Showing posts with label movie. Show all posts
Showing posts with label movie. Show all posts

Tuesday, December 8, 2015

The First Rule of Security




   That's a classic scene from a great movie.  And, if you think the movie is twisted, you should definitely read the book or the audiobook!

   Many people know that the first rule of Fight Club is that you don't talk about Fight Club.  That's because they didn't want to draw attention.

   But in security, the first rule of security is:


   That means a number of things:
  • Security Awareness - a program at your organization to promote security themes.  I like to focus on information people can use at home.  I've talked about this in the past.
  • Public Awareness - similar to security awareness but here security pros, IT pros, law enforcement pros, or really anyone, talks to the public about security and privacy issues.  There are opportunities through the schools, community centers or school district parent organizations.
  • Conferences - are a great way for people to learn more about security and for security and IT pros to learn more, improve their skills and make great contacts.  I was recently at the HIMSS Privacy & Security Forum in Boston.  I saw old friends and made new ones, heard some great speakers (and did a bit of speaking myself) and learned a few things.
  • Professional Organizations - There are many IT and security professional organizations.  Some of the organizations I participate in include ISSA, ISACA and Infragard.  There are local chapters in most areas.
  • Other local groups - in addition to the formal professional organizations, many areas have local groups for security leaders or security practitioners.  You can find out about these groups and conferences or professional organization local meetings.
  • 1:1 discussions - talk with a security pro about security!  Even better... talk with someone who's not a security pro about security!
   Here's the thing... the attackers - the people who are trying to break into networks or your home computer to steal data - talk to each other.  They share ideas and techniques.  They learn from each other.  We must do the same.

   How do you talk about security?

Tuesday, September 1, 2015

The XORcist (aka Get Rid of Bad Encryption)

   I remember when the movie version of the Exorcist came out.  I was in high school and it was probably the scariest, most graphic movie released by that time.  Parents didn't want their kids to see it.  There were all kinds of media discussions about the potential detrimental effects to roller-skating Linda Blair, who played the possessed Regan.  It was a freaky movie, at least for it's day, though it was way surpassed in gore by the slasher movies of the 80s.

   I recently read the book (well, you know... audiobook!).  It's well written and I recommend it.  But it is graphic, and there's plenty that wasn't in the movie.

   Easily as scary is the way many systems and sites handle encryption!  For those who don't get the title... XOR is a basic mathematical function that all computers can do easily and quickly.  It's critical for computer operations, and is used in some encryption operations, but is not really a strong encryption method by itself.  If you want to learn more about XOR, look here or here.

   I've covered problems with passwords many times here.  One of the problems that has allowed password breaches to work is poor encryption of the password file.  XOR is not a strong encryption method!

   So what does this all mean?  I have two messages... one for programmers and one for everyone else.

   Programmers.  Don't invent your own encryption.  There are fantastic, freely available encryption routines out there that you can use in your code.  Or, your organization may already have standard encryption methods you can use.  Bottom line is that 2000 years of mathematics has led us to some pretty solid encryption algorithms.  Use them!  Friends don't let friends use bad encryption!  Here are some great references.

   Everyone else.  Password storage should use something we call a "one-way hash".  Not a tasty dish, but a method of encrypting data so it can't be decrypted.  That means that no one should be able to tell you your password!  So, if you call customer support or the help desk because you forgot your password, and they can tell you your actual password... run!


   Can you think of any examples of bad encryption?  Do you know of any websites that can show you a forgotten password?