Security's Everyman

Security's Everyman

Wednesday, November 08, 2006

Vendor Selection

As I've mentioned before there are a lot of changes taking place where I work. Many of those changes involve us doing things for ourselves that have been done for us in the past. So I've spent a lot of time meeting with vendors lately. As we have gone through the process of meeting with various vendors to either provide a product or service I've been pretty impressed with most of those we have meet with. The FUD has been kept to a minimum (contrary to my post a few months ago) and the meetings have been productive for the most part.

We have to get 3 bids for most of these projects so at times we talk to several vendors and then narrow our list to the top 3 or 4 to actually invite to submit a bid. We did just this with one service that we needed and a couple of weeks ago I sent an RFP to the 3 selected vendors. Then early last week I received a bid from one of the vendors that had NOT been selected. At first I didn't think much about it because that stuff happens. But then it hit me that the bid included my internal RFP document that I had created and maintained control over. No one else in my company even had a copy of it. I quickly checked my sent items box to make sure that I had not sent it to the wrong vendor and I hadn't. Then I checked my Exchange logs and other audit logs to see if someone else in my company got a hold of it and sent it out. No evidence of it anywhere. Next I called the vendor to see where they got the document. The guy I had been dealing with there was out of the country until the end of this week and no one else knew anything.

That leaves only 2 options that I can see (if anyone else sees any others please let me know). Either the email was intercepted after it left my exchange box or one of the 3 chosen vendors shared it with this other company. The first I can live with (like it or not). The second does not sit will with me. Well I sent the vendors a letter outlining the situation and asking for them to do an internal investigation. Two of them have called back very concerned and with unequivocal denials that it happened by anyone within their company. No response from the third. Are they still investigating or is their silence convicting them?

I doubt that it came from anyone of the actual sales people or their trusted group that helps them put together a proposal, but maybe someone a little farther down the food chain who stands to make a few bucks from a "friend" if the other company actually gets the contract. Who knows. I do know that the 4th company is still not in the running. Their price was much lower, but I think that I would be getting what I paid for and that is not what I need.

If anyone has any thoughts on this or if something similar has happened to you please write me and let me know. This is a first for me and I'd love to know how others handled it.

Tuesday, November 07, 2006

Voting on Diebold Machines

I voted today on a Diebold DRE Voting machine. I've voted on the same one in the past, but this time I paid close attention to the whole process. It was quick and painless. After I had completed the ballot I reviewed my selections to ensure that what it said it was going to register was what I really wanted. After feeling confident that I was going to cast the ballot that I desired to I pressed the the "Cast Ballot" button and away it went. Of course I have no idea what happened to it after that. It may have been intercepted by a malicious politician or someone from the Taliban who wants to ensure that democracy is thwarted. More than likely it was cast just as I voted, but ......

Sorry for the cynical comments, I know that this is a very serious subject that has to be addressed VERY soon. I have even gone on record with a few unflattering comments on the whole issue, especially in regard to the Diebold machines. Those who have taken this up as their call to arms need to continue to get the news out and the rest of us need to do the same. Those in a position to affect this directly either through policy or what ever need to do all in their power to ensure that things get done right. We need to pressure the politicians to enact regulations that have teeth and pressure the manufactures of the machines to do all the right things in regards to security and auditing.

I have faith that this will eventually have a happy ending. Even Hansel and Gretel had to go through some tough times prior to their happy ending.

Go Vote

Today is election day and ALL of us need to go vote. It doesn't matter who you vote for as long as you vote. Too many people fought too hard and gave up too much for us to sit around and ignore our rights and responsibilities. Elections, at any level, are important and deserve our full attention and participation.

As Americans we love our rights and freedoms. Don't let them disappear because you chose not to participate.

Remember, with freedom comes responsibility.

Friday, November 03, 2006

Careful who you trust

Just a personal story of how even those of us who are Security Pros can let our guard down and do the very thing that we keep telling others not to do. I want to stress that I am not suggesting that this was a malicious act. It was just a "freak" coincidence that teaches a good lesson.

Yesterday I sent Martin McKeay about a personal email asking him a question about PCI compliance. I know that in addition to being "Captain Privacy" as Shimel calls him he is very knowledgeablePCI. A little while later he replied to my email and included a link to a website that he recommended I check out (you know where this is going now don't you).

I hate to admit it but I did click on the link with out any hesitation or checking to make sure it was legitimate. After all Martin is a trusted Security Pro and I have had some contact with him over the last few months regarding the CISSP test and such. I've given him my thoughts and kudos on his podcast a few times. I had no reason not to trust him. Yet I really don't know him so I should have been more careful. Haven't we all heard similar excuses by our users?

What was really scary about this incident though is that the site that he sent me to has a pdf on it that I needed to download and read. As soon as I clicked on the pdf link FireFox crashed. :( My heart sank and I felt like such a loser. I immediately isolated my laptop from the rest of the network and spend quiet a while checking to make sure that I had not been compromised. After I was convinced that all was OK I went back to the site and downloaded the pdf and quickly became despondent because it told me just how much extra work was going to be required for me on the compliance side.

But all is well. Martin is not a hacker in hiding. :) His help was GREATLY appreciated. I just wish that I had been a little more careful. Crow doesn't taste too good. At least most of my users don't read my blog.

Wednesday, November 01, 2006

Imagine That

Someone using file sharing app to steal personal data. I just can't believe that would happen. :)
http://test.denverpost.com/nuggets/ci_4564807

Tuesday, October 31, 2006

A Few Quick Thoughts

Just a few posts and articles that I saved over the last few days.

GOOD READS

F-Secure post on selling domain names. Pretty clever on the part of the bad guys. We need to get the word out to others to pay careful attention to what is actually in the address bar. We may not get everyone to check certificates but this is a quick and easy check.

Another good F-Secure Post related to the one above. Having more TLD's that are specific to industry would help cut down on successful phishsing.

Here is a good article that Michael Farnum wrote for ComputerWorld about the debate between much of the blogsphere (too many to list) on Zero Day vs. Less than Zero Day exploits. I've got thoughts on the whole thing, but I'm tired of reading about it and don't want to add to the fray. That goodness it is slowing down.

Bruce Schneier points us to a good write up on a better voting machine. They still have a long way to go, but I think that the right technology implemented in the right way will make voting secure and reliable. It's far from there now. If it were up to me I would pull ALL electronic voting machines for this election and go back to punch cards.

Here is 2 cents of my input on the Risk Management debate going on. I'm linking to The Mogulls post but I would recommend reading the others that he links to. Hopefully I'll get a chance to put the other 98 cents in later. I like this topic. Risk Management can't be something that is accomplished by any one group be it management or IT staff. It does take a concerted effort by many different departments in order to do it effectively. You can't expect Management to understand how to implement the technology or even to know what technology to implement. Nor can you expect IT to understand how to come to an understanding of the what and why of Risk Management. I know that many in IT do understand, but they are a small percentage of IT as a whole.

That's all for now. I'll be with vendors all day tomorrow so you may not hear from me for a couple of days.

Rethinking Security

Things at work are getting very hectic. Some major changes have caused us to stop and shift direction in many areas and rethink where we are going, how we are getting there and what we will do once we are there.  To make things worse management has moved a deadline up by about 5 weeks while increasing the amount of work required to reach the deadline. This isn't a "soft" deadline either. It's meet it or hit the road. If for some reason this deadline isn't met we would not be able to conduct business until ALL of the items on the list are complete.

In the process of this we are having to rethink how we do security. How it impacts us in day to day business, how threats and vulnerabilities will be dealt with and how we will respond if a breach occurs. In some ways things will be easier in the long run simply because we will not be as heavily regulated as we would be before the changes were announced. The down side of that is that the lack of regulation has already put some members of management into the mindset that security won't be as important as it should be.

