Showing posts with label Quote. Show all posts
Showing posts with label Quote. Show all posts

Wednesday, March 28, 2007

Another Cup of Cocoa: Responsibility

MySpace, YouTube, Web 2.0 there is so much happening and available out there. It is all exciting and there are so many possibilities opening up.

The freedom of the Internet and web works both ways. The same technology lets you explore web sites on the other side of the world allows anyone in the world to attack your system and steal from you.

In the real world people choose where to go and can avoid areas where the "criminal element" tend to hang out, or if in a less reputable neighborhood one can always be aware of the surroundings. On the Internet it isn't quite as intuitive, but there are steps that should be taken.

First everyone must take responsibility for them selves. Just like when we lock our doors and put safety belts on in the car.

As stated before hardware firewalls, software firewalls, and anti malware software should be installed and kept updated.

Mcafee Site Adviser works on both Internet Explorer and Firefox and can provide a warning when you wander into a "bad" site, and better yet will post warning on Google search listings to warn you prior to an actual visit.

Javascript has contributed greatly to the look and feel of the web today, but while many sites use it on many it is not necessary. Javascript is so powerful that it is used for malicous purposes as well including drive-by-downloading. With Internet explorer script control is an all or nothing option turn it on for a site or turn it off for the site. Firefox with the NoScript add-on allows more granular control and allows controls within the web page.

Stay tuned for the next Cup Of Cocoa post about "sand boxing" to help contain malware. Until next time remember:
In view of all the deadly computer viruses that have been spreading lately, Weekend Update would like to remind you: when you link up to another computer, you're linking up to every computer that that computer has ever linked up to.
— Dennis Miller

Tuesday, March 6, 2007

Risk Options

Old, but still relevant.
Wisdom consists in being able to distinguish among dangers and make a choice of the least harmful.
— Niccolo Machiavelli, The Prince
Value vs. Cost

This is still one of the hardest aspects of security today. What are your different assets worth and how much will you spend on protecting them? The difficulty raises when intangible assets are involved. How much is a customer list worth? What about credit card information?

For a corporation a $2,000 laptop is not a major asset, but when customer data resides on the laptop the value of the asset just increased. Now spending $1,000 on the laptop's security (Physical lock down cable, encryption, phone home software, etc.) may be an acceptable cost.

On the other had when is risk transfer the best solution?

Consider the owners of rare gems and artwork. I bet every single one has an insurance policy that covers theft and destruction. While the owner would rather keep the object some or all the financial risk is transfered to the insurance company.

Monday, March 5, 2007

https is all I need, right?

Everyone talks about only sending you information over a secured connection when ordering or sending personal information over the internet, but is that all you should be concerned about?
Using encryption on the Internet is the equivalent of arranging an armored car to deliver credit card information from someone living in a cardboard box to someone living on a park bench.
— Gene Spaffor
In other words both ends of the communication must be secure. With phishing, pharming, malware (including rootkits), drive-by-downloading, computers without passwords, etc. Your home computer is at risk. What are you doing to protect your computer?

Then there are all the security breaches and lost computers, tapes, etc at the web sites/stores you shop at. look at TJX the company behind JMaxx, Marshalls, Winners, HomeGoods, TKMaxx, AJWright, and HomeSensse. TJX experienced, and tried to cover-up, one of the most extensive long term security breaches in history. Additionally it has been the one that has had the most fraudulent charges directly linked to the break-in.

Don't let a secure connection lull you into a false sense of security. Your personal information my already be out there.

Sunday, March 4, 2007

Evolution: Fun, Bragging Rights and Profit

In the Beginning

Back in the old days it was the curious looking to expand their understanding of systems. They could hack together a program in fact the best hack was the most concise and elegant code.

Organic Evolution

Some of these hackers turned their focus deep into the bowels or the computers and their operating systems. Of course this required a higher privilege level so cracking into accounts with greater privileges, usually called root on unix systems, and thus began the evolution of the modern day hacker.
Sidenote: Crackers are hackers that use their skills for breaking into systems, in much the same way as an assassin uses their abilities as a marksman to kill. Alas the public has picked up the term hacker so life goes on.
Pressure to be the best

As time passed pride demanded that these hackers proclaim their victories to the world. hackers would post their conquests on underground communication channels and then started proclaiming them to the world in the form of defaced web pages.

As time passed and tools automated finding and breaking into systems. At first these where transfered "underground," but many migrated to the mainstream. Additionally security researchers and administrators began to write their own tools to find and patch the holes before the hackers did.

Scavengers Appear

These tools gave rise to the script kiddies. People that learned how to run the tools, but did not know how to use them. These are the people that scan large blocks of the internet looking for something to attack. They tend to attack based on port not application. in other words these are the ones that launch Microsoft IIS attacks on Apache Web Servers.

The hard core criminal element eventually caught wind of this new avenue for illegal profits. This has given rise to two basic criminal categories the botnet herders and the professional crackers.

Botnet herders initial growth and expansion is very similar to script kiddies. In their recruitment phase spam, drive-by-downloads and scans are used to recruit new bots, or zombies, into the herd. These botnets can then be used doe DDoS attacks, SPAM prorogation, and other nefarious for profit motives.

The professional cracker will case their target and look for vulnerabilities and unprotected avenues to launch their attack. The professionals will learn their prey including partners, remote workers, IP addresses, key employees, environment.
Amateurs hack systems, professionals hack people.
— Bruce Schneier
Update: The professional hackers tend to be freelancers or directly controlled by organized crime.

Saturday, March 3, 2007

One

One simply one. One crack one unguarded entry point of entry or one moment of opportunity. So true, and so deadly at the same time:
We only need to be lucky once. You need to be lucky every time.
— The IRA to Margaret Thatcher, after a failed assassination attempt.

Probably the most famous example of one point of weakness is Achilles heel (http://en.wikipedia.org/wiki/Achilles%27_heel). In short Achilles' mother dipped him in the river Styx, and the water from the River made him invulnerable. Except for where the mother held him with her finger and thumb on his heel. Thus he was invulnerable except one spot, his heel, which lead to his downfall.

Friday, March 2, 2007

Why is Defense so Hard?

The basic premises is that you defend every attack vector. While the attacker probes for the one weak point where your defenses can be bypassed or breached.
Securing a computer system has traditionally been a battle of wits: the penetrator tries to find the holes, and the designer tries to close them.
— M. Gosser
When possible in the physical world fortifications are used to limit the attack vectors and defense in depth is obtained by layering using obstacles such as walls, cliffs, moats, and rivers.

A more modern description could be a football game The goal, pun intended, is to breach the other teams defense and score.

No one gets points added to their score for the number of plays that are successfully defended against.

Sunday, February 25, 2007

Isn't that so cute...

The user's going to pick dancing pigs over security every time.
— Bruce Schneier


This in one sentence summarizes how the bad guys penetrate defenses time after time. how can that cute little game be harmful.

This is also why Vista's UAC giving administrator rights to every setup program that is run.

Friday, February 23, 2007

Ultimate Security

Now this is getting to be truly secure:
"The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards - and even then I have my doubts."
- Gene Spafford, Ph.D., Purdue CERIAS

I like to expand on this by having the concrete cover computer sealed in a lead box that is dropped off at a random location in the ocean... then of course you have to kill the crew to keep the location secret.

BTW there is no data recovery option with this level of security.

Thursday, February 22, 2007

Liberty Boxes

Everyone runs across quotes in their digital life, and some are worth sharing.
"There are four boxes to be used in defense of liberty:
soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)