Posts

Showing posts from 2010

iPhone Security Guide

Image
Last week a reporter asked for my opinion on iPhone Security, I said I thought it was a good idea. But seriously, Apple are actually taking steps to better secure the iPhone, this is driven by Apple's desire to impact the business smart phone market more, and better compete with the likes of Blackberry, who are the dominate force when it comes to business smart phone usage. Blackberry has been widely adopted by larger enterprises not only because their devices are easy to centrally manage, but because it comes with a whole raft of essential business security features, such as device level encryption and remote wipe functionality. When you think about it, you realise your iPhone is absolutely crammed with your personal information, think about the details within your Contacts list, Email accounts, Facebook account and even your personal photographs and videos all stored on the device, so if you care about your privacy ...

The Human Factor: Turning your Prime Weakness into your Prime Defence

Image
The slides from my talk on information security awareness at RSA Conference Europe 2010 The Human Factor: Turning your Prime Weakness into your Prime Defence  

Love it or Hate it, PCI DSS helps cut UK Card Fraud

Image
UK card fraud is significantly decreasing, according to the “UK Cards Association” statistics UK card fraud is down 20% to £187m for the first half of 2010. http://www.theukcardsassociation.org.uk/media_centre/press_releases_new/-/page/1037/ There are several reasons why card fraud in the UK has been dropping in my opinion: 1. Chip & Pin Chip & Pin, known as EMV in the payments industry, has been highly successful in cutting "cardholder present" fraud, namely face to face debit and credit card transactions, since its adoption in the UK in 2005. Chip and Pin has forced card fraudsters to commit fraud against stolen UK cards in different ways, typically by using online payments or by creating counterfeit UK credit cards to use in countries where Chip and Pin hasn’t been mandated. However since 2005 more and more countries have observed the huge success of Chip and Pin in the UK, and have been adopting the same payment approach, this in turn is also helping to red...

An Evening with Samy, creator of the Samy MySpace Worm

Image
Last night I was out talking security, drinking beer and eating curry with Samy Kamkar, following his presentation at an OWASP Chapter event in Leeds. Samy was responsible for writing and delivering the infamous Samy MySpace Worm in October 2005, which was one of the fastest growing malware infections to date. Samy Kamkar Samy delivered an excellent and fresh presentation at the OWASP Leeds Chapter meeting, highlighting several areas of new research and frankly new concern for us all. But I’ll save that for another blog posting once I’ve investigated it further, however you can read a little about one issue he discussed, which was highlighted in a recent BBC News report “ The Web attack knows where you live ” http://www.bbc.co.uk/news/technology-10850875 What I found particularly interesting about his presentation aside from the vulnerabilities and clever exploits, was you got to see how his mind ticks, his thought processes in finding and ex...

No Data Protection in Outer Space!

Image
I just found out my name is on board the IKAROS spacecraft, which is currently solar sailing its way from Earth to Venus. Apparently this is a benefit of my membership of the Planetary Society – yes I do have other interests outside information security. IKAROS For more info visit http://planetary.org/programs/projects/solar_sailing http://www.guardian.co.uk/world/2010/may/17/space-yacht-ikaros-japan-venus I don’t recall agreeing for my name to be sent into space, but I’m sure glad they did it, especially as this spacecraft may change course of interplanetary and interstellar exploration forever, plus the spacecraft could end up drifting in space for eternity, but I'll save further discussion on that for a different themed blog. So getting back to security, to be perfectly clear, an individual’s name on its own doesn’t require any protection and is not a requirement of legal acts such as the UK Data Protection Act. This is a common misnomer, it is only when you co...

Zurich UK Data Breach: Are large fines good for Information Security?

Yesterday (24th Aug 10), one of the largest fines for a data breach in the UK was issued, with the Financial Services Authority (FSA) announcing a £2,750,000 fine of the UK arm of Zurich Insurance (Zurich UK). Some 46,000 Zurich policyholders had their unprotected personal data, which included bank account and credit card information, “go missing” during a routine data transfer to a South African data centre in August 2008, with Zurich only noticing the breach a year later. By the way Zurich were actually fined £3.25m but were given a 30% discount for settling the fine early, see the FSA press release for more details -  http://www.fsa.gov.uk/pages/Library/Communication/PR/2010/134.shtml But do large fines actually work and help businesses, and indeed industries to become more Information Security savvy, and help enforce businesses to operate with better information security practices? Well I think the answer is a clear and resounding YES. And even more so when data breaches and...

How to choose the right PCI DSS QSA

Image
A few weeks ago (1st July 2010), I was a speaker and an expert panellist at PCI London . One particular subject which I spoke about generated a lot of interest from the mainly merchant delegates, and the QSA representatives, it was my views on PCI Qualified Security Assessors (QSAs). Specifically how merchants should go about selecting a quality QSA to help become and maintain their PCI DSS compliance. In my experience in working within the payment security field and with PCI compliance for many years, I find there are still far too many dodgy QSA individuals and QSA service providing companies out there, misadvising their clients with bad advice and providing merchants with what I personally call placebo PCI DSS compliance assurance. Low Budget means PCI Fail A QSA company should never be selected solely based on cost, as you tend to pay for what you get in the QSA provision world. Low budget tends to underpin a half hearted approach to PCI compliance, usually su...

