Thursday, April 8, 2010
iPad - A PC Buddy
I am looking at the iPad from a business perspective, somewhat similar to the iPhone: can/should a business look at adopting the iPad? What have I found to be effective in my normal day in life as a CEO?
Waiting for the 3G? You will have to buy another data plan; the sim card in the iPad is a micro version, smaller than your iPhone. I was hoping I could switch sim cards, when using the iPad and not iPhone.
Typing. Hmm, lots of people are giving the iPad a thumbs down on typing; however, I typed this blog on my iPad. One thing you definitely need if you are going to type is the iPad case, $39. The case fits your iPad very nicely, and has a flap that folds under it, positioning the iPad at a 30' position for your hands to type (it also doubles as a picture frame). You cannot rest your hands on the key pad, but it helps in typing still. If you have typed on your iPhone before, the iPad is 100 times better!!
Tablet? Nope. It's not even close. I have a colleague that has been using a tablet PC for years and we both agree, if you want a working tablet the iPad is not for you. Others are referring to the iPad as a tablet PC; this is definitely not the case. In fact, when you first get the iPad you have to connect it to iTunes; it cannot "be useful" by itself.
First, it needs a buddy to work; you have to connect it to your PC before you can start to use it.
Second, you cannot access file shares or network drives; the only way (besides e-Mail) to transfer files is through iTunes.
Third, for those looking for handwriting recognition, it's not included. There are some apps that claim to do it, but the reviews are pretty poor. Also, the iPad doesn't come with a stylus (of course) so writing with your finger is a little awkward.
Video out. I purchased the VGA adaptor for the iPad, and was disappointed in a few things.
First, the video out doesn't display your entire iPad; only certain apps were written to output to the VGA adaptor.
Second, when using an app that does display via the VGA adaptor, the screen goes black, therefore you cannot see what you are displaying. I am also an adjunct professor and this really sucks for interactive presentations. On the bright side there is a built in laser pointer; if you hold down your finger, a red dot appears--pretty cool.
Pages, Keynote, Numbers. These applications have been rewritten specifically for the iPad. I am impressed with the functionality of the applications. Clearly when I want to do some heavy lifting with numbers I use my PC with Excel. You don't have to buy these applications to view Word, Excel, PowerPoint or other formats, similar to your iPhone. However, they are necessary if you are going beyond reading a document. One downside to Pages is that you cannot access the menu screen in landscape mode (which is the default with using the case).
Goodbye, Kindles. I haven't read a newspaper in years. I don't watch the news, either (see the Yes book by Jeffrey Gitomer), so I was amazed when I downloaded the USA Today app and read the paper! It is really nice to read and very interactive. In fact, reading anything on the iPad is a dream. When reading legal contracts or SOW I would prefer to print rather than read on my PC screen. Not the case with the iPad.
IPad for Kids. I bought two iPads, in the hopes of giving one to my kids (twins), who are seven. They have iPhones and Macbook Pros, so another Apple gadget would be perfect for them. I let my son use my iPad; the first thing he did was to go visit Club Penguin. "Bummer," he said, "just like my iPhone, I cannot download this thing called Flash". I chuckled; yep, Apple is still trying to figure that one out. Unfortunately this excludes me from moving the kids to the closed architecture of the iPad, which would be easier for them to use and keep up to-date.
Misc. As an FYI you can use the power cord extender if you have other Apple products; you will definitely need this with the iPad. The iPad power requirements are much greater than the iPhone; therefore, it charges really slowly when connected to your PC. Also the standard iPhone charger for your car doesn't work either; not enough juice.
There are no USB ports on the iPad, which again limits the functionality and ability to do "other" things with it.
Apps. The iPad can use iPhone apps, but you will definitely want to use apps tailored specifically to the iPad.
Mail. I am using the iPad for email (Exchange), my University email (Gmail), Calendaring, and of course web browsing. The interface for the email is really nice. I like to position the iPad in the landscape mode (which is how the iPad case does also).
To wrap up, if you are looking for a companion for your PC or a buddy to carry around, then the iPad is for you. I have been carrying mine around, and it is nice to use as described above. Where I used to use my iPhone to browse and access email, I now use my iPad. You definitely will find the iPad next to me at home and work, and if it's not being used by me, someone almost always is touching it.
by Ken Stasiak, CEO, President and Founder, SecureState
Read more!
