Saturday, February 10, 2007

4th Annual Enterprise Security Asia Conference

4th Annual Enterprise Security Asia Conference

A big thanks to the folks at AC-Nergy who put on an excellent conference in Kuala Lumpur last week: Dyanna, Jin Yin, Christopher, and Andrea. Also to chairpersons Michael Mudd of CompTIA and Stan Singh of PIKOM.

The two sets of slides that I presented can be found at the newly re-launched Cobb Associates site. And a quick reminder to (ISC)2 attendees: this event is approved by (ISC)2 for CPE credits.
.

Wednesday, February 07, 2007

Meet the new OS, same as the old OS: AV, Vista, and Microsoft MS-DOS 6

News that Microsoft's own anti-virus [AV] product does not do a good job of protecting the new Microsoft Vista operating system will come as no surprise to the infosec "old guard" who remember Microsoft's first foray into anti-virus back with MS-DOS 6.0 in 1993. A detailed deconstruction of this product's shortcomings was written by one of the early AV pioneers, Y. Radai at the Hebrew University of Jerusalem. He graciously allowed me to reprint it in my PC and LAN security book and a copy is archived here in an Adobe PDF.

Unless you are a real AV history buff you may not want to read the whole thing (and if you are a real AV history buff you've read it already). But everyone should take note of the final sentences where Radai summarized the effects of Microsoft's decision to make its own AV and bundle it with the OS:
True, many people who have never before installed AV software will now do so, and this seems to be a benefit. However, they will be under the false impression that they are well-protected.
Enough said? After all, few things are more worrying to an information security professional than someone having a false sense of security. One of them is a lot of people having a false sense of security.

And who are these folks who just gave Microsoft Live OneCare a failing grade? Virus Bulletin, which has a sterling reputation for objective AV testing. If VB says a product does not do a good job, you can rest assured it does not (of course, depending on the product you are using, the assured rest may not come easily).

Sunday, February 04, 2007

More VA Data At Risk? Reminds me of last summer

Looks like another black eye for the Department of Veterans Affairs. A hard drive containing thousands of unencrypted records apparently went missing. Here is what I wrote last summer for a local magazine, after the BIG data leak at the VA:

During a hotter than average summer you might think the only exposure problems we face in Saint Augustine are those caused by the UV index. And it would be nice to think the only chills we've been getting come from ice cream or the ice in our drinks. Unfortunately, some folks in town have been receiving chilling news about their personal exposure. It goes something like this: "Information identifiable with you was potentially exposed to others."

In fact, if you were one of the more than 26 million American veterans whose data was on an external hard drive stolen from the home of a Veterans Affairs employee in May, you will have read those words already, in letter from the VA. What sort of data are we talking about? According to the letters that started going out in the first week of June: names, Social Security numbers, and dates of birth, as well as some disability ratings. That is enough information to get an identity thief started, running up bills in your name.

Sadly, some local veterans who bank with VyStar were hit with a double dose of chilling news about their personal exposure. They also received letters from the Jacksonville-based credit union informing them that hackers had acquired their names, addresses, Social Security numbers, birthdates, mothers' maiden names, and email addresses. The exact number of people affected was not revealed by VyStar, which would only say it was less than ten percent of its 344,000 membership. However, that type of data would give an identity thief a running start, in several directions. For example, the email addresses could be used for very targeted and effective "phishing" attacks in which falsified email is used to trick recipients into revealing such valuable data as account numbers and passwords.

I know that at least one of the affected Vystar members was a local resident, because I had breakfast with him recently, at Jasmine's on San Marco. Over a latté and breakfast burrito he lamented that he had received letters from both VyStar and the VA. Perhaps a little too glibly I said that if he got a third letter we would write an article about him. That afternoon I noticed a new security breach exposing Floridians. Approximately 133,000 Florida driver and pilot records were on a Department of Transportation laptop stolen from a government vehicle in July.

So how should you react if this happens to you? Are you at risk if your data is exposed? What can you do to protect yourself? To answer these questions, begin by examining any information you have about the exposure. For example, here's what Vystar said about that incident: "Vystar has no indication that the stolen data has been used or will be used for identity theft or fraud."

Fortunately, you don't need to be a computer security expert to see through that one. Your first clue that this is not a very reassuring statement is how the data was exposed. According to Vystar's own report, hackers stole it. These days, that is not good. In the good old days of mainframes and early personal computers the term "hacker" did not necessarily mean someone who broke the law, more like someone who broke into the technology just to see how it worked. Hacker today can mean someone who steals bank records, either for their own nefarious purposes, or for resale to someone even more nefarious. There is a thriving black market in identity data. Organized crime is a big player in that market.

Even if your data was on a computer stolen at random, which may be the case with the stolen VA laptop and hard drive, you need to be wary of assurances that "there is no indication the data has been used for identity theft." Any computer security professional would want to add the word "yet" to that statement. After all, how can you tell if the data has been used? The beauty of all things digital is that they can be copied over and over without any indication that they have been copied. A data thief seldom erases the data, just lifts a copy so you are none the wiser.

Another assurance that bears closer inspection is this one, as seen in the VA letter: "Authorities believe it is unlikely the perpetrators targeted the items because of any knowledge of the data contents." Well, contrary to the VA's claims in the letter, the VA employee had been taking home the same sort of data for years, with permission. This implies that someone could indeed have targeted the data; but even if they didn't, your average thief today probably knows a thing or two about computers. Imagine getting that computer home and finding all that data. Knowing that it could be worth dollars per record might tempt a common burglar to branch out into data trafficking.

