<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-34349059</id><updated>2026-05-08T15:22:49.375-04:00</updated><category term="hacking"/><category term="business"/><category term="cybersecurity"/><category term="hacker"/><category term="information security"/><category term="security"/><category term="APT1"/><category term="Chinese hacking"/><category term="bad news"/><category term="breaker"/><category term="builder"/><category term="ceo"/><category term="china"/><category term="clever playfulness"/><category term="comment spam"/><category term="cyber security"/><category term="cyber war"/><category term="cyberwar"/><category term="cyberwarriors"/><category term="defense"/><category term="executives"/><category term="good news"/><category term="how I got started in infosec"/><category term="infosec"/><category term="infosec career advice"/><category term="infosec career tips"/><category term="infosec job advice"/><category term="katie moussouris"/><category term="malware"/><category term="origin story"/><category term="ostrich"/><category term="ostrich effect"/><category term="pentagon"/><category term="pentest"/><category term="presentation"/><category term="preventing malware"/><category term="preventing viruses"/><category term="protecting against malware"/><category term="richard stallman"/><category term="seth godin"/><category term="spam"/><category term="stages of vulnerability response grief"/><category term="threat intelligence"/><category term="vulnerability disclosure"/><category term="vulnerability response"/><title type='text'>Beau&#39;s Cybersecurity Blog</title><subtitle type='html'>doing what I love; loving what I do</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default?start-index=26&amp;max-results=25&amp;redirect=false'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>55</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-34349059.post-7210465704382525667</id><published>2014-08-23T18:31:00.000-04:00</published><updated>2014-08-23T18:34:50.044-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="clever playfulness"/><category scheme="http://www.blogger.com/atom/ns#" term="hacker"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="katie moussouris"/><category scheme="http://www.blogger.com/atom/ns#" term="pentest"/><category scheme="http://www.blogger.com/atom/ns#" term="richard stallman"/><category scheme="http://www.blogger.com/atom/ns#" term="stages of vulnerability response grief"/><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability disclosure"/><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability response"/><title type='text'>Hacking And Politics</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
I&#39;ve got a short definition for hacking that I like. It&#39;s independent of technology and doesn&#39;t have many of the nasty implications of many of the mental models people have. This is not as succinct and elegant as the definition &lt;a href=&quot;http://www.disclose.tv/action/viewvideo/110365/Hacking_is_Playful_Cleverness_Richard_Stallman__SpotlightRT/&quot;&gt;Richard Stallman&lt;/a&gt; gives, where hacking is &quot;clever playfulness&quot; but I think it is much better as a functional definition.&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
Hacking is a method of circumventing an accepted expectation or system to achieve a goal faster, more efficiently or more effectively than would otherwise result.&lt;/blockquote&gt;
Here a system can be described as a set of processes. Therefore a computer system is a set of computer processes. Software code defines these processes and the computer executes them with or without human interaction. So computer hacking is merely circumventing these codified processes. The process owner must protect against such circumventions which lead to undesirable outcomes. Failure to do so can be called a security flaw. A person who circumvents processes, then, can be called a hacker. They didn&#39;t make the flaw, only found and used it.&lt;br /&gt;
&lt;br /&gt;
This definition also works for other types of hackers. There are popular communities and labels of travel hacker, life hacker, social hacker, growth hacker, etc. I&#39;ve even seen articles about garden hacking. Can you even find an activity or thing that doesn&#39;t return any results for a Google search when you append hacker to it?&lt;br /&gt;
&lt;br /&gt;
Laws are another example of accepted expectations and processes. Hackers - and I include social, political and business hackers like entrepreneurs - see the loopholes in laws that were created, either intentionally or otherwise. And that makes them potentially threatening to the governments that created these laws. But not necessarily. A government that seeks to codify accepted expectations and processes should seek out feedback from hackers if they wish to ensure they are creating better laws.&lt;br /&gt;
&lt;br /&gt;
Most of these flaws are not discovered before laws formally codify them. Like in computer hacking, some seek to discover and use these flaws for their own benefit. And some seek to discover and publish them so that they can be fixed. A government&#39;s response to this publication is telling about its willingness to make laws with minimal flaws.&lt;br /&gt;
&lt;br /&gt;
Some see a heavy-handed response to quash public knowledge of flaws in the policy and legal code as indications that the flaws were created &lt;i&gt;intentionally.&lt;/i&gt;&amp;nbsp;I am not one of those people. I think it instead better resembles the reaction that software makers have when researchers point out flaws in their code. They go through &lt;a href=&quot;https://www.youtube.com/watch?v=T6e70upcfl4&quot;&gt;Katie Mousourris&#39; five-stages of vulnerability response grief&lt;/a&gt;. (It&#39;s a good 7 minute watch.)&lt;br /&gt;
&lt;br /&gt;
I would say these political, economic and other systems &lt;b&gt;must&lt;/b&gt; be tested for flaws so they can be addressed. Think of this as hardening politics, the economy and the social order. If we don&#39;t help to harden it we are helping those who seek to gain personal advantage from the flaws. We can use structures and frameworks for security testing as blueprints until better ones are available. Or maybe they already are and I&#39;ve just missed them.&lt;br /&gt;
&lt;br /&gt;
What are your thoughts?&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/7210465704382525667/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/7210465704382525667' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7210465704382525667'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7210465704382525667'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2014/08/hacking-and-politics.html' title='Hacking And Politics'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-3760801577785074672</id><published>2014-08-23T15:20:00.000-04:00</published><updated>2014-08-23T15:20:41.491-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="breaker"/><category scheme="http://www.blogger.com/atom/ns#" term="builder"/><category scheme="http://www.blogger.com/atom/ns#" term="business"/><category scheme="http://www.blogger.com/atom/ns#" term="hacker"/><category scheme="http://www.blogger.com/atom/ns#" term="infosec"/><category scheme="http://www.blogger.com/atom/ns#" term="origin story"/><title type='text'>My Infosec Origin Story</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
Everybody likes a good origin story. Especially these days with comic book heroes and villains getting origin story movies and TV shows. It explains a lot about the character that you&#39;ve come to know well and helps you understand motivations and brain wiring.&lt;br /&gt;
&lt;br /&gt;
The other day I was talking to someone about how I got into infosec and I realized I could sum it up pretty quickly. So here&#39;s my own personal infosec origin story:&lt;br /&gt;
&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;Always been a technology guy. But then it started to get boring.&lt;/li&gt;
&lt;li&gt;Started breaking technology - hacking. Then that got boring.&lt;/li&gt;
&lt;li&gt;Protected technology and information from the breakers. Boring.&lt;/li&gt;
&lt;li&gt;Now making and breaking business plans, models and ideas. Disruptive entrepreneurialism. It&#39;s not boring yet, but we&#39;ll see.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/3760801577785074672/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/3760801577785074672' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/3760801577785074672'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/3760801577785074672'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2014/08/my-infosec-origin-story.html' title='My Infosec Origin Story'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-1841052493743224737</id><published>2014-08-22T10:52:00.000-04:00</published><updated>2014-08-22T11:01:35.443-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="bad news"/><category scheme="http://www.blogger.com/atom/ns#" term="business"/><category scheme="http://www.blogger.com/atom/ns#" term="ceo"/><category scheme="http://www.blogger.com/atom/ns#" term="executives"/><category scheme="http://www.blogger.com/atom/ns#" term="good news"/><category scheme="http://www.blogger.com/atom/ns#" term="ostrich"/><category scheme="http://www.blogger.com/atom/ns#" term="ostrich effect"/><category scheme="http://www.blogger.com/atom/ns#" term="presentation"/><title type='text'>Eliminating Ostrich Effect In CEOs</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
NPR reports on a new study that demonstrates the &lt;a href=&quot;http://www.npr.org/blogs/health/2014/07/28/333945706/why-we-think-ignorance-is-bliss-even-when-it-hurts-our-health&quot;&gt;Ostrich effect in people&lt;/a&gt;. That&#39;s where the ostrich buries his head in the ground to avoid danger. The ostriches who do this and then don&#39;t die go on to have babies. And the gene for this behavior gets passed on. I don&#39;t know if ostriches really do that or not. Still, it&#39;s a staple of cartoon humor. Silly birds.&lt;br /&gt;
&lt;br /&gt;
The results of the study indicate that people will pay money to avoid learning health news that might be negative. Specifically, subjects paid $10 to NOT have their blood tested for Herpes Simplex 2 (that&#39;s the worse one). Ever have a relative or friend who avoided going to the doctor even though there was clearly a problem? Ostrich effect. Silly birds.&lt;br /&gt;
&lt;br /&gt;
That&#39;s a very interesting study. If you think about it, this makes sense:
&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;Touching a hot stove hurts. So we avoid touching it by using an oven mitt or simply keeping hands away.&lt;/li&gt;
&lt;li&gt;Bad news is painful. So potential of bad news makes us avoid information altogether.&lt;/li&gt;
&lt;/ul&gt;
This can be generalized to partially explain why many leaders throughout history (and today) have surrounded themselves with toadies. They don&#39;t want to hear the bad news so they gradually insulate their mind with the functional equivalent of oven mitts.&amp;nbsp;&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Look at CEOs with cybersecurity. The CISO tends to always bring bad news so they just stop inviting him, or putting him under someone else who can oven mitt him off. Ostrich effect. Silly birds. Silly environmental threats.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Knowing that a CISO can change his content or delivery to reduce this effect. For instance putting today&#39;s report in context. &quot;Yes we&#39;re not great, but we&#39;re doing much better.&quot; Or bringing good news along with any bad news, such as &quot;We saved over $300K last year in employee downtime from reducing malware infections. Also we still had lots of malware infections.&quot; Or keep smiling throughout the conversation, maybe telling a joke or two to improve the mood. &lt;a href=&quot;http://www.tesco.com/everylittlehelps/&quot;&gt;Every little helps&lt;/a&gt;. Or bring donuts. Executives love donuts don&#39;t they?

&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/1841052493743224737/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/1841052493743224737' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1841052493743224737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1841052493743224737'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2014/08/npr-reports-on-new-that-demonstrates.html' title='Eliminating Ostrich Effect In CEOs'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-3011569978970838359</id><published>2014-08-13T19:08:00.000-04:00</published><updated>2014-08-13T19:08:16.164-04:00</updated><title type='text'>Are We Magicians?</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
Computerized technology pervades every aspect of our life, from cars, to medical devices, and increasingly every electronic thing around us. Only a select few people understand this technology well, meaning for most people it is well in advance of what they know how to use and manipulate effectively. As Arthur C. Clarke said, &quot;any sufficiently advanced technology is indistinguishable from magic.&quot; For most people the world around us is indistinguishable from magic.&lt;br /&gt;
&lt;br /&gt;
So then people who can bend this technology to their will are indistinguishable from magicians. And that is just what hackers do - use our techniques, tactics and processes to bend this technology to our will. This mastery gives us the power to manipulate and control the world around us. And with great power comes great responsibility. It is time for hackers to assess the way we use our power - or don&#39;t use it - and ask whether what we are doing is responsible.&lt;br /&gt;
&lt;br /&gt;
This year at Black Hat and DEF CON, two of the premier hacker conferences, the theme seemed to be &lt;a href=&quot;http://www.itworld.com/security/431271/defcons-latest-challenge-hacking-altruism&quot;&gt;hacking altruism&lt;/a&gt;. For the past few years I&#39;ve noticed a trend of information security people advocating for fixing problems, not just finding them. Over the past year or two I think the community has realized that our ability and responsibility to impact the world reaches far beyond the technical.&lt;br /&gt;
&lt;br /&gt;
For years now the community has been helping each other. Community members with problems get help, from money to marrow. Now we have begun looking outward to others who need our knowledge and experience if they are to get any help.&lt;br /&gt;
&lt;br /&gt;
I like this recent development and so do most in the community. So look for more impact from hackers coming soon to a problem space near you!&amp;nbsp;&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/3011569978970838359/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/3011569978970838359' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/3011569978970838359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/3011569978970838359'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2014/08/are-we-magicians.html' title='Are We Magicians?'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-3298056619279197397</id><published>2013-12-03T12:48:00.000-05:00</published><updated>2014-08-24T16:23:56.042-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="how I got started in infosec"/><category scheme="http://www.blogger.com/atom/ns#" term="infosec career advice"/><category scheme="http://www.blogger.com/atom/ns#" term="infosec career tips"/><category scheme="http://www.blogger.com/atom/ns#" term="infosec job advice"/><title type='text'>How to Get Started in Information Security</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;I&#39;ve seen a lot of people lately asking how to get started in the Information Security industry. I think there are a lot of misconceptions about what you need, like expertise with tools, certifications, experience in a role, etc. Those help, but I don&#39;t think that&#39;s the number one thing that gets you into the industry. I think the biggest things are curiosity and dedication. Those two things will ensure that the rest follows. And if you don&#39;t have those drives for an Infosec career then you haven&#39;t found what you want to be doing for the rest of your life, so keep looking.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;But there&#39;s more to it that you&#39;ll pick up along the way. Rather than tell you what I think you should do I&#39;ll tell you how I got into the industry then try to distill the lessons and skillsets that I think have been most important for me. The story will hopefully tell you why I think the skillsets are important so you can understand for yourself what&#39;s the best path for you.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;I started out working break-fix PC support. Someone would call the help desk and if they couldn&#39;t work it out over the phone I&#39;d go out and fix it. I got good at malware cases - spyware, popups, network worms, etc. because I was curious about how to get rid of the malware, not just reimage the system. That doesn&#39;t always cure the issue, as I learned, but it was typically quicker to fix and less work on my part because I didn&#39;t have to copy the data, reinstall software, etc. On larger-scale malware incidents then I was on the front lines to help. And whatever I learned I wrote up for others so they didn&#39;t have to learn the same thing.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