Monday, March 29, 2010
The Prospect Theory Problem
Whether we realize it or not, we information security consultants frequently find ourselves outside the world of simple business logic and standard economics and more a part of the mysterious realm of game theory, prospect theory and probability transformations.
Let me explain.
In 1738, a Swiss mathematician named Daniel Bernoulli wrote a paper entitled Exposition of a New Theory on the Measurement of Risk, which introduced a new idea. The Idea was that economic risk is relative based on the perceived utility of the money by its recipient. In other words, an amount of money has less value to an already wealthy person than it has to a poor person. Using a mathematical function, Bernoulli theorized, one could correct the expected value based on variables like risk aversion, risk premium, payout level, etc. Bernoulli's paper was the first formalization of “marginal utility”, which was widely accepted and continues to have broad application in economics even today.
A couple hundred years later in 1979, two psychologists named Daniel Kahneman and Amos Tversky began expanding on the idea of Marginal Utility theory by conducting a series of experiments in Israel, the University of Stockholm and the University of Michigan on how the prospect of gaining versus losing money affected intrinsic risk calculation. It was from these experiments that “Prospect Theory” developed. Prospect Theory differs from Marginal Utility theory in a number of important respects.
First, it replaces the notion of “utility” with “value.” Whereas utility is usually defined only in terms of net wealth, value is defined in terms of gains and losses (deviations from a reference point). Moreover, they found that the value function for losses is significantly different than the value function for gains. In short, the loss of $X is always felt more than the gain of $X.
Kahnemann and Tversky came to their conclusions through uncovering an interesting and shockingly consistent pattern that they referred to as the reflection effect.
In a nutshell, here’s what they did: Test subjects were offered two choices, the first involving a potential loss, and the second, a potential gain.
Scenario One- The test subject was asked to pick between:
Option A: A 100% chance of losing $3000 or
Option B: An 80% chance of losing $4000, and a 20% chance of losing nothing.
Scenario Two - Next, choose between:
Option C: A 100% chance of receiving $3000 or
Option D: An 80% chance of receiving $4000, and a 20% chance of receiving nothing.
What the study showed was that 92% of the subjects chose option B in the first scenario, while only 20% chose option D, the seemingly equivalent choice, in the second scenario. They found that a similar pattern held regardless of positive and negative prizes, and probabilities. This led Kahnemann and Tversky to conclude that when decision problems involve not just possible gains, but also possible losses, people's preferences over negative prospects are more often than not the inverse of their preferences over positive prospects. Simply put – human beings are risk-averse when it comes to potential gains, but for some reason we become risk loving when faced with scenarios involving potential losses. Daniel Bernoulli didn’t account for that back in the 16th century.
The challenge for the information security professional is how to manage the Prospect Theory problem of an organization (or decision maker within the organization) that is normally fiscally cautious, becoming risk loving when discussing the potential impact of security failures. To some degree, regulatory compliance has forced large portions of the private sector to invest in risk management and mitigation activities whether they like it or not. However, there are still many organizations that require convincing, and Prospect Theory tells us that selling the idea of risk aversion in a loss-focused scenario will not be easy.
One way to approach this problem is through the pseudocertainty effect. The pseudocertainty effect demonstrates that people’s choices can be easily affected by simply reframing the descriptions of the outcomes without changing the actual utility or any of the facts. In other words, we transform what appears to be a potential loss into a potential gain. For example, ask yourself the following question:
Scenario One:
An epidemic breaks out that is likely to kill 600 people if left untreated.
Treatment strategy A: will save 200 people.
Treatment strategy B: has 1/3 chance of saving 600 people and 2/3 chance of saving nobody.
Which approach would you choose?
Scenario Two:
An epidemic breaks out that is likely to kill 600 people if left untreated.
Treatment strategy C: 400 people will die.
Treatment strategy D: there is a 1/3 probability that nobody will die, and a 2/3 probability that 600 people will die.
Which approach would you choose?
If you’re like most people, you recommended Treatment Strategy A in the first scenario. Most people (almost 3/4) prefer the definite positive outcome of saving 200 people, to the conditional but larger positive outcome of saving 600 people.
