Some days I feel the world will be a much easier place to live in if we simply adopt the ostrich approach. If something looks slightly challenging, let’s just stick our head in the ground for a while and the problem will simply go away.
Those of you who enjoy tracking threats, attacks, malware and the likes probably heard about the Stuxnet worm by now. For the rest of you it is malware targeting windows environments running Siemens software used by industrial companies. Once on systems, it uses Siemens default passwords to connect to the database and collect information.
Does not sound like a big deal. Nobody is using default passwords these days and even in case they foolishly did, just change the password and have a good night sleep, right?
ahmmm… unfortunately in that case I had to look for a different topic for my post…
Those of you who follow my blog know by now that I’m not really a security radical, but rather moderate and open minded when it comes to the way security specialist grasp the world. But I can tell you that this incident is mind boggling even for me.
Sin #1: using hard-coded passwords – happens from time to time, irresponsible behavior, slap on the wrist.
Sin #2: sin #1’s hard-coded passwords are the default ones and are similar for all customers – doh!
Sin #3: these passwords cannot be change (per Siemens) or the systems will stop working – what were these guys thinking? It is even worse than creating a system with no authentication mechanism at all, zip, open to the public, web 2.0 like... You communicate a FALSE sense of security that there are controls in place to secure usage of the system (i.e. authentication), yet the passwords are known to the public and cannot be changed?!
Top it with Siemens’ response (reportedly advised customers not to change their default passwords, arguing it “may impact plant operations.”), leaving customers out there in the cold having to choose between bad and worst…
There are many articles describing this incident, an example: http://tiny.cc/osg8q
I’m positive Siemens will snap out of their current state of mind and resolve it, but the unfortunate part is the fact that this phenomenon and state of mind is not limited to Siemens. Some still use hard-coded passwords, some still use default passwords and some don’t change passwords.
It is time to GET BACK TO THE BASICS!
1. Authentication between systems should be externalized and governed by processes/tools that can rotate and secure credentials.
2. Default passwords might be good for the initial bootstrap/setup procedure, however should be changed and should definitely be unique per customer
3. There are tools designed to address the whole privileged accounts challenge regardless whether it is performed by humans or non carbon based entities (such as application, services, or devices).
Unlike the common belief that vulnerability of internal, powerful credentials are a target for internal threat only, the reality is privileged accounts are a gem for external attackers. More frequently than you imagine external attacks target these powerful accounts, as hijacking these accounts makes external hackers’ life/job much easier.
Next week is Burton Group’s Catalyst week, stay tuned for my take-aways/insights from the conference and sunny San Diego!
Friday, July 23, 2010
Tuesday, July 20, 2010
The Jerry Maguire take on Security
I have a strong feeling this post is going to be my Jerry Maguire’s “Mission Statement”…
A couple of comments for those who have not seen the movie:
1. Keep reading as watching the movie is not a prerequisite
2. You should probably consider watching it, it has some funny quotes
A recap - Jerry Maguire is a 1996 film starring Tom Cruise about a sports agent who has a moral epiphany and is fired for expressing it, who then decides to put his new philosophy to the test as an independent with the only athlete who stays with him (Wikiquote.org - http://tiny.cc/sqj8p).
My case is obviously different: it is not so much an epiphany but rather some thoughts/insights, and the whole firing part???
Despite the many changes the security community experienced, one thing seemed to stick with us throughout the years (especially as compliance has been bolted on to security) – FEAR.
If we’ll scare them they will come!
Fear as a way of thinking about the challenges, fear as a design criteria, fear as a way to prioritize features, fear as a driver for pricing, and certainly fear as a selling tactic.
It is kind of a negative way of thinking, don’t you think?
Recently I have participated in the Enterprise 2.0 conference. Surprisingly these guys approach issues differently, on the verge of a Woodstock atmosphere. It is all about collaboration, opening up the organization, loosing controls, doing good for everyone (rainbows and violin background music…). Almost too much positive thinking for me…
In the audience I could notice quite a few CIOs, most of which participate in our (security) conferences as well. It simply mind boggling what is going through their minds when they hear both enterprise 2.0 and security pitches. The contradiction is simply amazing.
