Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Friday, 29 November 2013

Cyber Broken Windows Theory

In 1982 a now famous paper by James Q. Wilson introduced the Broken Windows Theory.  Consider a building with a few broken windows.  If the windows are not repaired, the tendency is for vandals to break a few more windows.  Eventually, they may even break into the building, and if it's unoccupied, perhaps become squatters or light fires inside.

This theory has an uncanny parallel with current information security practices - poor security hygiene allows cyber-crime to flourish.  Consider a computer with a few unpatched vulnerabilities.  If the vulnerabilities are not patched, the tendency is for criminals to start exploiting them.  Eventually, they may even break into the computer, and if unprotected, perhaps add it to a botnet or just trash it.

By not patching our systems, we are not just victims of cybercrime, we are unwitting accomplices.

One unrepaired broken window is a signal that no one cares, and so is one unpatched computer.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com

 

Friday, 25 October 2013

Stone Aged Security

Humans have been stealing from each other since we first chose to pile rocks up in a cave.  The current media frenzy might make us think of cybercrime as a new issue, but it is really just the most recent incarnation of what is the probably the second oldest profession.

The same societies, defences, attacks and innovations that were created in the physical world have all been rediscovered and recreated in the online world.  No-one seems to have noticed this before now.

Stone Age Society (10,000 BC)

The stone age is generally considered to be the advent of agriculture at the end of the last ice age.  Before this everything was done manually and just-in-time.  Society developed towns, and people started to develop specialised skills, but each skill replaced a manual process from before.  There were very few defences and very little interconnectivity.

Stone Age IT (1940)

The IT stone age is generally considered to be the advent of programmable digital computers at the end of the last world war.  Before this everything was done manually and just-in-time.  Engineers developed computers, and people started to develop specialised skills, but each skill replaced a manual process from before.  There were very few defences and very little interconnectivity.

Bronze Age Society (3,000 BC)

The bronze age is defined by the advent of the use of bronze as the primary material for tools and weapons.  It took nearly 7,000 years.  Society developed cities, and the primary government was the city state.  Improvements in efficient trade and commerce were limited by slow communication and lack of coordination.  When necessary armies were raised from farmers.

Bronze Age IT (1975)

The IT bronze age is defined by the advent of the use of microprocessors as the primary building block for computers.  It was 200x faster, and took only 35 years.  Engineers developed CPU designs, and the primary way of using them were via open documentation.  Improvements in efficient trade and commerce were limited by slow communication and lack of coordination.  When necessary armies were raised from enthusiasts.

Iron Age Society (1,000 BC)

The iron age is defined by the advent of the use of steel.  It took about 2,000 years.  Society developed global empires and the first gamers.  The empires were defended by standing armies, but eventually failed as the God-given right to rule crumbled, and plagues ravaged the land.

Iron Age IT (1985)

The IT iron age is defined by the advent of the use of desktop computers.  It was also 200x faster, and took only 10 years.  Engineers developed Microsoft and the first gamers.  The companies were defended by standing armies of lawyers, but eventually failed as the monopoly abuse caused them to crumble, and computer viruses ravaged the land.

Middle Ages Society (500 AD)

After 1500 years, feudalism replaced nation-states and monarchs ruled.  Knowledge was democratised, and the first open universities and printing technologies were created.  Pillage and piracy became a real source of income.  Walled castles were built to keep the enemies out, but weren't effective because trade became more important than protection.

Middle Ages IT (1993)

After 8 years, feudalism replaced monopolies and ideas ruled.  Computing was democratised, and the public Internet was created.  Pillage and piracy became a real source of income.  Firewalls were created to keep the enemies out, but weren't effective because commerce became more important than protection.

Industrial Age Society (1800 AD)

After 1300 years, coal and steam were developed as a new source of power.  Society moved from monarchies to republics.  Laws replaced swords as the way of settling differences, and defences moved out to the state, and in to the building level.

Industrial Age IT (1999)

After 6 years, high-speed broadband was developed as a new source of power.  Innovation moved from established companies to start-ups.  EULAs replaced dongles as the way of protecting software, and defences moved out to the ISP, and in to the host level.

We are now in the Social Stone Age.  It seems unlikely that anyone will look back to IT to see how it will turn out, so I'm sure that we will develop the same societies, defences, attacks and innovations all over again!

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 9 August 2013

War on War on Cybercrime

Be afraid.  Be very afraid.  The UK has just announced that it is losing the war on cybercrime, and needs to consolidate cybercrime policing into a new unified structure as part of a shakeup of the country's policing.

Any time a government declares a “war on something”, it costs money, achieves nothing, and distracts from the real issues.  For recent examples consider the total failure of the “war on drugs”, “war on terror”, and “war on poverty”, just to name a few.  War on cybercrime will be no different.

All of these wars are justified by the belief that the government needs to be seen to be doing something, combined with the unshakeable assertion that they are better at protecting us than we are at protecting ourselves.  I disagree with both sides of the argument.

We live in a world with a higher standard of living, with more freedoms and less crime than ever before.  There is no public outcry to protect us.  The only outcry is that generated by the media and the government themselves.

What we need is better education and the tools to protect ourselves.  We are all being attacked all the time, and we can protect ourselves without relying on an ineffective government oversight body that in the end does nothing but serve platitudes.

We need to declare a war on the war on cybercrime.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Tuesday, 25 June 2013

To Protect and Serve Coffee

So much is currently in the news about government surveillance, I'd like to look at a different intersection of law enforcement and data retention - how the police can help you when you are the victim of a cyber-attack.