I also made sure to take care of the whole problem before leaving. Again, mainly because I was trying to be more efficient (some might say lazy). If I didn&#39;t I&#39;d have to come back out to solve the original problem. And that often meant walking through some basic awareness information so that the system didn&#39;t become reinfected. I wasn&#39;t great at that, but the people appreciated it. It was this bedside manner that meant I was assigned to the higher profile cases with the folks who were more important in the organization.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
When a security role opened up I applied for it. I researched for the interview and conversations, looked over what I&#39;d been working on most and how I&#39;d solved those problems. Then all of the questions were about appsec rather than anything I&#39;d been doing. Oops. I guess I still did OK because I got an offer. It was lower than I knew it should be so I asked for industry average. I didn&#39;t get it, but I did get about 5% more than the original offer.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
I started reading all the blogs and magazine articles I could, in between doing security things. I figured I&#39;d start writing too. I started my own blog to pass on lessons learned in plain English (&lt;a href=&quot;http://beauwoods.blogspot.com/search?updated-min=2006-01-01T00:00:00-05:00&amp;amp;updated-max=2007-01-01T00:00:00-05:00&amp;amp;max-results=8&quot;&gt;go back to the early days of Beau&#39;s Cybersecurity Blog&lt;/a&gt; and see how raw that stuff was). And comment on other peoples&#39; blogs and stories. People started to notice and comment back, email me, etc. and that encouraged me and keep up my momentum.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
When I told my boss I was hitting the ceiling she said she understood and was glad - it meant I was growing and thriving. There wasn&#39;t room for me to move up so I let her know I was going to start looking at other organizations. She said that was a good idea - it&#39;s always easier to turn down an offer than to get one in the first place.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
So I took stock - what was my passion, how could I best monetize my skills and why was I doing this? My passion was helping people fix problems. My most in-demand skillset was my communications and problem solving skillset, as well as my familiarity (not expertise) with security tools. My why (this is always the most important one) was so I could travel the world and work from anywhere, which meant I needed to improve my network connections and ability to make them more than anything.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
So I began a low-intensity search - I still had a job so I could afford to wait for the right opportunity. Trawling job boards, Craigslist, companies I wanted to work for, asked friends, etc. Within a month I found one that looked perfect. I reached out, looked around and found who the hiring company was and applied directly too. Just like the last time I did lots of research and preparation and built a dossier on all the people I&#39;d be talking with, as well as their execs in case I met one of them. All of that came in handy and they hired me. (They also found my blog and liked what I was writing about so that helped too.)&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
Repeat that process a few more times and here I am.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
Below are a couple of lists. The first is traits I found inside myself when I found the right outlet - the area I felt I belonged and was passionate about. The second is the skillets I worked to improve along the way. Both lists are in order that I feel were most important. You&#39;ll see that there aren&#39;t any specific tools listed - that&#39;s because I don&#39;t think a large investment in time in those really helps. But familiarity and some experience playing with the top tools in what you want to do certainly does. If you&#39;re just going for an entry-level job then that&#39;s all they&#39;ll be expecting.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
Traits&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
&lt;/span&gt;
&lt;br /&gt;
&lt;ul&gt;&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
&lt;li&gt;Curiosity&lt;/li&gt;
&lt;li&gt;Desire to get better&lt;/li&gt;
&lt;li&gt;Self-exploration&lt;/li&gt;
&lt;li&gt;Humility&lt;/li&gt;
&lt;li&gt;Ambition&lt;/li&gt;
&lt;/span&gt;&lt;/ul&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
Skillets I worked hard at improving
&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
&lt;li&gt;Communication (quantity and quality)&lt;/li&gt;
&lt;li&gt;My value and place I fit best&lt;/li&gt;
&lt;li&gt;Root-cause analysis&lt;/li&gt;
&lt;li&gt;Patience&lt;/li&gt;
&lt;li&gt;Perspective&lt;/li&gt;
&lt;li&gt;Some technical tools&lt;/li&gt;
&lt;/span&gt;&lt;/ul&gt;
&lt;span style=&quot;color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;b&gt;Update: &lt;/b&gt;Some links below from others who have written on the same topic.&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
&lt;/span&gt;&lt;/ul&gt;
&lt;span style=&quot;background-color: white; color: #222222; font-family: arial; font-size: x-small;&quot;&gt;
&lt;/span&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;&lt;span style=&quot;color: #222222; font-family: arial; font-size: x-small;&quot;&gt;&lt;a href=&quot;https://twitter.com/jcran&quot;&gt;JCran&lt;/a&gt; writes how he &lt;a href=&quot;http://blog.pentestify.com/2014/03/07/getting-started-in-security-a-message-to-a-student/&quot;&gt;helps students get started in information security&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;color: #222222; font-family: arial; font-size: x-small;&quot;&gt;Reddit provides some great &lt;a href=&quot;http://www.reddit.com/r/netsec/wiki/start&quot;&gt;resources for exploring and learning infosec on your own&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;color: #222222; font-family: arial; font-size: x-small;&quot;&gt;Contrast Security on &lt;a href=&quot;http://www1.contrastsecurity.com/blog/how-to-get-started-in-appsec&quot;&gt;how to get started in application security&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;color: #222222; font-family: arial; font-size: x-small;&quot;&gt;Brian Krebs talks with several &lt;a href=&quot;http://krebsonsecurity.com/category/how-to-break-into-security/&quot;&gt;high-profile infosec personalities on getting started in the field&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;color: #222222; font-family: arial; font-size: x-small;&quot;&gt;Chris Grayson provides a &lt;a href=&quot;http://www.slideshare.net/ChrisGrayson/so-you-want-to-be-a-hacker&quot;&gt;presentation with definitions, approaches and tools for getting into infosec&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/3298056619279197397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/3298056619279197397' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/3298056619279197397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/3298056619279197397'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2013/12/how-to-get-started-in-information.html' title='How to Get Started in Information Security'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-8553533929017005474</id><published>2013-04-11T03:06:00.000-04:00</published><updated>2013-04-11T03:45:38.920-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="information security"/><category scheme="http://www.blogger.com/atom/ns#" term="malware"/><category scheme="http://www.blogger.com/atom/ns#" term="preventing malware"/><category scheme="http://www.blogger.com/atom/ns#" term="preventing viruses"/><category scheme="http://www.blogger.com/atom/ns#" term="protecting against malware"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><title type='text'>Some Thoughts on Malicious Software Prevention and Protection</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
&lt;br /&gt;
Today I got a message from a business associate of mine apologizing for a delay in the work, because he&#39;d been hit by malicious software (malware). As it turned out, I replied, computer security is what passes for a day job for me. So I came up with some instructions for him to help improve his security. These should be fairly easy for a non-technical person to use, though a moderately technical person may need to set things up.&lt;br /&gt;
&lt;br /&gt;
Leave feedback in the comments if you agree, disagree or have any additions. Here&#39;s the list, in order of what I&#39;m calling Return on PITA (ROP) - or, most benefit for the least pain wins.&lt;br /&gt;
&lt;h4 style=&quot;text-align: left;&quot;&gt;
Preventing malware infection&lt;/h4&gt;
&lt;ol style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;Make your account a &quot;Limited User&quot; instead of &quot;Administrator&quot;. This prevents the malware from running on your system without you first entering your password.&lt;/li&gt;
&lt;li&gt;If you are running Windows, make sure you are on 7 or higher. Windows 7 provides lots more security controls that balance protection with usability. One key feature is AppLocker which prevents unknown software from running without entering your password. The downloadable tool EMET enhances protections and Windows Defender is excellent, free anti-virus software.&lt;/li&gt;
&lt;li&gt;Keep all your software updated. Windows does a nice job of updating itself, but other software isn&#39;t always as good. I don&#39;t generally like to recommend specific software, but in this case it&#39;s hard to find if I don&#39;t: Secunia PSI is free for personal use and keeps you updated about...well updates.&lt;/li&gt;
&lt;li&gt;Be skeptical before opening email attachments or links. This takes some practice, but it&#39;s as easy as stopping and asking whether something makes sense or not. Many of the email scams today look real, unless you apply some skepticism. Why would a) this person/company be b) sending me this information c) through email and d) how can I see if it&#39;s legit?&lt;/li&gt;
&lt;/ol&gt;
&lt;h4 style=&quot;text-align: left;&quot;&gt;
Reducing fallout from malware&lt;/h4&gt;
&lt;div&gt;
&lt;ol&gt;
&lt;li&gt;Work with your financial institution to increase account security. Many people erroneously assume that banks reimburse for financial loss from malware, but that&#39;s only for personal accounts. Banks differ in what they offer and can help you figure out what works best for you.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Use online backup storage. You can store your documents on the Internet securely, so if something happens to your computer you can still get your documents back. Several companies offer a small amount of storage for personal use for free. Also store software licenses so you can rebuild.&lt;/li&gt;
&lt;li&gt;Use password safe technology. This is software that will track your passwords and store them protected on your computer and the Internet, as well as generate strong passwords. This means you can have a strong, unique password for each website which reduces the likelihood of having multiple accounts compromised at once.&lt;/li&gt;
&lt;/ol&gt;
&lt;h4 style=&quot;text-align: left;&quot;&gt;
Cleaning up after malware infection&lt;/h4&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;ol style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;Notify financial institutions immediately. They will put more scrutiny on your transactions and can work with you to add security measures to your account.&lt;/li&gt;
&lt;li&gt;Even the best cleaning may leave&amp;nbsp;malware&amp;nbsp;behind. It&#39;s best to wipe everything and start over. Download applications from their legitimate website. Stored copies and third-party sites could have&amp;nbsp;malware&amp;nbsp;embedded in the legitimate software.&lt;/li&gt;
&lt;li&gt;Change passwords from a known-clean system. Start first with the websites that could cause the most damage, such as financial institutions or where you could have fraudulent charges against accounts (for example, iTunes and Skype).&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;h4 style=&quot;text-align: left;&quot;&gt;
Busting some common misconceptions about malware&lt;/h4&gt;
&lt;b&gt;Anti-virus and a firewall are NOT very effective.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
Your firewall is designed prevent random computers on the Internet from starting to talk to yours. But most&amp;nbsp;malware&amp;nbsp;is spread through the web and email, which means you start to talk with the computer with the&amp;nbsp;malware. That means your firewall is largely useless.&lt;br /&gt;
&lt;br /&gt;
Anti-virus software works by trying to know all of the&amp;nbsp;malware&amp;nbsp;out there and blocking it. The problem is that&amp;nbsp;malware&amp;nbsp;is generated faster than anti-virus can keep up, using techniques that ensure anti-virus companies don&#39;t see the exact&amp;nbsp;malware&amp;nbsp;you&#39;ve downloaded. Anti-virus fails more often than it succeeds at blocking&amp;nbsp;malware&amp;nbsp;in real-world testing.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Malicious software is NOT just spread through sketchy sites.&lt;/b&gt;&lt;br /&gt;
Most&amp;nbsp;malware&amp;nbsp;today is actually spread through legitimate websites. Malicious attackers break into and store their&amp;nbsp;malware&amp;nbsp;legitimate sites, infecting visitors. It&#39;s also common for ads to contain&amp;nbsp;malware&amp;nbsp; so even large and well-protected websites present some risk.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;One web browser is NOT inherently more secure than another.&lt;/b&gt;&lt;br /&gt;
This was true at one time, but it&#39;s not anymore. Some&amp;nbsp;malware&amp;nbsp;still spreads by attacking the web browser, but much more will attack supporting applications like Adobe Reader or Sun Java - two technologies that are independent of your web browser.&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/8553533929017005474/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/8553533929017005474' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/8553533929017005474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/8553533929017005474'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2013/04/some-thoughts-on-malicious-software.html' title='Some Thoughts on Malicious Software Prevention and Protection'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-3033690548354183003</id><published>2013-03-13T13:32:00.000-04:00</published><updated>2013-03-13T13:32:21.157-04:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="APT1"/><category scheme="http://www.blogger.com/atom/ns#" term="Chinese hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber security"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber war"/><category scheme="http://www.blogger.com/atom/ns#" term="cybersecurity"/><category scheme="http://www.blogger.com/atom/ns#" term="cyberwar"/><category scheme="http://www.blogger.com/atom/ns#" term="cyberwarriors"/><category scheme="http://www.blogger.com/atom/ns#" term="defense"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="pentagon"/><title type='text'>A Light Look at Cyberwar Capabilities</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
There has been lots of news for several months about military-grade offensive security capabilities. Within the past couple of weeks this focus has ratcheted up. The tipping point, in my mind was when Mandiant[1] released a report on Chinese hackers that they were tracking. The report claimed a lot of things, among them that the individuals mentioned in the report were carrying out offensive attacks for the Chinese military, against the US military, military contractors and other companies. That&#39;s pretty scary stuff! But keep in mind that this report was heavily hyped and coincided with one of the biggest security conferences, so maybe pure altruism wasn&#39;t at the heart of the report, maybe it was also in large part driven by PR value.&lt;br /&gt;
&lt;br /&gt;
So now there are lots of people at high levels in the government talking more openly about cybersecurity threats. Generals are testifying in front of congress, the president is meeting with CEOs (I guess they&#39;re security experts?), everybody in the government seems to be saying the US is under attack and needs to defend itself. The rhetoric is building to a fever pitch and I&#39;m a bit concerned about what this means for the future. But for now let&#39;s look at what the current situation is like.&lt;br /&gt;
&lt;br /&gt;
What a lot of the talk comes down to is one thing: we&#39;re being spied on. Well hey that&#39;s no surprise is it? Isn&#39;t that what the whole Cold War was about? &quot;But&quot; we hear &quot;spying is a lot easier with computers because...&quot; and then they go off and spout a lot of nonsense that comes down to &quot;...we got caught off guard and didn&#39;t protect ourselves early enough.&quot; OK well that&#39;s too bad and we need to fix that problem so let&#39;s go do that.&lt;br /&gt;
&lt;br /&gt;
But then if it&#39;s so easy for other people to spy on us, isn&#39;t it easy for us to spy on them too? Aren&#39;t we already doing that? That&#39;s a side of the conversation that not a lot of mainstream media talks about, but that a lot of people in the security industry are laughing about. Just within the last couple of years there have been reports of Iranian nuclear facilities being targeted by sophisticated malicious software and most of the evidence points to the US or US contractors as having created it. Ironically about a year before it was officially-unofficially reported that the &lt;a href=&quot;http://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cyberattacks-against-iran.html?pagewanted=all&quot;&gt;Iranian cyberattacks were authorized by the President&lt;/a&gt;,&amp;nbsp;&lt;a href=&quot;http://www.nytimes.com/2011/06/01/us/politics/01cyber.html&quot;&gt;he declared that cyberattacks against the US would be considered acts of war&lt;/a&gt;. Whoops.&lt;br /&gt;
