Security's Everyman

Security's Everyman

Wednesday, July 04, 2007

Let Freedom Ring

I usually try to keep this completely Information Security related but today is a special day and thus I will detour from my normal format.

231 years ago the men who signed the Declaration of Independence took a stance for what they believed to be right and the best course for the colonies. They risked their lives and homes and many of them paid a very heavy price. Loss of life, family, land, possessions. They were willing to make the sacrifice for freedom.

Since then men and women have served this country in the armed forces and many have lost family, possessions, homes and their lives. They did this not because they were forced into it. They did it not because they wanted to be heroes. They did it because they believe that freedom is worth fighting for and that preserving freedom in America is worth the cost. They did it because they too believe in the same things that fueled the fires of the American Revolution.

I want to take this time to personally thank everyone of them for what they have done. Thank You for the sacrifices that you made for us. Thank You for serving your country.

I also want to lift up in prayer those who are currently serving our country. Especially those who are in Iraq and Afghanistan. These men and women are facing danger every day for us. It doesn't matter what your opinion on the war is these soldiers need our support. Lets give it to them.

GOD BLESS AMERICA!!

Tuesday, July 03, 2007

User Awareness Training in Action

All of you know that I feel strongly that UA training has great value in keeping us more secure in our online and work network lives. I've caught flack from some for my hard line stance on it but this story just goes to show how effective it can be. I'll say it again, "a good information security program includes UA training and daily secure practices from the IT staff." The best part of this is that it was done in day to day life and not via classes and boring material. If all IT professionals practice security around their users, take time to talk to and explain secure practices to their users then this is what can happen. Rebecca Herold tells the story of awareness from her kids.

Friday, June 29, 2007

Security Mentoring

How do you become a "Security Expert"? You can take classes in high school, college and trade school. You can attend "vendor training" or security related classes offered by many different organizations (Global Knowledge, ISC2, New Horizons, etc). You can attend seminars and conferences such as BlackHat, ShmooCon, SANS, etc. You can read books and practice with your own computer, home network or use some online labs. You can participate in forums (security catalysts community, friends in tech, etc). You can read blogs and "security" websites (Andy ITGuy, Tao Security, SearchSecurity, etc). You can join in on chats using IRC or other Instant Messaging type clients. You can join organizations such as ISSA, InfraGard, ISACA.

All of these are good and viable ways to learn about information security and how to practice it and do it. Of course the best way is OJT. On the Job Training. The school of hard knocks. Working side by side with other security professionals who have already been there and learned things by experience. It has been said that experience is the best teacher. This morning on my ride into work I was listening to Chuck Swindoll speak about learning through confrontation. He said that he thinks that the best teacher is "guided experience". I must agree. You can learn a lot from experience but if you don't have someone there to help you understand all that the experience has to offer then you are missing out. If you don't have someone there who will challenge your experience and more importantly, the lessons that you think you are learning then you are missing out on a valuable resource.

Chuck said that "the difference between experience and guided experience is confrontation".
Not confrontation in a arrogant, mean, way but in a way that is meant to challenge and lead. That is what makes a really good security professional. Someone who learns from others as well as on their own. Now please don't misunderstand me and think that I'm saying that w/o a "mentor" you can't and aren't a good security professional. That is not what I'm saying. But it will make you a better one. In order for that to happen you have to have someone who has the knowledge and the desire to pass it on. They have to be willing to be tough without being mean. Then you have to be willing to learn. Listen to what they say whether you like it or not. Take it to heart and make the change.

The security landscape changes too quickly for any of us to know it all and continue to know it all. It changes too fast for us to go it alone. We need mentors to help us along the way. Hopefully you will get the chance to actually work with others who can guide you and hopefully you will get the chance to guide others. If for some reason you don't have that opportunity (all you SMB IT and security guys) then look for ways to hook up with someone in your area. Look into some of the links above for organizations, blogs, training offerings and such that can guide you through the maze of information security.

FTP is Secure?

I'm a really nice guy and usually don't point out what is HOPEFULLY just an oversite on someone elses part but this is just TOO ridiculous and WRONG to let go.

This article on ComputerWorld.com starts off in very wrong way. To quote:

For years, file transfer protocol has been the standard for file transfer security. While FTP still offers the gold standard in security over the Internet,
Since when did FTP become the gold standard in security? Since when did FTP offer any form or security?

I really, really, really hope that the writer meant SSH or SFTP instead of FTP. I really hope that he wasn't quoting from a press release that was sent to him by the company who has finally solved all of our file transfer woes. I really hope that he retracts this statement and corrects this error.

Thursday, June 28, 2007

An Open Letter to Marketers

Dear Marketing Professional,

I often receive press releases from you about various new offerings that are coming out from this vendor or that vendor. I probably will never blog about one of them just because this blog is not for advertising. If I use something and really believe in it then I will write about it. Just as if I use something and it is a really bad product I will also write about it.

I'm not asking that you stop sending me the press releases because I do like reading about these products (usually). What I am asking is that if you are going to send me something DO NOT attach a .pdf or anything else to it. That is one sure fire way of not getting your release read or published. In todays world of rampant malware being spread in every conceivable way I will NEVER open an attachment that I receive from some random marketer.

As you probably can tell I did receive just such an email today. Not only was there an attachment with it but the person didn't even have a signature beyond a name. I am a security professional and if you are marketing to security professionals you probably should NOT employ the very practices that we preach and rant about.

Sincerely,

Andy ITGuy

Tuesday, June 26, 2007

Incident Response Response

Things happen all the time in the digital world. Often they go unnoticed for a long time and sometimes things go our way and we are aware of something going awry early on. When this happens we need to be prepared. We need to have a plan in place to deal with all that is involved in tracking a cyber criminal. Now I'm not a forensics guy for that you need to talk with Harlan Carvey
or The Security Monkey but I do know enough to realize that there are some best practices that you can employ to make the job of IR and forensics much easier. The nice people over at Network World have even put together a good article for you on how to be prepared for your next hack.
It covers many things that you need to do to ensure that you are covering the bases. Many of the things that they talk about can be easily forgotten in the heat of the moment but they are crucial in the investigation process.

Sunday, June 24, 2007

Successful Security

I'm really tempted to copy and paste this entire article here. Hoff nails it right on the head with this one. It's a no holes bared quick look at what we as Security Professionals need to know and understand. If we want a successful program then we have to look beyond the day to day things that often occupy our time. We have to move outside our self imposed little boxes and look at the big picture.

He gives a nod to Rothman's P-CSO in the intro to this and it does contain a lot of the same principles that Rothman and others (including myself) often preach.

Some of the Key points that I liked are:

  • Measure something - like it or not if you can't measure it chances are that it won't last long or it will never get implemented. Management demands measurable results.
  • Don't be a technology crack whore - technology is not the answer to everything. It may be fun to play with and it may look cool in the data center but if the processes aren't in place and the people don't understand them then technology will not work.
  • Shut Up and listen - Our job is to secure and enable. We can't do this if we only tell the users what we want we have to listen to what they need.
  • Learn to say yes by saying no and vise-versa - We often have to say "no" but we don't have to me rude about it and when we say no we need to explain why in a way that makes sense to the users.
Hoff, great job.

Thursday, June 21, 2007

Things I'm quickly looking at

I've been super busy lately and haven't been able to keep up with my feed reading like I'd like to. Obviously my posting has slowed quiet a bit also. Today I've got a little breathing room so I decided to post links to several articles that I saw that I quickly looked at and found to be of interest or value. If you haven't already done so check them out.


