Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

DefCon 33 arrives, my talk from DefCon III survives


The T-shirt I bought at my first DefCon, which was DefCon III in 1995

DefCon, the very popular annual hacking conference held annually in Las Vegas opens today, August 7th and runs through the 10th. This is DefCon 33 and I'm a bit sad I can't be there. This would have been an anniversary event of sorts, the 30th anniversary of my first Defcon talk. And I will miss seeing all the folks I know that will be there this year.

The good news is that Jeff Moss—the founder of DefCon—had the wisdom and the foresight to insist, even back in 1995, that all talks delivered at Defcon be archived. That means anyone with an internet connection learn from past events, which is great because in my experience DefCon never fails to deliver cutting edge information about digital technologies, how they work, how they don't, and what that might mean. 

DefCon III shirt with human inside
More than a few times I have used the DeCon archives to find out when a particular vulnerability was discovered or explotied for the first time. 

As a big believer in learning from history rather than repeating it, I like to debunk statements like "we had no idea criminals would exploit our technology like that."

Really? You mean nobody from your security team went to the session at DefCon X where exact same exploit was demonstrated?

And on a personal level, those DefCon sound archives mean I can still listen to what I said, 25 years ago, preserved as an audio (.m4b) file. 

If you want to listen, just go to the DEFCON III Archive and search for Cobb. My talk was titled: The Party's Over: Why Hacking Sucks. Alternatively, you may be able to listen in your broswer (not all browsers are supported). The talk is about 49 minutes long and while the sound starts out rough, it quickly gets better.

My goal with this talk was to generate dialogue about the ethics of hacking, and I think I succeeded. In fact, the audio captures that quite well. As someone who had been working on the computer security problem since the 1980s, I have to say that I learned a lot from that 1995 session and appreciated everyone's input. The feedback from the audience must have been okay because I was invited back the next year

A Cobb in a Kilt, 2018, DefCon 26, 
My talk at DefCon 4 in 1996 was about how to go from being a hacker to being an infosec professional. The title was 101 Things to Do With an Ex-hacker. Like many early DefCon talks this one took some unexpected turns. For example, I talked for a bit about trainspotting, not so much the movie as the hobby in which you try to see as many railway locomotives as possible. 

Trainspotting was one of my hobbies when I was a boy, back when steam engines were still is service. My point was that in our enthusiasm to explore this fascinating pre-digital technology we would sometimes break the law and trespass into locomotive sheds.

The parallel with hacking was that despite this illegality, some of us matured into respected professionals with rewarding careers. Indeed, one of my fellow trainspotters has had a long and fulfilling career writing and editing books about trains. 

Anyway, the talk lasts less than 30 minutes and might be worth a listen, eve if it's just as a historical curiosity. However, before you click this link to that talk be warned that there is some swearing, albeit in a very polite voice.

Over time, the Defcon archives have evolved to become a quite amazing cornucopia of knowledge and history, a feast for eager minds, and a legacy for future generations. 

Thanks Jeff and DefCon! Thanks your foresight!

And please accept my apologies for not being their this year. I will be keeping an eye on things from 5,000 miles away in Coventry, England, where I'm looking after my mum (96) and my partner Chey, herself a Blackhat speaker (Why Government Systems Fail at Security, 2001).

P.S. For more about Chey and her current condition, you may want to read this.

The Welcome Page


This post used to be pinned to the top of the blog but I decided to let it move down the stack. It's purpose was, and still is, to explain that I am Stephen Cobb and this is my personal blog. 

The blog was set up in 2005 but I didn't start regular blogging on it until 2006. That's because I had another blog, also started in 2005, where I covered my main interest back then: information security.

Over time, this blog became a place to talk about things other than cybersecurity. Things like dealing with several medical conditions: my primary aldosteronismbasal cell carcinoma, and very low grade prostate cancer; also my partner's hemochromatosis and Giant Cell Arteritis (UK readers can just add an 'a' after the 'e' in the hemo words).

Brief notes on 70+ years of life

I was born in a house in the medieval city of Coventry, in the middle of England, in the middle of the last century, to parents who survived heavy aerial bombardment in the global conflict known as World War Two, which ended seven years before my life began. 

After going to university—first in Leeds and then in Canada — I travelled the world for several decades before moving back to the city of my birth with my partner and our adopted cat, Lola (seen above).