My overall goal in all of this is to meet the deadline obviously, but also to impact how security is viewed by the organization as a whole. The right people have to be "shown the light" in regards to seeing that security will have a big impact on how we do business whether or not we are required to monitor, log, or report specific items.

Most people view security still as being simplistic things such as keeping AV up to date and installing a firewall. They don't see the importance of multiple layers of security and how event A can point you to event B which shows a weakness or a breach. Not only that users still don't see how seemingly simple things such as running Skype on their systems can be a problem or how putting their PDA on the wireless is dangerous. They want to be able to go where they want to go on the Internet, hook up to any wireless that will let them, install any program that they deem necessary or fun and still have unfettered access to company resources.

Security has to be rethought from not only those of us who implement it but from those who recommend it and the end user. The digital world is a dangerous place and we have all got to be prepared for it. Part of that means that as Security Professionals we have to come out from behind our firewalls and work with management and end users to make them understand the whys and wherefores of what we do. We can't continue to hide behind our server room doors and make fun of "stupid users". Part of the reason they are stupid is because we have not done our part to educate them.

The changes that are coming at work will have major impact on me and all of my users. Now I have a decision to make, will I lock them down and tell them to "shut up and  go color" or will I work to make sure that they are on my team in keeping everything secure?

Friday, October 27, 2006

Hiding in public places

I have a friend who is in hiding, sort of. He is hiding from a bad relationship and has left the state. He left because his new spouse lives and works in another state, but he was glad to leave the state. He was really worried about the ex. Of course I know where he is because we keep in touch. From time to time I do various web based searches to see if I can find him and up till recently I was unable to locate him on the web. Pretty good considering how easy it is to find most anything on anybody.

Well the other day I was on MySpace (I know, but I have a brother in law in the military and he won't communicate any other way) and I decided to look up a couple of friends. As I was looking at some of their friends who do I see but my hiding friend. Right there in plain view for all the world to see. His name and location were all faked, but you can't hide your face on a picture. Again I had to go back to my "I just don't understand". All that work to hide and he was hiding in public. Needless to say I got in touch with him and informed him that he had been found and that he probably should put up a different picture.

Drug Dealer Found w/ Nuclear Weapon Data

This article from Techworld.com points out the ever continuing struggle security professionals face in securing data. We all know that it's impossible to secure everything to the point that we would like it. That is why we do Risk Analysis and then determine what we will protect and how we will protect it. It would be comforting to know that data that is classified as "Secret Restricted Data" is secured to the point that it can't be stolen, but it doesn't seem that is possible either.

Thursday, October 26, 2006

Rich Unknown Relatives

I can't tell you how many times I've received emails telling me about the death of a long lost relative or someone who could have been. It' amazing how many Willinghams that live over seas were rich and died with no known family. I'm just so lucky that the executor or their estate found me so I can become rich. Well me and the executor. Why is it that he or she gets more money than I do?

I bring this up because the other day I received a new phishing email. It's similar to the ones mentioned above. I'm sure all of us have gotten them. I'm just amazed that people actually fall for them, but this new one I got is pretty slick. I'm including the body just because it's so good.

Dear Friend,

I'm happy to inform you about my success in getting those funds transferred under the cooperation of a new partner from paraguay . Presently I'm in paraguay for investment projects with my own share of the total sum. Meanwhile, I didn't forget your past efforts and attempts to assist me in transferring those funds despite that it failed us some how.
Now contact my secretary in nigeria, her name is VIVIAN OBASI on vivian_obasi1_1@myway.com ask her to send you the total of $450.000.00 which I kept for your compensation for all the past efforts and attempts to assist me in this matter in the past. I appreciated your efforts at that time very much.So feel free and get in touch with my secretary VIVIAN OBASI and instruct her where to send the amount to you.
Please do let me know immediately you receive it so that we can share the joy after all the sufferness at that time. In the moment, I’m very busy here because of the investment projects which me and the new partner are having at hand.Finally, remember that I had forwarded instruction to the secretary on your behalf to receive that money, so feel free to get in touch with VIVIAN OBASI she will send the amount to you without any delay.
Regards,
sanetor John E Williams Esq

How many people that have received the rich, familyless, dead guy email and didn't fall for it will fall for this? Even if you don't believe the first one this one is almost too easy not to follow through on. Pretty slick.

Wednesday, October 25, 2006

Security-Go-Round

This article on DarkReading.com brings up some interesting fodder for thought. Security professionals realize that technology just isn't doing the job when it comes to protecting our resources so we should focus more on user training. But wait, we learned long ago that user training was a waste of time in many cases. So we spent more money on technology that isn't doing the job. Now we hire more security professionals to help but there aren't enough good security pros out there. Now we are left with entrusting our junior guys with the task of securing our networks. But they don't have the skills so we have to get them trained and certified. And it keeps going round and round.

There is good news in all of this.

  1. We improve the security awareness of the end users (I can dream can't I).
  2. We improve the technology.
  3. We improve the security of the company through implementing 1 and 2.
  4. We improve the skills of those who are in the field.
  5. We improve ourselves by getting better positions in the field.
  6. We improve each other by sharing what we have learned via blogging, podcast, etc..
This is all part of the cycle of how this world works. We can make the best out of it and improve or we can let it run us over and lose ground. I know that I only looked at the "bright" side of this but I'm in a good mood this morning and didn't want to start off with a negative post. This cycle reminds me of one of my favorite songs by Dan Fogelberg that has a similar theme. In it he says:
The higher you climb, the more that you see
The more that you see, the less that you know
The less that you know, the more that you yearn
The more that you yearn, the higher you climb.

Tuesday, October 24, 2006

Reactionary Security

Isn't it just like the government to rush out a multimillion dollar "security" project because it is reacting to something. This article from ComputerWorld outlines how the TSA is basically rushing out a ID card that has not been fully tested and the main reason is because they are under pressure to get something out. Apparently rolling out the appropriate solution isn't necessary. Just get something out so it looks like we are on top of things.

This quote seems to sum up the attitude of those pushing to get this implemented. "Moving quickly to implement the TWIC program 'without developing and testing solutions to identified problems to ensure that they work effectively could lead to further problems, increased costs and program delays without achieving the program's intended goals,' the GAO said."

Apparently ensuring that taxpayer money is spent in the best manner isn't high on the list here. I wouldn't mind extra money being spent if it was going to do some good, but to blatently push a so called security objective before it's time is stupid.

Maybe this is the same group that screwed up configuring all thoser DNS servers we heard about a few weeks back.

Novell Virus

Now there are 2 words you don't often see together. As I've said before I started out in the IT world using OS/2 and Novell and this is the first time I can remember seeing a virus that targeted Novell. I know that there have been some, but I don't remember them. I received my copy of the SANS @Risk Security vulnerability report last night and this was the top story. In my mind this says something about what the bad guys are wanting to do. Just like with Apple, it's not that Novell is so much safer than Microsoft it's that it wasn't being targeted. Smaller user base less potential for impact. Now that the motive is profit rather than impact everything is fair game.

I also am guilty of ignoring things that don't directly impact me at times. This is true when I review this newsletter each week. If it applies to me I check it out. If not I let it pass. Probably not the wisest thing to do. Why? Because that leads to apathy and laziness. I need to keep up with security as a whole not just my little corner of it. If I plan on advancing my career past where it's currently at I need to focus on my goals and areas of responsibility while at the same time keeping an eye out on everything else that is going on. If not I'll get left behind.

A Strong Foundation

A friend called me the other day with a concern and complaint. Here is the jest of what he said.

Everyday I work hard to ensure that my company network is as secure as possible. Currently we don't have much in place in the way of formal policies. Thankfully that is in the process of changing. What we do have is loosely defined and rarely enforced. Since I hold the responsibility of ensuring the 3 A's of Security are all there I have implemented my own policies. I enforce them and update them as I see fit. I often get accused of being on a power trip, but that's OK. I know why I do what I do. It's because I see that as being my reason for being hired by the company.