At this point you might be wondering what happened to all the marvelous computer security technology you see in movies: passwords, fingerprints, encryption. These are not science fiction. They exist and they are relatively effective, cheap, and easy to use. The reality is that they are not used nearly as much as they should be. One way you can tell is to read between the lines of an "exposure" announcement. The VA made no mention of passwords; the Department of Transportation did. You can bet the DOT data was password protected, the VA data was not.

So what can you do when your data is exposed by one of these incidents? The first step is to take advantage of any resources provided by the "breachee," the entity whose security was breached, thus leading to the exposure. For example, VyStar has provided a lot of information about Internet security on its web site. In addition, it has said it will provide identity theft protection to all those affected by the breach. This is a smart move because it helps to limit the company's exposure to damage claims. Several years ago I provided testimony in a class action suit brought by another group of military personnel whose data was exposed as a result of the TriWest security breach in Arizona. The victims were seeking to force TriWest to pay for identity theft protection. As far as I know the case is still unresolved, but the security lapse has already cost TriWest several million dollars.

The primary defensive action you can take, regardless of what the breachee does, is place a temporary fraud alert on your credit bureau account. This should alert you to anyone trying to open new accounts in your name. To place an alert contact one of the three main agencies: Equifax (www.equifax.com or 800-525-6285); Experian (www.experian.com or 888-397-3742); TransUnion (www.transunion.com or 800-680-7289). The alert is free, good for 90 days, and may get you a free credit report. In fact, getting a credit report on yourself is a good all-round defensive measure, even if your data has not, to your knowledge, been exposed. If it has been more than 12 months since you saw your credit report, check it out, via the contacts above, to make sure it contains no surprises.

None of this implies that the party whose inadequate security made the exposure possible is off the hook. The VA is currently under pressure to improve security and do more for the victims. You can learn more at www.firstgov.gov/veteransinfo.shtml. Sadly, if you visit the site created to keep vets informed about the May incident, you are greeted by news of an August incident. That's right, another computer went missing, this time exposing the insurance records of tens of thousands of vets.

Is there any good news? Well, I can say that the VA/VyStar victim I know has not received a third letter, yet. I'd like to say I see light at the end of the tunnel but, based on my 25 years of work against computer fraud and abuse, I don't. So be prepared to act in defense of your identity, keep abreast of new incidents, and cast a critical eye over any letters you receive. I'm afraid more of us will be over-exposed before things get better.

Friday, February 02, 2007

What's Up With Dataflation?

A few years ago I coined the term 'dataflation' in an effort to focus attention on the possible negative effects of widespread exposure of personally identifiable information (PII, like name, address, Social Security number, mother's maiden name, pet's name, credit card number, and so on). My thinking had been pointed in this direction by the large number of security breaches in the first half of 2005 and the massive amount of PII that they exposed (66 million records).

Plenty of people were focused on the immediate effects of this phenomenon and the media paid attention. We saw articles on What to do if it happens to you. How to protect your identity online. What companies should do to prevent such breaches. A lot of good advice was dispensed and recent figures show it might be having a positive effect. (Remember: "The best weapon with which to defend information is information.")

However, there was no immediate sign of improvement during 2005 and I continued to focus on the cumulative rather than individual effects. What would these exposures mean to the current and future value of information? How would this impact trust within society? What would be the effect on commerce, particularly e-commerce? And what effect does trust have on growth? (There are indications that more trust = stronger GDP growth, starting perhaps with the 1997 paper by Knack and Keefer, click here for a list of articles).

To me it seemed like there had to be some sort of inflationary effect on personal data, hence data-flation. Perhaps, I wondered, the more bits of personal data pertaining to you that are known by everyone, the less value each piece of that personal data would have, notably when it comes to authenticating you, to a system, a merchant, a bank, a government agency, and so on.

My article for TechTarget on the subject of dataflation was published in October, 2005. Then I witnessed the massive exposures in early 2006 which included the 28.6 million veterans (including a friend of mine who was also 'exposed' at the same time by his credit union). So I continued to think about dataflation. When I was invited to speak at Interop Moscow I chose it as the topic of my presentation.

Then a strange thing happened. In the Q&A session after my presentation, one member of the audience told me that you could find just about any data about anyone in Russia on the streets of Moscow, sold on CD. Unfortunately, I didn't have enough time or Russian to go and buy any of these CDs, but several people confirmed that large numbers of records were sold to these street-level data vendors by employees of various government agencies. We did not have enough time for a protracted discussion, and there was something of a language barrier, but I think I sensed an implied statement: "Our data is hopelessly exposed and our society/government/economy is not crumbling."

Now, I am not an expert on the Russian economy, but I think one could argue it is not doing as well as it might. One might further suggest that a lack of trust is one reason, although proving this statement is probably an entire masters or even doctoral thesis. Furthermore, I am open to pondering that implication. Maybe dataflation won't happen and everything will work out. It's just that, when you look at a compilation of the ever-increasing numbers, such as this amazing table at Privacy Rights Clearing House, it is hard to believe we are on the right track.

