Posts

Showing posts from 2007

The 12th Breach of Christmas (UK)

On the Twelve Day of Christmas the Information Commissioner disclosed to me... 12 hundred wrongly addressed questionnaires ( DVLA Dec 07) 802. 11 Wifi WEP is broken (now takes just a minute to crack) 1 to 10 UK companies PCI compliant (Survey by Logic Group in Sept'07 revealed that only one in ten UK companies have the proper security standards to handle our card payments securely) 9 NHS Trust Breaches (Dec 2007) 8 "Significant" HMRC Security Incidents ( HMRC revealed further "significant" breaches in Nov/Dec 07) 7 out of 10 websites vulnerable ( Cenzic Study Finds Web Applications Vulnerable to attack May 07) 6 ,000 personal records mislaid (by N.I. Driver and Vehicle Agency - Nov 07) " Twenty-Five " Million Records Lost ( HMRC Nov 07) 4 in 10 WiFi routers unsecure (according to a report by Moneysupermarket .com Apr 07) 3 Million Learner Drivers Lost (by Driving Standards Agency Dec 07) 2 Discs Missing ( HMRC discs holdin...

Tis the Season to Discloses Data Breaches

It appears this time of year coupled with the spectre's shadow of the 25 Million unprotected records lost by the HMRC last month, makes an ideal time to disclose data breaches to the UK public. We really need proper California style data breach disclosure laws in this country. So what's new in the last 7 days... Well the NHS disclosed 10 (ten) data breaches at various NHS trusts around the country, one of which involved the loss of 168,000 records of which most were children’s records. In a statement they said "extremely high level of security", but typically do not explain any details about the security measures. It would appear it's the old recipe of sending data on discs again. Fair play to the NHS if proper encryption was used, but so far I haven't really seen any details about each of these 10 incidents and when they actually occurred. I suspect the NHS powers that be choose not to disclose these incidents when they were discovered, but have been forc...

Hidden Flash Cookies

I was speaking to some pals of mine who where asking about deleting Internet history and removing cookies etc from their PCs for privacy. However none of them knew what “Flash Cookies” were and how to find and view them on their systems, let alone change flash settings and remove them, so I agreed to do a post about them. To recap, a regular cookie is a small text file created by websites via your web browser and stored locally on your PC. The file is tiny, which is probably why it's called a cookie. The information within the file is used to store or reference direct information about your habits and usage on a particular website, such as where you went on the website, and what you did. These cookies allows websites to be smart, so the website remembers who you are and what you like, often personalising or tailoring aspects of the website to make life easier or for directed marketing. However a lot of people have privacy concerns about having their surfing habits tracked, moni...

And Yet another UK Government Data Breach

It's the same old recipe...Take one UK Government department, a couple of Discs, copy thousands of records containing sensitive personal data of UK citizens on the Discs unencrypted and then post. Don't these people ever learn! This time it was the turn of Driver and Vehicle Agency (DVA) in Northern Ireland who dispatched two discs by Parcelforce on either 20th or 21st November. The discs holding around 6,000 people's personal details, never arrived at the intended destination, namely the DVLC Headquarters in Swansea. The head of the DVA said the information was not encrypted and included the details of 7,685 vehicles and more than 6,000 vehicle keepers. The data included the keeper's name, address, registration mark of the vehicle, chassis number, make and colour. The DVA also said they were not optimistic that the discs would ever be found. I'm not even going to post any more on this, in fear of repeating myself, just read my last post made last Friday... ...

UK Government InfoSec is Systemically Broken

I don't really like knocking my own government, but their approach to protecting our personal information is like a banana republic. This week another government department, namely the Driver and Vehicle Licensing Agency (DVLA), posted over 100 questionnaires holding people's details including their dates of birth and "Motoring Offence History" to the wrong addresses. The DVLA said it was caused by human error, as if to say it makes this breach acceptable. So this is another government violation of the government's own Data Protection Act, however it pretty pointless fining these government departments isn't it, as it would be like fining yourself. There is just no "stick" to push information security in these organisations, it's not like the private sector where companies are heavily fined and breach publicity has a serious impact on a business brand, which is always important in competitive marketplaces. In my view there definitely needs to b...

