Posts

Showing posts with the label Crypto

eWaste safety hazards and information risks

Image
A warning in the New Zealand Information Security Manual  caught my beady eye yesterday: “Electrical and electronic equipment contains a complex mix of materials, components and substances, many which can be poisonous, carcinogenic or toxic in particulate or dust form. Destruction and disposal of WEEE [Waste from Electrical and Electronic Equipment] needs to be managed carefully to avoid the potential of serious health risk or environmental hazard.” Disposing of eWaste presents environmental and safety hazards arising from noxious/toxic/carcinogenic chemicals such as gallium arsenide (GaAs) and polychlorinated biphenyls (PCBs), plus the obvious dangers when handling sharp-edged metal or plastic chassis fragments, wires, printed circuit boards and CD/DVD discs plus  leaky electrolytic capacitors and old batteries . While there may be money to be made by extracting and recycling valuable metals  and reusable components ,  subsystems and modules , that's really a jo...

Skyscraper of cards

Image
Having put it off for far too long, I'm belatedly trying to catch up with some standards work in the area of R oot o f T rust, which for me meant starting with the basics, studying simple introductory articles about RoT. As far as I can tell so far, RoT is a concept -  the logical basis, the foundation on which secure IT systems are built. 'Secure IT systems' covers a huge range. At the high end are those used for national security and defence purposes, plus safety- and business-critical systems facing enormous risks (substantial threats and impacts). At the low end are systems where the threats are mostly accidental and the impacts negligible - perhaps mildly annoying. Not being able to tell precisely how many steps you've taken today, or being unable to read this blog, is hardly going to stop the Earth spinning on its axis. In fact' mildly' may be overstating it. 'Systems' may be servers, desktops, portables and wearables, plus IoT things and all mann...

Hacking the Microsoft Sculpt keyboard

Image
In its infinite wisdom, Microsoft designed data encryption into the Sculpt wireless keyboard set to protect against wireless eavesdropping and other attacks. The keyboard allegedly* uses AES for symmetric encryption with a secret key burnt into the chips in the keyboard's very low power radio transmitter and the matching USB dongle receiver during manufacture: they are permanently paired together. The matching Sculpt mouse and Sculpt numeric keypad use the same dongle and both are presumably keyed and paired in the same way as the keyboard. This design is more secure but less convenient than, say, Bluetooth pairing. The risk of hackers intercepting and successfully decoding my keypresses wirelessly is effectively zero. Nice! Unfortunately, the keyboard, keypad and mouse are all utterly dependent on the corresponding USB dongle, creating an availability issue. Being RF-based, RF jamming would be another availability threat. Furthermore, I'm still vulnerable to upstream and downs...

Travelex vs Sony shootout

Image
The Travelex ransomware case study is coming along nicely. Over the dull grey NZ weekend, I prepared a timeline of the ongoing incident to compare and contrast against the Sony Pictures Entertainment ransomware incident at the end of 2014.  Already, Travelex is well ahead on points, restoring UK customer services within 3 weeks of the attack with more on the way. The incident timeline is substantially compressed relative to Sony's: they are getting through whatever needs to be done more quickly. Travelex has done well to keep its retail customers updated throughout, from the initial rapid disclosure on Twitter through to brief informational pages on the web, an FAQ , plus a statement and talking-head videoblog by its CEO on Friday just gone. Full marks from me! As far as I'm concerned, Travelex has managed the disclosures and public comms well, releasing professionally-crafted, informative briefings about the evolving situation, reassuring customers and not trying to cover th...

Leaving a digital legacy

Image
Yesterday morning, I checked the ISO27k Forum messages as usual. Among the ping-pong of ongoing conversations was a sad request to stop emailing a Forum member who died just last week. His widow sent a few polite messages through his email account to the whole list, replying to an assortment of recent Forum emails. Presumably she didn't read or comprehend the 'unsubscribe' instructions from Google at the bottom of every message, and given the circumstances, it's entirely understandable - not least because I think she is Spanish, while the Forum and its instructions are in English. Unsubscribing someone from an email list is a simple example – something that’s easy for those of us who frequently use managed mailing lists (or groups or reflectors or Special Interest Groups or whatever they are called) but is not necessarily obvious to those who don’t, especially when they are in turmoil, grieving and overloaded with a million difficult tasks all at once. It’s an extraord...

Security awareness for off-site workers

Image
Hot off the production line comes May's security awareness and training module about working off-site . The 69th topic in our portfolio was inspired by a subscriber asking for something on home working. It ended up covering not just working at home but  the information risk and security implications of working on the road (digital nomads), in hotels, on supplier or customer sites and so forth , touching on online collaboration and other related areas along the way. Module #193 is 95% brand new, prepared from scratch during April and blended-in with a little updated content recycled from previous modules on workplace security and portable ICT security, plugging the gap, as it were. I'm proud of the guideline (item #04), part of the staff awareness stream .  At 16 pages, i t is lengthier than normal due to the sheer variety.  With the odd touch of humor and stacks of pragmatic security tips for home and mobile workers, it would make a neat little awareness booklet or eDoc...

Zombie data

Image
Over on the  ISO27k Forum   recently, someone raised the concern that a cloud services provider may have deleted and certified deletion of a customer's data at the primary location but somehow neglected to delete the copy/copies at their Disaster Recovery location/s, leading to problems later if the data then turns up unexpectedly, possibly in a different legal jurisdiction such as an overseas DR facility. That scenario is possible and might be a concern ( e.g. for GDPR compliance reasons) so yes it’s an information risk of sorts. Potential mitigating controls include: Clarifying the requirement for the cloud services provider to delete and certify deletion of ALL data copies including DR, backups, archives, caches and assorted fragments that might be loitering in odd corners of the data centres, IT systems, networks, fire safes and filing cabinets, and reinforcing it with additional checks/audits plus strong penalties and liabilities; Using encryption wit...