Wednesday, January 24, 2007

What's Next next? A new time for Daylight Saving Time

Just a quick post to point out the change in DST this year which will require some systems to be patched. I have some tech details over on Cobb on Tech. From a security perspective, the possibility exists that someone could exploit mis-matches between systems that correctly auto-update time on on 3/11/2007 and those that do not (mis-match being the non-technical term for who-knows-what-kind-of-synchronization-errors). One area to watch [apologies for the pun] will be access control devices for both perimeter and system security.
.

Sunday, January 21, 2007

Much Anticipated Brussin Blog Now Online

Attention all serious blog readers! There's a new tech blog on the block and I'm betting it will become a "must-read" for anyone serious about Web 2.0, Business 2.0, and the whole intersection of technology and business. The blog is called "What Comes Next" and the blogger is David Brussin.

While David Brussin might not be a household name in high tech households, I would add the caveat "yet." I've been in the high tech field for over 25 years and have yet to encounter a sharper mind than Brussin's. It was no coincidence that he was named to the 2004 list of the world's 100 Top Young Innovators by Technology Review, MIT's Magazine of Innovation. Brussin has that rare combination of a. technical brilliance (he was building serious commercial networks before he graduated from high school) and b. business acumen (he had co-founded two successful startups before he was thirty, and both were snapped up by public companies).

Then there is c. he is very articulate. So, not only does Brussin come up with valuable and sometimes highly complex insights, he can put them into full sentences that are easily understood. Now, you sometimes meet people who have a or b or c. Occasionally you meet people with two of the three, but rarely do you encounter someone who has all three AND a sense of humor AND above average scores in tact and diplomacy.

So check out Brussin's blog. I hope you find it as interesting as I do.

Thursday, January 18, 2007

Small Business Continuity Gets a Boost: IMCD from ContingenZ

What if you could buy a large amount of expert advice on how to keep your business running despite everything that fate throws at you? Want to learn how? Read on...

Everyone knows that small businesses are the true powerhouse of free market economies, whether in the US, the UK, the EU, or beyond. Most people also know that the failure rate of small businesses is very high. What a lot of people don't realize is that many of those failures could be avoided if only small businesses did a little more advanced planning. This fact gets lost in the seemingly endless array of factors that adversely impact small businesses: fire, flood, wind damage, snow days, power outage, earthquake, employee theft, virus outbreaks (biological and digital), hacking, abrupt departure of key employee(s), prolonged office evacuation due to nearby toxic spill, over-eager customer driving through the front window and mowing down the file server, unexpected incarceration of treasurer, public relations snafus. All of these happen and it is hard to predict when (you don't have to believe if global warming to know that the weather has been mighty unpredictable and frequently severe in recent years).

But all of these things have something in common: they are incidents, and incidents can be managed. Hence the art and science of Incident Management. One of the finest practitioners of this art is my friend Michael Miora who started a company called ContingenZ. The idea was that he couldn't be in two places at once and there just aren't enough incident management experts to go around meaning that smaller businesses couldn't afford to hire one. So why not distill his expertise into a piece of software that any business owner or manager can use to create an incident management plan and business continuity strateg precisly tailored to the specific needs of the company?

And that is what Michael Miora has done, working with someone I also know quite well, Mike Cobb. Both Mike and Michael are CISSPs with a ton of experience in business management and data security. The product they came up with, IMCD, is now available in two versions. The more expensive Pro version is suitable for larger companies (and some very large companies are using it right now). The brand new and considerably less expensive Small Business Edition is ideal for small firms. What is more, businesses large and small can download a trial copy of IMCD to check it out.

This is a product that could literally save your business and it may well make you a ton of money even if--fingers crossed--you never have a single incident to deal with. How? Consider what happened to one of IMCD's first customers, a small firm specializing in shipping antiques that was in the running to get a big fat contract from a major shipping company. Like many big companies establishing new vendors, this one was doing due diligence. Did the small company have a business continuity plan? Yes, replied the small company. Can we see it? asked the big company. Umm, yes, well, it is sort of...informal, replied the small company. No formal plan, no big contract. And so the small company used IMCD to formally document its business continuity plan in a complete set of highly professional documents automatically generated by the software.

Result, the company that bought IMCD got the contract. And should anything ever happen to disrupt their business they are well placed to "keep on trucking." Scobb says "Check it out!"

[Disclaimer: I don't own stock in this company. Even if you buy a zillion licenses to IMCD I won't get a single penny. On the other hand you will make two of my friends very happy.]

Monday, January 15, 2007

Prairie Dogs and Information Security

I have blogged elsewhere about the Bush administration's interference with science. In the Union of Concerned Scientist's great catalog of these crimes against reason there's an interesting example of why it is important that everyone learn the basics of information security. The example concerns the white-tailed prairie dog (aww shucks, ain't he cute y'all).

The scientists claim that Julie MacDonald, of the Mountain Prairie Regional Office of the Fish and Wildlife Service, "directly tampered with a scientific determination by FWS biologists that the white-tailed prairie dog could warrant Endangered Species Act protection, and further, prevented the agency from fully reviewing the animal's status." A strong allegation. Any proof? How about Microsoft Word "track changes" edits? Yep, when you go altering reports written in Word you best be careful. Word tries hard not to forget. Check out the detailed sample here, illustrated in a pdf file that shows just what the changes were. As evidence of the scientists' claims I think the phrase that comes to mind is "dead to rights."

