Friday, August 2, 2013

REVIEW: RVAsec 2012 - Software Security: A Waste of Time?



RVAsec 2012 - Software Security: A Waste of Time?

https://www.youtube.com/watch?v=vtGXgRQXE4k

This is a presentation at a security conference covering the value of the Microsoft SDL.  He shows that some measurements are not necessarily valid, but comes out believing that the Microsoft SDL is definitely worthwhile, whatever the net impact on vulnerabilities, as it is a more proactive approach rather than a reactive one.

He recommends running all freely available fuzzing tools against your system since someone will eventually do that and you may as well catch things before they do.  He recommends reviewing the SANS Top 25 App Security vulnerabilities annual list.  A question is asked at the end about applying the SDL to agile, but he basically says “it’s hard” and “work through things” rather than providing much clear guidance.

Thursday, January 24, 2013

It is a Dangerous World

I was fighting off the flu along with some personal business during much of the Java hoopla, but it reminds me that we live in a very dangerous world.  I suspect we will find that all kinds of core tools have major flaws in them.

Some of this is because most development is not done with security in mind, even in organizations where that is supposed to be a priority.  Getting things working and out the door is far more important in many cases.  This is logical since that is how money is made, but it is ultimately dangerous since it is also how money can be lost.

Though the lost money often comes at the expense of others, so the risk is not properly applied in that sense, making for somewhat perverse incentives.

It is like the credit card brands pushing the issues of compliance on card processors instead of providing a much more secure structure themselves.

I don't see any good solution to this.  A recent article made a good point that we cannot stop using the technologies that have enabled the productive use of modern technologies.  The challenge is going to be figuring out how to do so in spite of such flaws.

Friday, November 23, 2012

Don't Plan Because You are Uncertain?

Don't plan for uncertainty until you are certain:

http://www.csoonline.com/article/721150/certainly-uncertain

This humor comes too close to reality in many organizations.

The CISM

I never did post a note here that I finally got all the paperwork in for the CISM.  I passed the test a while back, but it took a bit to follow up with the paperwork.  One challenge I see is that it is much more limited about what will qualify for CPEs. 

I listen to a lot of podcasts and while the CISSP allows those, the CISM appear to not count them.  Going and sleeping through a conference is fine as long as you have the piece of paper at the end.  I will have to keep my eye out for valid outlets to keep this updated.  Fortunately it looks like the classes I teach will help, so I may not have as hard a time as it seemed at first.

Congress is not Always the Solution

Good thoughts in the latest Salted Hash commentary.

http://blogs.csoonline.com/security-leadership/2458/dear-congress-please-keep-your-dirty-hands-cybersecurity-email-privacy

The danger is that so many fail to realize that things like this have great potential for abuse, especially of those with low personal restraint.  Anything could become a national security issue and could justify spying.  It is quite dangerous to trust government to protect us in all areas.

Monday, January 2, 2012

Quality Software is Secure Software

The focus on software development is usually getting the system completed on time and hopefully at or under budget.  Some organizations may even add a requirement that few known bugs may ship with the product, though the amount of testing and validation of that can vary greatly.

The security of those systems usually comes some position after that, especially if the organization doesn't have a regulatory requirement for that.  In fact, even those organizations may only pay lip service to the need for secure software until they face a breach of their own.

Much of that is driven by business needs.  The eyes of the leaders is on profit and loss (as it should be) and the new system needs to be available to help with the profit of raising income for the company.

This is as it should be, since a company without income and profits will soon be out of business, but it minimizes the impact of defects and security flaws on the business.  Some organizations are starting to understand that defects can be costly, but only a few of those realize that security flaws are just another kind of dangerous defect.

Realizing this would help make educating people about the value of preventing or quickly fixing defects or security flaws more effective since only one message would need to go out.

Saturday, December 24, 2011

I Passed the CISSP!

I just found out that I passed the CISSP exam I took several weeks ago!  I was surprised, but this turned out just like my CISM exam.  I thought I failed that too, but now I have the key information security certification under my belt to go with all the other hands on ones I have completed!

Tuesday, November 22, 2011

FIrst CISSP Attempt

I am often too much of a perfectionist and while I have passed several SANS certification tests and even ISACA's CISM test, I kept waiting to tackle the CISSP until I thought I knew enough. I finally decided to sign up for it a little more than a month ago, figuring I could retake it if needed. I suspect I will need to do so as several of the questions on the test were nothing like the material I jammed into my head in the last few weeks, in addition to all my hands-on time prior to that. I am annoyed that I even missed a PCI question that I should have known better on. Overall, a quite annoying test. Annoying in a different way than the CISM, but annoying nevertheless. I did feel I failed that when I took it, so perhaps the outcome will be better, but I won't know for a couple of weeks.

