fine. Further, for even renting that video.. another fine."

The point is that there is a lot on this page that is unnecessary. Under the proposed Privacy Act, a company would have to be able to answer why each and every field is required for each and every form. Further, they would need to make sure that they protect your information to a reasonable amount of care. Further they would need to notify you if they suspect that your information is leaked. They would also have to contact you if they need more information or need to use the information for other purposes. And they would not be able to share this information with other companies. 

Right now there is no legislation making it illegal for companies to share information (excluding credit information). This video shop could (I'm not saying they would) easily share all this gathered information with anyone they wanted and could even sell this information. Most people ignore spam sent to "Dear Sir" or such but spam made using this information could be sent to you and addressed "Dear Mr .....". 

Also, since the company doesn't have to do any protection of information and doesn't need to notify anyone of a breach - this increases the risk of your information leaking. So lets look at two cases...

The information leaks and someone wants to infect your PC so they can use it to send spam or to use it to steal your money using something like Zeus... they send you an email addressed to you specifically looking as though they are from a garage. Since they know where you live, they can customise the email to be a garage in your area. They could also make it specify your registration number.... "Mr Baranov, I am from <Big Name Garage> in Blahblahville. Your car registration number EGG156GP was recently at our garage.....please look at this bill in pdf format". At this point you are either surprised or cross ("I never took my car to that garage!") Either way, you open the attached pdf to get more information and your PC is infected. You know not to open attachments from places you don't know but these people seem to know so much about you...

Alternatively, the thieves use the ID number to create a fake ID book. They use the employer information to create fake pay cheques and take out credit in your name. They have enough information above including your telephone numbers, address and even friends of yours. Even if the company granting the loan phones the company you work for, they would confirm employment ... "Yes, Allen works here"

I'm not picking on this particular video rental company (hence the company name covered) because all companies from big to small collect more information than they need and don't necessarily protect it to the best of their abilities and without laws in place they won't because protecting customer information is difficult and costly and breach notification is embarrassing for a company.

Almost all countries in the world have laws protecting their citizens and their information. South Africa has one of the best based on bits taken from the best Privacy legislation from around the world. It is currently in Bill form so it is not yet approved and is not binding as a law. Anyone who is concerned about their personal information, is sick of spam and nervous about hackers taking over their bank accounts should want this law to be passed as soon as possible. 

The privacy bill is important to you!

Friday, March 9, 2012

The Meaning of Life Part 1 - The Firewall

[Your Firewall does nothing...yet]

This is the third time I am writing this blog post because I just couldn't seem to get the thought straight and the tone and level right. My first two attempts took a whole bunch of text to say this:

Basically Firewalls came before NAT. NAT is a magic network concept that creates a type of one-way-mirror allowing devices on the inside of the firewall to establish a two way communication session without the other side knowing exactly what device is making the connection and devices outside the firewall can't establish a connection to devices inside the firewall.

(The above paragraph is not totally correct but it is correct enough and stops me having to type a whole networking 101 essay which is besides the point of this post. If you know better exactly what NAT is about then smile smugly, if you don't accept that the above is "correct enough". Either way - read on.)

NAT is so effective that almost half (wild estimate) of hackers' tools and time and thoughts revolve around getting past NAT- the only effective way being to get the inside device to "dial-out". (Think of the protection that NAT affords us as being a door that opens only from the inside and hackers concentrate on getting someone inside the door to open it.)

So, while Firewall rules and policies are weird and wonderful little twisty adventures, NAT pretty much makes them redundant.

And Firewall engineers know this (although may not admit as such). So, then, what is the point of this article?

IPv6 is coming and with it the loss of NAT. We won't need it any more. And we won't want it.

This is my opinion and the network security and general network engineers disagree with me. They argue that NAT is so useful that we will have it around for many years even once IPv6 becomes the norm. Either we will stick with IPv4 private networks inside and IPv6 networks outside or we will have IPv6 networks inside that will remain private.

I have three arguments against this and time will tell whether I am right or wrong.

1. The number of devices will explode. We are well on the way to this already but I think it will accelerate. We have the hardware, we have the software. We just need it all to become easy. So, look around you and imagine what would not benefit from being connected (ignoring security for the moment). Your car keys could beep when you SMS them - what a lifesaver. Your desk could sense when you are behind it. Your chair could auto adjust depending on who was sitting on it. Your desk calendar could be digital. The lighting above you could notify you when the light bulbs are due to run out. They could turn on and off depending on whether someone was in the room. Your desk phone would have an IP address and not a telephone number. That is a lot of IP addresses, now times it by the number of people in a site, then by the number of sites in the company etc. It is starting to add up to a lot of IPs especially since companies are already struggling to allocate IP addresses just for the devices we have now. A company with 2000 employees and each one has 30 devices needing IP addresses would be testing the limits of IPv4.

