Good evening. Welcome. Just time for a quick update (with apologies to John Oliver and Last Week Tonight).
The following links are humbly presented as evidence that I am still very actively involved in researching security, mainly as it relates to crime and computers, a.k.a. cybersecurity and cybercrime.
1. Blog posts on We Live Security, of which there are many. These are conveniently listed here.
2. Webinars on Brighttalk, which include this introduction to risk analysis and this look at cybersecurity legislation.
3. Slide decks posted on Slideshare, like this one: Cybercrime and the Hidden Perils of Patient Data. I used that deck when talking to a group of about 40 dentists in San Diego. Here's a deck I used in security awareness sessions with about 400 petroleum plant workers in Texas.
4. Snippets posted on Twitter by @zcobb, which may consist of quotes, statistics, pieces of information that I think will help people better understand security challenges. Here's an example:
So, while the rate of posting here on S. Cobb on Security has not been stellar of late, it's not because I'm not working on security problems.
Cybersecurity, AI, crime, fraud, risk, trust, privacy, gender, equity, public-interest technology
Saturday, May 30, 2015
Sunday, January 04, 2015
Why Willie Sutton Robbed Banks: the real answer, and what it has to do with the #SonyHack
Willie Sutton was one of the most notorious American bank robbers of the twentieth century, spending two years on the FBI's list of Ten Most Wanted Fugitives.
Sutton is also the subject of one of the most frequently cited - and bogus - anecdotes in all of security (we're talking everything from physical security to information security and cybersecurity). At just about every security conference that I've attended, someone has used some version of the following:
Sutton is also the subject of one of the most frequently cited - and bogus - anecdotes in all of security (we're talking everything from physical security to information security and cybersecurity). At just about every security conference that I've attended, someone has used some version of the following:
"When a reporter asked the bank robber Willie Sutton why he robbed banks, Sutton replied: "Because that's where the money is.""
Saturday, December 20, 2014
Why the #SonyHack is not cyberwar
Here are two links that are essential reading for anyone tempted to invoke the term "cyberwar" to describe the hacking of Sony Pictures and its subsequent canceling of The Interview.
Book: The Tallinn Manual on the International Law Applicable to Cyber Warfare. This is the primer on the subject. Readable online at no charge.
Article: Cyberwar: reality or a weapon of mass distraction. Very readable paper by my friend and boss, security expert Andrew Lee (.pdf file).
Hopefully, politicians and commentators talking about the Sony Pictures hack will familiarize themselves with the facts and arguments laid out in the above publications before crying War!
Book: The Tallinn Manual on the International Law Applicable to Cyber Warfare. This is the primer on the subject. Readable online at no charge.
Article: Cyberwar: reality or a weapon of mass distraction. Very readable paper by my friend and boss, security expert Andrew Lee (.pdf file).
Hopefully, politicians and commentators talking about the Sony Pictures hack will familiarize themselves with the facts and arguments laid out in the above publications before crying War!
Friday, December 19, 2014
Dear George Clooney - A word about cybersecurity
The following letter was written in response to remarks made by the actor and activist, George Clooney, in this article: Hollywood Cowardice: George Clooney Explains Why Sony Stood Alone In North Korean Cyberterror Attack
Dear Mr. Clooney,
I have great respect for your work sir, on film and off; I have a feeling we hold many of the same views on politics and economics and social justice. So it makes me sad to see how badly people have briefed you on the stark realities of cybersecurity. You seem to be under the impression that America can, with impunity, tell cyber criminals to "bring it on". You appear to be having difficulty understanding why big companies don't want to provoke hackers. Please allow me to explain.
In my own work I have seen the way in which multinational companies generate billions of dollars in profits by applying digital technology to improve productivity. My job has been, for the better part of two decades, advising companies on how to defend this highly profitable digital technology that they deploy.
Sadly, time and again, too many times to count, my fellow security professionals and I run into companies and company executives who reject our advice as too costly to implement, as an unreasonable burden on their business. When we say that the path they are taking comes with a large amount of risk, they either don't believe us or they say, "fine, we'll risk it."
Dear Mr. Clooney,
I have great respect for your work sir, on film and off; I have a feeling we hold many of the same views on politics and economics and social justice. So it makes me sad to see how badly people have briefed you on the stark realities of cybersecurity. You seem to be under the impression that America can, with impunity, tell cyber criminals to "bring it on". You appear to be having difficulty understanding why big companies don't want to provoke hackers. Please allow me to explain.
In my own work I have seen the way in which multinational companies generate billions of dollars in profits by applying digital technology to improve productivity. My job has been, for the better part of two decades, advising companies on how to defend this highly profitable digital technology that they deploy.
Sadly, time and again, too many times to count, my fellow security professionals and I run into companies and company executives who reject our advice as too costly to implement, as an unreasonable burden on their business. When we say that the path they are taking comes with a large amount of risk, they either don't believe us or they say, "fine, we'll risk it."
Sunday, August 24, 2014
The Continuing Pain of Cybercrime Explained in One Simple Graph
- number of people with cyber skills
- the amount of resources devoted to deterring cybercrime
- the level of regulatory compliance
- the national resolve to address the problem
- international resolve to address the problem
- number of people on the Internet
- number of things on the Internet (IoT)
- the ease of use and accessibility of cybercrime tools
- the number of people prepared to engage in cybercrime
Just to be clear, globally speaking, C is a net negative. Cybercrime can be positive for criminals and their immediate economic environs, such as communities with limited options for legal employment of a gainful nature. However, C undermines the primary factors by which the upward angle of A can be increased: economic prosperity and political stability.
Saturday, August 09, 2014
Is this your Sample Information Security Policy?
If you or your organization is the original creator of the following Sample Information Security Policy then I would like to hear from you:
Every organization needs an Information Security Policy (although they may call it something different). When used appropriately the organization's whole approach to security will be guided by the policy document, a copy of which may well be requested during discussions around mergers, partnerships, and bids for new business. I have discussed the role and importance of security policy in several webinars, including this one directed at small and medium sized businesses.
Tuesday, May 13, 2014
Privacy for Business: eBook from 2002
I published "Privacy for Business: Web sites and email" in 2002. Much of the content about privacy principles in business is still relevant. You can download the book free of charge in electronic form as long as you respect the copyright and license agreement.
(2016 Update: You might also find this more recent article and privacy white paper helpful.)
By clicking the DOWNLOAD button on this page you agree to abide by the licensing agreement below.
(2016 Update: You might also find this more recent article and privacy white paper helpful.)
By clicking the DOWNLOAD button on this page you agree to abide by the licensing agreement below.
License for the electronic edition of Privacy for Business: Web Sites & Email
THE ABOVE NAMED WORK (AS DEFINED BELOW) IS PROVIDED UNDER THE TERMS OF THIS CREATIVE COMMONS PUBLIC LICENSE ("CCPL" OR "LICENSE"). THE WORK IS PROTECTED BY COPYRIGHT AND/OR OTHER APPLICABLE LAW. ANY USE OF THE WORK OTHER THAN AS AUTHORIZED UNDER THIS LICENSE OR COPYRIGHT LAW IS PROHIBITED.
BY EXERCISING ANY RIGHTS TO THE WORK PROVIDED HERE, YOU ACCEPT AND AGREE TO BE BOUND BY THE TERMS OF THIS LICENSE. TO THE EXTENT THIS LICENSE MAY BE CONSIDERED TO BE A CONTRACT, THE LICENSOR GRANTS YOU THE RIGHTS CONTAINED HERE IN CONSIDERATION OF YOUR ACCEPTANCE OF SUCH TERMS AND CONDITIONS.
1. Definitions
- "Adaptation" means a work based upon the Work, or upon the Work and other pre-existing works, such as a translation, adaptation, derivative work, arrangement of music or other alterations of a literary or artistic work, or phonogram or performance and includes cinematographic adaptations or any other form in which the Work may be recast, transformed, or adapted including in any form recognizably derived from the original, except that a work that constitutes a Collection will not be considered an Adaptation for the purpose of this License. For the avoidance of doubt, where the Work is a musical work, performance or phonogram, the synchronization of the Work in timed-relation with a moving image ("synching") will be considered an Adaptation for the purpose of this License.