That being said I obviously can't enforce these "policies" on all users. I still have to answer to those in authority over me. That is where the frustration factor comes in. What good does it do to work hard to lock most all the doors and windows to my network when you have to leave a side door open so that certain users can do as they please? Why not just put up a firewall, install AV, setup a patch server and walk away? Spend the rest of your time cleaning monitor screens and mouse balls.

Management needs to realize that when you leave a door open the bad guys will find it. One rogue user (intentional or unintentional) is all it takes. It's hard enough to keep the rogue users out without giving "special" users permission to be rogue. Management thinks that since we currently don't have to comply with regulations (meaning SOX, GLBA, etc) that we are OK for now. Once we have to start complying we will change.

Now for my 2 cents. That makes about as much sense as saying that I currently don't have termites (this analogy works well in the south) so I don't need to protect against them. Once I have them I will start getting treatment. A network that is left open will be compromised and once you start complying with regulations the problems will still be there. They are not going to magically go away just because you put in a few controls and implemented policies. Unless this company plans on starting completely from scratch they will be starting with a compromised network most likely. Those few machines that have been left open will still be compromised after they are locked down. Locking down a machine will not prevent a well planned piece of malware from doing it's job. The lockdown is designed to keep it off your system not to keep it from doing damage once it's there (mostly).

Just as in building a building you have to start with a strong foundation. Too often the foundation of a companies network is weak and rotting. Once it's in place it's almost impossible to rebuild it. All you can do is shore it up. Work hard to convince management that security has to be a priority and has to apply to everyone whether regulations require it or not.

Saturday, October 21, 2006

Week in Review

It's Saturday afternoon and I've got a lot of catching up to do. With vacation and sick servers at work I've had very little time for blogging. I saved my favorite stories from the week and hope to catch up on them now.

PRIVACY CONCERNS (or lack of concern)

I've started reading the series on Privacy on MSNBC that Martin McKeay recommends. I've only read a few paragraphs and it's already making me sick, angry and scared. There are 9 different articles on this and I've only skimmed a few of them. I'm sure once I've digested them I'll have more to say.

Martin also points out a good article on Identity Theft protection here.

 

MICROSOFT NEWS

It seems that many people couldn't wait for the first security flaw to be found in IE 7. It had only been out 24 hours when the news was full of reports of the first reported flaw. They did sort of get vindicated because the flaw was not in IE 7 but in Outlook Express.

I almost feel bad for MS because the whole world almost expected it. Of course there are going to be flaws found. It happens in ALL software not just MS software. I know that they have had a pretty rough track record but the wolves just couldn't wait to jump on them.

Then when they do finally come out with some serious security practices there are those who complain about that. I wrote about not liking the idea of having MS being in charge of my AV and security as well as the OS. As I've read more about their PatchGuard technology in the 64bit version of Vista I'm not so sure that I wouldn't like it in all versions. If it really keeps software from hooking into the kernel then that will stop a lot of malware that we deal with today. Symantec, McAfee and others who want access to it don't seem to realize (actually they do, they just know that the end of malware puts a big hit on their bottom line) that if they get to hook then so will the bad guys. I'm sure that before this all gets ironed out security will be reduced and/or the bad guys will find a way around this and we will still have more to do than we can handle. Job security at it's finest.

It's also good to see that I'm not the only one who is confused on this subject. Pete Lindstrom of the spire security blog has a good post that links to other writeups on this.

 

GOING BEYOND THE BASICS

I've written before about how I feel strongly that our job as Security Professionals it to know more than the technology behind what we do. We need to know the reasons behind why a technology will or will not help our company meet it's business objectives. We need to understand business process as well as technology. We also need to understand the regulations that affect our industry so we can best meet the audit and regulatory requirements that they bring with them. Michael Santarcangelo of the Security Catalyst website is also supporting this mindset. He is developing what he calls Security 2.0 to help those of us in security to better understand this and learn how to implement it into our daily practices. I encourage everyone to check out what he has to say.

 

FINAL THOUGHTS (for today)

Diebold has once again let source code "slip through" the cracks. I'm in talks with Diebold to provide some equipment for my company but their total lack of professionalism in how they have handled this whole voting issue is giving me severe second thoughts. They have demonstrated complete incompetency in all of this. If they can't seem to get anything right on the evoting side of the business how am I supposed to trust them with the financial side of things?

SearchSecurity.com has an article that when I first saw it I thought "good grief why do they keep writing about the obvious", but then I remembered that even in IT and Security we have more than our fair share of slackers who need to be reminded about such basic things. Unfortunately my company does not have a policy in place currently that prevents IPODS and other such devices from being connected to machines, but I do hope that it happens in the near future.

Thursday, October 19, 2006

Vacation Blues and a Salute to our Military

I've just about decided that vacation isn't worth it. You rush to get out of town. You rush around while you are gone. You get back at the last minute. Then when you get back to work you have tons of email and voicemail to sort through plus playing catch up on the work that wasn't done while you were gone. That's how it goes if you are lucky. I wasn't so lucky. I came back to a sick Exchange Server and a sick accounting server. Luckily neither of them seemed to be too bad. They are both back up and running. I don't know why I'm complaining it's kinda the norm. Last time I took more than a day off our Blackberry server crashed and our CIO had to rebuild it.

But all that said it was worth it because we went to visit my brother-in-law who is about to be deployed somewhere in the middle east. This is quiet possibly the last visit we will have with him until he returns in 18 months or so. We gave up our planned vacation next week to make the visit.

I'd appreciate it if all of you would keep him and the rest of our military men and women in your prayers while they are out serving our country so we can be free. When you get the chance tell them that you appreciate what they are doing for our Country.

Wednesday, October 18, 2006

Today's News

Kudos to Netflix

You gotta love it when you hear about a company that finds out they have a potential security issue and they fix it BEFORE it becomes a problem and BEFORE it even becomes public. I'd love to see more companies be this proactive instead of the trend of many to deny a problem and hope that we are dumb enough to think it will go away on it's own.

The Week of the Trojan

I posted on Monday about the McDonalds MP3 Trojan and since then there have at least 2 others that have made the news. One was a mistake and the other was probably intentional. Apple shipped some of their popular IPODS with a Windows virus. The thing that gets my goat about this is that in what has become typical Apple fashion they don't just admit that there is a problem they have to attack someone else. In this case they put in a jab at Microsoft saying "As you might imagine, we are upset at Windows for not being more hardy against such viruses, and even more upset with ourselves for not catching it," compare this to the Netflix story above. The other story is a website promoting the zcodec was actually a trojan. This one was probably meant to be malicious from the start.

Microsoft and Privacy

I'm not sure how I feel about this yet. Microsoft has published their internal privacy guidelines hoping that other companies can learn from them. I'm glad that they are taking proactive steps not only internally, but also to help others. What I'm not sure about is their exact motives. Given their record of past privacy issues I can't help but think that this is a PR scheme. Even if it is if it helps others do a better job then I can live with it.

Schneier's Top Ten Security Trends To Watch

Here is a link to Bruce Schneier's Top Ten List that he spoke about at Hack in the Box a couple of months ago. As usual he has good insight and I'm not here to dispute any of the things on his list. I did want to comment on number 10. He says that Regulations will drive security audits. I think we all agree with this and know it to be true. This is why I think it is so important that we have a good understanding of the various regulations that affect our business. Maybe I'm preaching to the choir here, but I know too many security professionals who think that regulations are a different group in the company and they don't have to know them. They are looking for trouble.

Monday, October 16, 2006

Scary Stuff

I'm not an analyst. At lease not a professional one. I mean that I don't make a living by looking at things like this story and determining what they mean and what impact they may have on the industry or on society in general. I do analyze stories like this and come up with my own thoughts and this one scares me. I have not read the full patent nor done much research on this, but just the fact that one company could own such a patent does not give me a warm fuzzy.

