Friday, 15 November 2013

Balkanization of the Internet

There have been a number of well-known information security personalities who have been publicly saying that the revelations the capabilities of national governments to undertake wholesale surveillance of the Internet will lead to its Balkanization.  If you believe the hype, the Internet will fragment and become less well connected as we all pull back in fear of everyone else's big brother.

I just don't believe it.  There are two really good reasons why this won't happen.

Firstly, all evidence suggests that we really don't mind about mass surveillance.  In 2006 the United Kingdom was described as being the most surveilled country among the West.  Since 2001 the USA has spent untold billions conducting illegal electronic surveillance on its own citizens, as well as doing its best to have a live packet capture of the entire Internet.  In a Western democracy, if we don't like what the government is doing, we can vote them out.  Not only have we not voted them out, we have year-on-year given them even more power.

This is not to say that these are good things, nor that one day we might say that enough is enough and reel the power back in, but it isn't going to happen in 2014, and may not happen for another generation.

Secondly, the Internet really is trans-national, and outside the control of any one country.  It was originally designed by the technical elite, without any consideration of governance.  It is now run primarily for the benefit of the business elite, who don't want governance as it may get in the way of their business models.  Any attempt to Balkanize the Internet, or set up controlling choke points will be worked around using both technical and business controls.  It is far too late to be trying to set up Internet borders and passport security.

This on the other hand is generally a good thing.  All the repressive regimes on the planet have done everything they can to limit Internet access, and they have universally failed.  The smarter ones have moved back to surveillance rather than control.

Within the next year or so, I strongly predict that the Internet will go through a phase-change from default clear-text to default encrypted, and the state security agencies will wring their hands and weep into their budgets.  But the rest of us will get on with our lives and use the Internet for what it was designed - porn and funny cats.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Tuesday, 12 November 2013

CQR Achievements in 2013

The only constant in the Information Security industry is change, and that has been no different for us.  Looking back we can see that 2013 has been a really good year for CQR.  It’s impressive how far we have come and what we have learned.

This year we were Platinum sponsors at the Oceania CACS Conference in Adelaide, not only was there a great turn out, there were also a great number of informative presentations, workshops and opportunities to meet with other professionals within the industry.

Our Business Security team has doubled in size, and we now have a high level of skill and experience that we can offer to clients who understand that Information Security is more a business problem than a technology one.
 
This growth has allowed us to take the opportunity to refine some of our services to make them more appealing packages.  One way of doing this has been to develop an area of our ISMS (Information Security Management System) offerings, and so we have created the ISMS Jumpstart programme.  The core aim of the programme is to both define an appropriate scope and governance framework for organisations, and also to expose areas that need to be addressed to implement an ISMS.  It gives the implementation a ‘Jumpstart’ by developing an implementation plan and future roadmap.

We have also been working on improving the business value of our Onsite Security Specialists (OSS) service, which is designed to give organisations regular and recurring access to our pool of skilled information security specialists.  Whether it’s for one day per month or five days per week, our OSS service is helping organisations solve their information security challenges by having one of our specialists become one of their onsite team members.

Our most ambitious and exciting development this year is our portfolio of information security awareness videos covering a range of issues that confront organisations and their staff every day.  We are very proud of this service as we are the only company in Australia who can offer this type of training support.  The videos have been born from ideas developed within CQR and have been developed and produced with significant input from all areas the company.
Internally we have seen our personnel change, with new faces joining and some old faces moving on and even one of our alumni returning to us.  We are confident that our strong teams both in Australia and the UK, will continue to forge great relationships both inside the organisation and with our clients.

With our 10 year anniversary approaching and the updated certification of ISO27001 waiting for us in the New Year we are looking forward to the Christmas break and spending time with our families and friends and welcome the challenges of 2014.

You can find more information on everything we’ve achieved on our new website at www.cqr.com or by following us on Twitter @CQR.

Sarah Taylor
@cqr www.cqr.com

Friday, 8 November 2013

Death Star Risk Assessment

We would like to thank Lord Vader and the executive team for the time and support they have given us in undertaking our risk assessment of the new Death Star weapons platform.  We understand that you have finished your initial development, and plan to go live in the very near future if the system tests codenamed Alderaan are successful.

We have considered the project risks in the areas of people, process and technology.