So who has it right?
Are we right and they are naïve, or they have it right and we are simply afraid?
As with most things, I believe the truth is somewhere in between.
You would rightfully say organizations spend their security budgets addressing threats. And Rod Tidwell’s immortal motto is probably correct (from the movie of course): “Show me the money!” security vendors should continue addressing these threats and fears. Hey, this is our thing and we should keep on doing it.
However I still believe there is a place for positive thinking in our domain (security). The infrastructure play and information our security systems are exposed to can be leveraged for positive spins. Topics such as increase awareness, productivity and reduce cost can all be addressed.
Just a few simple examples (I’m keeping the real interesting ones for internal usage…):
1. While monitoring usage of applications the system can recommend (potentially even automate) adding the more popular apps under the SSO umbrella.
2. As we monitor behavioral patterns for fraud detection we can contribute to optimize web applications increasing productivity and reducing cost.
3. During the access control to unstructured data we can identify usage frequency and suggest lower cost storage for hardly used documents or “cache” more frequently used data.
4. And even small frustrating thing as laptop’s startup time can be improved as application usage is monitored, we can identify hardly used apps/services and remove them from the startup sequence.
Can you imagine positive thinking can become a differentiator in the security domain?
Do you believe customers will actually be willing to spend their security $$$ on positive things?
A couple of comments for those who have not seen the movie:
1. Keep reading as watching the movie is not a prerequisite
2. You should probably consider watching it, it has some funny quotes
A recap - Jerry Maguire is a 1996 film starring Tom Cruise about a sports agent who has a moral epiphany and is fired for expressing it, who then decides to put his new philosophy to the test as an independent with the only athlete who stays with him (Wikiquote.org - http://tiny.cc/sqj8p).
My case is obviously different: it is not so much an epiphany but rather some thoughts/insights, and the whole firing part???
Despite the many changes the security community experienced, one thing seemed to stick with us throughout the years (especially as compliance has been bolted on to security) – FEAR.
If we’ll scare them they will come!
Fear as a way of thinking about the challenges, fear as a design criteria, fear as a way to prioritize features, fear as a driver for pricing, and certainly fear as a selling tactic.
It is kind of a negative way of thinking, don’t you think?
Recently I have participated in the Enterprise 2.0 conference. Surprisingly these guys approach issues differently, on the verge of a Woodstock atmosphere. It is all about collaboration, opening up the organization, loosing controls, doing good for everyone (rainbows and violin background music…). Almost too much positive thinking for me…
In the audience I could notice quite a few CIOs, most of which participate in our (security) conferences as well. It simply mind boggling what is going through their minds when they hear both enterprise 2.0 and security pitches. The contradiction is simply amazing.
So who has it right?
Are we right and they are naïve, or they have it right and we are simply afraid?
As with most things, I believe the truth is somewhere in between.
You would rightfully say organizations spend their security budgets addressing threats. And Rod Tidwell’s immortal motto is probably correct (from the movie of course): “Show me the money!” security vendors should continue addressing these threats and fears. Hey, this is our thing and we should keep on doing it.
However I still believe there is a place for positive thinking in our domain (security). The infrastructure play and information our security systems are exposed to can be leveraged for positive spins. Topics such as increase awareness, productivity and reduce cost can all be addressed.
Just a few simple examples (I’m keeping the real interesting ones for internal usage…):
1. While monitoring usage of applications the system can recommend (potentially even automate) adding the more popular apps under the SSO umbrella.
2. As we monitor behavioral patterns for fraud detection we can contribute to optimize web applications increasing productivity and reducing cost.
3. During the access control to unstructured data we can identify usage frequency and suggest lower cost storage for hardly used documents or “cache” more frequently used data.
4. And even small frustrating thing as laptop’s startup time can be improved as application usage is monitored, we can identify hardly used apps/services and remove them from the startup sequence.
Can you imagine positive thinking can become a differentiator in the security domain?
Do you believe customers will actually be willing to spend their security $$$ on positive things?