Not being a patent lawyer and only giving the patent a quick look it seems to me that they have been given the rights to tcp/ip traffic that has voice, video and data on it. Sounds like my network and most others that I know. Including the internet. Unless I did miss something then this only applies to ethernet networks so maybe I'll invent the non-ethernet internet that will replace the current ethernet one and then I'll own the patent. :)

McDonalds gives customers a break, or a trojan

Check out this story on the F-Secure blog. Another example of a company doing something without getting IT and security involved. A simple review of the MP3 players before shipping probably would have found this trojan and prevented a major security breach. Plus I can't wait to see the law suits that come from this.

Friday, October 13, 2006

They just don't understand

I've had a few posts where I've stated that I just don't understand. I don't understand why someone one do this or that, or not do something, or whatever. Now I've figured it out. It's not me. It's them. They just don't understand how serious security really is and how many bad things are out there just waiting for a chance to get into the network.

Just a little while ago one of our employees came to me and said that they had someone here that was trying to do a web demo but they couldn't access the Internet and wanted me to "fix" if for them. Then they looked at me like I was crazy when I told them no. I don't know this person or what kind, if any, of AV protection they have, what malware may be on their system or anything. Yet they honestly expected to just waltz in here and jump on the network.

I do feel better now. I was beginning to think that I was the problem.

Why I'm in IT and Security

When people that I knew in college and previous to that hear that I'm in IT they usually get a glazed over look and ask how in the world that happened. I was never fond of computers and really had no use for them. That is until I took the time to understand them and realized that they were not the enemy. (my redneck background really had a hold on me)

Once I got into IT I realized that I not only had a knack for it but that for once I really liked what I was doing. I enjoyed the challenge that it presented and I loved learning new things. Especially when I would figure out how to do something on my own. It's hard to describe the feeling of exhilaration you get when you come across a new or better way of doing something. After I had been in IT long enough to see what was what I had to make a choice on where I wanted my career to go. I quickly ruled out programming. I just don't think like they do. It's a completely different mindset. As I explored the options I kept getting drawn to security because I saw that it was where I could really make a difference. I knew that I could have a good career in pure networking or administration, but that wasn't where I saw the real difference being made. At least not for me.

After focusing my career on security I realized that there were still choices to be made. Do I focus on the perimeter, the interior, getting in (penn testing), keeping them out, educating others, policy and procedure, or what. I spent some time dabbling in various areas to see where my skills and talents were and where my interest was. I know where I want to go and I'm working on how to get there. I'm improving myself in the areas that will help me achieve my life goals and will make these things happen.

Many people wonder why put all this work in to something when I could have easily chosen the path of least resistance. The answer is that I'm just not made that way. I don't believe that God put me here to sit back and take the easy path. He put me here to make a difference in everything that I do. If you have been reading some of my recent post you have figured out that I don't like apathetic people who jut get by and that I take my responsibilities seriously. Martin McKeay wrote a nice piece on having a career and not just a job that I feel tied in nicely with some of my earlier tirades. Then this morning I ran across a great piece by John Maxwell that really stoked my fire, thus this post.

I may not be the most knowledgeable person on any topic (duh) and I may not be the best security professional in the world (again stating the obvious), but I do know that I am going to give it my all and continue to do it with passion. If the passion leaves then I'll post one more blog saying good bye and if you look hard enough you will find my new blog about my new job and new passion.

Today's Thoughts

The Value of Certification

Martin McKeay has a good article on CW about certification. In it he talks about how certification is really nothing more than a piece of paper that says that you study and test well. I can't count the number of times that I've worked with someone who was certified in various technology areas yet they couldn't apply their so called knowledge to real world technology and problems. I think certification is a good thing, but it's too easy in many cases and need to be backed up by real world experience. As I'm sure we all know some of the sharpest and best technology professionals have never been certified in any field. They just go out and do the work and do it right.

Spammers vs. ICANN

I'm all for Spamhaus and others who put up a good fight against spammers. I'm also not a big fan of lawsuits just for the sake of getting to play your way. I'm really not in favor of the courts trying to force their opinion on a US company that has the potential for such wide spread controversy. Not only does this involve companies in 3 different countries, but it involves the world. SPAM and the Internet are worldwide issues and can't be treated like a US only problem. Check out this CW article by Robert McMillan to read more on this.

User Education

This article on CNet News caught my attention. It's about the futility of user education. I'm a big fan of user education. Not because I think that it's all that effective, but because I think that part of my job as a security professional is to teach others how to be more secure. Even if a lot of it goes in one ear and out the other. I like sharing my knowledge and I know that it helps a lot of people and that makes it worth it. Although I do want to replace some users computer with a Palm M105 and a etch-a-sketch.

At Work

We are in the midst of MAJOR changes at work. Many of them are contingent on a couple of things that are still up in the air. We are having to plan for 3 or 4 different scenarios and they range from drastic differences to minor changes. What I like about this is that it keeps me on my toes and I'm rarely bored. It also gives me the opportunity to delve into areas that are not in my normal day-to-day responsibilities. As I mentioned before I like to stay on top of issues that may come back and bite me either directly or indirectly. Regulatory and compliance  issues have a real chance of doing that. What is frustrating about that is trying to sort through all the legalese to get to the meat of what a regulation requires. Some of them are well summarized with documents that take you right to the heart of what you need to know. Some of them though are brutal and require either a good imitation or lots of money to figure out what you need to know. But like I said it keeps me on my toes. Especially as I'm close to taking the CISSP test all of this extra work gives me opportunity to stay sharp in this area. Of course there is also those times when I've just finished several hours or days of work on a plan only to find out that my boss just came from a meeting where things were changed that totally void my plan or cause me to make major revisions. Oh yeah, the really good thing about these changes is that some of them will force the company to implement some things that I've been pushing for since I've been there. It can only go up hill from here.

 

Wednesday, October 11, 2006

Back Scratching

When I started blogging way back when ( about 6 weeks ago) I quickly noticed that if I didn't do something to get noticed then my blog would be just for my own enjoyment. Not excatly what I had in mind when I started this. I did all the things that was suggested on the blogger tips page of blogger.com and this helped a little but my readership still consisted of me and a couple of friends. It wasn't long before I got a mention on the Network Security Podcast with Martin McKeay and a link in his show notes. Then Alan Shimel mentioned me in a blog post and before I knew it my readership picked up quickly. A few other, Mike Rothman and In The Trenches, made mention of a thing or two that I wrote and again my readership went up. I'm not saying all of this to toot my own horn (goodness knows my readership numbers aren't that high), I'm mentioning this to return the favor not only to these guys who I've already linked to and quoted in the past, but to a new feed that I'm now part of. I received word today that my feed will be included in the Headlines from the Security Roundtable over at SecurityCatalyst.com. I'm fully convinced that if you have something to say that others will promote you to their readers and I hope that I can turn someone on to some of those who have helped me.

I'd just like to say thanks to all those who have linked to me and mentioned my blog and I look forward to continuing to learn from all of you and hopefully add something of value to the security blog community.

Check out my links to the right of my page (if you are getting this via RSS go to my blog page http://andyitguy.blogspot.com) and visit some of my favorite blogs and web sites.

A new take on IT Security


So if you do something that goes against the company security policy does IT call these guys? I know I wouldn' t want the Hell's Angels after me. I wonder if they use computers from Chopper Computers?

Interesting Things

This has to be filed under the heading "What are they thinking!" I bet this is just people (especially IT pros) who are testing IE 7 in preparation for Microsoft forcing it on us soon. That or Microsoft's Mind Machine is hard at work trying to brainwash us. I tested IE 7 on a couple of machines and had nothing but headaches with it. It's not going on my systems anytime soon.