&lt;br /&gt;
So let&#39;s look at what we know about the US cyberwar capabilities. The first thing I&#39;ll do is to look at where these US capabilities come from. There&#39;s several different angles so I&#39;ll take a shot at enumerating them for discussion but I&#39;m sure I haven&#39;t gotten them all called out so leave comments if you know of others.&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;US Civilian Government Cybersecurity groups like those run in the NSA.&lt;/li&gt;
&lt;li&gt;US Militarty Cyberwarriors.&lt;/li&gt;
&lt;li&gt;US Government contractors.&lt;/li&gt;
&lt;li&gt;US allies like Israel who supposedly has a pretty potent force.&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
Alright, so let&#39;s see if we can take a guess about what resources we have to bring to bear.&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;&lt;b&gt;US Civilian Government Cybersecurity&lt;/b&gt; - I mentioned the NSA. The CIA probably also has some people. Maybe FBI. Maybe some others. I haven&#39;t run across much information here, but if you know of where some of that could come from I&#39;d love to look at it. The White House wants a lot more of these people and I&#39;m sure Congress is going to fund that. Now it&#39;s an interesting thought experiment to ask whether CIA analysts and traditional spies are actually cyberspies. They probably use computers as well as other techniques to carry out their jobs, but does that put them in the cyber arena?&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;US Military Cyberwarriors&lt;/b&gt; - There&#39;s a great article over at &lt;a href=&quot;http://killerapps.foreignpolicy.com/posts/2013/03/07/how_many_cyber_troops_does_the_military_have&quot;&gt;Foreign Policy magazine came up with 53,000-58,000 Cyber troops&lt;/a&gt;. That&#39;s the ones that you can count and I&#39;ve got to suspect that there&#39;s more. Also important to note that these are just troops with an offensive mission, not a defensive one. Now to put that into perspective, this is about 4% of the 1.5M active duty troops and is more than all of the CIA (20K according to Wikipedia) and FBI (36K according to their site) agents combined! Hardly a small number. And that&#39;s just the obvious ones. No word on what they&#39;re spending, but probably a good deal of money here.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;US Government Cyber security contractors&lt;/b&gt; - This is probably one of the largest parts of the cyberwarrior force. There are a lot of reasons that the government would use private companies for this, including the fact that these companies can do things that are illegal if done by the government. Also there&#39;s a lot less red tape and oversight so you can hide a lot of money and efforts this way and get them out fast. Most people suspect this is who largely developed the malicious&amp;nbsp;software&amp;nbsp;that targeted Iran over the better part of the last decade. We also know that companies like HB Gary have been supplying cyberweapons to the government for a while, and companies like VUPEN sell attacks as well. I think it&#39;s safe to assume that if it&#39;s true, this is a pretty mature part of capabilities.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;US allies&lt;/b&gt; - The US allies can provide a lot of things to the US, probably mostly access and information. &amp;nbsp;I don&#39;t have a lot of knowledge about this so I won&#39;t go into it too much but if you know something, share.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div&gt;
That&#39;s a lot of force that the US has to bring to the cyber fight without spinning up a bunch of hype and rhetoric. So why are politicians and others talking so much about this stuff? Why not just go out and do what you want? I can&#39;t really say. I think it either comes down to distraction from other problems they would rather not address (healthcare, finances, economy, drones) or they need popular support for some new thing that they want to do and they know you wouldn&#39;t support it unless you were scared of hackers.&lt;br /&gt;
&lt;br /&gt;
&quot;What does this mean for your weekend?&quot; or &quot;So what?&quot; Well for starters I think it&#39;s important to understand that there&#39;s more than one side to every story. The reality is that the US has been engaging in cyberwarfare already. Definitely against Iran and most likely against&lt;br /&gt;
&lt;br /&gt;
A lot more people a lot smarter than me have written good stuff about this too, here are some:&lt;br /&gt;
&lt;a href=&quot;http://erratasec.blogspot.com/2013/03/cyberwar-you-lack-imagination.html&quot;&gt;Cyberwar: You Lack Imagination&lt;/a&gt;&amp;nbsp;by Erratasec&lt;br /&gt;
&lt;a href=&quot;http://krypt3ia.wordpress.com/2013/02/20/apt-1-the-good-the-bad-and-the-ugly/&quot;&gt;APT1: The Good, The Bad and The Ugly&lt;/a&gt; by Krypt3ia&lt;br /&gt;
&lt;a href=&quot;http://threatthoughts.com/2013/02/21/comments-on-comment-crew/&quot;&gt;Comments on Comment Crew&lt;/a&gt; by Kyle Maxwell&lt;br /&gt;
&lt;a href=&quot;http://jeffreycarr.blogspot.com/2013/02/mandiant-apt1-report-has-critical.html&quot;&gt;Mandiant APT1 Report has Critical Flaws&lt;/a&gt; by Jeffrey Carr&lt;br /&gt;
&lt;a href=&quot;http://cybernonsense.blogspot.com/2013/02/chinese-hackers-and-security-malware.html&quot;&gt;Chinese Hackers and Security Theater&lt;/a&gt; - a three-part series by Cyber Nonsense&lt;br /&gt;
&lt;a href=&quot;http://fabiusmaximus.com/2011/09/02/28486/&quot;&gt;Cyberwar: The Pentagon Cyberstrategy&lt;/a&gt; - a multi-part series by the excellent Marcus Ranum from a few years ago&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[1] Mandiant seems to have gotten the lion&#39;s share of the attention (and rightly so, the report and the video they released are compelling to look at) but they&#39;re far from the only ones selling Fear, Uncertainty and Doubt (FUD). I&#39;m not singling them out for that, just for the fact that their report and all the hype that followed in its wake seemed to make for a tipping point.&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/3033690548354183003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/3033690548354183003' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/3033690548354183003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/3033690548354183003'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2013/03/a-light-look-at-cyberwar-capabilities.html' title='A Light Look at Cyberwar Capabilities'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-1770220926824034265</id><published>2013-02-26T11:00:00.000-05:00</published><updated>2013-02-26T11:00:07.110-05:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="china"/><category scheme="http://www.blogger.com/atom/ns#" term="cybersecurity"/><category scheme="http://www.blogger.com/atom/ns#" term="hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="information security"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="seth godin"/><category scheme="http://www.blogger.com/atom/ns#" term="threat intelligence"/><title type='text'>Lessons from Journalism in Threat Intelligence</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
Seth Godin has a great blog post that is relevant to information security professionals. He discusses &lt;a href=&quot;http://sethgodin.typepad.com/seths_blog/2013/02/real-time-news-is-neither.html&quot;&gt;the problem that the closer to the event, the more expensive and less reliable the information is&lt;/a&gt;. This problem directly correlates to issues we face in trying to get reliable information about threats, vulnerabilities or other news. That&#39;s because as time goes on the story gets shaped and influenced by multiple accounts, investigations and analysis. &lt;br /&gt;
&lt;br /&gt;
Try this experiment. Find all of the Twitter messages about China and Hacking from the last 6 months and read them, as well as the linked articles. I&#39;ll wait. Ha - just kidding that&#39;d take you years to take in (if you did exactly what I said I apologize - don&#39;t follow every instruction you read on the internet)! Now go take a look at a few articles on China and Hacking in a reputable business periodical like The Economist, Time, etc. In 45 minutes you&#39;re up to date on everything from 6 months of twitter feeds. 45 minutes versus 1+ years. That&#39;s a huge difference in terms of cost.&lt;br /&gt;
&lt;br /&gt;
And reliability also suffers. In going through the Twitter exercise (again, really sorry about that lost year) you probably found that lots of the info was bogus, misleading, bad conclusions, duplicated, etc. Acting on that bad information costs money too (unless you spend lots of money to try and eliminate the bad information, but that again costs money).&lt;br /&gt;
&lt;br /&gt;
Most companies have figured out that it&#39;s expensive to stay up to date on information. That&#39;s why there&#39;s a big business in Threat Intelligence services. Companies outsource that function. But it&#39;s still important to keep in mind that you&#39;ll never have a perfect picture of the news just after it&#39;s happened. Think of it like a Polaroid picture. No matter how much you blow on it or shake it, it still develops at the same speed. &lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/1770220926824034265/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/1770220926824034265' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1770220926824034265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1770220926824034265'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2013/02/lessons-from-journalism-in-threat.html' title='Lessons from Journalism in Threat Intelligence'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-6375460850446616171</id><published>2012-08-16T07:23:00.002-04:00</published><updated>2012-08-16T07:24:40.465-04:00</updated><title type='text'>Simple Way to Increase Security and Privacy and Reduce Spam</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
&lt;div&gt;
A few years ago I came up with a technique to reduce my spam messages. I&#39;m sure I wasn&#39;t the first to think it up, but it&#39;s worked very well for years and I&#39;ve never missed a real message or wasted too much time on spam. After IOActive released some privacy research they&#39;ve done this week I realized this can help with that too.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
If you haven&#39;t followed the story, IOActive did some automated scanning of popular web services for high-profile executives. They were looking to find out whether people like Steve Ballmer use Dropbox, or if the CEO of Zappos uses Nikeplus.com (yes in both cases). This was accomplished by attempting to register for these sites using the executives&#39; official corporate email address.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Their approach was a pretty clever way to get the information. There may be a perfectly valid reason for some of the findings. For example, if an executive&amp;nbsp;publicly&amp;nbsp;announces his and his company&#39;s support for another service. But the number of results - 930 accounts across 840 executives - suggests that at least some of these are for personal use.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;
My Technique&lt;/h3&gt;
&lt;div&gt;
I use a different email address for each new account I set up. But I don&#39;t have to create tons of new free accounts at Gmail or Hotmail. I own several domain names, one of which is just for creating throw-away email addresses. Any email to that domain gets redirected to my primary email account. Once it&#39;s there, it is put into a folder without ever hitting my inbox.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Sounds like it might be tricky to remember all these addresses, but it&#39;s not really. I just use a consistent formula for coming up with the address. For example, &quot;site.com@domain.com&quot;. To remember your account name just look in the browser bar.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
And ever since I started using a password manager it&#39;s gotten even easier and more secure. I just create a random name and password and store it all away. The software figures out my username and password, I just have to click a couple of buttons.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;
Fighting Grey-Mail&lt;/h3&gt;
&lt;div&gt;
If you&#39;re not familiar with grey-mail, it&#39;s the emails you get that come from accounts you&#39;ve signed up for on the Internet. Now these aren&#39;t quite spam, because they come from known senders to accounts you provided, but then they&#39;re also not something you want to wade through constantly.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
I woke up this morning to about a half-dozen new pieces of grey-mail in my email. But I didn&#39;t have to look at any of it, I only know the number because I clicked on the folder I have that collects it automatically. The system I use works perfectly because it&#39;s automated, I have total control and it never misjudges an email.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
I simply dump all the messages that come in but aren&#39;t addressed to me directly over to a folder. I check that every once in a while and try unsubscribing from the biggest offenders. It usually works, but sometimes it doesn&#39;t. And of course if I&#39;m expecting anything then I go check that folder.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;
Increasing Security and Privacy&lt;/h3&gt;
&lt;div&gt;
And this also adds a little more security to your accounts. But it&#39;s the security-through-obscurity kind of system, so don&#39;t rely on it solely. If you&#39;re the kind of person who reuses passwords - and just about everybody does this to some extent - then you have some additional protection against password reuse attacks. If a hacker has the account emails and passwords for one of your accounts, they can&#39;t then get into other accounts without a little extra work. That won&#39;t stop a determined attacker, but it will protect you against somebody just running a list.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;
The Result&lt;/h3&gt;
&lt;div&gt;
I still get spam emails. Even with this system every day I get a handful of messages that show up in my spam folder. But it&#39;s not many - in fact, far less than the grey-mail number. In the last month I have gotten 9 spam messages, but over 150 grey-mail.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
The only people who have the email address I use are my friends. So either my friends&#39; accounts have been compromised or somebody guessed my email address. But still, only 9 spam messages per month and no time wading through grey-mail is pretty&amp;nbsp;spectacular! And as a side benefit I&#39;m protecting my privacy and security a little bit more.&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/6375460850446616171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/6375460850446616171' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/6375460850446616171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/6375460850446616171'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/08/simple-way-to-increase-security-and.html' title='Simple Way to Increase Security and Privacy and Reduce Spam'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-2848809943897225278</id><published>2012-07-16T16:50:00.001-04:00</published><updated>2012-07-16T16:50:33.898-04:00</updated><title type='text'>Wall of Creeps</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Lately there&#39;s been a lot of conversation about how to curb creepy behavior at Defcon. Last year women and goons had &lt;span style=&quot;background-color: white;&quot;&gt;&quot;red&quot; and &quot;yellow&quot; cards that they gave to guys who were acting like asses. This plan backfired, as the cards became sought-after swag leading to high demand. The idea was floated this year and has been nearly universally shot down as ineffective, counter-productive and immature.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;background-color: white;&quot;&gt;I propose a different tact - a Wall of Creeps. Creeps - men, women or otherwise - would have their photo on a physical or virtual wall, outing them. The idea is that public shame would act as a&amp;nbsp;deterrent&amp;nbsp;to keep people who are clearly over the line, more under control without forcing conformity. This tactic removes the incentive (scarcity and perceived exclusivity of the cards) and mixes in a strong social disincentive. It won&#39;t stop all acts of creephood, but should help cut down on the truly&amp;nbsp;aberrant&amp;nbsp;behavior.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;background-color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
The photo would be a mug shot taken by a goon, which means somebody has to be creepy enough to get dragged to a goon and have the goon stop what they&#39;re doing long enough to take the photo. That reduces false positives. Also there should be some criterion for redemption, such as a donation to a cause or a handwritten note or whatever else would make the offendee forgive. Maybe a TTL or a minimum sentence too. After 3 infractions though the creep&#39;s photo would be posted for the rest of the con.