Passwords are dead

Image
I've blogged about passwords several times. It's a zombie topic, one that refuses to go away or just lie down and die quietly. On CISSPforum, we've been idly chatting about user authentication for a week or so. The consensus is that passwords are a lousy way to authenticate, for several reasons. First the obvious.  Passwords are: Hard to remember, at least good ones are, especially if we are forced to think up new ones periodically for no particular reason; Generally weak and easily guessed, due to the previous point; Sometimes generated and issued not chosen or changeable by the user; Readily shared or disclosed ( e.g. by watching us type), or written down; Readily obtained by force, coercion, deception and other forms of social engineering such as phishing or password reset tricks, or interception, or hacking, or brute force attacks, or spyware or .. well clearly there are lots of attacks; Often re-used (for different sites/apps etc ., and over time). Next comes some les...

P2P messaging

Image
The awareness module on email and person-to-person messaging is gradually taking shape. Today we've brainstormed the information risks associated with email and P2P messaging and arranged them on an Analog Risk Assessment graphic: So far, the risks are scattered across the green and amber zones with none in the red high-risk region. However, there are more than 20 risks already identified hence, taking them all into account, the cumulative risk is significant. Furthermore, many directly concern employees' insecure use of email/P2P systems - falling for scams, making typoos and inappropriately trusting the veracity of messages for examples. This is clearly an important topic for security awareness purposes. We'll reconsider, adjust and refine the risks as the module develops, using the ARA graphic to illustrate some of the briefing papers and presentations. By the way, phishing is but one of the 20+ information risks in this domain. Even if we group it with spear-phishing, w...

Email security

Image
As part of the background research for next month's awareness module on 'email and messaging security', I figured it is about time I got to grips with secure email. You'd have thought I'd be on top of it already, given that my career started nearly 30 years ago with email system administration and then information security! Truth is, I've managed OK without it until now. The few times I have really needed to send secure email, I have either used a secure webmail facility provided by the client or achieved the same ends using AES-encrypted WinZip archives, sharing the secret password off-line. Now, I find myself needing to communicate securely with a company that doesn't offer secure webmail but does (allegedly) use PGP for secure email. Hmmm. Today I re-discovered a key reason for not bothering with secure email - the very same reason that has caused me to try, fail and give up previously. The process of configuring MS Outlook - a commonplace, mainstream ema...

28 days of awareness: day 25

Image
We're plummeting towards the end of month deadline, hence working this weekend to complete the remaining writing in time for the awareness materials to be proof-read and packaged for delivery. The professionals' awareness materials are usually the last to be finished, partly because they include the newsletter that picks up on news items right up to the point of delivery. Another reason is that I'm a self-confessed geek with an IT background, hence the materials in this stream are easier to write - so much so that if I started with them I would probably not leave enough time and energy for the other two streams.  Having written those other materials first, I now have a reasonable picture of the topic area as a whole, including the wider personal, business and societal context. I have come up with a few angles I want to bring up and delve more deeply into for the professionals, most obviously the technologies associated with ransomware and the cybersecurity controls. However...

Cryptography - our security awareness topic for July

Image
Cryptography gives us powerful and yet fragile information security controls.  Strong confidentiality and authentication mechanisms are wonderful provided they are well designed, implemented, used, managed and maintained … but cryptographic controls have a nasty tendency of failing open, sometimes becoming spectacularly insecure - which is just one of the information risks associated with cryptography.  Since this is ‘only’ a security awareness module, we’ve avoided delving into the advanced mathematics that underpins cryptography, while at the same time giving enough information for the module to be both interesting and actionable. Cryptography is a complex, technical topic, for sure, but that's no reason for the awareness program to ignore it and hope for the best! Even if you have the expertise and interest to research and prepare your own awareness materials, wouldn't you rather spend your valuable time interacting with your colleagues, spreading the word about information...

Malware awareness update 2016

Image
Despite thinking that it would be relatively straightforward to update last year’s malware awareness module for 2016, when we did the research it turned out that the malware situation has taken a turn for the worse since last March, so we ended up writing a slew of brand new content.  Just to whet your appetite ... l ast year we raised concerns about bank Trojans. Bank Trojans definitely haven't gone away, unfortunately, but ransomware has (arguably) become an even more significant threat today.  It's not a good sign when the authorities admit defeat, advising " Just pay the ransom ". Other  emerging trends in the shady world of malware covered in the new security awareness module include: Multifunctional malware  that is remotely controlled, remotely updated, remotely targeted, and (through encryption and obfuscation) more variable than earlier generations. This stuff is  hard  to identify, block and control, a tough challenge even for the very best antivi...

On cryptography

Image
On Cryptography The focus on key length obscures the failures of cryptography Mar 21, 2013 | 07:39 AM |  No comment By  Gary Hinson   Light Reading   Should companies continue sinking yet more money into cryptography? It's a contentious topic , with respected experts on  both   sides  of the debate. I personally believe that cryptography is generally a waste of time and that the money can be spent better elsewhere. Moreover, I believe that our industry's obsessive fascination with crypto serves to obscure greater failings in security design. In order to understand my argument, it's useful to look at cryptography's successes and failures. One area where crypto doesn't work very well is health. We are forever trying to secure health records using encryption.  We apply the very finest mathematical and statistical trickery known to Man to scramble them beyond comprehension.  But then medics go and decrypt them in order to use them, call...