Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Tuesday, August 7, 2012

Episode 22: When the rain from the cloud is just your tears

The tale of Mat Honan's remotely wiped Apple products has now been committed to the lore of the Internet. But this tale as with any comes with a proviso that has long been the anchor of the 'superhero' story; "With great power comes great responsibility." Our reliance on technology as the super-hero in our modern life has set us up for spectacular falls, akin to any great fallen-hero story-arch.

We have great power in our hands with our smart phones, mobile devices, cloud-enabled hand-held & remote technologies, & yet we wield these powers with little to no real responsibility. Mat Honan originally supposed that his accounts were brute force attacked (something he later retracted), but days later we learn they weren't. He was the victim of social engineering; the attackers rang Apple support, managed to pass through their security protocols due to "Apple's centralised single user account approach."

Blaming Apple is easy, but the fact is we are seeing further centralisation of our online lives with more & more of our accounts & services being linked together via our Twitter, OpenID or Facebook accounts. Each node we link in this way just increases our vulnerability. With security compromises of user databases on the rise, our entire 'digital life' faces compromise from any one of the countless services we interlink.

But that's not even the bigger risk. Publicising information about ourselves in such a carefree manner on social networking sites gives 'hackers' (calling them this when we make it this easy for them denegrates those who are 'real' hackers) less work to do when searching for information to use against us in a social engineering scam, when they wish to target someone.

The real threats as a result of our digitalisation is not our own personal Twitter, Facebook, LinkedIn, or Tumblr accounts - the real risk is our employers, & our businesses. As we increase the drive towards BYOD, our personal & business accounts become increasingly intermingled, something Honan discovered when his employer Gizmodo experienced as part of his account compromise, where tweets from Gizmodo were sent by the hacker.

Very few security breaches today are carried out by brute force. Most are the net results of social engineering, or end user stupidity - the breaches of Irish Department of Foreign Affairs systems by people linked to Anonymous earlier this year showed that stupidity really was the over-arching issue, with passwords such as 'Password1', which demonstrated two failures;
  1. A failure culturally within the Department of Foreign Affairs ICT to educate users about the security of ICT systems, & to ensure a clear understanding of the requirement to always operate a 'strong password' policy
  2. A failure of the users themselves to understand that given the sensitivity of information they handle from where they work, that security should always be to the forefront of their thoughts when working within ICT systems
Security breaches are often where 'hacker' opportunism meets 'end user complacency'. I have always maintained that the biggest threat to any business is not external, but at every level inside a business, even more so at executive level. Social Networking as powerful a tool as it is for good to be used by us, can just as easily be turned against us at a moments notice.

To protect you from yourself, there are a few simple steps I would recommend & suggest:
  • every time you "link" a social media account to another account or app, ask yourself "Am I really happy with this connection being made permanently? What's this company's history on security like?"
  • If you authorise an app to link to one of your social networking accounts, regularily review that connection - if you don't find yourself using it often, revoke access until it is absolutely needed again - don't leave authorisations blindly open
  • Who can view your social networking streams? How much information do the reveal about you? Perhaps the only people who should see your streams are those you know, & not the great wide world.
  • Are your personal passwords themed with your work password choices? If they are, address it immediately. 
  • Do you save passwords in your browsers, or directly in applications? If so, remove them. Then change your passwords.
  • Is your password comprised of a word with numbers, even with capitals? If so, this is hacker101 from a dictionary list. Even words where letters are replaced with numbers are straight from hacker101; i.e. 'l33t' should ring a bell with most.
  • Do you use the same password for multiple services? If so, this is a rookie mistake, & often how many online gamers accounts get compromised. Using the same password or variants of over & over is just putting you one step at a time closer to getting burned. Badly.
  • Ask yourself can anything I reveal or have revealed on my social networking sites help lead someone to one or more of my passwords? If your answer is 'yes' or 'I'm not sure', you've a problem you need to address.

Monday, November 14, 2011

Episode 15: The one where Ireland leaves the front door unlocked

Ireland is at an incredible juncture in its history. Our national debt is of gargantuan proportions, we're in a harsh period of austerity, & the real economy is on the verge of complete collapse with barely any growth, & things are looking to only get worse for the citizens. Our exports however are the only thing that's saving our bacon. Richard Bruton, the Minister for Jobs, Enterprise & Innovation stated last month in the Dail that "Ireland is well placed to exploit opportunities in new sectors such as Cloud Computing & Digital Gaming, Life Sciences & Clean-tech". He went further to state that "Ireland’s services sector continues to grow & in 2010 accounted for 45.3 per cent of total exports."

