Posts

Showing posts from July, 2007

Incident Disclosure is really a No Win Situation

Recently a UK City Council announced a data breach involving tens of thousands of credit cards, I’m not going to name them as I don’t really want to be associated in defending them. The facts of the security incident and how it was discovered is very different from the press headlines, which basically laid into the Council for having bad security and not being security responsible by putting thousand of it’s users at high risk of credit card fraud by putting these deatils unsecurely online. However after reading through press releases and a bit deeper into some of the news reports, it painted a slightly more responsible picture. The Council had hired an external Security Expert – no, not me ;) to check and test the security of their systems, this expert found that a data file had accidentally been uploaded to a public website in error by a member of staff. The file held credit card transaction details for thousands of council tax payments and parking fines, however the credit card ...

Door-to-Door Personal Information Gathering

It's just after lunch time on a sunny Saturday afternoon, it's great to finally have some sunshine for once, it's been a very rainy summer in the UK. Anyway about 5 minutes ago my door bell rang and I was greeted by a smartly dressed young man, who handed me a leaflet, advertising a carpet cleaning or something like that and a free prize draw for a car. According to the leaflet is was by a company called "Total Homecare (lancs)". It's what happened next that really bothered me... young man>we're new the area I'm just handing out leaflets, we do carpet cleaning, and we having a free prize draw for a new car (car was a cheap Nissan Micra) me>ok, but most of my house has wooden floors and I already have a car , so I'm not really interested young man>ok, let me just take your name... me>hang on minute, I'm not the sort of guy that hands out personal details to people I don't know. young man>Oh don't worry about that it...

Those Darn Google Spin Doctors

The BBC News website hailed a Google response to their recent privacy criticisms, with Google announcing they will now auto-delete their search engine's locally stored cookies after just two years, instead of by the year 2038. But here's the thing, the Google cookie "auto-delete date" resets back to two years after each visit! So unless you don't visit google.com for over two years (how likely is that), then they'll never delete anyway! I have no problem with the Google cookie, as after all if I was super paranoid I could just manually delete their bloody cookie myself after each visit, but what a complete non-story! Those darn Google Spin Doctors, I suppose they were just running out of ideas for their weekly privacy news story.

The Best Hacker/Security Movies

It’s fair to say my recent blog entries have been a bit too serious of late, so I guess its time for a more light-hearted security related blog entry, so here's my top three favourite Security/Hacker movies of all time. 3. WarGames Sure WarGames is an old and dated film by todays standards, but it has a nice example of war dialling, which has pretty much gone into the hacking history books. There's plenty of other realistic hacking techniques, like actually stealing password from the school secretary's draw, (locking draws should be part of a tidy desk policy right?), still the second half of the movie kind of goes completly off the rails. 2. Firewall This is the movie where the Security guy, not the hacker, is the hero! Sure it might not be the best movie ever made, but it makes my list for one particular scene, which is near the beginning, when Harrison Ford actually enters an Access List on a Cisco Router, “correctly”, although if I was tetchy I would of expected ...

Big Brother is already watching You!

Continuing the theme from my last blog entry, in regards to the idea of a “Big Brother” state impeding over individual rights…so what’s the deal with individual privacy erosion anyway? Well as far as I’m concerned that boat has not already sailed, but is over the horizon out of sight, the George Orwell “1984” state is already here! Let’s look at the evidence in the UK. The UK is the most CCTV intensive country in the world, the average UK citizen is caught on CCTV cameras 300 times a day. However since the general induction of CCTV into urbans and shopping environments, which first appeared in the UK 50 years ago, CCTV has played a vital role in solving many crimes, and now plays a role in crime prevention in all UK city centres . Moving on, Tesco is the UK’s leading Supermarket, they are probably best described as more of a multi-billion pound corporation, as staggeringly Tesco account for £1 out of every £7 spent in the UK high street. Tesco success is built on data mining, as...

Terrorism Risk Assessment

After reading through news website comments, listening to radio talk shows and general conversations with peeps down the pub, the biggest debate post the failed UK terrorist attacks, isn't about the changing the "foreign policy", or "pulling our troops out of Iraq", it's the old chestnut personal Civil Rights Vs State Security. On scrutiny I found that most of those who sided with the extra security measures for the state over personal rights infringement, tended to because of fear of being a victim. For me as a security guy this isn't rational thinking, as they just aren't risk assessing the situation properly. So what leads people to think in this way? Well as terrible and deplorable terrorist acts are, I think the way the media over sensualises it, not only encourages these acts in the first place, but is helping instilling an irrational fear. I mean if I put on my "risk managers" hat, I know for a statistical fact that I am more likel...