However, in the second scenario the same number of people choose Treatment Strategy D and are willing to accept the risk of a larger negative outcome (600 people dying) to have a chance of averting an otherwise definite negative outcome (400 people dying).
The fascinating thing about the two scenarios and the treatment options presented above is that the information in both of them is identical in every way. Treatment A is the same as Treatment C, and Treatment B is the same as Treatment D with no variation. The only difference is in the presentation, the wording. Everything else is identical and yet respondents consistently reach opposing conclusions for each scenario.
What this tells us is that we can lead our risk loving clients through important decisions about risk by framing the outcomes in a way that will satisfy their sense of value, and in turn, convert the risk-loving into the risk-averse; which is what good security management is all about. By understanding the client’s mindset, and framing our solution appropriately using Prospect Theory, we can increase the perceived value of information security services exponentially… even if the client didn’t realize we did it.
By Charles P. Braman, VP of Consulting
Read more!
Friday, March 19, 2010
Law and Disorder
Part of the problem lies in the adage that "Nobody does security unless they have to." Translated, it means most organizations won't have a decent security program unless they get hit with compliance issues or a breach. What's that, you ask? “Aren't these firms subject to compliance?” I'm glad you asked that! These groups have a tendency to slip under the radar with a somewhat 'holier than thou' attitude. For example, let's look at the FTC Red Flags Rule to protect against ID theft. It's supposed to apply to companies that extend credit to persons or corporations, although the term 'creditor' is very broad in scope. When the American Bar Association realized it applied to them, they responded by suing the FTC and were granted exemption. They did the same thing when the Gramm-Leach-Bliley Act (GLBA) was passed for financial institutions and applied to lawyers who did financial planning. About the same time, the American Institute of CPAs also petitioned for Red Flag exemption. They have lobbied for exemption from the Consumer Financial Protection Agency Act of 2009 as well.
Of course, there are problems with the 'it’s not my problem' approach and we really need to read between the lines here a bit. If you look at something as basic as the FTC Red Flags Rule, it really isn't asking for all that difficult of a program - basic security, privacy, and notification. It's not like they are being asked to be ISO 27001 or PCI compliant. So why did the ABA and AICPA push back so hard? They both claim that due to the nature of their business, ID theft is very low risk. Of course, I believe they would not have pushed back if they had enough of a security program to meet the Red Flags Rule. Therefore, I'd bet most of them don't have one. They also said these things could be cost prohibitive to small CPA firms. But when it came time for an exemption to SOX 404(b) for small businesses that the CPA firms assess, the Center for Audit Quality, associated with the AICPA, fought it because that might hurt the investors that are supposed to be protected. So are we supposed to conclude they want to help the investor, but not the consumer?
Today, however, these firms are running of out wiggle room. There is an onslaught of compliance that sooner or later will be inevitable. For example, with the HITECH Act in ARRA, firms now realize they are pretty much stuck with HIPAA compliance if they handle PHI from a client as a Business Associate. They also realize that private standards, like PCI, that are enforced through contract now are unavoidable. Additionally, if firms have clients in states like Massachusetts and Nevada which have new trends in breach laws that include prevention, and not just notification, they likely are subject.
Of course, some of these compliances allow for risk-based decisions in which the firms may decide , like they did with Red Flag, that they think the organization still is low risk. I suppose it just will take some breaches to create a more sobering atmosphere. There is almost no industry that can really afford to adopt the 'it would never happen here' mentality, as we see breaches aren't just focused on financial institutions. Don't forget that the bad guys are both highly organized as well as lazy. If they recognize that there are 'soft spots' here, it could lead to some serious concentration of efforts on these gold mines of sensitive information.
The point is not to say that all law and CPA firms are ignorant of security risks and ripe for a breach. It's more to state that there is a general attitude problem that needs a big reality check. Eventually, these organizations need to increase their security posture and incorporate assessments for quality management. The early adopters will reap the benefits of understanding their risks sooner so they can minimize their risks earlier, or have more time to do so before being confronted with compliance deadlines.
Read more!
