Tuesday, 16 July 2013

Whistleblowing Cognitive Dissonance

I'm not a fan of over-government.  I'm not a fan of security theatre.  I'm not a fan of the product of over-government and security theatre, which is a fair description of the recent public disclosure of the security services data collection apparatus.  So it might surprise you to know that I'm not a fan of Edward Snowden.  And to put all my cards on the table, I'm also not a fan of Julian Assange.

So why do I have this cognitive dissonance - the discomfort experienced when simultaneously holding two or more conflicting ideas, beliefs, values or emotional reactions.

I have to look at who really benefits, who really pays, and who gets hurt along the way.

In the specific security cases that are in the news today, who primarily benefits is easy - the whistleblower.  There is no doubt that Julian Assange has managed to create and nurture a cult of personality around himself to the point that even WikiLeaks are distancing themselves from him.  It is equally true that none of us would have ever heard of Edward Snowden.  But both of these gentlemen have manipulated the media into thrusting them into the international spotlight.

Remember that the mission of the NSA is to do exactly what they are doing.  As is GCHQ and DSD.  The public mission statement of DSD is "Reveal their secrets, protect our own".  The subtle part of this is to use the secrets that are revealed to grease the wheels of international diplomacy.  The recent disclosures have manifestly damaged international diplomacy, so not only have we as a society not benefited from them, we've actually been hurt instead.

The irony is that the outraged public also have a level of cognitive dissonance here.  It's fine for us to spy on the untrusted foreigners, but it isn't fine for us to spy on our own.  We are all foreigners to someone!

Real whistleblowers that do it for the public good - like Erin Brockovich - stay and fight for what they believe in.  They don't immediately flee and seek protection in non-extradition countries.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 5 July 2013

If a Bear and a Shark had a fight, who would win?

If a bear and a shark had a fight, who would win?  It's a philosophical conundrum indeed, and there are many thousands of web pages, videos and even Facebook sites dedicated to it.  In case you were wondering, opinion is almost exactly split on the matter.

But amazingly this question is relevant in an information security context.  Today, the bear is the NSA and the shark is the MPAA.

If we assume that it is true that all the world's intelligence services are gobbling up every packet that passes across their borders, then they are accumulating the greatest trove of copyright material on the planet.  What about notorious torrent sites like The Pirate Bay?  Not even close.  Every movie, TV show and music track ever downloaded by anyone is sitting on a government server somewhere, because it was in the bitstream.  The security services won't want for Game of Thrones episodes any time soon!

Is this wholesale piracy acceptable in the support of fighting terrorists?  I remember seeing an anti-piracy message on a DVD that said that piracy funded terrorism!  Ah, the irony.  I predict that soon the giant media companies will start to raise trillion dollar lawsuits against the governments for stealing all their material.  With the level of statutory damages that could be levied they could bankrupt a nation state.

The law is not simple.  It is not consistent.  And it doesn't apply the same to all of us, no matter what our politicians say.

The intersection of surveillance and copyright is murky water indeed, so at this stage I'm giving it to the shark.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Friday, 28 June 2013

The Ostrich Approach to Security Management


If you find that your security has been compromised, the normal approach the most businesses take to addressing it goes something like this...

Step 1: Admit you have a problem.

Step 2: Blame someone else.

Step 3: Hire a lawyer.

I'm going to spend some time on step 2, as I think that this is where the process really goes off the rails.  Before we can blame someone else, we need to decide who to blame.  All too often instead of blaming the attacker, we blame our IT department for not managing our systems appropriately.  How could they possibly have let this happen?
 
The answer is depressingly simple: senior management are taking the ostrich approach to security management.  If I can't see it, it can't hurt me.  If I stick my head in the sand, I can't see it.  I know how to stick my head in the sand.  Problem solved!

The outcome of this approach is that the perennially blamed IT department are not given guidance on what they should be protecting, how they should be protecting it, nor the training to protect it in the first place.  Most IT departments simply are not competent to answer the question: "Are we secure?".  The only honest answers they could give are "I don't know" or "As best I know how", but this isn't what management want to hear, so this isn't what the IT department says.

To quote Spaf's first principle of security administration: "If you have responsibility for security but have no authority to set rules or punish violators, your own role in the organization is to take the blame when something big goes wrong."

Sand is cheap.  Real security is a lot more valuable.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com

Tuesday, 25 June 2013

To Protect and Serve Coffee

So much is currently in the news about government surveillance, I'd like to look at a different intersection of law enforcement and data retention - how the police can help you when you are the victim of a cyber-attack.

Unfortunately the decision to involve the police is not trivial, and really depends on what outcome you are hoping for.  If you just want the problem to go away, involving law enforcement can get in the way of your recovery, as they will want to collect forensically sound evidence, and the process of going to court can and does take years.  Even if you go down this path, the likelihood of restitution is very low and it will cost a fortune.  So most businesses don't bother.

If it were a physical crime, we automatically report it as this is a necessary precondition to claiming on our insurance.  There is also no stigma about being broken into physically.  But things are different in the cyber world - there is no cyber-insurance to claim on, and there definitely is a stigma about being hacked.  This is even more reason for businesses to fix it and move on without police involvement.

