Posts

Showing posts from 2015

2016 Cyber Security Predictions

In 2015 saw the rise of hackers motivated to steal data for the purpose of public extortion and public shaming. The Ashley Madison data breach was one highest profile examples, where the hackers attempted to blackmail the company to close down its infidelity website operations. When the company failed to comply with hacker's demands, the hackers released millions of Ashley Madison members account details online. In 2016 I think we will see more company sensitive user databases targeted for the purpose of blackmail by cybercriminals, and for the purpose of public shaming by hacktivists, hell bent on causing reputational damage to any companies they take a dislike to. 2016 will finally see the demise of arguably the greatest user inconvenience and 'Achilles Heel' in cyber security, the humble password. In the coming year more organizations will embrace ‘no password’ authentication models, using authentication alternatives to a password, such as biometrics, picotograp...

What is Tor and Should your website block Tor users?

Image
Great infographic by State of the Internet which raises an interesting question, should websites block Tor users?  Certainly one for debate, my view is it depends on your website 'marketplace', function and risk, in other words perform a risk assessment, a lazy answer I know. But i f like me you find yourself often explaining what Tor is to business folk, so they can perform those risk assessments properly, you'll find this infographic comes in quite handy. As it does a simple job of explaining Tor; who uses it, how it provides anonymity  online, and how cyber criminals are embracing the tool for various illicit purposes. I recommend checking out the  State of the Internet website  for further info, statistics and reports on Web and DDoS attacks, which continue to blight the Internet.

TalkTalk Hacked (again) - Consumer Advice

A lot of TalkTalk customers have been contact with me today asking for my advice following TalkTalk's announcement of yet another major data breach . The TalkTalk press release states "there is a chance that some of the following data may have been accessed: Names Addresses Date of birth Phone numbers Email addresses TalkTalk account information Credit card details and/or bank details" And given TalkTalk are unable to confirm whether any of this data was encrypted when assessed, if you are a TalkTalk customer you should take this statement seriously and assume your personal information, bank account and/or credit card details you held with TalkTalk are now in the hands of cyber criminals and fraudsters. What to Do In summary all TalkTalk customers must be extra vigilant in checking their bank and credit card accounts for fraudulent transactions, and for attempts of fraud by covert cyber criminals using their personal information against them. Statement Che...

Top security best practices for IoT applications - Combating IoT cyber threats

I have written the following article for IBM which was published today on  IBM Development Works . https://www.ibm.com/developerworks/library/iot-security-best-practices-iot-apps/ The Internet of Things is changing the way that businesses operate, especially in the areas of warehousing, transportation, and logistics. These changes make the security of IoT devices even more crucial, given the time and money that is required if a hacker breaks through the defenses. This article outlines the best practices for securely developing robust IoT solutions.

To Firewall or not to Firewall – Trusted & Untrusted Networks

The big danger of firewall deployments within a complex dynamic network infrastructure (a typical enterprise) is you end up with placebo network security. It is a problem that creeps in with each firewall rule change over the course of time. No one ever seems to be concerned when adding a new rule to a firewall ruleset, but removing a rule is a fearful business, so often it is not risked, so not to break anything.  The g eneral adhoc adding of rules without first understanding the entire ruleset is what seriously weakens firewall security, it makes rulesets hard to understand and can mushroom into an ineffective firewall configuration. So instead of allowing a network range through on specific set of ports as a single rule, you end up with tens of rules allowing individual IPs each on a specific port. I have seen firewall rulesets with thousands of unnecessary individual rules, caused by a combination of poor firewall management, lack of change control...

Enviable Business Cloud Adoption & Cloud Security

I was quoted in an interesting discussion type article on Business Cloud Adoption at  CIO.com   How Line Of Business Is Driving The Move To The Cloud I have picked out my quotes which underlines my view that IT and Security functions must be agile and accommodating to the business cloud wants. While the business in turn must be careful not be so bamboozled by the efficiency & cost saving gains, and all those sexy sales buzzwords, they neglect the security question when procuring cloud services. On Cloud Adoption “Quite often businesses adopt cloud services outside the IT function whether is it Sales using Salesforce or HR using LinkedIn for recruitment, or general staff using Dropbox,” said UK-based Information Security Expert Dave Whitelegg. “The traditional internal-facing IT department can be quickly left behind by buy-and-go cloud service adoption" On Cloud Security “Cloud data security concerns should be addressed by IT carrying out ...