One of the growing areas of concern in the tech sector continues to be security. Major gaming hubs from Sony, Nintendo, Enix, Sega Pass, Nintendo & Steam have in recent months come under attack to be compromised, as have Nokia, The Sun, CitiBank to name but a few. When you look through the major gaming names previously mentioned, you realise that these guys are in the top tier of that sector, & with their millions, they got their security totally wrong.

If we're going to engage digital gaming as a means to increase our exports alongside cloud computing, we must place an incredible amount of attention on us having a strategy for cyber security in Ireland. In the area of cloud computing, as each market around the world begins the embrace, the first question is always around security, & it continues to be a question even in further developed cloud computing markets.

Ireland is one of the more mature markets for cloud. The sales penetration levels wouldn't tell you that, but it is much further along over four years later from when Ireland's first indigenous cloud computing provider entered the market. Back then, security was a huge issue, & there was alot of scaremongering about the security of the cloud versus traditional managed or collocated I.T. infrastructure services. So, with the market being more mature & over a hundred cloud computing services providers in Ireland, the tech exports market being so crucial to our economy  you'd assume Ireland had a cyber security strategy already in place.

You'd be wrong. According to a question posed by Clare Daly last week to Pat Rabbitte, our Minister for Telecommunications, Energy & National Resources, that framework document doesn't yet even exist. His department are only in the process of developing it for publishing some time in 2012. We're hedging our survival as a country on I.T. services, & the digital economy & we have absolutely no framework as a country on the single biggest threat & concern to that sector?

Coincidentally, my collegue over at CloudBook, Thu Pham, wrote a great article about the concerns of security in the Cloud for SMB's (or, SME's to us in Ireland). While this article does discuss things from a US market standpoint, we're trying to attract US cloud market players to Ireland. So this does provide some viewpoint into what kind of market expectations these players have to work in back home.

Yes, you could revert to type & cast that off as a typically Irish response to a problem, & that it is the same slip-shod approach that was taken to our banking sector; "we'll worry about those problems after the fact." But that's not acceptable. It can't be. If we're spending huge resources on trying to attract direct foreign investment from technology based services companies, positioning Ireland to take advantage of cloud & digital gaming opportunities, this legislation must be of absolute priority.

Four years ago under the previous government, the question was asked about the Irish Governments shift to cloud computing, & the then-Minister for Communications, Eamon Ryan stated that only one department had engaged in looking at a virtualisation or cloud computing strategy so far, & that was his own department. It may be of interest to know that Cloud Computing has been part of Dail discussion 37 times since this present administration has come to power. In seven months, that is approximately five times a month without an exclusion on parliamentary breaks. Thirty seven discussions, with no sign or mention of a government strategy for Cloud Computing to address the costs & inefficiencies of the Government I.T. infrastructure.

There has also been no real approach made to the Cloud Computing industry in Ireland by Government. Discussions behind closed doors with the big five about direct foreign investment don't count. They're not the real players. Had the Government made approaches to companies like Hibernia-Evros, Network Recovery (who recently achieved ISO certification on their cloud), SunGard AS Ireland, DigiWeb, DediServe, DEG-Telecity-Redbus (recent merger of Telecity Redbus & DEG), Eircom, or the any of the other players, any of these players would have made alot of PR hay from the opportunity without any hesitation.

There needs to a proper industry working group, which would help understand the size of the Irish Cloud Computing market, its potential value to the Irish economy from service exports, & its potential for growth, market penetration & adoption throughout the business chain. This group needs to work with the department of trade, the department for public finance & expenditure, as well as the department of communications to help it understand what is needed from a national cyber strategy.

Ireland asked & got its change of leadership earlier this year, it is now time that changed leadership acted like leaders, instead of dithering like a deer in the headlights, reach out to  those in the Irish Cloud market, reach out to those in the Digital arts markets (gaming/entertainment etc.), form some proper advisory working groups, & get on with helping to make the push behind a group of industries that form the tech sector that helps support our exports to allow us to fix our real economy, or are they going to continue to bet the farm on those who will move at a moments notice for tax & cost sakes premiums?