- "Collection" means a collection of literary or artistic works, such as encyclopedias and anthologies, or performances, phonograms or broadcasts, or other works or subject matter other than works listed in Section 1(f) below, which, by reason of the selection and arrangement of their contents, constitute intellectual creations, in which the Work is included in its entirety in unmodified form along with one or more other contributions, each constituting separate and independent works in themselves, which together are assembled into a collective whole. A work that constitutes a Collection will not be considered an Adaptation (as defined above) for the purposes of this License.
- "Distribute" means to make available to the public the original and copies of the Work through sale or other transfer of ownership.
- "Licensor" means the individual, individuals, entity or entities that offer(s) the Work under the terms of this License.
- "Original Author" means, in the case of a literary or artistic work, the individual, individuals, entity or entities who created the Work or if no individual or entity can be identified, the publisher; and in addition (i) in the case of a performance the actors, singers, musicians, dancers, and other persons who act, sing, deliver, declaim, play in, interpret or otherwise perform literary or artistic works or expressions of folklore; (ii) in the case of a phonogram the producer being the person or legal entity who first fixes the sounds of a performance or other sounds; and, (iii) in the case of broadcasts, the organization that transmits the broadcast.
- "Work" means the literary and/or artistic work offered under the terms of this License including without limitation any production in the literary, scientific and artistic domain, whatever may be the mode or form of its expression including digital form, such as a book, pamphlet and other writing; a lecture, address, sermon or other work of the same nature; a dramatic or dramatico-musical work; a choreographic work or entertainment in dumb show; a musical composition with or without words; a cinematographic work to which are assimilated works expressed by a process analogous to cinematography; a work of drawing, painting, architecture, sculpture, engraving or lithography; a photographic work to which are assimilated works expressed by a process analogous to photography; a work of applied art; an illustration, map, plan, sketch or three-dimensional work relative to geography, topography, architecture or science; a performance; a broadcast; a phonogram; a compilation of data to the extent it is protected as a copyrightable work; or a work performed by a variety or circus performer to the extent it is not otherwise considered a literary or artistic work.
- "You" means an individual or entity exercising rights under this License who has not previously violated the terms of this License with respect to the Work, or who has received express permission from the Licensor to exercise rights under this License despite a previous violation.
- "Publicly Perform" means to perform public recitations of the Work and to communicate to the public those public recitations, by any means or process, including by wire or wireless means or public digital performances; to make available to the public Works in such a way that members of the public may access these Works from a place and at a place individually chosen by them; to perform the Work to the public by any means or process and the communication to the public of the performances of the Work, including by public digital performance; to broadcast and rebroadcast the Work by any means including signs, sounds or images.
- "Reproduce" means to make copies of the Work by any means including without limitation by sound or visual recordings and the right of fixation and reproducing fixations of the Work, including storage of a protected performance or phonogram in digital form or other electronic medium.
2. Fair Dealing Rights. Nothing in this License is intended to reduce, limit, or restrict any uses free from copyright or rights arising from limitations or exceptions that are provided for in connection with the copyright protection under copyright law or other applicable laws.
3. License Grant. Subject to the terms and conditions of this License, Licensor hereby grants You a worldwide, royalty-free, non-exclusive, perpetual (for the duration of the applicable copyright) license to exercise the rights in the Work as stated below:
- to Reproduce the Work, to incorporate the Work into one or more Collections, and to Reproduce the Work as incorporated in the Collections; and,
- to Distribute and Publicly Perform the Work including as incorporated in Collections.
The above rights may be exercised in all media and formats whether now known or hereafter devised. The above rights include the right to make such modifications as are technically necessary to exercise the rights in other media and formats, but otherwise you have no rights to make Adaptations. Subject to 8(f), all rights not expressly granted by Licensor are hereby reserved, including but not limited to the rights set forth in Section 4(d).
4. Restrictions. The license granted in Section 3 above is expressly made subject to and limited by the following restrictions:
- You may Distribute or Publicly Perform the Work only under the terms of this License. You must include a copy of, or the Uniform Resource Identifier (URI) for, this License with every copy of the Work You Distribute or Publicly Perform. You may not offer or impose any terms on the Work that restrict the terms of this License or the ability of the recipient of the Work to exercise the rights granted to that recipient under the terms of the License. You may not sublicense the Work. You must keep intact all notices that refer to this License and to the disclaimer of warranties with every copy of the Work You Distribute or Publicly Perform. When You Distribute or Publicly Perform the Work, You may not impose any effective technological measures on the Work that restrict the ability of a recipient of the Work from You to exercise the rights granted to that recipient under the terms of the License. This Section 4(a) applies to the Work as incorporated in a Collection, but this does not require the Collection apart from the Work itself to be made subject to the terms of this License. If You create a Collection, upon notice from any Licensor You must, to the extent practicable, remove from the Collection any credit as required by Section 4(c), as requested.
- You may not exercise any of the rights granted to You in Section 3 above in any manner that is primarily intended for or directed toward commercial advantage or private monetary compensation. The exchange of the Work for other copyrighted works by means of digital file-sharing or otherwise shall not be considered to be intended for or directed toward commercial advantage or private monetary compensation, provided there is no payment of any monetary compensation in connection with the exchange of copyrighted works.
- If You Distribute, or Publicly Perform the Work or Collections, You must, unless a request has been made pursuant to Section 4(a), keep intact all copyright notices for the Work and provide, reasonable to the medium or means You are utilizing: (i) the name of the Original Author (or pseudonym, if applicable) if supplied, and/or if the Original Author and/or Licensor designate another party or parties (e.g., a sponsor institute, publishing entity, journal) for attribution ("Attribution Parties") in Licensor's copyright notice, terms of service or by other reasonable means, the name of such party or parties; (ii) the title of the Work if supplied; (iii) to the extent reasonably practicable, the URI, if any, that Licensor specifies to be associated with the Work, unless such URI does not refer to the copyright notice or licensing information for the Work. The credit required by this Section 4(c) may be implemented in any reasonable manner; provided, however, that in the case of a Collection, at a minimum such credit will appear, if a credit for all contributing authors of Collection appears, then as part of these credits and in a manner at least as prominent as the credits for the other contributing authors. For the avoidance of doubt, You may only use the credit required by this Section for the purpose of attribution in the manner set out above and, by exercising Your rights under this License, You may not implicitly or explicitly assert or imply any connection with, sponsorship or endorsement by the Original Author, Licensor and/or Attribution Parties, as appropriate, of You or Your use of the Work, without the separate, express prior written permission of the Original Author, Licensor and/or Attribution Parties.
- For the avoidance of doubt:
- Non-waivable Compulsory License Schemes. In those jurisdictions in which the right to collect royalties through any statutory or compulsory licensing scheme cannot be waived, the Licensor reserves the exclusive right to collect such royalties for any exercise by You of the rights granted under this License;
- Waivable Compulsory License Schemes. In those jurisdictions in which the right to collect royalties through any statutory or compulsory licensing scheme can be waived, the Licensor reserves the exclusive right to collect such royalties for any exercise by You of the rights granted under this License if Your exercise of such rights is for a purpose or use which is otherwise than noncommercial as permitted under Section 4(b) and otherwise waives the right to collect royalties through any statutory or compulsory licensing scheme; and,
- Voluntary License Schemes. The Licensor reserves the right to collect royalties, whether individually or, in the event that the Licensor is a member of a collecting society that administers voluntary licensing schemes, via that society, from any exercise by You of the rights granted under this License that is for a purpose or use which is otherwise than noncommercial as permitted under Section 4(b).
- Except as otherwise agreed in writing by the Licensor or as may be otherwise permitted by applicable law, if You Reproduce, Distribute or Publicly Perform the Work either by itself or as part of any Collections, You must not distort, mutilate, modify or take other derogatory action in relation to the Work which would be prejudicial to the Original Author's honor or reputation.