Here is an article that should help me sell some of my security ideas to the suits. And my users can't understand why I don't just give out VPN access to anyone. It's bad enough that I have to give out so many laptops with wireless access.

My development guys are crying now. Now that Microsoft has ended support for XP SP1 they have had to upgrade to SP 2. They fought it tooth and nail but finally had to give in.

Today should be fun as we start patching and testing. The really bad thing is that a large part of my network is currently under a business partners patch management department and they don't test. Just push and pray. They did this last year with the October patches and broke our primary application. It took weeks to straighten it out.

I haven't followed this much but this article raises a lot of questions. The first one being how can they be so sure that these $100 laptops are going to be as bulletproof as they seem to be claiming. If anyone knows more about this I'd love to hear it.

Anti-Virus Whining and Moving on

I've never been a fan of Symantec/Norton or most of their products. I do use it at work as my AV product, but only because I inherited it and the CIO isn't willing to change at this time. I guess if I have anything good to say about them it's that I have made a little money on the consulting side when I have to go and fix a system that was hosed because the user either installed or upgraded their version of the home internet protection suite.

Now Symantec and McAfee (who I'm also not crazy about) along with a few others are crying about Vista. Whiners aren't high on my list either.  I do find it interesting that while many are crying fowl Kaspersky Labs is defending Microsoft. Either they know something that the others don't or they are hoping that by playing nice they will have an "in" with Microsoft and Vista while the others are out, or maybe they just have a positive outlook on things. Alan Shimel has a good story about those who are whining in his fable The Squealing Pigs, the Golden Goose and the Big, Bad Wolf.

Something else I'm not excited about is letting Microsoft have my servers, desktops and security. I don't care how seamlessly OneCare integrates with Microsoft products (especially Vista) I'm scared of having a Microsoft AV product. I will keep an eye on it and see how it compares to other products. If it shows itself to be a good product I will consider using it as one tier of protection.

I do like the fact that Symantec is not sitting back on their laurels while the Vista issue unfolds. They announced several new or upgraded products and initiatives earlier this week. Some of them look promising. I'm not sure yet how I feel about their Security 2.0 initiative, but they are showing that they don't intend to roll over and play dead. If they lose market share in the desktop space then they intend to gain in other areas. I like that mindset. I'll reserve judgement on the products until I see how they perform.

 

Monday, October 09, 2006

The Problem with IT and Security

Laziness, apathy or poorly trained IT staff? After reading this NetworkWorld article on the state of DNS server configuration I'm once again scratching my head and wondering what is going on.  I just don't get it. Why is it that there are so many instances of poorly implemented technology. Is it because so many unqualified people got into IT because they thought it was the road to riches? Is it because they see it as an easy job that doesn't require much physical exertion? Is management putting that much pressure on them to get it up and running? Why?

I know that if you are unfamiliar with a product that you can overlook some things that leave it vulnerable, but why are you putting it into production if you are unfamiliar with it? Why are you not taking the time to read the documentation or do a google search on common issues and problems? I just don't get it. Especially when the item can really cause a major problem, not only for you but for the whole company or internet. I like what the guys at Pauldotcom.com advocate. They scan everything with Nesus or Core before putting it into production.

I'd like to think that there is a good reason for this. But I've been in this too long to know better. I've seen too many servers, switches, routers, firewalls, and other appliances just configured with a new password and ip address. Then they were put on the network, marked off the list and the next task was started. When I was consulting I ran into many instances where a company called and said that they were having probems. As they described them and/or I looked into them in almost every instance the problem was do to improper configuration or implementation. Only once or twice was the problem related to vendor software issues or hardware problems.

Two of the incidents that really stand out are the time a guy put a dual-homed server that served as the domain controller on both the internal network and the internet. Needless to say that didn't go well. The other one was when a company called and said that since migrating to Windows 2000 that they were having all sorts of problems with authentication, printing and everything else excpet internet and SMTP email. The company that did the migration installed DNS for AD, but they pointed the servers to public DNS servers. Go figure. I just don't get it.

 

Thursday, October 05, 2006

Stating the obvious, but doing something about it.

ComputerWorld reports about the GAO (Government Accountability Office)report the the WAN that carries data for the Medicare network has security vulnerabilities. Who would have thought? There is both good and bad news in this, besides the obvious bad news that there were vulnerabilities.

The bad news is that this was a managed implementation by AT&T. They were paid $76.6 million dollars over 4 years to operate the WAN. I know that there will be problems and issues in any WAN implementation that large, but when you have been operating the WAN for the last 3 years and there are 47 vulnerabilities that have not been fixed something is wrong.

The good news is that CMS (Center for Medicare and Medicade Services) acted on the news as soon as they were informed by the GAO. It's good to see someone take responsibility for problems and work on getting them fixed right away instead of pointing fingers at AT&T or anyone else. I applaude them for taking action to fix problems.

 

It keeps getting worse

Redmond Magazine now has an article on IT Gone Bad. The stories just get worse and worse.

 

Poll Results

Technorati tags: ,

Shortly after my last post I ran across the results post from Dark Readings Scruples poll. I'll let you read it and keep my fingers quiet this time.

Wednesday, October 04, 2006

IT and Integrity

I started to write about the DarkReading.com IT Scruples poll the other day and never did get my thoughts fully together. Then yesterday I ran across a ComputerWorld blog about The Importance of Integrity and read about the "humorous" Toorcon joke about the Firefox flaws. Now I HAVE to write.

This kind of stuff is not funny and it IS unethical. It may have been meant as a joke, but when you do something that causes bad press for someone and causes them to lose time and money trying to find problems that don't exist then it quickly ceases to be funny. It's sad enough that so many seem to be taking such a casual stance towards integrity and honesty in their job. Especially when your job is IT security. Did the company hire you to secure the data from everyone but you? Just because you have access to it does not mean that you can or should look at it.

I don't understand why so many people think that integrity is something that you use when it's convenient for them or when it serves their best interest. Integrity matters at work, home and everywhere. If you are dishonest in one place then you will be dishonest in another.

In the world of IT Security there are pretty much 2 groups, the Black Hats and the White Hats. Just because you work in the White Hat world doesn't mean that you are a White Hat. If you cheat, lie and steal then in my book you are a Black Hat.

Now, having said all of that let me clarify a couple of things.
1. I'm not perfect. I have done unethical things in the past.
2. I'm not talking about someone who does something once or twide or makes honest mistakes.
3. I am talking about someone who thinks that they can so these things regularly because of the
position they hold and the trust that has been given to them by their company.
4. I am talking about someone who does something purposefully malicious (even once) that is
just plain stupid. Like lying about vulnerabilities or lying about their experience or talents just
to get a job. (Listen to ITT's Roll Call Segment to hear a good story about this)

One quick story and I will get off my soap box. I used to work with a guy who was a very talented network guy. He knew a lot of stuff and taught me lots of things. His problem was that he thought he was above the law when it came to honesty and integrity. It cost him his job with the company that we worked for. It didn't take him long to find a new job but he soon lost it also. He quickly found another job and then he got caught. It seems that he obviously lied about getting fired from his previous 2 jobs, but he also lied and told them that he was certified as an MCSE and a CCNP. Once these lies were discovered he was reported to both Microsoft and Cisco and supposedly has been black balled from ever holding certs with either company. I'm not sure if they do black ball but if so he does deserve it.

Monday, October 02, 2006

Speaking of Compliance

Here are 3 good articles on compliance specifically relating to data archiving, retention, and deletion. Also IM issues.

Computer World IM Article

Byte and Switch Data Forensics Article

Information Week Data Deletion Article

Pretexting and compliance

With the HP scandal being front page news there is a lot of talk about what they did, what was legal and what was ethical. It should make all of us think about our situations and where we are security professionals and our companies stand on similar issues. It should also lead us to look at where exactly we stand in regards to compliance on these and other issues. How many of us really knew if pretexting was legal and what regulations cover it.