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Con-goers would be invited to heckle and deride offenders for as long as their face is up there, but not physical violence, doxing, harassment, or generally being a creep/ass, etc. The board could also be used for party organizers to blacklist certain people, etc. I&#39;d love to hear feedback - what do you think?&lt;/div&gt;
&lt;div&gt;
&lt;/div&gt;
&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/2848809943897225278/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/2848809943897225278' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/2848809943897225278'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/2848809943897225278'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/07/wall-of-creeps.html' title='Wall of Creeps'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-7001821758451446872</id><published>2012-06-08T05:58:00.000-04:00</published><updated>2012-06-08T05:58:01.844-04:00</updated><title type='text'>Interesting Conversation from Gold Farmer</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
I saw this &lt;a href=&quot;http://diablo.incgamers.com/blog/comments/concerned-diablo-3-farmer-interviewed-on-economy-bots-and-more#more-22038&quot;&gt;interesting conversation posted on a Diablo III fansite&lt;/a&gt; today and it has a lot of relevance to Information Security. The interview is around the act of gold farming, or using automated bots to find massive amounts of in-game gold and items that can then be sold for cash. But at one point the conversation goes into how online game accounts are compromised.&lt;br /&gt;
&lt;br /&gt;
The gold farmer claims that most game account compromises come from one source - forums. Attackers compromise a fan forum site and get the username, email and passwords (or hashes). These credentials are then used to attempt to log into the game, as well as email accounts, PayPal, banks, credit cards and other online services. The entire process of checking accounts is automated through tools.&amp;nbsp;These accounts can then be either used by the original criminals or sold to other criminals.&lt;br /&gt;
&lt;br /&gt;
See below for the relevant text or see the entire &lt;a href=&quot;http://diablo.incgamers.com/blog/comments/concerned-diablo-3-farmer-interviewed-on-economy-bots-and-more#more-22038&quot;&gt;interview with a Diablo III gold farmer&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: Do you have any information on the account hacking that people are reporting even with having the authenticator?&lt;br /&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: Yeah, I know everything about that.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: Would you be willing to share that information with us?&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: They don’t hack the computers, the passwords.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: When you say they don’t hack the computers, they don’t have the player’s computers or they don’t hack Blizzard’s computers?&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: They hack forums and such and take the same email and password and test it on Blizzard.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: That’s what I thought. And that is testament to all of you guys out there who are using the same email and password for forums and such for your game.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: If they have 1 million stolen emails and passwords they might get 1% to 10%&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: What type of websites are targets for this?&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: Diablo websites or Blizzard in general.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: So you are talking about Diablo fansites that have forums that you know have been succesfully hacked these and get the log ins and passwords.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: Yeah, correct, it’s easy.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: And in the forums of BLizzard are you able to get anything out of there?&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: No. Blizzard is bullet proof, logically.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: I ran forums quite a while ago and we had 130k+ members and we had issues with hack attempts at our forum accounts quite often. We were very puzzled about it. There was one time when they got everyone’s log in and password but they didn’t log into anyone’s forum account. Do you suppose that when they got into our forums do you think they were just looking to match up&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: Yeah. They used it to try on people, mail and Blizzard and such. It’s called combo.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: Is that a mispronunciation of your program or is that what it’s actually called?&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: Nah. It’s made to make combo lists.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: We reset everyone’s password, we did that for them. We were worried they were trying to hack into the forum accounts. This was many years ago by the way. What I didn’t realise then but I’m realising now is that this was all about accessing the game accounts and it had nothing to do with our forums. I bet that alot of these forums that are getting compromised are getting compromised over and over again. Would you say that is correct?&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: Yeah and Paypal and banks, Facebook and so forth and small percent Russian spammers.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: They are testing this against multiple things, they are not just testing this against Diablo account they also test against Paypal and their bank log ins.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: They test it against everything and sell it.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: How much do they sell these for?&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: It depends on what’s on them.&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;MeD&lt;/strong&gt;: 10c an account, $10 an account? Do you know the range there?&lt;/div&gt;
&lt;div style=&quot;color: silver; font-family: Verdana, Geneva, Arial, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: -webkit-auto;&quot;&gt;
&lt;strong&gt;&lt;span style=&quot;border: 0px; color: #ffce80; font-family: inherit; font-style: inherit; font-weight: inherit; margin: 0px; padding: 0px; vertical-align: baseline;&quot;&gt;Farmer&lt;/span&gt;&lt;/strong&gt;: ??? Doesn’t sell.&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/7001821758451446872/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/7001821758451446872' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7001821758451446872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7001821758451446872'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/06/interesting-conversation-from-gold.html' title='Interesting Conversation from Gold Farmer'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-8595019206058418986</id><published>2012-06-06T17:14:00.000-04:00</published><updated>2012-06-06T17:36:22.027-04:00</updated><title type='text'>LinkedIn Password Hash Redux</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
This LinkedIn password hash leak has become a real storm of activity today. This post might not have much longevity, but I hope to quickly recap and summarize what we know, what we don&#39;t, what we guess and what we recommend. Everything here comes from correspondance on Twitter, blogs and what have you, so it should all be taken with a grain of salt (pun not intended).&lt;br /&gt;
&lt;br /&gt;
What we know:&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;6.5 Million password hashes were posted on a password cracking website. The author said they were from LinkedIn and that they were unsalted SHA-1 format. Some of the hashes had several digits zeroed out.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;No account names were included with the post, meaning it&#39;s not possible to link the passwords to accounts with the data found.&lt;/li&gt;
&lt;li&gt;LinkedIn has been investigating whether there was an internal breach, but has not yet&amp;nbsp;publicly&amp;nbsp;acknowledged anything they have found.&lt;/li&gt;
&lt;li&gt;LinkedIn has said that &quot;&lt;a href=&quot;http://blog.linkedin.com/2012/06/06/linkedin-member-passwords-compromised/&quot;&gt;some of the passwords that were compromised correspond to LinkedIn accounts&lt;/a&gt;.&quot; However, this statement is sufficiently vague that it could mean nothing more than common passwords are used for LinkedIn and found in the compromised data.&lt;/li&gt;
&lt;li&gt;Many security researchers who use unique passwords for LinkedIn and no other site have found those passwords in the leaked data. These passwords are said to be highly unlikely to be used by anyone else.&lt;/li&gt;
&lt;li&gt;An Android app update occurred shortly after the breach was discovered. However, it&#39;s unclear if the two events are related.&lt;/li&gt;
&lt;li&gt;A &lt;a href=&quot;http://blog.skycure.com/2012/06/linkedout-linkedin-privacy-issue.html&quot;&gt;security vulnerability in the LinkedIn iOS app&lt;/a&gt; reported today does not call out password security as an issue.&lt;/li&gt;
&lt;ul&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;div&gt;
What we don&#39;t:&lt;/div&gt;
&lt;div&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;We don&#39;t know whether there was a breach at LinkedIn or not. Likely they haven&#39;t yet completed their internal investigation.&lt;/li&gt;
&lt;li&gt;We don&#39;t yet know if more information was leaked, such as account names, credit card numbers or other private information.&lt;/li&gt;
&lt;li&gt;We don&#39;t know if more accounts have been exposed than those found in the original source.&lt;/li&gt;
&lt;li&gt;We don&#39;t know if there is an active vulnerability that could be exploited again to gain access to more password hashes.&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
What we guess:&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;Mikko Hypponen has suggested that the list may have come from a &lt;a href=&quot;http://www.theverge.com/2012/6/6/3067523/linkedin-password-leak-online&quot;&gt;LinkedIn web interface vulnerability&lt;/a&gt;, but was simply speculation based on past breaches.&lt;/li&gt;
&lt;li&gt;Researchers have speculated that passwords that have digits zeroed out have already been compromised, or that they are used for banned passwords.&lt;/li&gt;
&lt;li&gt;There has been speculation that some password hashes are not from LinkedIn, though it&#39;s hard to find evidence either way.&lt;/li&gt;
&lt;li&gt;There has been speculation that the &lt;a href=&quot;https://news.ycombinator.com/item?id=4073309&quot;&gt;6.5 Million passwords may cover all accounts on LinkedIn&lt;/a&gt;, due to some passwords being used by many different people. However, a number of people have reported that their password was not found among those leaked.&lt;/li&gt;
&lt;li&gt;Some reports suggest the &lt;a href=&quot;https://twitter.com/CrackMeIfYouCan/status/210397255189004289&quot;&gt;leaked passwords may be 6 months old&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
What we recommend:&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;If you have a LinkedIn account, change your password soon. Make it something strong. &lt;a href=&quot;http://blog.linkedin.com/2012/06/06/updating-your-password-on-linkedin-and-other-account-security-best-practices/&quot;&gt;LinkedIn published some very generic account and password security suggestions&lt;/a&gt;, but I prefer the excellent &lt;a href=&quot;http://xkcd.com/936/&quot;&gt;xkcd panel on password&lt;/a&gt;s.&lt;/li&gt;
&lt;li&gt;Many security professionals have called for LinkedIn to begin adding a salt value in their password hashing process, in order to strengthen security.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Other security professionals have mentioned specific password storage mechanisms built into programming languages which represent the latest techniques in thwarting password cracking, such as &lt;a href=&quot;https://twitter.com/tqbf/status/210438466109063169&quot;&gt;bcrypt, scrypt and PBKDF2&lt;/a&gt;. This has the added benefit of reducing the risk of an improper implementation which could itself lead to security issues.&lt;/li&gt;
&lt;li&gt;Two sites have been set up to check your password against the list. The sites appear to be safe, in that they won&#39;t steal your password, but for the paranoid you can also submit the password hash.&amp;nbsp;&lt;b&gt;I don&#39;t personally recommend that anyone do this&lt;/b&gt;, unless you have already changed your LinkedIn password and it was unique. But it&#39;s fun to look for possible passwords! &amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;
&lt;ul&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://linkedin.biorra.com/&quot;&gt;http://linkedin.biorra.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://leakedin.org/&quot;&gt;http://leakedin.org&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/8595019206058418986/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/8595019206058418986' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/8595019206058418986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/8595019206058418986'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/06/linkedin-password-hash-redux.html' title='LinkedIn Password Hash Redux'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-8093417732859542247</id><published>2012-05-27T13:58:00.001-04:00</published><updated>2012-06-08T02:52:23.733-04:00</updated><title type='text'>On the Recent Blizzard and Diablo 3 Account Compromises</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
&lt;div style=&quot;-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
As an avid Diablo fan, I eagerly watched and waited for Blizzard to create &lt;a href=&quot;http://diablo3.com/&quot;&gt;Diablo 3&lt;/a&gt;. My first impression is that they did a masterful job creating it. Yes, there are some initial frustrations, but it definitely has that Diablo feel to it and despite the running jokes about Error 37 as a new prime evil, I&#39;ve found that the most powerful boss enchantment has been Time Thief - the ability to suck hours off the clock without me realizing it. Bravo, Blizzard, Diablo 3 is a triumph!&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
But recently there has been a lot of controversy around compromised accounts in Diablo 3. Many players have found that their characters have been stripped of gold and high-level gear. That&#39;s as much a tragedy as being robbed in the physical world - the possessions you&#39;ve worked for so long and felt so happy to acquire are taken from you by an unknown assailant. People feel violated and angry, which is understandable and which is our nature. Many have lashed out at the closest target.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
The most common and convenient target of anger has been Blizzard&#39;s security and practices. Many accusations have sprung up that Blizzard, its servers, the game or other technology has been &quot;hacked&quot; and that essentially any player or account could be compromised because of that. In an interesting parallel, this is commonly the first thing people assume when their bank account has been compromised.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&amp;nbsp; &lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
The banking world has long confronted security challenges for online services. For as long as online banking has been a reality, malicious individuals have been hoping to compromise accounts and steal money from them. And so banking has come a long way in combating those threats. I&#39;ve performed dozens of audits for financial institutions around their information security practices, including a component dealing with authentication in online banking (&lt;a href=&quot;http://www.fdic.gov/news/news/financial/2005/fil10305.html&quot;&gt;FIL-103-2005&lt;/a&gt;, &lt;a href=&quot;http://www.fdic.gov/news/news/financial/2006/fil06077.html&quot;&gt;FIL-77-2006&lt;/a&gt; and &lt;a href=&quot;http://www.fdic.gov/news/news/financial/2011/fil11050.html&quot;&gt;FIL-50-2011&lt;/a&gt; if you want to look it up).&amp;nbsp;&lt;span style=&quot;background-color: yellow;&quot;&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
Today, banking is one of the safest activities you can engage in online, although it is also one of the most targeted. Cybercriminals from around the world target banks, banking sites and accounts and it has become every bit as disciplined and efficient as any business. The complexity and innovation is staggering. Yet excellent security measures taken by banks effectively thwart almost any attack out there, when used as intended on both the bank&#39;s side and on the account holder&#39;s side.&amp;nbsp;&lt;/div&gt;
&lt;br /&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
Most bank account compromises in the last decade or so haven&#39;t happened because the bank was hacked - they&#39;ve happened with legitimate account credentials. It used to be that most online banking accounts were compromised by the victim giving away their username and password or other sensitive information after clicking on links in fake emails. But banks improved the security and attackers responded by becoming more sophisticated. Now most of the time compromises happen because the account holder logs into their account from a computer that has malicious software installed. And it&#39;s highly likely that this is what has happened with most of the Diablo 3 account compromises.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;b&gt;So how does this relate to Blizzard and to Diablo 3?&lt;/b&gt; &lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
Blizzard has, in fact, said that &lt;a href=&quot;http://us.battle.net/d3/en/forum/topic/5149542352?page=1#6&quot;&gt;malware has been the root cause in nearly all of their compromise investigations&lt;/a&gt;. Today&#39;s cybercriminals have become very sophisticated in their methods. As Blizzard has also pointed out, there is no one way that they get the information and access necessary to compromise accounts. Essentially they use whatever means they need to, in order to get what they want. In practice, this means there are likely multiple groups, each using many different types of attacks to get as many accounts as they can.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
As with bank account holders, gamers have gotten more savvy about giving away information which would allow someone else to access their account. But the attackers have adapted as well and use other ways of getting that information than by sending fake emails. Here are some of the more creative and sophisticated ways the thieves operate.&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;By calling you, if you can believe it! There&#39;s a good &lt;a href=&quot;http://youtu.be/jb69H7l0vJA&quot;&gt;video walking through a typical attack where a cyber criminal may call you on the phone&lt;/a&gt;.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Text messaging or emails directing you to call a phone number, 
usually about account compromise, expiration or closing. The phone 
number then has a recording asking you to enter your information. You never even have to talk to a person and you&#39;ve given up too much information.&lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;If you are using the same email address and password on another site, if that site is compromised your Diablo 3 account may be too. These compromises happen somewhat frequently, such as the &lt;a href=&quot;http://www.isdpodcast.com/episode-277-gawker-pwnage-laptop-thief-bank-class-action-oracle&quot;&gt;Gawker Media account compromise&lt;/a&gt; a couple of years ago.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;It&#39;s possible to buy compromised systems from cybercriminals. Many of the more sophisticated networks have millions of computers that are infected - far too many for the original criminals to take advantage of. So they sell access to others. &lt;/li&gt;