5. Representations, Warranties and Disclaimer
UNLESS OTHERWISE MUTUALLY AGREED BY THE PARTIES IN WRITING, LICENSOR OFFERS THE WORK AS-IS AND MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND CONCERNING THE WORK, EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, INCLUDING, WITHOUT LIMITATION, WARRANTIES OF TITLE, MERCHANTIBILITY, FITNESS FOR A PARTICULAR PURPOSE, NONINFRINGEMENT, OR THE ABSENCE OF LATENT OR OTHER DEFECTS, ACCURACY, OR THE PRESENCE OF ABSENCE OF ERRORS, WHETHER OR NOT DISCOVERABLE. SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES, SO SUCH EXCLUSION MAY NOT APPLY TO YOU.
6. Limitation on Liability. EXCEPT TO THE EXTENT REQUIRED BY APPLICABLE LAW, IN NO EVENT WILL LICENSOR BE LIABLE TO YOU ON ANY LEGAL THEORY FOR ANY SPECIAL, INCIDENTAL, CONSEQUENTIAL, PUNITIVE OR EXEMPLARY DAMAGES ARISING OUT OF THIS LICENSE OR THE USE OF THE WORK, EVEN IF LICENSOR HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
7. Termination
- This License and the rights granted hereunder will terminate automatically upon any breach by You of the terms of this License. Individuals or entities who have received Collections from You under this License, however, will not have their licenses terminated provided such individuals or entities remain in full compliance with those licenses. Sections 1, 2, 5, 6, 7, and 8 will survive any termination of this License.
- Subject to the above terms and conditions, the license granted here is perpetual (for the duration of the applicable copyright in the Work). Notwithstanding the above, Licensor reserves the right to release the Work under different license terms or to stop distributing the Work at any time; provided, however that any such election will not serve to withdraw this License (or any other license that has been, or is required to be, granted under the terms of this License), and this License will continue in full force and effect unless terminated as stated above.
8. Miscellaneous
- Each time You Distribute or Publicly Perform the Work or a Collection, the Licensor offers to the recipient a license to the Work on the same terms and conditions as the license granted to You under this License.
- If any provision of this License is invalid or unenforceable under applicable law, it shall not affect the validity or enforceability of the remainder of the terms of this License, and without further action by the parties to this agreement, such provision shall be reformed to the minimum extent necessary to make such provision valid and enforceable.
- No term or provision of this License shall be deemed waived and no breach consented to unless such waiver or consent shall be in writing and signed by the party to be charged with such waiver or consent.
- This License constitutes the entire agreement between the parties with respect to the Work licensed here. There are no understandings, agreements or representations with respect to the Work not specified here. Licensor shall not be bound by any additional provisions that may appear in any communication from You. This License may not be modified without the mutual written agreement of the Licensor and You.
- The rights granted under, and the subject matter referenced, in this License were drafted utilizing the terminology of the Berne Convention for the Protection of Literary and Artistic Works (as amended on September 28, 1979), the Rome Convention of 1961, the WIPO Copyright Treaty of 1996, the WIPO Performances and Phonograms Treaty of 1996 and the Universal Copyright Convention (as revised on July 24, 1971). These rights and subject matter take effect in the relevant jurisdiction in which the License terms are sought to be enforced according to the corresponding provisions of the implementation of those treaty provisions in the applicable national law. If the standard suite of rights granted under applicable copyright law includes additional rights not granted under this License, such additional rights are deemed to be included in the License; this License is not intended to restrict the license of any rights under applicable law.
Monday, April 28, 2014
Business Continuity Management: Sounds boring yet saves lives, companies, butts
Lately, I've been revisiting an area of information security into which I have dived deeply on several occasions over the years: Disaster Recovery, which is pretty much the same as Business Continuity Management or BCM, which includes Business Continuity Planning (BCP). Along the way I have assembled a list of high quality BCM resources and articles that folks might find useful (and available for free in most cases). You will find the list at the end of this article. Here's a scene-setting quote from one of the articles:
Disasters can strike at any time – often with little or no warning – and the effects can be devastating. The cost in human lives and property damage is what makes the evening news because of the powerful tug of human interest. Much less coverage, however, is given to the disruption, struggle and survivability of business operations. A study fielded by the Institute for Business and Home Safety revealed that 25 percent of all companies that close due to disasters – hurricanes, power failures, acts of terror and others – never reopen. (Disaster Preparedness Planning: Maintaining Business Continuity During Crisis, Disruption and Recovery)
Monday, April 14, 2014
Internet voting security: a scary tweet that reached 227,391 (even before Heartbleed)
Last month I tweeted a picture of some computer code that was part of an Internet voting system. That picture was re-tweeted so many times it reached more than 220,000 Twitter users. So, that had to be some pretty amazing code, right? Yes, as in amazingly frightening. Take a look, and then read on for a short explanation, and also a long one if you have the time.
A very clever computer scientist, Joe Kiniry, has been concerned about the security of Internet voting applications for some time. Joe is a former Technical University of Denmark professor, now Principal Investigator at Galois. In his research Joe noted this section of code in a program that was actually used for national elections in a European country.
The coder(s) have included a comment reminding themselves that security checks still need to be coded. My tweet suggested that this slide nicely illustrated the question of “what could possibly go wrong?” when it comes to Internet voting. Of course, the best answer to that question is: So much could go wrong you simply cannot use the Internet to elect public officials in a fair, honest, secret ballot!
A very clever computer scientist, Joe Kiniry, has been concerned about the security of Internet voting applications for some time. Joe is a former Technical University of Denmark professor, now Principal Investigator at Galois. In his research Joe noted this section of code in a program that was actually used for national elections in a European country.
The coder(s) have included a comment reminding themselves that security checks still need to be coded. My tweet suggested that this slide nicely illustrated the question of “what could possibly go wrong?” when it comes to Internet voting. Of course, the best answer to that question is: So much could go wrong you simply cannot use the Internet to elect public officials in a fair, honest, secret ballot!
Sunday, January 19, 2014
A call to action we ignore at our peril
You don't have to watch all of this video to know that Josh Corman has clearly articulated the massive scope of the IT security challenges we face today, and he has done it using language that even a CEO or a Middle School teacher can understand. I think the whole thing is worth watching, but if you cut to minute 15 you get to the crux of the matter:
"Our dependence on technology is growing faster than our ability to secure it....Issues of public safety and public concern require public discussion and public solutions...We are going to be the ambassadors of technical literacy."My committment to my ambassadorial duties is my New Year resolution. Let the educational outreach begin.
Thursday, January 16, 2014
The Privacy Meter Redux
My prediction that data privacy is going to be a hot topic in 2014 was not surprising, but I am surprised at how many interview requests I've had so far, and we're barely halfway through January. Yesterday I found myself filling a last minute request to appear on a local TV channel. So I dusted off the trusty privacy meter.
I created this learning device in 2001 and it went into my privacy book that came out in 2002. And it is just a visual device, an image to use as a tool when discussing privacy. (Feel free to use it, you have my permission, it is released to the public domain.)
The idea is to ask people to self-assess where they fit on a scale from closed book to open book. They do not need to reveal their "privacy reading" but they do need to think about whether or not it is fair to impose their position on others.
In other words, there is no correct reading, but plenty of scope to use the meter as a basis for discussion. For example, suppose you are an open book. Is it fair to make others become open book about their personal data if they prefer to be more of a closed book? On the other hand, if you think you are a closed book, are you prepared to provide information about yourself in order to authenticate your identity and establish trust?
The idea is to ask people to self-assess where they fit on a scale from closed book to open book. They do not need to reveal their "privacy reading" but they do need to think about whether or not it is fair to impose their position on others.
In other words, there is no correct reading, but plenty of scope to use the meter as a basis for discussion. For example, suppose you are an open book. Is it fair to make others become open book about their personal data if they prefer to be more of a closed book? On the other hand, if you think you are a closed book, are you prepared to provide information about yourself in order to authenticate your identity and establish trust?
