It may be cliché but security is an ever-changing world. I am often asked how I keep up to date on the latest security trends and news in this rapidly changing world. The two primary tools I use to do this are security podcasts and Twitter. Being a consultant I spend a lot of time on the road and have long periods of free time while driving or flying to clients’ sites. While on the road, or during my daily commute, I fill those open hours by listening to podcasts. I am going to discuss the security podcasts I listen to, with a short description of each one. In a future post I’ll discuss how I use Twitter to keep in touch with the security community and stay on top of emerging trends.
ASIS Security Management Podcast is a monthly podcast containing highlights from the ASIS Security Management magazine. The magazine and podcast tend to be heavily focused on physical security, but there is some information security mixed in also. This is a great podcast if you want to learn more about physical security.
Crypto-Gram Security Podcast is simply Bruce Schneier’s monthly Crypto-Gram newsletter read aloud by Dan Henage. If you don’t have time to read the printed version of Crypto-Gram, this is a great way to keep up to date on a fascinating newsletter. If you haven’t read the Crypto-Gram newsletter you owe it to yourself to check out this podcast. I leave every podcast thinking about a security problem or issue in a new way.
CyberSpeak is a podcast focused on forensics. It is hosted by two formal federal agents who have spent their careers doing data forensics work. This show covers everything from basic to cutting edge forensic techniques. Whether you are a novice in forensics or an experienced forensics examiner, you will learn something from each episode.
Eurotrash Security Podcast comes to us from a band of security professionals and hackers based in Europe. This is one of the few podcasts that covers information security from a European point of view, so it is curious to see how security concerns over there line up and differ from the concerns in the States.
Exotic Liability Podcast is often offensive, usually informative, but always a fun time. This podcast is definitely not safe for work. So be careful where you listen to it. I recommend skipping this podcast if you are offended at obscene language and concepts. Topics usually focus on penetration testing and social engineering. The hosts also have some entertaining war stories about penetration testing.
OWASP Security Podcast focuses on all aspects of web application security. Many of the episodes are short interviews with experts in this field. This podcast is a wonderful way to learn about or keep on top of web application security topics.
Network Security Podcast is a weekly security news podcast covering new stories from the previous week. This show covers all aspects of security. The hosts comment on the news stories, often adding insight which makes the program well worth the listen.
PaulDotCom Security Weekly focuses on the technical side of security. Shows usually include a technical segment, new stories from the previous week, and interviews with special guests. If you want to learn more about the technical side of security this is a podcast you must check out. They also provide very detailed show notes which can be helpful when trying to implement an attack discussed on the show. An episode of PaulDotCom Security Weekly often is broken into two parts and the entire weekly show usually runs two to three hours. If I am running short on podcast time in a week, I also will use the show notes to determine what topics are of interest so I can fast forward to that portion of the podcast.
Risky Business is a news show which focuses on security from down under. The host of the show, Patrick Gray, does a very good job of explaining security concepts and concerns. Patrick also has a good handle on the importance of balancing security with business requirements, something many security folks forget. Because of these two factors, this is a great show for someone just getting into security.
SANS Audio Cast is a short weekly newscast produced by SANS. Episodes tend to be ten to fifteen minutes long so it is a great way to quickly catch up on the hot security news from the previous week. Even if I am running behind on podcasts, I try to listen to this one the week it is released while the information is still fresh.
SecuraBit Podcast is a security news podcast that focuses on technical security topics. I mainly listen to SecuraBit for the special guests they have, who tend to be big names in the security community.
Security Justice is hands down the best security podcast ever made. This monthly podcast covers a variety of security topics but tends to lean more toward physical security and the convergence of physical and logical security. This also is the only security podcast recorded live in a bar. Because this podcast is recorded in a bar, expect bar like language that may not be safe for work. Also in the interest of full disclosure, I should state the author of this post is also a co-host on this show so his views of the show are most likely biased.
Social Media Security Podcast focuses on the security concerns related to social media sites such as Facebook, Twitter, MySpace, and LinkedIn. The team that runs socialmediasecurity.com hosts the show. This podcast is a great way to learn about the threats in the emerging area of social media. The show also provides great case studies and stories that can be used for end user education and awareness training.
Social-Engineering.org Podcast is a monthly podcast focusing on social engineering. Produced by the team that run social-engineering.org, the podcast covers a number of topics related to social engineering. This podcast brings in some amazing guests. At first the guest’s or show topic’s relationship to social engineering might not be clear, but hang in there and the team always ties in how they relate. At its roots this podcast is about how to influence people, which is an important skill for any security professional to have. So even if you are not interested in social engineering, I still recommend you check out a few episodes of this podcast.
The Southern Fried Security Podcast looks at security from the CSO and management level, which is a welcome change from the often technical-heavy security podcasts. The podcast focuses on integrating security into a business and the importance of balancing the business needs with security. Most security professionals have a hard time achieving this balance, so do your self a favor and listen to at least a few episodes of this podcast.
If any of these podcasts sound interesting to you, I recommend you download a few episodes and give them a listen.
What security podcasts do you listen to? Any podcast you think I should start listening to? If so, tell me why in the comments.
Read more!
Friday, May 7, 2010
Thursday, April 29, 2010
"All Your 900 MHz Are Belong to Us"
If you were asked, “Does your organization use unencrypted wireless communications?”, what would your answer be? Responses may include ones such as “We don’t utilize wireless networks,” or “Our cell phones are our only wireless devices.” These answers may be somewhat true; however, many organizations may not have thought completely about their answer and assets. More specifically, the 900 MHz frequency range comes to mind. The 900 MHz frequency range is used by many common devices yet is often utilized in an unsecure manner for corporate use.
In short, the 900 MHz frequency range is an attacker’s playground. There is so much information that can be gleaned from playing in this space of which many folks are unaware. Two-way radios, simple wireless communication devices, and other items are more common than one might think that utilize this common and open communication channel. I’ll examine two cases in which SecureState engineers were able to obtain valuable information via trivial methods during both physical penetration tests and social engineering exercises.
