A place to talk about information security, Internet safety and, of course... coffee! Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
It's US Cyber Security Month and, like clockwork, we have Yahoo! in the news again telling us that the worst case from the past just keeps getting worster (I can make up words, can't I??? :-). They are now counting their breached accounts at over 3 billion! How many people are there in the world these days?... Last year at this time, they announced the breach of 500 million Yahoo! account passwords and other info (while announced in 2016, the breach actually took place in 2014, and is not the same as the password breach they had in 2012! - yes, I know... it's hard to keep up!). In honor of both Cyber Security Month and Yahoo!, I'm re-running a post I wrote in... wait for it... 2012! Not only is everything I wrote in that post 100% relevant today, but I even commented on that 2012 Yahoo! breach. The more things change, the more they stay the same. Happy Cyber Security Month! They're dead. They're here to stay.
They're safe. They're breached.
They're encrypted. They're visible.
They're complex. They're too simple.
Once again, the topic we love to hate... Passwords! And, you know what else??? It's also that greatest of holiday celebrations... US Cyber Security Month!
Passwords are a mess! A "good" password has these features:
hard to create
hard to remember
hard to enter
probably has to be changed as soon as you memorize it
plus other inconsistent, random rules depending upon the site
According to Cyberbullying Research Center, the National Crime Victimization Survey (NCVS) is a large-scale data collection effort led by the U.S. Census Bureau and the Bureau of Justice Statistics. This study has been going on since 1973. In 1989 they added supplemental questions focused on school-related incidents, and stepped this up to a more in-depth biennial survey in 2005.
Cyberbullying is still a major issue. It's been over 4 years since I've written on thissubject. While there is perhaps more visibility, the basic problems haven't changed.
Based on the above benchmark, at first glance, bullying appears to be trending down over the past decade.
While there have been some high-profile cases over the years, this is a real, current and ongoing issue.
ESCROW - Extreme Security Cool Resources Of the Week. OK, well sometimes you start with the acronym and see how you can make it work! And I've got a good one for you.
It's a bit geeky, but if you're interested in learning more about the more in-depth technical aspects of security you will enjoy this resource. And I've got another, less geeky, resource.
Everyone knows about Youtube. You can find just about anything there, but there's so much content that sometimes it's hard to find what you're looking for.
Some of the resources have difficulty ratings to help you choose the right course of video. For example, this one on Wireless LAN (WLAN) security is rated "easy" (and that's certainly in the eye of the beholder!).
For those who don't want anything that in depth, here's another tip. You can go to Youtube and search for "cybersecurity for beginners". There are many basic information security videos there including this one from NOVA PBS:
Check some of these out and let me know what you think!
I guess I can't get around having to comment on Pokemon Go.
If you have children, or if you were, born in the 90's through the 00's then you know all about Pokemon. It used to be about the cards, action figures and, of course, the video games. Remember the Game Boys, game cartridges and all the sounds and music?!
With Pokemon Go, the game has gone from sometimes mobile to really mobile. And from sometimes social to a social phenomenon.
It's not farfetch'd!
For some reason, many adults seem to dislike this game, siting issues like inattention to surroundings, time spent playing, etc. I think the game is great! Here are my top reasons why (major caveat... I have not actually played the game! These are my observations as a technology and security professional and as a parent):
It gets kids out of the house - many people need a little Vitamin D. One of the biggest complaints about gaming and computers for kids is that they don't get outside enough.
It gets kids moving - #exercise. While there have been some attempts at game-ifying exercise, such as Wii Fit, it never really caught on. Pokemon Go gets people outdoors and moving around. In fact, part of the game is logging lots of steps.
It's for "kids" of all ages - parents can play along with their kids! You don't have to play, but at the very least it's a great opportunity to be involved.
It's really social - you may remember that, back in the day, players could connect two Gameboys so two people could battle. Now people are connecting IRL (In Real Life) as they hike trails, walk through cities or congregate at parks or other PokeStops.
It's another step toward acceptance of AugmentedReality. Unlike VirtualReality, in which one is entirely immersed in a manufactured visual scene, Augmented Reality overlays images, text or other information on top of what you are actually looking at.
