Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, 25 October 2013

Stone Aged Security

Humans have been stealing from each other since we first chose to pile rocks up in a cave.  The current media frenzy might make us think of cybercrime as a new issue, but it is really just the most recent incarnation of what is the probably the second oldest profession.

The same societies, defences, attacks and innovations that were created in the physical world have all been rediscovered and recreated in the online world.  No-one seems to have noticed this before now.

Stone Age Society (10,000 BC)

The stone age is generally considered to be the advent of agriculture at the end of the last ice age.  Before this everything was done manually and just-in-time.  Society developed towns, and people started to develop specialised skills, but each skill replaced a manual process from before.  There were very few defences and very little interconnectivity.

Stone Age IT (1940)

The IT stone age is generally considered to be the advent of programmable digital computers at the end of the last world war.  Before this everything was done manually and just-in-time.  Engineers developed computers, and people started to develop specialised skills, but each skill replaced a manual process from before.  There were very few defences and very little interconnectivity.

Bronze Age Society (3,000 BC)

The bronze age is defined by the advent of the use of bronze as the primary material for tools and weapons.  It took nearly 7,000 years.  Society developed cities, and the primary government was the city state.  Improvements in efficient trade and commerce were limited by slow communication and lack of coordination.  When necessary armies were raised from farmers.

Bronze Age IT (1975)

The IT bronze age is defined by the advent of the use of microprocessors as the primary building block for computers.  It was 200x faster, and took only 35 years.  Engineers developed CPU designs, and the primary way of using them were via open documentation.  Improvements in efficient trade and commerce were limited by slow communication and lack of coordination.  When necessary armies were raised from enthusiasts.

Iron Age Society (1,000 BC)

The iron age is defined by the advent of the use of steel.  It took about 2,000 years.  Society developed global empires and the first gamers.  The empires were defended by standing armies, but eventually failed as the God-given right to rule crumbled, and plagues ravaged the land.

Iron Age IT (1985)

The IT iron age is defined by the advent of the use of desktop computers.  It was also 200x faster, and took only 10 years.  Engineers developed Microsoft and the first gamers.  The companies were defended by standing armies of lawyers, but eventually failed as the monopoly abuse caused them to crumble, and computer viruses ravaged the land.

Middle Ages Society (500 AD)

After 1500 years, feudalism replaced nation-states and monarchs ruled.  Knowledge was democratised, and the first open universities and printing technologies were created.  Pillage and piracy became a real source of income.  Walled castles were built to keep the enemies out, but weren't effective because trade became more important than protection.

Middle Ages IT (1993)

After 8 years, feudalism replaced monopolies and ideas ruled.  Computing was democratised, and the public Internet was created.  Pillage and piracy became a real source of income.  Firewalls were created to keep the enemies out, but weren't effective because commerce became more important than protection.

Industrial Age Society (1800 AD)

After 1300 years, coal and steam were developed as a new source of power.  Society moved from monarchies to republics.  Laws replaced swords as the way of settling differences, and defences moved out to the state, and in to the building level.

Industrial Age IT (1999)

After 6 years, high-speed broadband was developed as a new source of power.  Innovation moved from established companies to start-ups.  EULAs replaced dongles as the way of protecting software, and defences moved out to the ISP, and in to the host level.

We are now in the Social Stone Age.  It seems unlikely that anyone will look back to IT to see how it will turn out, so I'm sure that we will develop the same societies, defences, attacks and innovations all over again!

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 6 September 2013

Political Insecurity

Australia will be going to a national election in early September, and the only security that appears on the platform of any of the major parties is the political security that comes through a populist agenda, rather than a strong stand on securing the intellectual capital of the nation.

The Government’s job should be to set high level policy, and help us help ourselves, rather than try to protect us from every movie plot threat.  This is what I'd like to see on the next government's agenda.