And change tracking is not the only way that Word coughs up secrets. Ever open a Word doc with Notepad or Texpad (which happens to be my favorite text editor)? You may well find stuff that doesn't appear in the document itself, stuff you thought you had deleted. Similar problems can occur if you are careless with Adobe Acrobat documents. See a great example of the Word issue (involving Tony Blair, Colin Powell, and the war on Iraq) on Richard Smith's fascinating Computer Bytes Man site.

The point here is that companies using Word or Adobe documents to store and distribute information need to know exactly how those programs work so those documents don't store any information that you would prefer to keep secret.
.

Tuesday, January 02, 2007

Divining the Devilish: Factors affecting the future of Microsoft Vista

Having previously complained about a lack of "compare and contrast" coverage of Vista versus prior Microsoft operating systems, I feel I should weigh in with a little C&C of my own (with the caveat that this is a blog, not a white paper, so you won't be getting footnotes and fancy formatting—those cost extra).

We know that Vista will be attacked by hackers of all stripes. Only time will tell how well Vista resists attack. One thing to look for in the months to come is the emergence of any "class of vulnerabilities." These are not fragile students, but problems of similar type, for example, memory leaks or buffer overflows. You don't need to get too technical to spot this. Just watch for a Vista hack to be revealed and then patched, only to be followed by news of another hack via a minor variation on the previous technique. This would strongly suggest that code review has not been rigorous enough. and could well presage the sort of rolling patch situation we are in with XP and Office products. Painful as that patch situation is, the early emergence of evidence that Vista is going to be in the same boat will further discourage adoption.

And herein lies one of the variables that emerge from a C&C: rate of adoption. When Windows NT was first released it attracted very little attention from hackers (defined as people who like to pick things apart, for a range of reasons). They were heavy into UNIX back then because if you wanted to explore big and interesting networks, UNIX was the OS you would most likely encounter (if you wanted to do more than explore, the money was also in UNIX and/or mainframes). This created a false aura of security around NT. While UNIX hacks were being announced all the time, NT was relatively--albeit temporarily--unscathed.

But two things happened to change that. One was considered a success for Microsoft, growing adoption of NT in corporate America, as well as the government, the military, and colleges. The other was considered a success for the PC world: the widespread availability of cheap CD-ROM drives and CD-burners. No longer did you need a foot high stack of floppies to install or steal NT. Just a thin, slim, light and easy to conceal CD. Around the 1996-98 time frame you could buy a pirated NT CD for a couple of bucks in Hong Kong or get someone to burn you copy. I remember the first DefCon at which hackers started getting excited about NT. Part of that excitement came from the simple fact that NT was accessible. You could get at it in order to play with it.

So, two factors to consider for Vista are: ease of piracy and extent of adoption. Today we have much faster pipes down which to stuff pirated code and DVD-burners are standard equipment. The strength of Vista's copy protection will be a factor (one that is already under concerted attack). As to adoption. The very thing that Wall Street analysts are mumbling with foreboding--slower than hoped for Vista upgrading--could work to Microsoft's advantage. Several classes of hacking activity are all about the installed base (c.f. first Word macro virus of 1995 after Word doc format had become de facto standard).

But we must also contrast as well as compare, and the landscape of computer abuse today is much different from what it was a few years ago, most notably it is better-funded and more criminally-inclined. That will serve to negate the copy protection obstacles. Suppose you're a criminal who expects most banking systems to be Vista-based by oh-eight. Spending some serious money on cracking Vista in oh-seven might strike you as a good investment (and like they say, anyone who thinks organized crime doesn't make investments hasn't been to Vegas).

However, the most helpful history lesson at this juncture may well be that of "risk displacement" (also discussed here). Even if Vista holds up well in the face of concerted attacks and provides greater protection to users against some forms of information abuse, the level of effort expended to abuse information is unlikely to go down. Not to be flippant, but it is likely to go around. Improved technical controls typically lead to more concerted social engineering attacks (you put a password on the system, the attacker gets the user to reveal the password, and so on).

Just so we are clear, this is NOT the fault of Microsoft. This is the fault of human beings in general--flawed creatures that we are--and the failure of countries around the world to elicit better standards of behavior from their citizens. What would be wrong of Microsoft would be to foster the notion that Vista will somehow make the world a safer place for computing. With three "most secure yet" operating systems under its belt, and IT security spending at all time highs, Microsoft has to know that things are still not very safe out there.
.

Sunday, December 31, 2006

Told You So: Spam surge drives net crime spree

Not it's not my imagination: Spam is on the rise and criminals are to blame. Brings new irony to the phrase "there ought to be a law against it" and deeper for Bill Gates promise that spam will be solved in 2006.

p.s. Wonder why it's spam and not SPAM but sometimes Spam? Get the official word here.

Wednesday, December 27, 2006

Whole New Security Vista? There's a target painted on new Microsoft OS

"Hi-tech criminals are looking forward to the consumer release of Windows Vista, say security experts." BBC News. Why? Because it is presents new opportunities, new possibilities for abuse.

"What?" you say, "surely this is the 'most secure version of Windows yet.'" (As proclaimed by Microsoft.) According to the BBC article, if new features won't get you to upgrade to Vista, security enhancements should, according to the co-president of Microsoft's platform, products and services division, Jim Allchin,. Vista will still be worth getting, thanks to its better defenses against phishing attacks, spyware and other malicious code, Allchin told the BBC. "Safety and security is the overriding feature that most people will want to have Windows Vista for."

