Posts

Showing posts with the label online security

Why most security fails and LiveEnsure® does not ?

Image
Mary Meeker informs us that there are now 1.1bn  Smartphones  (17% of all mobile phones) and these are driving Internet growth with a total of 2.4bn people now connected to the Internet. Mary Meeker Internet trends The universe for hackers just grows and grows.    One of the most lethal of these attacks is Zeus (ZITMO) – which is aimed squarely at Smartphones. The Zeus attack is an example of several attacks now being launched that are based wholly on anticipated behavior, especially as it relates to social media, single-sign-on and BYOD. A sophisticated Zeus campaign stole an estimated €36 million, or $47 million, from over 30,000 customers across more than 30 banks in Europe this summer. The Eurograbber campaign, as it has been named, used custom versions of Zeus and Zeus in the mobile (ZITMO) Trojans to bypass the two-factor authentication measures to compromise customer bank accounts, Darrell Burkey, director of IPS products at Check Point Software Te...

SITES DONT GIVE A DAMN ABOUT YOUR SECURITY

The sheer volume of reportage on hacking is overwhelming.   The sites being hit are the ones that you and I use every day.   Some provide useful information, some, valuable services and others perhaps just news or trivia.   We use them multiple times a day – sometimes without even being fully aware that we are,  like DropBox.   We use these sites  to store personal and business information, to connect us with potential clients, employers and employees, to help us choose insurance providers, to send us our groceries and some, to just play on.   Dropbox allows us to seamlessly log in by re-referencing a cookie they have planted on our computer to ‘verify’ our identity.   LinkedIn also uses the same technique when we log in.    A user name and password.  How secure is that ?    Well,  not very,  given that both of these sites have been hacked and your and my perso...

WHY SECURITY MATTERS? (or LET’S START A ‘PASSWORD SPRING’ ! )

You would be forgiven for thinking that perhaps most people have become somewhat nonchalant about online security and that the prevalence of hacks has made most of us somewhat immune to the dangers.    Indeed I would say that some sites have become almost cavalier about their attitude to their member’s security.  The recent hacking of LinkedIn certainly did not elicit the kind of response I would have expected, indeed hoped for,  as a member.   I get the impression that it was something of an irritant that they hope won't come again – and are certainly not bothering with beefing up security.  Far too much hassle.   So is their reaction reflective of their members lack of interest – I think not,  as one of their members has tried to sue them for failing to provide adequate security.  ( http://articles.latimes.com/2012/jun/21/business/la-fi-tn-linkedin-5-million-hack-20120621 )   LinkedIn have said that they will salt their passwords...

TRUST

Trust /trəst/   :   Firm belief in the reliability, truth, ability, or strength of someone or something. The foundations of the working of human society are built on trust.  This has been so since the beginning of recorded history.   As our communities evolved from hunter gatherer groups into agricultural chiefdoms, and ultimately modern states their operation, increasing complexity and success relied not only upon our cultural evolution as posited by Robert Wright in Non-Zero ( Non Zero )  but also upon trust.   Trust is integral to our ‘culture.’  The birth of capitalism and the rapid economic and technological growth of the last five centuries began with the pooling of capital used by investors to underwrite a ships trading expedition called the ‘ contratto di commenda ’ .  Such ventures could not have happened without the inherent trust that the investors had - that the expedition’s captain would return the profits to the investors....

The future is bright and it is mobile (in fact it is here !)

There are so many pundits out there who have finally jumped on this bandwagon.   But lets be honest,  five and a half (or is it now closer to six)  billion people,  can’t be wrong – the mobile revolution is finishing its transition from what have been predominantly voice services to broad-band data services.  The devices that we used to just talk on are now full blown computers and we use them for everything – although we do actually still use them to talk on as well too!.  ( See my previous blog:   http://rossmac2310.blogspot.com/2011/10/human-evolution-and-mobile.html ) There are so many exciting threads to this trend : the Internet revolution in Africa and other emerging markets,  the plethora of new services being created every day that add value to our everyday existence and the emergence of real competition in the mobile handset space.   I applaud Microsoft ( and Nokia) for their exciting new partnership and a handset t...

HUMAN EVOLUTION AND THE MOBILE

We in the southern part of the UK have started to see our Indian summer start to slowly fade as we get into this first week of October.    It has been a wonderful but disorientating week with temperatures in the high 20’s (80’s F) – and clear blue skies - I could have sworn this was Jo’burg in Summer.   All that was missing was the swimming pools ! Well I know that parts of the mid-West have also had some great weather.  Indeed in the good ol’  US of A October has become known as  National Cyber Security Awareness month.    Who would have thought ten years ago that a whole month would be ‘honoured’ with such a strange moniker.     Well I guess 10 years ago no one would have predicted that we would have become so utterly dependent on the Web – our every waking and in some instances sleeping moments have some Web connection.    E-mail, social-media,  telephony,  shopping, business, entertainment, gaming  – ju...

SIX MONTHS ON AND EPSILON STILL DONT SECURE THEIR USERS

In April this year,  Epsilon Data Management LLC  (one of the world's largest providers of marketing-email services) , a division of Alliance Data Systems Corp issued a statement, " On March 30th, an incident was detected where a subset of Epsilon clients' customer data were exposed by an unauthorized entry into Epsilon's email system. The information that was obtained was limited to email addresses and/or customer names only ." ( http://www.fastcompany.com/1744738/the-epsilon-breach-should-you-be-angry-worried-or-bored ) When it's all said and done, the Epsilon hack may be the largest name and email address breach in the history of the Internet.  Epsilon handles more than 40 billion emails annually and more than 2,200 global brands. If you are thinking you are safe because you opted-out of marketing emails, think again ( http://blogs.computerworld.com/18079/epsilon_breach_hack_of_the_century ) Epsilon required their customer...

