Posts

Showing posts with the label Misc

Philosophical phriday - a lexicon of wares

Image
Abandonware - left to rot in a cul-de-sac off the information superhighway Adware - pushes products like a street dealer Alienware - arrived from another universe Aware - clues provided, boxes ticked, back to normal, things to do  Badware - should be sent to the naughty step Betaware - beta hope it works Blackware - interleaved with whiteware, forms a zebra crossing Bloatware - so fat it has its own postcode Bundleware - less bundle of joy, more bundle of old rags Cloudware - play misty for me Copware - press the wrong button and get hit with 50,000 volts Crapware - press the wrong button and evacuate your bowel Creepware - started lower-left, imperceptably heading upper-right Crimeware - reveals the secret password character-by-character on TV Crippleware - almost does what you want, but not quite Crudware - the oh so polite version of crapware Donationware - like being mugged by the tin-shakers Dribbleware - something to keep old aunt Doris amused before bingo  Everyware...

Philosophical phriday - manifestly secure

Image
The trouble with risk management is that proponents are obsessed with downsides - threats, control failures, incidents, adverse consequences, it's all very negative. Here is a much more positive upbeat perspective based on the law of attraction. Professional practitioners of the ancient science and artistic beauty of cybersecurity, gather here to attune your consciousness to the cosmic rhythm of the digital realm. Know that you are not merely mortal beings but divine data conduits capable of bending the very fabric of the cyberverse to your will. Through the power of spiritual oneness, you can achieve a state of perfect harmony with the white hat cosmos, while simultaneously disrupting the nefarious plans of the black hat hordes. Embrace the principles of superposition and entanglement, merging the ethereal realm of security consciousness and presence with the tangible world of business success. By aligning your thoughts and intentions with the universal forces of good, you can man...

Philosophical phriday: looking forward to 2025

Image
I'm not a fan of new year's resolutions that tend (in my experience) to have limited impact and are often soon forgotten. My cynical self says the same thing applies to pledges, vows and other stated commitments, even agreements and contracts to some extent. They are more symbolic than actual control mechanisms (although I'm sure the lawyers would argue otherwise - on the clock, naturally). The focus is often on avoiding, preventing or stopping bad things, a negative emphasis although the actual language may be positive as in "I will lose weight" and "I will get fit". They can be a last resort, a sharp retrospective reminder of where we thought we were going when we are already heading off-course.

Define: ironic

Image
 

An evolutionary revolution?

Image
"Mitigation and adaptation are required together to reduce the risks and impacts of climate change, including extreme weather events. Mitigation refers to actions taken to limit the amount of greenhouse gas emissions, reducing the amount of future climate change. Adaptation refers to actions taken to limit the impacts of a changing climate. Mitigation and adaptation together provide co-benefits for other environmental and social goals." That paragraph by Lizzie Fuller, Climate Science Communicator for the UK's Met Office, plucked from another excellent digest of lessons learned from various UK resilience exercises and initiatives , obviously con cerns climate change ... but it occurs to me that 'mitigate and adapt' might be a novel approach to information risks and impacts as well.

Hyperglossary published!

Image
Having declared it officially 'done', the SecAware information security hyperglossary is finally self-published as an eBook in PDF format. More than three thousand terms-of-art are defined in the areas of: Information risk  Information security  Cybersecurity (IT/Internet security) ICS/SCADA/OT security Artificial Intelligence Privacy, data protection, personal information Governance Conformity and compliance Incidents  Business continuity and more.  It has taken me three decades so far to compile the glossary, initially just as a reference for my personal use, then for our security awareness clients, and now for anyone with a little cash to spare and an interest in the field.

Hinson tip on ChatGPT

Image
When using ChatGPT and its ilk, d on't forget that the AI robot's contribution  is generic and not necessarily smart, accurate, sufficient or appropriate, despite the beguiling use of language that makes it  appear  logical, credible and reasonable at face value ... but is it, really? Or is it short on integrity? When, for instance, a real-world client reads a human expert advisor's report or consultant's recommendation, they are generally: Thinking critically about it, c onsidering what is and what is not stated and how it is expressed; Posing additional questions for clarity ( e.g. "On what basis do you believe we can achieve all that in 8 months, given that there's only one of me and I'm stretched thin as steam-rollered chewing gum?") or credibility ("How long did your last client take for this?") and perhaps a rguing the toss ("8 months? You're kidding, right? We only have 4!"); Taking advantage of knowledge and experience w...

