Monday, 31 May 2010

When marketing fails to deliver

Well it has been a while since I last blogged and that is because I have just been so manic, busy beyond belief, mostly because of work. It has been eventful, firstly with new deployments eating most weekends as well as technical challenges.

Lately I have been battling with Blackberry encryption. In the past this was a straight forward setup with their old version of BES Professional so I thought I would try out the new version BES Express. According to the marketing blurb on RIM’s website it leads you to believe their new freeby product Blackberry Enterprise Server Express 5 supports PGP.
This link http://na.blackberry.com/eng/services/business/server/express/features.jsp#tab_tab_security

and has the following info:

Flexible security architecture
For implementations requiring additional security, PGP®, S/MIME and PGP/MIME are also supported. Over 35 IT policies further support the needs of your business by providing adjustable security levels and capabilities that include the following:
• Impose a device lock-down
• Wipe data from a lost or stolen device
• Wirelessly enforce security settings such as Bluetooth® lockout”


Having read the bit that says “flexible security architecture for implementations requiring additional security, PGP, S/MIME and PGP/MIME are also supported” I thought bingo! This should be quick and easy to configure however after two weeks of pulling my hair out and eventually deciding to bite the bullet, admit defeat and pay for Blackberry support, they have come back to say, “errrr actually it doesn’t support PGP”.

This has been a bit of a blow for me seeing as I had recently deployed a new BES Express server for our business based on this info, predominantly to get the new features such as HTML mail. Alas, when it came down to it I could not find the option to configure PGP in the server and so it turns out neither could their support team.

I guess the bottom line is that you can’t always believe what you read! It is a shame that this little exercise has cost me a support ticket and also two weeks of my time on and off trying to sort this out.

Wednesday, 12 May 2010

Time for change

After a week of political uncertainty we now have a new government, a historic moment of political compromise. It will be a time of change and a time of spending reviews. There will be cuts to public spending, there has to be because it is unsustainable and you definitely cannot borrow your way out of debt so something must give.

My only worry is that it will be cuts that are deemed low hanging fruit and the significance or importance is not appreciated compared to a quick budgetary win. As always it is down to perception of what is important to the individual making the cuts and there will be some difficult decisions to make however this should in no way compromise our security or information assurance. Data is precious, it is valuable, I am mindful of the average cost of a record for a data breech and also how valuable data is to the criminal world.

There were some interesting facts presented at the Ecrime Congress in London this year about how much personal data is worth, information about individuals that is being bought and sold around the globe. Credit card details, addresses, bank details, information we all hold dear is being traded.

My overarching fear is that with the exabytes of data that the last government harvested will become vulnerable unless security measures are kept and tightened. This is a difficult task in a climate of prudence and austerity where it would be easier to cancel the security project and save a bit of money now and worry about data loss later which would be a bigger crime than the wasting of billions to date has been.

So by all means cut the waste but let’s not cut back on security, especially when it comes to the data they have about you and me!

Thursday, 6 May 2010

is this the death of PGP innovation?

It has been a little while since my last post, I have been manic. The big news for me has been the recent purchase of PGP by Symantec. I make it no secret, although I try not to promote it here, that I think the PGP product set is a great platform for encryption. I love the way the product platform fits together than delivers the company slogan, defending data to the core. It is a Ronseal slogan, it does what it says.

All business, no matter how big or small, rely on data, without data you cannot function no matter what your business. Think about it, even if you don’t have computers you still keep financial records, transaction histories, customer information. All examples of data. PGP deliver a great product suit that gives end to end protection and has the widest spread of products delivering the most protection in the market.

My only worry is that with Symantec taking them over (along with several other encryption businesses) that the innovation and product diversity will start to dwindle and we will lose what has been, up until now, the market leader with regards to encryption. Their boast used to be that they were agnostic only delivering encryption products rather than a whole portfolio of products with encryption being one of them.

I am interested to see how this develops, especially now that Symantec has binned its consulting division, and I hope that Symantec value the strength of the PGP product portfolio as much as I do and keeps on funding the innovation rather than just absorbing it into their ever growing range of products.

Saturday, 17 April 2010

To patch or not to patch, that is the question...

Well patch Tuesday has been and gone and I see that Microsoft has been put in a difficult situation this month with XP security patches. The month before last they released a patch that, when installed on computers that were infected with the Alureon rootkit, caused the machines to endlessly crash. The dilemma they face is if people suffer a bad experience when applying security patches then they are less likely to apply future patches. A kind of damned if they patch and damned if they don’t.

A lot of people slate Microsoft for producing insecure operating systems but the bottom line is that the products are so huge it is almost impossible to prevent vulnerabilities. Think about the complexity of creating an OS that will run on hardware that is outside of your control. A one size fits all product, it is a tall order. Also if I had a pound for the number of times I have heard "if you buy a Mac you won't have these problems" I would be very rich and it shows how naive this viewpoint is. Macs don’t suffer as much because it doesn’t make the headlines as much due to the number of users. Microsoft has far higher market share so generates more attention when exploited and you have a much wider attack surface.

When XP was first launched it comprised of approximately 40 million lines of code, Vista was 50 million lines, which is a lot of room for unforeseen errors.

So in this round of security updates Microsoft has made smart patches. They will check the machine to determine if it has the Alureon rootkit and if it does it will not install the security update to prevent the machine from endlessly crashing. Whilst I understand this approach it defeats the object of patching in the first place.

