Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, August 20, 2008

UK National Risk Register

The UK Cabinet Office has now made public information from the previously classified UK National Risk Register. This is available at http://www.cabinetoffice.gov.uk/reports/national_risk_register.aspx.


This seems to backup what many scientists have been saying. The greatest risk to the UK is not terrorism, or even global warming. It's an Influenza Pandemic.

Thursday, July 03, 2008

Hacking in Canberra

This week I've made my first visit to our nation's capital - Canberra - for a 6-day course in Hacker Techniques, Exploits and Incident Handling.

Canberra is a strange little city. It seems to me to be a cross-between Washington and Milton Keynes, in that it's clearly a Government town; the Federal government being the largest employer in this capital city which has only a population of 300,000. Yet like Milton Keynes, Canberra has an artificial feel to it. You can see the planning and design - it's not a city that has grown organically like most others. It's even got some of the same 60's carbuncles as Milton Keynes!

I've come to Canberra completely ill-prepared for the freezing temperatures. It's about 13 degrees C in the day but it drops down to zero at night. I new what the temperatures would be before I arrived and I thought I'd be ok, after all I am from the UK! However, I didn't realise how much I've acclimatised to the Queensland weather over the past year. 13 degrees C feels to me like -5 did in the UK! All I've brought is a thin jacket and some jeans and t-shirts. I didn't even pack a jumper.

Because it's so cold, tonight has been the first evening that I've dared to venture out. I had a gander around the city centre (which isn't much bigger than Doncaster town centre) and then went to the flicks to watch Hancock. I had planned to see the Indiana Jones film but the timing didn't work out very well, so then it was a toss-up between Hancock and Sex and the City. No contest - I couldn't bear the thought of sitting through 2 hours of self-obsessed women talking about shoes and Prada handbags.

I was pleasantly surprised with Hancock. I thought it was just going to be just another dumb superhero movie but it was actually really good. Of course the action scenes and special effects were good, that's a given, but this added in a really funny script, as well as some character development and a few twists and turns to boot. Definitely one I'd recommend for 90 minutes of pure escapism. I plan on seeing Indian Jones tomorrow night, If I can be brave enough to go out into the cold again. I'm not expecting anything great from Indian Jones and the blah blah whatever-it-is as most of the reviews I've read have been pretty damning. I'll try and keep an open mind.

Being holed up in the National Convention Centre each days means I haven't had chance to take in any of the sights of Canberra. All the things I'd like to see are only open during the day. I'll probably come back here sometime in the future with Rach & Lauren. In particular I'd love to take a tour of Parliament House and the National Museum of Australia.

As for the course, i've really enjoyed it. Over the past few months I've been quite dissolusioned with my career and frankly have been getting bored to death of doing security compliance work. This course has re-awakened the geek inside me and allowed me to get back to my technical roots. Learning the technicalities of how to break into systems is much more fun that just learning how to defend them!

As much as the content of the course has been really good and up-to-date, the best bit about the course so far has been having access to the knowledge and experience of our tutor - Bryce Galbraith. Bryce is very much an expert in this industry and is a contributing author to the bestselling book 'Hacking Exposed: Network Security Secrets & Solutions'. He has worked with a ton of Fortune 500 companies and has also worked on Foundstone's world renowned Attack and Penetration team.

Of course I had a decent knowledge of hacking before I came on this course (you're not much of a security consultant if you don't know how the bad guys exploit the vulnerabilities you're telling companies to fix), but this course has significantly enhanced my knowledge and brought it up to date with the latest exploits and attack vectors. I'm looking forward to Saturday when we get to put all we've learnt into practice with a live 'capture the flag' exercise - where we all compete to hack into a system.

I tell you, there's some scary stuff happening out there and there's a good reason to be paranoid about your computer security. A lot of the myths around security have been dispelled this week. Do you think I can't get around your personal firewall? Think again! Do you think I can't sniff your traffic on a switched network? Think again! You think your wireless network is secure because you've enabled WPA2 instead of WEP? Think again!

It's a shame this damn code of ethics prevents me from using my knowledge for evil. I could be rich in no time!

Thursday, May 22, 2008

AusCERT 2008

On Wednesday I attended AusCERT 2008. AusCERT is an annual conference for the IT Security industry organised by the Australian Computer Emergency Response Team. Held at the plush surroundings of the Crown Plaza Royal Pines Resort on the Gold Coast, the event is a chance for vendors such as Check Point, Microsoft, Symantec, CA, and the likes to show off their wares, and also a chance to hear presentations from industry leaders, as well as get some free training to boot (although it's not free). Representatives from such luminaries as the US Department of Homeland Security and NSA were also in attendance.