Tuesday, March 16, 2010
Changing the Landscape of Pentesting
Many pentesters don’t see an unencrypted service enabled on a firewall which protects an organization’s PCI zone and wonder “why” this service is allowed but rather how I can use this service to break into this system. The recommendation for such vulnerability would be to use a more secure service; however, what is lost is “why” the vulnerability occurred in the first place and the impact to the business if such vulnerability was exploited especially with regard to the environment in which it was discovered. A penetration assessment needs to be just as much interview based (if not more) as it does technical. Without understanding the underlying reasons as to why such vulnerabilities occurred in the first place, it is impossible to provide any other recommendations other than tactical to the client. The client will then tactically remediate the vulnerability maybe by updating a system with a specific patch or shutting down a specific service and then a year later vulnerabilities of a similar nature will resurface. Why? Because the underlying reasons as to why such vulnerabilities occurred in the first place are unknown. Is it a patch management problem? Is it a change management problem? Are there no policies and procedures or minimum security baselines preventing such vulnerabilities? Is it a management problem? Is it a line-of-business problem? Is it a combination of the above? The list goes on and on, but without trying to understand the “why” it is impossible to truly help the client. It is no longer acceptable to report that the entire compromise of an organization’s Windows domain was obtained without at least attempting to
understand “why” it was possible and how to protect against future occurrences.
Today’s market has become so diluted with companies and individuals claiming they can perform penetration assessments (if you don’t believe me attend Defcon one year). Organizations need to have a better understanding as to how these hired service providers are actually performing these assessments. If a company performs security assessments with little or no interaction with their client, be very skeptical of using this company. As the old cliche goes, you get what you pay for. Bottom line is, penetration testing is no longer for the geeky technical guy who only cares about breaking into systems or for someone who knows how to run a vulnerability scanner. It’s for professionals who truly understand security and are interested in really helping an organization reduce their overall risk.
Read more!
Friday, February 26, 2010
Periodic PCI Compliance Activities
Annually
3.6.4 Periodic cryptographic key changes:
- As deemed necessary and recommended by the associated application (for example, re-keying); preferably automatically
- At least annually
6.6 For public-facing web applications, address new threats and vulnerabilities on an ongoing basis and ensure these applications are protected against known attacks by either of the following methods:
- Reviewing public-facing web applications via manual or automated application vulnerability security assessment tools or methods, at least annually and after any changes.
- Installing a web-application firewall in front of public-facing web applications.
9.5 Store media back-ups in a secure location, preferably an off-site facility such as an alternate or backup site or a commercial storage facility. Review the location’s security at least annually.
9.9.1 Properly maintain inventory logs of all media and conduct media inventories at least annually.
11.3 Perform external and internal penetration testing at least once a year and after any significant infrastructure or application upgrade or modification.
12.1.2 Annual process that identifies threats, vulnerabilities, and results in a formal risk assessment.
12.1.3 Perform a Security Policy review at least once a year and update when the environment changes.
12.6.1 Educate employees upon hire and at least annually.
12.6.2 Require employees to acknowledge at least annually that they have read and understood the company’s security policy and procedures.
12.9.2 Test Incident Response Plan at least annually.
Bi-Annually
1.1.6 Review firewall and router rule sets at least every six months.
Quarterly
8.5.5 Remove/disable inactive user accounts at least every 90 days.
8.5.9 Change user passwords at least every 90 days.
9.1.1 Use video cameras or other access control mechanisms to monitor individual physical access to sensitive areas. Review collected data and correlate with other entries. Store for at least three months, unless otherwise restricted by law.
11.1 Test for the presence of wireless access points by using a wireless analyzer at least quarterly or deploy a wireless IDS/IPS to identify all wireless devices in use.
11.2 Run internal and external network vulnerability scans at least quarterly and after any significant change in the network (such as new system component installations, changes in network topology, firewall rule modifications, product upgrades).
Weekly
11.5 Deploy file integrity monitoring software to alert personnel to unauthorized modification of critical system files, configuration files or content files; and configure the software to perform critical file comparisons at least weekly.
Daily
10.6 Review logs for all system components at least daily. Log reviews must include those servers that perform security functions like intrusion detection system (IDS) and authentication, authorization, and accounting protocol (AAA) servers (for example, RADIUS).
12.2 Develop daily operational security procedures that are consistent with requirements in this specification (for example, user account maintenance procedures, and log review procedures).
Immediately
8.5.3 Set first-time passwords to a unique value for each user and change immediately after the first use.
8.5.4 Immediately revoke access for any terminated users.
12.3.9 Activation of remote-access technologies for vendors only when needed by vendors, with immediate deactivation after use.
