Two hikers are walking through the woods. They come around a bend in the trail into a clearing where they can take a break, when suddenly a bear steps out of the woods and roars. One hiker quickly bends down to tighten his boot laces. The other hiker says, "what are you doing? You can't outrun a bear!". The first hiker says, "I don't have to outrun the bear, I only have to outrun you!".
One of the biggest changes in information security over the past two decades has been with the attackers. Rather than the old stereotype of a hoodie-wearing loner in the basements with Mountain Dew, Twinkies and old computers, today's attacker is typically trained, smart and well-funded. Instead of defacing websites for fun and notoriety, attacks today are a business.
It's a simple risk/reward equation. There is a cost to any attack. Email-based attacks are very inexpensive to launch. Developing sophisticated malware is expensive. And the more expensive an attack is pull off, the higher the potential gains need to be to make a profit.
Information security is very complex. It's as much an art as it is a science. There are basic things that everyone should do, like patching systems and using strong, long passwords. And then there are complex solutions to complex problems that need to be artfully implemented to compliment the way people do their work.
There are so many high profile breaches in the news. Some of these are the result of highly skilled and motivated attackers going after a specific target. But many more are "crimes of opportunity".
As I see it, there are basically three kinds of online attacks:
A place to talk about information security, Internet safety and, of course... coffee!
Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
Showing posts with label basics. Show all posts
Showing posts with label basics. Show all posts
Tuesday, November 28, 2017
Tuesday, October 4, 2016
Can't Live with 'em, Can't Live without 'em
They're dead. They're here to stay.They're safe. They're breached.
They're encrypted. They're visible.
They're complex. They're too simple.
Once again, the topic we love to hate... Passwords! And, you know what else??? It's also that greatest of holiday celebrations... US Cyber Security Month!In honor of US Cyber Security Month and the recently announced breach of 500 million Yahoo! account passwords and other info (while announced in 2016, the breach actually took place in 2014, and is not the same as the password breach they had in 2012! - yes, I know... it's hard to keep up!), I'm re-running a post I wrote in... wait for it... 2012! Not only is everything I wrote in that post 100% relevant today, but I even commented on that 2012 Yahoo! breach. The more things change, the more they stay the same. Happy Cyber Security Month!
-----------------
Passwords are a mess! A "good" password has these features:
- hard to create
- hard to remember
- hard to enter
- probably has to be changed as soon as you memorize it
- plus other inconsistent, random rules depending upon the site
Perfect!
Tuesday, August 23, 2016
ESCROW - Extreme Security Cool Resource Of the Week!
ESCROW - Extreme Security Cool Resources Of the Week. OK, well sometimes you start with the acronym and see how you can make it work! And I've got a good one for you.
It's a bit geeky, but if you're interested in learning more about the more in-depth technical aspects of security you will enjoy this resource. And I've got another, less geeky, resource.
Everyone knows about Youtube. You can find just about anything there, but there's so much content that sometimes it's hard to find what you're looking for.
Enter SecurityTube, securitytube.net, and SecurityTube, securitytube-training.com - originally created as a way to aggregate information security videos in one place. These are some fantastic free online learning resources.
Some of the resources have difficulty ratings to help you choose the right course of video. For example, this one on Wireless LAN (WLAN) security is rated "easy" (and that's certainly in the eye of the beholder!).
For those who don't want anything that in depth, here's another tip. You can go to Youtube and search for "cybersecurity for beginners". There are many basic information security videos there including this one from NOVA PBS:
Check some of these out and let me know what you think!
It's a bit geeky, but if you're interested in learning more about the more in-depth technical aspects of security you will enjoy this resource. And I've got another, less geeky, resource.
Everyone knows about Youtube. You can find just about anything there, but there's so much content that sometimes it's hard to find what you're looking for.
Enter SecurityTube, securitytube.net, and SecurityTube, securitytube-training.com - originally created as a way to aggregate information security videos in one place. These are some fantastic free online learning resources.
Some of the resources have difficulty ratings to help you choose the right course of video. For example, this one on Wireless LAN (WLAN) security is rated "easy" (and that's certainly in the eye of the beholder!).