Saturday, January 11, 2014
Why there is so much cyber crime: #1 It's our spending priorities
With the number of potential victims of the Target data breach now topping 100 million, a lot of people who have never really given much thought to cyber crimes are asking: Why? How is it that criminals can commit computer crime on this scale with apparent impunity? After all, we pay taxes to be protected from the kind of scum that perpetrate crimes like this.
There are a number of answers to the question "why is there so much cyber crime?" But for me, the first answer on the list, the one that has been ignored by most of the talking heads who've been hashing over the scant details of the Target breach on TV, looks like this:
Despite all the hot air from politicians over the last 15 years, repeatedly pledging to do something about computer crime, the U.S. has failed to make fighting cyber crime a priority. I think these relative spending numbers make that clear. I would love to hear anyone argue that we are spending enough money to track down and prosecute cyber criminals right now.
An academic study published in 2012 put the total U.S. law enforcement spend on the fight against cyber crime at $200 million per year. I decided to be generous in my chart and rounded it up to $250 million.
The figure of $15 billion is often cited as the annual cost of the war on drugs, so apparently that is 60X more important than cyber crime. We know from the Snowden revelations that spy agencies spend over $52 billion per year, so apparently we think that what they do is 200X more important than fighting cyber crime.
How about we shave $0.5 billion off the intelligence agency budgets and spend it on bringing cyber criminals to justice? That's a 3X increase over what we spend right now. That might well be enough to put a significant number of perpetrators behind bars, including the ones we could afford to bring to the U.S. from other countries, thereby tipping the risk/reward equation against the bad guys and in the favor of honest citizens.
I'm writing to my representatives in Washington to tell them what I think our priorities should be. I'm sending them this chart. If you agree, I invite you to send it to the folks who are supposed to be representing you.
There are a number of answers to the question "why is there so much cyber crime?" But for me, the first answer on the list, the one that has been ignored by most of the talking heads who've been hashing over the scant details of the Target breach on TV, looks like this:
An academic study published in 2012 put the total U.S. law enforcement spend on the fight against cyber crime at $200 million per year. I decided to be generous in my chart and rounded it up to $250 million.
The figure of $15 billion is often cited as the annual cost of the war on drugs, so apparently that is 60X more important than cyber crime. We know from the Snowden revelations that spy agencies spend over $52 billion per year, so apparently we think that what they do is 200X more important than fighting cyber crime.
How about we shave $0.5 billion off the intelligence agency budgets and spend it on bringing cyber criminals to justice? That's a 3X increase over what we spend right now. That might well be enough to put a significant number of perpetrators behind bars, including the ones we could afford to bring to the U.S. from other countries, thereby tipping the risk/reward equation against the bad guys and in the favor of honest citizens.
I'm writing to my representatives in Washington to tell them what I think our priorities should be. I'm sending them this chart. If you agree, I invite you to send it to the folks who are supposed to be representing you.
Thursday, January 02, 2014
My #4 personal privacy and security prediction for 2014: A BIG year for good/bad news
As we enter 2014 it is clear that two events in 2013 have rocketed data privacy and information security to the highest level of public awareness that these the complex topics have ever attained. I'm talking about the Snowden revelations and the Target breach.
For me, this surge in public awareness of the importance of data privacy and cybersecurity is both exciting and frightening.Why? Because 2014 is obviously going to be a big year for those of us who work in these closely intertwined fields, a year when more people than ever before will be concerned about securing their data, yet more distrustful than ever of the folks who are trying to help them do that (among whom I count myself).
Consider that I have spent the better part of 20 years writing and speaking about these issues, starting with computer security, then network security, system security, information assurance, data privacy, and now "cybersecurity." You could say that I have wanted nothing more than to make the world aware of the importance of these things, for the simple reason that, without such awareness, the true potential of digital technology will never be realized.
Let me put it a different way: Are you wondering where the flying cars are? Are you disappointed that in 2014 we don't yet have them, or transoceanic high speed rail service, or the handheld medical scanner that can diagnose the top 100 medical conditions in a single swipe? I believe we would have achieved these or similar technological marvels by now if it were not for the massive distraction of information insecurity.
I don't want to wander off into too many examples, but consider one: Towards the end of the last century email was poised to become a universal tool for managing transactions cheaply and easily. Then came the spam-plosion, a massive surge in unsolicited commercial email that rose to become 80% or more of all email and had Internet service providers (ISP's) buying new servers once a fortnight just to maintain legitimate service. Combine that with the inability of the major email providers to agree on improvements to email protocols, and you have the death of transactional email that is still hampering large slices of our economy, like banking, healthcare, government, and retail.
So the good news / bad news in 2014 goes like this:
The answer is no, but although part of me feels hurt and even insulted by this line of questioning, objectively-speaking I cannot object, particularly when I see these pages from a catalog of hardware and software crippled by the NSA, in other words, produced by my own government. I am sure that the people who developed these things thought they were doing the right thing, and only intended them to be used for righteous purposes like defending our nation. But the people in charge clearly failed to consider what would happen to the nation when the world found out about them.
I bet you a box of donuts that in 2014 at least one person will ask me where they can get a USB cable that is certified uncompromised. The fact that I don't have a good answer really bothers me. More people than ever before are going to be asking security professionals for help in creating secure systems, even as those professionals try to deal with NSA-fueled doubts about the very building blocks of such systems. One way or another, or both, it's going to be a BIG year.
For me, this surge in public awareness of the importance of data privacy and cybersecurity is both exciting and frightening.Why? Because 2014 is obviously going to be a big year for those of us who work in these closely intertwined fields, a year when more people than ever before will be concerned about securing their data, yet more distrustful than ever of the folks who are trying to help them do that (among whom I count myself).
Consider that I have spent the better part of 20 years writing and speaking about these issues, starting with computer security, then network security, system security, information assurance, data privacy, and now "cybersecurity." You could say that I have wanted nothing more than to make the world aware of the importance of these things, for the simple reason that, without such awareness, the true potential of digital technology will never be realized.
Let me put it a different way: Are you wondering where the flying cars are? Are you disappointed that in 2014 we don't yet have them, or transoceanic high speed rail service, or the handheld medical scanner that can diagnose the top 100 medical conditions in a single swipe? I believe we would have achieved these or similar technological marvels by now if it were not for the massive distraction of information insecurity.
I don't want to wander off into too many examples, but consider one: Towards the end of the last century email was poised to become a universal tool for managing transactions cheaply and easily. Then came the spam-plosion, a massive surge in unsolicited commercial email that rose to become 80% or more of all email and had Internet service providers (ISP's) buying new servers once a fortnight just to maintain legitimate service. Combine that with the inability of the major email providers to agree on improvements to email protocols, and you have the death of transactional email that is still hampering large slices of our economy, like banking, healthcare, government, and retail.
So the good news / bad news in 2014 goes like this:
- Are most consumers now aware that cybercrime is a serious problem? Yes. Can a young working mother buy diapers at a discount store without fear of losing her identity, and all the money in her back account, despite the billions that have been spent on cybersecurity? No, because we have grossly under-funded the vital work of catching the cyber-scum at the root of that fear.
- Are most companies now aware that cybercrime is a serious problem? Yes. Can a company develop new products without fear of them leaking from their computers to a nation state agency and/or its clients? No, because it is possible that every piece of hardware and software you buy to build your dreams has already been hacked, back-doored, or otherwise compromised, thanks in part to your own tax dollars at work (see this article or the pictures here if you are not clear on this).
The answer is no, but although part of me feels hurt and even insulted by this line of questioning, objectively-speaking I cannot object, particularly when I see these pages from a catalog of hardware and software crippled by the NSA, in other words, produced by my own government. I am sure that the people who developed these things thought they were doing the right thing, and only intended them to be used for righteous purposes like defending our nation. But the people in charge clearly failed to consider what would happen to the nation when the world found out about them.