Thursday, October 27, 2011

How Greedy and Stupid Can You Get?

I knew it before, but I am finally digging through the latest Shon Harris' CISSP book. Instead of going with the standard Confidentiality, Integrity and Availability, the book calls it Integrity, Confidentiality and Availability (ICA). I suppose this is so they can trademark the term. How stupid. I suppose we are going to see the CPT-PI soon (Control Protocol for Transport - Protocol Internet).... Some smart people in the security training business, but too worried about locking off their own material and not enough about producing excellence. I guess that's what happens when you become a bunch of prima donnas. I have seen similar stupidity in many places.

Wednesday, September 7, 2011

I attended the Dallas OWASP meeting earlier today. Charles Henderson from Trustwave was talking about their data breach report for 2010. Some notes I took with my comments: - Attackers are continually looking for the weakest link. Should be obvious, but we always need to keep this in mind. - Organized crime doesn't trust each other. This means they often use strong security in their own work. How ironic. - Attackers will normally try to use the existing infrastructure to get compromised data out of the organization and back to their control. - More targeted attacks today. Example given: Sally is pregnant. Attacker finds her direct reports, sends "baby pictures" about the time she is due. This is a very targeted phishing email. We still need to be very cautious, even with "expected" email. - Attacking requires customization today. Too many automated tools can find the "easy" stuff. - One wireless attack is to setup a wireless access point that a laptop with a hard connection to an internal network will automatically connect to. This could end up with a wireless connection directly into the "protected" network. I wasn't clear if the names of these potential WAPs can be learned from the traffic the laptop sends out or not. I will need to investigate this more. - The less you know about a device, the more you are likely to trust it. Very interesting. We will press "ok" the less certain we are. Scary.

Tuesday, August 9, 2011

Steganography Hits the Big Time

An attacker has to figure out how to get information out of machines they have compromised. DLP filters sometimes work against this, though merely sending the data out in some fashion has a strong chance of providing a warning of the compromise.

Thus attackers are staring to use steganography to get data out of compromised computers.

Scary.

Wednesday, July 6, 2011

Android Security Flaw

I recently had to adjust the settings on my Android phone to allow applications from "any source" so I could get some downloads from Amazon. While Amazon has complete instructions on how to do that and it frees me from only using the Android Store, why do I need to totally remove the limits to do so?

A better design would be to allow me to have a limited set of sites that could install applications on the phone, limiting installations to only those sites. Then I could add Amazon to the "approved list" and keep a lot more security without opening the barn door for anyone to walk in.

I would report this somewhere, but it is not clear at all where to do so. A search for "android feedback" just takes you to a Google page to give feedback on their market, without any ability to add comments. Not very helpful.

Thursday, December 16, 2010

Compliance or Information Security

Some in the information security field argue that compliance requirements like PCI and SOX are ultimately harmful to true information security, since it places so much of the focus on just meeting the requirements, rather than on really being secure.

While this may be true for a limited number of organizations, I am convinced that that most companies that only take a "checkoff" approach to these regulations would not have strong overall information security efforts even if the compliance requirements did not exist. In fact, I suspect that many of them would be doing much less in the area of information security.

I did have someone state that PCI worked against true security at one point, though I can't remember the precise argument now. I wasn't convinced then nor am I now. Some of the specific requirements may be squirrely, but the overall direction is great.

I do believe an organization with a strong information security practice would not have problems meeting related regulations. They may have to do a few more things, but strong information security will already be dealing with the related concerns.

I am not sure such an organization exists though, so this may just be a pipe dream!

Tuesday, November 30, 2010

Defense Has Value

It is quite common to here "defense is dead" when thinking of information security today. This trite phrase has some truth, but is also off target in some ways.

The idea of defending a single point and being "secure" is definitely dead, though it was really never alive in the first place.

The idea of improving defenses to the point that your network or enterprise is harder than others to attack is a worthwhile effort and remains quite alive.

Work on improving your defenses. Don't stop because a vendor promises a tool that is a "completely new approach". Solomon really was right, even when applied to information security. "There is nothing new under the sun." :)

Brad

Are the Threats Really Different?

I am currently watching a webinar about the current Internet threats. One thing that immediately jumps out to me is that it doesn't really seem all that different, just more of the same. We aren't watching actions on the systems with sensitive data sufficiently.

Everyone still wants a silver bullet, a single chokepoint where we can put defenses and relax. While this would be a great thing to have, it doesn't exist and we need to clue in and realize that.

This truth has been around for a long time, we are just now realizing it. It is quite common to hear "perimeter defense doesn't work anymore," but I am not sure it ever really did. It just blocked some low-level threats, which "worked" without really solving the problem. The low-hanging fruit is always going to be the simplest and easiest. What we consider "low-hanging" varies over time. Thus we will always be strengthening things, but it ultimately comes back to the same thing: Protecting systems with access to sensitive data. The methods will get better over time, Avoid mere vendor hype, realize this is a fact of our lives in the information security field.