#1.  Include cyber security in the education curriculum.  At the moment the only area of interest is cyber-bullying (“Won’t someone think of the children!”) but this isn’t enough, and is a misdirection of resources.  The problem is much bigger than that.

#2.  Make software vendors liable for the faults in their products.  If a car crashes because it wasn’t designed properly, the manufacturer gets sued.  If you lose your bank account because the software you use wasn’t designed properly, you lose and the manufacturer points to an EULA that says they aren’t liable.

#3.  Engage with the private sector.  We are better at practical and pragmatic security than they are.  So work with us instead of the military industrial complex, who only want to ramp up the cyberwar rhetoric to get even more money from the public purse.

Make your vote count.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 23 August 2013

Game of Phones

Apple iOS 7 will be released next month, and it's time for us to once again declare our allegiance to our feudal technology overlords.  Overlords that are starting to feel remarkably like those from the popular HBO TV show.

Blackberry is House Stark.  Solid, loyal, dependable, secure and dead.  Their only hope are their bastard offspring.

Android is House Lannister.  They have spent many years behind the scenes manipulating the empire, and have only recently seen the opportunity to show their power openly.  Technologically dominant, and masters of strategy, they are sure they can think their way to the top, and then hold it.  Security comes through threat, rapid change and the culling of the weak.

iPhone is House Targaryen.  They have come from out of the wilderness and they have dragons, an ancient mystery that has not been harnessed by anyone in living memory.  They also have a sexy leader, and everyone emotionally wants to get behind them.  But after the initial revelations at the end of the first season, there really hasn't been anything new for the last two years.  Security comes through central control and fervent loyalty of the followers.

Windows is House Baratheon.  They were once dominant, but time has passed them by, and internal bickering stops them from really being a force any more.  Because they have ruled in the past, they believe they have the absolute right to rule in the future.  Security isn't a concern, only survival, but only the most loyal followers expect anything other than a spectacular crash.

The thing to remember is that the only winners in the Game of Phones are the main houses.  If you are a peasant or vassal - and in reality we all are - then the best we can do is raise our flag in support of one of the main houses, and hope they don't sacrifice us for their greater good.

Until then, enjoy the ride.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Monday, 17 June 2013

PRISM splits the Red from the Blue

It has recently been reported that the NSA has a classified electronic surveillance system called PRISM, that has been systematically and wholesale vacuuming up information on Internet users.  The vast majority of the data comes from Yahoo, Google and Microsoft.

I'm shocked, stunned, and more than a little amazed.

Not that they are doing it of course, as Blind Freddy could see that it was going to happen.  I'm shocked, stunned, and more than a little amazed at the people who are surprised by this, and are suffering a fit of moral indignation.

We live in a world of pervasive electronic surveillance.  From satellites mapping the globe, to Google cars collecting photographs and WiFi traffic, to CCTV cameras in every major city with active face recognition, to the supermarket loyalty card you use for a discount, to your friends and family posting your every move on Facebook, and finally to governments snooping on the Internet.  We can have heated discussions about whether this should be, and what it means, but the horse has well and truly bolted.

This is not new.  This is not unexpected.  This is not a surprise.  Mostly we did it to ourselves.  The real question is what are we going to do going forward, and this is something we do have a choice about.

The providers that are reported to be the major source of information are the free e-mail services, the ones that already data-mine your e-mail to serve you targeted adverts.  As you didn't pay for the service you are not their clients, you are their product - they sell your eyeballs.

If you want to take back control, choose to use a different provider.  If you want to make it harder to be snooped on, choose to always use encryption.  It might be impractical to go completely off the net, but you can choose to not make it easy.  Or you can choose to keep the benefits you have at the cost of your privacy.

Security is your choice.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com


Tuesday, 14 May 2013

Writing Secure Software is Hard

All code is crap.  I know, because I've written a lot of it.  A long time ago, in a galaxy far far away, I wrote a large PHP based enterprise application that is still in production use today.  It's also being used as an example of how not to write code that will survive penetration testing.