For those who don't want anything that in depth, here's another tip. You can go to Youtube and search for "cybersecurity for beginners". There are many basic information security videos there including this one from NOVA PBS:
Check some of these out and let me know what you think!
Labels:
basics,
cybersecurity,
information,
infosec,
online,
resources,
security,
SecurityTube,
video,
wifi,
Youtube
Tuesday, September 15, 2015
Bring It On Home
I'm giving a presentation at the Twin Cities ISSA Security Awareness SIG. I'll be talking about a number of different methods I've used over the years to create buzz and interest about security and make topics accessible to everyone.
I was planning to refer to one of my earliest blog posts, covering my general philosophy on this topic. But... going through past posts it appears that, while I've alluded to the ideas, I never actually wrote the post! So I'll do that now!
Like the song says, I try to bring it on home. I find that while people do want to understand security rules at work, when we start talking about things like home computers, smart phones and family internet safety, then we get peoples' attention.
And that's a great thing! For a bunch of reasons:
I was planning to refer to one of my earliest blog posts, covering my general philosophy on this topic. But... going through past posts it appears that, while I've alluded to the ideas, I never actually wrote the post! So I'll do that now!
Like the song says, I try to bring it on home. I find that while people do want to understand security rules at work, when we start talking about things like home computers, smart phones and family internet safety, then we get peoples' attention.
And that's a great thing! For a bunch of reasons:
- When people think about protecting themselves and family and data, it helps them remember that in the office we are protecting customers'/patients'/users' privacy and data.
- Security needs the eyes and ears of all staff to help us know what is going on. Security Awareness focusing on personal topics helps open the communication channels to the security team. We're not so scary! :-)
- When staff understand more about how security topics can help them, we gain real evangelists.
And yet there is still controversy about the usefulness of Security Awareness. But I think it's one of the most important and useful things we can do to help secure our environments.
Here's a link to the slides from my presentation.
And here are a few of my past favorite security awareness posts:
If you are a computer use, what are some topics you'd like to learn more about?
If you are an information security professional, what tips and techniques would you like to share?
If you are an information security professional, what tips and techniques would you like to share?
Tuesday, September 9, 2014
(SuperValu) Wrote Me A Letter
I'm hearing the Joe Cocker version of Box Tops song! (though I always picture John Belushi doing this!)
I don't want my summer to end, but October is coming soon and, in the US, October is National Cyber Security Month. This will be the first post of a series on Identity Theft that will carry us into October.
First of all, the term Identity Theft is a misnomer. According to Findlaw:
First of all, the term Identity Theft is a misnomer. According to Findlaw:
Theft is often defined as the unauthorized taking of property from another with the intent to permanently deprive them of it. Within this definition lie two key elements:But, with Identity Theft, your identity is not actually stolen, because you still have use of it. A more accurate term is Identity Fraud. Someone is using your identity, without permission, to execute fraudulent transactions or commit other crimes. And, in many cases it's just aspects of identifying or financial information that is being used fraudulently, like your credit card.
1) a taking of someone else's property; and
2) the requisite intent to deprive the victim of the property permanently.
The taking element in a theft typically requires seizing possession of property that belongs to another, and may also involve removing or attempting to remove the property. However, it is the element of intent where most of the complex legal challenges typically arise in theft-related cases.
Labels:
access,
account,
activity,
attack,
basics,
breach,
communication,
consumer,
Heartbleed,
identity,
identity fraud,
infosec,
practices,
stolen
Tuesday, May 13, 2014
The Best (First Good) Password Policy Ever!

- good passwords are hard to remember, and;
- passwords you can remember are easy for attackers to guess.
- 8 characters;
- upper/lower case;
- numbers;
- special characters.
Labels:
access,
account,
ArsTechnica,
basics,
controls,
encryption,
infosec,
login,
master password,
password,
passwords,
policies,
policy,
practices,
vault
Tuesday, April 29, 2014
How Do You Spell CISO? - What's a CISO Do? part 2
For those of you who are not familiar with Secure360, it's THE upper midwest US security conference. There's still time to register, come on out and enjoy!