My partner of 39 years, the phenomenal Chey Cobb, is a US citizen, legally resident in the UK. I am a citizen of both the UK and the US. We have both spent, and continue to spend, a lot of time researching how humans create and confront technology risks and health challenges. I write about my research for a variety of websites and publications, like:
This blog is where I write about more personal stuff such as: the fact that I'm retired, although I'm still open to interesting projects; my plans to publish another book, but I'm not sure when; my attempts to raise awareness of the medical problems which disabled my partner; the role of registered carers and how it can be supported; my hopes for radical reform of the patriarchal medical establishment that continues to fail women so badly. 
Photo of a Minolta lens on my Olympus camera

On a lighter note, Chey thinks I should have a hobby to take my mind off things, so I'm been trying "classic glass" photography: using lenses from old 35mm film cameras to take pictures with modern digital cameras (for example, the Minolta lens on my Olympus camera shown here).

On a more serious note, I feel the need to use some of my "free" time to contribute to society. So in addition to sharing my knowledge about thwarting digital criminals, I serve on the board of a charity, Carers Trust Heart of England

I also do driving jobs for our local hospital as one of the hundreds of UHCW Volunteers. As I travel around Warwickshire collecting and delivering patients I engage in another hobby: sampling independent coffee shops and their menus.

Fortunately, I still find some time to continue my research at the nexus of ethics and technology. I am currently exploring the harm caused by abuse of technology, which I have written about here. and talked about here, on YouTube.

If you want to contact me, you can use the form on this page or find me on Facebook or LinkedIn

Note: I am aware of some formatting issues and missing images in the older articles on this site—a side-effect of moving this blog from WordPress to Blogger—I'm fixing them as and when I can.

Fighting malware, cybercrime, and hemochromatosis = I've been busy


I enjoy reading a wide range of blogs. Recently, I was shocked to visit one of my own blogs -- this one -- and see that I had not posted anything since February. Surely I had written more than that? In fact, I have been doing a lot of writing, but on other blogs. So I decided to post a roundup of recent writings and presentations, for my own edification, and to show that I have not been slacking. Enjoy!

Living Security


A lot of my writing these days appears on We Live Security, the website that grew out of the Threat Blog at blog.eset.com. Here are some highlights:

Being Security


I have also been writing some posts about security and privacy on my first blog, Scobbs Blogspot. The idea is to put security pieces there when they are not a good fit for We Live Security, for example, a strong personal opinion, or a speculative piece. (In general, I want to keep this blog here, Cobbsblog, for non-security stuff.) Recent posts on Scobbs Blogspot include:

Security Slides and Webinars and Podcasts


You can find some of the slides from my security presentations at SlideShare under the zcobb account. These include slides that ESET graciously makes available for anyone who is working to increase security awareness in their organization. Here is a recent example from a webinar on cybercrime:



Some of my security education presentations are done as webinars and you can find these in the ESET channel on a service called BrightTalk. The channel requires a one-time registration process but is free and there are dozens of recorded webinars available from myself and my colleagues.

I have also recorded a lot of podcasts on security and privacy. These are available on this page but they are not marked as to author. All of the podcasts are worth a listen and feature my fellow researchers at ESET.

Earlier this year I answered several questions for a reporter while visiting the Latin America headquarters of ESET. Topics covered in the resulting video include the effects of Snowden's revelations about the NSA, the relationship between privacy and security, and social media issues for young people. Spanish subtitles are provided.



Fighting Hemochromatosis


My writings on hemochromatosis started here on this blog in 2008, with "dsgds". Then, in 2010, I created CelticCurse.org and post there when I have something substantial. Here are some recent posts.

In addition to Celtic Curse, I created another channel of communication about hemochromatosis, the Hemochromatosis page on Facebook. This has reached over 100,000 people so far this year and led to the publication of the first ever "Hemo Doc Stars" list of recommended hemochromatosis doctors from around the world.

So, the next time I am wondering to myself "what have I accomplished this year?" I can look at this page and refresh my memory. And the above is not everything. I also got accepted into a postgraduate degree program in security and risk management in the Criminology Department of the University of Leicester, in England. I hope to have time to share some instructive tales of distance learning here as the program progresses.

Happy Blogging New Year 2014!


Happy New Year! While it took me a few days to get around to this, I did want to mark the beginning of the new year with at least one blog post here on Cobbsblog. In fact, I have been doing quite a bit of blogging around the turn of the year.

Over on WeLiveSecurity.com I was privielged to present some of the 2014 security predictions from my fellow researchers at ESET. My colleagues in Latin America shone again this year, producing a 30+ page review of malware trends and predictions.

That report very rightly fingered privacy as a hot topic for 2014 and I am heading for Washington, D.C. in a few weeks to be on a panel about data privacy at a Data Privacy Day event at the Pew Charitable Trusts (January 28 is Data Privacy Day).

Predictions are one thing, but what practical good are they? What advice can they generate for IT security managers? I will try to answer that question in a free webinar happening January 15 on ESET's Brighttalk channel.

