Posts

Showing posts with the label cloud security

Why colocation – in Africa ?

--> All companies – large and small – have IT requirements.   Especially today in the age of big data where everything is connected and all functions are automated and digitised and need to be online.   Those enterprises that are large enough – such as banks, MNC’s, Telco’s, mining houses have been able to afford to build their own data centres to house their IT infrastructure.    Others like SME’s which could not afford to (build their own DC’s) opted for a ‘server room’ or outsourced some of their requirements to a Cloud provider. There are numerous challenges for all companies in respect of how they approach ensuring the reliable provision of IT capacity to run their businesses.    Some companies are not big enough to justify their own DC (scale) and there is a shortage of IT expertise (skill).    Often times those that have the scale to build their own DC’s   then run foul of not having the requisite skills to run the...

The upcoming African data centre boom

Why build Data Centres in Africa when the rest of the World is better geared for them with power and connectivity and they continue to be built at a rapid pace in these advanced markets?     On the face of it – it makes more sense to continue hosting data and services in North Carolina or in Finland if you are an Africa corporate with data hosting and storage requirements. However things are changing in Africa.   “ Ex Africa semper aliquid novi ”   to quote Pliny the Elder – There’s always something new coming out of Africa.    What now?    Well there have been a few drivers.   Firstly there is now connectivity between Africa and the rest of the World.     Numerous submarine cables provide an instantaneous connection between the various landing points and the World Wide Web (in other words the Internet.)   Secondly there is a large effort to install fiber optic capacity within and between numerous African countr...

Live Ensure® launches latest product features into US Market

  Live Ensure ® the SAAS  multi-factor authentication solution has spent the last year and a half field trialing the mobile version of the product with a few select customers who have collectively made millions of authentications without a single breach or failure.  Feedback provided valuable input which allowed the product to be further refined and streamlined making the user experience even better while making the solution stronger.   Live Ensure ® is easily integrated into an existing log-in form including SSO solutions like Twitter and Facebook.   This means that sites which allow users to log in e.g. with Twitter can now include a strong authentication layer thereby thwarting ID theft hacks which have become ubiquitous.   Examples are too numerous to mention but the weakness of password log-ins to emails ( Bush Hack )  and social media products (Twitter and Facebook) and their consequent failure are well documented. ...

FIDO, the password and Live Ensure®

Image
FIDO or Fast Identity Online was launched last week by a couple of Internet big hitters most notably PayPal.   They clearly have a vested interest in ensuring that their transactions are secure.     FIDO aims to provide specifications or standards to the industry that embody  an approach to authentication which starts to move away from the ‘security by obscurity ‘  or user name/password paradigm prevalent today.   The main reason why the incidence of hacking is sky-rocketing.   [ Twitter Hacked ] FIDO aims to leverage hardware devices such as phones and tablets as well as fingerprint readers, webcams, TPM ( Trusted Platform Module)  chips and tokens into an open-standard whereby there will be inter-operability between different systems but which comply to the standard.   A client/server architecture in combination with some hardware fingerprint starts to approach a much more secure approach th...

Out with the Old and in with the New

I was asked today by a board member to respond to a question from a prospective investor who wanted to know how Live Ensure (our service) differed from two other – lets call them ….the more traditional solutions.  For the sake of this blog we will call them the Old and the New solutions.   Let me describe the Old Co solutions to you briefly.  They both embody technologies which are over a decade old ( think RSA ) such as tokens and servers ( both physical and virtual).  Their solutions rely on the user entering a PIN into a browser and thereby satisfying the ‘something you know ‘ part of strong authentication.   Here it is slightly edited. The biggest weakness of both Old Co solutions are the vulnerability to MITM and MITB attacks. Both require the user to enter a PIN ( something you know ) ie a second factor over and above the user name and password ( the single factor or weak authentication ). The user enters this PIN back into the browser which is...

Why most security fails and LiveEnsure® does not ?

Image
Mary Meeker informs us that there are now 1.1bn  Smartphones  (17% of all mobile phones) and these are driving Internet growth with a total of 2.4bn people now connected to the Internet. Mary Meeker Internet trends The universe for hackers just grows and grows.    One of the most lethal of these attacks is Zeus (ZITMO) – which is aimed squarely at Smartphones. The Zeus attack is an example of several attacks now being launched that are based wholly on anticipated behavior, especially as it relates to social media, single-sign-on and BYOD. A sophisticated Zeus campaign stole an estimated €36 million, or $47 million, from over 30,000 customers across more than 30 banks in Europe this summer. The Eurograbber campaign, as it has been named, used custom versions of Zeus and Zeus in the mobile (ZITMO) Trojans to bypass the two-factor authentication measures to compromise customer bank accounts, Darrell Burkey, director of IPS products at Check Point Software Te...

