Posts

Showing posts from September, 2013

2000 to 2013: The Moving Sands of Information Security

Image
I am been in the information security game for a very long time, many of the fundamental security controls haven’t really changed a great deal, and continue to remain best practice, such as deploying anti-virus, patch management and decent firewall management, the business environment where these security controls are applied has radically shifted, especially over the course of the last decade.   So lets take a trip down memory lane back to the year the 2000, the world has just found out that the Y2K bug was a complete none starter, aside from making IT contractors a bob or two. Meanwhile the Internet is starting to find its way into mainstream business, even so secretaries were still being asked if they had any experience in using the Internet during job interviews. And if you had a job title with the word “Cyber” in it, people assumed you were some sort of a Dr.Who extra. Policies Starting with the cornerstone of all good information security management, the informatio...

Security by Staff Responsibility instead Enforced IT Controls

Image
Today IT security controls are enforced on the end user without prejudice, all for the purpose of migrating the human risk. These controls, especially endpoint security controls, are typically applied because it is best practice to do so, and not as a result of a risk assessment.  What if the application of technically enforced security controls was taken as an action of last resort? Can human responsibility be be just as affective as an enforced control? Can it be more advantageous in managing the same risk?   These our my thoughts. Lets take a English FA Premier League football match, there is a risk that spectators in the stands will invade the pitch, and impacting on the match and threatening safety  Yet spectators rarely invade football pitches at English matches, even though they aren't fenced in. A fence is an example of an enforced control meant to prevent fans from accessing the pitch.  My argument is the fans are self re...

iPhone 5S "Touch ID" Fingerprint Security

Image
Apple announced the new iPhone 5S today, the introduction of a new fingerprint recognition access system on the smartphone, called "Touch ID", grabs the security attention. Fingerprint reader is the main button Security of the Fingerprint Reader The fingerprint reader is not like the traditional readers you see on laptops, and is actually part of the main button on the phone. The reader is no security gimmick as it is not a outdated optical reader, which works by taking and comparing a picture of your fingerprint, it is a capacitance reader,which is a more advanced and secure technology. Capacitance readers uses an electrical current to map your fingerprint, measures the minuscule differences in conductivity caused by the raised parts of your fingerprint, which makes it very difficult to defeat. I don't like to advocate the security of anything without inspecting, researching and testing a device myself, but I will say this reader has certainly been designed ...

Square Enix Final Fantasy XIV Accounts Security Warning

Last week I posted on  How to keep your Final Fantasy XIV Online Account Safe & Secure Today (9th Sept), Square Enix posted an urgent security warning concerning account security for the game. Confirming a "third party" was using account names and passwords, which they believe to have been obtained from security breaches of other companys' online services. Square Enix's advice mirrors my own, setup and use their one-time password system, or ensure your password is unique to your Square Enix account Since my post I have been asked...  Why would anyone be interested in hacking gaming accounts like FFIX? 1. For the Money. Rare in game items, which it can take many hours of gameplay and luck to obtain, can be sold off in game auction houses for a great deal of game currency. Players over the course of time built up lots of such items and lots of in game currency (gold/gill), these rewards for sometimes hundreds of hours of gameplay hav...

GCHQ Cracks SmartPhone Codes, Privacy Outrage or Lifesaver?

The Edward Snowden fallout continues with the steady trickle of classified revelations released by the media.   The latest appears to be confirmation of GCHQ ability to crack or bypassed the encryption on Blackberry and Android smartphones. This news isn't really that shocking given cracking encryption is a core part of what GCHQ has done for decades. It is also important to understand that nowhere does the released documentation say GCHQ have been breaking into everyone’s smartphones and harvesting our private data on mass, I doubt they’ll have resource and funding in the UK to do that. My assumption is breaking smartphone encryption is a necessary GCHQ tool for gathering information on specifically targeted bad guys, for example suspected and known terrorists.  Several terrorist plots have been foiled since the 7/7 atrocities, so what if GCHQ's ability to access encrypted smartphone electronic messaging and call information, had played a key par...

Bullrun & Edgehill: US NSA & UK GCHQ have broken Internet Encryption

I have always suspected this and now according to newly leaked documents  by Edward Snowden, the NSA and GCHQ are said to have defeated most of the online encryption used by internet users and the likes of Microsoft, Google, Yahoo and even banks. The usage of supercomputers, court orders and the good old application of pressure to internet service providers, are all said to be tools used to gain access to encrypted data by the government agencies. "In recent years there has been an aggressive effort, lead by NSA, to make major improvements in defeating network security and privacy involving multiple sources and methods, all of which are extremely sensitive and fragile" "NSA has introduced the BULLRUN CoI to protect our abilities to defeat the encryption used in network communication technologies" The US programme name is Bullrun, and is said to have a £150m annual budget, while the UK GCHQ counterpart is called Edgehill. These codewords come from battles in ea...