I made some information security predictions of my own, over on my security blog: scobb's information security blog. That blog was in fact my first, and lately I have been reviving it. My idea for 2014 is to use Cobbsblog for more personal posts, and put my security related posts on scobb's. Of course, in 2014 I will be writing about security on WeLiveSecurity.com as well, but sometimes I have things to say on the topic that don't quite fit there.

And sometimes my thoughts will migrate to other blogs. For example, Graham Cluley liked my prediction about the persistent misrepresentation of antivirus software, and reprinted it (with my permission) on his very information blog.

I wish you a safe and happy 2014 and pledge to do my best to provide you with informative and thought-provoking content all year long.

Free professional security advice for Palestinian hackers


First of all, welcome. I am glad you found this page. Please don't hack it.

Who am I? I am one of many people in the computer security world who have great sympathy for the Palestinian people. We agree with you that the Palestinian people deserve to live in peace. We let our politicians know what we think. We use social media to spread news and awareness of the injustices suffered by the Palestinian people at the hands of Western governments and their allies in the region.

As computer security professionals, we also work hard to protect the privacy and cybersecurity of hundreds millions of individuals around the world. Some of those people are Palestinians. For example, I work at ESET, a company which protects the computers and smartphones of many millions of people in more than 180 different countries. I'm guessing some of them are Palestinian sympathizers.

Recently, some of you have been busy redirecting website traffic AWAY from sites that many people, including some Palestinian sympathizers, rely on for help in protecting their privacy and their data, and TO a page that calls for Palestinian rights. I have to say, I don't think this strategy is helping you, or the Palestinian cause; it hurts law-abiding human beings who use computers and smartphones to make an honest living, to connect with their families, and in some cases, to campaign for peace and justice.

[Note: When I say sympathy with the plight of the Palestinian people, or sympathy with the Palestinian cause, I mean that I think the people of Palestine have been, and are being, treated inhumanely, and that they deserve a secure homeland in which they are free to enjoy the rights and liberties that Americans take for granted. I do not mean that violence against civilians in pursuit of political aspirations is justified: it is not, ever, no matter what side you are on. Yet complacency and apathy in the face of inhumanity and injustice are equally objectionable.]

So, what is my professional advice? Use your computer skills to advance the cause in ways that don't impact innocent digital bystanders. Let me give you an example. This website you are reading right now is hosted on a web server that was hacked a few months ago in the name of freedom for Palestinians. The same web server hosts information about a potentially fatal genetic condition that doctors often fail to diagnose. That website helps a lot of people but it went down because someone thought hacking it would help the Palestinian cause. Did it help? I don't see any evidence that it did. Several kind and generous people had to give up their time to fix the website. Some innocent people in need of helpful information could not get to that information for days.

kdms-palestineDid the hack provide any benefit to anyone? Not really. Security experts already know that websites can be hacked, and it is well known that the DNS servers which direct traffic to websites can be messed with. But the more protection that is applied to protect sites and infrastructure, the more expensive and cumbersome the Internet becomes. And I'm guessing you use the Internet for more things than hacking. How about use of the Internet to organize humanitarian aid for Palestine? How about use of the Internet to raise awareness of, and sympathy for, the Palestinian cause? Why not apply your skills and energy to those efforts? Help the people who are trying, or may be persuaded to try, to help you.

No quest for peace and freedom can prosper without a critical mass of support that comes from many quarters. Annoying people who might otherwise be persuaded to support you just seems counter-productive.

Respectfully...Stephen Cobb, CISSP

Robot or not? Robotic surgery and risk, part one


A security geek goes to see a surgeon about having an operation. The surgeon says, "We may use the robot."

The geek thinks: "Robot! Cool. What OS does it use? Is it on the network? Has anyone hacked this type of robot yet?"

I am that geek and I will get to those questions in a moment, but here's a question you need to be thinking about: Is it okay for a machine to slice into people and perform surgery, such as removing organs they no longer need? I'm thinking about this for several reasons, including my upcoming adrenalectomy and my job as a security researcher at ESET. But why do you need to think about this? Because robotic surgery is no longer science fiction: nearly half a million surgical procedures were performed robotically in North America in 2012.

So, there's a good chance that, if you need any one of a number of types of surgery in America today, your healthcare provider will want to use a robot. Are you okay with that? Clearly, most people will want to ask themselves:  Does the surgeon's use of a robot increase or decrease the risks to me, the patient? In this post and others that I am planning to write, I hope to shed light on this question.

Note that I am not a doctor, nor am I a medical researcher, but I have some experience with risks related to digital technology. I work for a company that works to improve the safety of digital technology. A surgical robot is digital technology. Here's a simplified diagram of a robotic surgery setup:

Sketch of 3D robotic surgery step

The surgeon guides the robot tools from a 3D imaging console using hand and foot controls communicating over wires to the device. Note that the surgeon's console can be some distance from the patient (in telesurgery it could be miles away).

