Posts

Systems Integrators in a SAAS world

Picture the scene.   You are a SAAS provider.  Your products works for SME’s as well as large corporates.   You know you will need to sell through the channel to get to the larger enterprises.   You engage with the ones who have the best profile for your offering.    You have a great first round – they love your stuff – they say “ we want to sell your service .”    But first…………. we have a few questions.   Now you roll back the clock.   Sigh.   You are in a time warp as you read the questions :  • Where is [ product/service  name]  hosted ?  • Please give us Network, Application and Security Architecture diagrams • What is the models for enterprise clients to sign up?.  • What toolkits are available?  • How will we be able to assist our clients with implementation ?  • How do we monitor and support our clients ?  • Is your product IP protected? • Please provide reference...

CYBER LESSONS FROM SANDY

Whether in the 'real' world or the Cyber world there are real threats and dangers and there are perceived threats and dangers.   Sandy has just taught us about the reality of the force of nature when an extreme event occurs.    Destruction has been wrought on an unprecedented scale.  While we know that physical harm can be effected through  cyber-terrorism/war such as Stuxnet – the reality is that the hype about Cyber war is just that – hype.   These events, like Sandy, are rare.   I contend that the sources of much of the scare-mongering  (about the ‘threat’ of Cyberwar )  are more often than not , entities/organizations/newspapers / journals that have a vested interest in the proliferation of FUD about the weakness of our Cyber defences.    Don’t get me wrong – I am just as concerned as the next guy about cyber security – all I am saying is – lets get some perspective on the matter.   The defences that were put up again...

NatWest mobile banking fail and why real innovation in security is needed

Not a good week for NatWest innovative banking services.  NatWest Get Cash fraud   ( Get Cash Pulled ) A combination of a simple phishing attack and a fundamentally insecure service led to many users of the Get Cash service ( a sub set of the NatWest mobile banking app – powered by Monitise) being defrauded of cash from their accounts.    The system allows users to get cash from an ATM by keying in a ‘secure cash code’ into the terminal.    The assumption is that once you have logged in to your app you are legit and so you ping the system for the code.   A user name and password level of security – that’s it!.   No better than 99% of all apps on the Net today.    Needless to say the service was shut down once the fraud started becoming rampant.    Does the drive for customer convenience completely outweigh basic security rules. ?   The problem with this kind of solution and others that rely on the presentation ...

SITES DONT GIVE A DAMN ABOUT YOUR SECURITY

The sheer volume of reportage on hacking is overwhelming.   The sites being hit are the ones that you and I use every day.   Some provide useful information, some, valuable services and others perhaps just news or trivia.   We use them multiple times a day – sometimes without even being fully aware that we are,  like DropBox.   We use these sites  to store personal and business information, to connect us with potential clients, employers and employees, to help us choose insurance providers, to send us our groceries and some, to just play on.   Dropbox allows us to seamlessly log in by re-referencing a cookie they have planted on our computer to ‘verify’ our identity.   LinkedIn also uses the same technique when we log in.    A user name and password.  How secure is that ?    Well,  not very,  given that both of these sites have been hacked and your and my perso...

DROPBOX DROP THE BALL ..

My last blog touched on the DropBox hack.   It seems that they have now decided to rectify the situation.  ( DropBox Fix security )  But many clients have been left wondering.  How at risk was I and now am I ?   I wonder how much it has impacted their reputation ?    Do you entrust your personal and/or corporate data to them or to any of the other Cloud services out there.  The better known ones are Google Drive,  Evernote, Box,  YouSendit, Sugarsync,  MS SkyDrive and Egnyte.   If so then you should be concerned.   Why?  Because all of these services rely on you proving who you are merely through the provision of a user name and password.    Why is that so bad?   Because nowadays you can get password breakers off the Internet that will crack most passwords in seconds. ( Password cracker ) .   New sites are being hacked every day with serious consequences for the them and their users (i....

DROPBOX HACK – WHY YOU SHOULD CARE ?

DropBox is flying as a company.  More and more of us are entrusting our data to their servers in the Cloud.    I am one of those.  The service is great, it works and it works from multiple devices.  However there is just one thing.  It is not secure.  Read about their latest breach here. ( http://www.zdnet.com/dropbox-gets-hacked-again-7000001928/ )  and also here ( http://gigaom.com/cloud/dropbox-yes-we-were-hacked/ ) I have been going on about passwords and their manifest weakness for months here and in other media.   DropBox have come back to their customers saying that they promise to do more – better passwords – better security …..blah blah blah. So what kind of solution should they use? Well first of all they have millions of customers.  So whatever they go for is going to have to be easy to deploy and should not require the distribution of some kind of hard token OTP generator a la all of...

WHY SECURITY MATTERS? (or LET’S START A ‘PASSWORD SPRING’ ! )

You would be forgiven for thinking that perhaps most people have become somewhat nonchalant about online security and that the prevalence of hacks has made most of us somewhat immune to the dangers.    Indeed I would say that some sites have become almost cavalier about their attitude to their member’s security.  The recent hacking of LinkedIn certainly did not elicit the kind of response I would have expected, indeed hoped for,  as a member.   I get the impression that it was something of an irritant that they hope won't come again – and are certainly not bothering with beefing up security.  Far too much hassle.   So is their reaction reflective of their members lack of interest – I think not,  as one of their members has tried to sue them for failing to provide adequate security.  ( http://articles.latimes.com/2012/jun/21/business/la-fi-tn-linkedin-5-million-hack-20120621 )   LinkedIn have said that they will salt their passwords...