I bet you a box of donuts that in 2014 at least one person will ask me where they can get a USB cable that is certified uncompromised. The fact that I don't have a good answer really bothers me. More people than ever before are going to be asking security professionals for help in creating secure systems, even as those professionals try to deal with NSA-fueled doubts about the very building blocks of such systems. One way or another, or both, it's going to be a BIG year.
Wednesday, January 01, 2014
My #3 personal privacy and security prediction for 2014: Cyber won't be icky any more
I predict, and sincerely hope, that in 2014 most of us information security professionals will stop apologizing whenever we use the letters c-y-b-e-r like in cyber crime, or cyber security. I also predict/hope we will stop putting "cyber" in ironic air quotes or pronouncing it in a snide tone that implies we are above using words that the world has thrust upon us.
Let's face it, computers, networks, information systems, endpoints, digital devices, tablets, smartphones, Internet-enabled-DVD-players, Bluetooth insulin pumps, they are all cyber.
So computer security, network security, information system security, endpoint security, digital device security, tablet security, smartphone security, Internet-enabled-DVD-player security, Bluetooth insulin pump security, they are all cyber security, or cyber-security, or cybersecurity.
In 2014 we are going to have to answer a lot of questions about the security of digital information. In our answers we can call it digital security, or refer to "the security of all things digital", but it is also okay to say cyber security. And referring to the bad guys as cyber criminals is a lot easier than saying "those who would subvert any or all things digital with criminal intent."
In 2013 there were times when I said things like cyber scammers and cyber scum well as cyber criminals. I'm not going to apologize for that because I think the general public gets what cyber means. It means all things digital, it means my data and the devices and systems that process and store them. Cyber security is about protecting that stuff. Let's save our erudition and expository powers for the many other, more complex and nuanced concepts that will need to be explained in 2014, like why public key encryption needs private keys, and what pseudo random number generators have done for us lately.
Let's face it, computers, networks, information systems, endpoints, digital devices, tablets, smartphones, Internet-enabled-DVD-players, Bluetooth insulin pumps, they are all cyber.
So computer security, network security, information system security, endpoint security, digital device security, tablet security, smartphone security, Internet-enabled-DVD-player security, Bluetooth insulin pump security, they are all cyber security, or cyber-security, or cybersecurity.
In 2014 we are going to have to answer a lot of questions about the security of digital information. In our answers we can call it digital security, or refer to "the security of all things digital", but it is also okay to say cyber security. And referring to the bad guys as cyber criminals is a lot easier than saying "those who would subvert any or all things digital with criminal intent."
In 2013 there were times when I said things like cyber scammers and cyber scum well as cyber criminals. I'm not going to apologize for that because I think the general public gets what cyber means. It means all things digital, it means my data and the devices and systems that process and store them. Cyber security is about protecting that stuff. Let's save our erudition and expository powers for the many other, more complex and nuanced concepts that will need to be explained in 2014, like why public key encryption needs private keys, and what pseudo random number generators have done for us lately.
Sunday, December 15, 2013
My #2 personal privacy and security prediction for 2014: NSA-GCHQ-NRO will dominate
Here is another of the privacy and security predictions I am making for 2014. This is in addition to the ones I contributed to We Live Security where I had the honor of presenting predictions from my fellow researchers at ESET.
Note that the following are my personal opinions, which may differ from
those of my employer (although my employer has some pretty cool
opinions).
The National Reconnaissance Office has already made a big play for attention with its latest spy satellite, NROL-39, launched in early December sporting a logo that many pundits will claim says it all: NOTHING IS BEYOND OUR REACH.
While NSA and GCHQ are initials known to millions around the world, the NRO has lurked in the shadows, despite having a budget about the same size as the NSA; that's $10.3 billion and $10.8 billion, for the NRO and NSA respectively for 2013, according to the Washington Post.
Note that in the mid-1990s the budgets were $6 billion and $3.6 billion, with NRO spending far-outpacing the NSA and CIA.
Expect someone to put more detailed spending numbers together as the work of these agencies comes under increased scrutiny in 2014. For example, all three have a history of using military employees who are paid out of their respective armed forces budgets. So the total U.S. spend on surveillance and code-breaking activities may be more than has yet been reported.
If the NROL-39 logo is any indication, very little of the NRO budget has gone into public relations and incident response planning. It is hard to imagine more disastrous imagery and sloganeering for a spy satellite launched post-Snowden. No wonder that within a few days we heard loud and clear from the world's technology giants demanding global surveillance reform. (A topic I discussed recently over on Tech Republic.)
The #1 privacy and security story in 2014 will be the NSA
Snowden-sourced papers will continue to leak, further revealing just how thoroughly America's National Security Agency has pursued the goal set by its leadership: make sure no piece of information about any person anywhere is beyond reach. While the NSA has dominated much of the privacy and security news in 2013, the story may evolve into a triple play in 2014, with GCHQ on one side, NRO on the other.
The National Reconnaissance Office has already made a big play for attention with its latest spy satellite, NROL-39, launched in early December sporting a logo that many pundits will claim says it all: NOTHING IS BEYOND OUR REACH.While NSA and GCHQ are initials known to millions around the world, the NRO has lurked in the shadows, despite having a budget about the same size as the NSA; that's $10.3 billion and $10.8 billion, for the NRO and NSA respectively for 2013, according to the Washington Post.
Note that in the mid-1990s the budgets were $6 billion and $3.6 billion, with NRO spending far-outpacing the NSA and CIA.
Expect someone to put more detailed spending numbers together as the work of these agencies comes under increased scrutiny in 2014. For example, all three have a history of using military employees who are paid out of their respective armed forces budgets. So the total U.S. spend on surveillance and code-breaking activities may be more than has yet been reported.
If the NROL-39 logo is any indication, very little of the NRO budget has gone into public relations and incident response planning. It is hard to imagine more disastrous imagery and sloganeering for a spy satellite launched post-Snowden. No wonder that within a few days we heard loud and clear from the world's technology giants demanding global surveillance reform. (A topic I discussed recently over on Tech Republic.)
My #1 personal privacy and security prediction for 2014: Antivirus will be slandered, again
Here is one of the privacy and security predictions I am making for 2014. This is in addition to the ones I contributed to We Live Security where I had the honor of presenting predictions from my fellow researchers at ESET. Note that the following are my personal opinions, which may differ from those of my employer (although my employer has some pretty cool opinions).
I predict that, although this assertion is simply not true, and has not been true for many years, that fact will not deter people from repeating it, over and over. This is a bit like Car and Driver or Consumer Reports saying that cars cannot be started without first engaging the crank handle.
True, there was a time, long ago, when crank handles were routinely used to start cars, just as some antivirus programs were, in the distant past, based solely on signatures derived from known bad code. I've got a free t-shirt and more for the first mainstream journalist who breaks rank from the ill-informed herd and points out that any AV app worthy of the name today uses a lot more than signature matching to protect systems from malicious code.
(With huge hat tip to the guys in Norway who posted that YouTube video of a hand-crank start: they are braver men than me; I've seen how much pain a crank handle can cause.)
The media will repeat a massive lie about antivirus technology
I predict that in 2014 every major newspaper and magazine will perpetuate, to the detriment of data security and human understanding, the grossly erroneous notion that "for an antivirus firm to spot malware, it first needs to have seen the malware, recognized that it's malicious code, and written a corresponding virus signature for its products."I predict that, although this assertion is simply not true, and has not been true for many years, that fact will not deter people from repeating it, over and over. This is a bit like Car and Driver or Consumer Reports saying that cars cannot be started without first engaging the crank handle.
(With huge hat tip to the guys in Norway who posted that YouTube video of a hand-crank start: they are braver men than me; I've seen how much pain a crank handle can cause.)
Saturday, October 12, 2013
Free professional security advice for Palestinian hackers
First of all, welcome. I am glad you found this page. Please don’t hack it.