Slicing and dicing with da Vinci

If your healthcare provider does want to deploy a robot as part of your surgery there are a couple of data points we know already. First, the procedure is likely to take a bit longer. Second, the procedure will cost more. Third, the robot they will use is most likely to be the da Vinci Robotic Surgical System. The da Vinci is made by Intuitive Surgical, a company that went public 13 years ago at $9 a share [ISRG]. This was the same year the FDA approved the system for general laparoscopic surgery. Intuitive has since traded as high as $585.67, which might lead you to think that things are going well in robo-surgery land.

Unfortunately, and I mean this sincerely as a fan of technology and a believer in the potential of robotics to improve our world, some things have not gone well. For example, according to one law firm:
there are now more than 4,500 complaints about the da Vinci surgical robot in the FDA’s MAUDE (“Manufacturer and User Facility Device Experience”) Database—50 or so of them involving the death of the patient—and 30 lawsuits against the manufacturer, Intuitive Surgical, Inc.
You don't have to take a lawyer's word for this because MAUDE is on the Internet. and you can look up reports yourself (I count 500 reports involving Intuitive surgical so far this year). Bear in mind that reporting medical device problems to MAUDE is not mandatory, so there is no way to tell the actual number of problems with the da Vinci system.

Then came a bunch of studies examining the cost and efficacy of these million dollar marvels (yes, a da Vinci robot can cost over $1.5 million). Together with the lawsuits and media scrutiny, these have depressed share prices for ISRG, which is now trading around $430 with some analysts predicting values of $300 within the year.

Somewhat ironically, given my initial security geek reaction to the idea of a robot slicing into my flesh--fear of hacking--none of the problems with this particular technology cited so far have anything to do with malware, coding errors, comms failures, or hacking. The greatest risk factor right now, in my opinion? The impact of market forces on safety.

Sales pressure and medical devices

Intuitive is under tremendous pressure from shareholders to sell more robots and get more robotic surgeries performed. This leads to marketing tactics that oversell benefits and downplay risks. For example, Johns Hopkins research shows hospital websites making excessive use of industry-provided content to sell robotic surgery and overstate claims of robotic success. A CNBC investigation quoted Suraj Kalia, a Northland Capital analyst, in a recent report on the company:
Our extensive field checks highlighted a story where aggressive marketing drives the message and true clinical utility seems secondary in nature.
There is a lot of pressure on Intuitive to market the heck out of their product because a lot of doctors are now expressing doubts about the value of robotic surgery. Consider the blistering Statement on Robotic Surgery by James T. Breeden, MD, president of ACOG, the American College of Obstetricians and Gynecologists (with 56,000 members, ACOG is the nation’s leading group of physicians providing health care for women). Here's the short version: "there is no good data proving that robotic hysterectomy is even as good as—let alone better—than existing, and far less costly, minimally invasive alternatives."

Here are some of the figures that ACOG quotes:
At a price of more than $1.7 million per robot, $125,000 in annual maintenance costs, and up to $2,000 per surgery for the cost of single-use instruments, robotic surgery is the most expensive approach. A recent Journal of the American Medical Association study found that the percentage of hysterectomies performed robotically has jumped from less than 0.5% to nearly 10% over the past three years. A study of over 264,000 hysterectomy patients in 441 hospitals also found that robotics added an average of $2,000 per procedure without any demonstrable benefit...an estimated $960 million to $1.9 billion will be added to the health care system if robotic surgery is used for all hysterectomies each year.
Between the medical questions and the growing number of lawsuits, Intuitive is under pressure, the kind of pressure that should, I believe, influence the way you interpret what people say about robotic surgery. Is the hospital pushing it on you? Is the hospital pushing it on the surgeon? Is the hospital skimping on robotic training, given the manufacturer's claim that surgeons are ready after two or three operations? Is the motive to achieve the best healthcare for you or is the motive a need to pay back the huge investment in hardware and supplies and maintenance contracts? Are doctors and hospital administrators being plied with luxury vacations and other perks to encourage them to use the robot more often in a wider range of procedures, including yours?

Those questions are currently more pressing than the need to analyze the da Vinci system's coding and connectivity. So far, I have found no indications that the system has been hacked and it does not appear to be connected to any networks. But that may change as the pressure to perform remote robotic surgery grows, powered by the perception that this can expand healthcare delivery at lower costs than training more surgeons. Already we see FDA approval for passive telemedicine robots. The term telesurgery has been coined and tests of procedures performed over the Internet are under way.

What's next for robotic risks?

In my next post I will break down the technical risk factors in more detail. These include analog issues, like build quality (here is a self-reported problem with da Vinci hardware that can cause burns), and also logical issues, like the security of device programming.

