Posts

Showing posts from June, 2007

Finally got CCSP!

Wahoo! I just passed the final exam on the Cisco Certified Security Professional (CCSP) track. It was the final of 5 exams which I have taken over the pass 3 years, and to be honest I'm glad to have finished them, as it allows me to focus a little more on Information Security Management and the process side of things. At least I get a well earned break from reading those thick Sybex books!

Home WiFi Jamming

To conclude a trilogy of WiFi Security blogs this week, I’m going to touch on an accidental home encounter I had with WiFi signal jamming. As we become ever more WiFi enabled, particularly in the UK, where there has been a bit of WiFi explosion of late, with whole areas of cities becoming WiFi enabled. There is little doubt in my mind that we will become more and more dependant on WiFi networks. Anyone who has read any formal IT Security book will know about the CIA Triad, Confidentially, Integrity and Availability, well security wise this post is going to be about Availability, i.e. jamming the WiFi signal. Now you might think WiFi jamming sounds a bit far fetched and that it would require a lot of expensive equipment and expertise, but as I accidently discovered recently, it does not have to be. A couple of weeks ago I finally gave in and bought my kids a Nintendo Wii, well I figure it keeps them physically active while playing the video games, which sounds like a fair trade off ...

Are WiFi BotNets Possible?

Following from my blog about unsecured Home WiFi networks and just how widespread they are in "home user" land. I have been wondering whether it might be possible to create a kind of "WiFi BotNet". Let’s say the attacker setup in a metropolitan area, constructed an antenna to boost the WiFi range of their device, allowing the attacker to scan and connect to any unsecured or low security WiFi networks over a significant range. Going from my own experience, there should be plenty of unsecured WiFi access points within a metro area. From this point I have two theories. One trick could be to try and connect to several WiFi networks at the same time and create a kind of mini BotNet, perhaps by the attacker fashioning a network access point, this could provide major bandwidth and anonymity for the attacker. I need to investigate this theory further. Or the other way, which I think could be easily possible, is to automate connecting to each unsecured WiFi network in ...

Badly Secured Home WiFi

It still amazes me just how many home users and small businesses out there are using unsecured home wireless networks. I visited a friend over the weekend to help out with a computer related issue, I booted my laptop up, enabled my WiFi card, and I immediately picked up several WiFi access points, of which two had no encryption, no passcode required! One of the SSIDs was even called "NetGear". I also picked up a small business WiFi network called " WEP", oh dear, lol. It's frightening what some home WiFi users are leaving themselves exposed to. Anyone in the vicinity could easily use their WiFi connection to visit "dodgy and illegal websites”, should this activity be discovered by the authorities, who will track them down through via the ISP, it will be on the WiFi owner’s door which the police will be knocking. It also begs the question if someone wanted to "get away" with visiting dodgy websites, by deliberately leaving open their WiFi connectio...

Who's the IT Security Expert?

So I'm the author of the ITSecurityExpert blog, but what's my background? Well I'm based in the UK, so although I sing from the same hymn sheet as my US counterparts security wise, there are sometimes little twists with my view points. For instance in the UK we are governed by the Data Protection Act law, and there’s those pesky European laws to consider. Although I must stress I’m a Security Professional from a “techie” background rather than a background of “Law” or there I say it, “Quality”. I've been in IT Security for over 15 years, to be honest at first I didn't realise I was doing IT Security, but looking back I certainly was. In the nineties I spent several years designing, building and implementing locked down (secured) Servers, Workstations and networks, which I installed onto Royal Navy battleships and submarines for a third party company. These IT systems didn't house anything exciting like weapon systems, just a boring engineering maintenance applic...

Google Tops Security Bad Boys List

Surely Google can't be as bad as Microsoft, Apple and AOL when comes to Web Data Security? Well according to a new report by Privacy International (PI) they are the worst! I have previously blogged about my own love - hate relationship with Google, with my own "hate" due to Google's somewhat questionable approach to recording and holding user search information. But at the moment Google appear to be getting bashed in the press every week with anti-privacy stories. I can't really say how much creditability PI or the PI report's rating system has, as clearly PI will have their own agenda, but the Google points they raise are interesting reading, as are the points on the other big internet heavyweights. Definitely good stuff for me to take into consideration when I am thinking and advising about web security within my working environment. Follow the link below for the full PI report. http://www.privacyinternational.org/issues/internet/interimrankings.pdf

PCI Encryption Practice Flawed due to the Banks?

I’m no PCI assessor, but I am involved in helping a business reach PCI DSS compliance. On the encryption front, the PCI standard requires cardholder data to be stored in an approval PCI encrypted format on the backend database. In addition to this, PCI has a big focus with the database encryption key management, ensuring the private key is not known in full by a single person etc. I don’t have any issues with this despite good key management being a real pain to implement, it all makes good security sense, but here’s my observation and big issue with the PCI encryption requirements. When the merchant sends the cardholder data to the bank for the card payments to be processed, the cardholder data is exported from the database unencrypted and sent to the bank in an unencrypted format, sure it’s over a point-to-point private connection, but wasn’t whole PCI point to prevent the cardholder data from being readable on the database Server? The bank payment process is a requirement of the b...

Cheap yet Effective Information Security

Many Information Security study books will tell you about the holy Security Trinity of Confidentially, Integrity and Availability, the so called CIA Triad, which is all fair and well. But I live by another holy Security Trinity, Policies, Users and Technology. The most important area is, and will always be, with User Security Awareness. However, you cannot sort the Users out until you have your Information Security Policies in order, so your first stop has to be tackling the policy paper work first, and then to ensure you get that all important senior management backing. Clearly Technology plays a very important role within the trinity, but unlike Policies and User awareness, technology has by far the highest the budget costs. You will always have to fork out for the basic security systems like firewalls, swipe card systems, Anti Virus systems and the rest of it. However depending on your business and some of the risk mitigation, a lot of the expensive “additional” security tech...

The Lonley Life of Security Management

Interested in a Career in Information Security? As well as having a good foundation of Information Security knowledge, courage of your convictions, a basic common sense and a ton of enthusiasm, there's one other aspect to consider before making the career plunge. The role of an Information Security Manager / Officer, especially in a small to medium sized company where you are a one man security department, can be a lonely role. Sure one aspect is do have involvement with every department and person within the organisation, but let me explain why: 1. It's great to think you'll always get management backing, and if you end up working for a decently security focused (or concerned) organisation, in general you will, it’s very important you have this backing if you are to be successful in security management. However there will be always some managers that will disagree with your security stance, risk evaluations and recommendations, sometimes they don't like to be told what...