Encryption has been in the news again - whether it's ransomware, law enforcement and iPhones, bitcoin, quantumcomputing, or potential newlaws. Before we can "decrypt" all these issues, we need to talk a bit about what encryption is and isn't.
There's an old saying in Security... "if you think encryption is the answer, you might not have understood the question". I never liked the tone of that statement because it sounds kind of elitist, but it is basically true. And that's because encryption is very confusing.
Encrypting data is great because it means it can't read by unauthorized people. And that is the trick... how to let the right people in and keep the wrong people out. If my encrypted data is unreadable by anyone then that's called Ransomware!
Encrypting my data so only I can read it is pretty easy. It means that only I need the "key". Of course, I better not loose that key! Encrypting my data so I can share it with you is also pretty easy. We just need a "shared secret". If I need to share my data with a bunch of people then we get into something called "public key cryptography". Here's a good explanation of that.
Encryption is basically a solved problem. Because math. #math. There are many great algorithms with cool names like Elliptic Curve, RSA and Two-Fish.
Of course, when we talk about breaches, we're usually talking about someone "stealing" data. It's not actually "stolen" because you still have it. It's more accurate to say that in a breach the data is exfiltrated. This is also called an attack on the confidentiality of the data.
In security, we talk about the C-I-A triangle, Confidentiality, Integrity and Availability. Confidentiality is about the secrecy of data. Integrity is about the accuracy of data. Availability is about being able to properly access data when it's needed. A well-rounded security program needs to consider all these aspects.
What is somewhat different this year is the crypto-/ransom-ware attacks. In these cases, the attack is a virus that typically gets in as an email attachment. Someone opens the attachment and the virus executes. It finds files in network shared directories and encrypts them. Now, encryption is often a good thing, but that's when you (or your organization) has the decryption key. In a crypto-ware attack, only the attacker has the key. That's a problem. It becomes ransom-ware when the attacker offers to provide the key for a "small" consulting fee, usually paid via the anonymous crypto-currency, bitcoin.
These are basically attacks to the availability of data. We've seen instances of hospitals or other organizations temporarily shutting down as a result. These could also be considered attacks to the integrity of the data - though I think we have not yet seen the real integrity attacks... and they are coming.
A number of people alerted me that a recent episode of CSI:Cyber, which aired on 11/1/15, had as its theme a cyber attack on a hospital. The episode was entitled "hack E.R." (see what they did there??? :-) )
The episode begins with an ominous image showing up on computer screens and all systems in a fictional hospital being under the control of an online attacker. They threaten to kill a victim every four hours if not paid a ransom. They then kill a victim by causing an infusion pump to deliver a fatal dose of morphine while preventing the patient's heart monitor from alarming.
We then follow the CSI:Cyber team and the hospital staff as they try to solve the mystery and track down and stop the attacker. I won't give a full synopsis nor a review. You can find some of that here and here (spoiler alert - these linked articles do give away the ending).
Let's review what was potentially real and some of the deficiencies of the episode. First the realistic.
I've been posting comments in line with the weekly themes put together by DHS. This week the theme is Building the Next Generation of Cyber Professionals.
Whenever information security managers get together, one of the topics is often the talentcrunch. In almost any metro area in the US there is close to zero unemployment in security. Add to that the coming brain drain as the baby boomers retire, and we have a looming problem.
On the positive side, we're seeing more university and community college infosec programs.
But there is more work than people. The federal government estimates that they need 10,000 new infosec professionals in the coming years. How is that going to work?
We continue our celebration of US Cyber Security Awareness month! This partnership between Homeland Security, NCSA (National Cyber Security Alliance) and the MS-ISAC (Multi-State Information Sharing and Analysis Center) is an opportunity to recognize the importance of information security. It started in 2003 as a way to build awareness for online security and privacy and to encourage individuals, business and government.
This is another of my weekly posts connected with the weekly themes put together by DHS. This week the theme is Your Evolving Digital Life.
You practically need to be online to survive and thrive in today's world. Whether we're talking about digital natives or newbies, we all need to handle some aspects of our lives online. And all ages are involved! Senior Citizens are the fastestgrowing online demographic group. Not to be outdone, over 33% of babies born in the US already have some kind of online presence! And people aren't the only online residents... our refrigerators, cars, scales, lightbulbs, powergrids and medical devices have joined us.