I leave you now with a link to the AJOG report "The commercialization of robotic surgery: unsubstantiated marketing of gynecologic surgery by hospitals," and a link to a report that really rips into Intuitive. The author quotes a lot of sources that appear to check out. After reading it you are likely to question whether or not robotic surgery is right for you. As of now, I am going to ask my surgeon to take a more hands on approach.

2,500 Blog Posts and Counting


Stephen CobbThat's 2,500+ blog posts if you count all my posts across all my blogs and those of my employer (ESET). My blogging is now very infosec-oriented, but I'm still spreading the word about the silent genetic killer, hereditary hemochromatosis, on the Celtic Curse blog and the largely-self-sustaining Facebook hemochromatosis page, which now has over 1,750 followers. Of course, all views expressed on cobbsblog.com are mine and not those of my employer.

Security and Privacy Links: Marketing cybersecurity


As some of you know, I hit the ground running when I landed in San Diego at the beginning of September, happy to be back in California, wrestling with my first love, information security.

Okay, so that prose was a trifle purple--not to be confused with a delicious purple trifle--and information security is not, strictly speaking, my first love.

But hopefully you get the point: I was ready to up my game in the fight against digital malfeasance after three fun years focused on the marketing of marketing software to marketers (three highly successful years, I might add, because the marketing software, Monetate, was clearly headed for best of breed from day one and can now be found on major websites from PETCO to QVC).

There were a number of happy congruencies in this latest development. My marketing skills had been honed, my marketing experience broadened, just in time to sell a fresh message of cybersecurity awareness to a deeply digital world. That message goes like this: "The bad guys are badder than ever, better funded, more organized, but there are simple steps we can all take to make cyberspace a lot safer tomorrow than it is today."

For me, this was just the right time to run into ESET, a Slovakian company with a growing presence in North America and a strong commitment to the public good, as evidenced by a pioneering community initiative called Securing Our eCity. I spend part of my time working on this initiative and the rest on research and publication, in all its forms, including blogging, tweeting, and speaking. Here are just a few of my efforts so far:

On TV:



Speaking:



Quoted:



Published:



Bonus Security Video: Malware Delivery Scam:


The Apartment With Everything, Now Available Everywhere (Irony Included)


So here's something way more ironic than anything in the Alanis Morissette song of the same name. My wife found a gorgeous apartment to rent in San Diego, for only $1,000 a month (I will explain why she was looking in a moment). The place looked great in the photos and it sounded great in the description on Craigslist:
"2 Bedroom, 2 Bath, fully furnished, modern kitchen and bath, cable TV, Internet wi-fi, electricity, water, local phone included. Nestled in a quiet, almost suburban-like setting, you're just a few minutes away from world-class dining, shopping and the verve of theaters, clubs and nightlife. Great location, great features. All at a location that's exactly right, exactly where you want to be."

All that for $1,000 in San Diego, California? Sounds fantastic, but hardly ironic. So let me add the most interesting thing about this place, something not immediately apparent: it is also for rent in Boston, San Francisco, Seattle, Washington, and many other cities in America. But even that's not ironic, that's just another sick cyber-scam.

Apartment ScamLet me add some more data points. My wife and I have spent many years working in the field of information security--where uncovering online scams and other cyber-crime was part of the job--and we are planning to move to San Diego next month, for my new job as Security Evangelist for ESET, a software company dedicated to fighting cyber-crime. We don't need a furnished apartment, but this place looked inviting (and it could lead one to think rent in downtown San Diego is very affordable).

So here's the irony: The apartment that I wanted to rent in order to facilitate my move to a new job fighting cyber-crime turned out to be a cyber-scam!

I was going to provide links to the scam pages (they were mainly on Craigslist) so you could check them out--they were quite professional with fewer typos than your average scam --but after my wife sent Craigslist a description of the scam they pulled it from all the cities mentioned above.

Of course, there may have been other complaints but my wife actually got the scammer to send her an email, which provided further details of the scam that she passed along to Craigslist. Apparently the scammer claims to be out of the country and seeks to get the prospective renter to send her a deposit, presumably before they find out that the whole thing is a fraud.

Notes: I say "her" only because the name most often associated with these fake apartment listings is Amanda Dawson (although I'm pretty sure that is not the scammer's real name). Also note that I think Alanis Morissette is a very good actor and singer, I just don't like the song  "Ironic" because most of it isn't. I don't know why I have a problem with errors in works of art, but I do. For example, the great big hole in Lord of the Flies--you can't use a short-sighted person's glasses to make fire--spoils that book for me (maybe it's because I've been myopic since I was 11 and tried using my glasses to burn paper on several occasions until my father sat me down and told me the facts of light).

More for Virgins, Less for Screw-ups: The surprising cost of data breaches


In its fourth annual study on data breaches, the Ponemon Institute examined the costs of 43 companies that had been hit by a data breach. The study found, not surprisingly, that the cost per record breached had risen (actual numbers coming up).