Security Today - Cyber Information Security News Stream & Alerts Twitter Feed

Image
I was an early adopter to Twitter, opening my  @securityexpert  account back in October 2008, I found Twitter has been an excellent tool for picking up and sharing information security news, articles, major breaches and critical vulnerability alerts. As well as making my own contributions I often retweet tweets of InfoSec interest, education and intrigue, however I have always had a strict policy of never allowing my  @securityexpert  account to send any automated tweets, every tweet is manually sent or is retweeted by yours truly. Once you go down that road the personal nature of the account goes. I recognise that many of  followers of the account are interested are in the latest news, so with that in mind I have launched a new Twitter account to provide a more comprehensive and more regular stream of InfoSec news. @securitytoday  has been launched  to just tweet cyber information security related new...

Snoopers’ Charter Law Eroding our Digital Privacy is Sneaking In

Image
The UK parliament re-opened for business today with a new UK government, which means a new raft of laws. While the media and the public were pre-occupied with rights eroding laws on unions to take strike action, and the possible replacement of the Human Rights Act, there was another proposed law in the list which seriously erodes another fundamental human right, our right to privacy. In the last coalition government the Liberal Democrats blocked this law on privacy grounds, but with the LibDems blown away in last month's general election, there is nothing to stop a Conservative majority government placing the Snoopers' Charter law. Anti Austerity and Pro Union Protesters in London after the opening of Parliament The Snooper's Charter is actually the nickname for the Communications Data Bill. The intended bill will grant ‘official’ permission for UK government agencies to read our email, listen to our phone calls and access our web browsing history. The law require...

EU Data Protection Tsunami Warning

Image
I attended a couple of data protection conferences this month, I heard a significant amount of naivety about the proposed EU Data Protection regulations. I listened to supposedly expert DP speakers talk about lobbying for changes to the EU regulations, and a general denial that many of the new requirements were actually going to happen, hence my tsunami warning analogy. UK Business needs to prepare to surf EU DP Regulation Tsunami Seismic ‘once in a lifetime’ privacy Law Change By end of this year, or early next year at the very latest, the European Parliament will enshrine into European law the biggest shake up in data protection and privacy legalisation we'll probably ever see in our lifetimes, it is that huge of a deal. Granted it will likely take another two years before it comes into force.  Today we are standing on the beach, those that look will observe the dark spectre of a tsunami approaching far on the horizon, it is coming in, first we nee...

Lenovo's Superfish is Adware at Best and Malware at Worst

Image
Since the middle of 2014, Lenovo have been pre-installing a piece of software commonly known as 'Superfish' onto its new laptops and PCs. In recent days the "Cyber Security" press has questioned the validity of Superfish, saying that it invades personal privacy, and that it exposes Lenovo users to data theft, they do have a point. Although Lenovo aren't the first to covertly push the privacy boundary for commercial gain, and they won't be the last either. Adware at Best Superfish operates fairly covertly in the background of the operating system, as you search online the software returns related advertisements back onto the desktop. These advertisements are chosen by Lenovo, and provide revenue to Lenovo when clicked upon. This is in affect adware, namely a user unwanted and unnecessary piece of software running on the operating system, it appears to be of no benefit or aid to the user, its main purpose is to provide an income for Lenovo. If we needed any a...

The Ongoing Security Awareness Problem:

Image
Quite often I am sent reports, InfoGraphics and articles to post on this blog, many are too sales orientated or too off topic to consider, but the odd one is well worth sharing. So the following post and InfoGraphic has been provided by the UAB Collat School of Business , focusing on, in my view, the most riskiest and yet most neglected areas of Information Security, staff information security awareness. This is a little US focused, but the findings and advice mirrors what's seen within UK businesses. I've highlighted some very alarming statistics which shows the management 'god complex' attitude towards information security, and the business data leakage to the cloud. Employees and General Information Security Over 80%t of companies say that their biggest security threat is end user carelessness. 75% of companies also believe that employee negligence is their greatest security threat. 3% of all United States full-time employees admitted to using the same col...

2015 & UK websites still fail miserably to protect Customer Data

The New Year was ushered in with news that both Moonpig.com and the UK Police National Property Register websites, had vulnerabilities that placed millions of UK citizen’s personal information at risk of data theft. Moonpig had 3 million customer records exposed by a basic web application vulnerability. By changing the customer ID number on an unauthenticated API request (the website's Application Programmable Interface). An attacker could return different website users personal data, which included their name, address, birth date and email address. By writing a simple script an attacker could (might) have taken a copy of millions of customer records. Worst still this serious vulnerability was reported to Moonpig some 18 months ago. It only takes a few minutes on the Moonpig website to see they are a million miles away from adhering to industry best practice web (application) site security, as advocated by the likes of OWASP . It appears that the Moonpig website has never...