Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Unisys Security Index

Unisys have released their latest security index reports which also have a break out section for Australia. While this report covers far moer than InfoSec (it includes items such as terrorism/national defence, health and financial security) there are sections on Internet Security, shopping & banking online and computer security (viruses and spam).

From their summary:
  • Six out of 10 (58%) Australians never secure their mobiles, PDAs or smartphones by using, and regularly changing, a password or PIN. Only 18% say they always secured their mobile device
  • Young Australians are protecting their identities online by limiting the information they post on social networking sites with 70% of 18-34 year olds saying they do it always, compared with only 44% of those aged 50+
  • The top two areas of concern for Australians are ID theft related: Unauthorised access to/misuse of personal information (56%) and other people obtaining/using credit card/debit card details (55%)
Australians are ending the year more relaxed than they started. The overall level of concern on key security issues, tracked by the Unisys Security Index, stands at 115 out of 300, down 8 points compared to April 2010. This reflects a drop in concern for all four areas of security with the biggest fall recorded for national security which has an index of 110 down 11 points since April.

What's interesting is the state-by-state comparion, with people in WA, NSW and VIC more worried (+7%) about internet security than those in SA and QLD.


Those over in WA seemed to be the most worried overall, topping the lists for all four sections: national security, financial security, internet security and personal security.

"Scary Internet Stuff"

Symantec Education have posted some pretty good videos to help explain internet nasties to non-technical people:

#1 Phishing
#2 Botnets
#3 Cybercrime Underground
#4 Drive-By Downloads
#5 Misleading Applications
#6 Denial of Service Attacks
#7 Pests on your PC
#8 Losing your Data
#9 Net Threats

They're quick and easy to watch without being too heavy on the marketing.

Cloudy Weather

The Cloud. These days it seems all-encompassing and unescapable. Perhaps we should have called it 'fog computing' as it seems to have the ability to bamboozle and confuse non-techie types with promises of milk and honey for little or no effort. While it certainly has it's merits, a lack of true definition and standards show it's immaturity at present.

But even in world of magical clouds there's a darkside, for with a greater availability in cheap computing power comes the opportunity for shady-types or in this case, researchers, to use the 'power of the cloud' to crack WPA encryption. WPACracker allows you to run a 285 million word dictionary-based attack to crack WPA-PSK and ZIP file encryption. Purely for research purposes of course!

Using Clouds or 'cloud-like' constructs for crime is nothing new, shown by the prevelance of botnets such as the massive Conficker botnet (estimated at 10-15 million hosts) or the spam spewing Cutwail botnet that could blast out 74,000,000,000 spam messages a day (that's 51,000,000 a minute!).

While I'm on Cloud matters, I spotted a recent interesting little tidbit about personal cloud storage provider Evernote. It seems for their customers, security is an add-on extra that is only available to premium subscribers....

Apparently 'excellent security' means encrypting authentication information only with the remainder sent in the clear. Are we past the age of better security being basically a good idea or advertised as a lure for customers and it turning into a premium extra charge? I hope not.

(thanks for some of the info in the post above to a Circus contributor who must remain anonymous - you know who you are!)

National Cyber Security Awareness Week

It's National Cyber Security Awareness week this week (6–11 June)

From the website:
National Cyber Security Awareness Week is an annual initiative of the Australian Government held in partnership with industry, community and consumer groups and state and territory governments.

It is designed to raise awareness among Australians of cyber security risks and simple steps they can take to protect their personal and financial information online.

National Cyber Security Awareness Week 2010 is from 6 to 11 June. It will promote six easy tips for better online security:

1. Install security software and update it regularly.
2. Turn on automatic updates so that all your software receives the latest fixes.
3. Get a stronger password and change it at least twice a year.
4. Stop and think before you click on links or attachments.
5. Stop and think before you share any personal or financial information about yourself or your friends and family.
6. Know what your children are doing online. Make sure they know to stay safe and encourage them to report anything suspicious.

Security is hard right?

Security is hard right? It must be or everybody would be doing it right. OWASP have released their new Top 10 web vulnerabilites for 2010, which still contains 7 of the items in the top 10 from 2007 and 6 items from the 2004 top ten. Progress in educating developers and eliminating some of the biggest threats seems slow. I'm not sure why.

I (along fellow Security Circus poster Richard) recently spent a day working our way through some rather incomplete and arcane documentation from a large software vendor trying to determine how they required SSL to be implemented between both the seperate elements of their product and the endpoint clients.
Between poor documentation, requiring OpenSSL & Java KeyStore/keytool and the software not trusting common 3rd-party CAs (such as Verisign), it was a long and frustrating experience. And that was for two guys with a reasonable understanding of PKI. For a developer or sysadmin who was new to security or unsure about PKI in general it would have been a nightmare.