The Power of PlayStation

I was fascinated to read about a New Zealand Security guy called Nick Breeze, who conducted brute force password cracking experiments using the processor at the heart of the Sony PlayStation 3. He stated he was able to brute force 8 character passwords using the PS3 processor and a password cracking application in just hours; usually it would take days on a regular desktop PC. This type of password cracking typically defeats the type of protection you find on a password protected Zip file (*cough H-M-R-C missing CD cough*). The PS3 multi-core processor, called the “Cell Processor”, was developed by Sony, Toshiba and IBM a couple of years back. The Sony version of the processor can calculate 256 billion calculations per second, which is faster than 4GHz PC. It manages this speed due to having 7 cores within the processor, so can carry out 7 calculations at the same time, so trying 7 brute force passwords at the same time. Imagine the type of processing power than could be gained by ...

HMRC: CDs should be treated the same as the Server Room

This is rapidly turning into the HMRC data breach blog! I post a lot about this issue at the moment because I have personal vested interest as do many others, there are further developments almost on a daily basis, and for anyone who cares about the security of personal information in the UK, this is still a huge issue which frankly still gives me great cause for concern, and provides much thought about data security in general, which I feel compelled to write about. Anyway, I was in discussion with several people today in regards the missing HMRC CDs, one view was that HMRC regarded the internal mail as "private" postage, a view which doesn't sit with me at all. The way I think about it is like this, if you were to copy the company's entire database, "The" Crown Jewels of the organisation to a piece of media. Shouldn't you be applying the same security measures as to the live database, as held on the Servers? Think about all the physical security as...

HMRC: More Discs Go Missing, Is it Foul Play?

Yet more CD/DVDs have gone missing within HMRC's internal postage system, this time a batch of 6 "discs" have disappeared in transit in between Preston and London. This incident was spotted by HMRC on 30th October and apparently held customer complaint conversations, which I certainly would regards as personal information. This is the third HMRC postage containing sensitive CDs which has gone missing within the same month, October 2007. Don't forget the CD which HMRC sent(lost) to Standard Life, which held 15,000 records, as reported on 2nd November, I can't forget that missing disc, as my personal details were on it! So I have to ask whether there could be foul play? I can't answer that for certain as I don't work for HMRC or know all the facts, however I'm going to have a go at speculating since two of incidents involve my peronal information. Organised criminals have been know to target large intuitions just for their data, going through exte...

HMRC: Emails Confirms Poor CD Password Protection

NAO have released details of their Email correspondence with HMRC leading up to the HMRC data breach, and answers a couple more questions I had with incident. Click Here for NAO Emails From the NAO Emails it is very clear to understand the HMRC data was zipped (compressed to make the data files smaller), likely with an application called Winzip. The so called password protection of CD we are told about is just a Winzip password, which wouldn't be very hard to defeat. See http://www.zipcure.com/ for instance. On analysing what was said in the Emails further and ignoring the political spin about them... NAO rep. states "I do not need address, bank or parent details in the download - are these removable to make the file smaller?" - Clearly NAO were not asking for the removal of the sensitive data for security, it appears the NAO wanted to receive a smaller database on the grounds of it being easier to manage on a single CD, i.e. a single zip file. This is contrary t...

HMRC: Who asked for the data and why?

I have now found out the answer to one of my burning questions in relation to the HMRC data breach. Which was, Why on earth would HMRC have any requirement to send the entire database outside their organisation? The lost HMRC CDs were destined for The National Audit Office (NAO), a body which scrutinises public spending on behalf of Parliament. http://www.nao.org.uk/ “The role of the National Audit Office (NAO) is to audit the financial statements of all government departments and agencies, and many other public bodies. We also report to Parliament on the value for money with which these bodies have spent public money. As well as providing accountability to Parliament, we aim to bring about real improvements in the delivery of public services.” As part of the preparations for the 2007/08 audit of the HMRC by the NAO, the NAO instead of requesting the usual sample of data to audit, requested a full copy of client benefit data. No doubt because the funding and costs of child benef...

HMRC: The Identity Theft Risk

Just to confirm what data was on those missing HMRC CDs (unencrypted): Full Name Full address National Insurance Number Date of Birth Partner's details Names Sex and age of children Bank/savings account details If those CDs fall into the wrong hands then half of the UK population are at increased risk at identity theft. I think the information would be difficult to use break into online bank accounts directly, although it's worth noting some people do use their children’s names as passwords and there are the odd password reset process which ask for your date of birth and mother's maiden name, but the fraudster would need to compromise the account holders Email account or PC. The real risk with this information is with Identity Theft, which is the UK's fastest growing crime. What is Identity Theft? - Simply put, it is when a someone assumes your identity and racks up credit\loans in your name with no intent of paying it, and/or commits to other fraudulent...