How about other compliance issues? Often compliance and security are handled by different groups but they can directly affect each other and if the left hand doesn't know what the right hand is doing then we can bring trouble on ourselves. Compliance is tricky ground and depending on what industry your company is in, is it public or private, who our customers are, what data we have, etc.. we may be subject to several different regulations. They may be industry specific, state or federal. Here is a good blog post on the pretexting issue specifically, but it points out that not knowing can get you in trouble. Ignorance is certainly not bliss.

I know in the financial industry we come under scrutiny from a long list of agencies and regulations. I don't claim to know all the why and wherefores of what may bite me, but I have to have a good idea as to what they are so that I can reccommend and impelement the proper controls and technologies to keep us out of hot water. It my not be my job technically, but I'm not going to take a chance that I will implement something that another department says is OK and then find out later that it doesn't do the job or that it actually put us out of compliance. I won't go around (to quote the bloggers phrase of the week) "with my head stuck in the sand".

This is very similar to what I wrote about a few weeks back regarding HIPAA. I was astonished to find out who had no idea that they were subject to HIPAA and even more astonished to find out that many didn't care. Instead of security by obscurity they were going to claim compliance by ignorance.

3rd Party Patches

I'm not a fan of 3rd party patches as I mentioned in a previous post. I think that there are too many unknowns and potential problems. Although something I had not thought about was brought to my attention by this CNet News.com article. ZERT (Zeroday Emergenty Response Team) is not only patching current versions of OS's but also versions that are no longer supported by Microsoft and therefore not being patched by Microsoft. I'm fortunate in that I don't have to support any non-supported versions of Windows, but I know plenty of guys who do. What are they to do unless a third party helps them out?

Thursday, September 28, 2006

Play Day

 Today I had a lot of "maintenance" things to do so while they are running in the background I'm taking time to "play" and catch up on reading. I've decided to play with a few of the portable web browsers and sandboxie to see how I like them and if I think they would be worth using and reccommending to some of my friends and consulting clients. Here is what I played with today: Firefox portable, torpark, Opera (It's not portable, but I haven't used it before) and Sandboxie

I'll start with firefox portable because it was the one I liked the best. It was easy to install and I was able to import my favorites and other settings with no problem. Even after shutting it down and restarting it all was well. No settings seemed to be lost. Now this may not be the best for pure privacy, but I can tweek it plus it does keep most of my browsing data off the hard drive.

I'm not overly crazy about torpark. It works OK if you disconnect from the tor network, but that kinda defeats the purpose. From the hard drive it ran OK, but even that took a couple of days. At first it rarely connected to a web site and then it was like using a 14.4 modem. I had to try it on 2 USB keys before it would ever connect and it was way too slow. I would have to be fearful of my life and ID to use it when there are other options.

I heard about sandboxie not long ago and decided to try it out. It seems to do a pretty good job of keeping stuff off your system. I ran Firefox, Thunderbird, and Yahoo IM in it and none of them seemed to mind at all. I did have trouble trying to do things like email an article from a web page and copy and paste. It took me a few minutes to figure out what was going on then I remembered sandboxie. Those are slight inconvenienced that I could live with.

I also decided to give opera a try. I've heard lots of good things about it and was not disappointed. I haven't decided to give up firefox for it, but I will keep playing around with it. Two things that I would like to see. If any of you know if this is available I'd love to know. I would like to be able to open multiple tabs at startup like firefox and I would like to be able to have a "no scripts" type of plugin for it.

Tuesday, September 26, 2006

My Mama told me......

I don't always listen to good advice. Especially when it comes to dealing with people or vendors who prove time and again that they are less than trustworthy. That being said I will give credit where credit is due. Microsoft has released a patch for the VML vulnerability. They did it early and out of cycle. So here is a big THANK YOU to Microsoft for getting on this quickly. If I'm gonna bust their chops when they are bad I'll pat them on the back when they are good.

IE Patch

The big talk lately is the IE VML vulnerability that has many shaking in their boots, and rightfully so. IE has huge market share at work and home. What is also worrisome is that porn and gambling sites also have huge market share at work and home. These are the places that lots of malware live. Unfortunately, it seems, that even "trusted sites" are becoming infected at pretty alarming rates. You never know where you will get hit.

Microsoft is dragging it's feet on releasing a patch. The give "workarounds" that most people won't apply because they either don't know about it, don't think they are vulnerable, or are too afraid that they will mess up their computer. My favorite is when Microsoft says that users just need to avoid going to sites that are likely to have the malware on them. Like those who do this are going to wait a month before getting their internet porn fix just so MS can get a patch out.

Now there are at least 2 third party patches out. Zert and eEye both have released a patch that will fix this. I applaud them for being willing to step up and fill in the gap that Microsoft has left, but I have severe reservations about using either of these myself. For one I don't know how the patch will affect my system and if it breaks it will MS support me? What about my apps? How will this patch affect my applications? Especially those that rely on IE functionality. Who will support me if one of these breaks because of the patch? If it was just my personal system at stake I would be a little more willing to try something like this, but when it comes to corporate resources I can't take chances such as this. Now comes the dilemma. What about the chance that we take that someone (or many) will visit a site that has been compromised? I know that I have users who visit porn sites at work and at home with company laptops. How do I know if they have been hit? How do I convince management that this, or something like it is serious and likely to happen? Small company politics and a history of very few problems have made them complacent. I have one user that I'm highly suspicious that he has been hit. Maybe not by the VML issue, but something. His IE history is full of porn sites and he is having some "odd" issues. I can't do anything about it (except waste time trying to fix it) because it's his personal laptop and he has been given permission to use it for work. (Luckily in recent days I have been able to get a new policy in place for new personal laptops that gives me some teeth to growl with. Unfortunately this doesn't apply to previous personal laptops).

All that said I have my own patch and work around for the VML vulnerability. I don't use IE unless I absolutely have to. I'm a FireFox fan and only use IE when the site requires it. Even then I lock it down tight.

Friday, September 22, 2006

Who really should be responsible?

Bruce Schneier and many others are advocating making software vendors liable for buggy code if it can be proven to be the cause of a security breach. The argument is that when it hits them in the pocket book they will start being proactive about security and not reactive. This was espoused by Bruce at Hack in the box this week. Here is a ComputerWorld article that gives the condensed version. He states that we are losing the security war and that technology alone can't win it.

As would be expected I agree with his basic assessment. We are losing and no matter how much technology we throw at the problem we don't seem to be getting ahead. Not to mention that there is the human aspect to the problem. Management that doesn't really see the need to spend more on security, users who don't use basic common sense, mobile/remote users, poorly configured equipment (whether out of the box or by the sys admin). I'll stop here but we all know that I could go on and on. It's going to take more than education and technology to win this war. Bruce says that it will take economic incentives. I think that holding vendors responsible is a great idea, but I see flaws in it also. The legal system is one big flaw that stands out. If we are going to hold vendors responsible economically then we will have to prove beyond a shadow of a doubt that their poor coding and that alone was the reason for the breach. IT departments will have to prove that everything else was configured perfectly or the vendor will use that as part of their defense. "If exhibit A was improperly configured then how do we know that the breach wasn't made because of this."

It going to take holding both vendors and companies responsible and being aggressive in pursuing and prosecuting the bad guys. If this happens then the vendor will be forced to code safely and the companies would be forced to provide training, funding and the best possible IT staff. It would even weed out a lot of low hanging fruit on the IT tree.

Thursday, September 21, 2006

Apple Eating Crow?

Finally, David Maynor and Johnny Cache get some satisfaction. Apple has finally admitted that there is a problem with their wireless driver. Unfortunately they still refuse to admit that this is related to the to the presentation at Black Hat last month. How does Apple expect us to believe that they just happened to find flaws, on their own, shortly after Black Hat? Their integrity and credibility seems to be getting worse and worse. I had considered getting a Mac after I played with one running Paralles and Windows, but then I read about Chris Hurleys experience and now seeing how they have handeled this has changed my mind.

