Posts

Time to Start Preparing for the New EU Data Protection Law

Image
It's not secret that the UK Data Protection Law is long overdue a major overhall. Today's data protection law was actually devised in the early 1990s, long before the Internet explosion, Google and Facebook didn't exist, while common day concepts like big data mining and cloud computing was even beyond the imagination of science fiction writers of the time. The UK Data Protection Act (1998) is mostly derived from the European Data Protection Directive of 1995 and the 1984 UK DPA. Back in 1995 there was barely one million internet users in the UK, since then the usage of digital personal information has massively changed, it is high time for our data protection laws to catchup. Human rights is a cornerstone of the European parliament's legal approach, with the right to privacy and the protection of personal data, regarded as a fundamental right for every EU citizen. For years European MPs have sort to introduce tighter privacy and data protection laws, how...

Heartbleed made Simple

Image
HeartBleed has suddenly become a very well known security  vulnerability, because this simple vulnerability in OpenSSL has turned out to be  one of the most critical and potentially devastating of all time, with over half million trusted websites said to be vulnerable . Over the last couple of days various security advocates and vendors have been lined up by  the media , with ominous warnings of grave danger online due to Heartbleed. Heartbleed is a Catastrophic Bug in OpenSSL - Bruce Schneier However I have generally found main stream media have focused far too much on trying to sensationalise instead of explaining the vulnerability properly, and not explaining how organisations should resolve the problem, and how users can protect themselves. It is fair to say the media coverage has led to much confusion on Heartbleed, with both organisations and users alike, which I’ll attempt to dispel. Heartbleed made Simple Heartbleed, also ...

Security Awareness Lesson on Loose Lips by Football Stars

Image
Last week I was left rather concerned about the state of security awareness in the UK, after hearing various people in my train carriage rattle on loudly about information which was clearly meant to be kept confidential , a World War II awareness phrase comes to mind, Loose Lips sink Ships.  However my faith in personal security awareness has been somewhat been restored, as over the weekend I noticed many football superstars demonstrating a very simple security control, a control which I believe has been coached to them by their clubs, in other words information security awareness training. This simple tactic is to cover your month when speaking, a technique used to mitigate the risk of media, and perhaps opposition teams, from being able to eavesdrop what you are saying, namely by them using lip reading experts to interpret what is being said by watching TV or camera footage. This practice was very evident in last night’s El Clasico, Real Madrid versus Barcelona, a ...

Information Careless Great Britain: All Aboard the non-Privacy Train

Image
This week I experienced a rather concerning two hour journey from London aboard a Virgin Pendolino train. Might be the Age of the Train, but it's not the Age of Privac y Awareness I had just taken my seat on board, and the train had just cleared the tunnel just north of Euston station. As I was settling in to the journey I noticed something through the gap of the two seats in front, like a magpie drawn to a sparkling object, something had caught my eye. I have spent years conducting security assessments, checking system logs and databases for the presence of credit card data. During this time I have unwittingly developed the canny knack of quickly spotting a 16 digit primary account number of a credit card, along with a expiry date and the 3 digit security code. My eyes were drawn to the laptop screen of the passenger in front, which had a webpage fully on show, which displayed his typed in credit card details, including the 3 digit security code, which was not obfuscat...

Was Flight MH370 Cyber Hijacked?

Image
The disappearance of Flight MH370 is turning into one of the biggest mysteries of the age, the evidence is sketchy, everyone seems to have their theory, and the media are running riot with endless speculation. As a security professional I can’t help but wonder whether there was a cyber element to the incident, especially given the high amount of technology used in modern fly-by-wire jet planes like the Boeing 777-200ER. Was Flight MH370 Cyber Jacked? I have managed and consulted with many cyber security incidents over the years, but the following will be my own conjecture. When I usually deal cyber incidents, my golden rule is to only deal with the facts and the evidence, and saving any speculation for the Sherlock Holmes fan club. But with this incident I am allowing myself the luxury of exploring potential cyber attack possibilities with the MH370 flight disappearance, as over the week quite a few people have asked me whether the flight could have been hacked, the ‘cyber j...

GCHQ Privacy Disregard Touches the Optic Nerve

The latest GCHQ revelation courtesy of The Guardian and Edward Snowden, is arguably the most privacy damming of them all. A GCHQ surveillance program called 'Optic Nerve', collected more than 1.8 million webcam imagines from Yahoo chat accounts between 2008 and 2010. The program saved one webcam image every five minutes from unknowing Yahoo users using private webcam chat.  One of the stolen GHCQ memos made no bones that the service struggled to keep the large store of sexually explicit imagery collected from the eyes of its staff. The fact these images were collected on mass and indiscriminately without the knowledge of Yahoo's users, the vast majority of which are law abiding, is a real privacy invasion. Most worryingly is that such an undertaking could be "green lighted" by senior officials, this beggars belief, pointing to a general lack of human morality and to the uncontrolled power our security agencies have. This is what happe...

Has your Website Account been Hacked?

The relentless stream of data breaches by big business continues, with the likes of Vodafone ,  Tesco , Sony , Adobe and Yahoo , all losing their customer's personal data on mass due to their inadequate security. How do you know if your username, email address and password have fallen into the hands of a cyber criminal due to these breaches? There is one website that seeks to provide some assurance to that question,   https://haveibeenpwned.com  appears to be have acquired the stolen data from the Internet's criminal underworld and allows anyone to freely search it for their own username and email, the website returns a response which states if the account is known to have been compromised or not, namely listed within the stolen database. The website says it has over 161 million stolen accounts that are searched, all this data has been compiled from several of the high profile data thefts. Although the hacked businesses are responsib...