Posts

Showing posts from August, 2007

The Dangers of Shadow IT

In case you are not aware of the term “Shadow IT”, it basically refers to those users within the corporate user base, who pretty much do their own thing IT wise within the corporate environment. Think about it, gone are the days where the vast majority of corporate help desk calls revolved around user related help like “How do I create a table in Word?”, “How do I do formula in Excel” etc. Why? Because users are more technical savvy these days, especially within younger users, who have grown up with PCs and the Internet all their lives, they tend to solve their own IT problems instead of bother the help desk . If your organisation doesn ’t have a good security culture, you’ll find these sorts of users can be up to all sorts of tricks, such as installing their own applications, using unauthorised hardware like USB hard drives, installing network hardware like Switches and Hub, and God forbid wireless access points, as well as using the Internet for all sorts of things which was nev...

Expect The Best, Prepare For The Worst

I really have to start letting go of what I do for living when relaxing outside the work place, I just watched "The Bourne Ultimatum", I noted a safe was opened using supposedly secure but a single authentication method using only biometrics, in that it scanned a finger print and had voice recognition (no password). If it had only used dual factor authentication, perhaps with a passcode (i.e. something you know), then Jason Bourne might of found it a lot harder to get it open and steal the contents! Oh I got slightly annoyed that film's heroine said "the firewall" was blocking user level access rights to a file, if the Firewall was blocking she shouldn't of even got close to remote accessing the file in question in the first place, but hey that's hollywood, I really shouldn't be a kill joy. The thing that stood out the most for me, was when the bad guy CIA director used the phase "Expect The Best, Prepare For The Worst" in regards ...

The World's Biggest DNA Database

In one of my earlier blog entries about the UK being the ultimate Big Brother state, I touched on the Police's national DNA Database. Well I recently discovered more than 715,000 DNA records were added to the UK national Police database last year, which brings the total number of DNA records to a staggering 4 Million records, making it the world's biggest DNA database. So what if you are an upstanding UK citizen, do not be fooled into thinking that this DNA database isn’t of concern, as if any of your relatives have DNA on the Police system, then that DNA can lead the Police to your door. There have already been several high profile cases of the Police tracking down criminals through relatives DNA, the most notable was the Yorkshire ripper hoaxer, who was tracked using DNA evidence collected over 25 years ago. Personally I like the idea of the Police having a national DNA database, as it helps to catch the bad guys and provides a deterrent, especially to serious crimes. Som...

UK Personal Internet Security Report

A UK government committee released an interesting report on Personal Internet Security. Personal Internet Security Report These government reports can be a bit hard to digest, but to quote directly the reports key recommendations. “The current assumption that end-users should be responsible for security is inefficient and unrealistic” and then goes on to urge security responsibility to be taken by government and ISPs, and then calls for more laws and industry standards. “The Government have insisted in evidence to this inquiry that the responsibility for personal Internet security ultimately rests with the individual. This is no longer realistic, and compounds the perception that the Internet is a lawless “wild west”" I don’t quite agree with this report, sure I’m all for more laws and standards for businesses, but when it comes to home users, they should be educated more, rather than trying to apply the nanny state. Protecting people with technology and laws just isn’t...

UWB: Broadband Bluetooth

OFCOM (UK regulator) has given the go ahead for Ultra-Wideband (UWB) to be used within the UK, they have deregulating the required radio waves so a license is no longer required to use them. The next step is for Europe to agree the UWB standards which will take a few months, but I understand manufacturers are already developing UWB devices. UWB uses part of the radio spectrum to transfer large amounts of data, such as media files, over short distances, so it's a kind of broadband Bluetooth. For example in the home UWB can be used for the wireless sending HD video data from a HD Camcorder to a HD TV, or MP3s could be streamed to wireless speakers . As you can imagine there are plenty of data transfer possibilities with this technology. They say UWB will have a range of around 10 metres; however they said that about Bluetooth when that first came out. We'll have to wait and see the security aspects and security challenges this new technology will bring, but I imagine it will ...

Web 2.0 is Fundamentally Broken

"Web 2.0 is fundamentally broken," says Robert Graham, the CEO of Errata Security . "Using the tools it's easy to hijack other people's credentials. It's a fundamental flaw in Web 2.0". Well I have to say the evolution of Web 2.0 (web apps) is what scares me the most in terms of Information Security today. At Black Hat 2007 Robert Graham of Errata Security demostrated how easy and quick it was to break into the most common Web 2.0 applications like GMail, HotMail, MySpace and FaceBook. Using Errata's soon to be released & freeware tools "Hamster" and "Ferret", Robert scanned the Black Hat wireless network during his presentation, sniffing out user's URLs until he found a user using GMail. After which he was able to very quickly open up that persons session and display the poor guys GMail inbox on the big screen, thanks to the Errata tools. This hack works as the Errata application is able to grab the users cookie, fro...