Posts

Showing posts with the label Social engineering

Phrilosophical phriday - phake news

Image
I understand that AI/LLMs suffer hallucinations, but this piece circulating on AP seems credible to me: "President Trump, known for his calm demeanor and measured responses, found himself in an unexpected situation. A-list celebrity, Greta Thunberg, known for her outspoken political activism and massive social media following, had chained herself to the White House gates. She demanded a meeting with the President to discuss climate change policy, refusing to leave until he agreed. This wasn't a typical publicity stunt from Thunberg although she was dressed somberly as usual. Her impassioned speech, live-streamed to millions, focused on the President's recent approval of an offshore drilling project. She argued it contradicted his campaign promises of prioritizing renewable energy. The situation placed President Trump in a delicate position. Ignoring Thunberg risked alienating young voters who saw her as a powerful voice for their generation. However, giving in to her deman...

Philosophical phriday - countering outrageous misinformation

Image
For decades, I have appreciated  Peter Sandman 's approach to outrage - the social phenomenon in which groups of people react strongly to some perceived threat, issue, concern or whatever, drawing-in other like-minded individuals via social media. The echo chamber (positive feedback loop) can rapidly escalate emotions to an unreasonable degree with a lack of reasoned, critical thinking - according to those allegedly responsible for the issue anyway.    In the case of, say, the placing of 5G cell towers in/near schools, the outraged can become furious that the risk (as they see it) is being 'callously ignored' by the equipment suppliers, site developers, authorities and scientists, and enraged that they are 'not being taken seriously'. From their perspective,  thanks to group think (social endorsement),  the  perceived   risks are portrayed and understood to be deadly serious .  Leaders within the outraged community gain notoriety, influence and p...

Define: ironic

Image
 

Checklust security

Image
" Seventy Questions to Assess Cybersecurity Risk on a Rapidly Changing Threat Landscape "  is an ISACA 'industry news' article by Patrick Barnett.  Whereas normally I give 'industry news' and checklists a wide berth, Patrick is (according to the article) highly qualified and experienced in the field, so I took  a closer look at this one. The prospect of condensing such a broad topic to a series of questions intrigued me. I'm not totally immune to the gleaming allure of well-conceived checklists. Patrick says: "There are 70 questions that can be asked to determine whether an enterprise has most defensive principles covered and has taken steps to reduce risk (and entropy) associated with cybersecurity. If you can answer “Yes” to the following 70 questions, then you have significantly reduced your cybersecurity risk. Even so, risk still exists, and entropy must be continuously monitored and mitigated. There is no specific number of layers that can remove...

Putting policies under pressure

Image
A note on LinkeDin led me to an intriguing scientific research study that tested the following five hypotheses: People who receive instructions via a written policy about rules will have better knowledge of these rules than those that do not.  People who receive a shorter form version of policy about the rules with less text will have better knowledge of the rules than those who receive a longer training form.  People who receive a written policy outlining the rules in a more vernacular and less legal technical language will have better knowledge of the rules than those presented with a more formal-legal-styled training text.  People with better knowledge of rules will also comply more with such rules. The more legal rules align with people’s personal and social norms, the higher people score in their knowledge of these legal rules.  

Ten tips on tackling a thorny infosec issue

Image
A member approached the  ISO27k Forum   this morning for advice: " What would you recommend to do if our warnings as ISMS department specialists/auditors are not taken into account?" What can realistically be done if  management isn't paying sufficient attention to information risks that we believe are significant ?  This is a thorny issue and not an uncommon challenge, particularly among relatively inexperienced or naïve but eager information risk and security professionals, fresh out of college and still studying hard for their credentials. It can also afflict the greybeards among us: our passion for knocking down information risks can overtake our abilities to convince managers and clients. Here are ten possible responses to consider: 

Google customers phishing

Image
We're seeing a steady stream of 'update your email'-type crude phishers along these lines: I have lightly redacted the URL, but those action buttons are clearly not  pointing to an IsecT domain.   Firebase Storage is a Google cloud storage/app service: Google promotes Firebase security in terms of high availability and authentication for their customers i.e. web developers using Firebase to host content on the web. No mention of security for their customers' victims though and although Google can't be held entirely responsible for its customers' nefarious activities, I presume (hope!) they have the processes in place to identify and respond efficiently to incidents of this nature. I've reported this incident through a Firebase customer support channel as there is no obvious way for us to report misuse of their services by phishers etc. I'll let you know how they respond. PS  They didn't.  Harrumph.