More UA fodder. Good article on DarkReading about how people are the root of the problem and thus why they need training.
http://www.darkreading.com/document.asp?doc_id=127294

Another good DarkReading article. This one is on the value of having a well trained IT staff.
http://www.darkreading.com/document.asp?doc_id=127295

DarkReading is our winner today with 3 straight awards in my picks of the day.
http://www.darkreading.com/document.asp?doc_id=127289

Rebecca Herold is quickly becoming one of my favorite bloggers. Today I discovered that in addition to her Realtime Community site she has another site that is also loaded with great information regarding privacy.
http://www.privacyguidance.com/

Cutaway jumps in with both feed talking about how Universities need to take care to secure and protect sensitive information.
http://www.cutawaysecurity.com/blog/archives/156

The Liquid Matrix blog rings in about the woeful state of DHS. Maybe they should call it the Department of pwnedland Security.
http://www.liquidmatrix.org/blog/2007/06/20/dhs-acknowledges-own-computer-break-ins-800/

Finally I'll leave you with some "lite" reading from the guys at Matasano. They make my head hurt.
http://www.matasano.com/log/885/exploring-protocols-part-1/

Why do security?

I've got mixed feelings regarding compliance. On one hand I like it because it is forcing many companies to do things that they wouldn't normally do to better secure their network. On the other hand too many companies are only doing what they have to do to pass their compliance
audit. They are checking the boxes on their compliance checklist and missing a hole somewhere because that area isn't on the compliance "watch list". They may be making the auditors happy for now but what about next year when they come back? What about next week when the bad guys find your vulnerability? After that happens you are going to then be forced to take action to fix the problem. Only it may be more expensive and difficult to fix than if you had done it when it should have been done. Not to mention the clean up costs.

Compliance is not the reason to secure. You secure because what you have on your network is worth something to your business. You secure because a breach will hurt your business and possibly destroy it. You comply because you have data that is valuable to other people. Things such as customer and employee data, credit card numbers, social security numbers, etc... All of these things are "protected" by your compliance checklist, but if a hacker gets into your network through some venue that is not on the checklist it doesn't really matter what is checked and what isn't.

When considering security for your network you have to look past compliance and look at the "real" picture not the one painted by GLBA, SOX, HIPAA, PCI or any of the others. Listen to your IT Security staff (or those who have a clue), listen to consultants, VAR's, Vendors etc... Don't just cast them off as either trying to get all the cool toys to play with or trying to sell you more than you need. Yes, those things happen, but you should at least consider what they have to say and look at it with an eye towards gaining knowledge on what will really make you secure.
Too often companies look at the bottom dollar and what will fill the check boxes. The only problem is that the check boxes keep increasing in number and the bottom dollar can't been seen because of hidden costs that you can't know about.

Friday, June 15, 2007

My Security RoadTrip

Martin asked several of us to tell our Security story again. I told it here (which was an updated story from earlier) and this time I'm going into a little more detail. Hope you enjoy it and I promise no Sun Tzu quotes Amrit.
____________________________________________________________________

I've mentioned before about how I got started in IT and sort of moved into Security but as I look back at what I wrote I didn't go into much detail about why and how I made the change.

I used to think that security meant a firewall and AV. The company I worked for never patched machines and I don't think that we even put AV on all machines (can't remember for sure). We ran MS Proxy Server 2.0 for a firewall and that was the extent of our security.

When we built a new data center we decided to "upgrade" our infrastructure we put in a Cisco PIX and MS ISA 2000 server. We put in McAfee EPO to manage AV. It was then that I started monitoring the firewall logs and ensuring that all our machines were updated with AV and we even started some patching. It was around this time that Code Red (or some high profile virus/worm) hit. It was then that I realized the implications of having a secure environment. I was also noticing attacks that were being attempted on our network from the outside. Several projects that I was involved in required me to do lots of research and talk with vendors about their offerings. I started realizing that there was lots of cool "toys" out there that allowed me to see deeper into the network and do things to mitigate the risks that I was starting to see.

My Boss was pushing me to upgrade my CCNA to CCNP. I had decide that I wanted to focus more on Security and asked him if he would object if I pursued what was at the time the equivalent of the CCSP (I think it was call CSS I and CSS II). He agreed and I started studying for it. Shortly after that I was laid off and my next job was a consulting position where I was hired to be the Security Specialist for the companies clients. I did network surveys to look for security weaknesses in their environments. Of course Security awareness was still in it's infancy (especially in small town USA) and most companies didn't want to pay for the service or the recommended changes to their environment. So I spent lots of time doing network monitoring and maintenance.

Until a month ago I had never held a pure security position. It was always just part of my job as a Network Engineer. I personally took the initiative to make it my priority and primary focus. As I was looking at what direction I wanted to take my career I decided that obtaining the CISSP over vendor certs would benefit me more. Since I was on my own for training, study, paying for tests, etc I had to choose carefully. Thus even though I'm qualified to work with several vendor devices I'm not certified on any of them.

There it is. My story. Long winded as it may be.

Thursday, June 14, 2007

Scott Wright at the SecurityViews blog has a good post where he gives his take and analysis on the Pfizer laptop breach incident. He said that he make this into a series. I hope he does.

He makes some good points about what went wrong, what could be done differently and what the implications are. My favorite on for a couple of reasons is this:

Get serious about security awareness in the organization. Policies are no fun to read, and just having them doesn’t make them happen automatically. Security awareness training and regular updating is essential. But it doesn’t have to be tedious, and people need to be kept up to date on what to watch for.
I like this because right now I'm in the middle of reviewing, updating and creating new policies for my company. They are dull and it's hard to stay away while doing this at times. Unfortunately if you make them fun then legal whines and they rewrite them in a way that no one can understand. I also like it because it re-enforces my belief that security awareness training is a KEY piece in a security program and maintaining a secure environment.

I just turned to todays entry of my handy "The Art of War" calendar and what do you know Sun Tzu has an appropriate comment for this very thing.

If your own army is hesitant and confused, you bring trouble on yourself, as if you were to bring enemies in to overcome you.
If we don't have effective security awareness training then our "army" will be hesitant and confused. They don't know what is and isn't safe to do because they don't live this stuff like we do. We have to train them. We have to give them the knowledge and understanding of what is going on so that they are not hesitant and confused. How many "average" computer users know the dangers of file sharing software? Their friends use it and their computers haven't crashed. What about the dangers lurking on sites such as My Space and porn sites. Do most people really think that by surfing for porn that they are possibly giving bad people access to their online banking credentials? No they don't. They aren't aware of the problems.

That is why a good security awareness program at work will not only benefit the company but the employee and their family and friends also. When they know the reality of this they will share it with others. Information Security may be focused on the corporate network but it expands way beyond the borders of our firewalls. Someone posted a comment on my "Why IT doesn't really get security" post where he said that he had all but given up on security awareness because ... well I'll let you read it here, it's a bit long. He has some good points but as I've said before we can't give up on security awareness training. We can't quit our users. Technology can only do so much. People have to do the rest.

Let's be careful out there,

Andy ITGuy

Sarcasm, bad passwords, and Dilbert under a Southern Moon

Since it's so 1990's to use The Art of War for security analogies or to use Dilbert to explain management principles I'll just point you to a Dilbert cartoon for a security analogy.

Tuesday, June 12, 2007

Why IT doesn't really get security

Since I've started my new job I've there have been four (4) different occasions where members of the IT staff have given me their USB thumb drives to transfer data to. These are guys that I work with daily but I don't know them and they don't really know me. One guy even gave me a U3 drive.

Now I take all the normal precautions against getting owned this way. Autorun is disabled and I have HIPS and AV installed on my laptop. While 3 of the 4 stood by while I copied the data to their drive the other one gave me his drive and walked away. I had it for over an hour before he came back for it. Those who did stay with me weren't paying attention to what I did. I could have copied data from their drive to my laptop or copied more than they expected to their drive.

This is just a sampling of part of the problem that the average IT guy has when it comes to really understanding security. They may get some of the more obvious security concerns such as what to do to secure a router or how to properly secure data on a shared drive. They may even understand some of the risks associated with various activities, but if they continue to pass around USB keys to people that they don't really know (and walk away!) then there is a problem. I think that many IT professionals do things such as this because they figure that they can trust one another and hopefully they can, but carelessness in one area will eventually lead to more carelessness unless they are very aware of their actions.