First, SecureState was hired to perform work for a casino in the United States. Engineers were staying at a hotel approximately 3 or 4 miles away from the casino. From the hotel, a simple ham radio was used to listen to the 900 MHz frequency range and eavesdrop on the radio conversations of casino guards. From this, one could identify when guard shift changes occurred, when large sums of money were being transported, their origination, and destination as well. It doesn’t take a rocket scientist to explain why this is an issue. Other, more sophisticated attacks could be carried out using this information. With a sub $100 radio readily available at your neighborhood Radio Shack, the 900MHz frequency range may be capable of being used to listen in on your organization’s unencrypted communication.
Second, SecureState again fired up a ham radio to perform reconnaissance for a physical penetration test on a financial institution. Upon perusing the 900 MHz frequency range, it was identified that unencrypted wireless telephone headsets were being used in the helpdesk area. From this, SecureState was able to listen to password reset calls, and other issues being addressed at the target financial institution. There is no question why this is an issue, and this isn’t the end of it. Better yet, even after the phone call ends and the headset is put back in its cradle to charge when not in use, it acts as a bug in the office. The headset still transmits despite not being on a call. This means that all conversation in the helpdesk area, even while not on a telephone call, can be eavesdropped upon! Two solutions to this potential exposure are using the Plantronics CS55 and CS70 digital headset models. They both digitally encode and encrypt the audio and transmit it using TDMA technology. These headsets will provide sufficient protection against wireless headset eavesdropping. As best practice, it also is recommended that executives and executives’ assistants do not use wireless headsets for sensitive communications.
With those two simple case studies, it is clear that with less than $100 of readily accessible equipment, your organization may be vulnerable to such eavesdropping. Perhaps in your organization’s regular 802.11 wireless network enumeration looking for rogue access points, the 900 MHz frequency range should be included as well.
Read more!
In short, the 900 MHz frequency range is an attacker’s playground. There is so much information that can be gleaned from playing in this space of which many folks are unaware. Two-way radios, simple wireless communication devices, and other items are more common than one might think that utilize this common and open communication channel. I’ll examine two cases in which SecureState engineers were able to obtain valuable information via trivial methods during both physical penetration tests and social engineering exercises.
First, SecureState was hired to perform work for a casino in the United States. Engineers were staying at a hotel approximately 3 or 4 miles away from the casino. From the hotel, a simple ham radio was used to listen to the 900 MHz frequency range and eavesdrop on the radio conversations of casino guards. From this, one could identify when guard shift changes occurred, when large sums of money were being transported, their origination, and destination as well. It doesn’t take a rocket scientist to explain why this is an issue. Other, more sophisticated attacks could be carried out using this information. With a sub $100 radio readily available at your neighborhood Radio Shack, the 900MHz frequency range may be capable of being used to listen in on your organization’s unencrypted communication.
Second, SecureState again fired up a ham radio to perform reconnaissance for a physical penetration test on a financial institution. Upon perusing the 900 MHz frequency range, it was identified that unencrypted wireless telephone headsets were being used in the helpdesk area. From this, SecureState was able to listen to password reset calls, and other issues being addressed at the target financial institution. There is no question why this is an issue, and this isn’t the end of it. Better yet, even after the phone call ends and the headset is put back in its cradle to charge when not in use, it acts as a bug in the office. The headset still transmits despite not being on a call. This means that all conversation in the helpdesk area, even while not on a telephone call, can be eavesdropped upon! Two solutions to this potential exposure are using the Plantronics CS55 and CS70 digital headset models. They both digitally encode and encrypt the audio and transmit it using TDMA technology. These headsets will provide sufficient protection against wireless headset eavesdropping. As best practice, it also is recommended that executives and executives’ assistants do not use wireless headsets for sensitive communications.
With those two simple case studies, it is clear that with less than $100 of readily accessible equipment, your organization may be vulnerable to such eavesdropping. Perhaps in your organization’s regular 802.11 wireless network enumeration looking for rogue access points, the 900 MHz frequency range should be included as well.
Read more!
Labels:
900 MHz,
ham radio,
radios,
wireless,
wireless headsets
Wednesday, April 28, 2010
Trouble in the Cloud
Our development team initially started using Microsoft Azure as our primary platform for hosting our external website. We signed up as a Community Technology Preview (CTP) member to receive the "Introductory Special," which gave us access to the content delivery network at no additional charge. Microsoft Azure guarantees that at least 99.95% of the time you will have connectivity and 99.9% of the time they will successfully process, add, update, read, and delete requests. Unfortunately, we have experienced at least 5 outages during a 3 month duration that we had NO control over. Due to these outages and many other issues we had while hosting with Microsoft Azure, our development team has decided to move our application from Microsoft Azure.
Let's talk about data backups. Well, there is not much to say, because you cannot back up your database or any of the content that is hosted with Microsoft Azure; however, you can take "snapshots" of a particular item in each of the containers that exist. In order to do this, we used a windows based client called Cloud Storage Studio by Cerebrata to manage our content: http://www.cerebrata.com/Products/CloudStorageStudio/Default.aspx. This product alleviated some of the qualms that we had with Microsoft Azure. Another alternative to data backups was simply creating a local copy of our SQL database and using SQL Compare by Redgate to synchronize our local SQL database with the SQL Azure tables in the cloud: http://www.red-gate.com/products/SQL_Compare/index.htm.
Pricing is another area to watch out for when using Microsoft Azure. Microsoft may lure you in with their "Introductory Special" offering free services and no monthly commitment. We experienced a high volume of outgoing and incoming requests early on and noticed how quickly the fees accumulated. In fact, our Azure costs nearly tripled by our third month. For more information about how the storage, data transfers, compute times, and transactions are measured, please read the Microsoft Azure pricing guide: http://www.microsoft.com/windowsazure/pricing/.
Uploading updates to the cloud has been a very painful process. Every time we uploaded an update to Microsoft Azure, it took anywhere from 15-25 minutes to process an 8-10MB package. This means 15-25 minutes of down time for our live application! That is not even the most frustrating part. Cache is not king when it comes to updating content on Microsoft Azure. Microsoft Azure utilizes dozens of servers across the world so you can have faster access to stored content. Unfortunately, if your application is cached across even a few of those servers it takes about 48-72 hours for the servers to update the cache. The caching option can be turned off; however, disabling this option may result in the loss of performance when accessing content. We experienced many issues with a simple change to a graphic not being reflected on the live application. We had to suspend or restart our live application, resulting in a loss of 15-20 minutes, just to see the change.
