Friday, 2 August 2013

IPv6 Insecurity

Vint Cerf - one of the founders of the Internet - quipped last year that the current IPv4 Internet is the experimental version, and that IPv6 is the production version.  If this is true, then approximately 100% of businesses are still on the beta release and have no plans to move to production.  How can this be, in a world of 36 month IT replacement cycles, when IPv6 has been deployment ready since 1999?

There are a number of reasons, some technical, some psychological, but all to do with security.

Reason #1: Making unnecessary changes breaks things.  There is no compelling reason even today to move to IPv6.  The total number of IPv6 *only* services is approximately none, so not migrating does not limit anything.  Sure we will eventually run out of IPv4 address space, but I predict we will make do at least until 2020.

Reason #2: Complexity reduces security.  Not everything supports IPv6, so deployment requires a dual-stack approach, which significantly increases complexity, and therefore decreases security.  While this is true today, given a 36 month IT replacement cycle, everything will eventually support it by 2016.

Reason #3: We don't understand it.  This is the real reason for the lack of adoption.  IPv6 is not just IPv4 with longer addresses.  It does some things very differently than IPv4, and breaks the well-understood IPv4 security model.  There is no NAT.  There is no ARP.  Multicast matters.  ICMP matters.  We could fix this today, but it will take a generational change of CIOs to really embrace it.  Maybe it won't be scary by the Unix timestamp rollover in 2038.

Interestingly for those of us with a few grey hairs, we've been here before.  We made this same transition from IPX to IP in our Novell networks 20 years ago, but with one very significant difference.  We didn't dual-stack.  On a flag day we just changed all the configurations and got on with it.  But we can't do that this time, because now everything is interconnected, and the risk of cutting ourselves off today is much higher than the risk of running out of addresses at some point in the future.

IPv6 is definitely the future.  While the future is already here, and not very evenly distributed, for most of us the time is just not right.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Tuesday, 16 July 2013

Whistleblowing Cognitive Dissonance

I'm not a fan of over-government.  I'm not a fan of security theatre.  I'm not a fan of the product of over-government and security theatre, which is a fair description of the recent public disclosure of the security services data collection apparatus.  So it might surprise you to know that I'm not a fan of Edward Snowden.  And to put all my cards on the table, I'm also not a fan of Julian Assange.

So why do I have this cognitive dissonance - the discomfort experienced when simultaneously holding two or more conflicting ideas, beliefs, values or emotional reactions.

I have to look at who really benefits, who really pays, and who gets hurt along the way.

In the specific security cases that are in the news today, who primarily benefits is easy - the whistleblower.  There is no doubt that Julian Assange has managed to create and nurture a cult of personality around himself to the point that even WikiLeaks are distancing themselves from him.  It is equally true that none of us would have ever heard of Edward Snowden.  But both of these gentlemen have manipulated the media into thrusting them into the international spotlight.

Remember that the mission of the NSA is to do exactly what they are doing.  As is GCHQ and DSD.  The public mission statement of DSD is "Reveal their secrets, protect our own".  The subtle part of this is to use the secrets that are revealed to grease the wheels of international diplomacy.  The recent disclosures have manifestly damaged international diplomacy, so not only have we as a society not benefited from them, we've actually been hurt instead.

The irony is that the outraged public also have a level of cognitive dissonance here.  It's fine for us to spy on the untrusted foreigners, but it isn't fine for us to spy on our own.  We are all foreigners to someone!

Real whistleblowers that do it for the public good - like Erin Brockovich - stay and fight for what they believe in.  They don't immediately flee and seek protection in non-extradition countries.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 5 July 2013

If a Bear and a Shark had a fight, who would win?

If a bear and a shark had a fight, who would win?  It's a philosophical conundrum indeed, and there are many thousands of web pages, videos and even Facebook sites dedicated to it.  In case you were wondering, opinion is almost exactly split on the matter.

But amazingly this question is relevant in an information security context.  Today, the bear is the NSA and the shark is the MPAA.

If we assume that it is true that all the world's intelligence services are gobbling up every packet that passes across their borders, then they are accumulating the greatest trove of copyright material on the planet.  What about notorious torrent sites like The Pirate Bay?  Not even close.  Every movie, TV show and music track ever downloaded by anyone is sitting on a government server somewhere, because it was in the bitstream.  The security services won't want for Game of Thrones episodes any time soon!

Is this wholesale piracy acceptable in the support of fighting terrorists?  I remember seeing an anti-piracy message on a DVD that said that piracy funded terrorism!  Ah, the irony.  I predict that soon the giant media companies will start to raise trillion dollar lawsuits against the governments for stealing all their material.  With the level of statutory damages that could be levied they could bankrupt a nation state.

The law is not simple.  It is not consistent.  And it doesn't apply the same to all of us, no matter what our politicians say.

The intersection of surveillance and copyright is murky water indeed, so at this stage I'm giving it to the shark.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 28 June 2013

The Ostrich Approach to Security Management


If you find that your security has been compromised, the normal approach the most businesses take to addressing it goes something like this...

Step 1: Admit you have a problem.

Step 2: Blame someone else.

Step 3: Hire a lawyer.