HMRC: UK's Biggest Data Breach Ever

The lost of two CDs holding 25 Million personal records by HMRC, is the biggest data breach in UK history, it's almost half the population. The data lost included children's names, full addresses, dates of birth, National Insurance numbers and where relevant bank and building society account details. How did this breach occur? In October, a junior HMRC employee downloaded the entire HMRC database and placed all the data onto two CDs, and then put the CDs in Jiffa bag and stuck it in the internal post for the attention of NAO, who requested it. This package never arrived at the destination NAO, so on finding out the same junior HMRC employee downloaded the entire database and placed the data on CDs again, but this time sent it by recorded mail, this did arrive. The lost CD is described as password protected by HMRC, however I would like to make it very clear the data on the CD is NOT encrypted, therefore is far from secure being read, and I understand the password system can ...

Shambolic HMRC loses yet another CD

It’s well documented on this blog, on how the UK Government department, Her Majesty's Revenue & Customs (HMRC), failed to protect my own and 15,000 others personal information,losing a couriered unencrypted CD a couple of weeks back, and then there was the incident with an unencrypted HMRC laptop going missing a couple weeks before that. Now they have completed the hat-trick big time, this time losing a bunch of CDs holding 15 Million children benefit records, which I understand held names, address, date of birth and bank account details for around 7 million British families. Apparently the CD went missing after being couriered between HMRC headquarters in Washington, Tyne and Wear and London, when exactly how this happened isn’t clear yet, however ministers have known about the problem for 9 to 10 days. I understand another HMRC internal investigation is underway, while the police are still investigating. So yet again the CD was sent unencrypted and yet again I wish to h...

UK WiFi Theft is Rife

A recent UK survey by Sophos revealed 54% of those surveyed had used someone else’s wireless Internet access without permission. Many within the media are calling this practice “WiFi Piggybacking”, and I’ve even seen quotes from liberal academics backing the practice. In my view this is plain and simple WiFi Theft, its wrong and it’s completely illegal in the UK. The offence is under section 125 of the Communications Act 2003, which states that "a person who (a) dishonestly obtains an electronic communication service, and (b) does so with intent to avoid payment of a charge applicable to the provision of that service, is guilty of an offence”. The maximum penalty is six months in jail and/or a fine of up to £5,000. There have been several prosecutions under this act. In fact I'm aware of the arrest of a 39 man in August, who was spotted using on his laptop in the street, accessing an unsecured WiFi connection within someone’s home in Chiswick, London. I have heard some peo...

Frank Abagnale's advice to me Re:HMRC

I know all about the various methods and processes in which HMRC could of protected my private information, but now my info could be in the wild and in the hands of bad guys, who better to give me some advice than Frank Abagnale. If you haven't heard of Frank, he's the guy the "Catch Me If You Can" movie was based on, after serving his time Frank provided consultancy to several banks, helping them to beat fraudsters, and he went on to be known and respected as a leading expert in Identity Theft. Here is his advice to me... "Sorry that this happened to you. Most of the time when identities are lost/stolen in this method, the people who steal the information sell it to a buyer who sits on it normally for about 2 -3 years. Unlike stealing credit card data where the credit card issuer can cancel the cards, you can't change your name, date of birth, National Insurance Number/Social Security Number, etc. So the longer they sit on the information the more valuab...

Lack of Data Discloure Laws

Well I lodged a complaint about HMRC with the Information Commissioner today, basically the guys who enforce the Data Protection Act, as I am still far from happy about the bad practice which led to my personal details being lost by HMRC, the time it took for disclosure and then being misled about the data encryption of the CD. I'll post up the response when I get it. Meanwhile I noticed my involvement with this was discussed on Martin McKeay's (and Rich Mogull's) excellent Network Security Podcast , by the way I heartily recommend this podcast for anyone who is interested in learning more about Information Security and the latest topics within the field. One interesting point was made about our lack of disclosure laws we have in the UK compared to the US, which I have to say is true, we don't have any clear laws on breach disclosure within the public and private sectors, we rely and trust companies and organisation ethics. I think it would of been a very dangerous ga...