Who am I? I am a computer security professional with over 20 years experience, just one of many people in the computer security world who have great sympathy for the Palestinian people. We agree with you that the Palestinian people deserve to live in peace. We let our politicians know what we think. We use social media to spread news and awareness of the injustices suffered by the Palestinian people at the hands of Western governments and their allies in the region (for example, see my pins of infographics about the Occupation).
As computer security professionals, we also work hard to protect the privacy and cybersecurity of hundreds millions of individuals around the world. Some of those people are Palestinians. For example, I work at ESET, a company which protects the computers and smartphones of many millions of people in more than 180 different countries. I’m guessing some of them are Palestinian sympathizers.
Who am I? I am a computer security professional with over 20 years experience, just one of many people in the computer security world who have great sympathy for the Palestinian people. We agree with you that the Palestinian people deserve to live in peace. We let our politicians know what we think. We use social media to spread news and awareness of the injustices suffered by the Palestinian people at the hands of Western governments and their allies in the region (for example, see my pins of infographics about the Occupation).
As computer security professionals, we also work hard to protect the privacy and cybersecurity of hundreds millions of individuals around the world. Some of those people are Palestinians. For example, I work at ESET, a company which protects the computers and smartphones of many millions of people in more than 180 different countries. I’m guessing some of them are Palestinian sympathizers.
Tuesday, September 03, 2013
More information security articles from Stephen and Michael
Here's an update on the information security stuff we've been writing. Three articles from SearchSecurity by Mike and a link to my archive on We Live Security.
- Expert Michael Cobb discusses why known Java security vulnerabilities are on so many endpoints and how to contain them -- without updating Java.
- The recent Ruby on Rails security vulnerabilities can be patched. Expert Michael Cobb discusses the fallout and offers help with remediation planning.
- Is Microsoft's Bing search engine more susceptible to search engine poisoning than Google? Expert Michael Cobb discusses Bing security.
- From NIST's Cyber Security Framework to NSA's impact on Wall Street.
Saturday, March 30, 2013
Criminal hackers force down volunteer site serving hemochromatosis help
Just a quick note to say that the website I created at CelticCurse.org is offline at the moment due to compromise by illegal access. It looks like criminal hackers forced their way into the server that hosts the site and installed their own code to launch DDoS attacks.
If you are not familiar with the site, it is an entirely volunteer project that serve up information and resources for people with hemochromatosis, a potentially fatal genetic disorder that affects millions around the world. Due to low awareness in the medical community hemochromatosis is widely under-diagnosed and often ill-treated, leading to a lot of needless pain and suffering.
I am working to restore the site, but in the meantime people who need more information about hemochromatosis can visit:
If you are not familiar with the site, it is an entirely volunteer project that serve up information and resources for people with hemochromatosis, a potentially fatal genetic disorder that affects millions around the world. Due to low awareness in the medical community hemochromatosis is widely under-diagnosed and often ill-treated, leading to a lot of needless pain and suffering.
I am working to restore the site, but in the meantime people who need more information about hemochromatosis can visit:
- The Facebook Hemochromatosis page (please Like the page, it will help spread the word).
Monday, March 25, 2013
More security articles from Michael Cobb, CISSP-ISSAP
-
Heading Off Advanced Social Engineering Attacks
March 18, 2013An inside look at how social engineering attacks are developed -- and how you can protect your organization -
What Antivirus Shortcomings Mean For SMBs
January 23, 2013Accepting the risks that come with relying solely on AV not only puts data at risk, but also could kill future earning potential -
Six Security Services Every Small Business Must Have
January 10, 2013A look at managed services for small and midsize businesses, and how to choose the ones that work for your organization -
Five Security Tools Every Small Business Must Have
January 08, 2013Small businesses often are short on security skills, staffing and budget. Here are five tools that can help -
Measuring Risk: A Security Pro's Guide
August 07, 2012A look at the tools for evaluating security risks -- and some tips for putting the resulting data into business context -
Evaluating And Choosing Threat Intelligence Tools
July 15, 2012So you want to collect and analyze your own threat data. What tools do you need? Here are some tips for finding the right ones -
When To Outsource Security -- And When Not To
June 04, 2012New Dark Reading report offers insights on the advantages and pitfalls of bringing in a third party to help with security -
How Did They Get In? A Guide To Tracking Down The Source Of An APT
April 18, 2012Advanced persistent threats can be complex and sophisticated. Here are some tips on how to analyze them -
How To Detect And Defend Against Advanced Persistent Threats
Tuesday, December 04, 2012
More Cobb security resources
This is just a quick post to update links to Cobb-sourced information security resources. Here's a round of articles by Mike Cobb, CISSP:
Best Practices: 6 Security Services Every Small Business Must Have
Best Practices: 6 Security Services Every Small Business Must Have
Best Practices: 5 Security Tools Every Small Business Must Have
Strategy: Evaluating and Choosing Threat Intelligence Tools
Strategy: Measuring Risk: A Security Pro's Guide
Strategy: Finding the Right Security Outsourcing Balance
Strategy: Tracking the Source of APTs
Strategy: Detecting and Defending Against Advanced Persistent Threats
Strategy: Stop Illicit Data Dumps
Biometrics for the Rest of Us
Strategy: Biometrics
And here is a handy link for the articles Stephen Cobb posts on the ESET blog:
Stephen Cobb on the ESET blog
Strategy: Evaluating and Choosing Threat Intelligence Tools
Strategy: Measuring Risk: A Security Pro's Guide
Strategy: Finding the Right Security Outsourcing Balance
Strategy: Tracking the Source of APTs
Strategy: Detecting and Defending Against Advanced Persistent Threats
Strategy: Stop Illicit Data Dumps
Biometrics for the Rest of Us
Strategy: Biometrics
And here is a handy link for the articles Stephen Cobb posts on the ESET blog:
Stephen Cobb on the ESET blog
Sunday, October 07, 2012
More Cobbs on Information Security: Selected articles by Stephen & Michael
As you may know from my previous post, my first book on computer security was published in 1992. That led to an invitation to speak at the 1994 Virus Bulletin conference, and in 1996 I was one of the first people to pass the CISSP exam. A few years later, my brother Michael Cobb, became an MCDBA and then a CISSP, and later a CISSP-ISSAP.
Michael, who also writes as Mike Cobb, is also CLAS (stands for the UK's CESG Listed Advisor Scheme--CLAS consultants play a key role in providing Information Assurance advice to government departments and other organisations that provide services for the government.)
Over the year's Mike and I have written and spoken a lot about security. W've taught a lot of security classes, and delivered a host of security and privacy themed seminars, podcasts, and webcasts. Right now I am working up the strength to create a library of links to as many of these as I can find online. But in the meantime, here are 5 recent items from each of us.
Mike/Michael Cobb writes for a variety of publications, including SearchSecurity and Dark Reading. Here are 5 recent articles:
Michael, who also writes as Mike Cobb, is also CLAS (stands for the UK's CESG Listed Advisor Scheme--CLAS consultants play a key role in providing Information Assurance advice to government departments and other organisations that provide services for the government.)
Over the year's Mike and I have written and spoken a lot about security. W've taught a lot of security classes, and delivered a host of security and privacy themed seminars, podcasts, and webcasts. Right now I am working up the strength to create a library of links to as many of these as I can find online. But in the meantime, here are 5 recent items from each of us.
Michael's List
Mike/Michael Cobb writes for a variety of publications, including SearchSecurity and Dark Reading. Here are 5 recent articles:- Measuring Risk: A Security Pro's Guide
- Evaluating and Choosing Threat Intelligence Tools
- When To Outsource Security - And When Not To
- How Did They Get In? A Guide To Tracking Down The Source Of An APT
- How To Detect And Defend Against Advanced Persistent Threats
Stephen's List
I write for the ESET Threat Blog as well as my own blog and SC Magazine's Cybercrime Corner. Here are 4 widely read items and an index of my posts from the ESET blog:- Data security and digital privacy on the road, what travelers should know
- FBI Ransomware: Reveton seeks MoneyPak payment in the name of the law
- Malware RATs can steal your data and your money, your privacy too
- Privacy and Security in the Consumer Cloud: The not so fine print
- Library of Stephen Cobb's articles on the ESET Threat Blog
Sunday, July 22, 2012
Cobb's PC and LAN Security: 20th anniversary of publication (available as a free download!)