There are many demands on the CISO. But part of the art of the position is to juggle the more granular tasks with overall priorities while trying to be strategic.
Labels:
assessment,
assets,
basics,
business,
CISO,
CObIT,
compliance,
enterprise,
good_practices,
maturity,
NIST,
planning,
program,
roadmap,
strategy,
tactics
Tuesday, November 5, 2013
Cyberbullying - Improvements or More Problems?
In addition to Cyber Security Awareness Month, October was also Cyberbullying Awareness Month. There were a number of online campaigns to raise awareness on the topic including some high-profile pages on Facebook and Cartoon Network.This is an important topic and needs our attention. I have given many presentations over the years on Internet Safety topics. This past weekend my wife, a clinical psychologist, and I partnered on a presentation on Bullying and Cyberbullying at our local school district parent fair. Here are the slides.
Unfortunately, bullying has been around as long as there have been people. The internet, social networks and mobile devices supplement have turned "old school" bullying into a 24x7 assault.
Labels:
awareness,
basics,
bullying,
cyberbullying,
cybersecurity,
hero,
internet,
kids,
online,
people,
schools,
social,
social_network,
support,
teens
Tuesday, October 15, 2013
Online Self Defense - Passwords
Next week I'll be presenting at the Cyber Security Summit in Minneapolis. I hope to see you there!
It's Cyber Security Month! And the more things change, the more they stay the same. The key advice for online self-defense I've given in the past is just as true now. So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.
Last week I started a series on themes I covered in a talk entitled "Online Self-Defense". In part 1 of that series, posted here, I talked about protecting your computer. This week we'll look at passwords.
Passwords are a mess! A "good" password has these features:
It's Cyber Security Month! And the more things change, the more they stay the same. The key advice for online self-defense I've given in the past is just as true now. So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.
Last week I started a series on themes I covered in a talk entitled "Online Self-Defense". In part 1 of that series, posted here, I talked about protecting your computer. This week we'll look at passwords.
Passwords are a mess! A "good" password has these features:
- hard to create
- hard to remember
- hard to enter
- probably has to be changed as soon as you memorize it
- plus other inconsistent, random rules depending upon the site
Perfect!
Tuesday, October 8, 2013
Online Self Defense - Your Computer
It's Cyber Security Month! And the more things change, the more they stay the same. The key advice for online self-defense I've given in the past is just as true now. So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.
Happy US Cyber Security Month! This partnership between Homeland Security, NCSA and MS-ISAC is an opportunity to recognize the importance of information security. How are you celebrating?
Last week I ran a couple of sessions at work on awareness and security. Over the next few posts I will be reviewing some of the 3 themes I covered in a talk entitled "Online Self-Defense". You can view the slides on my slideshare page. (actually, the talk focuses on just 2 of the themes but that's OK!). Since everything comes in threes (omne trium perfectum), I will give 3 easy tips for each theme (and some bonus tips as well).
The first theme is protecting your computer or device.
Happy US Cyber Security Month! This partnership between Homeland Security, NCSA and MS-ISAC is an opportunity to recognize the importance of information security. How are you celebrating?
Last week I ran a couple of sessions at work on awareness and security. Over the next few posts I will be reviewing some of the 3 themes I covered in a talk entitled "Online Self-Defense". You can view the slides on my slideshare page. (actually, the talk focuses on just 2 of the themes but that's OK!). Since everything comes in threes (omne trium perfectum), I will give 3 easy tips for each theme (and some bonus tips as well).
The first theme is protecting your computer or device.
Labels:
anti-malware,
apps,
automatic,
basics,
controls,
cyber,
cybersecurity,
firewall,
malware,
mobile,
network,
online,
passwords,
patching,
protections,
router,
security,
tablets,
technology,
updates
Tuesday, September 3, 2013
Putting the Face in Facebook
As can happen in a month whose name contains an "a", "e" or "u" :-), Facebook has once again made changes to its privacy policy and practices. And, as always we all have two choices: accept the changes (and adjust our settings and practices appropriately), or; leave Facebook.