2. "We are an X shop" is a joke. Most companies stick by the "we are a Microsoft shop" and so only allow Microsoft products. That is, until the CEO wants an iPad. A month after the iPad was released Gartner did a quick poll and three quarters of the CEOs asked had company issued Ipads. How did the companies manage to roll out a proper policy in time, how did they do governance? How did iPads become a strategic tool? It didn't. The CEO asked and the CEO got. Then upper management, upper-middle management, etc. All of a sudden the iPad was a business tool. IPv6 devices that are connected will be so unbelievably cool in ways we can't even imagine now. They will be the cutting edge and they will make your CEO and all your staff so cool. And because they are connected, they will make them cool to their peers. And the ones that are portable - like the keys you can SMS will work without a problem at the CEOs home but not on your antiquated IPv4 network. Guess what will happen then.

3. Management of IPs on an IP by IP basis will become difficult to impossible. So, where does this leave the network guys?  How do you manage 30 devices per person? Should you even? Should these devices talk out of the network? What is allowed on the network? What is not? What should talk to what?

So, what does this mean for the Firewall? Well, I don't know. Already with NAT there are Firewalls that have way too many rules. They have rules that are never used, and those that are too big for their purpose. There are rules that are just plain dumb and ones that are highly critical to the business but no one knows how they were made or why just that closing them would stop business. What happens when everyone in a company has over 30 personal IP devices, some that are on a public network and some that are not, some that talk out, some that are talked to, some that talk amongst each other, some that dial out, some that are expecting connections from others, some that will be for safety reasons (think firefighting equipment that checks pressure on a minute-by-minute basis and phones home with the results), some that will be in use by the coolest people in the organisation (the marketing guys with thick black rimmed glasses), some that will be used by your CEO (and when they stop working, you get notified via the CIO who is pissed off that his boss is unhappy) and most that have some blatantly stupid vulnerability that script kiddies are constantly polling for. Oh, and lastly, this will all happen on port 80 by the way.

Mr Firewall, it is time for you to step up. IPv6 will set some challenges for you.

[PS. While writing this article I was wondering if it would not be a plan to actually scrap internal networks altogether and go for a "GPRS-type" network where everything is all in the open anyhow. How one would protect against vulnerabilities on the devices, I'm not quite sure. Also, you'd need to block your servers off from the open network... or they may be "in the cloud" already. Maybe every one of these devices would need its own little firewall. Discuss.]

Information Security Analyst Available.

[Hire Me... Please.]

I am currently searching for a job so if any of my dedicated readers know of anything...please let me know.

I have about 10 years of experience in Information Security and am currently an Information Security Analyst for The South African Breweries Ltd. I have built up a wealth of technical knowledge but my most recent experience is in management which means getting vendors to put security controls in place, risk assessments, awareness, security architecture, policies and related documentation, etc.

I am well known in the security community in South Africa for my passion about Information Security and willingness to talk at length about the topic.

I am looking for something along the lines of "Security Analyst", "Security Manager", "Security Architect" as I feel my skills would be quite appropriate for these or similar job titles.

My preference would be to stay in Johannesburg or Pretoria but I would be happy to consider anything in South Africa or even overseas.

I don't want to bore you with all my details but anyone who is interested or may know of someone interested, please can you email me at: baranov <at> elucidate <dot> co <dot> za and I will forward you my full CV and supporting documentation.

PS. Any job that would require "out of the box" thinking would be very highly considered. My favourite project was an awareness project that I did covering the topic "phishing" which I am particularly proud of and would elaborate on but I have to save something for the interview...

Tuesday, November 22, 2011

Google's Next Big Thing

[A company owned by geeks - its obvious what is next: KITT]

I think, after spending quite a while putting all the information I have together and filling in the blanks what Google's next big aim is.

So, from what I can tell the original founding members of Google - Larry Page and Sergey Brin put this list together as things to do with their lives:

  1. Get rich, famous, powerful
  2. Take over the world
  3. Create a car as cool as KITT

I figure the above is any geek's list. It certainly would be my list. So, having completed points 1,2,3,4 already it is time to work on point 5.

So, sub-points for this are –

  1. It must talk
  2. It must take orders
  3. It must drive itself
  4. It must come when I talk to my watch
  5. It must be bulletproof
  6. Turboboost!


So, point 5 has been done so let’s see about the other points:

Point 1 and 2 are done by Android already but Apple has taken it to the next level. I guess Google will take it even further. Naturally you’d need an android device embedded into the car. Guess who owns android technology? Google. The first commercial car radio was made by Motorola Mobility – Google owns them. But watch Motorola Mobility for a talking “box” that can also listen, chat and take orders. (So, I’ll check off points 1 and 2...)