The Stephen Cobb Complete Book of PC and LAN Security first appeared in print in 1992, an amazing 20 years ago. In celebration of this anniversary, I'm publishing a PDF copy of the most recent version of the book, freely downloadable under a Creative Commons license. The large file size of this 700 page tome led me to publish it in three easily digestible parts: Part One; Part Two; and Part Three. (Yes, my organizational skills are legendary.)
Despite the title, which was imposed by the publisher, the volume that appeared 20 years ago was by no means a "complete book" on the subject; nor is it now a contemporary guide. However, you can still find it on Amazon, even though Amazon.com did not exist when the first version was published. The images immediately on the right are the current Amazon listings of the three versions (which I will explain shortly).
If you are inclined to take this particular trip down computer security's memory lane, I suggest you download the free electronic version rather than purchase on Amazon. On that trip you will find a few items of note, such as this:
Despite the title, which was imposed by the publisher, the volume that appeared 20 years ago was by no means a "complete book" on the subject; nor is it now a contemporary guide. However, you can still find it on Amazon, even though Amazon.com did not exist when the first version was published. The images immediately on the right are the current Amazon listings of the three versions (which I will explain shortly).
If you are inclined to take this particular trip down computer security's memory lane, I suggest you download the free electronic version rather than purchase on Amazon. On that trip you will find a few items of note, such as this:
The goal of personal computer security is to protect and foster the increased creativity and productivity made possible by a technology that has so far flourished with a minimum of controls, but which finds itself increasingly threatened by the very openness that led to its early success. To achieve this goal, you must step from an age of trusting innocence into a new era of realism and responsibility, without lurching into paranoia and repression.I'd say that's a decent piece of prognostication for 1992. It's one of the reasons I have kept the book available all these years, a mix of nostalgia and history. At some point in the future it might be interesting to see what computer security looked like in the late 20th century.
Three Versions and a Free Version
I made a lot of changes when I turned that 1992 volume into The NCSA Guide to PC and LAN Security--a 700 page paperback that was published in 1995--but that edition is also very outdated these days. Around 12 years ago I obtained the copyright to these works and, through an arrangement with the Authors Guild, got it reprinted as Cobb's Guide to PC and LAN Security. This was done largely for sentimental reasons and the copies are only printed on demand. However, in that process I obtained a high resolution scan of the entire book. I then converted this to text using Adobe OCR software. The result is what I have put online. (Warning: you may encounter OCR errors and artifacts; no claims are made as to accuracy of the information in this document; use at your own risk and discretion).LEGAL STUFF: THIS FREE ELECTRONIC EDITION IS LICENSED BY THE AUTHOR FOR USE UNDER CREATIVE COMMONS, ATTRIBUTION, NONCOMMERCIAL, NO DERIVATES.
Computer Security Prognosis and Predictions
I plan to post more thoughts on computer security "then and now" but for now I leave you with another quote from the 1992 Stephen Cobb Complete Book of PC and LAN Security:The most cost-effective long-term approach to personal computer security is the promotion of mature and responsible attitudes among users. Lasting security will not be achieved by technology, nor by constraints on those who use it. True security can only be achieved through the willing compliance of users with universally accepted principles of behavior. Such compliance will increase as society as a whole becomes increasingly computer literate, and users understand the personal value of the technology they use.
Friday, June 29, 2012
Stuxnet, Flame, Information Security and Privacy Blog Posts
I thought I would update the blog for June by listing some of my recent articles and posts from elsewhere, mainly the ESET Threat Blog, unless stated otherwise.
- Stuxnet, Flamer, Flame, Whatever Name: There’s just no good malware
- The negative impact on GDP of state-sponsored malware like Stuxnet and Flame
- Data security and digital privacy on the road, what travelers should know
- Cybercrime and the small business: Basic defensive measures
- Malware RATs can steal your data and your money, your privacy too
- Privacy and Security in the Consumer Cloud: The not so fine print
- Cyber crime as a market - Information security experts often talk about the costs of cybercrime to businesses, but a new report from Russia quantifies how much criminals make in the "cybercrime market." (SC Magazine)
- America's privacy and security enforcer - The FTC has made major moves this year in its fight against cyber crime, and if enterprises and organizations aren't careful, they may be facing a team of the agency's investigators. (SC Magazine)
As you can see, the reports that Stuxnet was indeed a U.S. government project sparked a couple of articles. It also got me talking on a podcast: Demystifying nation-state attacks and their impact
Wednesday, May 16, 2012
QR Code Privacy Issues and AT&T
Ouch! After saying that I thought AT&T had done a better-than-average job with its QR code scanner app for the iPhone someone pointed out that AT&T's scanner is one of a number of such apps that have privacy issues. The point was made in a comment on the ESET Threat Blog by Roger Smolski who runs this excellent website focused on QR codes.
It seems that, like me, Roger is a fan of technology but keeps a wary eye on potential downsides, like a QR code scanner that does more than the user bargained for. This definitely seems to be the case with the AT&T scanner, which let's AT&T know what you scan. I liked the AT&T scanner for installing with a preview option by default, but now dislike it because of this under-disclosed sharing of data that I consider personal (i.e. what QR codes I choose to scan).
According to Roger, confirmed by his technical code scanner analysis, some QR scanner apps, like NeoReader, are gathering data on your use of the app. The AT&T scanner is an example of this. An example of a decent scanner that does not do this is Bar Code Scanner for Android. I am going to have to look further for an iPhone QR Code scanner app that is independently confirmed as "non-tracking." In the meantime, here are other QR/privacy articles by Roger Smolski:
Oh, and BTW, FYI, it seems QR Code is a registered trademark of Denso Wave Corp. So maybe I will adopt Roger's usage of 2D codes to avoid stepping on anyone's IP toes.
It seems that, like me, Roger is a fan of technology but keeps a wary eye on potential downsides, like a QR code scanner that does more than the user bargained for. This definitely seems to be the case with the AT&T scanner, which let's AT&T know what you scan. I liked the AT&T scanner for installing with a preview option by default, but now dislike it because of this under-disclosed sharing of data that I consider personal (i.e. what QR codes I choose to scan).
According to Roger, confirmed by his technical code scanner analysis, some QR scanner apps, like NeoReader, are gathering data on your use of the app. The AT&T scanner is an example of this. An example of a decent scanner that does not do this is Bar Code Scanner for Android. I am going to have to look further for an iPhone QR Code scanner app that is independently confirmed as "non-tracking." In the meantime, here are other QR/privacy articles by Roger Smolski:
Oh, and BTW, FYI, it seems QR Code is a registered trademark of Denso Wave Corp. So maybe I will adopt Roger's usage of 2D codes to avoid stepping on anyone's IP toes.
Monday, April 23, 2012
AT&T Gets QR Code Scanner Right
AT&T might not be the best-loved company in America but it deserves praise for getting something right: The QR code scanner that it supplies for the Apple iPhone has a preview-and-authorize mode installed as the default.
I have explained why this is important in this article on QR codes and NFC tags which includes a video that makes the point quite vividly: You should not let your hardware act on the instructions embedded in a QR code of NFC tag without first knowing what those actions are. The AT&T code scanner for iPhone is set up to do that. Other scanners also have that ability but do not behave that way by default.
I have bashed AT&T for poor wireless products and service on numerous occasions, but I believe in praise where praise is due. Security has long been a priority at AT&T. Over the years I have trained thousands of AT&T employees on everything from server security to security in the workplace. So I was happy to see their QR code reader was designed right.
Sunday, March 18, 2012
Cybersecurity Reading List for March 2012
Cybersecurity reports, blog posts, and white papers are not in short supply these days, so I thought I would help folks decide what subset to read. I'm hoping this will make up for some of the neglect this blog has suffered over the past few months, due in no small part to my heavy--yet enjoyable--workload at ESET.