Unfortunately, lack of historical perspective is widespread in the marketing sector of the IT industry, and too often it spreads to the media that covers IT. Where are the articles that compare and contrast the claims for Vista with those made for Windows NT, which was also claimed to be the most secure version of Windows yet, as was XP Professional? (Notice a pattern here?)

Believe it or not, I have some sympathy for Microsoft at this point because it is faced with a three-pronged dilemma (and we all know those three-prongers can be painful). Here are the three in play at the moment:
  1. Claiming that something is the "most secure ever" is like painting a target on it. I recall arguing against the launch of a web security certification program back in about 1996 for this very reason. Hackers were big into defacing web pages at the time and locking down a site was pretty difficult with the tools available. So putting a "Certified Secure" sticker on the home page would have been a red rag to a herd of hackers.
  2. But Microsoft had to claim Vista wasthe most secure ever because there don't seem to be enough other new things in the OS to warrant paying the asking price for the upgrade.
  3. But Microsoft is a huge company and [IMHO] it is hard for huge companies to achieve excellence in anything, particularly where there are competing goals.
And writing secure code is a major case of competing goals. The whole thrust of computing over the last 25 years has been broader, faster, smoother access to data, often using cutting edge tools. Security is all about tried and tested tools and roadblocks, not for the sheer joy of being obstreperous--for example, in the manner of Dilbert's 'Mordac the Preventer' character--but due to the classic dichotomies between "free & open" versus "safe & secure," and so on.

At the turn of the year it is always interesting to consider what the future holds. Will Vista be a boon or a boondoggle? Developments on the security will likely be the deciding factor.

Thursday, December 21, 2006

California Hacking on Such a Winter's Day: USC hacker sentence after UCLA hack

I thought the juxtaposition of these two stories was interesting, on the 12th and 21st of December:
UCLA warns 800,000 people that hacker gained access to their personal information
USC hacker sentenced to 6 months of home detention
Now add this November nugget to the mix:
Rising cost of data security breaches: $182 per record
Now consider this: the June 2005 breach of USC's online student application system compromised 275,000 records and caused the university to shut down the site for 10 days and the perp gets 6 months home detention. But if the cops had found one twentieth of an ounce of crack on the guy he would be going to jail for a minimum of five years. Somehow, something is screwed up here.
.

Saturday, December 16, 2006

Internet Explorer 7 User Interface Fiasco: Am I nuts or not?

As astute readers will have surmised, I'm in my mid-fifties. At this time in a person's life it's not unusual to wonder, from time to time: Am I going soft in the head? For me, one of those times was my first use of IE7. Here is a little bit of what the program looked like when I installed it. Astute observers will observe there is no menu bar (File-Edit-View -etc.).
Because web browsing is now the thing I do the most on my computer--actually writing within the web browser as I am right now--I like to place my browser controls in a particular configuration. And I like some sort of consistency. So I set to work on IE7. I found you can get the old menu bar to show up, but the process is a pain. Furthermore, any further configuration hits the wall pretty quick. For example, the IE7 toolbars won't move, for me. This was so unexpected that I thought for sure my senile dementia was setting in. There I was, clicking and dragging and nothing was happening. In fact, the default UI is such a big departure from a. the norm, b. common sense, I deduced that, because I couldn't 'fix' it, I must be losing my marbles.

But no! It is Redmond that has lost its marbles on this one. How do I know? Another blog came to my rescue. I found this "Blog of Fusion" and began reading. Phew! It wasn't just me. Others were having the same "issues."

What had me really scared--before I found that blog--was an illustration in an article at microsoft.com. See that "Classic Menu" option? I couldn't find that in my copy of IE7, as shown below. Then I noticed the article was published in June. I had installed the 'shipping' version of IE7 in December. Tthis seems to be evidence that Microsoft--at one point in the Beta--allowed what the shipping version does not allow.

Check out the screen shots. My version of IE7 doesn't allow me to drag toolbars like the article shows. Seems they must have ditched this stuff during the final build and, with breezy indifference, failed to correct their own web site. BTW, that page at microsoft.com is the top result if you Google: internet explorer 7 toolbar customize.

So, can you imagine how many thousands of people around the planet are going to a. try to customize the IE7 toolbar, b. get stuck, c. Google to that page, d. waste hours resolving the resulting contradictions?

I mean no offense to the poor microserf who wrote that stuff--he probably asked them to take it down and they didn't. When I was a Microsoft Vendor, everyone that I met in Redmond seemed smart, pleasant, and very earnest, but also out of touch with reality. And the entities to which they reported within the organization were more than a little messed up. In short, a classic example of how a bunch of smart, well-intentioned people can add up to a dumb bunch of decisions. (We are seeing another of these dumb decisions play out right now: "Improved security is the rasion d'etre for the next expensive Windows upgrade.)

One specific criticism of IE7 that I haven't seen elsewhere is that the row for the tabs of the new tabbed browsing feature (a feature that got me using Firefox as my main browser several years ago) seem to be fixed on the same line as the main buttons. This gives decidedly less space to the tabs than you have in Firefox. Also, if you remove the traditional menu, the View command is gone. There is no button for it. So the only way to get the traditional View menu item back is a right click in a select area of the tab/button bar.

Makes no sense to me, and thanks to fellow bloggers, I'm pretty sure I'm not senile, yet.
.

Wednesday, December 13, 2006

Need Help With Computer Security? Check cobb.com

Just a quick reminder that you can find a bunch of free articles about computer security at the cobb.com web site. Enjoy!