The event is similar to an annual event I used to attend in the UK - InfoSecurity Europe - which is held at the London Olympia. Although AusCERT is not nearly the size of InfoSecurity Europe.

I was pretty disappointed by AusCERT 2008. I thought I might have made a bad choice with the presentations I attended but after speaking to others the general consensus was that it was pretty crappy all round. There were a couple of gems in their but mostly it was presenters telling me stuff I already new. A lot of the presentations were too high-level to be of any value.

Every year you find that there's a new theme - a new subject which is getting the industry in a flap. This year it was web 2.0 security. This is not surprising really with the amount of stories you hear about privacy issues around Facebook, MySpace and other similar social networks that are able to harvest vast amounts of personal data. I advise everyone to be very careful about what information they put on social networks. Even if you set up your privacy settings properly it doesn't necessarily mean that your data is safe.

A combination of factors means that your data could still be at risk. The look and feel of Facebook is slick because it uses AJAX - a web scripting language for which hackers keep finding new vulnerabilities. Also, many of the applications that you may add to your Facebook, such as FunWall, aren't built by Facebook, they are built by third parties. Meaning that these third party applications, that Facebook has little control over, is also accessing your private data and could be doing anything with it, as this BBC article explains.

The one presentation that I did find interesting was presented by the Standard Chartered Bank and was an overview of their project to roll-out two-factor authentication for their customers across 15 countries. I know many banks have been trailing this for a while now but not many banks have actually implemented it due to the cost and administration issues around issuing and managing tokens. However, this is set to change as they slowly get over the issues; and as the take-up of internet banking continues to increase, so does the risk of internet fraud.

So if you use internet banking you're probably likely to find that the way you log-on is set to change in the next couple of years.

Two-factor authentication means that when you use internet banking, instead of just presenting your username and password, and maybe some secondary information like the 1st and 4th character in your PIN (this is all classed as one-factor authentication - something you know), you will also require a second factor of authentication, such as something you have, or less commonly, something you are (biometric identification such as fingerprint, face scan, retina scan, etc). The most common implementation of two-factor authentication is using a token that creates a One-Time-Password. The bank would issue you a token which displays a randomly generated number, This number is usually either generated when you press a button, or it's a number that constantly changes every 60 seconds or so. By entering the number displayed on the LED screen on your token, you're proving that the person authenticating to internet banking is the person that was issued the token, i.e. you, or so the theory goes. Obviously it's not fool-proof, but it does add another level of security to the process.

Many companies use two-factor authentication for employee remote access to their networks. One of the big issues with token-based two-factor authentication is the cost of the tokens and the management of them. This is particularly a problem when you're using it in a business to customer (B2C) environment like a bank, when you may have to issues tokens to 1 or 2 million customers.

To get around this, another option is to use the customer's mobile phone as the 'something you have' device. So for instance, when entering internet banking a text message could be sent to your mobile phone with a random number that you would enter into the internet banking login screen. Alternatively, there's a thing called IVR callback, which basically means that you would receive an automated phone call from your bank which would say something like 'Someone is attempting to log on to your internet banking account, if this is you, press 1'.

None of these methods are fool-proof - they all have an element of risk. For instance, when it comes to using mobile phones for two-factor authentication you're then relying on a third party - the telecommunications provider - as part of the process.

Anyway, the findings from their surveys were quite interesting, as was the story the presenter told about banking fraud in Malaysia.

Some of the other presentations were dire though.

One presenter, who was doing a presentation about the security risk management lifecycle, I swear must have based her presentation skills on David Brent in The Office. At one point, to the amazement of all of us, she actually picked up a bag full of some stupid plastic keys that they were handing out to everyone with their branding on it, and dramatically threw them across the stage. As they scattered everywhere across the stage she shouted 'You see people, how on earth can you get a grip of your network if you're having to manage that many applications' or something like that. I was gobsmacked and had to stop myself from laughing out loud. What did she think she was proving by that display? Didn't she feel a bit stupid that she now had to go and pick all of those keys up?

The good points about the day was 1) we got served a really nice meal at lunch time, and 2) I came home with some freebies, although one of these was a Microsoft t-shirt which has the words 'Microsoft: Our Security Rocks' printed on it, which I thought was a bit ironic given the awful reputation of Microsoft's security.

Sunday, January 20, 2008

Reported UK Data Losses - It's Worse Than You Think

It comes as no surprise to me that we're seeing a lot of news reports lately regarding lost or stolen government laptops and removable media containing personal information. In the last week alone we've seen records of 600,00 people have been lost by the Royal Navy, as well as the loss of 4000 patient records by Stockport Primary Care Trust.