&lt;li&gt;It&#39;s also possible to buy accounts from cybercriminals. Often they have account credentials for systems they don&#39;t typically target - for example if they only target bank accounts, they may sell gaming accounts for some additional profit.&lt;/li&gt;
&lt;li&gt;Newly compromised accounts are prioritized. The criminals have so many accounts they target the ones that have the highest net worth first. There are stories of operations centers with account queues where each new account is evaluated and ranked according to the amount of money the thieves can get.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
By far the most common way most bank accounts are compromised, and likely Diablo 3 accounts, is simply by installing malware on your computer without you knowing it. Without going into the myriad ways that this can happen, it&#39;s sufficient to say that you don&#39;t have to visit the shadier side of the Internet to run into malware. &lt;a href=&quot;http://news.softpedia.com/news/Ninety-Percent-of-Malicious-Sites-are-Infected-Legitimate-Ones-146838.shtml&quot;&gt;Most sites that distribute malware are legitimate&lt;/a&gt;. In fact, &lt;a href=&quot;http://www.stopbadware.org/home/pr_02222012&quot;&gt;more than 90% of infected sites find out that they&#39;re compromised from someone else&lt;/a&gt;. Even some of the most mainstream sites have become malware distributors at times - &lt;a href=&quot;http://www.rawstory.com/rs/2011/11/10/fbi-hackers-manipulated-internet-ads-generating-millions-in-payments/&quot;&gt;ESPN, NASA and the Wall Street Journal have all infected their visitors with malware&lt;/a&gt;. Many of these sites use standard malware toolkits which exploit dozens of vulnerabilities, generate new malware package for each site visitor and test it against the common antivirus suites before sending it along. It sounds like science fiction, but it&#39;s not.&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;b&gt;How to protect yourself?&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
Security
 is hard. That&#39;s what makes it so hard for an organization like Blizzard
 to give you one simple answer. But that&#39;s not what a lot of people want
 to hear - even the people in charge of security for companies with huge
 budgets to protect their information assets often ask &quot;What&#39;s the one 
thing I should do?&quot; So it&#39;s not a surprise that most individuals would 
look for the &quot;silver bullet&quot; solution, if you will.&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
It&#39;s hard to describe how to protect yourself much better than Blizzard themselves did. So instead of rehashing it, I&#39;ll just link to &lt;a href=&quot;http://eu.battle.net/d3/en/blog/4899104/Battlenet_and_Diablo_III_Account_Security_-25_05_2012#blog&quot;&gt;Blizzard&#39;s excellent article on keeping yourself safe from account theft&lt;/a&gt;. But if you&#39;re in a hurry I&#39;d say the top 3 things you can do are:&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;ol style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;Use the authenticator. Banks use similar technology to protect millionaires and billionaires. If you value your stuff, you can&#39;t get a better bargain than this! Even the cost of the physical token is inexpensive compared to what it&#39;s worth. Blizzard modestly says they&#39;re selling these at cost, but that really means they&#39;re taking a loss because of all the infrastructure and personnel resources they deploy on the back end. &lt;b&gt;If you&#39;re looking for a &quot;silver bullet&quot; to protect your Diablo 3 account, this is the closest you&#39;ll come&lt;/b&gt;.&lt;/li&gt;
&lt;li&gt;Don&#39;t reuse passwords. If you use the same password for your email, battle.net and bank, odds are you&#39;re practicing poor password security. My recommendation is to use something like &lt;a href=&quot;http://lastpass.com/&quot;&gt;LastPass&lt;/a&gt; or &lt;a href=&quot;http://keepass.info/&quot;&gt;KeePass&lt;/a&gt;, which make good password security easy.&lt;/li&gt;
&lt;li&gt;Update your OS, browser and plugins. Most modern operating systems and browsers will automatically update for you. But it&#39;s easy to see the update notification and procrastinate. Don&#39;t. Don&#39;t wait more than a day or two to update, once you see the notification. For plugins, it&#39;s sometimes harder because they don&#39;t often announce their updates. Adobe Flash, Adobe Reader and Oracle/Sun Java are the main attack vectors used of all the plugins out there, and they&#39;re getting better about notifying you of updates.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;b&gt;How can Blizzard do more to protect you?&lt;/b&gt;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;b&gt;&lt;/b&gt; I want to preface this section by saying that I don&#39;t know the details on what Blizzard is doing on their end to protect player accounts. I&#39;d guess there&#39;s a lot going on that they don&#39;t talk about, or at least that I haven&#39;t read about. But that doesn&#39;t mean they can&#39;t improve. But I know they&#39;re already doing a lot to secure accounts. In many cases, more than your bank does! Things like forcing stronger passwords, investigating many of the reported instances of theft, publishing and linking to a great deal of information, giving you the authenticators, proactively communicating security steps. It even seems like they&#39;re refunding money to some gamers whose accounts were compromised, even after determining that Blizzard wasn&#39;t at fault - that&#39;s got to be some of the best response ever from a gaming company! &lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
What follows is a few ideas I&#39;ve taken from other industries that may help Blizzard improve. (Or not - again, I don&#39;t know for sure what they&#39;re doing on their end.)&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;Look at metadata associated with each previous login for the account. Often this metadata will differ between legitimate and malicious login attempts. Things like geolocation, keyboard layout, OS or game language or other data will be significantly different between a player and a thief.&lt;/li&gt;
&lt;li&gt;Watch the common locations where compromised accounts are publicly posted for any gamer accounts that use the same account name or email address.&lt;/li&gt;
&lt;li&gt;Drop a unique &quot;cookie&quot; that identifies the system a player logs in from. If the cookie has changed since the last login, or the cookie has been used with multiple accounts, this should raise a flag.&lt;/li&gt;
&lt;li&gt;If there are multiple logins in rapid succession from a single IP or IP block, this should raise a flag.&lt;/li&gt;
&lt;/ul&gt;
All of these items can be indicators of a potentially compromised account or of a potential cybercriminal. Of course these measures consume personnel and system resources, meaning it will cost more to administer - but then how much do the reputation damage and time spent answering questions cost? And it will also result in frustrated players unable to login - but then you can take the stance of &quot;we&#39;re sorry that you&#39;re unable to login, but it&#39;s for your own security&quot; which is hard to argue with. And in conjunction with an email address, phone number, Skype or Twitter account, or other contact mechanism these false positives can be resolved very quickly. &lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
And for our part, players should really be more tolerant of security measures. Again, adding an authenticator to your account takes an additional 5 minutes to set up and 5 seconds to use in practice. But it cuts the probability of compromise to nearly zero &lt;b&gt;even if your system is fully compromised&lt;/b&gt;! And if you&#39;re like most people I know today, you appreciate it when your bank stops an apparently fraudulent transaction, even if it turns out to be legitimate. So do what&#39;s needed to help yourself be more proactive with security. A little initial setup can save you a lot of frustration in the end.&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;color: black; font-family: arial; font-size: small; font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
Is there anything I&#39;ve missed? Do you have a different opinion? I&#39;d love to hear about it so I can address the concern or amend my article. Constructive feedback is always welcome.&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;b&gt;UPDATE: &lt;/b&gt;In an interview, a &lt;a href=&quot;http://diablo.incgamers.com/blog/comments/concerned-diablo-3-farmer-interviewed-on-economy-bots-and-more#more-22038&quot;&gt;Chinese gold farmer claims to know the source of compromised accounts&lt;/a&gt;. According to him, forums are being compromised and the email addresses and passwords from there are used to try to log in to Battle.net. This is a pretty common tactic and underscores the importance of using unique passwords across sites and games. And if you&#39;re not willing to do that, get the Authenticator which will prevent this.&lt;/div&gt;
&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/8093417732859542247/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/8093417732859542247' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/8093417732859542247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/8093417732859542247'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/05/on-recent-blizzard-and-diablo-3-account.html' title='On the Recent Blizzard and Diablo 3 Account Compromises'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-7036266346447232860</id><published>2012-05-23T03:01:00.003-04:00</published><updated>2012-05-23T03:06:56.786-04:00</updated><title type='text'>New Research Published on Mobile Malware</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
Researchers at NCSU have started the &lt;a href=&quot;http://www.malgenomeproject.org/&quot;&gt;Android Malware Genome Project&lt;/a&gt;, which is designed to identify and classify known malware samples for study. The researchers&#39; results were recently presented and published at the Proceedings of the 33rd IEEE Symposium on Security and Privacy in San Francisco, California. The paper, entitled &lt;a href=&quot;http://www.csc.ncsu.edu/faculty/jiang/pubs/OAKLAND12.pdf&quot;&gt;Dissecting Android Malware: Characterization and Evolution&lt;/a&gt; (PDF link), analyzes the 1,200 samples collected between August, 2010 and October, 2011. The research analyzes the samples to attempt to determine how it is installed (infection vector), how it updates and its primary activities on the mobile device, as well as the sample&#39;s relation to other samples. &lt;br /&gt;
&lt;br /&gt;
The research groups infection vectors into several categories. Far and away the largest infection vector is through repackaging and redistributing modified versions of legitimate applications. The second group is spying applications - that is, software for one person to watch another person&#39;s activities. Some malicious software purports to do something (which it may or may not), but installs malware in addition - these are so-called Trojan Horses.&lt;br /&gt;
&lt;br /&gt;
There were also several primary types of activity that the samples performed. Many of the samples attempted to elevate privileges on the device by taking advantage of a flaw in the Android operating system. The goal with this action is to allow the application to have greater access to the functionality of the device. Nearly all of the samples attempted to connect the device to a larger group of compromised devices controlled by the malware authors - a so-called Botnet. Researchers found that another common activity was contacting premium services, such as SMS text messaging. Many of the malware samples also collected information, such as user accounts, text messages and phone numbers.&lt;br /&gt;
&lt;br /&gt;
The researchers also looked at the evolution of the malware samples and families over time. Specifically they looked in depth at two malware families to illustrate the rest, &lt;i&gt;DroidKungFu&lt;/i&gt; and &lt;i&gt;AnServer Bot&lt;/i&gt;. These two malware families show that authors have incorporated many sophisticated features to help circumvent detection and frustrate researchers attempting to study the samples, among other things. And their analysis showed that mobile malware is rapidly maturing. &lt;br /&gt;
&lt;br /&gt;
Some other interesting analysis was performed on the samples. The researchers ran all the collected samples against four mobile anti-virus packages Detection rates ranged from 20-80% effectiveness, with a big name A/V company firmly at the back of the pack. Unknown malware is likely much more successful than these results indicate, meaning anti-virus software really needs to catch up.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/7036266346447232860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/7036266346447232860' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7036266346447232860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7036266346447232860'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/05/new-publication-on-mobile-malware.html' title='New Research Published on Mobile Malware'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-7328627400731584942</id><published>2012-05-09T12:10:00.002-04:00</published><updated>2012-05-09T12:28:09.315-04:00</updated><title type='text'>Securely Deleting Data Before Donating or Recycling Your Devices</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
&lt;a href=&quot;http://allthingsd.com/author/katie/&quot;&gt;Katherine Boehret&lt;/a&gt; has a good article over on &lt;a href=&quot;http://allthingsd.com/20120508/when-the-devices-are-done/&quot;&gt;All Things D about recycling your technology&lt;/a&gt;.
 But it overlooks one crucial point - you need to make sure your 
information is deleted before you hand it over. If you don&#39;t, your 
information, including financial data, could wind up in someone else&#39;s 
hands. A recent case-in-point was made when many &lt;a href=&quot;http://www.techrepublic.com/blog/cracking-open/dont-blame-motorola-for-not-wiping-returned-xooms/408?tag=content;siu-container&quot;&gt;refurbished Motorola Xoom devices were sold with their old owners&#39; data still on them&lt;/a&gt;. When that happens it can lead to embarrassment (think private photos, 
videos), identity theft, financial fraud or other unpleasant things.&lt;br /&gt;
&lt;br /&gt;
To avoid any of these calamities, you&#39;ll want to take steps to wipe out 
your data. You should do this regardless of what the company or person 
you&#39;re giving it to tells you. But don&#39;t worry, securely erasing your 
information has never been easier! Many devices have mechanisms built in 
to do just that. And there are some good tools out there for your 
desktops and laptops.&lt;br /&gt;
&lt;br /&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;


Securely Erasing your iPhone, iPod Touch or iPad&lt;/h3&gt;
Apple&#39;s website has simple instructions on how to &lt;a href=&quot;http://support.apple.com/kb/ht2110&quot;&gt;securely erase an iPhone, iPod Touch or iPad&lt;/a&gt;. Here are the steps from Apple&#39;s support site:&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
You can remove all settings and information from your iPhone, iPad, or iPod touch using &quot;Erase All Content and Settings&quot; in&amp;nbsp;&lt;b&gt;Settings &amp;gt; General &amp;gt; Reset.&lt;/b&gt; &lt;/blockquote&gt;
For even more security, plug your device into your laptop and &lt;a href=&quot;http://support.apple.com/kb/HT1414&quot;&gt;use iTunes to restore the device&lt;/a&gt; to its factory settings (but do not restore from a previous backup) before using the &lt;i&gt;Erase All Content and Settings&lt;/i&gt; feature. Here are the steps from Apple&#39;s support site:&lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
&lt;ol&gt;
&lt;li&gt;Verify that  you are using the latest version of &lt;a href=&quot;http://www.apple.com/itunes/download&quot;&gt;iTunes&lt;/a&gt;  before attempting to update.&lt;/li&gt;
&lt;li&gt;Connect your device to your computer.&lt;/li&gt;
&lt;li&gt;Select your iPhone, iPad, or iPod touch when it appears in iTunes under Devices.&lt;/li&gt;
&lt;li&gt;Select the Summary tab.&lt;/li&gt;
&lt;li&gt;Select the Restore option.&lt;/li&gt;
&lt;li&gt;When prompted to back up your settings before restoring, select 
the Back Up option (see in the image below). If you have just backed up 
the device, it is not necessary to create another.&lt;br /&gt;
    &lt;img alt=&quot;Prompt text: &amp;quot;Do you want to back up the settings for the iPod before restoring the sofware?&amp;quot;&quot; height=&quot;165&quot; hspace=&quot;10&quot; src=&quot;http://km.support.apple.com/library/APPLE/APPLECARE_ALLGEOS/HT1414/HT1414_04--back_up_settings-002-en.png&quot; vspace=&quot;10&quot; width=&quot;390&quot; /&gt;&lt;/li&gt;
&lt;li&gt;Select the Restore option when iTunes prompts you (as long as 
you&#39;ve backed up, you should not have to worry about restoring your iOS 
device).&lt;br /&gt;
    &lt;img alt=&quot;Prompt text: &amp;quot;Are you sure you want to restore the iPod to its factory settings? All of your mnedia and other date will be erased.&amp;quot;&quot; height=&quot;198&quot; hspace=&quot;10&quot; src=&quot;http://km.support.apple.com/library/APPLE/APPLECARE_ALLGEOS/HT1414/HT1414_05--restore_dialog-002-en.png&quot; vspace=&quot;10&quot; width=&quot;390&quot; /&gt;&lt;/li&gt;
&lt;li&gt;When the restore process has completed, the device restarts and displays the Apple logo while starting up:&lt;br /&gt;
    &lt;img alt=&quot;Prompt text: &amp;quot;Your iPod has been successfully restored to factory settings, and is restarting. Please leave your iPod connected. It will appear in the iTunes window after it restarts.&amp;quot;&quot; height=&quot;176&quot; hspace=&quot;10&quot; src=&quot;http://km.support.apple.com/library/APPLE/APPLECARE_ALLGEOS/HT1414/HT1414_05--restored-003-en.png&quot; vspace=&quot;10&quot; width=&quot;390&quot; /&gt;&lt;br /&gt;
    After a restore, the iOS device displays the &quot;Connect to iTunes&quot; 
screen. For updating to iOS 5 or later, follow the steps in the iOS 
Setup Assistant.  For earlier versions of iOS, keep your device 
connected until the &quot;Connect to iTunes&quot; screen goes away or you see 
&quot;iPhone is activated.&quot; &lt;br /&gt;
    &lt;img alt=&quot;&quot; height=&quot;300&quot; hspace=&quot;10&quot; src=&quot;http://km.support.apple.com/library/APPLE/APPLECARE_ALLGEOS/HT1414/HT1414_06--connect-003-en.PNG&quot; vspace=&quot;10&quot; width=&quot;200&quot; /&gt;  &lt;img alt=&quot;&quot; height=&quot;300&quot; hspace=&quot;10&quot; src=&quot;http://km.support.apple.com/library/APPLE/APPLECARE_ALLGEOS/HT1414/HT1414_07--activated-002-en.png&quot; vspace=&quot;10&quot; width=&quot;200&quot; /&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/blockquote&gt;
&lt;br /&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;









Securely Erasing your Android Device&lt;/h3&gt;
If you have an Android phone
 or tablet, you also have an easy option to securely erase the data. 
Though it&#39;s not quite as simple as with Apple devices, since Android has
 many versions and many devices that it supports. On Android, within the
 &lt;i&gt;Privacy Settings&lt;/i&gt; dialog there is an option to delete all the data. The &lt;a href=&quot;http://support.google.com/mobile/bin/answer.py?hl=en&amp;amp;answer=169103&quot;&gt;Google online manual for Android&lt;/a&gt; describes the option this way: &lt;br /&gt;
&lt;blockquote class=&quot;tr_bq&quot;&gt;
Opens a dialog where you can erase all of your personal data from 
internal tablet storage, including information about your Google 
Account, any other accounts, your system and application settings, any 
downloaded applications, as well as your music, photos, videos, and 
other files.&lt;/blockquote&gt;
You should make sure that you have 
selected the options to delete internal memory and any memory on a SD 
card. If you don&#39;t have that option, the easiest thing to do would be to
 simply remove the SD card before donating, recycling, selling or giving
 it away.&lt;br /&gt;
&lt;br /&gt;

&lt;h3 style=&quot;text-align: left;&quot;&gt;
Securely Erasing your Blackberry Device&lt;/h3&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Research
 In Motion&#39;s Blackberry devices differ in the steps to wipe them. 