People risks.  The choice of armour for your troops appears to be more focussed on brand management than functionality.  Our assessment has found the following untreated risks:

(1) the armour does not protect against blaster fire; [risk moderate]
(2) the lack of identity badges increases the risk of social engineering attacks. [risk high]

Process risks.  There is little evidence that an effective management system has been deployed.  Our assessment has found the following untreated risks:

(1) management by force of personality and threat of death can be effective in small teams, but does not scale; [risk low]
(2) there are few documented processes for the management of the detention cells, trash compactor and other operational systems. [risk moderate]

Technology risks.  The specifications for the Death Star do not appear to effectively cover non-functional operational components.  Our assessment has found the following untreated risks:

(1) there is no technical security around the management interfaces to the weapons platform; [risk high]
(2) a small unshielded vent port has been detected that has full access to the central core. [risk high]

Our recommendation is that you correct each of these risks before going live, even if it delays the project.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Tuesday, 5 November 2013

Oceania CACS Conference 2013

5 weeks ago CQR was the Platinum sponsor for the 2013 Oceania CACS conference which was held at the Adelaide Convention Centre from September 23rd to 25th

CQR’s General Manager and Chief Technology Officer, Phil Kernick was one of the keynote speakers and presented on the Anthropology of Information Security. (A copy of his presentation can be found on the ISACA Adelaide Chapter website). In typical Phil Kernick fashion he provided the conference delegates with some interesting parallels between the rise of civilisation and the evolution of information security. The presentation was thought provoking and this left the audience with a different interpretation of the field in which we work. At it’s core Information Security is not new, it’s just the technology that surrounds it has evolved.

Other CQR team members who presented included Evan Pearce who discoursed on mobile device security and David Simpson who facilitated a full day workshop on “Navigating your way effectively through the Information Security jungle.”

Non CQR presentations of note included those by Robert Stroud and Stuart Mort as well as Chris Brookes from the Australian Signals Directorate.  The presentation by Duncan Chessell, a three times conqueror of Mount Everest, was also very well received.

A highlight of the conference was the CIO/CSO forum moderated by Robert Stroud (CA Technologies) which included Phil Kernick, Andrew Mills (SA Government Office of the Chief Information Officer) and Stuart Mort (Oracle Global Information Security). Having some of the best Information Security professionals in the country on the same table to answer questions and discuss a number of interesting, challenging and topical Information Security subjects was a unique opportunity. Many of the topics and themes were later debated at tables during the conference dinner that evening.

Oceania CACS was attended by over 100 delegates from all over Australia and many from abroad. It provided an excellent networking opportunity for all delegates to speak with likeminded security and audit professionals. The event was also a significant milestone in the CQR calendar. With over 15 of it’s staff in attendance, CQR enjoyed many diverse conversations with delegates and industry peers alike. One lucky attendee also won an iPad mini donated by CQR in our business card draw.

Yvonne Sears (ISACA member and CQR employee) took a formal photography role providing us with photos of the sessions that took place over the 3 day event, a selection of them will be added following this blog update.

Sarah Taylor & Gary Kite Senior Security Specialist
@cqr www.cqr.com


http://www.oceaniacacs2013.org/speakers.html#kernick
http://www.oceaniacacs2013.org/workshops.html
http://www.isaca.org/chapters4/adelaide/Pages/default.aspx




 

 


Friday, 25 October 2013

Stone Aged Security

Humans have been stealing from each other since we first chose to pile rocks up in a cave.  The current media frenzy might make us think of cybercrime as a new issue, but it is really just the most recent incarnation of what is the probably the second oldest profession.

The same societies, defences, attacks and innovations that were created in the physical world have all been rediscovered and recreated in the online world.  No-one seems to have noticed this before now.

Stone Age Society (10,000 BC)

The stone age is generally considered to be the advent of agriculture at the end of the last ice age.  Before this everything was done manually and just-in-time.  Society developed towns, and people started to develop specialised skills, but each skill replaced a manual process from before.  There were very few defences and very little interconnectivity.

Stone Age IT (1940)

The IT stone age is generally considered to be the advent of programmable digital computers at the end of the last world war.  Before this everything was done manually and just-in-time.  Engineers developed computers, and people started to develop specialised skills, but each skill replaced a manual process from before.  There were very few defences and very little interconnectivity.

Bronze Age Society (3,000 BC)

The bronze age is defined by the advent of the use of bronze as the primary material for tools and weapons.  It took nearly 7,000 years.  Society developed cities, and the primary government was the city state.  Improvements in efficient trade and commerce were limited by slow communication and lack of coordination.  When necessary armies were raised from farmers.

Bronze Age IT (1975)

The IT bronze age is defined by the advent of the use of microprocessors as the primary building block for computers.  It was 200x faster, and took only 35 years.  Engineers developed CPU designs, and the primary way of using them were via open documentation.  Improvements in efficient trade and commerce were limited by slow communication and lack of coordination.  When necessary armies were raised from enthusiasts.

Iron Age Society (1,000 BC)

The iron age is defined by the advent of the use of steel.  It took about 2,000 years.  Society developed global empires and the first gamers.  The empires were defended by standing armies, but eventually failed as the God-given right to rule crumbled, and plagues ravaged the land.