HMRC Data Breach CD was NOT Encrypted

I phoned HM Revenue & Customers (HMRC) again today to obtain further clarification on whether their missing CD was encrypted or not, as on Monday I was categorically told by a HMRC representative the CD was encrypted, although he couldn't say what type of encryption was used, in fact I repeated the question three times to be sure. After reading conflicting press reports about encryption of the CD, I decided to phoned HMRC again today. This time I was told by HMRC the CD wasn't encrypted after all, so I was completely mislead by them on Monday then. This just goes from bad to worst. And get this, I was then told not to worry as although the names were readable within the files in the CD, my National Insurance, Date of birth and pension reference details would be "difficult" read! In other words the data was in an unformated state. I explained to the HMRC rep. that is was actually something to worry about, as it probably wouldn't take too long to render the ...

HMRC Data Breach Update - I'm vulnerable!

I'm vulnerable to Identity Theft thanks to HMRC Update It turns out I’m one of 15,000 Standard Life customers to be at risk of fraud after personal details were lost by HM Revenue & Customs (HMRC). I had confirmation in addition to the letter I received on Friday. The CD holding my info (including National Insurance Number, Date of Birth and info about my pension) was sent from the Revenue office in Newcastle to the Standard Life’s HQ in Edinburgh, however the CD never arrived, apparently lost by the courier firm. Also I heard a rumour that second CD containing data on some customers from an unnamed second company has also gone missing, which if true might suggest something more sinister is afoot. HMRC have been quoted in saying the incident happened at the end of September, a whole month before any notification, which isn't good as they should be notifying much quicker than that. And on the data encryption front, HMRC won't say whether the information was enc...

I'm vulnerable to Identity Theft - Thanks a lot HMRC

When I arrived home today and I was greeted with a brown letter from Her Majesty's Revenue & Customs (HMRC). Did I owe them tax? No, much worst than that, HMRC have exposed me to Identity Theft big time, just less than a week after I posted up a guide on "Reducing your risk of ID fraud" too. ITSEeducing_your_Risk_of_Identity_Theft So here we have a top UK Government department which has dropped yours truly, into serious risk of Identity Theft, at no fault of my own. To quote from the HMRC letter... "At the end of September HMRC sent a CD to your pension provider, X (I've X them out as there not the ones at fault) with your surname, national insurance number, date of birth and plan reference number included on it. We are very sorry to tell you that the CD was lost after it had been collected from HMRC by HMRC's external courier and before it was delivered to X. This means that there is a possibility that your personal data could be accessed by som...

Unclever but Lucky People!

I just happen to own the domain “Network-UK.com” which I leased several years back as part of a project I was working on, which really didn’t take off the ground. Anyway for several months now I have been receiving misdirected Email to this domain, almost on a daily basis now, Email which appears to be meant for a London based UK employment agency using a similar domain name, addresses for a variety of individual accounts at the domain rather than one. Which in itself is kind of expected, however it’s the content of these misdirected Email which really concerns me. Due to the way forwarding works to my inbox, I can’t instantly tell if an Email was forwarded or not, and on occasion within my preview panel I can see these Email are about wages claims, and often include Full Name and Addresses, Bank Account numbers with Sort Code and bank name, Full Names and Phone numbers, National Insurance numbers, and even on occasion full colour scanned copies of passports! which as we all know is a ...

Identity Fraud Protection Guide Completed

I have completed and uploaded my guide to "reducing personal risk of card & identity fraud", with 20 key tips and some FAQs about Identity fraud/theft. ITSEeducing_your_Risk_of_Identity_Theft I had a lot of interest and requests to produce a formal guide by various site visitors and offline friends. I'm aware most of the guide will be just common old sense to any security professional out there, but the guide nor generally my website is aimed at the level.

Why do Spammers Spam?

I noticed Microsoft's Eileen Brown was pondering Spam in her Blog, asking “Why the heck do these spammers keep on spamming people?" http://blogs.technet.com/eileen_brown/archive/2007/10/15/a-lot-of-spam.aspx?CommentPosted=true#commentmessage Well here’s my response… It is because out of the tens of thousands of Spam Email they send, which costs practically nothing, there are always one or two gullible people who click through to buy a product or get done, making it a profitable and worthwhile exercise. “Two years from now the Spam problem will be solved ” - Bill Gates, January 2004 Bill got that wrong, it's increased big time since then. Why the problem? Well Standard Email is just not secure, it is impossible to tell or control who has actually has sent them, not without using Certificates and PGP etc, even the latest Anti-Spam software isn't the silver bullet.

Contactless Cards: Convenience before Security?