I'm going to spend some time on step 2, as I think that this is where the process really goes off the rails.  Before we can blame someone else, we need to decide who to blame.  All too often instead of blaming the attacker, we blame our IT department for not managing our systems appropriately.  How could they possibly have let this happen?
 
The answer is depressingly simple: senior management are taking the ostrich approach to security management.  If I can't see it, it can't hurt me.  If I stick my head in the sand, I can't see it.  I know how to stick my head in the sand.  Problem solved!

The outcome of this approach is that the perennially blamed IT department are not given guidance on what they should be protecting, how they should be protecting it, nor the training to protect it in the first place.  Most IT departments simply are not competent to answer the question: "Are we secure?".  The only honest answers they could give are "I don't know" or "As best I know how", but this isn't what management want to hear, so this isn't what the IT department says.

To quote Spaf's first principle of security administration: "If you have responsibility for security but have no authority to set rules or punish violators, your own role in the organization is to take the blame when something big goes wrong."

Sand is cheap.  Real security is a lot more valuable.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com

Tuesday, 25 June 2013

To Protect and Serve Coffee

So much is currently in the news about government surveillance, I'd like to look at a different intersection of law enforcement and data retention - how the police can help you when you are the victim of a cyber-attack.

Unfortunately the decision to involve the police is not trivial, and really depends on what outcome you are hoping for.  If you just want the problem to go away, involving law enforcement can get in the way of your recovery, as they will want to collect forensically sound evidence, and the process of going to court can and does take years.  Even if you go down this path, the likelihood of restitution is very low and it will cost a fortune.  So most businesses don't bother.

If it were a physical crime, we automatically report it as this is a necessary precondition to claiming on our insurance.  There is also no stigma about being broken into physically.  But things are different in the cyber world - there is no cyber-insurance to claim on, and there definitely is a stigma about being hacked.  This is even more reason for businesses to fix it and move on without police involvement.

But if we look at this in a slightly different way, the view changes.  Instead of looking to law enforcement to locate and prosecute the offenders, we can ask for their assistance in collecting and storing any evidence we might need in the future, and provide them with anonymised information that helps to build a profile of the cyber-crime landscape.

Less protect and serve, and more coffee and collaboration.

Unless you are the bad guys, the police are not your adversary, and they really can be good friends.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Monday, 17 June 2013

PRISM splits the Red from the Blue

It has recently been reported that the NSA has a classified electronic surveillance system called PRISM, that has been systematically and wholesale vacuuming up information on Internet users.  The vast majority of the data comes from Yahoo, Google and Microsoft.

I'm shocked, stunned, and more than a little amazed.

Not that they are doing it of course, as Blind Freddy could see that it was going to happen.  I'm shocked, stunned, and more than a little amazed at the people who are surprised by this, and are suffering a fit of moral indignation.

We live in a world of pervasive electronic surveillance.  From satellites mapping the globe, to Google cars collecting photographs and WiFi traffic, to CCTV cameras in every major city with active face recognition, to the supermarket loyalty card you use for a discount, to your friends and family posting your every move on Facebook, and finally to governments snooping on the Internet.  We can have heated discussions about whether this should be, and what it means, but the horse has well and truly bolted.

This is not new.  This is not unexpected.  This is not a surprise.  Mostly we did it to ourselves.  The real question is what are we going to do going forward, and this is something we do have a choice about.

The providers that are reported to be the major source of information are the free e-mail services, the ones that already data-mine your e-mail to serve you targeted adverts.  As you didn't pay for the service you are not their clients, you are their product - they sell your eyeballs.

If you want to take back control, choose to use a different provider.  If you want to make it harder to be snooped on, choose to always use encryption.  It might be impractical to go completely off the net, but you can choose to not make it easy.  Or you can choose to keep the benefits you have at the cost of your privacy.

Security is your choice.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com


Tuesday, 4 June 2013

Mandatory Data Breach Notification

The Australian Government has just announced that mandatory data breach notification laws will commence in March 2014.  This is an excellent start, and the Government is to be congratulated on the initiative.  I'm not normally one to promote more "cyber" legislation to cover new implementations of old crimes, but this really is a new type of crime for which no existing legislation adequately applies.

We've had identity theft for as long as we've had scammers, but in the pre-Internet world this was done one at a time, and required local knowledge and a lot of effort.  But now it can be done wholesale, from anywhere, to anyone, for nearly no cost.  And this is happening every day.

So how will mandatory data breach notification help?  It won't make us any more successful in prosecuting the attackers, so it won't reduce the number of attacks.  It has nothing to do with helping the people who are the subject of identity theft, so it won't reduce the impact of the crime.
 
Today the only sensible approach to take for any company that has a data spill is to cover it up.  There is no possible positive outcome from telling anyone, and a significant likely negative outcome in terms of reputation damage, share price reduction and loss of market confidence.  So this just looks like more victim blaming.

The real point is to make businesses care about security.  If they know that they will be named and shamed, they are more likely to take the necessary steps to not be breached, and therefore reduce the number of actual breaches, and so reduce the impact on the Australian people.  Raising the cost to the attackers is a win for everyone.

Better security is an investment in the future, not a cost to be minimised.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com