We continue our celebration of US Cyber Security Awareness month! This partnership between Homeland Security, NCSA (National Cyber Security Alliance) and the MS-ISAC (Multi-State Information Sharing and Analysis Center) is an opportunity to recognize the importance of information security. It started in 2003 as a way to build awareness for online security and privacy and to encourage individuals, business and government.
This is another of my weekly posts connected with the weekly themes put together by DHS. This week the theme is staying protected while always connected. That rhymes!
We are always connected! According to the Pew Research Center, in 2015 90% of american adults own a cell phone, 64% own a smart phone. And one of the major uses for smart phones is... not calls but social media! How do we stay safe online and on the move?
It's time again to celebrate that wonderful US event... Happy Cyber Security Awareness month! This partnership between Homeland Security, NCSA (National Cyber Security Alliance) and the MS-ISAC (Multi-State Information Sharing and Analysis Center) is an opportunity to recognize the importance of information security. It started in 2003 as a way to build awareness for online security and privacy and to encourage individuals, business and government.
This month I'll be putting out weekly posts connected with the weekly themes put together by DHS. This week the theme is creating a culture of security.
The message is simple... in the workplace security is a team sport. All organizations have customers, patients, systems and data to protect. To accomplish this, security must be part of everyone's job.
I've written about passwords plenty of times in thepast. Passwords are one of the main security touch-points for people, and it's often not a pleasant experience.
As we've discussed, it's hard for people to pick good passwords and remember them. So users need "tricks" to help the memory. One way I've told people to construct a password is to base the password on an embarrassing moment in your life - that way you won't forget the password and you also won't tell it to anyone else.
Apparently people have been using that, and similar, methods. NY Times reporter Ian Urbana wrote a great piece on this called "The Secret Life of Passwords". He asked people to tell him their passwords - yes, you shouldn't do that - but also the story behind the passwords. There are some very interesting stories. People seem to memorialize a part of their life in their passwords! You can read the full story here. Leo Laporte did a great interview with Ian in the Triangulation podcast. You can hear that here.
I'd like to focus to two aspects of this story that jumped out at me.
First is the story of Cantor Fitzgerald. They are a large financial firm who were headquartered at the World Trade Center in 2001. When the terrorist attacks hit the towers, Cantor Fitzgerald over two-thirds of their employees were killed. That was tragic.
I'm calling this part 2, but it's really the third in a series covering the consumer and enterprise sides of incidents and breaches. This is always an important infosec topic, but the recent highly publicized issues effecting Target, Neiman Marcus and, as we're told, 3 other organizations to be named later brings this to the forefront.
Many say that it's not a question of if we will suffer a breach, but when and how we will suffer a breach. And yet there are organizations that consider this an optional capability.
Last time we talked about the first two parts of the Incident Management program: Prevention and Planning/Preparation.
Next is: Communication. So these groups know their roles:
It seems that every few days we get additional news about the Target breach. There has been plenty posted about this including articles here, here and here. And, unfortunately for my colleagues at Target, I don't think we heard the last on this.
Last time I talked about the consumer side of the issue, and how individuals should protect themselves from the effects of an information breach. Today we'll look at the corporate side... Incident Management.
Incident Management is a critical part of any information security program. I don't think there's any governance framework that doesn't include this important topic. I'm a fan of the way NIST lays this out in SP800-61, with a few modifications.
In boxing and martial arts, the saying goes: the best way to avoid getting hit is to not be there.
By now, most of you have probably heard about the Target credit card information breach. This is very big here in Minneapolis, home of Target. All the details aren't out yet but it appears that credit card information for brick-and-mortar stores between Friday Nov. 27 ("Black Friday") and Sunday Dec. 15. Herearesomearticles covering the story. Here's Target's response and an FAQ.
I'd like to talk a bit about next steps. If you've been the victim of a data breach... what next?
First... for consumers. Target is a retail company and the direct victims of the breach are those of us who shopped at a Target store during the dates in question. Consumers have two concerns here: credit card fraud and identity fraud. (I don't like the term "identity theft" even though it is commonly used. No one can steal your identity... you still have it. They can improperly discover, and misuse, the details... a.k.a. fraud.)