Note This Blog: Dare Not Walk Alone is now with THINKFilm

The civil rights film that I have been involved with for the past few years, Dare Not Walk Alone, is making progress!

A major update on the film and related projects, like the campaign to rebuild the house at 521 North Woodlawn that was featured in the film, has just been posted on the Dare Not Walk Alone blog. Check it out!

Monday, December 11, 2006

Blogs of Note: I guess scobb's non-blog made it

Apparently there is something called "Blogs of Note" and this blog was listed there today. Not sure how much of an achievement that is, but thanks to anyone who might be responsible. I write mainly for my own sanity, but it's encouraging to think some people are reading what I write. To that end may I shamelessly plug some of the other blogs I have been building. They are not all in full flow yet, but getting there.
Obviously, the idea is to group my posts around subject matter. Hopefully it is not too ambitious. Time will tell. I think scobb's non-blog will continue to be the place that I put my thoughts on security.

More Secure Windows May Not Help: BusinessWeek makes a very good point

There's a nice article in Business Week that meshes with my view of computer security. Let me spell this out.
  1. Microsoft is spending a lot of money right now to encourage people who use Windows to upgrade, for a fee, to a new version called Vista.
  2. To justify the fee for the new version Microsoft is talking a lot about how much more secure Vista is than previous versions of Windows.
  3. All this talk may be creating an expectation that computer users will encounter fewer security problems in the future.
  4. This expectation is probably false.
The only way to make computing significantly more secure than it is today? Raise the general standard of behavior of people on this planet.

This may sound like a tall order--and it is--the task is not insurmountable. Law and order can eventually replace lawlessness, e.g. the Wild West. Standards of behavior within any given geographic entity can be improved, e.g. reduced drinking and driving in UK/US/et al.

Of course, these are changes that take decades to bring about. All the more reason to commit to the process now, rather than later. Remember, technology cannot create security; the sooner people set aside dreams of security based on the false promise that it can, the sooner the root problem will be addressed, and the better the interim security strategy will be.

Wednesday, November 29, 2006

What Are Security Breaches: Trousers they are not

Are you new to the world of computer security? If so you might appreciate a little orientation lesson.
  1. Computer security is about protecting information that is processed by computers, otherwise known as data, and the processes that use such data. This includes, for example, information about your bank account and how much money you have in it [data] and your ability to withdraw that money [process]. You want the data to be both secret and correct; and you want the process to work on demand. These are the three main pillars of computer security: confidentiality [secret]; integrity [correct]; availability [on demand].
  2. Computer security can also be referred to as information system security although technically an information system might include other elements besides just computers.
  3. Information system security is a part, or subset, of information security [because information security includes stuff that is not on computer, like a set of design drawings or company secrets whispered from one person to another].
  4. Information security can also be referred to as information assurance.
Suppose you are a bank and you have procedures and mechanisms in place to prevent anyone but an account holder from finding out how much money is in an account. If someone defeats those procedures and mechanisms the result is called a security breach, as in "my cannons have breached the walls of the city" and "Once more unto the breach dear friends."

Failure to prevent the breach may cost the bank money. The bank might be sued by the account holder. The bank may have to divert staff from normal duties to a review of records to determine the extent of the breach. If the breach exposes confidential information about a lot of customers the bank might lose some existing customers who are angry about this, and the marketing dollars that the bank spends to attract new customers might not work for a while due to bad publicity.

In my previous posting I cited a study that put a dollar amount "per record" on the cost of security breaches. I think the number is higher than many businesses realize.

Wednesday, November 15, 2006

Rising Cost of Data Breaches: $182 per lost customer record

My hat is off to Larry for his study of security costs. In some ways this latest Ponemon Insitute study is probably more indicative of the state of things than the annual CSI/FBI survey.

If you are trying to get your company to do a better job of securing data, try multiplying the number of customer records your company processes/stores (CRP) times cost of loss per record (CLR) and you might have a good starting point for budgeting project to overhaul your current security (CRP x CLR = the hit to profits from any single incident in which CRP number of records are exposed).

Larry figures the figure for CLR is $182. A breach exposing 10,000 records is thus a $1.82 million problem. Spend that amount on security upgrades and you arguably save an unknown number of exposures (there is nothing that says you won't get hit twice in one year for example). Spend anything less than that and you are playing a high stakes game of chance with your business and, if you are a C-level exec or board member, with your personal and professional liability.

And don't let your managers fob you off with "these studies are just scare tactics." Tell them I know Larry Ponemon and Larry Ponemon is no scaremonger.

Friday, November 10, 2006

Trust in Electronic Voting Eroding Faster Than Florida's Beaches

Yes folks, once again Florida leads the nation in eroding public trust in electronic voting systems. Check out the story so far in Sarasota. Lots of familiar themes and players. Zero doubt in my mind that the books were cooked (based on 30 years of experience with fraud, audit, and computer security).

In keeping with what I have blogged elsewhere, I predict the public will never trust electronic voting as much as paper and pencil ballots. And rightly so. I've worked with computers in all manner of situatons, from auditing oil companies with mainframes to building mission critical networks and securing mobile devices. They work quite well for a lot of things but not everything. I just don't see how you can make a trustworthy voting system out of them. So why bother? What is there to be gained?