Overall, Microsoft Azure does have its advantages over a single server hosting solution. For instance, Microsoft Azure or any other cloud computing alternative might be the preferred platform when hosting a global application which processes data intensive transactions requiring bandwidth and computing power because it is supported globally.
In my opinion, Microsoft Azure is unstable and could be improved with the development of options such as remote access to the SQL Azure tables and a more efficient way to release application updates with less down time. After some thought and discussion over weaknesses we encountered while hosting with Microsoft Azure, our team has decided to move our application from Microsoft Azure onto a more stable, cost-effective single server hosting environment.
Read more!
Let's talk about data backups. Well, there is not much to say, because you cannot back up your database or any of the content that is hosted with Microsoft Azure; however, you can take "snapshots" of a particular item in each of the containers that exist. In order to do this, we used a windows based client called Cloud Storage Studio by Cerebrata to manage our content: http://www.cerebrata.com/Products/CloudStorageStudio/Default.aspx. This product alleviated some of the qualms that we had with Microsoft Azure. Another alternative to data backups was simply creating a local copy of our SQL database and using SQL Compare by Redgate to synchronize our local SQL database with the SQL Azure tables in the cloud: http://www.red-gate.com/products/SQL_Compare/index.htm.
Pricing is another area to watch out for when using Microsoft Azure. Microsoft may lure you in with their "Introductory Special" offering free services and no monthly commitment. We experienced a high volume of outgoing and incoming requests early on and noticed how quickly the fees accumulated. In fact, our Azure costs nearly tripled by our third month. For more information about how the storage, data transfers, compute times, and transactions are measured, please read the Microsoft Azure pricing guide: http://www.microsoft.com/windowsazure/pricing/.
Uploading updates to the cloud has been a very painful process. Every time we uploaded an update to Microsoft Azure, it took anywhere from 15-25 minutes to process an 8-10MB package. This means 15-25 minutes of down time for our live application! That is not even the most frustrating part. Cache is not king when it comes to updating content on Microsoft Azure. Microsoft Azure utilizes dozens of servers across the world so you can have faster access to stored content. Unfortunately, if your application is cached across even a few of those servers it takes about 48-72 hours for the servers to update the cache. The caching option can be turned off; however, disabling this option may result in the loss of performance when accessing content. We experienced many issues with a simple change to a graphic not being reflected on the live application. We had to suspend or restart our live application, resulting in a loss of 15-20 minutes, just to see the change.
Overall, Microsoft Azure does have its advantages over a single server hosting solution. For instance, Microsoft Azure or any other cloud computing alternative might be the preferred platform when hosting a global application which processes data intensive transactions requiring bandwidth and computing power because it is supported globally.
In my opinion, Microsoft Azure is unstable and could be improved with the development of options such as remote access to the SQL Azure tables and a more efficient way to release application updates with less down time. After some thought and discussion over weaknesses we encountered while hosting with Microsoft Azure, our team has decided to move our application from Microsoft Azure onto a more stable, cost-effective single server hosting environment.
Read more!
Labels:
azure,
hosted services,
microsoft,
microsoft azure,
services,
windows azure
Wednesday, April 21, 2010
SSL Wars: A New Hope
A few months ago, I wrote a blog regarding some of the vulnerabilities I see in SSL implementations. In that blog I spoke about SSLv2 and Weak Encryption settings. The blog primarily addressed how these vulnerabilities could be used to compromise the confidentiality SSL can provide. Other than confidentiality, SSL also can be used to provide authentication, non-repudiation, and integrity.
Many of the vulnerabilities I encounter undermine the authentication that SSL provides. Examples of these vulnerabilities include X.509 MD5 Signature Collisions, Self Signed Certificates, and Subject Common Name does not Match FQDN vulnerabilities. In this blog I want to address the significance of the authentication SSL provides. Many times we take for granted the authentication portion of SSL, but in reality we use on a regular basis the authentication that SSL provides.
When you connect to a site like https://www.PayPal.com, how do you know that you are not actually connecting to an evil hacker’s website which they also named https://www.PayPal.com? How can you be sure that an attacker has not poisoned the DNS server that you use to look up the IP address associated with PayPal’s website and you have actually been redirected to a hacker’s site that looks like PayPal? How can you be sure that when you enter your username and password into this site that an attacker is not capturing your credentials and is planning on using them to compromise your PayPal account? In order to help address these issues, an Internet-based public key infrastructure (PKI) has been developed. SSL uses this infrastructure in order to help provide you with a level of protection.
A PKI incorporates public key encryption (also named asymmetric encryption). In public key encryption a device uses two keys in order to provide encryption. The first key is called the private key. This key the device keeps secret and does not disclose to the public. The second key is called the public key, which the device sends to anyone who wishes to communicate with the device over an encrypted channel. Information encrypted with the device’s public key can be decrypted only with the private key, and information encrypted with the device’s private key can be decrypted only with the public key. When client side software such as a web browser attempts to connect to a device using public key encryption such as a secure web server, the public key is used by the client side software in order to establish a secure connection.
In order to tie the identity of an organization with its public key, a public key certificate is created. This association is performed through something called a digital signature. The public key certificate basically says that the website https://www.test.com is owned by Test Corp. and is associated with the public key of 12345. A public key certificate can be self signed or endorsed by a third party. Self signed certificates basically say “I am Test Corp., I own https://www.test.com, and the public key of this website is 12345, because I said so.” The second way the public key can be associated with its identity is through endorsements. This is when a third party validates that a particular public key is associated with an identity. This can be explained as follows. In order to provide authentication, a website can send its public key certificate to a trusted Certificate Authority (CA) such as VeriSign. The CA verifies that the organization is who they claim to be (VeriSign basically asks to see the organization’s driver’s license). Once the CA has verified that the organization is who they claim to be, and they do own the website they are asking the CA to validate, the CA will sign the public key certificate of the website.