I was on national Radio Monday lunch time, taking part in a debate on cashless societies; specifically I was giving my (the security) perspective on the new Contactless Debit/Credit Cards, which will be rolled out within the UK early next year. My points were as follows: Since the introduction of Chip & Pin in the UK a couple of years ago, there are been a significant reduction in credit card fraud at the high street till (cash register), even the latest figures for the last six months show credit card fraud at the cash register is down by 11%, despite an overall rise in UK card fraud of 26%, which underlines the growing problem with card fraud. The trends show the bad guys are increasingly stealing UK card details to either use online, or to use them in countries where PIN numbers are not required to process transactions, i.e. using the magnetic strip on the back of the card instead of the chip, which I’ll get on to later in this rather lengthy post. The reason why Chip and P...

Reducing your Risk of Credit Card & Identity Fraud

Here's my 15 tips to help reduce your personal risk of credit card fraud and identify fraud. Oh when I say identify fraud\theft, I mean when someone assumes your identify to rack up credit\loans and other fraudulent activity in your name. 1. Invest in a decent shredder, avoid cheap shredders they are a false economy, they often don’t last long anyway, and can make shredding a real chore. Try to get into the habit of regularly shredding receipts, statements or anything else with financial and personal information. 2. Never ever disclosure your PIN number, login details or passwords. Often fraudsters will “confidence trick” by appealing to either greed or fear. For example if you are told you have won a competition or entry into a free cash draw, but you have never entered the competition, I 99% guarantee it is either a scam or an attempt to collect your personal details for marketing, just remember there is no such thing as a free lunch. Also fraudsters will use fear to by pas...

A tale of Social Networking sites (yet again)

In my last post the last thing I advised was to be careful what you post up on social networking sites, as it may come back to haunt you, well I had barely uploaded that post when yet another social networking news story broke in the UK. The British people love their Tennis and particularly Wimbledon, but for decades now we have been really unrepresented in this sport, with only one or two players in the top one hundred, which for a country of over 60 Million and a decent sized middle class, is pretty poor form. To remedy this, the Lawn Tennis Association (LTA), has been ploughing money into supporting young tennis players, which makes good sense really. Well two of these funded young players were found publicising a lifestyle of partying, drinking and eating junk food on the Bebo social networking site. Pictures included one in a street holding an empty bottle with a the caption “Me Drunk for a change”, and statements saying hates-“hangovers after a good nite owt[sic]” and “wiv th...

Facebook's Privacy Policy

A Facebook enthusiast recently asked me why I "hated" Facebook so much, well I don't hate Facebook at all, I have never posted or said such a thing, however I have to say I am not mad keen on the idea of the site and where it might be heading. Lets take Facebook's privacy policy for instance, it is over 3,500 words length and has the little caveat of “We reserve the right to change our Privacy Policy and our Terms of Use at any time.” Given that statement, you have to ask yourself whether you can trust Facebook with your private data? Their policy is well worth a read if you are a user of the site. http://www.facebook.com/policy.php So there are no restrictions or guarantees on how Facebook can use the huge amount of user personal data it has built up in recent times, some might say most of the company’s high value is based on the market-ability of this data. Then there is the old fundamental flaw of all social network sites, in that there isn’t any identify va...

Google on Global Privacy Standards

My love / hate relationship of Google is definitely in the loving zone after I heard Google chief, Peter Fleischer calling for Global Privacy Standards. I won’t regurgitate what Fleischer said, as there's a perfectly good report on the BBC News website linked below. http://news.bbc.co.uk/1/hi/technology/6994776.stm Also check out this link to a report which I have touched on a couple a months back, you should find it quite interesting if you are into personal privacy online. http://www.privacyinternational.org/article.shtml?cmd[347]=x-347-553961 I really think a hundred years from now, when history looks back on the last couple of decades, it will be recognised as the start of the Information Age, and when it comes to personal information privacy and information security, we are merely still trying to take our first steps. So it's just so refreshing to see that Google are looking ahead and attempting to take a lead in this area, and lets face it, Google are getting so pow...

Facebook: Welcome to the World of Google Hacking

To be completely honest, sites like Facebook has the same appeal to me as reality TV, which almost zero! Anyway a friend of mine a couple months back bullied me into setting up an account on Facebook. But being a typical paranoid security guy, I didn’t upload any photos or post any personal information, other than my name and a fake Date of Birth, I guess it’s the most boring Facebook page on the whole site! The way I understood it, Facebook was suppose to be a private network, where you add links and share your personal information including work and educational history with friends, work colleagues and former class mates etc. Significantly you either had to accept an invite or have your own invite accepted by another party, before your information is shared. But here’s the big scary change, Facebook are now allowing members personal information to be accessible by everyone, even non-members. We are not just talking private pictures either, but information such as people’s date of bi...