I'm glad that David and Johnny have been vendicated. If not directly by Apple then by their actions anyway. It's just a shame that so many people jumped on Apples bandwagon and tried to drag their names through the mud. Those of us who are Security pros know that they had too much to lose to make up stories just for the shock factor. I don't think anyone who really matters ever doubted them anyway.

Blogging Risks

SearchSecurity.com asks the question "Does blogging pose enterprise information security risks?
I think we all know the answer is a resounding, YES! As long as blogs are available to any and everyone (which they should be) then there will be someone who opens the door to the hen house either by mistake or on purpose. People know things that they shouldn't know and can't wait to tell others. Sometimes they don't realize that they are doing harm to their company, sometimes they do. I know myself that there have been times that I have written something and not posted it because after careful consideration I realized that it really wasn't anyones business outside of my company. Not to mention the old CYA kicks in and I realize that it could et me in trouble or cause undue heartache for my company. They have entrusted me with the "Keys to the kingdom" and I don't want to break that trust. I only wish that everyone else had that same frame of mind.

Wednesday, September 20, 2006

New IE Flaw

It looks like the hype has started on the new IE VML Flaw. Many are predicting doom and despair for IE users. I hope they are wrong, but I'm glad that they are out there. Why? Because the louder they scream the more attention they will bring to this. Hopefully that will mean that more people will be careful with their web browsing habits. There needs to be more done though. Microsoft needs to take action long before the Oct. 10th patch Tuesday. It is inexcusable for them to delay on patching issues that have the potential to cause so much trouble. It may be porn sites now, but soon it could be other sites like the issue with Samsung not too long ago. There are too many web servers out there that are poorly maintained and protected for this not to be taken seriously.

My suggestion is that everyone either write, call, or email Microsoft and insist that they fix flaws that are of this magnitude immediately instead of waiting until the next patch cycle. We should also inform them that we have downloaded and installed FireFox and will continue to use it as our web browser until they start responding (of course by then you will like FireFox much better and keep using it).

The more dependent we become on the web to do business and life the more critical it is for ALL software vendors to be VERY responsive to vulnerabilities. It may be a matter of national security one day.

Sorry, Wrong Number

This is really encouraging and makes me feel so good about my privacy. Rich Mogull, of Scurosis.com, posted an open letter to a healthcare company that keeps faxing him various medical records. They ranged from insurance records to test results. Again, another example of people just going about their daily job not paying attention (or caring) if they are doing it to the best of their ability or not. I'm sure (at least I hope) that Rich contacted them after the first time or two that this happened and let them know that they had a wrong number. Yet, if he did, they apparently continue to fax someones PRIVATE medical records to anyone who has a fax. I'm sure that HIPAA
(thanks Dr. Chuvakin) would not be very happy to hear this.

This also reminds me about an incident that happened at a former employer of mine. A Upper Management person was going through a nasty divorce and was having an email war with the soon-to-be ex-spouse and decided that they needed to print the emails for safe keeping. They ended up on the printer of a tech in a office over 100 miles away. OOPPS!

OS2, You could have been so much!

I was listening to PaulDotCom Security Weekly this morning (i've been out of town and am playing catchup) and they were talking about the Apple QuickTime patch that was just released. One point they made was that the vulnerability was disclosed to Apple on May 6th of this year and wasn't patched until Sept 12. 4 Months to patch a security hole while working on a new release of iTunes that is full of eye candy and fluff. I liked the older versions better myself. They also commented about how it was all about marketing and money and that is why they work hard on fluff and let other stuff slide. As I mentioned in my "about me" section I started in the world of OS2 when OS2 was already dead for the most part. As I worked w/ it and also on Win 95 machines I alsways wondered why OS2 died and Windows took over the market and it occurred to me that it wasn't due to Windows being a better OS it was all marketing. Bill Gates may be a software genious, but he is also a marketing master (or at least knew enough to get them on his team). IBM, on the other hand, failed miserably at marketing a much superior OS and thus we are stuck in a world of Windows.

Tuesday, September 19, 2006

Insecure Security

I was reading an article on Darkreading.com about PCI issues. One of the things it brought up was that credit card readers store the data from your magnetic stripe by default. So if someone can either compromise the reader or just take it they can get your card number, PIN, address and whatever else is stored on the mag stripe.

This is where security is lacking. Companies that put simple default passwords (or no password), making default settings that compromise security or make an otherwise secure device secure, and not implementing plain common sense is just outrageous! We talk about educating the user, implementing security in depth, using the proper countermeasures, etc... but the crux of the problem is vendors that will not do simple things like make their products secure (or at least partially secure) out of the box.

Would it be so hard for them to require the password to be changed on a device before it will operate? Would it be so hard to set the device NOT to keep sensitive data by default? Would it be so hard to include a tutorial for home users on how to secure the device?

This is just common sense and we as Security professionals are fighting one of our biggest fights against the vendors that are supposed to support us. We are never going to convince "joe home user" to secure his wireless, change the password, change the SSID, turn off unneeded services, block unnecessary ports, not to put their PC on the web without a firewall and NAT router, run updates regularly, install and keep current AV software, etc, etc, etc. There are just too many things that can go wrong and the average person is scared that they will mess up something if they do anything but plug it in and push next. This is true for setting up wireless, Internet access, windows, as well as the small business owner that sets up his own network or credit card scanners.

There needs to be a LOUD outcry from the security profession and all of IT to the vendors. MAKE IT SECURE BEFORE YOU SHIP IT!!!!!!!!!!!!!!!

Friday, September 15, 2006

Clever Bad Guys

It took a little longer than I thought it would, but it seems that the bad guys have finally figured out the best way to take advantage of vulnerabilities in Microsofts software. Wait until after patch Tuesday and then release your code. I have to admit having a specific day when patches come out is convenient as an admin. Although I would rather have to patch my systems more than once a month than have to go a whole month with a vulnerable system. I wonder if MS will patch this problem as quickly as they did the WRM flaw?

Please Excuse the Mess

For those of you who check my blog via Web browser. I just made some changes to my template on blogspot and it messed up some things. It may be a while until I get time to fix them.

Thursday, September 14, 2006

This makes sense

Mozilla's new Security Chief has announced that she would like to evaluate the code in Firefox and remove features that are no longer or rarely used. Imagine someone seeking to reduce the size and complexity of code. If more companies did this us security professionals might be out of a job before it gets outsourced.

Excellent Interview

Pauldotcom's Paul and Larry did an interview with Chris Hurley on Wireless issues. This was one of the most interestering and informative interviews that I've heard in a while. I highly reccommend listening to it.

FUD vs. Truth

One of the things that I've noticed as I find new blogs to read is that there is a lot of good natured disagreements between bloggers. One will make a comment on a topic and the other will blast him (but then it's almost as if you can see them going out to get a cup of coffee together later). Alan Shimmel currently has a debate going with most everyone else, but here he is in the ring with Mike Rothman regarding FUD and Vendor honesty.

Here is my two cents worth. Most vendors that I've talked with, especially if they are with a large company, will try to sell you using FUD until they find out that you didn't just fall off the turnip truck. Then many of them will continue this route because they don't know their own product well enough to debate it's merits with you. They know enough about technology to be dangerous and enough about sales and marketing to be stupid. And as long as they can find the people who will listen to their FUD and then buy based on that they will continue down the same path. I read a quote once the went something like this "As long as there is someone who will buy a cheaper product there will be someone to make it." The same could be said for sales. As long as people buy based on fear the sales people will pitch their product based on fear.

As security professionals, no matter what level you are on in the company, we must continue to fight to be involved in the vendor and product selection process. I've been handed a product too many times that was purchased without IT input and told to make it work. As long as this happens then we are at the mercy of the vendor.