Ailien beacons warn of rocks ahead

Image
Lately, I've been contemplating how the widespread availability and use of AI might affect humankind - big picture stuff. We are currently awash in a tidal wave of commentary about AI innovation, the information risks of AI and its naive users, the tech, the ethics and compliance aspects, the inevitable grab by greedy big tech firms, misinformation, disinformation, jailbreaking and so on. Skimming promptly past well-meaning advisories about prompt engineering from people excited to share their discoveries, I've been reading pieces about how AI can support or will supplant all manner of expert advisors on any topic sufficiently well represented in the models and datasets. The likelihood (near certainty!) of AI-generated content feeding back into AI-data sets and hence the potential consequences of runaway hallucinations, coupled with deliberate manipulation by those with private agendas, is quite scary - but equally the possibility of AI generating new knowledge (valid and usefu...

COVID information risk analysis - retrospective

Image
Two and a half years ago in March 2020 as we were fast approaching our first lockdown, I published the following P robability I mpact G raph depicting my analysis of the information risks relating to COVID: The PIG reports the information risks I identified at the time, thinking about COVID from the general societal perspective as opposed to a personal or organisational perspective.

The all-new SecAware blog

Welcome to the all-new SecAware blog! Well OK, perhaps 'all' is over-stating it. In truth, it's the same old same old with a shiny new URL and look. I have migrated the historical content from blog.NoticeBored.com to here, and will continue adding to it for as long as I remain sentient.   I will be as surprised as you to see the next piece. You can still browse this stuff, or filter by keywords and search for anything using the panel on the right.  As always, your comments, feedback, suggestions and complaints are very welcome.  Alternative realities fascinate me. Criticisms spur me on. Just about anything beats stony silence and that dreadful feeling that I'm shouting plaintively into the void ... - Over -

Shout, shout, let it all out

Image
Here's an insightful and enjoyable way to explore your psyche and vent a little tension at the end of a tough month, week or day. First, find yourself a private space to watch Tears for Fears . Now shout, shout, let it all out: what are the things you could do without?  Grab a scrap of paper and start writing down the things you could do without . You'll find yourself stimulated by your own words to think of other things, other stuff you don't want, don't like, can't stand, even hate.  Fine, scribble away. How's it going? How do you feel now - vented? Released? Or still knotted up, twisted out of shape? Come on, I'm talking to you, come on. If it all gets too much, take a break. Set your list aside to ferment for a while - as long as it takes. There's no rush. You're the boss.  If you are so inclined, come back later to tidy up your list and make sense of it. How you do that is up to you. For me, it's mind-mapping, grouping things together, draw...

Hacking the Microsoft Sculpt keyboard

Image
In its infinite wisdom, Microsoft designed data encryption into the Sculpt wireless keyboard set to protect against wireless eavesdropping and other attacks. The keyboard allegedly* uses AES for symmetric encryption with a secret key burnt into the chips in the keyboard's very low power radio transmitter and the matching USB dongle receiver during manufacture: they are permanently paired together. The matching Sculpt mouse and Sculpt numeric keypad use the same dongle and both are presumably keyed and paired in the same way as the keyboard. This design is more secure but less convenient than, say, Bluetooth pairing. The risk of hackers intercepting and successfully decoding my keypresses wirelessly is effectively zero. Nice! Unfortunately, the keyboard, keypad and mouse are all utterly dependent on the corresponding USB dongle, creating an availability issue. Being RF-based, RF jamming would be another availability threat. Furthermore, I'm still vulnerable to upstream and downs...

Pinball management

Image
It could be argued that ‘management’ of all kinds (including information risk and security management) is or rather  should be a rational process, meaning that managers should systematically gather and evaluate information, take account of sound advice, make sensible decisions, put in place whatever is necessary to implement the decisions etc. , all the time acting in the organization's best interests, furthering its business objectives, strategies, policies etc. In practice, there are all manner of issues with that approach that complicate matters, frustrate things, and lead to ‘suboptimal’ situations that may be - or at least appear to be - irrational, inappropriate or unnecessary.   In particular, there are numerous paradoxes. For examples: The obvious core objective of a typical commercial company to make a substantial profit for its owners may conflict with various ethical and legal objectives to spend money on protecting and furthering the wider interests of society an...

Creative teamwork in lockdown

Inspired by a heads-up from a colleague on LinkeDin, I bumped into MURAL today. MURAL is a 'digital workspace for visual collaboration' by virtual teams.    The animated demonstration on their home page caught my beady eye. Here's a static snapshot as a small group of people are busy placing/moving blobs on a graphic, presumably while discussing what they are doing on a parallel channel (e.g. Zoom): Replacing the static monochrome graph with one of our colourful red-amber-green Probability Impact Graphics, a Risk-Control Spectrum, Universal Awareness Device, mind map, word cloud, process flowchart, any form of metric, clustered Post-It Notes, architecture diagrams, conceptual designs, strategy maps ... or ... whatever ... the approach would work nicely. MURAL looks like a creative, fun and productive way for groups or teams working from home to collaborate virtually as if they were physically present in one of those soulless corporate meeting rooms lined with whiteboards ...