Phishing evolution

Image
The Interweb drums have been beating out news of an upsurge in phishing attacks over the past month or so. I’ve certainly had more than the normal number of things along these lines lately:     As usual, these are relatively crude and (for most reasonably alert people) easy to spot thanks to the obvious spelling and grammatical errors, often using spurious technobabble and urgency as well as the fake branding and sender email address in an attempt to trick victims.   The ‘blocked emails’ and ‘storage limit’ memes are popular in my spam box right now, suggesting that these are basic phishing-as-a-service or phishing-kit products being used by idiots to lure, hook, land and gut other idiots.   They are, however, using my first name in place of “Dear subscriber” or “Hello, how are you doing?” that we used to see, implying the use of mailmerge-type content customisation with databases of email addresses and other info on potential victims*. Moving up the scale, some curr...

Adjusting to the new normal

Image
According to alert AA20-133A from US-CERT : "The U.S. Government has reported that the following vulnerabilities are being routinely exploited by sophisticated foreign cyber actors in 2020: Malicious cyber actors are increasingly targeting unpatched Virtual Private Network vulnerabilities. An arbitrary code execution vulnerability in Citrix VPN appliances, known as CVE-2019-19781, has been detected in exploits in the wild. An arbitrary file reading vulnerability in Pulse Secure VPN servers, known as CVE-2019-11510, continues to be an attractive target for malicious actors. March 2020 brought an abrupt shift to work-from-home that necessitated, for many organizations, rapid deployment of cloud collaboration services, such as Microsoft Office 365 (O365). Malicious cyber actors are targeting organizations whose hasty deployment of Microsoft O365 may have led to oversights in security configurations and vulnerable to attack. ...

March 20 - COVID-19 infosec awareness special

Image
Today I trawled through our back catalog of information security awareness content for anything pertinent to COVID-19. The "Off-site working" security awareness module published less than a year ago is right on the button.  "Off-site working" complements the "on-site working" awareness module, about the information risk and security aspects of working on corporate premises in conventional offices and similar workplaces. Off-site concerns the information risk and security aspects of working from home or on-the-road ( e.g. from hotels or customer premises), often using portable IT equipment and working independently ... which is exactly the situation many of us are in right now. Off-site working changes the information risks compared to working in purpose-built corporate offices. Mostly, the risks increase in line with the complexities of remote access, portability and physical dispersion … but offsetting that, off-site working can be convenient, productive...

March 6 - cry-ber-security

Image
◄ This amuses me - part of an advertisement by NZ farm supplies company FFM for their quad bike safety helmets ... but the principle applies equally to knowledge workers in any industry. We used a similar concept for one of our social engineering awareness posters, emphasising the manipulation rather than protection ► Earlier this week, Gelo asked on the ISO27k Forum: "Based on ISO 270001 definition of Information Processing Facilities, can we consider a person as such? Considering that a person can process and store information in his mind?" I replied: " Before electronic computers, “computers” were people who computed . So yes Gelo, we can. People generate, store, process, use and communicate information." That is my cue for yet another dig at the cybersecurity movement. Do humans even feature in the myopic tech-centric world of those self-anointed cybersecurity experts? Would hard hats, other Personal Protective Equipment and Health and Safety appear on their li...

Simplicity itself

Image
"Simplicity is the default unless there's a good business reason to do something else. What is typically lacking are the business reasons ..." That comment on CISSPforum set me pondering during this morning's caffeine fix. We've been chatting about some training webinar sessions recently promoted by (ISC) 2 . Some say they over-simplify information security to the point of trivialising and perhaps misleading people. If you follow this blog, you'll know that this month I have been slaving away on an awareness module covering malware, a topic we've covered many times before - particularly the avoidance or prevention of infections but this year a customer asked us for something on publicly disclosing incidents in progress, a disarmingly simple request that turned into a fascinating foray into the post-malware-infection incident management and resolution phase for a change. I've been exploring and writing about what does, could or should happen after malw...