The most common place to find SSL being implemented is on the World Wide Web. Today’s web browsers (Such as Internet Explorer and Firefox) are given a list of trusted CAs. When the web browser connects to a web server, the web server will present the browser its public key certificate. The browser will check the certificate to see who the CA was who signed it. The browser will look through its list of trusted CAs to see if it trusts the organization who signed the server’s public key certificate. If the website’s public key certificate was signed by a CA that the browser trusts, then the browser shows the user the website without complaining to the user. The web browser will in most cases provide a pretty little lock icon to the user in order to show that the site is secure (Isn’t this nice of the web browser?). If the CA is not trusted by the browser, the browser will start shouting that it does not trust the site (This is accomplished through warning messages the browser shows the user).
Let’s use a real world Example of how SSL is used. A site like https://www.PayPal.com wants to prove to everyone that they are really owned by PayPal. In order to provide this proof, PayPal will contact a trusted CA like VeriSign and ask them to tell everyone that they are really owned by PayPal (Because everyone trusts VeriSign). VeriSign will work with PayPal in order to verify their identity (Basically VeriSign asks PayPal for their Driver’s License). Once VeriSign has verified PayPal’s identity and that they own https://www.PayPal.com, they will “sign” the websites public key certificate. This signature shows that VeriSign has verified the website’s identity.
Along comes a user named Joe. Joe wants to use his web browser in order to connect to PayPal in order to purchase a new video game (Notice that Joe is cool, because he is not purchasing stuff like clothes). In order to prove to Joe that https://www.PayPal.com is really who they claim to be, PayPal shows the browser its public key certificate. The browser checks to see the CA who signed the public key certificate and sees that it was signed by VeriSign. The browser looks through its list of trusted CAs and sees that VeriSign is a trusted CA. The web browser shows Joe PayPal’s website without showing any warnings. The web browser also shows the proverbial lock on the web browser which makes everyone feel warm and fuzzy. Isn’t this story wonderful? It has the makings of a wonderful movie . . . suspense, trust, and victory . . . but I digress.
Now let’s see what happens if an attacker makes a fake website named https://PayPal.com. An evil hacker named Franz (I think Franz is a good name for a hacker) wants to capture Joe’s PayPal credentials. In order to do this, the evil hacker creates a site named https://www.PayPal.com. Franz cannot contact a trusted CA to have them verify his identity, because he does not own the domain for PayPal (He does not have PayPal’s driver’s license). Instead, the hacker signs his own public key certificate. Franz signs the public key certificate for https://www.PayPal.com and essentially says “I am PayPal, I own https://www.PayPal.com, and my public key is 12345, because I said so.” Franz now redirects Joe’s browser to his site which is named https://www.PayPal.com. Joe’s web browser checks to see who signed the certificate of the website. The browser does not see the signer of the public key certificate on its list of trusted CAs. The web browser tells Joe that something is wrong with the website’s certificate. If Joe is smart, he will be alarmed by these error messages and will drop his connection with the website.
Researchers at Carnegie Mellon University found that the majority of users will ignore these SSL warnings and continue to the website anyway. This paper can be found at the following link: http://www.usenix.org/event/sec09/tech/full_papers/sunshine.pdf.
So, in conclusion, before you go clicking through those SSL warnings, I encourage you to take a second and really consider the risk involved in these actions. If you do not wish to share the information you are sending with the entire world, I would suggest not sending your information to sites with these SSL warnings. It is important that you actually trust the site that you are connecting to before you give your credentials, SSN, Credit Card, etc.
-Gary McCully
Read more!
Many of the vulnerabilities I encounter undermine the authentication that SSL provides. Examples of these vulnerabilities include X.509 MD5 Signature Collisions, Self Signed Certificates, and Subject Common Name does not Match FQDN vulnerabilities. In this blog I want to address the significance of the authentication SSL provides. Many times we take for granted the authentication portion of SSL, but in reality we use on a regular basis the authentication that SSL provides.
When you connect to a site like https://www.PayPal.com, how do you know that you are not actually connecting to an evil hacker’s website which they also named https://www.PayPal.com? How can you be sure that an attacker has not poisoned the DNS server that you use to look up the IP address associated with PayPal’s website and you have actually been redirected to a hacker’s site that looks like PayPal? How can you be sure that when you enter your username and password into this site that an attacker is not capturing your credentials and is planning on using them to compromise your PayPal account? In order to help address these issues, an Internet-based public key infrastructure (PKI) has been developed. SSL uses this infrastructure in order to help provide you with a level of protection.
A PKI incorporates public key encryption (also named asymmetric encryption). In public key encryption a device uses two keys in order to provide encryption. The first key is called the private key. This key the device keeps secret and does not disclose to the public. The second key is called the public key, which the device sends to anyone who wishes to communicate with the device over an encrypted channel. Information encrypted with the device’s public key can be decrypted only with the private key, and information encrypted with the device’s private key can be decrypted only with the public key. When client side software such as a web browser attempts to connect to a device using public key encryption such as a secure web server, the public key is used by the client side software in order to establish a secure connection.
In order to tie the identity of an organization with its public key, a public key certificate is created. This association is performed through something called a digital signature. The public key certificate basically says that the website https://www.test.com is owned by Test Corp. and is associated with the public key of 12345. A public key certificate can be self signed or endorsed by a third party. Self signed certificates basically say “I am Test Corp., I own https://www.test.com, and the public key of this website is 12345, because I said so.” The second way the public key can be associated with its identity is through endorsements. This is when a third party validates that a particular public key is associated with an identity. This can be explained as follows. In order to provide authentication, a website can send its public key certificate to a trusted Certificate Authority (CA) such as VeriSign. The CA verifies that the organization is who they claim to be (VeriSign basically asks to see the organization’s driver’s license). Once the CA has verified that the organization is who they claim to be, and they do own the website they are asking the CA to validate, the CA will sign the public key certificate of the website.