Unfortunately the decision to involve the police is not trivial, and really depends on what outcome you are hoping for.  If you just want the problem to go away, involving law enforcement can get in the way of your recovery, as they will want to collect forensically sound evidence, and the process of going to court can and does take years.  Even if you go down this path, the likelihood of restitution is very low and it will cost a fortune.  So most businesses don't bother.

If it were a physical crime, we automatically report it as this is a necessary precondition to claiming on our insurance.  There is also no stigma about being broken into physically.  But things are different in the cyber world - there is no cyber-insurance to claim on, and there definitely is a stigma about being hacked.  This is even more reason for businesses to fix it and move on without police involvement.

But if we look at this in a slightly different way, the view changes.  Instead of looking to law enforcement to locate and prosecute the offenders, we can ask for their assistance in collecting and storing any evidence we might need in the future, and provide them with anonymised information that helps to build a profile of the cyber-crime landscape.

Less protect and serve, and more coffee and collaboration.

Unless you are the bad guys, the police are not your adversary, and they really can be good friends.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Tuesday, 4 June 2013

Mandatory Data Breach Notification

The Australian Government has just announced that mandatory data breach notification laws will commence in March 2014.  This is an excellent start, and the Government is to be congratulated on the initiative.  I'm not normally one to promote more "cyber" legislation to cover new implementations of old crimes, but this really is a new type of crime for which no existing legislation adequately applies.

We've had identity theft for as long as we've had scammers, but in the pre-Internet world this was done one at a time, and required local knowledge and a lot of effort.  But now it can be done wholesale, from anywhere, to anyone, for nearly no cost.  And this is happening every day.

So how will mandatory data breach notification help?  It won't make us any more successful in prosecuting the attackers, so it won't reduce the number of attacks.  It has nothing to do with helping the people who are the subject of identity theft, so it won't reduce the impact of the crime.
 
Today the only sensible approach to take for any company that has a data spill is to cover it up.  There is no possible positive outcome from telling anyone, and a significant likely negative outcome in terms of reputation damage, share price reduction and loss of market confidence.  So this just looks like more victim blaming.

The real point is to make businesses care about security.  If they know that they will be named and shamed, they are more likely to take the necessary steps to not be breached, and therefore reduce the number of actual breaches, and so reduce the impact on the Australian people.  Raising the cost to the attackers is a win for everyone.

Better security is an investment in the future, not a cost to be minimised.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Monday, 8 April 2013

Running with Scissors

There are things that we just shouldn't do - like running with scissors.  We can be told not to do them.  We can know intellectually not to do them.  But until we've stabbed ourselves or someone else it just doesn't sink in.

I've been seeing a lot of discussion recently on attack as pro-active defence - especially related to botnets.  The proponents make a good case that they are making everyone safer.  The opponents say that any unauthorised access - even to disable malware - is wrong and must not happen.  In both cases they have the implicit assumption that the people who own the computers that have been turned into bots are also victims.  I think it's time we addressed the elephant in the room.  We should adjust our thinking and stop thinking of them as victims and start thinking of them as part of the problem.

The only reason they have been turned into bots in the first place is that they haven't enabled even the most basic protections on their computer.  They are running with scissors.  They are stabbing people with the scissors.

We can no longer accept this.  Basic protections won't stop a determined attacker, but turning on automatic patching and running a free antivirus solution will stop most of them being owned most of the time.

It's time the software and operating system vendors made it impossible to turn off these sort of basic protections.  And it's time for society as the real victim of cybercrime demanded it.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com


 

Monday, 25 February 2013

The Sky Falling, NOT!


FUD: Fear, Uncertainty and Doubt.  It seems to drive the product segment of the security market, and it really annoys me.  The sky is falling.  Cybercrime is rampant.  And on, and on, and on...

Let's dial the emotion down, and look at the underlying premise.  How safe online are we really?

As I look out my window, the sky is not falling, it is a beautiful blue.  However there are a few clouds and it may rain tomorrow.  If the doomsayers were in the weather industry instead, they would be telling us all the carry umbrellas at all times, wear raincoats just in case, and take out lightning protection insurance.  I don't see anyone on the street taking these sort of precautions, because they are all able to make a sensible assessment of the likelihood of rain.  Unfortunately they are not able to make a similar sensible assessment on the likelihood of a security compromise, so they worry.  And worry is the marketing tool of choice.

Cybercrime is certainly a problem, but the main problem is the "cyber" prefix.  Cybercrime is just crime.  We don't talk about transport-crime when a thief uses a car as a getaway vehicle.  We don't call it powertool-crime when a safe is cracked.  So why make such a big deal about the enabling technology?  Everything is online now, so everything is "cyber", so let's stop using the word.  People have been stealing from each other since they first decided to pile rocks up in a cave, and it is not much different today.  The majority of crime is theft and fraud, and this is a very rare event in everyday life.  It does happen.  It will continue to happen.  It may be a large absolute value, as much as hundreds of millions of dollars, but the world economy is in the hundreds of trillions, and if we've got crime down to below 0.0001% then we should be pleased about it, not worried by it.

I grew up in a small country town, where everyone knew everyone, and people didn't lock their doors.  Today the same town is much larger, unknown people are the majority, and everyone locks their doors.  In the online world, we are now in the large town, but still acting like we are in the small one.  We need to take sensible precautions against the bad guys, but not spend all our days worrying about them.  And at least know where your umbrella is!

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com