Social engineering awareness module

Image
December 2019 sees the release of our 200 th  security awareness and training module, this one covering social engineering. The topic was planned to coincide with the end of year holiday period - peak hunting season for social engineers on the prowl, including those portly, bearded gentlemen in red suits, allegedly carrying sacks full of presents down chimneys.  Yeah right! I'm fascinated by the paradox at the heart of social engineering. Certain humans threaten our interests by exploiting or harming our information. They are the tricksters, scammers, con-artists and fraudsters who evade our beautiful technological and physical security controls, exploiting the vulnerable underbelly of information security: the people. At the same time, humans are intimately involved in protecting and legitimately exploiting information for beneficial purposes. We depend on our good people to protect us against the bad people. Vigilance is often the only remaining hurdle to be overcome, m...

Social engineering awareness

Image
The next awareness topic is one of our regular annual topics. Social engineering has been around for millennia - literally, in the sense that deliberate deception is a survival strategy adopted by many living beings, right back to primordial times. So, what shall we cover this time around?  last time, we took a deep dive into phishing, a modern-day scourge ... but definitely not the only form of social engineering, despite what those companies pushing their 'phishing solutions' would have us believe. We picked up on 'business email compromise' as well, another name for spear-phishing.  In 2017, we explored 'frauds and scams' in the broad, producing a set of 'scam buster' leaflets explaining common attacks in straightforward terms, illustrated with genuine examples and offering pragmatic advice to avoid falling victim to similar tricks. Back in 2016, the 'protecting people' module covered: s ocial engineering attacks, scams and frauds, such as phi...

Forensic mythbusters

Image
We're currently researching for a future awareness module on forensics - a topic that has absolutely fascinated me since I was a kid through to my 20s as a geneticist (a "DNA scientist"). Naturally, for security awareness purposes, we'll be focusing on the use of forensics within the context of information risk and security ... but forensic science is all about information, including its availability and integrity, so our brief might yet widen. Today I stumbled across  The Innocence Network , a growing global movement to re-investigate dubious convictions, exonerate wrongly convicted people and press for improvements to criminal justice systems as appropriate.  Wrongful convictions are a treble tragedy: An innocent person is punished for something they didn't do. This is unjust and harmful to the individual, plus their families and social networks. A guilty person often goes free. This typically flows from point 1. I say 'often' and 'typically' be...

Leaving a digital legacy

Image
Yesterday morning, I checked the ISO27k Forum messages as usual. Among the ping-pong of ongoing conversations was a sad request to stop emailing a Forum member who died just last week. His widow sent a few polite messages through his email account to the whole list, replying to an assortment of recent Forum emails. Presumably she didn't read or comprehend the 'unsubscribe' instructions from Google at the bottom of every message, and given the circumstances, it's entirely understandable - not least because I think she is Spanish, while the Forum and its instructions are in English. Unsubscribing someone from an email list is a simple example – something that’s easy for those of us who frequently use managed mailing lists (or groups or reflectors or Special Interest Groups or whatever they are called) but is not necessarily obvious to those who don’t, especially when they are in turmoil, grieving and overloaded with a million difficult tasks all at once. It’s an extraord...

Cyber-blinkers and cyber-bling

Image
Security Tip ST19-001 Best Practices for Securing Election Systems - an advisory from the US government - is fascinating for the things it leaves out, more than those few it includes. At least five substantial omissions occurred to me literally as I was skim-reading the piece for the very first time: Physical security for voting systems and associated paraphernalia; Application design of voting software; Social media and voter coercion (the elephant in the room); Information risk management - a systematic approach to identify, evaluate and address the information risks as a whole (not just a few items seemingly plucked out of thin air); Assurance - clearly a crucial concern for elections, underpinning the entire democratic process (a raging herd of angry elephants here!).  Items 3, 4 and 5 on my little list concern the bigger picture. It's pointless securing the computer systems alone, even if that could be achieved which would take a lot more than is implied by this astonishingly...

Proofreading vs reading vs studying

In the course of sorting out the license formalities for a new customer, it occurred to me that there are several different ways of reading stuff: Skimming or speed-reading barely gives your brain a chance to keep up with your eye as you quickly glance over or through something, getting the gist of it if you're lucky; Proof-reading involves more or less ignoring the content or meaning of a piece, concentrating mostly on the spelling, grammar etc. with a keen eye for misteaks, specificaly; Studying  is a more careful, thorough and in-depth process of reading and re-reading, contemplating the meaning, considering things and mulling-over the messages at various levels. In an academic setting, it involves considering the piece in relation to the broader field of study, taking account of concepts and considerations from other academics plus the reader's own experience that both support and counter the piece, the credibility of the author and his/her team and institution, the techn...