Instead of trying to mention all versions and models, I&#39;ll suggest you 
look through &lt;i&gt;Settings&lt;/i&gt;, &lt;i&gt;Options&lt;/i&gt; or &lt;i&gt;Device Settings&lt;/i&gt; to find something that mentions &lt;i&gt;Security&lt;/i&gt;. In there, you should find something that says &lt;i&gt;Security Wipe&lt;/i&gt; or &lt;i&gt;Wipe Handheld&lt;/i&gt;. For specific directions you may be able to search the web and find help.&lt;br /&gt;
&lt;br /&gt;
The same advice for SD cards applies to the Blackberry as to the Android 
phones. If it doesn&#39;t offer you the option, you should probably just the
 card.&lt;/div&gt;
&lt;br /&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;


Securely Erasing your Windows Mobile Device&lt;/h3&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
Microsoft Windows Mobile also has multiple versions with different ways to 
securely erase your data. And again, my advice is to explore on your 
own. Look through &lt;i&gt;Settings&lt;/i&gt; or &lt;i&gt;Options&lt;/i&gt; until you find something called &lt;i&gt;System Tab&lt;/i&gt;, &lt;i&gt;Security&lt;/i&gt;, or &lt;i&gt;About&lt;/i&gt;. In there you should see &lt;i&gt;Reset&lt;/i&gt;, &lt;i&gt;Reset your Phone&lt;/i&gt; or &lt;i&gt;Clear Storage&lt;/i&gt;. Again, for specific directions you may be able to search the web and find help.&lt;br /&gt;
&lt;br /&gt;
And for SD cards on Windows Mobile devices, you should likely just keep it.&lt;/div&gt;
&lt;br /&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;


Securely Erasing your Desktop or Laptop&lt;/h3&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
There is some great free software called &lt;a href=&quot;http://www.dban.org/download&quot;&gt;DBAN that will securely erase data&lt;/a&gt;
 from your desktop or laptop. I&#39;ve personally used it for years and 
highly recommend it. Simply download the ISO file and burn it to CD or 
DVD. The method to do this varies across operating systems. If you need 
help, search the Internet and you&#39;ll find lots of information.&lt;/div&gt;
&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/7328627400731584942/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/7328627400731584942' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7328627400731584942'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7328627400731584942'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/05/securely-deleting-data-before-donating.html' title='Securely Deleting Data Before Donating or Recycling Your Devices'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-7596622745319442777</id><published>2012-05-09T10:02:00.000-04:00</published><updated>2012-05-09T10:02:23.938-04:00</updated><title type='text'>Off Topic: Traveling with Technology</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
There was a Twitter conversation with &lt;a data-mce-href=&quot;https://twitter.com/#!/mckeay&quot; href=&quot;https://twitter.com/#%21/mckeay&quot;&gt;Martin McKeay&lt;/a&gt; and &lt;a data-mce-href=&quot;https://twitter.com/#!/JGamblin&quot; href=&quot;https://twitter.com/#%21/JGamblin&quot;&gt;Jerry Gamblin&lt;/a&gt;
 today talking about how geeks handle traveling with all our technology.
 Jerry suggested that Martin write a blog post, but I decided to beat 
him to the punch. ;) This is part of an upcoming series of posts to my &lt;a href=&quot;http://meanderingwoods.com/&quot;&gt;travel blog&lt;/a&gt; under 
the heading of &lt;a data-mce-href=&quot;http://meanderingwoods.com/2012/05/travel-skills-art-of-packing.html&quot; href=&quot;http://meanderingwoods.com/2012/05/travel-skills-art-of-packing.html&quot;&gt;Traveling Skills: The Art of Packing&lt;/a&gt;. In this post I describe how and what I pack as a geek who travels with technology, as well as why. Even though it&#39;s a bit off topic, I&#39;m mentioning it here since so many of the folks who read this blog travel a lot.&lt;br /&gt;
&lt;br /&gt;
I hope you enjoy it! &lt;a href=&quot;http://meanderingwoods.com/2012/05/tips-for-traveling-with-technology.html&quot;&gt;Tips for Traveling with Technology&lt;/a&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/7596622745319442777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/7596622745319442777' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7596622745319442777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7596622745319442777'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/05/off-topic-traveling-with-technology.html' title='Off Topic: Traveling with Technology'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-4834070207557413232</id><published>2012-05-09T06:20:00.001-04:00</published><updated>2012-05-09T06:23:13.260-04:00</updated><title type='text'>Detecting DNS Changer Infection with CloudFlare and OpenDNS</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
If you&#39;re using &lt;a href=&quot;http://cloudflare.com/&quot;&gt;CloudFlare&lt;/a&gt; to enhance speed and security (it&#39;s a great, free service, by the way!), you&#39;ll want to check out one of their latest apps, created in conjunction with &lt;a href=&quot;http://opendns.com/&quot;&gt;OpenDNS&lt;/a&gt;. The app will notify your website visitors if they are infected with the &lt;a href=&quot;http://www.dcwg.org/&quot;&gt;DNS Changer malware&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
If you&#39;re not familiar with the DNS Changer malware, it modifies settings of the victim computers, rerouting traffic to banks and other sites of interests through the hands of the bot masters. This means sensitive information could be compromised. &lt;br /&gt;
&lt;br /&gt;
Last year the FBI was able to legally take over the DNS Changer rerouting systems, protecting the victims to some degree. However, the FBI has to relinquish control in July, meaning victim systems which have not been fixed will be unable to access websites as normal. The &lt;a href=&quot;http://www.fbi.gov/DNS-changer-malware.pdf&quot;&gt;FBI has an in-depth writeup on the DNS Changer malware&lt;/a&gt; (PDF link), along with information on how to find out if you&#39;re infected and how to fix the problem. &lt;br /&gt;
&lt;br /&gt;
Enter the CloudFlare application. If you enable this application, &lt;a href=&quot;http://blog.cloudflare.com/cloudflare-opendns-work-together-to-save-the&quot;&gt;CloudFlare will notify DNS Changer infected visitors&lt;/a&gt; to your website that are compromised. They also provide a link with instructions on how to fix the problem. Here&#39;s what the notification looks like:&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;http://s3.amazonaws.com/files.posterous.com/temp-2012-05-03/tmGasawDhCspjxIhnquHGgGbuJjElyufCiyECqBiADFodEdcDEAsgwsCkljz/banner_example.png?AWSAccessKeyId=AKIAJFZAE65UYRT34AOQ&amp;amp;Expires=1336559086&amp;amp;Signature=zwumXgWprcmxrDze0tI%2BUTublTc%3D&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;83&quot; src=&quot;http://s3.amazonaws.com/files.posterous.com/temp-2012-05-03/tmGasawDhCspjxIhnquHGgGbuJjElyufCiyECqBiADFodEdcDEAsgwsCkljz/banner_example.png?AWSAccessKeyId=AKIAJFZAE65UYRT34AOQ&amp;amp;Expires=1336559086&amp;amp;Signature=zwumXgWprcmxrDze0tI%2BUTublTc%3D&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/4834070207557413232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/4834070207557413232' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/4834070207557413232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/4834070207557413232'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/05/detecting-dns-changer-infection-with.html' title='Detecting DNS Changer Infection with CloudFlare and OpenDNS'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-4093527712532697981</id><published>2012-05-04T09:09:00.000-04:00</published><updated>2012-05-04T09:09:47.733-04:00</updated><title type='text'>Firewalls and Anti-Virus Aren&#39;t Dead - Should They Be?</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
Over the last several years, firewalls and anti-virus have been losing effectiveness. Many in the information security community have recognized this. Unfortunately many of the business and operations people haven&#39;t. The threats that these technologies (tools to assist in a solution, not the solution themselves) were designed to solve have changed. That&#39;s not to say that they do nothing - they can still be useful - but your organization needs to know what they&#39;re meant to counter and how to use them properly. &lt;br /&gt;
&lt;br /&gt;
I was inspired to finally write this down by a story Wendy Nather contributed to Infosec Island, entitled &lt;a href=&quot;https://www.infosecisland.com/blogview/20734-Why-We-Still-Need-Firewalls-and-AV.html&quot;&gt;Why We Still Need Firewalls and AV&lt;/a&gt;. While I agree with her general premise, I think the article doesn&#39;t get to the real heart of the issue. When firewalls and anti-virus were all we had and effectively countered 
the threats we faced, they tended to be used more as they were designed.
 But now, firewalls and anti-virus don&#39;t counter the majority of the 
threats and aren&#39;t used very well.&lt;br /&gt;
&lt;br /&gt;
Firewalls were invented a couple of decades ago to keep Internet-borne threats out. The &lt;a href=&quot;http://www.darkreading.com/security/news/208803808&quot;&gt;firewall has its roots in the early 1990s&lt;/a&gt;, a time when &lt;a href=&quot;http://en.wikipedia.org/wiki/History_of_the_Internet#Opening_the_network_to_commerce&quot;&gt;commerce was prohibited on the Internet&lt;/a&gt; and most companies didn&#39;t have any presence there. As computer networking grew in popularity, connecting to the Internet was a way to share information across organizations, as well as internally. However, within a decade, Internet attacks were prevalent and organizations needed a way to protect the devices on their network. The firewall was popularized as a way to enforce a hard separation between the outside and the inside. The major advantage to this approach was that it was much cheaper than securing every single device. And at the time just as effective, since most devices had no need to communicate over the Internet and so a small set of connections were allowed to pass through the firewall.&lt;br /&gt;
&lt;br /&gt;
The Internet landscape has changed drastically since then. And with it, the Internet threats. Modern business processes are highly dependent upon and thoroughly integrated with the Internet. Organizations invite masses of Internet devices into their network to deliver web pages, email content, support mobile devices and dozens of other reasons. At the same time, devices within the network routinely initiate communications to the Internet and pass data back and forth. Firewalls have gotten better, but they simply can&#39;t handle the new ways in which organizations work on the Internet, nor the more sophisticated threats. They still have a use as a tool to protect networks, but more tools are needed.&lt;br /&gt;
&lt;br /&gt;
Similarly, anti-virus was first developed to detect, prevent and remove individual viruses. These software packages were simplistic, identifying malicious programs and files by looking for indicators or &quot;signatures&quot; that were unique to each virus. This was, again, before the Internet was widely used and most virus transmission was very slow. The anti-virus industry was easily able to keep up with new viruses and forms of existing viruses. This was a time when the number of specimens was very small and they didn&#39;t change very often. Updating the signatures was a task done once a year or so, and in fact when the subscription-based licensing model for anti-virus was initially launched it was widely viewed as somewhat of a betrayal of trust - paying continually for the same software. It was a different time.&lt;br /&gt;
&lt;br /&gt;
But today&#39;s situation is vastly different from what anti-virus was designed to deal with. Because of the proliferation of Internet connectivity, malicious software spreads very quickly. Instead of taking months to spread to thousands of systems, it takes seconds to spread to millions. And the malware itself has become much better at avoiding detection, taking steps to hide its signature. Most viruses today are obfuscated a number of times and checked to make sure no anti-virus software can detect it - all in a matter of seconds, and all before it&#39;s sent out to its victim. And viruses are often created and distributed in such a way that anti-virus vendors don&#39;t get a copy before the malicious software finds its victim. And when it does infect a device, it frequently disables any anti-virus software and hides in such a way that it can&#39;t be detected except by sophisticated, usually manual techniques. Anti-virus software largely still relies on signature based detection, which is increasingly growing ineffective and often slows down system performance.&lt;br /&gt;
&lt;br /&gt;
Further decreasing the effectiveness of firewalls and anti-virus in organizations is the way they&#39;re used. Because of the massive number of connections in and out of a network, definitions of what is and is not allowed and exactly how to allow or deny network connections have become a sprawling mess. And underneath all this complexity, many organizations don&#39;t even do the basics right - properly configuring and managing these tools. And administering anti-virus often means running daily reports of issues and sending a technician onsite to manually investigate what&#39;s gone wrong. Firewalls and anti-virus cost many organizations millions of dollars a year and are failing to do what they should. &lt;br /&gt;
&lt;br /&gt;
So why should we keep these things around? In the case of firewalls, they do exactly what they are supposed to do and do it quite well. Organizations just need to get smarter about using them. That means limiting firewalls&#39; purpose to what they do well and handing off other duties to other tools. In addition, organizations need to make sure they have a good firewall management program - even small organizations. And anti-virus should be re-understood as a broader concept of endpoint protection. This includes securing configurations and access, restricting software to that which is known to be safe and putting tools in place to detect anomalous behavior. Anti-virus software packages can help fulfill the last piece - telling systems administrators that a known threat has been detected or that suspicious activity has been happening.&lt;br /&gt;
&lt;br /&gt;
But one thing I think we as security professionals should be advocating is reducing the amount of money and resources spent on these technologies. Instead, shift to more effective ways to secure an organization. For example, by providing better training to IT staff for using with the existing tools and technologies. Or improving security awareness programs so that viruses (not to mention many other types of attacks) are less likely to be effective. In the end, this will allow an organization to maintain the same level of security at a lower cost or to increase security at the same cost. &lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/4093527712532697981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/4093527712532697981' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/4093527712532697981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/4093527712532697981'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/05/firewalls-and-anti-virus-arent-dead.html' title='Firewalls and Anti-Virus Aren&#39;t Dead - Should They Be?'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-446478645180840449</id><published>2012-05-02T10:05:00.000-04:00</published><updated>2012-05-02T10:05:44.216-04:00</updated><title type='text'>What Infosec Can Learn from Enron</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
Enron&#39;s financial auditors and management conspired against their investors. 