Friday, June 25, 2010
Gold Rush – The return of the King
5:45pm – just as I was planning to head out to the Apple store I get the following alert:
SEVERE THUNDERSTORMS PRODUCE DAMAGING WINDS AND LARGE HAIL... AS WELL AS DEADLY LIGHTNING AND TORRENTIAL RAIN. GET TO SAFE SHELTER NOW... INSIDE A STURDY BUILDING OR IN A VEHICLE. DO NOT SEEK SHELTER UNDER TREES. IF YOU CAN HEAR THUNDER... YOU ARE CLOSE ENOUGH TO BE STRUCK BY LIGHTNING. DRIVERS SHOULD BE ALERT FOR PONDING OF WATER AND AVOID FLOODED ROADS.
A SEVERE THUNDERSTORM WATCH REMAINS IN EFFECT UNTIL 800 PM EDT THURSDAY EVENING FOR NORTHERN CONNECTICUT AND MASSACHUSETTS AND SOUTHERN NEW HAMPSHIRE AND CENTRAL RHODE ISLAND.
You got to be kidding me!
If you really think a deadly thunderstorm storm will hold me back from getting the prize, then think again.
6:10pm got to the store (still alive) only 5 people in line (all with pre-orders or tickets). This obviously proves that you get a better treatment if you are invited to the party…
7:00pm returning home as a winner, I’m probably looking at a romantic evening where together each one is busy updating his new iPhone…
Not sure what the big excitement is all about – after all it is just a phone (and an ipod and an email device and an app platform probably the coolest gadget around…)
I have finally figured out the name “iPhone 4”, looks like you have to wait 4 hours to get an iPhone…
Thursday, June 24, 2010
Gold Rush
I have finally decided to walk the walk and make the commitment. Despite the nasty mother in law (AT&T) I’m getting an iPhone 4.
For the first time in my life I’m going to actually wake up early, stand in line and on the premiere be one on the lucky ones (as well as additional 1M people) to have the new majestic device!
So this is how it went (so far):
5:40am – woke up (going to get the iPhone 4 today, YEAH!)
5:55am – reports on the internet: already long lines (still optimistic)
6:15am – the Dinoor team is out on the road (cautiously optimistic)
6:20am – Dunkin Donuts, and we are ready for the action (carbs are always good for the spirit)
6:25am – the parking lot is half full, at 6:25 in the morning!? (Um, Oh...right)
6:30am – finally standing in line, practically at the mall’s entrance with probably 200-300 people in front of us (it is going to be a long day)
7:01am – we are moving! Actually the other line (pre-order) is moving (shall I cut my losses here and now, i.e. leave?)
7:30am – made 10 feet progress and rumors has it the pre-order line is getting in first (50:1 ratio between the lines)
8:45am – nothing (let’s pack our thing and leave, such a looser…)
9:00am – there is a God up there, I have made it! I’m the proud owner of a … ticket assuring me an iPhone (the line is still long, but who cares?)
9:15am – leaving the scene as a winner, I’ll be back later on tonight to pick it up
Stay tuned for more on how the saga ends!
Monday, June 21, 2010
Worth Repeating
I find myself quite often quoting expressions I hear at different places. Surprisingly people seem to enjoy it and even (God forbid) use it at later times...
As an entertaining exercise, I’m going to post these valuable quotes from time to time at the “Worth Repeating” section on the right (keep scrolling down).
To kick it off I’m going to start with a few I’ve heard recently:
1. “Security is like life insurance, you only win when you lose” Dr. Rainer Janßen, Munich Re CIO, EIC 2010, Munich May 2010
2. “The cloud is cloudy, not transparent” someone at EIC 2010, Munich May 2010. While discussing Cloud and security concerns
3. “The bits move faster than people, make sure to bring the people with you” Sanjay Mirchandani, (EMC CIO), EMC World, Boston May 2010. While discussing the journey to the cloud.
4. “The technology market is definitely accelerating - it took IBM 40 years to become the evil, Microsoft 25, Google 10, Facebook 5 and Twitter 2.5” JP Rangaswami, Enterprise 2.0 conference, Boston June 2010
Enjoy!