The most common place to find SSL being implemented is on the World Wide Web. Today’s web browsers (Such as Internet Explorer and Firefox) are given a list of trusted CAs. When the web browser connects to a web server, the web server will present the browser its public key certificate. The browser will check the certificate to see who the CA was who signed it. The browser will look through its list of trusted CAs to see if it trusts the organization who signed the server’s public key certificate. If the website’s public key certificate was signed by a CA that the browser trusts, then the browser shows the user the website without complaining to the user. The web browser will in most cases provide a pretty little lock icon to the user in order to show that the site is secure (Isn’t this nice of the web browser?). If the CA is not trusted by the browser, the browser will start shouting that it does not trust the site (This is accomplished through warning messages the browser shows the user).
Let’s use a real world Example of how SSL is used. A site like https://www.PayPal.com wants to prove to everyone that they are really owned by PayPal. In order to provide this proof, PayPal will contact a trusted CA like VeriSign and ask them to tell everyone that they are really owned by PayPal (Because everyone trusts VeriSign). VeriSign will work with PayPal in order to verify their identity (Basically VeriSign asks PayPal for their Driver’s License). Once VeriSign has verified PayPal’s identity and that they own https://www.PayPal.com, they will “sign” the websites public key certificate. This signature shows that VeriSign has verified the website’s identity.
Along comes a user named Joe. Joe wants to use his web browser in order to connect to PayPal in order to purchase a new video game (Notice that Joe is cool, because he is not purchasing stuff like clothes). In order to prove to Joe that https://www.PayPal.com is really who they claim to be, PayPal shows the browser its public key certificate. The browser checks to see the CA who signed the public key certificate and sees that it was signed by VeriSign. The browser looks through its list of trusted CAs and sees that VeriSign is a trusted CA. The web browser shows Joe PayPal’s website without showing any warnings. The web browser also shows the proverbial lock on the web browser which makes everyone feel warm and fuzzy. Isn’t this story wonderful? It has the makings of a wonderful movie . . . suspense, trust, and victory . . . but I digress.
Now let’s see what happens if an attacker makes a fake website named https://PayPal.com. An evil hacker named Franz (I think Franz is a good name for a hacker) wants to capture Joe’s PayPal credentials. In order to do this, the evil hacker creates a site named https://www.PayPal.com. Franz cannot contact a trusted CA to have them verify his identity, because he does not own the domain for PayPal (He does not have PayPal’s driver’s license). Instead, the hacker signs his own public key certificate. Franz signs the public key certificate for https://www.PayPal.com and essentially says “I am PayPal, I own https://www.PayPal.com, and my public key is 12345, because I said so.” Franz now redirects Joe’s browser to his site which is named https://www.PayPal.com. Joe’s web browser checks to see who signed the certificate of the website. The browser does not see the signer of the public key certificate on its list of trusted CAs. The web browser tells Joe that something is wrong with the website’s certificate. If Joe is smart, he will be alarmed by these error messages and will drop his connection with the website.
Researchers at Carnegie Mellon University found that the majority of users will ignore these SSL warnings and continue to the website anyway. This paper can be found at the following link: http://www.usenix.org/event/sec09/tech/full_papers/sunshine.pdf.
So, in conclusion, before you go clicking through those SSL warnings, I encourage you to take a second and really consider the risk involved in these actions. If you do not wish to share the information you are sending with the entire world, I would suggest not sending your information to sites with these SSL warnings. It is important that you actually trust the site that you are connecting to before you give your credentials, SSN, Credit Card, etc.
-Gary McCully
Read more!
Monday, April 19, 2010
Brand Evolution
Evolution is key to survival in this business climate. That’s why SecureState has undergone a total rebranding effort and new website launch.
Overhauling your entire image is not necessary to rebrand. Simple tweaks to spruce up an image is often all that’s needed. And that’s what SecureState has done. There were already great ‘bones’ to the SecureState brand, so all we needed to do was freshen our image and allow our image to reflect the growth we’re experiencing. The changes have been integrated over a period of time and are now visible in every aspect of customer-facing material, from our Twitter page to client proposals and presentations to, of course, our brand new website, which has just been launched.
Speaking of our new website, be sure to check it out at www.securestate.com! A lot of hard work went in to ensure that our website is now in line with the image we wish to portray. Our website is also much more informative and user friendly, and showcases what’s best about our services and offerings.
One of the things you’ll probably immediately notice is that all of our rebranding has been incorporated throughout the website. We’ve also added a new Media Center–it’s a one-stop shop to find all of our new case studies, whitepapers, blog entries, events, social media outlets, and much more. Our homepage has been updated to allow easier access to our industry-specific service offerings and to highlight our client success stories, which scroll across the bottom.
The strength of our company is now better reflected in our brand. As SecureState continues to provide the best service possible, we’ll also continue to portray that in our identity.
Read more!
Overhauling your entire image is not necessary to rebrand. Simple tweaks to spruce up an image is often all that’s needed. And that’s what SecureState has done. There were already great ‘bones’ to the SecureState brand, so all we needed to do was freshen our image and allow our image to reflect the growth we’re experiencing. The changes have been integrated over a period of time and are now visible in every aspect of customer-facing material, from our Twitter page to client proposals and presentations to, of course, our brand new website, which has just been launched.
Speaking of our new website, be sure to check it out at www.securestate.com! A lot of hard work went in to ensure that our website is now in line with the image we wish to portray. Our website is also much more informative and user friendly, and showcases what’s best about our services and offerings.
One of the things you’ll probably immediately notice is that all of our rebranding has been incorporated throughout the website. We’ve also added a new Media Center–it’s a one-stop shop to find all of our new case studies, whitepapers, blog entries, events, social media outlets, and much more. Our homepage has been updated to allow easier access to our industry-specific service offerings and to highlight our client success stories, which scroll across the bottom.
The strength of our company is now better reflected in our brand. As SecureState continues to provide the best service possible, we’ll also continue to portray that in our identity.
Read more!
Thursday, April 8, 2010
iPad - A PC Buddy
So it's day four (4) with the new gadget and along with the countless others that have reviewed the iPad I figured I would make it one more.
I am looking at the iPad from a business perspective, somewhat similar to the iPhone: can/should a business look at adopting the iPad? What have I found to be effective in my normal day in life as a CEO?
Waiting for the 3G? You will have to buy another data plan; the sim card in the iPad is a micro version, smaller than your iPhone. I was hoping I could switch sim cards, when using the iPad and not iPhone.
