Posts

Showing posts with the label password

Out with the Old and in with the New

I was asked today by a board member to respond to a question from a prospective investor who wanted to know how Live Ensure (our service) differed from two other – lets call them ….the more traditional solutions.  For the sake of this blog we will call them the Old and the New solutions.   Let me describe the Old Co solutions to you briefly.  They both embody technologies which are over a decade old ( think RSA ) such as tokens and servers ( both physical and virtual).  Their solutions rely on the user entering a PIN into a browser and thereby satisfying the ‘something you know ‘ part of strong authentication.   Here it is slightly edited. The biggest weakness of both Old Co solutions are the vulnerability to MITM and MITB attacks. Both require the user to enter a PIN ( something you know ) ie a second factor over and above the user name and password ( the single factor or weak authentication ). The user enters this PIN back into the browser which is...

Why most security fails and LiveEnsure® does not ?

Image
Mary Meeker informs us that there are now 1.1bn  Smartphones  (17% of all mobile phones) and these are driving Internet growth with a total of 2.4bn people now connected to the Internet. Mary Meeker Internet trends The universe for hackers just grows and grows.    One of the most lethal of these attacks is Zeus (ZITMO) – which is aimed squarely at Smartphones. The Zeus attack is an example of several attacks now being launched that are based wholly on anticipated behavior, especially as it relates to social media, single-sign-on and BYOD. A sophisticated Zeus campaign stole an estimated €36 million, or $47 million, from over 30,000 customers across more than 30 banks in Europe this summer. The Eurograbber campaign, as it has been named, used custom versions of Zeus and Zeus in the mobile (ZITMO) Trojans to bypass the two-factor authentication measures to compromise customer bank accounts, Darrell Burkey, director of IPS products at Check Point Software Te...

SITES DONT GIVE A DAMN ABOUT YOUR SECURITY

The sheer volume of reportage on hacking is overwhelming.   The sites being hit are the ones that you and I use every day.   Some provide useful information, some, valuable services and others perhaps just news or trivia.   We use them multiple times a day – sometimes without even being fully aware that we are,  like DropBox.   We use these sites  to store personal and business information, to connect us with potential clients, employers and employees, to help us choose insurance providers, to send us our groceries and some, to just play on.   Dropbox allows us to seamlessly log in by re-referencing a cookie they have planted on our computer to ‘verify’ our identity.   LinkedIn also uses the same technique when we log in.    A user name and password.  How secure is that ?    Well,  not very,  given that both of these sites have been hacked and your and my perso...

The End of Passwords

Finally it seems … the penny has dropped.   Passwords are a poor substitute for real online security.   There is more and more ‘chatter’ about it.    Robin Henry writing in the Sunday Times on New Years Day talks of the end of ‘password hell’ invoking solutions in the pipeline from the Web Gods – Apple and Google.  The talk is of new biometric solutions such as facial and hand movement recognition.  Even IBM is talking this way.  ( http://www.forbes.com/sites/thestreet/2011/12/20/ibms-tech-predictions-for-the-next-5-years/ )  I agree with the notion that passwords are a dying breed but not that biometrics will become vogue.   They are fraught with problems of their own such as reliability, accuracy and the need for referencing of data-bases ( fail !) .    Why are passwords defunct?   Basically they are difficult to remember and they are easy to steal.    The solutions needed are those that require no cognitive l...

You need authentication

I am constantly amazed at the lassez faire attitude that the majority of businesses, large and small, have about their online security.  Those that require their users / members to log on will provide a user name and password log in to verify their identity – and that’s it.  I suppose that if the large players like Amazon and iTunes can get away with it then the smaller guys think that’s all they need to. The reality is that if the big boys get a hit – they have the firepower to deal with it.  But SME’s just need one bad hack and they are out of business.    2011 is going down as the year of the ‘Hack’ (  http://www.infosecurity-magazine.com/view/22481/year-of-the-hack-/?utm_source=twitterfeed&utm_medium=twitter)  with many high profile victims like SONY, RSA and Epsilon losing millions of their users personal information.    Despite this there seems to be the attitude that ‘ it cant happen to me’ .  ...

Authentication in ' context'

con·text /ˈkäntekst/ The circumstances that form the setting for an event, statement, or idea, and in terms of which it can be fully understood and assessed. authenticate [ɔːˈθɛntɪˌkeɪt] vb (tr)   to establish as genuine or valid What does context have to do with authentication? When you log on to a web site and enter your user name and password so as to ‘authenticate’ yourself all you are presenting are self reported credentials to the site.  If you present the correct credentials then the site accepts you as - who you say you are.   It takes you at face value.  It identifies you.  Liken it to a knight of old arriving at castle and announcing himself.   When you log on to a web site and it asks you to log in with a user name and password – you are in effect – announcing yourself – identifying yourself.   What happens if someone steals your password?   Then they can log on as you – the site is none the wiser – the thief has presente...