Wednesday, September 13, 2006

IBM Tape Drive

IBM has released a new tape drive that encrypts data as it is written to the tape. Will this breath new life into the dying tape backup market? At a starting price of $35000 I know it won't keep me from migrating to disk based backups. It sounds like they may be on to something for those companies who have the budget and can justify the cost. I am curious to see how much the tapes cost, what kind of read/write speeds they have.

Future of Podcasting

I'm relatively new to podcasting. I don't have one of my own yet and I just discovered them in December of 2005. I knew that they were out there, but I didn't realize just how much really good content there is out there.

Now it appears that there are those who would like to limit or even take away our rights to make our own podcasts. Martin McKeay brought this to my attention a few days ago. He has a link to a petition on his blog that I have already signed. I encourage all of you to do the same.

Elections gone awry

Martin McKeay often talks about the insecurities that are rampant in electronic voting machines. Here is another example of just how big a problem this could become. It wouldn't take much planning on the part of those who wanted to disrupt our elections to really make a mess out of things. And this article focuses on the physical problems not the technology issues. There are those who are just sitting on the sidelines waiting for a reason to scream and complain about what went wrong and why the results of this precinct or that precinct should be thrown out. There are too many problems, both known and unknown, with electronic voting for us to turn to it at this time.

I don't claim to be an expert on the subject by any means. I have to admit that if it wasn't for listening to Martin I probably would not have been aware that there were problems until they slapped us in the face. Expert or not I am a tax paying citizen who is VERY concerned about the very real problems that are waiting on the horizon. These aren't problems that may send unwanted emails or cause pop-ups on your PC. They could very well change the results of elections all the way from your local school board member to who is elected President of the United States. We need to keep on top of this and do all that we can to make sure that these issues are fixed and that we don't let this get out of control any more that it already has.

What can we do? Call your Congressmen and Representatives at both the state and federal level. Read up on the issues surrounding this and what others have to say. They may spark an idea in your head that helps to resolve this.

Monday, September 11, 2006

Is it Monday already?

Where have the days gone? I haven't blogged since last Wednesday and it's 11:00 pm. I'm staying up late just to blog since it's been almost a week. The work week has been full of work stuff and the weekend full of family stuff.

Some of the highlights of the work week.
One of our guys had 3 laptops stolen from his car last weekend. They were all personal, but one of them he used at work and I had just finished building one to replace the one he used at work. On Tuesday he brought me a new MAC w/ Parallels and wanted Windows installed. Then he was unhappy because I wouldn't give him admin rights on the windows side of his machine. He kept saying it was his machine and that he should have admin rights. I kept telling him that it was my network and he shouldn't have them. I was finally able to explain why I wouldn't let him have admin rights.

One day on the way to the office my boss called and told me that he was running late and that I needed to get the communications meeting with our future core platform vendor started. I didn't know that we had a meeting and I was the main player from our company. Can we say "lack of communication"?

I also just finished a full and complete inventory of all 13 offices because over the last couple of years things have come and gone w/o any documentation. I can assure you that won't happen again as long as I'm there.

Such is the life of a small shop IT Pro.

Wednesday, September 06, 2006

MS and Cisco joint NAC

This should prove to be interesting. If both companies put their best foot forward and don't rush this it could be a very good thing. If either or both of them rush it then it could be a nightmare.

HIPPA Breaches

InformationWeek has an article on Privacy Breaches reported by health care agencies. This isn't surprising at all. HIPPA is so vague, has so many "outs", and affects so many different industries that it's almost impossible to work with. When I was consulting HIPPA was a project of mine. The company I was with was a late comer in the game when we decided to actively pursue clients that needed help with HIPPA compliance. I spoke with people in health care (hospitals, nursing homes, doctors offices), insurance, law firms, and others that were affected and without fail all of them had either an apathetic attitude toward getting compliant, were depending on a software vendor to be compliant, or had no idea that HIPPA could affect them. I know that those I dealt with was a very small sampling but when you bat 100% it really doesn't matter how big your sample is. It still speaks volumes as to the attitudes that companies have towards HIPPA. Many will do the bear minimum to get Uncle Sam off their back.

Tuesday, September 05, 2006

Security by ignorance

I just checked Bruce Schneier's blog and he wrote on something that I heard late last week and meant to comment on and forgot.

California has just passed a law that requires manufactures of wireless components to put a sticker on the device or have a setup warning that tells the end-user that wireless is insecure by default and also include ways to secure wireless. Here is a link to a more in-depth article on the law.

Maybe if we ask the bad guy hackers to leave our networks alone via a banner they will and we will all be happy.

Broken Windows

This can't be good for business. CA eTrust Antivirus mistook a Windows file for a virus and deleted it from the system. This caused some servers to crash and not reboot. I have 2 problems with this.
1.) Why would a file that is vital to the proper operation of the OS be so easy to delete?
2.) Why would CA release an update that would do this?

Do they not review their code and test prior to releasing updates? It seems to me that a mistake of this magnitude is not excusable. Businesses rely on their servers to be up and running in order to make money and the downtime caused by such an oversight on the part of CA could be very costly to businesses.

I've never been much of a fan of eTrust and this does nothing to endear me to them.

Friday, September 01, 2006

Gone Phishing

As I mentioned in an earlier post about not responding to emails that try to sell you something or get you to give up personal information. The AT&T hack is a perfect example of why this is not a good idea. If the bad guys can look like the good guys their job is easier. That's why it's our job to pay attention and use common sense.

Spooky, but not surprising

I hate to say it but the survey conducted by Ponemon Institute LLC is not surprising (see link below). It is disheartening, but not surprising. It’s also a little spooky. How many hacks take place everyday on corporate data that are never caught? It’s hard enough for companies with large, experienced IT staffs to keep on top of things. Imagine what the small shops go through. As I mentioned in a earlier post I work in a small shop and my resources are limited. Many shops are in similar situations or worse. They may have staff but often the staff is inexperienced especially when it comes to security.

I used to be a consultant and almost every client I had relied on the company I worked for to provide ALL of their IT needs. If a breach occurred we may never know about it because we were only there one day a week and in a few cases it was less than that. In the year that I worked there I can only recall one incident where a breach was caught. I discovered the breach while investigating a Active Directory problem. It turns out that the breach caused the AD problem.

As security professionals we know that we can’t stop all attacks and that there may be some small ones that happen that we never find out about, but to think that so many companies are ill equipped to handle attacks is sad.

http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1213621,00.html

Things I don't understand

I know that being a Security Professional I tend to think differently, hopefully more security conscious, than the average person. I would never buy anything that was offered via spam, I'm very careful about the websites I visit especially if it involves buying something or filling in a form. So therefore I do not understand why spam and phishing is so popular (ok I do because I work with end users all day). I just read about the growing popularity of smishing. Then of course there is the 100 plus emails a day that I get that are spam (thank goodness for spam filters!). All of this happens because it is successful. People spend money on things they don't need and often they end up getting taken for a ride. I don't understand why people STILL fall for this.

I also don't understand people who sell things on w/o first making sure that it's free and clean of personal data. I know that the average person doesn't have the technology or the knowledge of how to really clean a system of their personal data. But that doesn't excuse selling a drive or other device w/o at least erasing files and cleaning cookies and other basic tracks. How hard is it to delete files, empty the recycle bin and then run defrag? I know this won't stop a determined person from finding what they are looking for but the average person who buys something used is looking to use it not scower it looking for data.

Finally there is the ordeal with Sun not cleaning up old vulnerabilities when they fix them.
Java updates leave vulnerabilities
That really doesn't make sense to me. Why fix something if you are going to leave the broken one behind. I read that they do this for forward compatablitiy issues. OK, but why not make a fix that also incorporates forward compatability? Knowing leaving a vulnerability behind is unexcusable for any reason. This is just another reason for full disclosure.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.