The truth is, this has been happening for years and the incidents that are being reported to the press are probably only a fraction of the actual incidents. In the UK there are no legal requirements for government departments or companies to publicly disclose data losses, so you have to draw the conclusion that the only reason why the Government is being upfront about losses at the moment is because they know this is an hot issue in the press and if they didn't offer full disclose it would probably be leaked anyway.

I was watching the news yesterday when David Milliband, the Foreign Secretary, made the remark that we cannot legislate against people having their laptops stolen from cars. That's all very well but he's missing the point entirely. You can't legislate against laptop theft but you can legislate against how data is stored and protected in the first place.

Another investigation on its own isn't going to stop this from happening again. As an Information Security Consultant who has worked with both local and central government, I've seen at first hand the systems and processes that are in place governing data protection, or rather lack of them. Unless there's a fundamental change to the approach to security within the Government this type of incident will occur again and again.

Based on my own experiences, there are a number of problems with current arrangements that make these incidents likely, including a lack of clearly defined legislation governing data security, insufficient independent regulatory oversight of security in government departments, and a lack of due diligence and contracts management when it comes to outsourcing services to the private sector.

For what it's worth, here's my two pennies worth of how I believe these issues could be resolved:

1. New legislation needs to be passed mandating strict standards for government systems

The Data Protection Act is not specific enough when it comes to requirements, and can be interpreted in a number of ways. That's why the Information Commissioner has such an hard job with enforcing the requirements and issuing penalties when things go wrong. The DPA has eight principles, one of which specifically addresses data security - Principle 7:

'Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.'

The key word here is 'appropriate'. Appropriate is subjective. The interpretation of Principle 7 in the Act itself doesn't particularly help either because it uses words such as 'reasonable measures'. In guidelines produced by the Information Commissioner supporting the Data Protection Act reference is made to more specific security requirements, but it can be argued that there is nothing on the Statute book that specifies the exact minimum requirements for protecting personal data. Similarly the Act does not properly reflect new technologies and new threats.

The government could address this by first updating the Data Protection Act to strengthen requirements which I believe it is already planning, but also implement new legislation that specifically addresses security standards for Government held data. This should be something similar to the US Federal Information Security Management Act (FISMA). FISMA is a comprehensive framework that has strict requirements for all federal agencies. The UK legislation would need to make it clear that government departments are required by law to implement the requirements of the HMG Manual of Protective Security, HMG Information Security Standards, as well as the recently published Information Assurance Policy. Whilst the MPS and security standards have been around for a while now, the continuation of these types of security breaches just goes to show that they are not being properly implemented or enforced.

2. The CSIA and CESG should be given a larger budget and more powers

In 2003, the Central Sponsor for Information Assurance (CSIA) was established in the Cabinet Office with responsibilities for providing strategic direction in information assurance across all government departments, guided by a National Strategy for Information Assurance.

The Computer Electronics Support Group (CESG) is the Information Assurance arm of GCHQ (GCHQ is responsible for electronic surveillance, similar to the NSA in the US) and acts as the National Technical Authority for the UK Government, similar to the National Institute for Standards (NIST) in the US. However, if you look at the output of the CESG and need for the CESG to rely on private sector specialists to carry out work on their behalf (through the CLAS scheme), it's clear that they have a long way to go before their standards become as clear or prolific as NIST, or they have the ability address Government security in a way that NIST is doing through the FISMA Implementation Programme.

As for the CLAS programme, even though HMG Security Standards specify that that IT projects should go through formal security accreditation by a CLAS consultant, many don't.

It seems to me that both CSIA and CESG don't have the budget or resources to properly fulfil their obligations, because if they did, we wouldn't keep having to read about data losses. If the CSIA and/or CLAS had the powers and resources to carry out regular, in-depth audits of all government departments and carry out full security accreditation and certification then issues such as poor data handling procedures and lack of encryption on laptops and backup tapes would be picked up and addressed.

3. Government departments should be given a dedicate Information Security budget

This may have changed now but from what I've seen IT security expenditure is usually taken out of the general IT budget. Companies that have good security generally ring-fence approx 15-20% of their IT budget specifically for security. Government departments should do the same.

4. Government departments should be subjected to more stringent regulatory oversight

When the Nationwide Building Society was fined £1 million by the Financial Services Authority (FSA) after a laptop was stolen containing thousands of customer's banking details, this was enough of a wake-up call to other banks to finally implement the end-device security programmes that their security departments had been recommending. A good proportion of the banks are now using technology such as that provided by the likes of PointSec and Safeboot to lock down laptops and encrypt the hard drives. I personally use TrueCrypt on my home laptop which is open source (free).