SECURITY SANS FRONTIERS

In many countries around the World, access to the Internet is seen as a basic right, and so it should be.    Those countries which have done so to date include :  Estonia, France,  Spain,  Greece  and Finland,  which was actually the first to do so in June 2010.  ( http://www.publicserviceeurope.com/article/642/internet-access-should-be-a-human-right)  I In fact the United Nations recently declared Internet access as a human right. ( http://www.itproportal.com/2011/06/04/un-declares-internet-access-as-a-human-right/ ) Obviously the next challenge is to build the infrastructure and provide the means of access.    But that is the subject of a separate discussion. So the “World”  has woken up to the importance of closing the digital divide and has also realized the importance of the Internet, and access to it,  to the functioning of society.   Amongst the many momentous events of the last twelve months ...

ANONYMOUS / LULZSEC /ANTI-SEC ARE DOING MORE GOOD THAN HARM !

I know,   I know – I hear the howls of protest even before finishing this first sentence.   “What about all the innocent lives exposed by the irresponsible publication of peoples names in positions of authority or in sensitive roles. ?”    But where does the fault lie ?  With those doing the breaking and entering?   Or those not providing adequate protection??  It is liked leaving your house locked without an alarm system, going on holiday, and coming back and finding it broken into.   Don’t be surprised.  You have no one to blame but yourself.  “ But these are criminals ! “  – I hear the sounds of self righteous chest thumping.    Maybe, but what they have done – I hope – is scare the s**t out of anyone who has anything (data) that is accessible via the Web  - and into ensuring that their ‘security’ ( if any ) - is rapidly upgraded.    This ranges from personal users who ...

DOES YOUR WEBSITE HAVE A LOG IN ?

Well - you’re probably thinking - this is going to make a fun read !!   Does my website have a log in ??  Well damn right it does ( you’re saying to yourself) – we can’t just let any old passer by onto our site!! I mean look at all these big cheeses being hacked like RSA , SONY and even the CIA !! But if users have to log in - that means they need to register and they need to remember yet another user name and possibly -  but not necessarily - another password.    Well - that means that customers desert in droves !  Or does it? Are customers put off when they have to log in ?  Well I guess a lot has to do with whether the service you offer is valuable enough.   Lets see – Twitter, Facebook and Gmail just to name a few at random – you would expect to see some kind of ‘identification ‘ process going on.  And indeed you do.  And now to make it all that much easier – SSO (Single Sign On) ,  OpenID and now BrowserID co...

ONLINE BANKING STAYS IN THE DARK AGE

 A large ( big 4 )  UK bank recently sent its corporate customers a letter advising them of their  ‘new’ security solution.   Here is an extract from the letter : " Online banking fraud and identity theft is increasing across the UK - in 2009 fraud across all UK banks exceeded £59m.  Fraudsters are becoming ever more sophisticated in their efforts to obtain personal information and gain access to accounts.  We're committed to keeping your Internet Banking service safe, so we're introducing a more secure way to bank online using a card reader.  A card reader is a small handheld device which you will need every time you bank online.  We'll send one to every registered user within your business.   " Talk about being underwhelmed.  If I was a customer I would be seriously unhappy.   But most  customers probably will not.  That is because they (probably)  don’t realize that :  1)    THEY are g...

What the Analyst said ....Why LiveEnsure and SiteKey/SitePass are not the same.

  So there I was on the phone to an Analyst today explaining (at a fairly high level )   some of the basic features of LiveEnsure TM   when he says – “   ahh – I get it – this is identical to Bank of America’s SiteKey/Site Pass system .”    Not having the details of said banks system at my fingertips – I was unable to correct the Analyst on his incorrect conclusion with any hard science.    We were also running out of time,   it was a bad line and…all I could say was – it is not the same – there is much,   much more going on under the hood with LiveEnsure TM .     So why is BofA’s SiteKey TM / Site Pass TM authentication system NOT identical to LiveEnsure TM   ? ·                 Device ID.    Although both ostensibly have a ‘hardware device recognition’ component – the BofA solution relies upon the re-referencing of a cookie (dow...

One swallow does not a summer make

Experts from Gartner have said that the recent 'froth' of M&A activity in the security space does not constitute a 'trend'.   While 'one swallow does not a summer make'  I would contend that this is in fact a trend and that it set to hold for at least another year.   Why? Well first of all the 'froth' was in fact more like a large set of Atlantic rollers breaking on the Cape coast!!!  Consider the number of deals that have taken place in the last 6 months ( see previous blog) crowned by the recent announcement by HP of its acquisition of Arcsight for $1.5bn. "   Hewlett-Packard  has agreed to buy high-end technology security company ArcSight for $1.5bn to profit from its customers’ increasing concerns about  protecting their data from hackers . The cash offer of $43.50 a share for Silicon Valley neighbour ArcSight was more than 50 per cent above where the company was trading before reports last month that it was courting buyers. It value...

