Showing posts with label BYOD. Show all posts
Showing posts with label BYOD. Show all posts

Tuesday, August 7, 2012

Episode 22: When the rain from the cloud is just your tears

The tale of Mat Honan's remotely wiped Apple products has now been committed to the lore of the Internet. But this tale as with any comes with a proviso that has long been the anchor of the 'superhero' story; "With great power comes great responsibility." Our reliance on technology as the super-hero in our modern life has set us up for spectacular falls, akin to any great fallen-hero story-arch.

We have great power in our hands with our smart phones, mobile devices, cloud-enabled hand-held & remote technologies, & yet we wield these powers with little to no real responsibility. Mat Honan originally supposed that his accounts were brute force attacked (something he later retracted), but days later we learn they weren't. He was the victim of social engineering; the attackers rang Apple support, managed to pass through their security protocols due to "Apple's centralised single user account approach."

Blaming Apple is easy, but the fact is we are seeing further centralisation of our online lives with more & more of our accounts & services being linked together via our Twitter, OpenID or Facebook accounts. Each node we link in this way just increases our vulnerability. With security compromises of user databases on the rise, our entire 'digital life' faces compromise from any one of the countless services we interlink.

But that's not even the bigger risk. Publicising information about ourselves in such a carefree manner on social networking sites gives 'hackers' (calling them this when we make it this easy for them denegrates those who are 'real' hackers) less work to do when searching for information to use against us in a social engineering scam, when they wish to target someone.

The real threats as a result of our digitalisation is not our own personal Twitter, Facebook, LinkedIn, or Tumblr accounts - the real risk is our employers, & our businesses. As we increase the drive towards BYOD, our personal & business accounts become increasingly intermingled, something Honan discovered when his employer Gizmodo experienced as part of his account compromise, where tweets from Gizmodo were sent by the hacker.

Very few security breaches today are carried out by brute force. Most are the net results of social engineering, or end user stupidity - the breaches of Irish Department of Foreign Affairs systems by people linked to Anonymous earlier this year showed that stupidity really was the over-arching issue, with passwords such as 'Password1', which demonstrated two failures;
  1. A failure culturally within the Department of Foreign Affairs ICT to educate users about the security of ICT systems, & to ensure a clear understanding of the requirement to always operate a 'strong password' policy
  2. A failure of the users themselves to understand that given the sensitivity of information they handle from where they work, that security should always be to the forefront of their thoughts when working within ICT systems
Security breaches are often where 'hacker' opportunism meets 'end user complacency'. I have always maintained that the biggest threat to any business is not external, but at every level inside a business, even more so at executive level. Social Networking as powerful a tool as it is for good to be used by us, can just as easily be turned against us at a moments notice.

To protect you from yourself, there are a few simple steps I would recommend & suggest:
  • every time you "link" a social media account to another account or app, ask yourself "Am I really happy with this connection being made permanently? What's this company's history on security like?"
  • If you authorise an app to link to one of your social networking accounts, regularily review that connection - if you don't find yourself using it often, revoke access until it is absolutely needed again - don't leave authorisations blindly open
  • Who can view your social networking streams? How much information do the reveal about you? Perhaps the only people who should see your streams are those you know, & not the great wide world.
  • Are your personal passwords themed with your work password choices? If they are, address it immediately. 
  • Do you save passwords in your browsers, or directly in applications? If so, remove them. Then change your passwords.
  • Is your password comprised of a word with numbers, even with capitals? If so, this is hacker101 from a dictionary list. Even words where letters are replaced with numbers are straight from hacker101; i.e. 'l33t' should ring a bell with most.
  • Do you use the same password for multiple services? If so, this is a rookie mistake, & often how many online gamers accounts get compromised. Using the same password or variants of over & over is just putting you one step at a time closer to getting burned. Badly.
  • Ask yourself can anything I reveal or have revealed on my social networking sites help lead someone to one or more of my passwords? If your answer is 'yes' or 'I'm not sure', you've a problem you need to address.