Government departments should be subject to similar compliance penalties. Now I'm not one who particularly believes that financial penalties for public sector bodies is the right way to go. After all, it's tax payers money that pays the penalty and it's tax payers, not company directors or shareholders as with a PLC, who ultimately lose out because there's less money to put into government services. However, it's clear that the current situation, where the Government suffers some embarrassment and a Civil Servant is forced to hand in his resignation (sometimes, not always), is not enough of a penalty. This is a tricky one, because if the penalties are severe then the departments concerned will be less likely to publicly disclose the incident in the first place.

How about this: what if (1) a law was introduced similar to the California Security Breach Notification Law making it compulsory to publicly disclose security incidents that impact personal data, and (2) senior management and ministers are made directly accountable for any security breaches. Depending upon the severity of the incident the Civil Servant up to the Minister and finally the Secretary of State will be forced to resign (completely from Government, not just shuffled to another post) and/or personally fined. That could work?

By the way, I believe strongly that a security breach notification law should be introduced that also applies to all companies. I've seen many a security breach that has been completely covered up internally and not even reported to the authorities through fear of damage to reputation and contractual penalties.

5. Improve due diligence and contracts management for outsourced contracts

The scary thing is that large parts of government services have been outsourced to the private sector, and many of these private sector companies have not made the investment in security that you would expect when we're talking about the protection of government systems and government held data.

I've seen at first-hand how companies bid for government contracts, promise the world in the bid so that they'll win the contract, and then fail to deliver what they've promised and get away with it because the Government doesn't carry out sufficient due diligence before awarding the contract, or in-depth audits for the duration of the contracts.

The likes of EDS and Capita have large multi-million pound contracts to manage a huge proportion of government IT systems and services. Some of these contracts run for 10 years and were written at a time when security wasn't the issue it was today. Even the contracts that are written today don't go far enough to mandate security requirements. The contracts that I've seen have some reference to the Manual of Protective Security and usually state that providers should 'demonstrate compliance with' ISO 27001 - the international best practice standard for Information Security Management. However, there's a big difference between compliance and certification.

ISO 27001 certification should be a minimum requirement, at least this would demonstrate that the company has a formal security risk management and governance framework in place, and this has been independantly verified by an external auditor. However, even this does not go far enough. I help companies achieve ISO 27001 certification and I know how easy it is to get certified by simply choosing the right auditor (there's a massive difference between success criteria from one auditor to the next) and producing documentation that looks the part but does not necessarily reflect reality. Government contracts should specify in detail the exact security requirements. Instead of having security specifications which have ambiguous statements like 'Data should be protected according to risk' they should say, for example, 'data held on backup media must be encrypted, and as a minimum AES encryption with a bit-strength of 256 must be used'. This would make it clear to service providers that investment in technology such as data encryption is not optional.

As for due diligence, what tends to happen in my experience is that bidding companies are asked to provide copies of company security policies and standards. This is not good enough. Just because the security policy stipulates that a certain level of security is required that doesn't mean that it's standard practice for the company to implement it. No, there needs to be thorough due-diligence which includes in-depth investigation, inspection of systems and processes, and even visits to reference sites.

Furthermore, once the contract is awarded, it's not good enough, as is usually the case at the moment, to simply send out an annual security questionnaire to the service provider. Again, just because someone puts some good sounding words in a completed security questionnaire it doesn't mean that those answers reflect reality. There needs to be regular, full, independent audits of all aspects of the IT environment and services being provided.

Anyway, I've said my piece. How are we supposed to have trust that the UK national ID card programme will securely hold our biometric identifier, an identifier that we can't revoke or change, or that the NHS Spine, which has been contracted out to BT, will securely hold all our health records? You may think so what if someone gets hold of my personal information, they can't do anything with it. Think again. The risk of identity theft should not be underestimated. Identity theft is said to be the fasting growing crime and with a few pieces of personal information it's possible for a fraudster to take over your entire life - access your bank account, get your mail redirected, get identity documents such as passports and driving licences issued to them in your name with their photo. There's many documented incidents that prove this is happening all the time.

I worry because my details are on UK and Australia government systems!

When I read about the loss of the Royal Navy laptop it made me wonder if I could be affected. It's been over 16 years since I joined the Navy but 600,00 records were lost and there's only 36,500 personnel currently in the Navy. I know the 600,000 figure includes people who have just expressed an interest in joining the Navy but even so, it makes you wonder how many years back the records go. After all, if they're allowing full recruitment records to be copied out of a central database and onto a laptop, and they're not encrypting the laptop hard disk, they're probably not doing much to enforce the fifth principle of the Data Protection Act - ‘Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes'.