As an entertaining exercise, I’m going to post these valuable quotes from time to time at the “Worth Repeating” section on the right (keep scrolling down).
To kick it off I’m going to start with a few I’ve heard recently:
1. “Security is like life insurance, you only win when you lose” Dr. Rainer Janßen, Munich Re CIO, EIC 2010, Munich May 2010
2. “The cloud is cloudy, not transparent” someone at EIC 2010, Munich May 2010. While discussing Cloud and security concerns
3. “The bits move faster than people, make sure to bring the people with you” Sanjay Mirchandani, (EMC CIO), EMC World, Boston May 2010. While discussing the journey to the cloud.
4. “The technology market is definitely accelerating - it took IBM 40 years to become the evil, Microsoft 25, Google 10, Facebook 5 and Twitter 2.5” JP Rangaswami, Enterprise 2.0 conference, Boston June 2010
Enjoy!
Thursday, June 17, 2010
ShaaS
Regardless of what people might say, the recent couple of years were great for the technology industry. We (technologists) exhausted the 3 and 4 letter acronyms, and at some point just when we thought 5 letters is the new 3 letter a miracle has happen.
The CLOUD was created enabling us to cloud wash everything by simply adding “aaS” as a suffix. This allowed us to start all over again with the 1-2 letters game.
As you can see I’m no different than the rest. So what is ShaaS (used in the title) all about? Is it simply Shlomi as a Service? Better guess again…
It is actually Sharing as a Service. A lot was said and written about collaboration and sharing of data but despite the chatter, solutions have not addressed some of the key challenges.
I’ll focus just on one of these challenges - modern collaboration and data sharing are dynamic by nature and cannot be controlled by static policies/controls.
Let’s follow a use case (as an example) – sharing a document with a group of people. The team can access the file, download it, read it, etc. But what happens two weeks from now when something has changed and I want to stop sharing the file with some members of the team? Using existing information protection techniques (such as DLP or DRM) will not allow me to do it as the file is already in possession of these people. Even if it was wrapped by some type of a shell (in the case of DRM), it is based on a static, outdated policy.
It is true Enterprise 2.0 guys say (rightfully) organizations should design for loss of control (including over data) as web 2.0 penetrates the enterprise. However while organizations promote sharing/collaboration they should protect their sensitive data.
Another interesting phenomenon is the different approach to data by enterprises and consumers. While the enterprise default is “secure first then ask questions”, for consumers it is all about sharing (security? privacy? No one cares!). It looks like consumers treat data as almost nonexistent unless it is shared.
It will be interesting to see a TTS (“Time To Share”) graph over time (i.e. time from actual event to when it is shared). I’m willing to bet TTS has dramatically gone down and is currently very low.
Evolution:
1. In the past one would take photos of an event, download it to the computer, upload it to your favorite social networking tool and share it with a selected audience.
2. Then it seems all devices introduced direct social networking posting capabilities.
3. Next using telepathy capabilities, thoughts will be automatically posted.
4. And finally, the ultimate sharing tool – the Twitter generator. Based on my interests and real events will automagically generate tweets in real-time (on my behalf). I will be perceived extremely smart, how cool is that?
The reality is probably somewhere in the middle, sharing of data is fundamental for the business, yet should be controlled to protect the business. Information protection systems should be morphed with data sharing tools taking its dynamic nature into consideration.
While I leave you with this, I’ll go back to think how to make Shlomi as a Service a viable business…
The CLOUD was created enabling us to cloud wash everything by simply adding “aaS” as a suffix. This allowed us to start all over again with the 1-2 letters game.
As you can see I’m no different than the rest. So what is ShaaS (used in the title) all about? Is it simply Shlomi as a Service? Better guess again…
It is actually Sharing as a Service. A lot was said and written about collaboration and sharing of data but despite the chatter, solutions have not addressed some of the key challenges.
I’ll focus just on one of these challenges - modern collaboration and data sharing are dynamic by nature and cannot be controlled by static policies/controls.