The system that was supposed to protect against this kind of fraud, 
instead worked against the people it was supposed to protect. And there 
was hell to pay when the organizations collapsed and when the fraud was 
exposed. The Harvard Business Review today makes the point that &lt;a href=&quot;http://blogs.hbr.org/cs/2012/05/if_the_auditors_sign_off_on_it.html&quot;&gt;just because an auditor approves something, that doesn&#39;t always mean its right&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Information security professionals, take a lesson from Enron: auditors aren&#39;t the sole authoritative voice, and they can be fooled or coerced just like anyone else. Too often internal and external auditors are trusted as &lt;b&gt;the&lt;/b&gt; arbiters of what&#39;s right and wrong. But this can fail an organization if the executives don&#39;t understand what role the auditors &lt;b&gt;should&lt;/b&gt; be playing.&lt;br /&gt;
&lt;br /&gt;
Auditors serve as an important check on the system by assessing against a known framework. But there is always room for interpretation in any standard. That&#39;s especially true in areas where standards are evolving quickly or where a new field is opening up. That was the case for Enron with the &quot;mark to market&quot; strategy, and that is true today in Infosec.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;How do auditors fail the organizations they serve?&lt;/b&gt; &lt;br /&gt;
Let&#39;s use the Payment Card Industry Data Security Standard (PCI-DSS) as an example. The &lt;a href=&quot;http://www.darkreading.com/blog/232900976/pci-dead-man-date-walking.html&quot;&gt;PCI-DSS has done a lot of good&lt;/a&gt; over the years it has been around. But as IT, payment systems and threats have changed, it has had a hard time keeping up. As an instructor famously said in a class I attended, the DSS only changes once every two years; but the Security Standards Council (SSC) can change the meaning of the words they use at any time.&lt;br /&gt;
&lt;br /&gt;
The PCI-DSS has also heavily misinterpreted. The standard is meant to be flexible so organizations can find the right security controls, rather than blindly following what&#39;s written. However, many auditors stick staunchly to the standard, verbatim. That means the company either has to jump through hoops to get their official compliance stamp, or can game the system to fit within the narrow definitions. Other auditors are so easily influenced or coerced by their client that virtually any control is deemed adequate. &lt;br /&gt;
&lt;br /&gt;
And there&#39;s room for abuse of the standards, as well. Some audit companies are well-known for providing &quot;clean&quot; or &quot;green&quot; reports to their clients (sometimes those who spend above a certain dollar level), regardless of what the actual security looks like. Breaches have left several organizations wondering why they paid high fees to auditors who didn&#39;t find the security flaws.&lt;br /&gt;
&lt;br /&gt;
So it&#39;s important to know how much to trust your auditors and what role they serve. You can&#39;t give them authority to make your decisions for you, but you can use them as advisers. In the Enron case, their auditors had huge amounts of business in other areas, meaning there was a conflict. In your organization the auditor may be trying to get a big contract, unseat a competitor, make a name for himself or whatever. In these cases the bad advice is almost always unintentional, but still present.&lt;br /&gt;
&lt;br /&gt;
Probably once every month or two I speak with a high-level executive 
looking to hire someone to check behind their auditor. It&#39;s usually 
because the executive suspects of one of the failures above. In reviewing the work done by the 
auditor I usually find that the executive&#39;s instinct is right.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;How can you help your audit succeed?&lt;/b&gt;&lt;br /&gt;
Choose your auditors carefully and use the right process. I helped write the &lt;a href=&quot;http://www.sans.org/reading_room/analysts_program/secureworks_11_2010_2.pdf&quot;&gt;SANS whitepaper How to Choose a Qualified Security Assessor&lt;/a&gt; (PDF link) and there&#39;s other &lt;a href=&quot;http://www.brighttalk.com/webcast/188/39117&quot;&gt;good questions to ask for choosing an auditor&lt;/a&gt; elsewhere. But it goes beyond just choosing the right auditor, you have to have the right audit process in place. Here are some tips to avoid the pitfalls that got Enron into trouble.&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;&lt;b&gt;Evaluate Reputation&lt;/b&gt;. Not just whether they&#39;ve done a lot of audits before, or whether all their clients pass, but whether they are perceived to have high integrity, technical capabilities and security knowledge. Don&#39;t get this from the auditor or their hand-picked references, ask around. Reputations follow companies and people and are spread quickly.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Evaluate Skillset&lt;/b&gt;. Auditors falling too far toward leniency or rigidity often do so because they are not well-versed in IT and security. That means they don&#39;t understand the intent of the standards they&#39;re auditing against, which means they can&#39;t possible give you good advice that&#39;s outside of the letter of the standard.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Oversight&lt;/b&gt;. Make sure there is good oversight of the auditors that are performing the work. This could be done by an internal audit group, a CISO or even a CIO. The point is that someone needs to make sure the work is not just done, but done right - thorough, accurate and independent.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Use Auditors as Checks&lt;/b&gt;. Don&#39;t forget that auditors should be checks on what you&#39;re doing, they shouldn&#39;t be telling you exactly how to do it. They&#39;ve often got a lot of good advice, but you have to weigh that advice carefully within the context of your business and your ethics.&lt;/li&gt;
&lt;/ul&gt;
But even going through a thorough diligence process can get you stuck with a bad auditor. That happens. But when it does, you&#39;ve always got the option to get a second opinion. And I&#39;ll leave you with a great video on &lt;a href=&quot;http://www.brighttalk.com/webcast/188/39117&quot;&gt;some signs you&#39;ve got a bad auditor&lt;/a&gt;. &lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/446478645180840449/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/446478645180840449' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/446478645180840449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/446478645180840449'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/05/what-infosec-can-learn-from-enron.html' title='What Infosec Can Learn from Enron'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-5142381247668877227</id><published>2012-04-28T09:36:00.001-04:00</published><updated>2012-05-07T04:49:50.069-04:00</updated><title type='text'>What Biosecurity Can Learn From Infosec</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
&lt;b&gt;Introduction&lt;/b&gt;&lt;br /&gt;
Recently there has been been debate over research on the H1N1 strain of influenza. This is the strain sometimes called avian flu or bird flu. Many researchers have been studying all they can about the disease, while many researchers, institutes and governments are trying to prevent more research. The arguments on both sides are complex and nuanced, and each side has many valid points.&lt;br /&gt;
&lt;br /&gt;
While I don&#39;t want to recap the entire argument, I&#39;ll try to summarize each position in a sentence or two. The pro- side believes that legitimate research will help us deal with any eventual version of the virus that can spread from human-to-human. The con- side belives that research makes it more likely that a very deadly strain might make its way out of the lab, or that terrorists or governments will be able to more quickly have a weaponized strain. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Current Situation&lt;/b&gt;&lt;br /&gt;
While public science on H1N1 may cease, the virus itself will keep evolving. Life will always experiment with new forms. 
Eventually one of these may be a variant of H1N1 that is successful in 
spreading human-to-human. That is, it finds a new evolutionary niche it 
can exploit.&lt;br /&gt;
&lt;br /&gt;
And certainly it&#39;s to be expected that 
organizations currently researching biotechnology for warfare would 
continue. What we saw with chemical weapons in the first World War was 
private research done by corporations being co-opted for use by the 
military. Bioweapons research groups may even reduce or discontinue 
their work in the presence of public research, because any effective 
weapon is likely to be much less effective if it is well understood and 
can be effectively combated.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Comparison to Infosec&lt;/b&gt;&lt;br /&gt;
There has always been a lot of research on finding security vulnerabilities in software. Some researchers look for vulnerabilities so issues can be fixed. Some researchers look for vulnerabilities so they can break into systems. And so in the Infosec community we used to have similar discussions as those going on in the Biotechnology and Biosecurity community now.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
That debate always used to remind me of a bad movie chase scene. 
When the person fleeing sees a big rock coming
 up quickly, he stays calm and turns at just the right angle - a near miss. When 
the person chasing sees it he panics and throws his arms in front of his face -
 a gratuitous explosion ensues.&lt;br /&gt;
&lt;br /&gt;
Fortunately in the Infosec industry we have mostly moved toward the first course - staying calm and taking just the right angle. But for a while we, too, had lots of people who tried to make the rock go away by hiding from it. Many times this was software developers who reacted more violently to the legitimate research than to the criminal research! And the software developers have benefited by having much more robust and secure products. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Benefits of research and publication&lt;/b&gt;&lt;br /&gt;
Research helps in that:&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;identifies potential issues before they are found in the wild&lt;/li&gt;
&lt;li&gt;allows us to prepare for likely strains before we see them&lt;/li&gt;
&lt;li&gt;able to refine methods of doing this kind of research&lt;/li&gt;
&lt;li&gt;gives us a better idea of the actual threat level - more or less severe than imagined&lt;/li&gt;
&lt;li&gt;shows us indicators of what an outbreak might look like&lt;/li&gt;
&lt;li&gt;shows us indicators of what an attacker might need to create a bioweapon&lt;/li&gt;
&lt;/ul&gt;
Publication helps in that:&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;publicizes the fact that these risks exist and are being studied&lt;/li&gt;
&lt;li&gt;attracts more scientists&lt;/li&gt;
&lt;li&gt;attracts more funding&lt;/li&gt;
&lt;li&gt;allows results to be peer reviewed&lt;/li&gt;
&lt;li&gt;identifies those working in the field to facilitate collaboration&lt;/li&gt;
&lt;/ul&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;/ul&gt;
&lt;b&gt;Alleviating fears&lt;/b&gt;&lt;br /&gt;
One fear is that the research may be co-opted by a nation state for biowarfare. But I would argue that the antidote for that is more research, not less. The same fear exists in Infosec and that&#39;s just the way we&#39;ve tried to deal with it. Hundreds of people doing security research, banging away on software. They&#39;re not going to find all of the bugs, but they&#39;re likely to find quite a few of them. Looking at it from the other direction, if governments quash open, public research, the only people who will be looking for a bug will be the ones looking for a weapon. And of course you can&#39;t legislate nature not to find a virulent strain.&lt;br /&gt;
&lt;br /&gt;
But like in the Infosec community, there is still a question of the right amount of disclosure. Some in both fields advocate a full disclosure stance. That is, every detail should be published as soon as it is known. Others advocate a more limited disclosure policy, only publicly releasing enough information to describe the issue and to protect against it. Releasing certain technical details only to those who will be a part of the solution to the problem.&lt;br /&gt;
&lt;br /&gt;
Publishing technical details is important for a couple of reasons. First, it ensures that the results can be replicated. This part of the scientific process is critical to the reliability of the results, as well as to identify potentially significant but unknown variables or mistakes. Second it provides foundations upon which future scientists can improve their techniques. Process and methodological innovation are critical to the scientific process, especially in this case where nature and bioterrorists are continually improving their results.&lt;br /&gt;
&lt;br /&gt;
In many minds, the biggest fear is that we do nothing. If nature or a bioweapons group creates a viable threat, our lack of preparation will doom us to a greater impact. But if we understand the H1N1 virus well then we will either have defenses in place or can quickly take action. And as previously mentioned, public research may discourage groups from trying to develop weaponized versions in the first place.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Summary&lt;/b&gt;&lt;br /&gt;
Biotechnology should be looking (particularly in the case of Avian H5N1 
Influenza) to increase scientific study and publication, rather than 
suppress it. The more scientists who work on it and publish their 
results, the more likely we are to find a way to defeat both a natural 
and unnatural strain of the disease. But certain technical details 
should be limited to a smaller group &lt;i&gt;who rigorously review those details &lt;/i&gt;to make sure legitimate researchers stay ahead of the alternatives. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Articles&lt;/b&gt;&lt;br /&gt;
http://www.virology.ws/2012/01/03/should-we-fear-avian-h5n1-influenza/&lt;br /&gt;
http://www.economist.com/node/21553448&lt;br /&gt;
http://arstechnica.com/science/news/2012/02/maybe-avian-flu-isnt-that-deadly.ars&lt;br /&gt;
http://arstechnica.com/science/news/2012/02/study-of-deadly-flu-sparks-debate-amidst-fears-of-new-pandemic.ars&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Update 2012-05-07:&lt;/b&gt; Since I published this article, I&#39;ve had some discussions and there have been some new developments.&lt;br /&gt;
&lt;ul style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;First, the paper in question has been published. Second, &lt;a href=&quot;http://www.nature.com/nature/journal/v485/n7396/full/485005a.html&quot;&gt;Nature has written a good article explaining the circumstances around publishing the controversial article&lt;/a&gt;.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Second, I want to make clear that what I&#39;m advocating is for Biosecurity to review our discussions and debate and apply it to their own situation. In other words, learn from our mistakes, successes and thought processes to speed up and improve their own.&lt;/li&gt;
&lt;li&gt;Third, I&#39;ve replaced &quot;Biotechnology&quot; with &quot;Biosecurity&quot; where it seems appropriate, in order to clarify to whom I am referring. I know Biotech spends billions and has well developed processes in place for research. Infosec ourselves can probably learn from their process.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/5142381247668877227/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/5142381247668877227' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/5142381247668877227'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/5142381247668877227'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/04/what-biotechnology-researchers-can.html' title='What Biosecurity Can Learn From Infosec'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-7094501781612950633</id><published>2012-04-20T03:43:00.000-04:00</published><updated>2012-04-20T03:43:24.209-04:00</updated><title type='text'>Cybercrime Does(n&#39;t) Pay?</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
&lt;div&gt;
Earlier in the week a couple of Microsoft researchers released &lt;a href=&quot;http://www.nytimes.com/2012/04/15/opinion/sunday/the-cybercrime-wave-that-wasnt.html&quot;&gt;a study of cybercrime financial loss statistics&lt;/a&gt; (&lt;a href=&quot;https://research.microsoft.com/pubs/149886/SexLiesandCybercrimeSurveys.pdf&quot;&gt;Sex, Lies and Cybercrime Surveys&lt;/a&gt; - PDF link). Effectively their research indicated that bad sampling, survey and statistical methods have led to a number of dubious results. I think most of us who are involved in the industry have known this intuitively for a while. Any time you have metrics purportedly 
for the same thing that vary by factors of 10-1000, that says something isn&#39;t quite right.&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
The conclusion of the paper is essentially that estimates of the cybercrime economy are grossly exaggerated. And they make the point well enough that I won&#39;t belabor it here. Go read the actual article (linked above). I&#39;m more interested in how this applies to other areas and studies. Here are a couple of points I think are particularly relevant, as well as a couple of others. &lt;/div&gt;
&lt;div&gt;
&lt;ol style=&quot;text-align: left;&quot;&gt;
&lt;li&gt;&lt;b&gt;Heavy Tails&lt;/b&gt;. Means (averages) are most useful when all the data are clustered closely around that number. When the distribution is very wide, you&#39;re going to have a problem getting people to understand what the results mean. For example, if I said that the average cost of a DVD player is $100 it doesn&#39;t tell you anything meaningful about the market for DVD players. That&#39;s because the costs range broadly, so the mean is almost arbitrarily in the middle somewhere.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Garbage In, Garbage Out (GIGO)&lt;/b&gt;. Since the data in these studies is typically collected by sending surveys, it&#39;s impossible to verify its integrity. In some cases people outright lie, but in others they simply don&#39;t know true costs and are just guessing. They may be higher or lower than the actual, but since there are never negative values, the overall trend almost necessarily has to push the number higher than the true value. But by how much it&#39;s impossible to know.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Attribution&lt;/b&gt;. It&#39;s not easy to know where fraud came from. How do you know that somebody stole your credit card number from an online database, versus going through your trash or copying it at the restaurant down the street? This kind of attribution is especially hard for consumers who often can only know about an incident after actual fraud or if they are issued a new credit card. If both things happen within a year or so, the consumer is likely to think one caused the other, though as we know correlation does not imply causation.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Self-Selecting Population&lt;/b&gt;. The people who respond have at least one thing in common - they return surveys. They may have other things in common, like a tendency to overestimate numbers, to be particularly susceptible to cybercrime, or any number of dozens of things that could influence the validity of these studies.&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;div&gt;