Another problem is that many IT departments are understaffed and they are always working in crisis mode. Even if they want to implement best practices in regards to security they don't have the man hours to do so. It's patch things together and then plan on coming back to fix it later. Unfortunately too often later never comes. Then if the department isn't understaffed they have the problem of lack of communication. One department is working on an initiative and another department is working on their project and they never meet to discuss how they may affect one another. They you have 2 projects that work against each other instead of together. Any security measures that one may have could be voided by the other.

I could keep going on and on with this but I think you get the point. Security doesn't come naturally for end users or most IT guys. It's something that has to be fought for. That's our job.

Info Security goes beyond the data

I've written before about how you need to be careful about what you say when you are in public places. You may be overheard talking about company secrets or just "gossip" that doesn't need to be out in the open. The same is true for using your laptop in public. People are curious and often will look to see what you are doing. I was riding home on the bus last week when I noticed the guy in front of me typing an email that contained info that I'm sure he didn't want the world to know. Yet there it was for all to see on his laptop.

We also have to be careful not to disclose too much information when talking to reporters. Just ask Terrell Karlsten. She is a spokesperson for Yahoo and she gave out a little too much information in an interview with InformationWeek. A hacker named Danny read the article and promptly used the information to find the flaw and write an exploit for it. Now before you come down too hard on Ms. Karlsten you need to consider what she had been told. Was she properly briefed on what to say and what not to say? Was there even a reason for her to know enough to be dangerous? Maybe she just needed to know that there was a vulnerability that involved a buffer overflow. Maybe she just needed to know that there was a vulnerability. Did she have any real idea as to what the implications of her statement were? I doubt it. Thus, another reason for a good security awareness program.

Good security covers all areas not just the data whether it be at rest, in transit or in use. It looks at the whole infrastructure and the company culture. It finds ways to work with everyone for the good of the company.

At least Yahoo was quick with a fix so hopefully the damage was contained. Makes me glad that I use Pidgen instead of Yahoo Messenger. :)

More Security Wisdom from The Art of War

"When your strategy is deep and far-reaching, then what you gain by your calculations is much, so you can win before you even fight. When your strategic thinking is shallow and near-sighted, then what you gain by your calculations is little, so you lose before you do battle."
This sums up the role of the Security Professional. You have to keep your eye on the big picture and not let the little things distract you. You can't let apathy set in.

Friday, June 08, 2007

P-CSO Bootcamp Revamp

As you know I spent Wednesday with Mike Rothman and the other brave adventurers on the Maiden Voyage of the Pragmatic CSO Boot camp. As I said it was a day well spent. Especially considering the fact that I just moved into a new position where I am in charge of security for all practical purposes. I'm not the CSO but it's up to me to ensure that we are secure. If I fail it's my head. Since I'm new here I have the opportunity to implement the steps in the P-CSO methodology from the very beginning so the timing was right.

We started at 9 and went until around 4. It was a small group (I think 10 is the most that Mike wants at one time) which was good. It allowed us all to share and learn from one another as we went over each of the 12 steps. The background of the guys that attended was varied but we all had the common understanding of security principles. We talked about what worked and what didn't work. Told stories about being hacked and cleaning up after the hack.

Mike took us through each step and allowed us to interact and ask questions. He didn't push us or force us to hurry onto the next section. The material was what is in the book and then some. He has some "freebies" that he gave us that adds value. He was able to expand on some topics based on his own experiences and on feedback that he has received from others.

Now I'm gonna dust off my copy of the book and take it, the materials and new knowledge I gained from the boot camp and prepare to kick butt in my new job.

If you get the chance plan on attending the next time he offers this. It's well worth it for CSO's, Security Managers and techies. Something for everyone.

Where is your malware?

The F-Secure Blog has a good post on where to look for malware launch points on windows boxes. The looked at thousands of samples of malware to see where they were hiding themselves in the registry to ensure that they were launched when the machine is rebooted. They have a nice graph and a list of the top 10 registry keys to look in to see if you are unknowingly infected.

Thursday, June 07, 2007

Something to Talk About

I just read an article in Fast Company Magazine that made me think. The article had nothing to do with Information Security, IT or computers. It had to do with marketing (which I dislike immensely). Yet marketing can make all the difference in a security program. (See my post about Selling Security). How we package and market our program can make or break whether or not we get the funding and approval to do what we have deemed as necessary to protect our environment. Do our policy recommendations get accepted? Do we get to implement this technology or this program that will improve our security posture? How we market and sell it may make all the difference.

In the FC article they talked about making your product “stick”. What is it that you do the makes your product stand out from the crowd? What makes people talk about your often sub-par product? (I'm not suggesting that we try to sell sub-par security) We have to think about our image to build and maintain credibility within the organization. We have to ensure that the security group is viewed positively within by management as well as by the end user. We have to adopt a positive posture of security and do all we can to eliminate the negative attitudes that WE have created over time. Our attitude towards end users, management, the company culture and our jobs has to be positive if we are to develop a positive security mindset within the company.

Yesterday I attended the maiden voyage of Mike Rothman's Pragmatic CSO Bootcamp. It was a day well spent. We talked about this very thing on and off through out the day. It seems that most every step in his 12 Step Security Master program came back to this in some form or fashion. In security it is all about image and credibility. If we are viewed as the group that wants to make it hard for the users to do their job or as the guys who don't want us to have any “fun” then we are developing a negative image. That image will spread throughout the entire organization if we are not careful and it may well come back to haunt us when it comes time to secure funding for projects.

At my previous job the marketing group branded the IT department as the “Red Tape” department (now you know why I don't like marketing). That came from the fact that every time they wanted to do something we put the brakes on them. Often we did it in ways that didn't help our image. They would say that they wanted to do such and such and we said NO!!!! and then walked off. They would ask to implement this technology and we would make them jump through hoops to justify it. Sometimes just because we could. Pretty sad, huh? I have to admit that I participated in that. Sometimes out of a spirit of being ornery and in a position of “control”, sometimes out of a spirit of joking around (I'd come back later and tell them it was approved just to irritate them) and sometimes because it was just a bad idea that affected security. After they branded us the “Red Tape” department it made me stop and think about our image in the company. I didn't like being the bad guy. If it is necessary to be the bad guy to remain secure that is one thing, but to be the bad guy because of an attitude is something else. So I decided to change that attitude. Not because I wanted to be liked but because I knew that a negative attitude affected the whole program and the company.

So what do you do to make your IS program “stick”? What do you do to make it stand out and be seen as a way to enable secure business practices? What things are going on that encourages a negative or positive attitude within your group, department and company? How can you make changes to improve the image of security within your company? It doesn't matter whether you are the CSO or your are the new guy who is stuck with the most boring security job in the company (log review) you can start with changing your attitude and how you react or respond to things that happen. It may not be easy or fun (after all making fun of dumb things that users do can be very funny at times) but it WILL make a difference over time.




Tuesday, June 05, 2007

Singing the PCI Blues

Back in December I posted about being happy that I had finally been able to get an answer to my question as to whether or not my then current employer was subject to PCI/DSS. The answer was that they were not and I was happy.

Now that I'm in my new job PCI is a part of my daily life. I'm now having to refresh my memory on PCI (I boned up a little in the past just in case) and am having to start the process of checking out what we are doing and what we still need to do. I like it though. It's new ground in some ways.

This position is much different than my past jobs in that I'm doing less hands on with the network devices and more security support work. Things such as working on updating policies, reviewing configs and change request, reviewing results of a 3rd party Pen Test and working to ensure the issues are corrected. After I get my self firmly planted here and get many of these projects either well under way or completed I am supposed to take over some hands on jobs. I'll have to see how that works out. There is lots to do here and I'd like to see this continue in a position where I continue to focus on moving us into a more secure direction and let others do the hands on under my guidance. But then again I the "geek" in me doesn't want to get too far removed from the 1's and 0's.


A new threat to security

I ran across this story today and it sends chills up my spine. A new wave of attack technology. DARPA is implanting chips in moths that will allow them to be controlled remotely and possible infiltrate enemy camps and beam back A/V signals.