Typing. Hmm, lots of people are giving the iPad a thumbs down on typing; however, I typed this blog on my iPad. One thing you definitely need if you are going to type is the iPad case, $39. The case fits your iPad very nicely, and has a flap that folds under it, positioning the iPad at a 30' position for your hands to type (it also doubles as a picture frame). You cannot rest your hands on the key pad, but it helps in typing still. If you have typed on your iPhone before, the iPad is 100 times better!!
Tablet? Nope. It's not even close. I have a colleague that has been using a tablet PC for years and we both agree, if you want a working tablet the iPad is not for you. Others are referring to the iPad as a tablet PC; this is definitely not the case. In fact, when you first get the iPad you have to connect it to iTunes; it cannot "be useful" by itself.
First, it needs a buddy to work; you have to connect it to your PC before you can start to use it.
Second, you cannot access file shares or network drives; the only way (besides e-Mail) to transfer files is through iTunes.
Third, for those looking for handwriting recognition, it's not included. There are some apps that claim to do it, but the reviews are pretty poor. Also, the iPad doesn't come with a stylus (of course) so writing with your finger is a little awkward.
Video out. I purchased the VGA adaptor for the iPad, and was disappointed in a few things.
First, the video out doesn't display your entire iPad; only certain apps were written to output to the VGA adaptor.
Second, when using an app that does display via the VGA adaptor, the screen goes black, therefore you cannot see what you are displaying. I am also an adjunct professor and this really sucks for interactive presentations. On the bright side there is a built in laser pointer; if you hold down your finger, a red dot appears--pretty cool.
Pages, Keynote, Numbers. These applications have been rewritten specifically for the iPad. I am impressed with the functionality of the applications. Clearly when I want to do some heavy lifting with numbers I use my PC with Excel. You don't have to buy these applications to view Word, Excel, PowerPoint or other formats, similar to your iPhone. However, they are necessary if you are going beyond reading a document. One downside to Pages is that you cannot access the menu screen in landscape mode (which is the default with using the case).
Goodbye, Kindles. I haven't read a newspaper in years. I don't watch the news, either (see the Yes book by Jeffrey Gitomer), so I was amazed when I downloaded the USA Today app and read the paper! It is really nice to read and very interactive. In fact, reading anything on the iPad is a dream. When reading legal contracts or SOW I would prefer to print rather than read on my PC screen. Not the case with the iPad.
IPad for Kids. I bought two iPads, in the hopes of giving one to my kids (twins), who are seven. They have iPhones and Macbook Pros, so another Apple gadget would be perfect for them. I let my son use my iPad; the first thing he did was to go visit Club Penguin. "Bummer," he said, "just like my iPhone, I cannot download this thing called Flash". I chuckled; yep, Apple is still trying to figure that one out. Unfortunately this excludes me from moving the kids to the closed architecture of the iPad, which would be easier for them to use and keep up to-date.
Misc. As an FYI you can use the power cord extender if you have other Apple products; you will definitely need this with the iPad. The iPad power requirements are much greater than the iPhone; therefore, it charges really slowly when connected to your PC. Also the standard iPhone charger for your car doesn't work either; not enough juice.
There are no USB ports on the iPad, which again limits the functionality and ability to do "other" things with it.
Apps. The iPad can use iPhone apps, but you will definitely want to use apps tailored specifically to the iPad.
Mail. I am using the iPad for email (Exchange), my University email (Gmail), Calendaring, and of course web browsing. The interface for the email is really nice. I like to position the iPad in the landscape mode (which is how the iPad case does also).
To wrap up, if you are looking for a companion for your PC or a buddy to carry around, then the iPad is for you. I have been carrying mine around, and it is nice to use as described above. Where I used to use my iPhone to browse and access email, I now use my iPad. You definitely will find the iPad next to me at home and work, and if it's not being used by me, someone almost always is touching it.
by Ken Stasiak, CEO, President and Founder, SecureState
Read more!
I am looking at the iPad from a business perspective, somewhat similar to the iPhone: can/should a business look at adopting the iPad? What have I found to be effective in my normal day in life as a CEO?
Waiting for the 3G? You will have to buy another data plan; the sim card in the iPad is a micro version, smaller than your iPhone. I was hoping I could switch sim cards, when using the iPad and not iPhone.
Typing. Hmm, lots of people are giving the iPad a thumbs down on typing; however, I typed this blog on my iPad. One thing you definitely need if you are going to type is the iPad case, $39. The case fits your iPad very nicely, and has a flap that folds under it, positioning the iPad at a 30' position for your hands to type (it also doubles as a picture frame). You cannot rest your hands on the key pad, but it helps in typing still. If you have typed on your iPhone before, the iPad is 100 times better!!
Tablet? Nope. It's not even close. I have a colleague that has been using a tablet PC for years and we both agree, if you want a working tablet the iPad is not for you. Others are referring to the iPad as a tablet PC; this is definitely not the case. In fact, when you first get the iPad you have to connect it to iTunes; it cannot "be useful" by itself.
First, it needs a buddy to work; you have to connect it to your PC before you can start to use it.
Second, you cannot access file shares or network drives; the only way (besides e-Mail) to transfer files is through iTunes.
Third, for those looking for handwriting recognition, it's not included. There are some apps that claim to do it, but the reviews are pretty poor. Also, the iPad doesn't come with a stylus (of course) so writing with your finger is a little awkward.
Video out. I purchased the VGA adaptor for the iPad, and was disappointed in a few things.
First, the video out doesn't display your entire iPad; only certain apps were written to output to the VGA adaptor.
Second, when using an app that does display via the VGA adaptor, the screen goes black, therefore you cannot see what you are displaying. I am also an adjunct professor and this really sucks for interactive presentations. On the bright side there is a built in laser pointer; if you hold down your finger, a red dot appears--pretty cool.
Pages, Keynote, Numbers. These applications have been rewritten specifically for the iPad. I am impressed with the functionality of the applications. Clearly when I want to do some heavy lifting with numbers I use my PC with Excel. You don't have to buy these applications to view Word, Excel, PowerPoint or other formats, similar to your iPhone. However, they are necessary if you are going beyond reading a document. One downside to Pages is that you cannot access the menu screen in landscape mode (which is the default with using the case).
