Tuesday, March 26, 2013

Attack Surface

   Last week I did a national webcast with Capella University.  The topic was the Insider Threat.  But my take on this is a bit different than what's usually said on this subject.  I talked a bit about this topic in my post last week.  You can see my slides here.

   As happens in some (perhaps not enough) InfoSec talks, during the presentation we touched on the topic of Risk Management.  In particular, we were talking about how to help keep honest people honest and good people to do the right thing.

   There are all kinds of "formulas" used to calculate, or more correctly - estimate, risk.


Tuesday, March 19, 2013

The Accidental Insider

   This week I did a national webcast with Capella University.  The topic was the Insider Threat.  But my take on this is a bit different than what's usually said on this subject.  You can see my slides here.

   The typical story about insider threat is about theft or fraud.  Here are some recent articles.  This is a real and present danger.

   But there is another category of internal issues... accidents.

Tuesday, March 12, 2013

lnk.shrtnrs (Link Shorteners) and Safety

   Recently I was speaking with a group about online safety.  Keeping to the basics, we discussed two main sources of problems: passwords and clicking on links.  I've discussed passwords a number of times here, here, here and here.

   One great way to avoid problems online is simply to not click on links!  Of course, that would probably render the web all but useless to you (well... I guess you could just type in url's but that would get old very quickly).  You probably followed a link to get to this post.  Actually, you probably followed a shortened link to get to this post.


Tuesday, March 5, 2013

Pro-Hero instead of Anti-Bully

   As I mentioned in my post last week, I recently did an Internet Safety and Tech talk for parents of preschoolers.  When I talk about this and related topics, I always talk about bullying and cyberbullying.

   Unfortunately, the concept of bullying has been around through the history of humans.  Interestingly, the term and specific study did not begin until the 1800s.  Of course, bullying is not just something that happens to children in schools.  My friend Denise Moreland discusses workplace bullying and bad management in her book (buy it here) and blog.

   There have been traditional ways parents and schools have tried to deal with bullying.  I'll discuss those below.  I say "tried" because these methods haven't really worked.  There's also been an anti-bullying movement over the past 10-20 years.  Even with all the media attention this gets, that method doesn't work either.

   I've recently learned of a new approach that I think can work!  It's called Pro-Hero.  Check out this great TEDtalk covering the basics.

Tuesday, February 26, 2013

Tech-Smart Parents and Preschoolers

   This past weekend I had the opportunity to do something fun and different!

   I've been lecturing on Internet Safety and Awareness to all kinds of groups for about 15 years.  I've met with parents and professionals at conferences, businesses, churches, school district parent fairs and have even provided training to law enforcement personnel.  I enjoy doing this and always learn something new.

   After presenting at a school district parent fair last fall, I was invited to present at a local Young Children and Technology conference, specifically covering technology for the preschool and younger set!  Since most of my material is targeted for parents of preteens, teens and older, I knew I had some work to do!

   As I dove into the research, I found that there are similar categories of issues, but clearly preschoolers and toddlers use technology different than teens.

Tuesday, February 19, 2013

So What's the Authentication Answer? - 3 Factors of Fail (part 7 - last!)

   We've been discussing the authentication problem for the better part of two months, and now it's time to wrap things up.  If you've gotten to this post through a link but haven't read the rest of the series, it starts with part 1 here.

   Each of the 3 factors of authentication have serious issues when used individually.  The challenge is that we need to log a person into a system or application in a way that reasonably assures the person is who they say they are and has rights to the system.  And, perhaps most importantly, any method we use has to work well for people!

   So, how do we find a solution?

   The key is to think about the user and the use.

Tuesday, February 12, 2013

Multi-Factor Fail - 3 Factors of Fail (part 6)


from: brainyquote.com
   In December I was at the NG Security Conference in Austin, TX.  We had a fantastic discussion with a group of key security leaders focusing on this "quote" and how it applies to information security.  I say "quote" because there is some question as to who said this or if anyone actually did!

   As I've been saying throughout this series of posts, it seems that this statement is exactly what we are doing in the world of authentication!  None of the typical factors of authentication have really solved our authentication and access problems, yet we continue to use the same mechanisms over again.