What are the security implications of this for us? Are we now also going to have to be exterminators? I know this sounds ridiculous, but if this gets into the wrong hands it could prove to be a real problem. Imagine a moth watching you enter you password or sending video of your security configs to a hacker. What about listening in to conversations about security plans or board meetings?

This gives a whole new meaning to "shoulder surfing". I gotta go get a can of bug spray. :)

Monday, June 04, 2007

Get Your Malware!!

I was browsing ha.ckers.org today when I ran across this post. Do people actually do this? Why not just invited a hacker to dinner and let him use your computer for a few hours while you are in the other room watching TV?

Wednesday, May 30, 2007

Selling Security, It's our job

It's good to hear someone else from time to time get on the same rant as me. I'm talking about my regular "We need to quit bashing users" routine. Pete Lindstrom rants about how we need to pay closer attention to the business needs and not whine and cry about how Management doesn't understand or care about us. Now Pete is talking specifically about a podcast that Marcus Ranum did where apparently Marcus does just that. I have not listened to the podcast and so I can't comment on the specifics, but suffice it to say that whether or not Marcus did "whine" or not isn't the point. The point is that often Management does NOT get security (or IT at all) but it's not their job to get us. It's our job to explain ourselves and why we are important. They are business people and we need to sell them on the business of security. I don't mean try to scare them with FUD, compliance or horror stories. I mean we have to present a business case to them for security. Why is it important and what kink of ROI can be gained from it. How we can implement it without making the users life miserable. How it can make the company money. That's what they care about. Management is about the business being successful. If we can convince them that a secure business is a successful business then we have done our job (or an important part of it).

Now, before I start getting comments and emails about how most security professionals aren't business people. How they need to stay focused on technology in order to be good at what they do. I know that and I'm not suggesting that we should all make a run for the board room, but as an industry we have to take the steps to prove our worth and value. Many companies implement security just to get the auditors and compliance people off their backs. They hate security and think it is a waste of time, money and resources. We can continue to wallow in the basements of industry or we can take it upon ourselves to change the attitude of not only the "stupid user" that we all so often complain about, but also the "Clueless C's" that often complain about us. Management isn't going to come to us until they see a clear benefit to the company. We have to provide that clarity of vision.

Sunday, May 27, 2007

New Blackjack


For the last 4 years my previous employer supplied me with a Blackberry. It was my first "smart phone" and I loved it. I started out with a 6510 which was old when I got it. Then I upgraded to a 8703e which I really liked. Color screen, pretty fast data speeds, more memory, etc... When I left that job I had to leave my Blackberry and get my own phone and calling plan. As I was looking at what carrier to use, what plan to get and what phone to get I kept looking at the free and low (under $50) phones. What can I say I'm cheap. As I looked at them I just couldn't get past the fact that I was losing so much functionality by going with one of those phones. Not to mention not having a full keyboard. I HATE having to push the 2 key three times to type a "C". I also dislike the fact that most of these phones don't allow you to associate more than one number with a contact and many of them don't give you a place to add email addresses or notes. Then there is the whole ordeal of having to manually add contacts to many of them. So I decided to go with a Samsung Blackjack. I didn't even get a data plan so I'm not using many of the features, but just having the "key" features that I'm used to is VERY nice. It's a little different than the Blackberry but close enough that there was not much of a learning curve. Overall I like it. The call quality is really clear and the features on it are useful. There are a few things that I don't care for but they are mostly semantics and I'm sure I'll get used to it. Now if I'd just get a little less cheap and subscribe to a data plan I'm sure I'd be thrilled. Maybe once I go permanent with my employer I'll take the plunge.

Becoming a Pragmatic CSO

Unless something happens between now and then I'm planning on attending the "Maiden Voyage" of the Pragmatic CSO training next week. I have to take unpaid time off since I'm new and since I'm on a contract for the time being. That stinks in terms of training and such. Until I go full time with the company I have to foot the bill, including not getting paid, for any training. Not a big deal for a single day event but it shoots me in the foot for anything such as BlackHat or DefCon. I know that the content of the P-CSO will be well worth it so I'm willing to go w/o pay for a day. I think Mike still has one or two seats available so if you want to go this is the opportunity. You will never get a price this cheap.

Hope to see you there!



Pushing without testing

My first week at work was pretty exciting. Several things happened that allowed me to jump right in and start putting my training to work. I'm not going to go into any details obviously, but there is one incident in particular that I want to talk about.

Our network is quiet extensive. It seems to have been well thought out in it's design and although security wasn't always a top priority they have done a pretty good job of implementing policies technologies to mitigate threats and to "shore things up". We have several partner networks that connect back to various segments of our network and one of them went awry this week. It wasn't exactly a security issue but easily could have been.

The partner, which maintains a important aspect of our business, pushed out an upgrade and it caused all sorts of problems. Fortunately this segment is completely separated from our core network and it is not accessible from the Internet in anyway. What if it wasn't though? What if we had an Internet facing interface that was affected by this. What if we didn't have an air gap between this network and our core?

The potential for a breach would have been very great. Either from the Internet or from the partner network. This just goes to show that diligence pays off in designing security for your network. I know many small and medium sized companies that would not have been so diligent in ensuring that the design of this was secure and that the proper controls were in place. Why? Lack of staff, knowledge and money.

How could this have been averted in our case? Obviously the vendor needed to do more testing before pushing out the upgrade. The biggest thing is that they pushed it all at once. Every location was upgraded at the same time so the problem affected all locations. If they had pushed it to one or two locations and then let it run for a day they would have discovered the problem and rolled back, fixed it and averted a big problem.

Other than that it was a quiet week. The other issues mentioned earlier were nothing compared to this. They just required some changes in the way a couple of things were configured and in how a couple of things were done. It does feel good to make a difference on your first week. Especially when it doesn't require me to be up all night working on something that broke. I think I'm gonna like this. :)


Thursday, May 24, 2007

User Awareness Awareness

I had to go to a training session yesterday for an app that is used for special purposes within my new company. It is used by several different groups some are regular computer users and some are not so savvy. The training went pretty well for all concerned up to the point where he was trying to explain the password policy for the app. It uses complex password requirements. You know Uppercase, Lowercase, number, special character. The problem was that it was explained poorly.

This is the problem with user awareness training that I'm always harping about. We take a subject that may be somewhat confusing for many people and make it even more confusing. Then we blame it on the user and call them stupid. These users aren't stupid. If they were they wouldn't be in the positions that they are in at work. They are very competent at their jobs. Also this goes back to poor security policies over many years. Users are accustomed to simple passwords. Having complex passwords that are poorly explained compounds the situation.

So what's the answer? First, when we plan our training (or explaining) talks we need to make sure that our examples make sense to not just us and others who are technical and regular users. We need to have someone who isn't so computer literate give us their input on how we explain the concept. Secondly, we need to work to change corporate culture on passwords and security. It may take a while and we may have to take "baby steps" but that is better than nothing or better than going from simple to complex and having the help desk flooded with calls because we took too big a step too quickly.

Tuesday, May 22, 2007

Thrown in head first

Two days on the new job and I have been thrown in head first. Not that that is a bad thing. I like it that way. They are giving me time to get adjusted and acquainted with the network, but they have already filled up my plate.

My title is Senior Security Engineer. I'm responsible for overseeing all aspects of network security. I don't have to do all of the work my self but I'm responsible for ensuring that it gets done and that it follows best practices, company standards, etc... I've spent the 2 days looking over network diagrams, device configs, Pen Test results and policies. The Pen Test and Policies are my first "major" projects to complete. I'm also trying to get up to speed on some of the devices that they use that I've not seen much of. The firewall and IDS systems are ones that I've not used before. That's not a big deal though.

So far I've seen both good and bad (imagine that) in how things are done. The best part is that they are aware that they need work and they have an idea as to where they want to go. It will be my job to refine that vision and make it happen.

All in all I'm happy with the position and where I think it will go.