Development of this application started in 1998, so in Internet years it is ancient.  A recent review of the application has found that XSS is possible in nearly every field, and while SQLI is harder to do that you'd expect, due to a protection framework I wrote to save me from writing bad SQL, it is still possible.

How can I have gone so far wrong?  The simple answer is I didn't know any better.

There are two foundation reasons why software developers don't write secure code.  The first is that they aren't told they have to, and the second is they aren't shown how to do it.  Both of these reasons applied to me - there was no specification for the application that included non-functional requirements such as security, and none of the university level courses I'd passed on software development even mentioned secure coding practices.  In my defence I'm going to throw in a third reason that these attack types were not well known at the time.

Unfortunately the foundations are just as weak today.  Most development projects don't include security in their requirements document, and most developers are not taught how to write secure code.  My third defence doesn't save us any more as the attack types are very well known.  Rapid prototyping methodologies just make this harder.

It's time to do it better.  All development projects need to have security as part of their project governance, and have developers trained by penetration testers on how their code will be abused.

Microsoft started in 2002 with their secure development initiative.  Most other large development companies have done the same thing.  But there are still a very large number of web facing applications being developed without the safety net of a secure software development lifecycle, and they will continue to fall over much to the surprise of their developers.

The 21st century has been around for a while now, but we're still writing code like it's 1999.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Monday, 22 April 2013

Why no-one gets SCADA security right

SCADA is an acronym for Supervisory Control and Data Acquisition.  That's a bit of a mouthful and unless you've studied Engineering it's not clear what it means, so here's a simple definition: SCADA is computer controlled physical processes.  The common examples given are power stations and water treatment plants, but it's much more than that.  Building management systems that control the temperature, lights and door locks: that's SCADA.  The production line at a large bakery that makes your bread: that's SCADA.  The baggage system at the airport that loses your bags: that's SCADA.  The traffic lights that annoy you on your drive to work: that's SCADA.

It's everywhere.  It's all around us.  And it's all implemented badly.  Maybe that's too strong - it's all implemented inappropriately for the threat model we have in 2013.

We have to set the way back machine to the 1980s to understand why we are in the mess we are today.

Traditionally SCADA systems were designed around reliability and safety.  Security was not a consideration.  This means that the way the engineers think of security is different.  In IT security we consider Confidentiality first, then Integrity and finally Availability.  This matches with our real world experience of security.  But in SCADA systems it's the other way around - Availability first, then Integrity, and finally Confidentiality a very distant third.

There are two very good reasons for this approach.

Firstly: Keeping SCADA systems running is like balancing a broom stick on your finger - you can do it, but it takes a lot of control, and if you stop thinking about it, the broom stick falls.  This is the fundamental reason that the dramatic scenes where the bad guy blows up a power station as shown in movies just can't happen.  If you mess up the control the power stations stops generating power, it doesn't explode.

Secondly: Every business that controls real world processes has a culture of safety: they have sign boards telling how many days since the last lost time injury, and are proud that the number keeps going up.  Anything that gets in the way of human safety is removed.  That's why control workstations don't have logins or passwords.  If something needs to be done for a safety reason, it can't be delayed by a forgotten password.

All of this made perfect sense in the 1980s when SCADA systems were hard wired analog computers, connected to nothing, staffed by a large number of well-trained engineers, and located in secure facilities at the plant.

That isn't true now.  Today SCADA systems are off-the-shelf IT equipment, connected to corporate networks over third party WAN solutions and sometimes the Internet, staffed by very few over-stressed Engineers, sometimes not located even in the same country.

So what happened in between?  Nothing.  Really.  SCADA systems have an expected life of about 30 years.  The analog computers were replaced by the first general purpose computers in the late 1980s, and they are only now being replaced again with today's technology.  They will be expected to run as deployed all the way to 2040.

I hope you've stocked up on candles.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com