Tuesday, November 23, 2010

Getting People to Think Securely

One of the most enjoyable parts of my previous work for a large airline was working on the security awareness efforts. While it was not as large as I would like, I did get to write up a monthly mini-article/hint/tip and I enjoyed finding ways to use real-life things to help readers be more secure in the things they did.

This did take more time than I think many realized and writing effective communications is often more like creating art than performing an engineering task. Finding the proper "muse" to express a meaningful point in the allowed space is a major challenge.

I would encourage all organizations that do not have any awareness efforts to at least start copying or creating some basic awareness articles. SANS has some great tips as do other sources.

Even small tips helping employees be safe in their own computer use can flow over to the workplace and make everyone more secure!

Brad

Sunday, August 1, 2010

Viewing Information as an Asset

One of the most important principles underlying effective information security is to get those involved to see information as a valuable item. Even those of us who know this have to actively work to keep ourselves properly focused on this basic fact.

It is easy to get caught up with the methods and practices and forget the reason for what we are doing. The methods and practices are very good and necessary, but we need to make sure they are properly scaled (effort/cost/etc.) to the information they are aimed at protecting!

Saturday, May 15, 2010

Learning Security and the iPad

I just purchased an iPad. You can see some quick comments in my companion blog here, but I wanted to comment in this blog about the interesting potential the iPad has for me as a learning tool, including in the field of information security. Its form factor makes it much easier to take with you or view in places a traditional computer or even laptop would not be as comfortable. I hope to be producing some tools, videos and other neat stuff in this area in the future. :)

Brad

Thursday, March 18, 2010

The Value of Certifications

I see two basic camps in the security realm when it comes to certifications.

The first would include those with an alphabet soup behind their name. CISSP, CISM, CISA, GSEC, GIAC, GSE, CEH, CCNA, CCIE, etc. I suspect I could keep typing for days and not list them all. Organizations that promote these will definitely push that they add value and validate that the holder knows something of value to an organization and is worth more. This may or may not be true, but certifying organizations do make a substantial income on people maintaining their certifications, so they definitely have a vested interest in believing that certifications are valuable and promoting them.

I would note that I am not convinced that certifications are always a cash machine, but they do fund the employment of many people, so the amounts are significant. Those people are probably needed for solid certification programs. This means that large sums are involved in the process, whether or not those involved make a lot of money personally.

The other end of the spectrum argues that certifications are completely worthless and work experience is all that matters. They often look in disdain on those with certifications. They tend to view certifications as creating "paper tigers," people who can pass a test, but who don't really know much practically. I suspect having a certification is a bad thing if one of these people is in charge of the hiring process.

What spurred me thinking on this again was an OWASP podcast with Mark Curphy. (Yeah, I am a little behind - the show was from last July.) He expressed the second view and seemed to disdain certifications in general.

I am more in the middle of both camps and see merit in both positions. I have personally acquired many certifications because I felt like it, not because I wanted some letters to add to my name. Even though experience is still more valuable, I would rate my M.S. in C.S. from Illinois as more valuable than them all (along with a B.S. in C.S. from their Engineering College) as far more valuable, since it laid a firm groundwork for all the many things I have dug into.

That said, my certifications, especially the SANS ones I hold (GSEC, GCFW, GCIH, GCIA, GPCI) helped me really master the material in this area. My background is more in programming/development than system administration, so having to have studied the material for those courses has helped me absorb a lot more than I would have with just reading a book. Of course I need to put things to practice, but that is true of anything.

My main point would be to not worship certifications, but don't disparage them out of hand either. Don't get any if you don't see the need, but don't automatically assume someone with several is really incompetent either!

The Insider Threat to Drivers

This article shows that the human factor is always going to be a major factor in any overall security stance. A disgruntled downsized employee used a former coworker's account to access a system for tracking and disabling cars that they now use frequently at "buy here, pay here" auto sales places. A bunch of people had unworking cars until they reserved this. It kind of makes you concerned for what the future could hold as we place more and more computerized control devices in cars and other electronic equipment.

http://www.dailytech.com/Disgruntled+Former+Employee+Wirelessly+Bricks+100+Cars+in+Texas/article17918.htm

I am reminded of a recent Onstar commercial where they remotely disable a stolen car so the police can catch it. While that sounds great, what would happen if a disgruntled employee got access to that system? It is very important that we make sure companies with that kind of control have very secure development processes. In this case, making it harder for a single employee to disable so many vehicles so quickly would have been a reasonable development limitation and would have limited the possible damage in a case like this.