Monday, May 21, 2007

Look Who's Talking Now

I started my new job today. I'll post a little about it in the coming days, but for now I want to talk about my commute. I live about 35 miles away from the new job so I decide to take public transportation. I take an express bus into town and then hop on the subway and get out right at my office building. I like this for several reasons. One, it's lots cheaper than driving 70 miles round trip in Atlanta traffic. Two, it gives me time to read, think, listen to my IPod or nap. Three, it keeps me from going to jail because if I had to sit in traffic for an hour or more every day I would go mad and do something really stupid.

From time to time I would look up from the book I was reading or wake from the nap I was taking and look around at the people on the bus with me. You wonder who they are, what they do, who they work for, etc... and if you listen close enough you can hear their conversations, phone calls, or see what they are reading or working on. The same thing is true for those who travel by air regularly. People just let the whole world in on what's going on with them. It doesn't matter if it's public, private, personal or professional. People just don't pay attention to what they are doing or saying.

Then today I ran across this article on Bankinfosecurity.com that talks about this very thing. The article requires you to register on their site for free, but the jest of it was that just by listening the author was able to glean lots of information about the bank that this person worked for. Name, phone number, part of an account number, etc... All because this person didn't take simple precautions while working and talking during a commute on public transportation.

It's easy to get caught up in the moment and forget about your surroundings, but if you are dealing with sensitive information you really need to pay more attention.

Sunday, May 20, 2007

My new gig

I'm excited to start my new job tomorrow. Not just because it brings in a pay check again, but because it will be interesting to see things from a different perspective. This will be my first purely security job. No more network admin responsibilities and no more trying to piece together free technologies to make a make something work as I want it to. I'll be working in an enterprise environment for the first time also. No more "small shop blues". I will finally have others at work that I can bounce ideas off of and talk to about concerns regarding security. I can get feedback from real live people instead of via email, posts and forums. I will get to experience what it's like to be in an environment where they have real tools to use. Where security is (at least in perception) taking seriously.

I read this post which pointed me to this post and it got me to thinking about my last job and how things would be different at my new job. Or will there be and difference? I sure hope so, but you never know.

When I left I had been preparing for this for about a week. I knew that this was a highly likely possibility that I would be laid off. Then as I wrote in my post about being laid off the morning that I was laid off I knew it just as soon as I walked in the door that day. I had spent the week getting things in order. I had ensured that I had backups of all data on my laptop that I needed. Not company data but personal things. I could have easily taken copies of ALL data on the network if I so desired. I had the access rights to EVERYTHING and if something had been set up so that I couldn't access it casually with my admin level rights I had the account info to get access to it. Obviously I had access that only myself and one other person had, but there wasn't any "real" protections in place to prevent the average user from taking anything that he/she had access to. It wasn't because we didn't want or have a need for it, but because we didn't have the money or staff to implement it.

Now that I am going into an enterprise environment it will be interesting to see what kinds of data protection they have in place. Will it be just as easy for someone to walk out the door with what they want or will there be things in place to either prevent it or at least make it VERY difficult. Unfortunately these are things that I probably won't be able to blog about. I'd love to be able to tell the story, but by doing so I will be giving away too much info that could be used against us. I'll have to see what I can do, but don't count on hearing much about it.


Friday, May 18, 2007

My vacation is over

Just wanted to let y'all know that my vacation is over and I start a new job on Monday. I really hoped that this wouldn't be a long break and it worked out to be 9 working days. After I get settled in and learn more about what I can and can't do I'll blog about the new gig. If may not be able to say much, but I'll do what I can.

Thanks to all of you who sent me notes and left comments on the blog. I appreciate your concern.

I hope I don't forget to set my alarm Sunday night. :)

Thursday, May 17, 2007

Identity Theft on the rise

One of my biggest fears is to have my Identity stolen or my financial data compromised. I'm careful about what I do online and when I do transact financial business online I'm careful to do it only from a PC that I trust and feel confident is free of malware. I check the URL to ensure that it's using a valid SSL cert and that it is the actual URL of the site I want it to be and not a phishing site. I only deal w/ reputable sites. I never give credit card info to those I don't know. If they won't accept PayPal then I don't buy from them. I don't click on links in emails that point me to financial sites. I always go to the site and navigate manually to the page that I need.

When it comes to physical transactions (ATM cards, Debit Cards, POS, etc) I check to ensure that the terminal is properly installed (as much as a visual inspection can do). I check to ensure that it's not a "face plate" over the real scanner that will capture my data. I ensure that I enter my PIN in a way that is not easily seen by others. I shred my receipts and others paper documents that may be used to steal my ID or financial data.

I take all of these precautions and still am in danger of being "tricked" into having my data stolen. This article from PC World points out that the crooks are getting better at getting our data. Of course this has been known for a long time, but now they have card terminals that are identical to those you use at WalMart and other stores. The only difference is that they have a circuit board that captures all card data. Then the crooks come back and get their terminals and your data.

Obviously this isn't easy and it takes skill and planning. It works because it looks and works the same. So now retailers and vendors have to step up their security to ensure that this doesn't happen. They have to develop and put measures in place to ensure that when a "rogue" terminal shows up on the network that it won't work. I don't know what they would be because I don't know the specifics of how they work, but I'm sure something such as encryption keys or activation keys that have to be entered prior to them coming online is a reasonable possibility. There must be some way of identifying each terminal and not allowing them to come online until they have been "approved" and entered in the system.

The key here is that if we are going to win this war vendors have to design their products in such a way that the plug and play mentality won't work. Making things easy is great but it doesn't work. It makes us less secure and makes the lives of the bad guys that much easier.

Wednesday, May 16, 2007

10% of web pages host malware according to Google

Did you see the article about Goggles research that said that 10% of web pages are hosting malware? Pretty scary stuff. Especially the part about most of it coming from banner ads and such. That means that the web site owner may not even know that they are hosting it.

Most of us aren't even fans of banner ads and this is another reason to not like them. I understand that the web site owners make money off of them and that allows them to do what they do without charging the site users a fee to visit the site, but we still just don't like banner ads.

Now for the security implications of this. Any time you post code on your site that points to another server you are opening yourself and your visitors up to potentially being compromised. How do web masters deal with this? What do they need to do to mitigate the risk associated with something like this?

Obviously the first thing is to do a review of the site that is being referenced as well as the code that they give you to put on your site. Then you have to be diligent to keep an eye on things to ensure that nothing changes over time. Just because it is (or appears to be) secure when you check it doesn't mean that it won't change.

Banner ads won't go away for a while so just as with everything else we need to be careful. Users need to be wary about what ads they click on. Stay away from those ads that take you to the "darker" side of the Internet. Stay away from those that go to places that you aren't familiar with. Just because it looks pretty doesn't mean that it is pretty.

Again I have to go back to education being a big part of the answer. Site owners have to be educated on how to operate a safe site and users have to know how to surf safely.

Tuesday, May 15, 2007

Time to think

I've taken the last week off from blogging and spent it focusing on my job hunt and career. I've spoken with several recruiters and friends. I've been on interviews and spent time online researching companies. Then on Friday we got a call from my wife's sister that she was ready to give birth so we went to Ohio for the weekend and saw our new nephew. We just got back in late last night and I'm ready to start the week off with more interviews and calls to potential employers.

I didn't pay much attention to the news in the security space last week so I don't have much to say about anything along those lines. What I do want to talk about is the importance of being prepared for something unexpected. As security professionals we often spend our days doing our best to mitigate risk, preventing breaches from occurring and being prepared in case they do occur. Many times it can take all of our time just to do this and when we get home the last thing we want to do is spend time on our career focus. So our resumes go untended and don't get updated with our latest accomplishments and achievements. We don't spend time developing other aspects of our career such as learning a technology that we don't use in our day to day work, learning a different aspect of security such as Risk Management, system assessment, policy creation, etc... Things that help make us a little more well rounded.

I say this because I have done some of this and some I haven't done. My resume was up to date and that was a big time saver since I had people requesting it right away. I have tried to learn new things but obviously I can't learn it all. As I've been looking at positions and talking to recruiters and hiring managers I realize just how much I don't know. It puts into perspective just how big the security space is.