Let’s follow a use case (as an example) – sharing a document with a group of people. The team can access the file, download it, read it, etc. But what happens two weeks from now when something has changed and I want to stop sharing the file with some members of the team? Using existing information protection techniques (such as DLP or DRM) will not allow me to do it as the file is already in possession of these people. Even if it was wrapped by some type of a shell (in the case of DRM), it is based on a static, outdated policy.
It is true Enterprise 2.0 guys say (rightfully) organizations should design for loss of control (including over data) as web 2.0 penetrates the enterprise. However while organizations promote sharing/collaboration they should protect their sensitive data.
Another interesting phenomenon is the different approach to data by enterprises and consumers. While the enterprise default is “secure first then ask questions”, for consumers it is all about sharing (security? privacy? No one cares!). It looks like consumers treat data as almost nonexistent unless it is shared.
It will be interesting to see a TTS (“Time To Share”) graph over time (i.e. time from actual event to when it is shared). I’m willing to bet TTS has dramatically gone down and is currently very low.
Evolution:
1. In the past one would take photos of an event, download it to the computer, upload it to your favorite social networking tool and share it with a selected audience.
2. Then it seems all devices introduced direct social networking posting capabilities.
3. Next using telepathy capabilities, thoughts will be automatically posted.
4. And finally, the ultimate sharing tool – the Twitter generator. Based on my interests and real events will automagically generate tweets in real-time (on my behalf). I will be perceived extremely smart, how cool is that?
The reality is probably somewhere in the middle, sharing of data is fundamental for the business, yet should be controlled to protect the business. Information protection systems should be morphed with data sharing tools taking its dynamic nature into consideration.
While I leave you with this, I’ll go back to think how to make Shlomi as a Service a viable business…
Monday, May 17, 2010
The Shlomi Cloud!
Facebook owns my photos, Google owns my emails/documents/contacts, LinkedIn owns my network, Delicious owns my favorites, and even my real URLs are not in my possession (but by the Tiny URLs of the world)…
Did I totally lose it?
I recently read about a new startup offering us to manage all our social networking sites from one place. Finally you can move pictures from Picasa to Facebook and then to Google docs, all from a single location. Kind of nice, right? While it is probably very useful (haven’t tried it yet), I say - not another aggregator please!
Instead I want to use a hub and spoke model and have my own Shlomi cloud (clouds are exceptionally trendy these days) where I own/control/manage/store eeevvvverything.
I can define my network (tree/forest of relationships) in one place and carry it (or a subset of it) with me to different social network sites (today to Facebook or LinkedIn, and tomorrow to the next big thing).
I can store all my photos, documents, etc. and delete them whenever I want, knowing no zombie copies are floating in the WWW wilderness.
I can create my personas and manage them, deciding which persona to present and when.
And all the great social networking sites can focus on the services they provide while referencing my identity from the Shlomi Cloud.
What do you think? Is it time to start the MyPersonalCloud.org movement, where everyone can create, own and control his own piece of identity?
Did I totally lose it?
I recently read about a new startup offering us to manage all our social networking sites from one place. Finally you can move pictures from Picasa to Facebook and then to Google docs, all from a single location. Kind of nice, right? While it is probably very useful (haven’t tried it yet), I say - not another aggregator please!
Instead I want to use a hub and spoke model and have my own Shlomi cloud (clouds are exceptionally trendy these days) where I own/control/manage/store eeevvvverything.
I can define my network (tree/forest of relationships) in one place and carry it (or a subset of it) with me to different social network sites (today to Facebook or LinkedIn, and tomorrow to the next big thing).
I can store all my photos, documents, etc. and delete them whenever I want, knowing no zombie copies are floating in the WWW wilderness.
I can create my personas and manage them, deciding which persona to present and when.
And all the great social networking sites can focus on the services they provide while referencing my identity from the Shlomi Cloud.
What do you think? Is it time to start the MyPersonalCloud.org movement, where everyone can create, own and control his own piece of identity?
Subscribe to:
Posts (Atom)