Tuesday, October 25, 2011

Episode 14: Happyslapped by a Cloud Marketeer

Cloud brokers & consultants like to talk alot about 'demistifying the cloud'. There's alot of whitepapers, case studies & cloud blogs on 'what is the cloud'. Marketing people almost soil themselves in delight at the prospects of how much money they can make from some of the cloud sales campaigns they design, complete with resplendent back slapping over well-earned cocktails on a Friday evening after work.

The I.T. industry is getting drunk & high of its own spin & the slap-happy tags of 'As A Service' onto things. But recently, I do believe this merriment has gotten to the stage of 'wasted'. That point of drunkeness where even the smallest task is nigh on impossible. I'm talking about the recent love affair with 'Bring Your Own Data' being slapped on as a marketing tag. Which usually comes now with a side order of 'all you can eat data'. Now sure, 'all you can eat data' is nothing new. Anyone who's worked in telecoms has had this phrase bandied about in meetings, internal memos etc..

But, this was never a phrase much seen in marketing. It would usually appear under 'unlimited data' with an asterisk pointing to small print telling you fair usage limits applied. The actual phrase 'all you can eat data' in the cloud is being used, & being used as its considered 'disruptive' & to make it stand out from the traditional straight-edged I.T./telecoms marketing speak of 'unlimited data'.

Okay, so disruptive marketing in the current I.T. services market is nothing new. But slapping 'Bring Your Own Data' on as a marketing piece frankly just shows both how desperately stupid marketing people are about the cloud, & also how incredibly badly those in the Cloud space have been about educating their customers, & also why the cloud space is so small right now. And this really shows in our nearest trading partner, the UK.

A new survey reveals that the current cloud computing services market for UK SMBs is worth £660m. According to the region-by-region reports done by the British Government that were published in October 2010, the total number of small to medium businesses in the UK is somewhere close to the order of 4.7 million. If you were to just take a pure average on that, the survey shows SME/SMB spend on cloud in the UK is currently valued at approx. £150 per year per small company. That's barely even the cost of a few Google premium mail accounts.

Stupidity such as 'Bring Your Own Data' is not marketing people being smart, or driving business into Cloud companies. In fact, the entire prospect of what the cloud offers, whether it is PAAS/SAAS/IAAS was always based on 'Bring Your Own Data'. It is in fact a fundamental of it. Calling it BYOD is stating the bloody obvious, & fooling no-one.

For example, in an IAAS scenario, you're asking people to bring their own data to your cloud facilities, otherwise they'd be bringing their own hardware & data & it would be classed as colocation. In the scenario of SAAS services, of course they're bringing their own data - whether they are a start-up, OR an established company. The same even goes for PAAS; you're bringing your own data to plug into a platform to generate systems in the cloud.

The marketeers in the Cloud have become too drunk off their own illusions of success that they can slap 'As A Service' on things, found a new cow to milk that upon inspection, even at possibly the biggest cross section of the potential market for Cloud, even just within the UK as an example they've made a cloud market worth roughly the same as the shared hosting market four years ago (i.e. pre recession/global market meltdown).

Success? I think not. Cloud marketeers need to get their heads out of the clouds, back onto a footing of reality, & actually engage with the prospective customers. The excuse of 'people won't pay' doesn't wash. They will. People look for cheap services because there's nothing to make them see beyond the value of the cheap services. And it's really a message that is crucial right now as the world still recovers; LOOK AFTER YOUR CUSTOMERS.

Slick marketing & corny chat-up lines like 'Bring Your Own Data' are like the prawn cocktail; dated, & no-one's really buying them. Return to basics, & bring your customers along with you, & give them the value they will pay for, & get rid of silly marketeers who are damaging the growth potential of the Cloud. You'll save yourself money too in the process that you can spend properly on your customers.