Web App Sec: With Great Power comes Great Responsibility

Thanks to the explosion of Web 2.0, companies have more power than ever on the Internet, however with great power comes great responsibility. Trends show hackers are targeting web applications increasingly, simply because they are easier to hack and the rewards are greater than traditional hacking, like writing viruses for example. Often companies get the network security level right, with proper DMZs and firewall configuration, but this is merely the foundation of providing web application security and in reality offers very little protection against application level attacks. The Security of Web Application starts right with the developers, especially if you code in house. Web Application Security training of developers is absolutely key and the use of Development Quality Assurance tools like SPI Dynamics WebInspect and Watchfire’s AppScan in the development cycle also plays a vital role. Sure these tools cost, but you are paying for the tools to be constantly updated by the ven...

All of the UK must be on DNA database!

To follow up my previous posting on the UK DNA database, which is the biggest in world and growing by 30,000 records a month, I said there were "moves" going on by the UK establishment to have everyone's DNA recorded in the database, well a senior UK judge yesterday was pushing for just that. What they won't tell you is that they don't actually need everyone's DNA in the database. As it only takes a family relative's DNA to provide a close enough match, which is enough to home in on an individual. http://news.bbc.co.uk/1/hi/uk/6979138.stm

Off the Shelf Malware with 1 Year Technical Support!

It’s common knowledge within the security industry that you can hire hackers, hire out the use of botnets and even buy zero day exploits, malicious scripts and viruses, but what surprised me recently, is that you can buy packaged Malware, which even comes with technical support. Recently one such package, MPack, a PHP malware kit put together by Russian hackers has been causing problems. MPack can be bought for £500 ($1000), and includes a year of technical support and options of purchasing extra exploitation modules. MPack exploits the latest vulnerabilities in M$ Windows web browsers; oh it is browser aware as well, so Opera and FireFox won’t save you. For the most part an infected MPack website scans your browser and OS for security flaws, and if it finds any it exploits them, as well as storing stats about your system for future reference. The fact the MPack product can be regularly updated by the hackers producing it, is its greatest danger, as it means it can stay ahead of Anti...

A Cashless Society

I often wondered how long it would be before there wasn’t any need to carry any physical money, well from today it appears we are well on the way, and even trends backup the move towards a cashless society. In 2004, card payments over took cash payments for the first time in the UK, while last year £321 billion ($642bn) card purchases were made in comparison to £274bn in cash, with the average Briton putting around £10,000 through card payments. Fraudsters stole around £428 million, which has actually come down slightly thanks to the introduction of Chip and Pin two-factor authentication. Today the big five UK mobile phone operators switched on “PayForIT”, which allows the payment of transactions up to £10 to be made by mobile phone. I love the idea of not needing to carry any cash, but I am rather sceptical about the use and the potential abuse of mobile phones by criminal elements. To be fair I haven’t had a chance to fully review the “PayForIT” process in great detail, but fro...

The Dangers of Shadow IT

In case you are not aware of the term “Shadow IT”, it basically refers to those users within the corporate user base, who pretty much do their own thing IT wise within the corporate environment. Think about it, gone are the days where the vast majority of corporate help desk calls revolved around user related help like “How do I create a table in Word?”, “How do I do formula in Excel” etc. Why? Because users are more technical savvy these days, especially within younger users, who have grown up with PCs and the Internet all their lives, they tend to solve their own IT problems instead of bother the help desk . If your organisation doesn ’t have a good security culture, you’ll find these sorts of users can be up to all sorts of tricks, such as installing their own applications, using unauthorised hardware like USB hard drives, installing network hardware like Switches and Hub, and God forbid wireless access points, as well as using the Internet for all sorts of things which was nev...