In this day where lay offs are common place and companies are outsourcing jobs more and more it is wise to be prepared. To know what you want to do today and in a few years. Do you want to move in a different direction down the road? If so you had better start preparing now. If you don't you will not be ready when you are ready to make a move.

One of the things that I'm doing to prepare for the future is working with Michael Santarcangello. He has a program called "Career Compass" that helps you to focus on what you want out of a career and where your strengths are. Hopefully I will have a new job before I've completed this but I know that it will be beneficial for the future. Even though I know where I want to go this will help me to focus more and take the right steps.

So my advice for the day is "be prepared". Take some time to update your resume and think about your future. Then start taking steps to make you future a reality.

Tuesday, May 08, 2007

When Things Don't Go As You Plan

Last week the company that I worked for hit a major road block that threw it for a loop. It really hurt financially and caused them to go into "emergency survival" mode. Part of that involved cost cutting and layoffs. Yesterday I became a causality of the cutbacks. My boss called me in at 4:00 and told me that he had pulled all the strings that he could to save my job, but had lost the battle. I saw it coming. I knew last week that it was a possibility so I started getting my house in order. Then yesterday morning when I came in I knew that something wasn't right. I could just feel it and I was right.

A few things happened that made me smile in spite of the "dreariness" of what was happening. First, it was obvious that my boss was not happy to have to lay me off. He told me that he had spent the last 3 day working every possible angle to prevent this from happening. Once he realized that he couldn't win he started working his network calling people and telling them that he had someone that they needed to hire. He called about 15 people trying to either get me another position or get some leads for me.
Second, as we left his office and went to my cube to collect my laptop my phone rang. It was a local Recruiter calling to talk to me about a position that they needed to fill. I have an interview tomorrow at 4:00. :)
Third, my only cell phone is a Blackberry that the company provides and pays for. He agreed to let me keep if for a couple of days while I got a new phone and transferred my number. One thing that he had to do though was disable my network and email account and then he was going to initiate an "erase" of my Blackberry via the Blackberry Enterprise Server. So he disabled my account and sent me a test email. It appeared on my Blackberry. He then told the BES server to erase my Blackberry. Nothing happened. He tried it again. Still nothing. This went on for about an hour as I was packing my office. He eventually gave up and just deleted my account from the BES server so I couldn't send or receive email on the Blackberry. Even the network didn't want me to go. :)

Anyway, I'm looking for a position if any of you are hiring or know someone who is. I'm in Atlanta, Ga and that is the place that I'm looking first. I'm open to relocating also. Lexington, Ky or Cincinnati, OH are my first choices, but I would consider other locations as well.

Here is a little about my work experience. I'm a CISSP, and my background is networking and security in a Windows environment. I'm experienced in WAN and LAN technologies, project management, team leadership, working with vendors from first meeting to negotiating contracts, physical security, systems analysis. I'm experienced in dealing with end users and Upper Management.

Hopefully you already realize that I have a passion for security and making it understandable for everyone. I like talking about security and helping others see it from a different perspective if possible. I also want to help those in the security profession understand their users better and learn how to relate better to them and understand where they are coming from.

Thanks for letting me "ramble" and I'd appreciate any help that any of you can give me. I'll probably post my resume online soon and I'll post a link here once it's up. I'd also like to say thanks to the guys in the TCC of the Security Catalysts Community for all of their words of support and encouragement during this time.



Thursday, May 03, 2007

No one is exempt

I ran across this article this morning. The author and some people he interviewed seem to have been under the impression that corporate networks were almost immune to bots and similar malware. At first I thought "how naive" but then I remembered that I used to think that also. That is until I thought about all the different attack vectors that a network is susceptible to.

Years ago, when malware was sparse, a firewall and AV software was all many companies (even large ones w/ big budgets) needed and used. Virus' popped up from time to time when someone took a floppy disk home and got it infected and then used it at work. Then email started being used more frequently to spread them but they were mostly limited to doing little "real" damage and could be contained fairly easily. The malware writers got smarter and the advent of the Internet as a critical tool of business for both home and business use raised the stakes.

Now a corporate network can be secure at the perimeter, secure at the end point (as secure as is reasonably possible) and secure on the wire, yet still be open to attack from many points. Machines can get infected and the protections in place are often totally in the dark that anything has happened. You can get infected by doing things you shouldn't be doing and you can get infected by doing things that aren't inherently dangerous (browsing a legitimate site that has been compromised). The corporate network may be adequately secured to prevent this (at least we like to think so) but your home network, the coffee shop, the book store and other open wi-fi hot spots are ripe for the picking. These are the places where many users get infected and then they often bring the infection back to the office.

I'd dare to say that most corporate networks are not equipped to notice this unless something really unusual happens to trigger and IDS/IPS or they happen to stumble across it. Michael at mcwresearch gives us a great example of this. I also tell a story here of a time when I "stumbled" across something at a client site.

This is what is so scary about today's malware. It's easier than ever to get infected and harder than ever to be detected. That's why it's so important that security professionals continue to work diligently in all areas to protect their little corner of the network and Internet. Everyone from the Security Researcher down to the desktop guy is important in the fight. No one is better than anyone else and no one is more important than anyone else. We all have to work together if we ever hope to win this battle.

Wednesday, May 02, 2007

The ineffectiveness of technology solutions

Amrit thinks that user awareness training is a waste of time and money. I think he is wrong. I think ineffective user training is a waste of time and money. I also think that if we follow his line of thinking on this that we should abolish user training and all technology designed to secure our networks. After all we spend lots of time and money on them and they still have vulnerabilities that allow the bad guys access to our systems.

I know he has been listening to lots of people gripe about "stupid users" lately and he has experienced his fair share of them in his life. I know I have and they are very frustrating. But statements like his regarding it being a waste are VERY unproductive. He said "As security professionals let’s focus our efforts on developing, defining, and implementing technical and procedural controls that are transparent to the end user and have as limited an impact on their computing experience as possible," That's all fine and good, but it's not something that we can all do. Not all of us are in positions where we can do these things, but most of us are in a position to teach someone how to be more secure. Not to mention that until the time comes that we have these "technical and procedural controls" in place we still have users who need to be trained. It's
unreasonable to think that a session (probably quiet boring) of UA training and a few emails, posters, and (more boring) documents to read will change a behavior that has been going on for years.

User Awareness training has to be relevant and interesting in order to be effective. Different people learn in different ways and to expect them to all fit into the same mold is unreasonable. We adapt spam filters and firewall rules and IDS/IPS signatures to various attack styles, why aren't we willing to adapt UA training to various learning styles?

Now all that said I do want to be fair and let Amrit finish the quote above. "
that doesn’t mean that no awareness training should be performed but in an enterprise it should probably consume 1% of 1% of the total security budget, of which on average is 4-8% of total IT budget." He isn't against user awareness he just doesn't like the current state of it and thinks that there are better ways to spend time and money. Fair enough. I just think that before we go off making statements like this in a public forum we need to think about them more.

Finding bots and learning from them

Michael at mcwresearch.com has a good post about finding a bot infected machine on his network. He outlines how he was alerted to the problem, the steps he took in investigating it, how it was resolved and lessons learned. Go check it out.

Tuesday, May 01, 2007

Tip of the Day - Write it down

I don't plan on making this a daily habit, but a few things have crossed my mind and keyboard lately that has made me want to write about something that is often overlooked. One of the things that started this was a thread on the Security Catalyst Community about password policies. A comment was made about the need to use different passwords for different service accounts, the need for complexity, using things such as PWSafe to keep them organized etc... Then the comment was made

Need I say that you should NOT write them down anywhere.
I replied that writing them down is a good idea as long as they were secured in case of emergency. In this particular case the guy who started the thread is the only IT guy for his company. The loss of these passwords could prove costly to the company. I know of a couple of instances where the lone IT guy left under bad circumstances and refused to tell anyone the passwords for the systems. They were able to recover them, but it wasn't easy or cheap.