As seems to often be the case in the fall, I'm doing a number of Internet Safety talks lately. Maybe it's the tie-in with October US Cybersecurity month, and I did somepostscelebratingthat. Maybe it's that fall makes us think about back to school (though maybe safety should be a "hotter" topic in the summer when kids have more free time!).
I've been presenting to groups about Internet Safety and related topics for over 12 years. I've got a few events coming up at work, so I'm updating my material. I've got a number of talks on these "consumer" issues. You can see my slides on my slideshare page. I regularly update my material. But what's really amazing to me is that the core, key messages have substantially remained the same.
For example, I recently did a presentation and blog post on bullying. The biggest change in online bullying in the past few years has been the news media attention. But what happens, how it happens and options for victims, unfortunately, hasn't changed much.
As I talk with people about these issues, and research and update my presentation material, I think there are 3 main areas in which things have substantially changed.
The rise and expansion of social media. In the early 2000's, we were talking about things like email, Chat like AOL Instant Messenger (AIM) and web surfing. Xanga.com was around, but MySpace and Facebook weren't even invented until around 2003! And, needless to say, there's been an explosion of social media sites with the latest trends favoring pictures and video. While kids had the ability to share too much information since the beginning, social media sites really drove the norms.
Technology. In particular... mobile technology. I used to recommend that families keep their computer (singular) in a common place like the family room or kitchen so kids' use could be seen. While that is still good advice, most families have more than one computer. And most teens, and many younger kids, carry a powerful computer with them wherever they go... their smartphone. While we still have options available for monitoring, and good communication is key, portable devices are really a game-changer.
Kids get it. During my Internet Safety talks of the mid-2000's, we used to play a little game. It was a live demo in which I would bring up a social media site, typically MySpace. The game was to see how few clicks it would take us to get to some inappropriate content (like kids/teens sharing too much personal information or posting pictures parents would wish they didn't). When I first started doing this demo it would only take a few clicks. Then, by around 2008, it took more. Then I would just save a few URLs of TMI pages. Then I gave up the game altogether! It's not that we can't still find inappropriate content, or examples of kids sharing far more than parents might want. But kids are doing a much better job of protecting their information online. Of course, kids, teens and young adults - actually digital natives in general - do have different ideas, definition and expectations of privacy compared to their parents!
One final thought... another thing that has changed is that the oldest digital natives - people who do not know of a time without pervasive digital media and technology - are now having their own kids and showing up at Internet Safety talks! But some things don't change and their kids still know more about technology!
What surprises you about changes in our online world over the past decade? What do you think has changed, or has not changed?
In addition to Cyber Security Awareness Month, October was also Cyberbullying Awareness Month. There were a number of online campaigns to raise awareness on the topic including some high-profile pages on Facebook and Cartoon Network.
This is an important topic and needs our attention. I have given many presentations over the years on Internet Safety topics. This past weekend my wife, a clinical psychologist, and I partnered on a presentation on Bullying and Cyberbullying at our local school district parent fair. Here are the slides.
Unfortunately, bullying has been around as long as there have been people. The internet, social networks and mobile devices supplement have turned "old school" bullying into a 24x7 assault.
This week I'm presenting at the Cyber Security Summit in Minneapolis. I hope to see you there!
It's Cyber Security Month! And the more things change, the more they
stay the same. The key advice for online self-defense I've given in
the past is just as true now. So to help us all celebrate, I'm
"re-featuring" a few articles I've run in the past.
This is the third post in my series on Online Self-Defense. We've covered malware and passwords,
two key issues effecting your online privacy and security. If you've
tried the simple tips I gave on those two subjects then you are now
safer than most web surfers.
Now, to keep you and your computer safe... don't click on that link!
It's Cyber Security Month! And the more things change, the more they stay the same. The key advice for online self-defense I've given in the past is just as true now. So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.
Last week I ran a couple of sessions at work on awareness and
security. Over the next few posts I will be reviewing some of the 3
themes I covered in a talk entitled "Online Self-Defense". You can view
the slides on my slideshare page. (actually, the talk focuses on just 2 of the themes but that's OK!). Since everything comes in threes (omne trium perfectum), I will give 3 easy tips for each theme (and some bonus tips as well).
The first theme is protecting your computer or device.