I have always thought it ironic that one of the biggest obstacles to getting organizations to take action on issues of data privacy and security is a lack of data, namely data about what a security failure might cost. If known, that cost can then be weighed against the cost of putting security measures in place.

After all, Adam and Eve did not cover their bodies in the garden of Eden,  likewise organizations operating in crime-free utopias have no need to spend money to protect against data exposures. In the real world, however it is sad but true that a certain percentage of people are not sufficiently constrained by either personal ethics or a fear of consequences and go about steal data for personal gain.

Thus the need for security spending to avoid the costs, which are now averaging over $200 per record. So, next time you read a story about some bank or retailer exposing thousands of records, you can just multiply by $200 to figure the hit they have just taken).

This study is more good work by Larry Ponemon and the Ponemon Institute. Consistently reliable data over time is particularly useful. For example, if you read up on all the data breaches that have been happening you might have formed the impression that more of them are now coming from third parties, i.e. people who process customer data for retailers, banks, etc. And the survey shows that yes, third party data breaches were reported by more organizations in 2008 than in 2005 (21% then, 44% now). Less predictable perhaps is the finding that third party data breaches are more expensive, $231 per compromised record versus an overall average of $202.

As you might expect, breaches experienced by data loss "virgins" are more costly, $243 versus $192 for "experienced" companies, sardonically referred to as "repeat data screw-ups" by Larry Dignan in the TechRepublic blog post referenced at the beginning of this post. What surprised and saddened me is that more than 84% of all cases examined by Larry Ponemon's team were repeat data breach offenders.

Sadly, until there is an uptick in the general standards of human behavior, things are likely to carry on like this. Data entrusted to the feckless will be exposed by the lawless, innocent lives will be disrupted, money will be lost, and the cost to defend against miscreants will mount.

Blog Backlog: Computer Security Handbook 5th Edition Launches


csh5I got a nice nod last week from Norwich University in an article about Wiley's soon to be launched 2,000 page behemoth: "Computer Security Handbook, 5th Edition."

It turns out that 37 of the 80 chapters are by people with Norwich connections. That includes me (Chapters 4, 7, 15, 20) and Chey (Chapters 15, 41, 73).

Although I got interviewed for the article, to highlight cooperation between Norwich professors and students, I kind of wish they had also mentioned Chey. She wrote a lot of the curriculum material for the original Master of Science in Information Assurance at Norwich. And I think she and I are the only couple to work together on a chapter in the new opus (Chapter 15: Penetrating Computer Systems and Networks, also with Mich Kabay).

On the whole, David Corriveau did a good job with the article. Hopefully, my comments conveyed the fact that Mich Kabay should get the credit my collaboration with Corinne LeFrançois at the NSA. It was a classic electronic encounter. Pure email, we never met in person. (It is worth noting that I also met Mich online, about twenty years ago, while I was living in Scotland and he was living in Montreal. That was back in the days of CompuServe.)

Mich is the one is the thread that runs through all of this, the MSIA program and the Computer Security Handbook, both CSH4 and CSH5. And with that, we wish the best of luck to "Computer Security Handbook 5th Edition" and all who sail in her!

Bamford Breaks Out: Shadow Factory exposes NSA, CIA, Hayden, Bush, 9/11


When it comes to books about the US intelligence agencies there's a lot of mumbo-jumbo and plain old BS out there. The shining exception has been the work that James Bamford has published about the National Security Agency [NSA]. And Bamford's latest book, the just released Shadow Factory, is really going to shake things up in the IC (spook-speak for Intelligence Community).

I ordered my copy from Amazon today and I urge you to do the same. But before your copy arrives you can get an idea of some of the shocking information it contains by checking out this explosive interview available in mp3 and Real Video. If the world was not in the middle of an economic meltdown right now, revelations like this would be headline news. Spoiler Alert: This interview includes explanations of how:

  • the NSA pays foreign companies and private contractors to create copies of all your Internet traffic;

  • the CIA prevented the FBI from tracking the 9/11 terrorists in America;

  • contractors in America swap tapes of our soldiers in Iraq calling home to their wives and girlfriends;

  • the head of the NSA, now the head of the CIA, General Hayden, agreed to Cheney's demands for an illegal domestic surveillance program to avoid personal embarrassment.


Bamford first brought the National Security Agency to the world's attention in 1982 with The Puzzle Palace. Back then the very existence of the NSA was classified, the book was essentially banned in the US, and Bamford was...