NatWest mobile banking fail and why real innovation in security is needed

Not a good week for NatWest innovative banking services.  NatWest Get Cash fraud   ( Get Cash Pulled ) A combination of a simple phishing attack and a fundamentally insecure service led to many users of the Get Cash service ( a sub set of the NatWest mobile banking app – powered by Monitise) being defrauded of cash from their accounts.    The system allows users to get cash from an ATM by keying in a ‘secure cash code’ into the terminal.    The assumption is that once you have logged in to your app you are legit and so you ping the system for the code.   A user name and password level of security – that’s it!.   No better than 99% of all apps on the Net today.    Needless to say the service was shut down once the fraud started becoming rampant.    Does the drive for customer convenience completely outweigh basic security rules. ?   The problem with this kind of solution and others that rely on the presentation ...

SITES DONT GIVE A DAMN ABOUT YOUR SECURITY

The sheer volume of reportage on hacking is overwhelming.   The sites being hit are the ones that you and I use every day.   Some provide useful information, some, valuable services and others perhaps just news or trivia.   We use them multiple times a day – sometimes without even being fully aware that we are,  like DropBox.   We use these sites  to store personal and business information, to connect us with potential clients, employers and employees, to help us choose insurance providers, to send us our groceries and some, to just play on.   Dropbox allows us to seamlessly log in by re-referencing a cookie they have planted on our computer to ‘verify’ our identity.   LinkedIn also uses the same technique when we log in.    A user name and password.  How secure is that ?    Well,  not very,  given that both of these sites have been hacked and your and my perso...

DROPBOX DROP THE BALL ..

My last blog touched on the DropBox hack.   It seems that they have now decided to rectify the situation.  ( DropBox Fix security )  But many clients have been left wondering.  How at risk was I and now am I ?   I wonder how much it has impacted their reputation ?    Do you entrust your personal and/or corporate data to them or to any of the other Cloud services out there.  The better known ones are Google Drive,  Evernote, Box,  YouSendit, Sugarsync,  MS SkyDrive and Egnyte.   If so then you should be concerned.   Why?  Because all of these services rely on you proving who you are merely through the provision of a user name and password.    Why is that so bad?   Because nowadays you can get password breakers off the Internet that will crack most passwords in seconds. ( Password cracker ) .   New sites are being hacked every day with serious consequences for the them and their users (i....

DROPBOX HACK – WHY YOU SHOULD CARE ?

DropBox is flying as a company.  More and more of us are entrusting our data to their servers in the Cloud.    I am one of those.  The service is great, it works and it works from multiple devices.  However there is just one thing.  It is not secure.  Read about their latest breach here. ( http://www.zdnet.com/dropbox-gets-hacked-again-7000001928/ )  and also here ( http://gigaom.com/cloud/dropbox-yes-we-were-hacked/ ) I have been going on about passwords and their manifest weakness for months here and in other media.   DropBox have come back to their customers saying that they promise to do more – better passwords – better security …..blah blah blah. So what kind of solution should they use? Well first of all they have millions of customers.  So whatever they go for is going to have to be easy to deploy and should not require the distribution of some kind of hard token OTP generator a la all of...

TRUST

Trust /trəst/   :   Firm belief in the reliability, truth, ability, or strength of someone or something. The foundations of the working of human society are built on trust.  This has been so since the beginning of recorded history.   As our communities evolved from hunter gatherer groups into agricultural chiefdoms, and ultimately modern states their operation, increasing complexity and success relied not only upon our cultural evolution as posited by Robert Wright in Non-Zero ( Non Zero )  but also upon trust.   Trust is integral to our ‘culture.’  The birth of capitalism and the rapid economic and technological growth of the last five centuries began with the pooling of capital used by investors to underwrite a ships trading expedition called the ‘ contratto di commenda ’ .  Such ventures could not have happened without the inherent trust that the investors had - that the expedition’s captain would return the profits to the investors....

Authentication in ' context'

con·text /ˈkäntekst/ The circumstances that form the setting for an event, statement, or idea, and in terms of which it can be fully understood and assessed. authenticate [ɔːˈθɛntɪˌkeɪt] vb (tr)   to establish as genuine or valid What does context have to do with authentication? When you log on to a web site and enter your user name and password so as to ‘authenticate’ yourself all you are presenting are self reported credentials to the site.  If you present the correct credentials then the site accepts you as - who you say you are.   It takes you at face value.  It identifies you.  Liken it to a knight of old arriving at castle and announcing himself.   When you log on to a web site and it asks you to log in with a user name and password – you are in effect – announcing yourself – identifying yourself.   What happens if someone steals your password?   Then they can log on as you – the site is none the wiser – the thief has presente...