This isn&#39;t just a problem that affects cybercrime statistics, though. The Ponemon institute annually puts out a similar 
&lt;a href=&quot;http://www.ponemon.org/blog/post/cost-of-a-data-breach-climbs-higher&quot;&gt;report on losses due to breaches&lt;/a&gt; (as well as a &lt;a href=&quot;http://www.ponemon.org/blog/post/second-cost-of-cyber-crime-study-is-released-today&quot;&gt;report on cybercrime&lt;/a&gt;). Their methodology is similar to the ones discussed in the Microsoft paper, and therefore suffers from some of the same flaws. To get consistent results over time that show a trend consistent with expectation, I suspect that some data manipulation goes on, which would add yet another layer of bad science (if true - I only have my gut instinct to go on, not any facts).&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
One
 group that tries obsessively to get the science right is &lt;a href=&quot;http://www.verizonbusiness.com/Products/security/dbir/&quot;&gt;Verizon Business who puts out an annual breach report&lt;/a&gt;. This uses much better science and statistics and 
can be counted on to have some rigor. Results can vary wildly year-over-year 
because they are always introducing new data populations (several groups 
contribute their figures, most with a different demographic that they 
serve), but that will normalize somewhat in the next 5 years as their 
data set gets big enough that new populations skew it less. The raw data is collected and published openly so there can be some good peer review of it, an important step for ensuring validity of results and conclusions.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
But these studies don&#39;t have to be done poorly. By changing the way the researchers go about it, they could get much better results. For example, if instead of going to consumers with a survey, the authors had been able to get the information from banks the numbers would have likely been very different. The banks would have objective measurements of customer losses, a properly large sample size, a randomly distributed population, and would likely know more about the source of the fraud. &lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Although many of these studies fail at basic science, I&#39;m hopeful that 
the information security industry will get better. Both at true academic
 research and at coming up with accurate public metrics for many of the 
most important data. We&#39;ll get there as we mature as an industry, but it will take a while. Until then, stay skeptical.&lt;/div&gt;
&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/7094501781612950633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/7094501781612950633' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7094501781612950633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/7094501781612950633'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/04/cybercrime-doesnt-pay.html' title='Cybercrime Does(n&#39;t) Pay?'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-1714923822996122195</id><published>2012-04-19T09:35:00.000-04:00</published><updated>2012-04-19T09:35:25.612-04:00</updated><title type='text'>Back: Better, Faster, Stronger</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
I&#39;m back! After about a 4 year hiatus in this space, I plan on remaking my place in the security blogosphere. Not that I haven&#39;t been active since then in security - I have! And I&#39;ve been involved in the community, too. But this space has been conspicuously vacant as I&#39;ve tried to maintain a relatively low profile.&lt;br /&gt;
&lt;br /&gt;
But now I&#39;ll be back to saying it publicly, rather than sending it through a corporate lens or self-censoring. I&#39;ll be posting as often as I find the time to cobble something together. If the past 4 years of output is anything to judge by, that will probably be a lot of stuff coming your way! And I&#39;m going to try to play around with the content, format and delivery too. Keep it loose and entertaining, as well as informative.&lt;br /&gt;
&lt;br /&gt;
One key to that, I think, will be to make better use of social media. I&#39;m going to start off with Twitter, as that tends to be where most of my colleagues and peers gather. So if you haven&#39;t already, hit me up @beauwoods.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/1714923822996122195/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/1714923822996122195' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1714923822996122195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1714923822996122195'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2012/04/back-better-faster-stronger.html' title='Back: Better, Faster, Stronger'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-4304860742295591416</id><published>2011-03-30T09:54:00.000-04:00</published><updated>2012-04-19T10:03:37.078-04:00</updated><title type='text'>Health Net Loses More Patient Records</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
This month news came out that &lt;a href=&quot;http://datalossdb.org/incidents/3422-unaccounted-for-servers-drives-contained-personal-medical-and-financial-info-on-members-employees-and-healthcare-providers&quot;&gt;Health Net lost another 1.9 million patient records&lt;/a&gt;. This comes on the heels of a 1.5 million record loss just two years ago.&lt;br /&gt;
&lt;br /&gt;
A previous data loss event happened in May of 2009, but the company only informed the state Attorneys General where
 disclosure laws exist, and that took nearly six months. They plan to, but have not yet, informed those 
affected. &lt;a href=&quot;http://www.healthleadersmedia.com/page-1/TEC-261704/Health-Net-Fined-55K-for-Data-Breach&quot;&gt;Vermont fined Health Net $55,000&lt;/a&gt; on behalf of the 525 state citizens who were affected. And &lt;a href=&quot;http://www.ihealthbeat.org/articles/2010/11/10/connecticut-insurance-commissioner-fines-health-net-375000.aspx&quot;&gt;Health Net paid $525,000 to settle two claims with the state of Connecticut&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
In the healthcare industry, the new HITECH provisions of the HIPAA rule address these data loss events. They require that an organization notify affected individuals within 60 days of a breach. Though there are provisions which would negate the obligation to notify (such as strong encryption or quick recovery), in the Health Net case these do not apply.&lt;br /&gt;
&lt;br /&gt;
In the May 2009 event, the company claims it took six months to identify what and whose data was lost. The information was stored unencrypted on a portable disk drive.  Not to worry, they say, the data was compressed only readable using specialty software. There are at least three things wrong with these positions.&lt;br /&gt;
&lt;br /&gt;
Companies need to know where their sensitive information is stored. Health Net claims that it took six months of forensic investigation to determine what was lost. There may be several explanations for this. Maybe they just don&#39;t know what they store where. Or maybe those trying to figure it out weren&#39;t good or didn&#39;t spend much time doing it. Or it&#39;s possible that the right people didn&#39;t know about the drive, didn&#39;t know it was lost or didn&#39;t know it may have contained sensitive information. But in the end, it comes down to a basic lack of data and asset tracking.&lt;br /&gt;
&lt;br /&gt;
Portable media is at high risk of theft and loss, so sensitive data stored there should be protected. Physical protection would mean keeping the media in authorized and secured areas; logical protection would mean encryption. But Health Net failed to do this.&lt;br /&gt;
&lt;br /&gt;
Though the data is supposedly unreadable without special software, I doubt this is the case. I&#39;ve sometimes found that proprietary formats - for which custom software is often very expensive - are nothing more than standard formats with cryptic file names. If you open the file with a text editor, document editor, image viewer or other widely available software, many times you have no problem extracting the data.&lt;br /&gt;
&lt;br /&gt;
But this problem isn&#39;t one that exists for Health Net alone. The &lt;a href=&quot;http://datalossdb.org/&quot;&gt;DataLossDB&lt;/a&gt; catalogs many of the data loss events that happen. Others remain undisclosed and unknown.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/4304860742295591416/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/4304860742295591416' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/4304860742295591416'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/4304860742295591416'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2011/03/health-net-loses-more-patient-records.html' title='Health Net Loses More Patient Records'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-1764452144892729625</id><published>2010-10-29T00:09:00.002-04:00</published><updated>2010-10-29T00:13:18.622-04:00</updated><title type='text'>Beau on the Local News</title><content type='html'>Blatant self-promotion. Hey, I can&#39;t help it. Check out the video, too.&lt;br /&gt;&lt;br /&gt;&lt;a onblur=&quot;try {parent.deselectBloggerImageGracefully();} catch(e) {}&quot; href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbje0jwgsX8xch-WqJOI5hfLe0Pz3gKCTpA4Acc8PziEkI1oQR_NvgInap6SOyYmcF1TZhrpQUloo8c2_xHstMMsExK-t674e14h1kSi1K4VZpYhjbnVx7UB33_yZkp0eclkU/s1600/Screen+shot+2010-10-18+at+11.11.42+PM.png&quot;&gt;&lt;img style=&quot;margin: 0pt 0pt 10px 10px; cursor: pointer; width: 400px; height: 306px;&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbje0jwgsX8xch-WqJOI5hfLe0Pz3gKCTpA4Acc8PziEkI1oQR_NvgInap6SOyYmcF1TZhrpQUloo8c2_xHstMMsExK-t674e14h1kSi1K4VZpYhjbnVx7UB33_yZkp0eclkU/s400/Screen+shot+2010-10-18+at+11.11.42+PM.png&quot; alt=&quot;&quot; id=&quot;BLOGGER_PHOTO_ID_5533315494368804050&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;object type=&quot;application/x-shockwave-flash&quot; id=&quot;video&quot; data=&quot;http://www.myfoxatlanta.com/video/videoplayer.swf?dppversion=5390&quot; width=&quot;320&quot; height=&quot;280&quot;&gt;&lt;param value=&quot;http://www.myfoxatlanta.com/video/videoplayer.swf?dppversion=5390&quot; name=&quot;movie&quot;&gt;&lt;param value=&quot;&amp;amp;skin=MP1ExternalAll-MFL.swf&amp;amp;embed=true&amp;amp;adSizeArray=300x240,,&amp;amp;adSrc=http%3A%2F%2Fad%2Edoubleclick%2Enet%2Fadx%2Ftsg%2Ewaga%2Fnews%2Fdetail%3Bdcmt%3Dtext%2Fxml%3Bpos%3D%3Btile%3D2%3Bfname%3Dfacebook%2Dsays%2Dapps%2Dtransmitted%2Duser%2Dinformation%2D101810%3Bloc%3Dsite%3Bsz%3D320x240%3Bord%3D389188023278796300%3Frand%3D0%2E8341895990474515&amp;amp;flv=http%3A%2F%2Fwww%2Emyfoxatlanta%2Ecom%2Ffeeds%2FoutboundFeed%3FobfType%3DVIDEO%5FPLAYER%5FSMIL%5FFEED%26componentId%3D133529629&amp;amp;img=http%3A%2F%2Fmedia2%2Emyfoxatlanta%2Ecom%2F%2Fphoto%2F2010%2F10%2F18%2F101810%5Ffacebooksecurity%5F11p%2EATL%5Ftmb0001%5F20101018232005%5F640%5F480%2EJPG&amp;amp;story=http%3A%2F%2Fwww%2Emyfoxatlanta%2Ecom%2Fdpp%2Fnews%2Ffacebook%2Dsays%2Dapps%2Dtransmitted%2Duser%2Dinformation%2D101810&amp;amp;category=news&amp;amp;title=101810%5Ffacebooksecurity%5F11p%2Emov&amp;amp;oacct=foximfoximwaga,foximglobal&amp;amp;ovns=foxinteractivemedia&quot; name=&quot;FlashVars&quot;&gt;&lt;param value=&quot;all&quot; name=&quot;allowNetworking&quot;&gt;&lt;param value=&quot;always&quot; name=&quot;allowScriptAccess&quot;&gt;&lt;/object&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/1764452144892729625/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/1764452144892729625' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1764452144892729625'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1764452144892729625'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2010/10/beau-on-local-news.html' title='Beau on the Local News'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbje0jwgsX8xch-WqJOI5hfLe0Pz3gKCTpA4Acc8PziEkI1oQR_NvgInap6SOyYmcF1TZhrpQUloo8c2_xHstMMsExK-t674e14h1kSi1K4VZpYhjbnVx7UB33_yZkp0eclkU/s72-c/Screen+shot+2010-10-18+at+11.11.42+PM.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34349059.post-1884906363670403522</id><published>2009-07-21T11:44:00.005-04:00</published><updated>2012-04-19T10:07:07.168-04:00</updated><title type='text'>Cyber War Against North Korea</title><content type='html'>&lt;div dir=&quot;ltr&quot; style=&quot;text-align: left;&quot; trbidi=&quot;on&quot;&gt;
I’ve heard people calling for &lt;a href=&quot;http://www.msnbc.msn.com/id/31072773/&quot;&gt;retaliation against North Korea&lt;/a&gt; for the latest  cyber attacks on the US and South Korean Internet sites. That idea is worse than  bad, it’s nearly insane. The best that could be hoped for in such a move would  be to saturate the attacker’s bandwidth and thus cancel out the attacks. The  worst that could happen would be a virtual Armageddon of factions fighting each  other on the Internet, with most of the damage being done to innocent  bystanders.&lt;br /&gt;
&lt;br /&gt;
The first mistake that proponents of retaliation make is  that they assume that &lt;a href=&quot;http://www.timesonline.co.uk/tol/news/world/asia/article6667440.ece&quot;&gt;North Korea’s government was behind the attack&lt;/a&gt;. But they  don’t ask for any evidence of this other than one of the possible beneficiaries  of the attacks would be the Kim Jong Il’s regime. In fact, conflicting evidence has been  pointing toward the &lt;a href=&quot;http://technology.timesonline.co.uk/tol/news/tech_and_web/the_web/article6715109.ece&quot;&gt;UK as one major source of the attack&lt;/a&gt;, and the &lt;a href=&quot;http://www.pcworld.com/businesscenter/article/168400/investigation_into_cyberattacks_stretches_around_the_globe.html&quot;&gt;botnet controller may reside in Florida&lt;/a&gt; – yet no calls have been made to attack the British or US governments.&lt;br /&gt;
&lt;br /&gt;
In fact, it&#39;s &lt;a href=&quot;http://www.nytimes.com/2009/07/17/technology/17cyber.html?_r=1&quot;&gt;unlikely that there is a North Korea-UK-US connection in these cyber attacks&lt;/a&gt;. It’s very difficult to  determine accurately and quickly who may be behind an attack. It is too easy to  hide the real source behind several layers of obfuscation and the perpetrator  may only be discovered after the attack has ended, if at all. The bottom line is that we just don&#39;t know who executed the attacks.&lt;br /&gt;
&lt;br /&gt;
Even if you  have the right country as the source of attacks, that doesn’t guarantee that the  government had any involvement. Looking at a different cyber-conflict, there’s  no doubt that Russians were behind the Estonian cyber attacks. But much of this activity was likely individuals within the country acting on nationalist sympathy, not  a government-sponsored network of attackers. As Marcus Ranum has pointed out, &lt;a href=&quot;http://conference.hitb.org/hitbsecconf2008kl/materials/KEYNOTE%202%20-%20Marcus%20Ranum%20-%20Cyberwar%20is%20Bullshit.pdf&quot;&gt;cyber war is unlikely&lt;/a&gt; (PDF link).&lt;br /&gt;
&lt;br /&gt;
Even if you assume that you have the right target, retaliating  against them will simply escalate the level of hostilities, not calm it. The  attackers will raise their level of attack and may practice asymmetric warfare,  taking out not just government sites but commercial ones, as well. One of the  best ways to change a government’s behavior is to hurt them financially or to  turn the people against them.&lt;br /&gt;
&lt;br /&gt;
Now consider a different scenario: someone  tries to get two other countries to fight each other. One individual can buy  access to 10,000 infected computers inside one of the countries. He then uses  these to launch an attack against another country’s Internet sites. The second  country then retaliates against the first. Voila! Cyber-war has erupted. In the  current botnet economy, this would cost $500-$1000 (according to a presentation  by Lenny Zeltser I can no longer find online).&lt;br /&gt;
&lt;br /&gt;
Some people have questioned why North Korea has  Internet connectivity at all. It would seem to be easy to find the choke points  – ISPs providing service – and get them to disconnect Pyongyang. With the McColo  situation, &lt;a href=&quot;http://www.eweek.com/c/a/Security/Botnet-Operators-Likely-to-Change-Tactics-in-Wake-of-McColo-Intercage-Shutdowns/?kc=rss&quot;&gt;the bad guys just jumped on other ISPs and diversified&lt;/a&gt;. With North  Korea, the people themselves are isolated from the rest of the world. But I  would suspect that the benefits from a connected country outweigh the potential  bad sides. It is much easier to get information out of the country via the  Internet than physically. So there is a vested interest in us having an Internet  connection out of North Korea – we can find out what goes on inside.&lt;br /&gt;
&lt;br /&gt;
So  the next time one of these cyber attacks happens and is hailed as the next step  in cyber warfare, take a step back and really look at the players and the  landscape. Consider what would be the best course of action. And remember that it is very difficult to determine who the attackers are, where they are located and what their motives are. Hopefully &lt;a href=&quot;http://holisticinfosec.blogspot.com/2009/07/pete-hoekstra-id-ten-t.html&quot;&gt;our  policy makers&lt;/a&gt; will do the same.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://beauwoods.blogspot.com/feeds/1884906363670403522/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment/fullpage/post/34349059/1884906363670403522' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1884906363670403522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34349059/posts/default/1884906363670403522'/><link rel='alternate' type='text/html' href='http://beauwoods.blogspot.com/2009/07/cyber-war-against-north-korea.html' title='Cyber War Against North Korea'/><author><name>bw</name><uri>http://www.blogger.com/profile/14184838605895449028</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>