- The paper "Follow the Money" offers great insight into the spam business today. A lot of other papers worth reading are listed on the same page.
- The Trustwave Global Security Report 2012 has a lot of interesting statistics, some quite surprising: "Industries with franchise models are the new cyber targets: more than a third of 2011 investigations occurred in a franchise business."
- The Verizon 2011 Data Breach Investigation Report (pdf) is almost a year old but still worth reading is you haven't already. Good background for the 2012 report.
- Some highlights from the forthcoming Verizon 2012 DBIR, like "29% of threat incidents involved the ability to guess a user's password correctly."
- Selections from the ESET Threat Blog:
- Drive-by FTP: a new view of CVE-2011-3544. Novel way to distribute the payload for the most common java exploit.
- OSX/Imuler updated: still a threat on Mac OS X and hiding Trojan code in erotic pictures.
- Modern viral propagation: Facebook, shocking videos, browser plugins, spreading Koobface, Boonana, Win32/Delf.QCZ, Yimfoca, and more.
Tuesday, January 03, 2012
Chinese hacks and Anonymous hacking: Lessons of the end game when nothing is 100% secure
I read about the hacking of the California State Law Enforcement Association or CSLEA website by Anonymous "for fun and m4yh3m!"just after reading about the latest round of hacking of Chinese websites. Nota Bene: I am NOT saying Anonymous hacked the Chinese websites; I'm NOT talking abut Chinese hacking of U.S. websites; and I'm NOT writing as an employee of any organization.
Sunday, August 14, 2011
Etymologically Speaking: Cracking or hacking, mobile phones or voicemail?
In the wake of the News of The World (NOTW) scandal in which "journalists" are alleged to have listened to, and sometimes erased, messages left on phones that did not belong to said journalists, the term phone hacking has shot up the charts of widely misused phrases.
As this very helpful article on Geek News Central points out, the NOTW scandal is not really about phone hacking, it is about voicemail hacking, which the article's title tries to make clear: How To Hack Mobile Phone Voicemail.
Like the proverbial Trojan Horse, which was really neither horse nor Trojan, we are probably stuck with phone hacking as a phrase hacked together by hacks to describe some types of phone system manipulation and/or phone user duping. Such subtle distinctions may not matter to some people, but I think they matter to information security professionals. Why? Because part of our role in society, one that I personally take very seriously, is trying to bring clarity to matters involving the theft of information, unwarranted invasions of privacy through the abuse of information systems, use of computer systems to commit fraud, and so on.
And perhaps no word in recent memory has been more abused and hacked than hackers. As Steven Levy firmly established more than 25 years ago in his book, Hackers: Heroes of the Computer Revolution, the word started out with a positive connotation, a subject he addressed at the recent DefCon hacker conference in Las Vegas.
For almost as many years, my good friend Dr. Mich Kabay has tried to maintain a consistent distinction between hackers and criminal hackers. In his copious writings and teachings on information assurance, Mich diligently avoids omitting the word criminal from the phrase, either for convenience or brevity (see these Google results for examples).
(In the 1990s, some people tried to get criminal hackers shortened to crackers but that was doomed by ambiguity, between the decidedly non-technical use of the term cracker in the Southern states and people who specialize in cracking encryption codes.)
While criminal hackers are generally to be reviled for the mess they are making of otherwise beneficial technology, some hackers may be deserving of praise. You can get a personal perspective on this distinction by watching the excellent documentary made by another good friend, Ashley Schwartau, titled "Hackers Are People Too."
All of which underlines the ambiguity--some might say neutrality--of information technology, and the need to use care, as well as clear and specific language, when discussing its use or abuse. Voicemail can be incredibly useful, but it can be abused and cause pain when "hacked" by people of questionable ethics. Encryption can protect your private information from prying eyes, or allow a criminal hacker to hold your data for ransom. Cracking encryption can save lives or expose people to their enemies.
You might say that the problem with technology is the people who abuse it. We need to distinguish them from the people who try to improve it. And choosing our words wisely is one way of making that distinction.
Footnote: I will have a lot more to say about this and other aspects of information security after September 1, which is when I transition to a new position: Security Evangelist for ESET.
Wednesday, July 13, 2011
The NOTW Phone Hacking Scandal: Lessons for risk managers keep coming
In the context of data privacy, cyber security, and risk management I once wrote: "Failure to police your employees and sub-contractors can have serious consequences."
In the last 6 days we have seen massive proof of that as the News of the World (NOTW) phone hacking scandal has erupted onto the world stage, spewing a toxic mix of consequences, the like of which we have never seen before.
Consider anyone who owned stock in BSkB. I documented their bad news yesterday. And consider any innocent employees of the News of the World who are suddenly without a job. If those people find it hard to get new jobs because of the stigma of being ex-NOTW employees, they could argue that NOTW robbed them of their professional reputation and possibly sue NOTW and its executives on that basis.
I will admit that the possibility of getting sued for running a company in such a disreputable manner that you drag down your employees with you is not a risk that I had previously considered. But we now see that such a thing could play out as a consequence of a company hiring people to do illegal hacking, or turning a blind eye to hacking, in other words, failure to enforce ethical business practices and appropriate privacy policies. Here's what the Guardian wrote on the subject around the 1.52pm mark on their July 10 live blogging of the NOTW scandal:
So, there you have one more risk of bad corporate governance: Revelation of the company's corrupt practices damaging the employment prospects of your employees, leading to lawsuits. And to think it all started with a voicemail PIN number being guessed or social engineered.
In the last 6 days we have seen massive proof of that as the News of the World (NOTW) phone hacking scandal has erupted onto the world stage, spewing a toxic mix of consequences, the like of which we have never seen before.
Consider anyone who owned stock in BSkB. I documented their bad news yesterday. And consider any innocent employees of the News of the World who are suddenly without a job. If those people find it hard to get new jobs because of the stigma of being ex-NOTW employees, they could argue that NOTW robbed them of their professional reputation and possibly sue NOTW and its executives on that basis.
I will admit that the possibility of getting sued for running a company in such a disreputable manner that you drag down your employees with you is not a risk that I had previously considered. But we now see that such a thing could play out as a consequence of a company hiring people to do illegal hacking, or turning a blind eye to hacking, in other words, failure to enforce ethical business practices and appropriate privacy policies. Here's what the Guardian wrote on the subject around the 1.52pm mark on their July 10 live blogging of the NOTW scandal:
Dismissed News of the World journalists who are unable to find replacement jobs and feel their professional reputations have been severely damaged could have legal grounds for suing News International, according to one employment law source. Owen Bowcott, who is the Guardian's acting legal affairs correspondent, writes about a Lords ruling that could have implications:Bowcott went on to say "Loss of reputation, the 1997 judgment pointed out, is "inherently difficult to prove" but it added that there is an implied mutual obligation of trust and confidence between employer and employee." The House of Lords judgment concluded. "Difficulties of proof cannot alter the legal principles which permit, in appropriate cases, such claims for financial loss caused by breach of contract being put forward for consideration."
"There is a precedent in a 1997 House of Lords judgment that covers the predicament of two former employees of the collapsed Bank of Credit and Commerce International who claimed they suffered the "stigma" of being associated with the ex-employer that put them at a "serious disadvantage" of finding new work. "In [Malik vs BCCI] the House of Lords upheld, in principle, the right of innocent ex-employees to sue a former employer for common law damages where revelations concerning the employer's corrupt practices had damaged their prospects of future employment in the industry," one employment expert suggested. "Corruption was assumed as a hypothesis for purposes of the decision"."
So, there you have one more risk of bad corporate governance: Revelation of the company's corrupt practices damaging the employment prospects of your employees, leading to lawsuits. And to think it all started with a voicemail PIN number being guessed or social engineered.
Subscribe to:
Posts (Atom)