Not specified, but suggest annually
12.8.4 Maintain a program to monitor service providers’ PCI DSS compliance status.
Read more!
Saturday, February 20, 2010
SSDs and Performance
Since my last SSD blog, prices have come down and larger drives have become available. I am in transition on my own laptop in running off a SSD with a secondary drive as a SATA disk, mainly for storage and running VMs (not counting the 1.5TB external USB drive I travel with). Also in that time frame I have transitioned to Windows 7, which, may I add, is a fantastic OS, probably the best OS Microsoft has ever released.
So, other than the fact that SSDs are more durable, faster, last longer, consume less power, and create less heat, there are a few things I didn't cover last time. We briefly touched on forensics analysis and how data is actually stored on SSDs, but we didn’t cover what operating systems (specifically Windows 7) are doing to take advantage of SSD technology. Seeing as how SSDs are falling in price (64GB SSDs are nearing $150, which is the size drive I am using), I feel more people will be moving to them, especially in high-end gaming rigs and laptop power users.
Why does the hard drive make such a difference? There are a variety of reasons, and they relate to both the OS and the hardware. We'll start with sequential read and write speeds. My game machine at home has 3 1TB SATA drives in it. Those drives can sustain about 100-120MB/s read speeds and 60-80MB/s write speeds. My SSD is rated at 270MB read/150MB write, which equals a big difference!
The other metric to keep in mind is the random speeds. Sure, when you're moving movies or ISO images or other large files, that’s sequential speed. But what about when your OS is writing a temp file, accessing the pagefile, or accessing data from your user folder? Those random reads depend greatly on access times. SSDs are now reaching blazing fast access times: well under 1ms in many cases (Intel's X25-M is reaching .01ms access times!). Sequential reads are hitting well over 250MB/s and write speeds are consistently over 100MB/s. Even on my old SATA disk, Windows was booting fairly quickly, getting to a login prompt in about 20 seconds. After making the switch to the SSD, my boot time is under 20 seconds, which includes the BIOS checks and logging in. Programs launch in ridiculously faster times, and everything is ultra snappy.
How are SSDs obtaining these speeds? As I talked about in my last blog, it’s because there are no moving parts. The data is stationary and the logic board just says, "Hey, data; come here, the CPU needs you." And off it goes, while with traditional platter drives, the logic board needs to move the read/write heads over a platter, find where bits are stored, and then transfer the data at the speed the platter spins. There's a lot of latency in that type of setup. In some cases, random read times are over 100 times faster at 4KB data chunks, which is what most Windows-based computer files are.
The next big thing is TRIM. To understand TRIM operations, you have to understand, at least a little of how SSDs really work. Last time we went over NAND and NOR memory types. Again, SSDs use NAND flash cell and are made up of millions of these memory cells. They are (in most cases) "clumped" together in 4kb chunks called pages. These pages are written to only at the size they are created, in this case 4kb. These pages can only be deleted or cleared at 128 pages at a time (which when you do the math is 512kb). The biggest issue that SSDs run into is that the drive never knows when a file on the system is deleted. So if you send an item to the recycle bin and then write another file over it, the drive will never know. So the SSD has to keep tabs on every memory cell it has. This is where the ATA-TRIM instruction comes into play.
The great thing about Windows 7 is that it supports TRIM instructions. TRIM instructions are simple. They tell the SSD that certain memory locations are empty so that the SSD doesn’t have to worry about keeping tabs on those locations until data is re-written there. SSDs track those memory locations by adding and dropping them from the Free Block Pool. Before TRIM support, performance degradation was a serious issue and many people were noticing SSDs degrade worse than traditional HDDs. Those were the days that Wipe and Reload would fix your problem. Now those problems are history... mostly. It's still an issue, but a MUCH smaller issue than the pre-TRIM days.
Now, with that understood, we can talk about Random Write times. Random writes are being done all the time on your system, and you've probably never noticed it. If you install an SSD in your system, you'll notice, as many people have, the big difference in speed. A big portion of that increase in speed is attributed to these Random Write times becoming so much faster. In the old mechanical drives there was a section of cache memory installed that ranged from 2-32MB of space. The new 2TB drives are shipping with 64MB of cache. This cache is used as a temporary holding spot, mainly for incoming data, so the drive controller could spin up the platters and move the read/write heads into position (an operation that could take between 5 and20ms). The drive will cache as much data as possible and send a success signal back to the OS so there is minimal interruption in the system.