SECURITY M&A GONE A BIT CRAZY ....

The tech sector and in particular the security sector within  has been extremely active during the past 6 months.  There have been numerous acquisitions that indicate an increased appetite for quality security assets.    Perhaps the most high profile of these was the recent acquisition of MacAfee by Inte l ( a $7.8bn transaction ) representing a premium of over 50% to the then prevailing market price.  A PE multiple of about 48 and 3.8 x Revenue. This was Intel’s largest ever acquisition. Symantec acquired Verisign’s Authentication business for $1.28bn - approximately 4 x revenues. (Second quarter revenues from this Unit was about $100m )  ( May ) ; CA has announced it will acquire Arcot systems for $200m in Q4 2010.  Arcot provides Identity Access Management and Authentication products  ( www.ca.com/www.arcot.com ) ;  VMWare has announced it will acquire Integrien and TriCipher .  (Sep)  HP has just announced it will acquire ...

SMB/E's underestimate the cost of cyber security breaches

I found this article at www.smallbusinesscomputing.com and I am repeating it here verbatim because I believe that it captures the essence of the challenges that lie ahead and the need for education and the provision of simple but effective authentication solutions.  What SMBs Don't Know About Security Can Hurt You April 23, 2010 Small and midsized businesses might be the lifeblood of the U.S. economy, but according to the latest Internet security survey from Panda Security, their generally lackadaisical efforts to protect consumer data is also making them a prime target for cyber thieves. More disturbing, particularly for customers swiping their credit cards or purchasing products and services online, the survey reveals that the vast majority of SMBs claim they don't know how to effectively prevent identity theft, lack the resources to install the technology that could thwart the majority of cyber attacks and, worse, seem to believe that it's really not their probl...

MOBILE INTERNET CYCLE DRIVING PRIVACY SECURITY SOLUTIONS

With over two billon Internet users and five billon mobile phone users these global networks bring people ever closer together. These technologies which include broadband (terrestrial) and 3G (wireless) allow for more and more data to be carried. We have entered the next Tech Cycle which is called the Mobile Internet. It was preceded by four tech cycles starting in the 1960’s with the Mainframe cycle. Approximately every decade thereafter we have had a new cycle; Mini-computers - 70’s; PC’s - 80’s and desktop Internet - 90’s. The Mobile Internet cycle triggered by the launch of the iPhone will see mobile internet access overtake fixed access by 2014. This will be driven by smart phone take up and 3G/4G rollout. We are already at the critical point of over 1bn 3G users. Other drivers are video ( YouTube); Social networking (Facebook) and VOIP. Much of this take up is occurring in emerging markets; there are 5 babies born every second - but there are 30 new mobile ph...

PERSONAL INFORMATION - ONLINE CODE OF PRACTICE

If you found my previous post somewhat disconcerting then have a look at this link which is the UK Information Commissioners Guide to the new legislation. " The code explains how the Data Protection Act applies to the collection and use of personal data online. It also provides good practice advice for organisations that do business online and are therefore subject to the DPA. " http://www.ico.gov.uk/ebook/ebook.htm and if you want more in depth information about the legislation itself then have a look at this video from Stewart Room. It makes it somewhat more accessible.

YOUR PRIVACY IN A VERY PUBLIC AND CONNECTED WORLD

So how do you value your privacy in the Facebook age ? Does it matter to you that the calls you make, the emails you send, your credit card transactions, the Internet sites you visit, the images of you travelling to work, your social networking posts are now stored at data centres in the Cloud and retrievable by myriad marketers, Government agencies and companies ? None of whom you ever entrusted with your information in the first place. Your digital footprint is a permanent record of your every move. Data is the pollution of the Information age. Everything we do generates data, and a secondary spin-off of Moores law is that every year it gets cheaper to store and process this data. So rather than sort through our e-mails and delete the ones we don’t need – we just keep them all – it is easier and cheaper to do so. The same thing happens with all of our data now. Most of ‘your’ data actually belongs to someone else. All of your G-mails, everything you ...

A NEW TECH CYCLE - CHANGING OUR WORLD

I suppose what I am really excited about - ( notwithstanding the doom-mongers of Global Warming, un-payable National debt, Euro-zone contagion, GM food and England’s prospects in the World Cup amongst other paranoia permeating and eating away at the soul of our society !! ) - is the fact that we have entered the next Tech Cycle. Amidst the threat of a double dip recession, oil spills in the Gulf of Mexico and Greek unrest who cares about the next Tech Cycle – the next Dot Bomb ? You may well ask ! The fact is that there have been four Tech cycles in the last 50 years and each one has been bigger and better than the preceding one. Let's remind ourselves of what they were : 1. The mainframe computing cycle started in the 60’s with the main players being IBM, NCR, Sperry ; then followed 2. The mini-computing cycle in the 70’s with the major companies being Digital Equipment, HP and Wang and then; 3. The PC era of the 80’s/90’s where we saw the rise ...