Monday, November 06, 2006

Save Millions on IT: Delay Vista Upgrade

Come on IT people, this is a no-brainer. Don't upgrade to Vista, yet if ever. At least wait until Service Pack 1 has been released and tested (which I predict will be late 2007, early 2008). Here's five ways you save:
  1. Fewer install hassles--let others learn the hard way and smooth it out for you.
  2. Lower software costs--avoid premiums [and headaches] on new versions.
  3. Reduced learning curve--if your users get Vista on their home PCs in the first half of 2007 they'll be training themselves.
  4. Reduced learning costs--as Vista training becomes commoditized.
  5. Hardware savings--the Vista delay (>2 years) has created a huge hardware surplus.
  6. Cut analyst bills--don't pay a dime to anyone who told you Vista was on track and early adoption was a good thing.
Twenty years of solid historical data show that the first version of Microsoft anything is:
  • shipped far too late but much too soon,
  • more trouble than it's worth,
  • often followed by successive versions which actually deliver on the original promises.
Remember, ad campaigns to the contrary, Microsoft doesn't care about anyone's business but its own. Otherwise it would not have acted in a way that is likely to cut $4 billion from PC sales this year. (Of course, I would also argue that any PC execs who believed Microsoft on delivery dates should be canned, sans parachute.)

About the only redeeming qualities Microsoft can rightfully claim right now is the relative stability of XP and the massive philanthropy of its founder.

Stephen

Thursday, September 14, 2006

Wired on Top of Splogs

Correct me if I'm wrong, but Wired seems to be leading the discussion of splogs, those sick abuses of blogging that merely serve to line some sad maladjusted scammer's pockets.

Spam + Blogs = Trouble by Charles C. Mann
How to Fight Those Surging Splogs by Nicole Lee

Proof of another scobb rule: People Will Mess Up Every New Technology for Profit. Of course, there will be counter-attacks as legitimate interests fight back. But don't you just wish humans as a whole were less greedy and just generally better behaved?

Thursday, September 07, 2006

Risk displacement and hardware viruses

Check out this timely column from Adrian Kingsley-Hughes:

As Windows becomes harder to crack, could virus writers start to target hardware? "On August 25th, security firm Symantec engineers announced they had discovered a virus that leveraged a flaw in the AMD64 CPU. This virus, called W32/W64.Bounds, was capable of binding itself to Windows executables in such a way that made it hard to detect. However, it's now been shown that this virus doesn't have anything to do with in AMD CPUs, but instead with the X86-64 instruction set itself. But could this be a sign of things to come?"

Anyone who has heard me talk about risk displacement will know my answer to his question: Yes.

As you harden security in one area, softer areas will be targeted. Savvy security managers at large companies learned this in the nineties. As they began to install firewalls most attackers moved on to target other, less protected networks. In fact, this phenomenon is at the heart of the Turntide anti-spam technology that I helped develop. We bet that spam software would not waste bandwidth trying to stuff spam into networks that appear incapable of accepting spam at a high rate of messages per second. We were right.

And as Adrian points out in his column, widely deployed hardware is an attractive target for malware authors. The first Microsoft Word virus did not show up until Word was the most widely used word processing application. Email viruses did not appear until email was widely used. So the big variable in the emergence of a hardware virus threat is the extent to which a "hard to crack" version of Windows is deployed.

BTW, Adrian's web site is a gold mine of useful information about PC hardware and software, check it out at http://www.pcdoctor-guide.com/wordpress/.

Wednesday, August 30, 2006

No, I won't live and breathe your product!

Why do software makers think you want to live and breathe their product? More and more applications seem to think they are the only reason you bought your computer. Even drivers are getting this way. I have recently installed HP printer drivers that are more than 50 megabytes. They add photoviewing, image management, file transfer, camera interfacing stuff that I don't want. They take over file associations. I bought the printer to print. Period. Am I the only person who just wants an HP printer to print? Or have I missed some liefstyle trend where printers are all about how I see the world and relate to it, digitally speaking?

Apaprently I am not the only person who has gotten ticked off...check out Simon Wilson's rant about the 170 megabyte HP driver. That was a while ago...it would be interesting to know if HP as reacted. It would sure be nice to have the option to go "basic driver only" during the install.

Sunday, July 16, 2006

New Microsoft Same as the Old Microsoft?

So Microsoft has spent years perfecting a means of patching holes in its flagship product--the Windows XP operating system--holes that had left XP-based computer systems vulnerable to various types of attack. When your computer is attacked you worry about a number of things, probably three. You don't want strangers accessing your private data (confidentiality). You don't want to your documents messed up (integrity). And you don't want to be denied access to your documents or your system (availability).

Well it seems some recent XP patches are themselves attacking data integrity. I noticed this myself when I came downstairs one recent morning and found my laptop had rebooted itself. The cause of the reboot? The Windows Automatic Update. The effect? A bunch of typing and research was 'lost.' That's right, Windows had rebooted without saving the latest version of my documents (and Microsoft Word did not even offer to recover the work when I re-started it).

I couldn't quite believe this, until I found other people had noticed the same thing. Blogger Tim Rains has a nice piece on this problem and what to do about it.

Thursday, July 06, 2006

Getting the Hang of This

So, maybe the point of a blog is to publish stuff that others will not. Like stuff that I have written but some editor somewhere decided was not worthy of publication. Here is an example. Hopefully there will time for more.