Facebook's Privacy U-Turn

Image
Facebook, one of the world's most successful online businesses, has been pushing our personal privacy boundaries continually since its launch in February 2004.  Today, thanks to mainly public pressure, Facebook's owners finally held its hands up to the privacy issues it faces, and have backtracked on their relentless push against their user's privacy, by launching more simple and powerful privacy settings for all 400 Million Facebook users. The heart of the Facebook business model like all social networking models, is the encouragement of its users to sign up and connect with as many individuals as possible, aka "friends". Facebook users are rewarded by adding “Friends”, especially the Facebook’s third party applications which actually profit for the practice. For them individuals with larger audiences of friends means larger advertising revenue. This causes the privacy problem, in that many Faceboo...

New Podcast: Home PC Malware (Virus) Protection

Image
I released my "monthly" Podcast, yes it's officially a monthly Podcast now. Although I cheated and used a recent radio interview for the content. The Podcast is about basic Home PC Malware (Virus, Worm, Trojan, Keylogger) Protection, and where to obtain decent Windows Anti-Virus Protection for Free.This podcast is aimed at day to day people outside the security industry. Podcast: Home PC Malware (Virus) Protection ITSecurityExpert on iTunes To go with this Podcast I have the following links and recommendations. Microsoft Windows Security Essentials Anti-Virus & Anti-Spyware https://support.microsoft.com/en-us/help/14210/security-essentials-download . Requires licensed copy of Windows Requires Windows XP, Vista and Windows 7 Windows XP, a PC with a CPU clock speed of 500 MHz or higher, and 256 MB RAM or higher. AVG Anti-Virus www.AVG.com/FREE AVAST Anti-Virus http://www.avast.com/ Spybot Search & Destroy Anti-Spyware/Anti Adware Protection ...

Does the Apple Mac need Anti-Virus Protection?

Image
If you are running on the latest Mac OS X at home and you allow Apple to automatically update Mac OS X on demand, then my advice is No, you don’t need anti-virus protection on your Mac at home, well not at the moment anyway. Apple themselves go out of their way to state Mac OS X is not effected by viruses and protects itself from other malicious applications - "The Mac is designed with built-in technologies that provide protection against malicious software and security threats right out of the box" - Apple. A word of caution with my view, which will be highly controversial to some, the Mac malware situation could change in the future should the bad guys decide to target the Mac OS in anger. Theoretically this may happen if the bad guys started to find they aren’t getting any joy out of attacking Microsoft Windows PCs, however this is currently not the case, there are no significant shifts in the malware OS attack vector occurring. In my view, I feel the bad guys will actu...

Home Anti-Virus is Completely Free, as it should be

Image
It's a real travesty that many home users are for paying for anti-virus protection on subscription, not realising they can obtain solid anti-virus protection for free. Commercial anti-virus vendors have been snaring home users for years by providing their commercial AV applications with new PCs, often pre-installing their anti-virus application onto the PC operating system itself as a free trial. Once the free trial has finished, home users end up signing up to the AV on subscription through fear, not believing they have any other free alternatives for anti-virus protection. However home anti-virus protection should be completely free, and it is completely free. For many years it has been long my personal belief home anti-virus protection should be provided completely free of charge, and in the case of Windows Operating System (OS); the OS most plagued by viruses, worms, spyware and other malicious software (malware), it should be built into the...

New Podcast: Removing Viruses, Worms & Spyware

Image
This podcast is aimed at day to day people outside the IT security industry using Microsoft Windows. This podcast gives a quick over view on the types of malware (Virus, Worms & Spyware), describes how to prevent malware infection on your PC, and how to remove malware from your PC following infection. IT Security Expert Podcast - Mar2010 : Removing Viruses, Worms & Spyware ITSecurityExpert on iTunes Free Malware Removal Tools Recommended in this Podcast Microsoft Windows Malicious Software Removal Tool Spybot - Search & Destroy AVG Rescue CD There are other free malware removal tools out there, including those which run online in the web browser. If anyone wants to recommend any they have used, please go ahead and make your recommendation in this post's comments - Thanks Notes 1. "Malware" is a collective term which includes Viruses, Worms, Keyloggers, Trojans, Spyware, Adware, and apps referred to as Crimeware 2. I recommend running these tools...

UK Shops with Minimum Spend OR Charges for Accepting Card Payments

Image
I really love those new Visa World Cup Football TV and the Barclaycard Contactless Card commercials (see below). These ads depict using Visa and Barclaycard plastic to pay for small transaction amounts, such as using your credit card to pay for your lunch, and paying by card for a haircut. But these TV commercials representation does not quite match the reality on the ground in the UK, where many cardholders appear to be continually taken advantage of and are becoming frustrated by small merchants shops who either apply a surcharge, or insist on the minimum spend for payments by card. This reality is in direct conflict with Visa, MasterCard and Barclaycard's overall strategy, namely for card payments to replace all cash payments, hence the recent introduction of contactless payments in the UK. Contactless cards are not just designed for your convenience but to allow the card brands to soak up the small payment transaction space. Can Merchants Apply a Mi...