Expect The Best, Prepare For The Worst

I really have to start letting go of what I do for living when relaxing outside the work place, I just watched "The Bourne Ultimatum", I noted a safe was opened using supposedly secure but a single authentication method using only biometrics, in that it scanned a finger print and had voice recognition (no password). If it had only used dual factor authentication, perhaps with a passcode (i.e. something you know), then Jason Bourne might of found it a lot harder to get it open and steal the contents! Oh I got slightly annoyed that film's heroine said "the firewall" was blocking user level access rights to a file, if the Firewall was blocking she shouldn't of even got close to remote accessing the file in question in the first place, but hey that's hollywood, I really shouldn't be a kill joy. The thing that stood out the most for me, was when the bad guy CIA director used the phase "Expect The Best, Prepare For The Worst" in regards ...

The World's Biggest DNA Database

In one of my earlier blog entries about the UK being the ultimate Big Brother state, I touched on the Police's national DNA Database. Well I recently discovered more than 715,000 DNA records were added to the UK national Police database last year, which brings the total number of DNA records to a staggering 4 Million records, making it the world's biggest DNA database. So what if you are an upstanding UK citizen, do not be fooled into thinking that this DNA database isn’t of concern, as if any of your relatives have DNA on the Police system, then that DNA can lead the Police to your door. There have already been several high profile cases of the Police tracking down criminals through relatives DNA, the most notable was the Yorkshire ripper hoaxer, who was tracked using DNA evidence collected over 25 years ago. Personally I like the idea of the Police having a national DNA database, as it helps to catch the bad guys and provides a deterrent, especially to serious crimes. Som...

UK Personal Internet Security Report

A UK government committee released an interesting report on Personal Internet Security. Personal Internet Security Report These government reports can be a bit hard to digest, but to quote directly the reports key recommendations. “The current assumption that end-users should be responsible for security is inefficient and unrealistic” and then goes on to urge security responsibility to be taken by government and ISPs, and then calls for more laws and industry standards. “The Government have insisted in evidence to this inquiry that the responsibility for personal Internet security ultimately rests with the individual. This is no longer realistic, and compounds the perception that the Internet is a lawless “wild west”" I don’t quite agree with this report, sure I’m all for more laws and standards for businesses, but when it comes to home users, they should be educated more, rather than trying to apply the nanny state. Protecting people with technology and laws just isn’t...

UWB: Broadband Bluetooth

OFCOM (UK regulator) has given the go ahead for Ultra-Wideband (UWB) to be used within the UK, they have deregulating the required radio waves so a license is no longer required to use them. The next step is for Europe to agree the UWB standards which will take a few months, but I understand manufacturers are already developing UWB devices. UWB uses part of the radio spectrum to transfer large amounts of data, such as media files, over short distances, so it's a kind of broadband Bluetooth. For example in the home UWB can be used for the wireless sending HD video data from a HD Camcorder to a HD TV, or MP3s could be streamed to wireless speakers . As you can imagine there are plenty of data transfer possibilities with this technology. They say UWB will have a range of around 10 metres; however they said that about Bluetooth when that first came out. We'll have to wait and see the security aspects and security challenges this new technology will bring, but I imagine it will ...

Web 2.0 is Fundamentally Broken

"Web 2.0 is fundamentally broken," says Robert Graham, the CEO of Errata Security . "Using the tools it's easy to hijack other people's credentials. It's a fundamental flaw in Web 2.0". Well I have to say the evolution of Web 2.0 (web apps) is what scares me the most in terms of Information Security today. At Black Hat 2007 Robert Graham of Errata Security demostrated how easy and quick it was to break into the most common Web 2.0 applications like GMail, HotMail, MySpace and FaceBook. Using Errata's soon to be released & freeware tools "Hamster" and "Ferret", Robert scanned the Black Hat wireless network during his presentation, sniffing out user's URLs until he found a user using GMail. After which he was able to very quickly open up that persons session and display the poor guys GMail inbox on the big screen, thanks to the Errata tools. This hack works as the Errata application is able to grab the users cookie, fro...

Incident Disclosure is really a No Win Situation

Recently a UK City Council announced a data breach involving tens of thousands of credit cards, I’m not going to name them as I don’t really want to be associated in defending them. The facts of the security incident and how it was discovered is very different from the press headlines, which basically laid into the Council for having bad security and not being security responsible by putting thousand of it’s users at high risk of credit card fraud by putting these deatils unsecurely online. However after reading through press releases and a bit deeper into some of the news reports, it painted a slightly more responsible picture. The Council had hired an external Security Expert – no, not me ;) to check and test the security of their systems, this expert found that a data file had accidentally been uploaded to a public website in error by a member of staff. The file held credit card transaction details for thousands of council tax payments and parking fines, however the credit card ...