Goodbye, Kindles. I haven't read a newspaper in years. I don't watch the news, either (see the Yes book by Jeffrey Gitomer), so I was amazed when I downloaded the USA Today app and read the paper! It is really nice to read and very interactive. In fact, reading anything on the iPad is a dream. When reading legal contracts or SOW I would prefer to print rather than read on my PC screen. Not the case with the iPad.
IPad for Kids. I bought two iPads, in the hopes of giving one to my kids (twins), who are seven. They have iPhones and Macbook Pros, so another Apple gadget would be perfect for them. I let my son use my iPad; the first thing he did was to go visit Club Penguin. "Bummer," he said, "just like my iPhone, I cannot download this thing called Flash". I chuckled; yep, Apple is still trying to figure that one out. Unfortunately this excludes me from moving the kids to the closed architecture of the iPad, which would be easier for them to use and keep up to-date.
Misc. As an FYI you can use the power cord extender if you have other Apple products; you will definitely need this with the iPad. The iPad power requirements are much greater than the iPhone; therefore, it charges really slowly when connected to your PC. Also the standard iPhone charger for your car doesn't work either; not enough juice.
There are no USB ports on the iPad, which again limits the functionality and ability to do "other" things with it.
Apps. The iPad can use iPhone apps, but you will definitely want to use apps tailored specifically to the iPad.
Mail. I am using the iPad for email (Exchange), my University email (Gmail), Calendaring, and of course web browsing. The interface for the email is really nice. I like to position the iPad in the landscape mode (which is how the iPad case does also).
To wrap up, if you are looking for a companion for your PC or a buddy to carry around, then the iPad is for you. I have been carrying mine around, and it is nice to use as described above. Where I used to use my iPhone to browse and access email, I now use my iPad. You definitely will find the iPad next to me at home and work, and if it's not being used by me, someone almost always is touching it.
by Ken Stasiak, CEO, President and Founder, SecureState
Read more!
Monday, March 29, 2010
The Prospect Theory Problem
At its essence, the decision to (or not to) implement information security policies or procedures is just a bet on odds. Anytime you risk anything of value on the outcome of something involving chance, you are gambling. No matter how you look at it, information security is, by definition, a gamble. This undeniable fact adds an interesting twist to the business decision-making process utilized by security decision makers when it comes to purchasing information security products and services.
Whether we realize it or not, we information security consultants frequently find ourselves outside the world of simple business logic and standard economics and more a part of the mysterious realm of game theory, prospect theory and probability transformations.
Let me explain.
In 1738, a Swiss mathematician named Daniel Bernoulli wrote a paper entitled Exposition of a New Theory on the Measurement of Risk, which introduced a new idea. The Idea was that economic risk is relative based on the perceived utility of the money by its recipient. In other words, an amount of money has less value to an already wealthy person than it has to a poor person. Using a mathematical function, Bernoulli theorized, one could correct the expected value based on variables like risk aversion, risk premium, payout level, etc. Bernoulli's paper was the first formalization of “marginal utility”, which was widely accepted and continues to have broad application in economics even today.
A couple hundred years later in 1979, two psychologists named Daniel Kahneman and Amos Tversky began expanding on the idea of Marginal Utility theory by conducting a series of experiments in Israel, the University of Stockholm and the University of Michigan on how the prospect of gaining versus losing money affected intrinsic risk calculation. It was from these experiments that “Prospect Theory” developed. Prospect Theory differs from Marginal Utility theory in a number of important respects.
First, it replaces the notion of “utility” with “value.” Whereas utility is usually defined only in terms of net wealth, value is defined in terms of gains and losses (deviations from a reference point). Moreover, they found that the value function for losses is significantly different than the value function for gains. In short, the loss of $X is always felt more than the gain of $X.
Kahnemann and Tversky came to their conclusions through uncovering an interesting and shockingly consistent pattern that they referred to as the reflection effect.
In a nutshell, here’s what they did: Test subjects were offered two choices, the first involving a potential loss, and the second, a potential gain.
Scenario One- The test subject was asked to pick between:
Option A: A 100% chance of losing $3000 or
Option B: An 80% chance of losing $4000, and a 20% chance of losing nothing.
Scenario Two - Next, choose between:
Option C: A 100% chance of receiving $3000 or
Option D: An 80% chance of receiving $4000, and a 20% chance of receiving nothing.
What the study showed was that 92% of the subjects chose option B in the first scenario, while only 20% chose option D, the seemingly equivalent choice, in the second scenario. They found that a similar pattern held regardless of positive and negative prizes, and probabilities. This led Kahnemann and Tversky to conclude that when decision problems involve not just possible gains, but also possible losses, people's preferences over negative prospects are more often than not the inverse of their preferences over positive prospects. Simply put – human beings are risk-averse when it comes to potential gains, but for some reason we become risk loving when faced with scenarios involving potential losses. Daniel Bernoulli didn’t account for that back in the 16th century.
The challenge for the information security professional is how to manage the Prospect Theory problem of an organization (or decision maker within the organization) that is normally fiscally cautious, becoming risk loving when discussing the potential impact of security failures. To some degree, regulatory compliance has forced large portions of the private sector to invest in risk management and mitigation activities whether they like it or not. However, there are still many organizations that require convincing, and Prospect Theory tells us that selling the idea of risk aversion in a loss-focused scenario will not be easy.
One way to approach this problem is through the pseudocertainty effect. The pseudocertainty effect demonstrates that people’s choices can be easily affected by simply reframing the descriptions of the outcomes without changing the actual utility or any of the facts. In other words, we transform what appears to be a potential loss into a potential gain. For example, ask yourself the following question:
Scenario One:
An epidemic breaks out that is likely to kill 600 people if left untreated.
Treatment strategy A: will save 200 people.
Treatment strategy B: has 1/3 chance of saving 600 people and 2/3 chance of saving nobody.
Which approach would you choose?
Scenario Two:
An epidemic breaks out that is likely to kill 600 people if left untreated.
Treatment strategy C: 400 people will die.
Treatment strategy D: there is a 1/3 probability that nobody will die, and a 2/3 probability that 600 people will die.