What Fighting Spam Taught Me About Marketing (and Market Forces)


Yesterday I reflected on the emergence of the spam problem and some early work on anti-spam strategies. I'd like to continue the topic today with a second observation from early in 2001:

2. A lot of people want to receive relevant offers.

This is not the same as observation #1 in my previous post: Some people like unsolicited email. Back in 2001, point #1 was true: a not insignificant percentage of email users were open to getting email they didn't ask for. This percentage dropped rapidly over the next few years as the quantity of unsolicited email that these people received increased, together with the proportion of that email which was deceptive and distasteful.

What did not change is point #2; it is human nature to be receptive to a good deal IF it is relevant. We realized this...

Child Porn: Why One Man's Innocence May Worry IT Managers


Computer security news out of Massachusetts this week could be a sign of big troubles to come for IT managers in enterprises, government agencies, and SMEs, in the U.S. and around the world. It's not a virus or worm or Trojan as such, although they may be involved. No, it's a case in which an innocent man lost his job and his reputation, and may now win a landmark suit against his former employer. Why? Because he was fired for having child pornography on his company laptop without adequate forensic evidence that he put it there.

The case of Michael Fiola could become a landmark of sorts, although some observers seem to have missed the point I'm going to make: Any employer considering taking action against an employee, based solely on what is 'found' on an employer-issued computer, must have solid forensic evidence to justify that action, and preferably be in a position to justify the action on additional, non-forensic grounds. Why? Because failure to do so could have serious consequences.

Legal Precedent, the CIO/CISO Remit, and Indian Affairs


Q. Have you spent much time at the U.S. government's Bureau of Indian Affairs web site lately?

A. No.

I didn't think so. Because, when you go to www.bia.gov it's not there. According to a recent news story that may be about to change, but don't hold your breathe. There hasn't been a web server at bia.gov for most of the past 7 years. Why? The short answer, which I consider to be highly instructive to Chief Information Officers and Chief Information Security Officers everywhere--inside the government and out--is this: "Because the judge just said No."

Allow me to elaborate. Back in 2001 a judge told the BIA to take its site off the Internet because it was not secure. And, in a judgment that strikes me as a brilliant application of commonsense, he added: "Don't put it back until it's secure."

How does a judge determine if a web site is secure? The same way that the Federal Trade Commission does: submit it to examination by an objective, independent third-party who is suitably qualified, such as a CISSP (Certified Information System Security Professional). And that's what the BIA did, in 2003, and again in 2004. Basically, the BIA kept reworking its systems to try and achieve a standard that I like to call "secure enough." That means the site can withstand all of the obvious, predictable and realistically feasible attacks.

And that pretty much sums up the real world standard used by site like Amazon.com and BankOfAmerica.com. For example, a site won't fail the "secure enough" standard just because it's encryption could be defeated by a brute force attack that would take $50 million super-computer to execute. A site will fail if it is found to be vulnerable to a known cross-site scripting attack or a SQL-injection hole that was patched six months ago.

Well now there is a Court Order permitting Internet reconnection for Indian Affairs and the agency is "on the path to full reconnection to the Internet." Note that this is not happening because the judge's security experts gave the site a clean bill of health. On the contrary, the United States District Court for the District of Columbia Circuit and agreed with the agency that the judge was out of line when he issued the Consent Order Regarding Information Technology Security that suspended the site back in December, 2001. So, the court gave permission for the "information technology systems of the Bureau of Indian Affairs (BIA), the Office of Hearing and Appeals (OHA), the Office of the Special Trustee for American Indians (OST), and the Office of Historical Trust Accounting (OHTA) to be reconnected to the Internet." It will be interesting to see how long that takes, and how secure the site proves to be, in a real 'real world' test.

In the meantime, companies might ponder how they would fare if all Web sites had to pass a security review before they were allowed to go live.

Anti-spam: A Stephen Cobb Podcast


A couple of months ago I recorded a 15 minute, interview-style podcast with Brian Kraemer of TechTarget on the subject of spam, then I promptly forgot about it. Well, today I remembered and figured I would embed it in a blog post.



For those who prefer a direct link to the original MP3 podcast file, all 14 megabytes of it, here it is: Cobb on Anti-spam.

I hope you find it useful listening. The target audience was mid-market CIOs (that is, Chief Information Officers at companies with 100-5000 employees or revenue up to $1 Billion). But I think it would be of interest to most SMEs (that is, small-to-medium sized enterprises). Finally, here's a link to the podcast on the TechTarget site.

Amazing Coincidence


In yesterday's post I remarked on the need for CIOs and CSOs to raise the INFOrmation SECurity threat level. (Okay, I didn't actually say that, but that was the implication of what I did say.) Why? Because times are tight and that puts a fresh edge on computer crime, data leakage, and plain old data theft.