Then this morning I was looking at the SANS @Risk Newsletter and it listed all the vulnerable apps. As I was looking at the list it occurred to me that many of these were small apps that are often installed unknowingly w/ other software or they are small apps that you install and forget about. If these do not have auto update features then when they become vulnerable you are at risk and won't even know it. Having a list of ALL apps on your system and doing regular Google searches for updates or checking their web sites for them is a good idea. If you don't write them down then you won't remember them and they will remain unremembered or at least you won't think of checking for updates.

Using things such as the freeware Belarc Advisor (free for personal use only) will greatly simplify your search for installed apps. There are also others out there that will give you a good snapshot of just exactly you have installed.

Monday, April 30, 2007

Bruce Almighty

The talk of the blogsphere and IT Security news sites lately has been about the comments that Bruce Schneier made at InfoSecurity Europe 2007.

Most of the talk has been people expressing their disbelief that he would make such a comment. They are saying things like "computers and the code that runs them are designed and developed by humans and therefore they will contain errors, flaws and mistakes. So how could he expect them to not be insecure?" Some are upset and they actually seem afraid that his comments will signal the demise of the security profession in a vein similar to Alan Greenspan making a comment that causes the stock market to rise or fall.

My first take on it is that of course it's an absurd comment. There is no way that systems and the code that runs them can be secure. If we had started with a security mindset from the early days of computers it would be a much more secure environment now but there would still be a need for security professionals because of the human factor. People make mistakes. Designers, developers, testers, implementers, and users all make mistakes that make it necessary to have security professionals.

My second take on his comment is that he is partly right. There is no real excuse for systems and code being released that is insecure out of the box. We have known the issues for years but vendors have chosen to ignore them so they can get products to market faster. They would rather send out faulty products and fix them later because it gets money in their pocket faster. Then they look like heroes when they patch something quickly. This is what is absurd. How would we feel if others did this. Imagine buying a car and having to have it patched regularly because the manufacture didn't check things like making sure the hood latch keeps your hood in place. How about buying a house that was build w/ half the nails because the builder wasn't sure if it needed all the recommended nails. How about buying a gas stove that has a newly designed gas regulator that was quickly sent to market. Finding that bug could be deadly.

I've commented before on the fact that vendors need to take more time in ensuring that their code is secure and that they need to do away with insecure practices. Things like default passwords in hardware that don't have to be changed, java upgrades that leave the old insecure code in place, and on and on.....

I make a pretty good living as a Security Professional and many of my friends and colleagues in the industry make lots more than I do. This is what is unnecessary. If vendors did their jobs then there would not be a need to pay security professionals the salaries that they often command. There also would not be a need for tech support staffs that are bloated and often inexperienced. There would not be a need for security conferences such as Infosecurity Europe 2007 and others.

There is no incentive for vendors to take extra time to ensure that their code is safe and secure. They know that when it hits the shelf it will be bought quickly. They know that once they release a service pack sales will again pick up. They know that there are hoards of Security Professionals out there working to ensure that vendor mistakes won't affect users. They also know that there are conferences that draw lots of people and they can attempt to sell more and more and more.

It's all about the money. Bruce is right. We shouldn't need many security professionals and we shouldn't have to go to security conferences. Software and systems should be secure, or close to it, out of the box. But we all know that it won't happen until there is no financial incentive for them to ship insecure products.

Thursday, April 26, 2007

???????

I don't even know what to call this post. I'm still shaking my head in amazement. Last week I posted about the Google Calendar Leak and just told everyone to be careful. I didn't think much more about it then yesterday I was listening to Pauldotcom Security Weekly and they were talking about it. Larry was giving examples of searches that he had done and talking about the information that was found. So this morning I logged into my Google Calendar account and started searching for key words and looking at the information that was divulged. At first I just laughed at the little things that I saw. Conference call numbers, names, agendas, etc... A potential hackers paradise or Social Engineers dream.

As I looked more and refined my search a little more I found LOTS of other interesting things. Full names and addresses of companies and employees, Network addressing schemes, dates for upgrades and changes to security and network devices, etc... and these were posted by the supposed network and security teams!!!!!!!!!!!!! I think my head is going to explode!!!!!!!!!!!!!

As I was looking at some of the calendar entries I noticed links to wiki's and other sites that were tauted to have more details and information that the participants needed to review to get ready for the meetings. Then it hit me. What if someone decided to post a fake entry that had links to sites that hosted malware. Then someone, maybe a malcontent or maybe a security professional, is checking this out and they decide to see what other info is out there. Next thing you know you are compromised.

Wednesday, April 25, 2007

It could have been digital data they were after

DarkNet has an article about a diamond heist that took place in Belgium. It was successful due to social engineering. The thief spent several weeks getting to know the bank staff and earned their trust. By doing so he was able to walk off with about 14.5 million US dollars worth of diamonds. My favorite quote from the post is this,

My dear friend, education is the key..not more locks and bolts.
The same holds true for Information Security. If our users don't know how to spot and handle phishers then we might as well just put up an open WI-FI to our network and post it in the paper.
We all know that the defenses we put in place are only as good as the way they were configured and the last patch that was released. All of it is for naught if our users are giving away the keys to the back door.

If you need some good User Awareness materials there are lots of places to look. Some are free and others range in cost low budget to big budget. A couple that I can recommend looking into are the Notice Board Awareness Newsletter, Microsoft has some pretty good free stuff, or you can talk to Michael Santarcangello about what his company offers. There are also lots of other options that you can find with a simple Google Search.

Tuesday, April 24, 2007

Security Leadership

One of my favorite topics to read about is leadership. I like to think of myself as a leader and hope that what I do is looked on by others as leading. I try to apply the principles of leadership in all that I do. Whether or not my official position is a leadership position or not doesn't matter I still strive to be a leader.

In my opinion the security industry is in need of leadership. It is a industry that is widely varied in scope and objective. You have many different disciplines that often doesn't communicate with each other and often even openly criticizes or looks down on each other. If we are all fighting against a common enemy then why can't and don't we work together. Why should we each fight our own battles also fight each other?

Obviously leadership in an industry that is so varied and that is populated by people from all over the world, many of who aren't even "officially" in the industry, and many of who are rebels by nature is not an easy task. There won't be any one person who rises up and claims the title of "Security Leader of the World". What we need is for those of us in Security to step up to the plate and lead where we are.

Leadership isn't a position it's a life style. It's doing what you can, when you can, as you can. It doesn't require that you be the Team Leader, Manger, or VP. You can lead from where you are by simply doing what needs to be done. By being an example of how a security professional does his job we lead others. I'm not talking about all of the day to day tasks that we do so much as the way that we do what we do. It's the attitude that we have as we do our day to day duties. It's how we react when a situation arises that requires us to step up a notch from our daily responsibilities.

We need to remember that leading takes place where we are if we will remember some basic ideas. Leaders have the following characteristics and they use them in their everyday life both at work and elsewhere.
The following is used by permission from Dr. John C. Maxwell's free monthly e-newsletter 'Leadership Wired' available at www.injoy.com.

  1. Adaptability – Quickly adjusts to change.

    Leaders in the middle may not be the first to know, but they are often the ones in charge of implementation. Adaptable managers in the middle are willing to embrace a change operationally even if they are not yet ready to do so emotionally.
  2. Discernment – Understands the real issues.

    Good leaders cut through the clutter to see the real issues. A smart person believes only half of what he hears, but a truly smart person knows which half to believe.
  3. Security – Finds identity in self, not position.

    Effective 360° leaders are secure enough in who they are to not worry about where they are. Instead of focusing on reaching a position, they focus on reaching their potential.
  4. Service – Gains fulfillment in serving everyone.

    A servant leader serves the mission and leads by serving those on mission with him or her. The true measure of leaders is not the number of people who serve them but the number of people they serve.
  5. Resourcefulness – Finds creative ways to make things happen.