Thursday, May 03, 2007

Am I speaking a different language?

Here's an example of the kind of battle I have on a daily basis trying to get people into a security mindset:

Me to Relationship Manager (RM): Can you please ask the client to complete the attached Business Impact Analysis (BIA) template so we can understand how valuable their data is in order to assess whether nor not the existing security measures are appropriate to the value of their data. It's important that they look at this from the perspective of what it would mean
to the business if the data was lost, disclosed or changed, based on worst-case scenario and irrespective of the likelihood of it happening or the security measures currently in place to prevent an incident. At this stage we need to understand the possible impact of a security incident, not the risk of an incident occuring - the likelihood and current mitigating security controls will be taken into account in the next stage.

(I also followed this up with a telephone call to ensure the RM clearly understood what I was asking for)

RM to Me: Please see the attached completed BIA

Me to RM: Thanks for that but can you please ask the client to amend the BIA to reflect the value of their data and impact of it being lost, disclosed or changed, without considering the likelihood of an incident occuring or the existing security controls in place. They've put in the summary notes that they have based their conclusions on the fact that they haven't had an incident in the past year (to their knowledge) and they have processes in place to mitigate the risk. Again, at this stage we're not considering existing security controls because we purely want to know the possible impact to the business in terms of financial loss, reputational damage, legal/regulatory penalties, customer impact, etc (as per the template) if the data was lost, disclosed or changed - we need to know the value of the data not the risk of an incident occuring.

RM to Me: I added in the extra comments - not the business. we just tried to add some common sense to the process - i.e. how the system actually works. If they had answered everything on a 'worse case scenario' then every answer would have been red, which I don't think helps anybody.

Me to RM: But that is the point, if it's all red it needs to be all red, you can't just change the value of their data because it doesn't help us. Again, this is the Value not the Risk, whereas the value would be all red, the risk value, taking into consideration existing controls and the likelihood of an incident might bring it down to Amber or Green, but at the moment I just need to know what it would mean to the business if their data was lost, disclosed, or changed, not the likelihood of it happening.

Finally the Relationship Manager understood what I was asking (even though I talked her through the process on the phone at the beginning and she made out that she understood).

You need a lot of patience for this job!

Thursday, April 05, 2007

Update Checker

I really like the new Filehippo Update Checker. It scans your installed applications and checks to see if you have the latest versions installed.

This is important because it's not just your operating system that can contain security vulnerabilities that need patching - applications need patching too, and many of your standard installed applications such as Realplayer and Adobe Reader are regularly updated by the vendors to plug security holes.

I also love the fact that this update checker is only 100k and doesn't need installing. You can just run the exe and off it goes - no installation files that adds the app to your Startup folder or makes changes to the registry of system files.

Saturday, March 31, 2007

TK Maxx security breach comes as no suprise

The security breach at TJX, owners of TK Maxx, which has led to the disclosure of 45 million customer's credit and debit card information comes as no surprise to us in the IT Security community.

Unlike banks, insurance companies and they're like who are regulated by the Financial Services Authority (FSA) in the UK, there are very little legislative and regulatory pressures on the retail industry to operate best practice security, which given that they have infrastructure in place to take payment card details is something we should all be worried about, to say the least.

The only reason we know about this security breach is 1) because the breach is too large to hide, and 2) the parent company has obligations under certain State law in the US to divulge security breaches. There's no such obligations for UK companies. Unless of course you count the 2006 Fraud Act which gives banks (not retail companies) the obligation for reporting losses due to fraud involving payment cards (however many banks know that they can easily get around this).

There's the Data Protection Act of course, but the Information Commissioner is pretty toothless. You don't hear of companies being fined £1 million by the Information Commissioner, like Nationwide was last month by the FSA.

From my experience, companies only implement good security controls if they've either been impacted by a security incident which has cost them a lot of money, or they've been audited by a regulatory board or client and have been forced to improve security. It's shocking to see the lack of protection around customer information in retail companies. Many retail companies don't even have any standard security monitoring devices on their network or servers, so for all we know, our information could be being disclosed every day and the companies aren't even aware of it, never mind us, their customers.

Security features in the new £20

It may have the feel of monopoly money but apparently the security features built into the new £20 note are quite good. Here's a handy guide for checking for forgeries:

http://news.bbc.co.uk/1/hi/business/6444003.stm#graphic