I also made the point that data theft was nothing new, something you can see for yourself if you Google the words data and theft and a year of your choosing. Serendipitously I chose 1985, and one of the results was this headline: "F-4 Design Data Taken in Theft at Parts Firm" from the Los Angeles Times, January 6, 1985:
"Computer cards containing sketches and design specifications for the F-4 Phantom jet fighter have been stolen from the Camarillo offices of a firm under investigation for alleged illegal shipment of F-4 parts to Iran, authorities said."

And wouldn't you know it, about an hour after yesterday's post I saw this story: Joint Strike Fighter secrets possibly compromised. Now, I should point out that this story does not say secrets were compromised, but it describes some less that stellar goings on at the Pentagon's Defense Security Service, which is apparently underfunded (like our soldiers in Iraq and Afghanistan and Walter Reed and Fort Bragg). There are three main points to note here...

Tough Times and Threat Levels: New wave of infosec issues:


Protecting information, and the systems that process it, is part science, part art. There is no scientifically established correlation [that I know of] between economic conditions and security breaches, but commonsense tells us that the temptation to steal, cheat, defraud, or simply fudge a little, can be greater when times are tough. Witness the Lending Tree case. "Several former employees of LendingTree are believed to have taken company passwords and given them to a handful of lenders who then accessed LendingTree customer data files."

Do such things happen in good times as well as bad? Sure, but I think the human mind is better able to justify certain acts, like data theft, when people are haunted by fears of foreclosure, bankruptcy, gas lines and food lines. And make no mistake, while stealing a loaf of bread might seem the most direct answer to the threat of hunger, data theft is an increasingly viable alternative when a desperate person needs money. Indeed, from an INFOrmation SECurity perspective, one things that makes the current economic downturn different from previous cycles is the existence of a thriving underground market for purloined data, on top of the ever-present market of unethical employees and employers.

When I was researching my first computer security book in the 1980s there was no shortage of examples of bad behavior involving data (e.g. "2 Arrested in Theft of DMV, Credit Data by Alleged Ring" LA Times, December 11, 1985; "Alleged Data Theft by AT&T Probed" Dallas Morning News, November 19, 1985; "Two Arrested in Theft of Customs Computer Data" Miami Herald, July 20, 1986, etc.). Two decades later there is a lot more data stored on computers, a lot more ways of stealing it, and a lot more ways of selling it. Consider:

New SQL attack methods are discovered.
New SQL attacks launched.
New methods of defeating disk encryption publicized.

These threats are real. These are not security experts crying wolf to drum up business. The need to batten down the hatches is greater than ever.

Navy Needs Information Security Staff: But HR web site is down


If the world economy is headed downhill as fast as some pundits claim, a job with the US federal government might be a safer option than trusting one's future to free enterprise. Or so I was musing this morning when I decided to peruse usajobs.gov.

I found numerous Department of the Navy openings for something labeled "Information Technology Specialist (Security)." These openings were spread across the country so there was bound to be one nearby. And the listing suggest some urgency: "This notice is issued under the direct-hire authority to recruit new talent to occupations for which Department of the Navy has a severe shortage of candidates or a critical hiring need. As such, this notice is targeted to qualified United States citizens who are not current permanent Federal employees."

Bingo! I'm a citizen. There's a critical hiring need OR severe shortage of candidates, let's check it out. I was told to visit https://chart.donhr.navy.mil/. I boldly clicked and, well, nothing. Turns out that server has been off the grid for the past three hours and counting.

Okay, it's a Saturday and these are government jobs. Maybe Information Technology Specialists don't work weekends. I can dig that. So I decided to do a little more digging. What could I expect to earn in one of these jobs? Oh let's say, roughly, something between about $28,862 and oh, how about in the region of around $152,670 per year. That's about as useful as a prospective employer answering "Money" when a job applicant asks "What does the job pay?"

In the private sector a good IT security specialist can earn $150K. But it is hard to imagine a n IT security job starting at $29K (that's less than $14 an hour). So the government has an employment web site that urgently seeks information security specialists who could start at a pay level most people with the necessary skills would rate as "not worth it," rising to an upper pay level that is a whopping 5X the low end, applications for which cannot be accepted right now because the server is down.

People used to ask themselves "Who's running this country?" The question now seems to be "Is anyone running this country?"

Hannaford Breach: A chance to learn


There is actually some upside to the recently announced multi-million record data beach at grocery chain Hannaford, including the possibility that it was detected a lot quicker than the retail mega-breach at TJ Max (although that assessment may change as more facts come out).

I liked the coverage here at SearchSecurity which addresses the event relative to both the PCI DSS, something my brother and I have been writing about for SearchSecurity, and business continuity, something I am working on at the moment with my good buddy Michael Miora, one of the best guys in the BC business.

There's bound to be be "more later" but in the meantime, feel free to check out Da Cobbs on SearchSecurity (that's Chey, Stephen, and Mike).