Which approach would you choose?
If you’re like most people, you recommended Treatment Strategy A in the first scenario. Most people (almost 3/4) prefer the definite positive outcome of saving 200 people, to the conditional but larger positive outcome of saving 600 people.
However, in the second scenario the same number of people choose Treatment Strategy D and are willing to accept the risk of a larger negative outcome (600 people dying) to have a chance of averting an otherwise definite negative outcome (400 people dying).
The fascinating thing about the two scenarios and the treatment options presented above is that the information in both of them is identical in every way. Treatment A is the same as Treatment C, and Treatment B is the same as Treatment D with no variation. The only difference is in the presentation, the wording. Everything else is identical and yet respondents consistently reach opposing conclusions for each scenario.
What this tells us is that we can lead our risk loving clients through important decisions about risk by framing the outcomes in a way that will satisfy their sense of value, and in turn, convert the risk-loving into the risk-averse; which is what good security management is all about. By understanding the client’s mindset, and framing our solution appropriately using Prospect Theory, we can increase the perceived value of information security services exponentially… even if the client didn’t realize we did it.
By Charles P. Braman, VP of Consulting
Read more!
Whether we realize it or not, we information security consultants frequently find ourselves outside the world of simple business logic and standard economics and more a part of the mysterious realm of game theory, prospect theory and probability transformations.
Let me explain.
In 1738, a Swiss mathematician named Daniel Bernoulli wrote a paper entitled Exposition of a New Theory on the Measurement of Risk, which introduced a new idea. The Idea was that economic risk is relative based on the perceived utility of the money by its recipient. In other words, an amount of money has less value to an already wealthy person than it has to a poor person. Using a mathematical function, Bernoulli theorized, one could correct the expected value based on variables like risk aversion, risk premium, payout level, etc. Bernoulli's paper was the first formalization of “marginal utility”, which was widely accepted and continues to have broad application in economics even today.
A couple hundred years later in 1979, two psychologists named Daniel Kahneman and Amos Tversky began expanding on the idea of Marginal Utility theory by conducting a series of experiments in Israel, the University of Stockholm and the University of Michigan on how the prospect of gaining versus losing money affected intrinsic risk calculation. It was from these experiments that “Prospect Theory” developed. Prospect Theory differs from Marginal Utility theory in a number of important respects.
First, it replaces the notion of “utility” with “value.” Whereas utility is usually defined only in terms of net wealth, value is defined in terms of gains and losses (deviations from a reference point). Moreover, they found that the value function for losses is significantly different than the value function for gains. In short, the loss of $X is always felt more than the gain of $X.
Kahnemann and Tversky came to their conclusions through uncovering an interesting and shockingly consistent pattern that they referred to as the reflection effect.
In a nutshell, here’s what they did: Test subjects were offered two choices, the first involving a potential loss, and the second, a potential gain.
Scenario One- The test subject was asked to pick between:
Option A: A 100% chance of losing $3000 or
Option B: An 80% chance of losing $4000, and a 20% chance of losing nothing.
Scenario Two - Next, choose between:
Option C: A 100% chance of receiving $3000 or
Option D: An 80% chance of receiving $4000, and a 20% chance of receiving nothing.
What the study showed was that 92% of the subjects chose option B in the first scenario, while only 20% chose option D, the seemingly equivalent choice, in the second scenario. They found that a similar pattern held regardless of positive and negative prizes, and probabilities. This led Kahnemann and Tversky to conclude that when decision problems involve not just possible gains, but also possible losses, people's preferences over negative prospects are more often than not the inverse of their preferences over positive prospects. Simply put – human beings are risk-averse when it comes to potential gains, but for some reason we become risk loving when faced with scenarios involving potential losses. Daniel Bernoulli didn’t account for that back in the 16th century.
The challenge for the information security professional is how to manage the Prospect Theory problem of an organization (or decision maker within the organization) that is normally fiscally cautious, becoming risk loving when discussing the potential impact of security failures. To some degree, regulatory compliance has forced large portions of the private sector to invest in risk management and mitigation activities whether they like it or not. However, there are still many organizations that require convincing, and Prospect Theory tells us that selling the idea of risk aversion in a loss-focused scenario will not be easy.
One way to approach this problem is through the pseudocertainty effect. The pseudocertainty effect demonstrates that people’s choices can be easily affected by simply reframing the descriptions of the outcomes without changing the actual utility or any of the facts. In other words, we transform what appears to be a potential loss into a potential gain. For example, ask yourself the following question:
Scenario One:
An epidemic breaks out that is likely to kill 600 people if left untreated.
Treatment strategy A: will save 200 people.
Treatment strategy B: has 1/3 chance of saving 600 people and 2/3 chance of saving nobody.
Which approach would you choose?
Scenario Two:
An epidemic breaks out that is likely to kill 600 people if left untreated.
Treatment strategy C: 400 people will die.
Treatment strategy D: there is a 1/3 probability that nobody will die, and a 2/3 probability that 600 people will die.
Which approach would you choose?
If you’re like most people, you recommended Treatment Strategy A in the first scenario. Most people (almost 3/4) prefer the definite positive outcome of saving 200 people, to the conditional but larger positive outcome of saving 600 people.
However, in the second scenario the same number of people choose Treatment Strategy D and are willing to accept the risk of a larger negative outcome (600 people dying) to have a chance of averting an otherwise definite negative outcome (400 people dying).
The fascinating thing about the two scenarios and the treatment options presented above is that the information in both of them is identical in every way. Treatment A is the same as Treatment C, and Treatment B is the same as Treatment D with no variation. The only difference is in the presentation, the wording. Everything else is identical and yet respondents consistently reach opposing conclusions for each scenario.
What this tells us is that we can lead our risk loving clients through important decisions about risk by framing the outcomes in a way that will satisfy their sense of value, and in turn, convert the risk-loving into the risk-averse; which is what good security management is all about. By understanding the client’s mindset, and framing our solution appropriately using Prospect Theory, we can increase the perceived value of information security services exponentially… even if the client didn’t realize we did it.
By Charles P. Braman, VP of Consulting
Read more!
Subscribe to:
Posts (Atom)