But if we look at this in a slightly different way, the view changes.  Instead of looking to law enforcement to locate and prosecute the offenders, we can ask for their assistance in collecting and storing any evidence we might need in the future, and provide them with anonymised information that helps to build a profile of the cyber-crime landscape.

Less protect and serve, and more coffee and collaboration.

Unless you are the bad guys, the police are not your adversary, and they really can be good friends.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Monday, 17 June 2013

PRISM splits the Red from the Blue

It has recently been reported that the NSA has a classified electronic surveillance system called PRISM, that has been systematically and wholesale vacuuming up information on Internet users.  The vast majority of the data comes from Yahoo, Google and Microsoft.

I'm shocked, stunned, and more than a little amazed.

Not that they are doing it of course, as Blind Freddy could see that it was going to happen.  I'm shocked, stunned, and more than a little amazed at the people who are surprised by this, and are suffering a fit of moral indignation.

We live in a world of pervasive electronic surveillance.  From satellites mapping the globe, to Google cars collecting photographs and WiFi traffic, to CCTV cameras in every major city with active face recognition, to the supermarket loyalty card you use for a discount, to your friends and family posting your every move on Facebook, and finally to governments snooping on the Internet.  We can have heated discussions about whether this should be, and what it means, but the horse has well and truly bolted.

This is not new.  This is not unexpected.  This is not a surprise.  Mostly we did it to ourselves.  The real question is what are we going to do going forward, and this is something we do have a choice about.

The providers that are reported to be the major source of information are the free e-mail services, the ones that already data-mine your e-mail to serve you targeted adverts.  As you didn't pay for the service you are not their clients, you are their product - they sell your eyeballs.

If you want to take back control, choose to use a different provider.  If you want to make it harder to be snooped on, choose to always use encryption.  It might be impractical to go completely off the net, but you can choose to not make it easy.  Or you can choose to keep the benefits you have at the cost of your privacy.

Security is your choice.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com


Tuesday, 4 June 2013

Mandatory Data Breach Notification

The Australian Government has just announced that mandatory data breach notification laws will commence in March 2014.  This is an excellent start, and the Government is to be congratulated on the initiative.  I'm not normally one to promote more "cyber" legislation to cover new implementations of old crimes, but this really is a new type of crime for which no existing legislation adequately applies.

We've had identity theft for as long as we've had scammers, but in the pre-Internet world this was done one at a time, and required local knowledge and a lot of effort.  But now it can be done wholesale, from anywhere, to anyone, for nearly no cost.  And this is happening every day.

So how will mandatory data breach notification help?  It won't make us any more successful in prosecuting the attackers, so it won't reduce the number of attacks.  It has nothing to do with helping the people who are the subject of identity theft, so it won't reduce the impact of the crime.
 
Today the only sensible approach to take for any company that has a data spill is to cover it up.  There is no possible positive outcome from telling anyone, and a significant likely negative outcome in terms of reputation damage, share price reduction and loss of market confidence.  So this just looks like more victim blaming.

The real point is to make businesses care about security.  If they know that they will be named and shamed, they are more likely to take the necessary steps to not be breached, and therefore reduce the number of actual breaches, and so reduce the impact on the Australian people.  Raising the cost to the attackers is a win for everyone.

Better security is an investment in the future, not a cost to be minimised.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com
 

Monday, 27 May 2013

The Law of the Internet

I've spoken to a number of journalists over the last few weeks who have all posited some variation of the simple question: "Don't national governments have the right to govern the Internet?"  While it is a simple question, it doesn't have a simple answer, and perhaps not for the reason that many people think.

There are many technology activists who see cyberspace as the first truly transnational place: where the existing rules don't apply, and a new set of rules - better rules - can take their place; where we can leave meatspace behind and become a meritocracy of the mind.  I strongly recommend reading "Snow Crash" by Neal Stephenson to get a sense of it.

I believe that there are three fundamental problems with this approach: (1) the Internet isn't a place; (2) we don't yet live in a futuristic dystopian civilisation; and (3) the Internet was not designed.  It's the last problem that causes all the angst.

If the Internet had been designed by governments, rather than organically grown by technologists, it wouldn't look anything like what we see today.  There would be the controls that national governments want, but there almost certainly wouldn't have been the flourishing of our society that connectedness has brought us.  If you want a real example of this, look at the Internet of DPRK, or the Great Firewall of China.  Then imagine each of these interconnected with deep packet inspection borders to mimic the physical borders we have today.  There would even likely be Internet passports to allow transit.

But it wasn't designed, and the law-makers were slow coming to the party.  By the time they noticed it was largely too late.  As John Gilmore famously said in 1993: "The Net interprets censorship as damage and routes around it."  It was too late in 1993, and it's way too late in 2013.

Does this mean that the netizens have won, and society as we know it will necessarily fall?

Of course not.  The problems that the Internet brings are the same problems that all societies have had over all of human history.  The links are just faster, and the people vastly more connected.  In the past if someone wanted a business to pay protection money they had to send a hard-man to bully the owners and do a little damage.  There was always the possibility of injury, arrest and incarceration.  Today they DDOS their website, with no possibility of injury, and almost no chance of getting caught.

But the crime is the same.  And the laws to deal with the physical crime are already on the books.

Governments can and should govern the Internet, but they can't control it.  Governing requires the consent of the governed.  Control requires technology.

The Internet is a people problem.  Until national governments realise this, they have no chance.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com