Of course most people won't leave Facebook, and if anything they will add more users than those that leave.
As I look through the changes (see Facebook's notice here with links to the details), I think there are three things to know...
Tuesday, August 20, 2013
Beyond the Checklist - Compliance v. Security
The point of the article is something I've been saying for years... That we can simply treat security regulatory standards as checklists. It's not about just meeting the minimum requirements. It's about integrating the standards into your security program.
Now, I'm not completely dismissing checklists. In fact, I think they have some great places within your program. For example: server build checklists; server hardening checklists, and; an SDLC checklist. I'm a big fan of the CIS checklists for hardened configurations. I also like a standardized secure engineering process (or SDLC) with specific steps.
As I've discussed here in the past, one size does not fit all. While we can all share our processes, it's critical to tailor any process or checklist to your environment.
But here's my main point... Compliance does not equal Security!
Labels:
access,
alignment,
basics,
business,
checklist,
compliance,
computer,
cybersecurity,
effectiveness,
encryption,
framework,
good_practices,
infosec,
PCI,
program,
requirements,
SDLC,
security
Tuesday, July 16, 2013
Are You the Customer... or the Product?
I regularly speak with people about Internet/Online Safety. One message I frequently give about free online services is:
I'm a big fan of free online services, but it's important that people realize what's going on. It starts with the privacy policy, which explains how an online service intends to use your data and information about you.
But I want to talk about cloud storage services. These services allow you to backup files, sync files between systems and devices, and have files available from anywhere. How are your files protected?
You're not the Customer... You're the Product.We often see people upset about changes in social networks like Facebook. Folks complain about "customer service", not realizing that they are not the customer! It's often the advertisers, or other backers, who are the real customers. And what those customers want is information... about the users of the service.
I'm a big fan of free online services, but it's important that people realize what's going on. It starts with the privacy policy, which explains how an online service intends to use your data and information about you.
But I want to talk about cloud storage services. These services allow you to backup files, sync files between systems and devices, and have files available from anywhere. How are your files protected?
Tuesday, July 9, 2013
The More Things Change...
As the saying goes... the more they stay the same. In our ever-changing world of technology and security, it always amazes me how things often don't change!
Let me clarify... there's always a totally new technology, programming language or social network to learn. Of course, computing power has changed drastically. Many of the techniques used by attackers to gain improper access to our information have changed.
Though many have not. And the advice we give to consumers and business users to protect themselves has not changed! Consider...
Let me clarify... there's always a totally new technology, programming language or social network to learn. Of course, computing power has changed drastically. Many of the techniques used by attackers to gain improper access to our information have changed.
Though many have not. And the advice we give to consumers and business users to protect themselves has not changed! Consider...
Tuesday, July 2, 2013
Want someone's password? Just ask!
SC Magazine recently put out an article entitled: More users than ever experiencing phishing attack attempts. According to the article, phishing attacks are on the rise.
Phishing is simply any kind of communication intending to extract (typically) personal information from someone. The scam usually tries to either get the victim to visit a malicious website or directly provide their information, via a reply to the attacker or in an online form.
Years ago, phishing emails were easy to spot. They typically used obvious From: addresses, poor grammar and spelling, clearly misleading url's, and overall poor imitation of a legitimate organization's communication.
But, as is often the case, the phishers have gotten better. The emails look legit, the grammar and use of language is good, and the links often go to realistic-looking, but malicious, sites. And email isn't the only delivery method.
So, how do we avoid, and help others avoid, these attacks?
Phishing is simply any kind of communication intending to extract (typically) personal information from someone. The scam usually tries to either get the victim to visit a malicious website or directly provide their information, via a reply to the attacker or in an online form.
Years ago, phishing emails were easy to spot. They typically used obvious From: addresses, poor grammar and spelling, clearly misleading url's, and overall poor imitation of a legitimate organization's communication.
But, as is often the case, the phishers have gotten better. The emails look legit, the grammar and use of language is good, and the links often go to realistic-looking, but malicious, sites. And email isn't the only delivery method.
So, how do we avoid, and help others avoid, these attacks?