Iron Age IT (1985)

The IT iron age is defined by the advent of the use of desktop computers.  It was also 200x faster, and took only 10 years.  Engineers developed Microsoft and the first gamers.  The companies were defended by standing armies of lawyers, but eventually failed as the monopoly abuse caused them to crumble, and computer viruses ravaged the land.

Middle Ages Society (500 AD)

After 1500 years, feudalism replaced nation-states and monarchs ruled.  Knowledge was democratised, and the first open universities and printing technologies were created.  Pillage and piracy became a real source of income.  Walled castles were built to keep the enemies out, but weren't effective because trade became more important than protection.

Middle Ages IT (1993)

After 8 years, feudalism replaced monopolies and ideas ruled.  Computing was democratised, and the public Internet was created.  Pillage and piracy became a real source of income.  Firewalls were created to keep the enemies out, but weren't effective because commerce became more important than protection.

Industrial Age Society (1800 AD)

After 1300 years, coal and steam were developed as a new source of power.  Society moved from monarchies to republics.  Laws replaced swords as the way of settling differences, and defences moved out to the state, and in to the building level.

Industrial Age IT (1999)

After 6 years, high-speed broadband was developed as a new source of power.  Innovation moved from established companies to start-ups.  EULAs replaced dongles as the way of protecting software, and defences moved out to the ISP, and in to the host level.

We are now in the Social Stone Age.  It seems unlikely that anyone will look back to IT to see how it will turn out, so I'm sure that we will develop the same societies, defences, attacks and innovations all over again!

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 13 September 2013

Staking a Claim in Social Media

This week I had a call from a lawyer who said that social media accounts in the name of one of their clients had been created and were being used for malicious purposes.  They wanted to know what they could do about it.

When deploying security controls we need to consider prevention, detection and response, and this case is no different.

Prevention.

There are a significant number of people - many of them in very senior roles - who wear as a badge of honour that they don't have any social media accounts.  Saying "I don't understand this new-fangled social media" may sound reasonable today, but 100 years ago the same people would have been saying "I don't understand this new-fangled electricity", and then gone on to sink their fortunes into steam power.

I'm not suggesting that everyone become Facebook addicts.  However I am definitely recommending that all companies and anyone with a senior role go out and register accounts on all of the major social media sites, as a prevention against anyone else doing it in their name.  There is no validation of who registers an account, and due to an interesting bootstrapping problem it really is impossible for the social media providers to confirm the identities.  Twitter's blue tick isn't the answer.

We did this with domain names a decade ago, and we have to do it all over again with social media now.

Detection.

Search for yourself on the search engine of your choice.  While it might be vanity, it also will allow you to determine if anyone else is pretending to be you.  Most of the major search engines allow you to set up alerts on new pages that they find with a given term, and you can use this as a detection mechanism against imposters.

This may be practical if you have a distinctive name, but is going to be quite difficult for the John Smiths of the world.  Even my name isn't unique in my own city, so getting in first and registering early becomes very important.

Response.

If and when someone does register a social media account in your name, there are a limited number of things that can be done about it.  It is always possible that they really do have the same name as you, and you got in late, in which case unless they are committing fraud by pretending to be you specifically you have no comeback.  Consult your lawyer on defamation laws in your jurisdiction as your only response.

Just like the domain squatters of the last decade, we now have social media squatters.  They can be dealt with in similar ways: (a) pay them what they ask to get the identity back; (b) raise a complaint with the social media provider; or (c) call the lawyers.  The difference here is that the social media providers are for profit companies, rather than not for profit organisations, and they don't have the same social responsibilities.

Ironic, isn't it.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 6 September 2013

Political Insecurity

Australia will be going to a national election in early September, and the only security that appears on the platform of any of the major parties is the political security that comes through a populist agenda, rather than a strong stand on securing the intellectual capital of the nation.

The Government’s job should be to set high level policy, and help us help ourselves, rather than try to protect us from every movie plot threat.  This is what I'd like to see on the next government's agenda.

#1.  Include cyber security in the education curriculum.  At the moment the only area of interest is cyber-bullying (“Won’t someone think of the children!”) but this isn’t enough, and is a misdirection of resources.  The problem is much bigger than that.

#2.  Make software vendors liable for the faults in their products.  If a car crashes because it wasn’t designed properly, the manufacturer gets sued.  If you lose your bank account because the software you use wasn’t designed properly, you lose and the manufacturer points to an EULA that says they aren’t liable.

#3.  Engage with the private sector.  We are better at practical and pragmatic security than they are.  So work with us instead of the military industrial complex, who only want to ramp up the cyberwar rhetoric to get even more money from the public purse.

Make your vote count.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com