The knowledgebase for the product was not much better, leaving me with little doubt that while many people may understand the need for security, the 'how' can be sorely lacking - and is not helped when the software developer/vendor (or integrator) seems to have little grasp of security themselves - or a disinclination to explain the details to their customers.

It reminds me a little of a UNIX sysadmin I worked with many years ago, before I was full-time in IT, who was so secretive about the system and how it worked he had three assistants quit in 12 months out of frustration. Was it secretive paranoia or simply keeping the 'knowledge' to himself as a power trip? (personally I suspect the latter...)

While there are always elements of security and IT in general that require secrecy, the how is not one of them. Explaining how to implement security so even a home user (or my Mom!*) can easily understand it and follow the steps is a good thing.

*Actually my Mom isn't too bad with her PC!

Economics and Security

No this post isn't about the cost of security - at least not in direct dollars!

I've been meaning to make this post for a while. Recently I read a great paper from Microsoft Research titled So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users

Some of the points in this paper really hit home about challenging the common wisdom about why users reject or bypass security and the indirect cost to them for something from which they're unlikely to suffer.

Applying ecomomic ideas such as externialities to Information Security is not new, Bruce Schneier has commented on it in the past in regards to software development and it is also mentioned in a chapter in Beautiful Security (which I don't have handy to pull the reference from).
Despite the old gag definition of economics being "The science of explaining tomorrow why the predictions you made yesterday didn't come true today" it is sadly still a step up from much of the FUD, voodoo and magic numbers pulled out of the air by some IT and IT Security folk.
One of the great challenges is, as always, getting useful metrics...

Another major point in the Microsoft paper that really made me sit up and think was their assertation that "Thus, to a good approximation, 100% of certifi cate errors are false positives. Most users will come across certi ficate errors occasionally. Almost without exception they are the result of legitimate sites that have name mismatches, expired or self-signed certi cates."
Thinking back over many years of surfing the 'net, I had to agree. I couldn't think of a particular instance where I encountered an SSL certificate error that wasn't a false positive.
The bad guys don't use SSL certificates....why bother when you can fool end users by placing a padlock as a favicon or just using an image of a padlock next to the login box on your phishing site?
Developers of legitimate sites don't help the situation either, by mixing secure and nonsecure content on the same page that brings up warning dialog boxes. What's your average end user to do? Assume the legitimate page is bad and deny themselves access to a service, or click on and further reinforce the message that it's alright to click OK on those boxes that appear and nothing bad will happen.
I visited two websites recently, both owned by major IT companies, that had mixed their secure and nonsecure content in this manner.
What's the solution? SSL everywhere and browsers that won't allow non-SSL verified connections?

Training end users is hard. Bringing them onside as allies in your security efforts without overburdening them with externialities or overstating the actual likely harm by using worst-case harm (ie: introducing FUD) is even harder.

Download limits and Security

I saw a few articles recently (to which I would post a link, but I can't find them again...) about how download limits are bad for security. The basic point being made was that developers can't be trusted to deliver secure software, so a plethora of security updates is inevitable. For those people subject to download limits, they may (or probably would) choose to spend their precious download limits on things they perceive as far more valuable to themselves than a patch for Windows or Acrobat.

The sudden interest seems to have come on the back of US ISPs such as Time Warner Cable looking at charging customers by the byte which has led to a consumer advocacy group asking Congress to investigate whether charging by the byte is 'price gouging'.

While it may be new for the US, this type of download limitation and additional charges for exceeding set caps is nothing new here in Australia or many other parts of the world.

But how could this affect security?

I was told a story from a South African Microsoft employee about the way ISPs divided up download limits in the Republic. As far as I recall, there was basically a generous allowance for sites hosted within South Africa, and a much smaller allowance for sites based overseas. As Microsoft did not have a windows update server in South Africa, this led to people being unwilling to update windows and burn up their precious overseas download limit. A partial solution was another Microsoft employee set up a private WSUS server within South Africa and advised people to connect to his server to obtain the frequent updates.
While there are obvious potential security issues with that solution, it is perhaps the lesser of two evils compared to not patching at all.

But do 'regular' users really pay all that much attention to their download caps? All sorts of applications rely heavily on internet access to be able to download updates, from Windows and Adobe Acrobat to itunes and anti-virus products. Would someone really disable their AV updates to save download allowance?

Speaking to a few non-IT friends the prevailing opinion is it is not something they even think about, and I imagine that is the common view. I suspect it would take being heavily slugged with extra charges for exceeding your allowance before most people even think about their download limits - although I have heard of people using 3G tethered internet connections on global roaming being unhappily surprised with hugh bills for unknowingly downloading patches and updates automatically while travelling.

At this point it seems like much ado about nothing, and the introduction of download limits in the US will hardly lead to a new age of poorly secured unpatched systems. The bigger problem is the underlying operating systems and applications that are built with security as an afterthought (if it is thought of at all), the constant downloading of updates and patches is simply a symptom.