Point 3 has been done by Google – and is on the way to be legal in Nevada (thanks to Google). Check off point 3.

Finally… a smart watch –  check. It needs to be able to talk to the car – check. It needs to be able to pinpoint your position – check. (Actually, not sure if these have GPS but it is not unreasonable to expect that they do or will have soon). It also needs to be able to relay orders again – check.

So, put all this technology together and you have the ability to call your car via your watch and ask it to come to you and it will – all by itself. 

The technology is all done… it is just a matter of putting it together. Take the car and make it bulletproof. Put run-flat tyres on it. (And cool black paint. And a funky red LED on the front.)

Now all the Google guys have to do is perfect Turbo-boost. And get Hoff-worthy hairy chests.

I wonder if Google will go into making helicopters that can fly faster than sound…? Maybe that’s next on their list.

Monday, October 24, 2011

A great loss to the IT world. One of its great inventors dies.


[Dennis Ritchie died at the age of 70.]

He was one of the most influential computer engineers ever. I could go into details as to what he did but lets look only at how his work contributed to Steve Jobs becoming a household name.

Ritchie created the C programming language and with Ken Thompson, Ritchie created the Unix Operating System.

With out Unix, Jobs would not have had a basis for his NeXT language which Apple bought bringing Jobs back into Apple and ultimately back into the CEO position.

Without Unix, Pixar would never have had Linux (derived from Unix) to do massive and cheap rendering. This means there would have been no Toy Story and all the movies that followed and no buy out from Disney.

Without Unix there would have been no base OS for iOS so no Operating System for the iMac, iPod, iPhone and iPad.

C on the other hand is the base of almost every modern programming language from C (itself) to C++ to perl to java etc etc. No Java means no apps for the idevices. It also means no cross platform applications like itunes and no way to get Office to be on both Windows and iOS without having to write the entire program to work on each. Even worse - if programs like Office were written in Assembly (as was the norm before C) then you would have to get a totally new copy of the software for every device even if you upgraded your PC from one processor to another.

To be fair if Ritchie had not created Unix or C, someone would have probably jumped in and created something similar. Or one of the languages and operating systems around in the 70s may have been more successful and changed the world we live in like Unix has but this isn't the case. Ritchie's contributions to the world have radically changed it and we will miss the inventor of these tools. It may be that Jobs was tasked with making some genious idevices up in Heaven and he called up the one guy he needed to help him more than anyone else. A heaven without Unix.... doesn't make sense.

Ps. on the other hand... Jobs's biggest competition Android would also not have been possible without Linux (based on Unix) and Java (based on C).

Wednesday, July 27, 2011

What are your rights regarding personal email? [Extra Bit]

[Are Facebook Saints?]

Just adding an extra point to my recent Blog post.

The question I posed in my last post about email sharing was triggered by Facebook stating that it is wrong for a person to mass move private details such as email addresses and telephone number etc to a new service provider without the person knowing. It is an interesting (and perhaps valid) argument which covers up what they would rather say which is "please don't move your Facebook contacts to our competition and set up an ecosystem (there must be a better word) there."

The point is that Facebook, through its partnership with Skype is forcing its users to do just what it is telling them they should not do with Google Plus.

I haven't used the Skype functionality in Facebook as yet so I'm not sure exactly how it works but from what I've read, once you use it once to chat through voice or video to a contact, it creates them as a contact in Skype. Essentially, by you chatting to someone over Facebook Video, you are creating a link to someone in Skype where one didn't exist before.

This really is very similar to what Facebook is arguing you shouldn't do by using automated ways of exporting Facebook contacts to create contacts in Google Plus.

Facebook is a business so one shouldn't be surprised when they choose profit over strange ethics but then expecting their users to abide by these ethics is a bit hypocritical.

Thursday, July 7, 2011

What are your rights regarding personal email?

[I'm not talking legally...just ethically]

So, someone gives you their business card with all their details. Can you load it on Outlook to make it easier for you to contact them. Can you add them to you phonebook on your phone? What if your phone gets stolen? Can you give it to a colleague? What if the colleague has some work for the person? What if the colleague is an annoying git? Can you give it to a salesperson who is selling selling something you think the person would want? Can you give it to a salesperson just to get them off your back?

Taking things further... Facebook argues that you do not have the right to take your 'friend's details off their network and use it on another network. Obviously Facebook have a vested interest in you not being able to move information off their network and tying you down but do they have a point?

Of course, they've never had an issue before with apps sharing users' details and downloading friends' information.

But this is not to judge Facebook on their new awareness of privacy, it is to ask the question. Should someone be confident to move your personal information including you email address to any system that they want to? Or should they ask first? Or should they just not do it at all?

Discuss. :)