    Creativity is the joy of not knowing it all. We seldom, if ever, have all the answers, but we always have the imagination to create solutions to our problems.
  6. Maturity – Puts the team before self. Nobody who possesses an unrelenting me-first attitude is able to develop much influence with others. A mature leader sees beyond his or her personal vantage point and has the courage to make sacrifices which advance the team.
  7. Communication – Links to all levels of the organization. We often think of communication in organizations as being primarily top-down. Leaders at the top cast vision, set direction, reward progress, etc. However, good communication is a 360-degree proposition. In fact, oftentimes the most critical communication comes from leaders identifying problems or solutions at the ground level and sending them up the chain of command.
We are fighting a never ending battle that requires all of us to lead from where we are. So each of us needs to take steps to improve our leadership skills and become the best leader that we can be. Don't wait for a position of leadership make your current position a leadership position.


Friday, April 20, 2007

More on Phishing

The guys at Pauldotocm Security Weekly mentioned a paper about how the SiteKey service used by Bank Of America can be fairly easily bypassed and used to Phish your login credentials. The paper was done by Stop-Phishing Research Group at Indiana University. You can find the paper on Slight Paranoia. This is really good reading. I haven't read all the comments yet, but am hoping to get around to it later this weekend.

The thing that really caught my attention is that (as in all phishing attacks) this is possible because users don't pay attention. If you are on your own computer and aren't presented with the SiteKey image most people make the assumption that something happened and it is OK. So they nonchalantly reenter their information and suddenly they have been caught. Once again if we can just teach people the importance of paying attention when they are online we will eliminate most successful phishing attempts.


Where exactly is your information?

Jeremiah Grossman of White Hat Security has a good post about the rise in popularity of web based services and the dangers associated with putting so much information on other peoples servers. You can check it out here.

What strikes me about this is that we are so willing to put information in places that we have no control over. We assume that because the site has an SSL certificate and a name that sounds good we will give them more than enough information to become us. We also willingly give them enough information to rob us blind and put us into serious debt. Now I'm not suggesting that most of these sites are malicious or that your data is really in danger, but we really need to be more cautious who we give our information to and where we put it. All servers, all sites and all companies are vulnerable to attack. Even the big names that we all trust have problems and issues that are beyond our control.


Thursday, April 19, 2007

Another Questionable Idea

Researchers have found a new way to open others up to unsuspecting avenues of attack. I just have a hard time believing that this is a good idea. How long do you think it will be until someone has hacked this and now they have unfettered access to these laptops to do with as they please. I'm not sure that these guys have even given thought to the security implications of this or how to make sure that it is secure. There is no mention of security on their web site. They need to add to their FAQ under "What other applications exist for WiPeer?" Trojans, bot node and other assorted malware.



Wednesday, April 18, 2007

More User Education Fodder

This article on ComputerWorld.com is just more proof that we need to continue to push forward with User Education. People need to be aware that ANYTHING that they post on the internet is subject to being found by other people. I know that they trusted Google to not share what they didn't want shared, but software has bugs that often aren't found until it is too late. People make configuration mistakes that accidentally expose info that wasn't intended to be exposed.

I realize that there are many people who will ignore all UE attempts and will do what they want. Even so I still believe that LOTS of people do things like this out of a lack of understanding of the possible dangers. In one example in the article the conference call number and PIN were posted by an employee of the companies IT department. Again, another example of how UE is needed by ALL employees. There are just too many from the CEO down to the person who spends all day pulling staples out of documents that just don't understand and need to be educated.


Why checking my RSS feeds first thing is a good idea.

I woke up at my normal time this morning and made a cup of coffee. I started to read some before checking my RSS feeds. While the coffee was brewing I picked up my Blackberry to check my emails from overnight.

Nothing. This is not a good sign. I have several status messages that are automatically sent that shoud be waiting for me.
I sent myself a test message.
Got a big red X.

So I booted my laptop and logged in to check things. Both BES and email servers were running. Lots of weird messages on BES server. Nothing I had ever seen before. Tried a few things and was able to clear up some of the messages, but still not messages coming or going. Checked my email server and no problems there. Checked my email and all of my automated messages from overnight were there.

I know that I should have gone to Blackberry support but held off. Normally I would have been more receptive to going directly to the Blackberry support but this week has been full of things going wrong and I just figured that this was just another one. After about an hour of troubleshooting I remembered that a PIN message bypasses the server. So I sent my Boss a PIN. Again, big red X.

Now I put 2 and 2 together and decided that it was a RIM issue. So now I pulled up my RSS feeds and one of the first things I saw was this article from Network World. If I had checked my feeds first thing like I usually do I would have had a much more productive hour.


Tuesday, April 17, 2007

Santa Catalysts is comin' to town!

Michael "Santa" Santarcangelo is coming to Atlanta. He is going to be passing through Atlanta and we thought it would be a good idea for him to spend a few days in town and try to put together some training events.

He is has 3 different offerings that we are looking to plan.

  1. Speaking about Security - a 2 day course that teaches you how to refine your presentation and security speaking skills. He is offering this this at a 40% discount and also giving away a free coaching session for those who sign up. We are looking to have between 10 and 15 people for this class.
  2. Making a Life - How to do more with less (and have less stress) - This is a half day session that helps you learn how to find balance between work and life.
  3. Setting Your Career Compass - This is also a half day session that helps you evaluate your skills and understand the situations in which you thrive. Designed to help you get a clear handle on your career goals.
Making a Life and Setting Your Career Compass are being offered as a morning and afternoon session with lunch thrown in.

Both of these are being offered at deep discounts. This is the first time Santa has taken these "public" and he is working out the kinks to prepare for his "Security Revival Tour" that is planned for this fall.

If you are interested in attending either of these or both of them drop me a quick email at andy.itguy@yahoo.com or email Santa at securitycatalysts@gmail.com

If for some reason you aren't familiar with Santa you can check out some of his stuff here.

Monday, April 16, 2007

Michael Farnum tried to run me off the road today!

OK, so it probably wasn't really since he is in Texas and I'm in Georgia. It sure did look like him though.

I was driving down the road and just as I started to turn right from the right hand turn lane the SUV next to me decided that he also wanted to turn right. The problem was that he wasn't in a turn lane. I ended up in front of him and I looked in the rear view mirror and this guy looked just like Farnum. I know my blog is gaining on his, but this is a drastic measure. If he had been wearing the Grinch outfit that Shimel gave him I think I would have wrecked.

Identity Management and You

An advisory group that I'm a part of has a discussion going on now regarding Identity management. This is a consumer advisory group so we're not talking enterprise ID management but consumer level. Helping mom and pop manage their various online identities. We all know the need for keeping separate identities for different types of web sites. It would not be advisable for me to use andyitguy for my ebay, banking and other financial sites. Having multiple online identities for different types of web sites is a good idea. I'm afraid that it's not a common practice among mom and pop though.

In my experience mom and pop are using mom and pop for their online identities no matter where they go. Banking, ebay, MySpace and everywhere else they go. Not only are they using the same ID they are using the same password. This is bad. Once the bad guys figure out their user ID and password for one site it isn't hard to figure out where else they go and easily get in there. Even if some sites require a "hard" password it's common practice to use a slight variation of their "normal" password. IE if your normal password is abc123 you may change it to Abc123#.

So where am I going? Back to stressing the need for user education. We have to continue to work on getting the word out to everyone that will listen to us. Those who won't listen have to be "tricked" by getting the word in front of them in other ways. The key is that we can't be quiet. We can't give up. We can't quit. We can work as hard as we are able to secure web sites, protect DNS servers, write secure code and everything else we can think of. That will help, but until we teach users how to surf securely our fight will be more difficult than need be.


Thursday, April 12, 2007

Something worth reading

I haven't posted much lately. Partly because of being busy and partly because I just haven't seen much out there that really caught my attention. Some of the bigger news items I've let slip by because everyone else has commented on them and I didn't have anything else to add or the stories were just repeats of the same ole thing from the past. Things like Microsoft having to reissue defective patches, being too slow on releasing a patch, blah, blah, blah.

Anyway, that changed this morning when I ran across this post from fellow Trusted Catalyst member Perry Carpenter. I wrote last week about the CIA triad and Perry has found a different take or an expansion of the CIA triad and tells us about it. Very good and interesting reading. Shoot over and take a few minutes to read about the Parkerian Hexad. It's worth the time.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.