Tuesday, May 14, 2013
One Size Does Not Fit All
The annual Secure360 conference kicked off yesterday in St. Paul with pre-conference sessions. Secure360 is the major upper Midwest security conference and has become a US national event, now in its 11th year (I think!).
I'll be pretty busy at this year's conference. I've actually spoken at every Secure360, but this year I did a half-day seminar yesterday on BYOD, and tomorrow I've got back-to-back talks - one on the Insider Threat I call "The Accidental Insider" (blog post), and one on authentication "3 Factors of Fail" (blog series starts here). Slides for all are on my slideshare site.
I've got a wide variety of topics to cover!
And that's what is so cool, and critical, about conferences.
Tuesday, April 9, 2013
Keeping Security Simple
This week I did a national webcast with Capella University. The
topic was the Insider Threat. But my take on this is a bit different
than what's usually said on this subject. I call it "The Accidental Insider". You can see my slides here.
I was talking about how I think that accidents are the major cause of breaches. I've talked a bit about how important it is to keep things simple here.
If you're an information security professional, hopefully you are familiar with the Verizon Data Breach Investigations Report (DBIR). You can see their page for the latest report.
One of the interesting things they point out in the report is summarized in this table:
I was talking about how I think that accidents are the major cause of breaches. I've talked a bit about how important it is to keep things simple here.
If you're an information security professional, hopefully you are familiar with the Verizon Data Breach Investigations Report (DBIR). You can see their page for the latest report.
One of the interesting things they point out in the report is summarized in this table:
Labels:
accident,
anti-malware,
attack,
basics,
breach,
DBIR,
effectiveness,
good_practices,
hack,
infosec,
insider,
KISS,
management,
passwords,
patching,
policy,
simple
Tuesday, March 12, 2013
lnk.shrtnrs (Link Shorteners) and Safety
Recently I was speaking with a group about online safety. Keeping to the basics, we discussed two main sources of problems: passwords and clicking on links. I've discussed passwords a number of times here, here, here and here.
One great way to avoid problems online is simply to not click on links! Of course, that would probably render the web all but useless to you (well... I guess you could just type in url's but that would get old very quickly). You probably followed a link to get to this post. Actually, you probably followed a shortened link to get to this post.
Tuesday, January 15, 2013
Something You Forgot - 3 Factors of Fail (part 2)
Last week we started talking about authentication and listing the 3 factors of authentication. This 2nd in the 5-part series will look at the 1st factor.
The 1st factor of authentication is "something you know". We usually think of this as passwords, but there can be other forms like: PINs; lock combinations; "secret" phrases (the phrase that pays!); picture identification; and secret pattern (like on your smartphone).
There are a few fundamental problems here. And they are mostly caused by something we can't change... we're trying to authenticate a human! (usually) So, rather than something we know, these authentication methods rapidly deteriorate into something you forgot. Here's why...
The 1st factor of authentication is "something you know". We usually think of this as passwords, but there can be other forms like: PINs; lock combinations; "secret" phrases (the phrase that pays!); picture identification; and secret pattern (like on your smartphone).
There are a few fundamental problems here. And they are mostly caused by something we can't change... we're trying to authenticate a human! (usually) So, rather than something we know, these authentication methods rapidly deteriorate into something you forgot. Here's why...
Tuesday, December 4, 2012
Keeping Up and Podcasts
Recently I was talking with a colleague about keeping up with information. We actually were comparing smartphones. During the conversation we talked about podcasts and podcatching software. I'll talk about what I use below.
We are talking about what podcasts we listen to. One thing that was surprised me was that he mentioned that many technical people he interacts with don't listen to podcasts! I found that surprising. I figured most technical and security people know all about podcasts. Podcasts are hardly new.
There are podcasts for all kinds of subjects. I listen to podcasts about security, technology, sports, news, science, leadership, getting things done/productivity and other subjects.
I think that listening to podcasts is one of the best ways to both learn and keep up.
Labels:
articles,
audio,
awareness,
basics,
devices,
information,
IT,
learning,
mobile,
online,
podcast,
productivity,
security,
social,
technology
Subscribe to:
Posts (Atom)