I think the only solution to this problem is that if you want machines to be stable and to function correctly then don’t be lazy, secure it with decent products and patch it regularly. After all, a security patch is an admission by Microsoft of a problem and highlights where the problem is, if you don’t fix the problem by patching someone will invariably exploit it.

Monday, 5 April 2010

Don’t we learn from lessons? Obviously not!

I read with worry that the NHS is offshoring medical records to India. The NHS is already the leakiest organisation in the UK haemorrhaging data as though the NHS computer system has a severed artery so what are they doing? Offshoring data processing to India, following the likes of mobile phone and credit card companies will only end in disaster, after all look what has happened, data has not been lost, it has been sold!

It infuriates me, offshoring data management has been proven to be insecure, impossible to regulate and a false economy. It is not cheap, it doesn’t save money in the long run, it costs money because of compensation, the cost of changing personal records and financial details and monitoring accounts for fraudulent transactions.

So a false economy and the stupidity of not learning from others mistakes make us all potential victims of data loss. What makes me even more frustrated is that Principle 8 of the DPA states:
“Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data”.

Judging by their track record so far I would suggest that the Indian sub-continent has so far been found to be willing when providing adequate levers of protection for the rights and freedoms of data subjects, all that they have done is sell personal details to criminal gangs and now our medical details are about to go the same way.

Sunday, 28 March 2010

Unique selling point?

Wouldn’t it be refreshing if service companies started to promote a unique selling point which is to offer their clients a secure environment! I know this sounds a bit daft but let’s look at some examples. The classic case is accountants. They process their client’s financial information and exchange this with their clients. A lot of clients send their data by email or on memory sticks both of which are totally insecure, you have to ask yourself why not send your financial details to the accountant on a postcard, it has the same level of security.

So my thought is why don’t accountants and the like offer a unique selling point to their clients, a secure way of transferring data. For example a secure portal for clients to login to so they can exchange data or the business supply their clients with encrypted USB sticks with the company logo on it so it advertises the business as well as proving the client with a way of protecting themselves and their data.

The implementation of such a solution could be promoted to the clients and used to secure new business as a USP.

Simple!

Wednesday, 24 March 2010

Quis custodiet ipsos custodes?

A lot of businesses don’t appreciate where threats come from; they defend the perimeter of their network without looking too closely within. I was reminded of this the other day when the story of the Swiss HSBC employee reared its ugly head again.

For those of you who don’t know a chap called Herve Falciani stole data about some customers with the view to selling this information. He was employed in the IT department so had privileged access to data. What was his motivation? Well it is reported that he was asking £2,000,000 for the data he stole.

Whilst the theft was made over three years ago it is still coming back to haunt not only the business but also the clients. HSBC has had to revise how many records were stolen twice now. First it was a handful, then 15,000 customers and more recently 24,000 customers affected by this theft. The implications are pretty catastrophic, for some more than others, because the details of their accounts have been exposed which in turn could risk them prosecuted by tax authorities!

So is too much power being left in the hands of the IT department? Yes they need some privileges to do their work but how much? As frequently demonstrated too much.

Most organisations have a security model that can be likened to a sieve, they know there are holes so they attempt to plug them. When they discover the next leak, out come the sticking plasters and another hole is plugged. Realistically this takes a great deal of effort, there is usually something that has been overlooked and so can be exploited. The thing is how much monitoring do you put in place and who monitors those doing the monitoring? After all if you have not spotted a security hole you won't be looking for it or monitoring it. At what point do you stop this process as well, there are only finite resources and in the end who will guard the guards

A recent survey has shown that a staggering 59% of ex-employees take some of their employer's data with them when they leave. This is a pretty high figure when you think about it. Over half of all people that have ever worked for a company will have some of its data. All of that data out there, uncontrolled and the business typically blissfully unaware of how many copies are floating about. Once outside the control of the business there is no way to stop how many times said data is subsequently copied.

I was also reminded of when my own business suffered from this very problem. Several years ago an ex-employee, whom I believed I could trust, surfaced at a competitor and as soon as they joined the competitor our clients started to get phone calls and emails telling them this person now worked for them and asking would they like to transfer their business.

Fortunately no personal data was involved however it did highlight to me the weakness we had by trusting people with privileges on our network. Whilst this also doesn’t speak much of this person’s character (especially as when they left I had reassurance from them that they would never do anything to betray any trust) it also made me appreciate how valuable even the smallest amount of data can be to someone else. I don't know what his motivation was, perhaps desperation to get a job so offering a list of potential new business on the condition of a job could have been the angle, I will probably never know and to be honest don't really want to.

We also did not know this was happening but fortunately several of our clients contacted us to make us aware that this was happening and I thank them for their loyalty to us. What made it so obvious was that the competitor had foolishly used privileged information only we had and in doing so exposed it's source.

After this exercise I immediately decided to change the way we worked and how we granted privileges to staff and so rolled persistent encryption on our data so that no matter who had access to our data, if it were ever copied it would be rendered useless outside of the control of our network. Fortunately the product we implemented is very good and forces encryption whenever anything is created but denies the ability of the creator/author to decrypt it.

Whilst I appreciate that this is not a magic bullet (trust me we also have some IDS, DLP and NAC in place as well as usual server security and auditing) I am able to rest more easily at night knowing that if someone has found a new way to copy our data outside of our control, and inevitably they will, it will be in a pretty useless format once they take it away.

After all there is only so much security you can put in place before you prevent someone from being able to do their job so instead of putting in too much, put in smart solutions that give the most protection for the least overhead like we have.