Stephen

Thursday, March 30, 2006

Laptop Thefts, Spam, and More of Same

Sigh...Some computer security vulnerabilities are timeless:

"Fidelity Investments last week disclosed that someone made off with a laptop containing the names, Social Security numbers and other information for 196,000 current and former Hewlett-Packard employees." Sci-Tech Today

The reasons for stealing laptops may change, but laptops used by business people are, by definition, loaded with business information. Now it seems, owing to corporate stupidity, they are also loaded with large amounts of personal information abouts large numbers of persons. The fact that a company like Fidelity had the 401K details of almost 200,000 people sitting on a laptop (instead of on a server in a locked room) is disturbing but sadly not surprising. It is not the first time something like this has happened and we confidently predict it won't be the last. Here's an article on the subject from 2000, ironically published in the HP Chronicle

As for newer vulnerabilities, there is a pretty good blog put out by Sunbelt, a Florida software company. Has some interesting stories about IE, eBay accounts for sale, and bots that might be used for more than spam (which has not gone away the way that Mr. Gates predicted--although this should come as no surprise, given that every major product in the history of Microsoft has been late).

Stephen

Thursday, January 26, 2006

Just in Time: Doom & Gloom for Oh Six

Wow, amazing how fast three months can pass. Here we are, late in January of 'oh six,' and I haven't even issued my annual proclamation about the state of the Internet and e-commerce. However, given my last posting, and my annual predictions in prior years, it probably comes as no surprise that I am not optimistic. Indeed, I can't remember the last time I was optimistic about the outlook for the Internet, maybe it was in the mid-to-late nineties, when I seem to recall a brief lull in virus outbreaks, very little spam or spyware, no phishing and no "for-profit" worms.

Alas, things have gone downhill since then. Sure, I use the Internet for a lot of things and find it incredibly useful. But I do so with trepidation, fully armed with paranoia and a variety of defensive mechanisms. My feeling today is that the incredible usefulness of the Internet is still, for a significant slice of the population, outweighed by the risks. My predictions for 2006? More large-scale privacy breaches, more articles about how some folks are turning away from the Internet, and yet more involvement by organized crime in acts of phishing, worming, and Internet fraud.

Oh, and the usual hand-wringing by countless boards and other bodies set up to "do something about this." Remember folks, we are less than four days away from solving spam, as predicted by Mr. Gates.*

Happy New Year!

Stephen

*Note, for all the things he has done wrong, like break the Sherman Antitrust law, and his failures, like not making Ctrl-Tab work the same in all Microsoft Office applications, I still have to confess immense admiration for Mr. Gates's approach to philanthropy. If only more CEOs, such as those in the drug industry and the petroleum industry, would give of their wealth the way that he has, kids today might not find it so hard to be unselfish.

Sunday, October 30, 2005

Web Threats Do Keep Users Away

According to Matt Hines, reporting a study by Consumer Reports WebWatch in eWeek on October 26, "U.S. Internet users are cutting back on the hours they spend online, shunning e-commerce and refusing to give out personal information as a result of the rising tide of Web-based crimes related to identity theft...As a result of those concerns, at least 30 percent of the 1,500 people interviewed for the survey said they have reduced the amount of time they access the Internet." See Web Threats Keep Users Away

And we are not surprised. We have predicted this for several years, and will go on predicting it until there is a major improvement in standards of conduct on the Internet. Of course, that is unlikely to happen unless there is an improvement in standards of conduct in society in general, which is unlikely to happen while so many public figures continue to act in such a shameless way (think Martha Stewart, Richard Scrushy, Bernie Ebbers, the Rigas, Dennis Kozlowski and Mark Swartz, sixteen Enron executives and counting). It's not just the crimes these people have committed, it's the way so many of them have tried to shrug off their misdeeds, or deflect punishment by professions of faith, or cheerfully gone on with their lives, with no apology to the millions of people whose lives they damaged.

Anyone who thinks this behaviour has no effect on the moral standards of today's children, who are the Internet miscreants of tomorrow, probably hasn't tried raising kids recently.

Stephen

Monday, October 24, 2005

An "Activist Judge" Gets Security Right

I don't know if U.S. District Judge Royce Lamberth fits the current definition of "activist judge" but he recently acted in what I consider to be an admirable way by pro-actively preventing computer security problems. On October 20 he ordered the U.S. Interior Department "to disconnect from the Internet all computer equipment holding data related to trust accounts it manages for American Indians, a decision that could cripple large sections of the agency's computer network."

While this is only the latest in a long saga of actions and responses between Judge Lamberth and the Interior Department, it is a timely reminder of what life would be like if networks were not allowed to be connected to the Internet unless they could prove, to the satisfaction of independent experts, that there were secure. In the latest security review "investigators testified they would give the department's computer security an 'F' grade or "one notch lower than an 'F' ... a 'G.'"

But that is not the most alarming fact in this story. The failing grade came after the department had spent $100 million on security improvements.

And for those who think government agencies are, by their nature, wasteful and incompetent, I am willing to bet there are Fortune 500 companies out there that would fail the same test.

Stephen

Friday, October 07, 2005

Dataflation Column Published

Okay, I took two months off (that's why I called it a non-blog).

Finally, Information Security Magazine published my column on dataflation (in the Perspectives column in the October 2005 issue). An expanded version is also available online here.

Hopefully it will spark some debate about how we cope with the steady unravelling of our secrets and the security they provide.

Stephen