With SSDs, this cacheing isn’t necessary. The memory pages are instantly available and writing of data takes micro-seconds instead of milli-seconds (ms). Remember what a page file is? It’s that huge 1-4GB file on your C: drive called "pagefile.sys." It looks like 1 file, but actually it contains small chunks of data the OS looks for instead of going to the system memory bus. Over 80% of the reads and writes to the pagefile consists of less than 20KB of data at a time. When Input/Output Operations Per Second (IOPS) are so much faster on SSDs than traditional HDDs, it’s no wonder OS speeds are so much snappier as well. Although I've heard people say not to use a page file when you have a ton of RAM in your machine, you should still use about a 1GB page file for programs that were written to use it.
One of the things Microsoft did to increase performance was decrease the amounts of random writes to disk. But what else can be done to help increase the performance of your SSD and help lengthen its life span? There's a lot actually. For starters, ensure that Disk Defragmenter is disabled. On old HDDs, everyone knew that when you defrag, your system seemed smoother. This is one of the worst things you can do to a SSD, so turn it off. Also, turn off Hibernation and System Restore. You should already have System Restore off; it’s a waste of space and a breeding ground for mal-ware. And if you've ever used Hibernation, you already know it stinks. Also, disable Superfetch and ReadyBoost. These technologies were built for performance increases when using mechanical HDDs and can pose performance issues to your new SSD. It is also recommended to disable Search Indexing in Windows.
Lastly, if you move to a SSD, I would recommend a few other things. The first should go without saying: install your OS from scratch. Don’t try using Partition Magic or some other HDD cloning software. Install a fresh OS, and, if you can, use 2 hard drives. Install your OS to your SSD and install ALL your aftermarket programs to your second drive. Your second drive, if it isn’t a SSD, should be a high RPM disk like a Western Digital VelociRaptor. This way you will keep all your documents and your User folder on your SSD, which are normally the smaller files SSDs fly with. You'll notice big increases in both speed and overall performance.
Read more!
Friday, February 12, 2010
Mitigating Visual Studio Application Manifest Information Disclosure in ClickOnce Deployments
Many would agree that information is an attacker’s best friend when attempting to profile a target and gain information to formulate a more targeted attack. Recently, I’ve come across several Microsoft ClickOnce applications that have leaked an internal domain and username by default. This blog will show you how to remediate the default information leakage.
When deploying Microsoft ClickOnce applications, the Publishing Wizard within Visual Studio creates an Application Manifest file with information about the installation. The file is XML based and has an extension of .application. By default, Visual Studio creates a temporary certificate to sign the ClickOnce manifests and results in a file with contents similar to the following:
If you look at line 8, you will notice that the publisherIdentity reveals the sensitive information (<internal domain name>\<username>).
First, we must generate a new certificate that does not contain sensitive information in it to sign our manifests. This can be done using the makecert.exe tool within the .NET SDK. Additionally, we will use pvk2pfx.exe for certificate conversion. These tools are normally installed in C:\Program Files\Microsoft SDKs\Windows\v6.0A\bin\. Of course, the Visual Studio directory may have a different version for your installation. Screenshots of the two tools follow:
First we generate a certificate and provide a private key password using the following command:
The result should say “Succeeded” after supplying the passwords. The result should be the creation of MyKey.pvk and MyKey.cer files in the current working directory.
Next, we use the following command and password from the previous step to generate a .pfx (Personal Information Exchange) certificate file:
This step will have created the file MyPFX.pfx in your current working directory. This file can now be used to sign your manifests. To do this, open your project in Visual Studio and view the properties of it by selecting “
From here, choose the “Signing” tab on the left side of the properties page to see something similar to the following (notice the sensitive information shown by default):
Choose the “Select from File…” button on the right, and browse to your newly created MyPFX.pfx file.
Type in the password, and your project should now show your newly created signing information similar to the following:
Save your project, click on the “Publish” tab, and publish using the “Publish Wizard…” or “Publish” buttons. By following the above steps using your own digital certificate, your ClickOnce installation will no longer leak sensitive information by default.
Read more!