ANONYMOUS / LULZSEC /ANTI-SEC ARE DOING MORE GOOD THAN HARM !

I know,   I know – I hear the howls of protest even before finishing this first sentence.   “What about all the innocent lives exposed by the irresponsible publication of peoples names in positions of authority or in sensitive roles. ?”    But where does the fault lie ?  With those doing the breaking and entering?   Or those not providing adequate protection??  It is liked leaving your house locked without an alarm system, going on holiday, and coming back and finding it broken into.   Don’t be surprised.  You have no one to blame but yourself.  “ But these are criminals ! “  – I hear the sounds of self righteous chest thumping.    Maybe, but what they have done – I hope – is scare the s**t out of anyone who has anything (data) that is accessible via the Web  - and into ensuring that their ‘security’ ( if any ) - is rapidly upgraded.    This ranges from personal users who ...

HACKING - A 50 DAY LOVE ( LULZ) FEST ( or safe sex for the masses)

Image
So Lulz have ( supposedly ) fallen out of love with us after only 50 days !!   WOW -  that was a short and sharp,  whirlwind romance.    One hell'uve steamy affair.    One day SONY,  the next day the IMF,  the next CIA – no one - was safe from her charms. This little slut(z) came into our lives for a bit of fun and has left us breathless and embarrassed with no-where to hide .  Why ?  Because she wanted to show that with a little bit of seduction –by showing a little cleavage /  a bit of leg – she was able to conquer all before her.   Like Helen of Troy – no one could resist her charms. She made us realize that we don’t actually know what protection is all about.   The protection we are  supposed to use  – was either damaged / wrongly spec’d or else we just could not get it 'on' quick enough.   Sure -  she may have laid some of our secrets bare – and many were left red-faced with no-where to...

REPUTATION MORE VALUABLE THAN CASH (ASK SONY)

The recent attack (it seems by Anonymous) on SONY which compromised the personal details of almost 100m of their gaming customers has caused massive damage to the SONY brand.   According to Interbrand in 2009 SONY’s brand value was $12bn.   You can safely assume that it will have taken a hit in the order of billions of dollars.  ( This excludes any legal action and the resultant loss.)  The same could be said of Epsilon and RSA who like SONY did not have a major financial breach but their good names have been severely compromised.   The loss to brand value as well as enterprise value could be massive due to the loss of future business.    (There is a report circulating citing research done on RSA’s customers of whom more than half stated that they would not be renewing their contracts. )    If not obvious before,  then now,  executives charged with the stewardship of large valuable corporations must r...

One swallow does not a summer make

Experts from Gartner have said that the recent 'froth' of M&A activity in the security space does not constitute a 'trend'.   While 'one swallow does not a summer make'  I would contend that this is in fact a trend and that it set to hold for at least another year.   Why? Well first of all the 'froth' was in fact more like a large set of Atlantic rollers breaking on the Cape coast!!!  Consider the number of deals that have taken place in the last 6 months ( see previous blog) crowned by the recent announcement by HP of its acquisition of Arcsight for $1.5bn. "   Hewlett-Packard  has agreed to buy high-end technology security company ArcSight for $1.5bn to profit from its customers’ increasing concerns about  protecting their data from hackers . The cash offer of $43.50 a share for Silicon Valley neighbour ArcSight was more than 50 per cent above where the company was trading before reports last month that it was courting buyers. It value...

MOBILE INTERNET CYCLE DRIVING PRIVACY SECURITY SOLUTIONS

With over two billon Internet users and five billon mobile phone users these global networks bring people ever closer together. These technologies which include broadband (terrestrial) and 3G (wireless) allow for more and more data to be carried. We have entered the next Tech Cycle which is called the Mobile Internet. It was preceded by four tech cycles starting in the 1960’s with the Mainframe cycle. Approximately every decade thereafter we have had a new cycle; Mini-computers - 70’s; PC’s - 80’s and desktop Internet - 90’s. The Mobile Internet cycle triggered by the launch of the iPhone will see mobile internet access overtake fixed access by 2014. This will be driven by smart phone take up and 3G/4G rollout. We are already at the critical point of over 1bn 3G users. Other drivers are video ( YouTube); Social networking (Facebook) and VOIP. Much of this take up is occurring in emerging markets; there are 5 babies born every second - but there are 30 new mobile ph...

PERSONAL INFORMATION - ONLINE CODE OF PRACTICE

If you found my previous post somewhat disconcerting then have a look at this link which is the UK Information Commissioners Guide to the new legislation. " The code explains how the Data Protection Act applies to the collection and use of personal data online. It also provides good practice advice for organisations that do business online and are therefore subject to the DPA. " http://www.ico.gov.uk/ebook/ebook.htm and if you want more in depth information about the legislation itself then have a look at this video from Stewart Room. It makes it somewhat more accessible.

YOUR PRIVACY IN A VERY PUBLIC AND CONNECTED WORLD

So how do you value your privacy in the Facebook age ? Does it matter to you that the calls you make, the emails you send, your credit card transactions, the Internet sites you visit, the images of you travelling to work, your social networking posts are now stored at data centres in the Cloud and retrievable by myriad marketers, Government agencies and companies ? None of whom you ever entrusted with your information in the first place. Your digital footprint is a permanent record of your every move. Data is the pollution of the Information age. Everything we do generates data, and a secondary spin-off of Moores law is that every year it gets cheaper to store and process this data. So rather than sort through our e-mails and delete the ones we don’t need – we just keep them all – it is easier and cheaper to do so. The same thing happens with all of our data now. Most of ‘your’ data actually belongs to someone else. All of your G-mails, everything you ...