- Password Management. There is some debate around whether you should consider changing your passwords now or changing your passwords after verifying that the patch has been deployed. My practical answer is to wait. Changing your password on an already-compromised website still results in a compromised password, so waiting to change until sites are patched makes better sense. My one exception to this is in situations where you are using the same password for multiple accounts. Immediately changing your password the password that you use for your 4 email accounts, 3 banking applications, 2 social media sites, and 1 online shopping service to 10 separate passwords is one way of minimizing any potential damage from a compromised account. Of course, managing and securing so many passwords can be painful; I recommend utilizing a secure password management tool to assist. My favorite? MiniKeePass.
- Financial Scrutiny. It's an old saw, but it still rings true: keep an eye on financial transactions and financial statements for potential fraudulent activity. Call your fiancial institution immediately if you see something that doesn't make sense.
- When in Doubt, ASK. So how do you know if websites you do business with are vulnerable to this flaw? If you like to get your geek on you can test a website yourself (though the results aren't necessarily conclusive); you can also consult the latest list of Heartbleed test results for popular sites that is circulating the web right now. The easiest way to find out, thought, is to ask the question of those sites which your frequent. Knowledge is power, and getting straight answers from the online entities which you frequent will help you better protect yourself as you move forward.
Wednesday, April 9, 2014
Tips and Tricks on Surviving the Heartbleed Bug
Sunday, March 16, 2014
Intelligence Redux
- 3,015,178,088 -- a number in excess of three billion
- 30151-70808 -- an overseas telephone number, most likely European
- (301) 517-8088 -- a North American phone number
- 301 is one of the area codes for Maryland
- I lived in Maryland from 1995 to 2003
- What do I need to know? What are the most important questions for you to get answered? In the military we referred to these questions as priority intelligence requirements (PIRs). Intelligence collection efforts should be focused on answering these questions first and foremost. Note that determining these questions may be simpler than you think. I remember an intelligence exercise from my GI days involving the transport of relief supplies into a fictional European country via military convoy. As the exercise assumed a hostile force which occassionally disrupted transports along the one major highway into the area, the #1 PIR each was always "Is the road open for travel?" I would imagine that some of the PIRs for most enterprises would be equally straightforward. Some examples:
- Are bad guys in my environment right now?
- Is sensitive data leaving my environment in an unauthorized fashion?
- Which bad guys trying to get into my enterprise?
- Where are the most likely/most vulnerable attack points?
- What is the best way to get the answers I need? Folks, PIRs can (and should) be answered by a multitude of sources. These include (but are not limited to)
- News reports
- Existing enterprise tools
- Communications via professional organizations
- Organizations which monitor threat activity regularly (CERTs, ISACs)
While a "threat intelligence" platform or service, properly constructed, might provide indications and warning about an iminent attack it may be argued that existing sources of data from within the enterprise are better suited to determining the current state of attack if properly monitored and utilized. Indeed, focused monitoring and analysis of open-source information providers may provide reasonbly accurate and timely indications and warning of threats and attacks against the enterprise.
- What do I intend to do with the intlligence gathered? Intelligence collection should not be an academic exercise. Answering your PIRs should drive action within your environment. If fulfilling a PIR does not drive even a minimal course correction on the actions and activities of the enterprise, then you need to consider whether or not you are answering the right questions...or whether or not you need to adjust you efforts down to that which is actionable within your current culture. This last phrase may seem like an anathema to the security professional, but given limited resources we must constantly balance our collection efforts against our execution priorities lest security become simply an academic exercise.
Saturday, March 1, 2014
A Three-Pronged Approach to Protection
Wednesday, February 19, 2014
Eulogy to Windows XP
(The following eulogy was written by Sam Marshall from Treca Educational Solutions. Enjoy! -K)
Many of you may have heard that Windows XP will soon see retirement and no longer receive updates or support from Microsoft. So let’s take a moment to remember Windows XP:
- When Windows XP was released on October 25th, 2001, President George W. Bush had not yet completed his first year in office.
- The minimum amount of RAM to run it was 64MB; the iPhone 5s comes standard with 1GB which is 16x more powerful
- When Windows XP was launched there was no Facebook, Twitter, or Pinterest
- Businesses wanting to install windows XP could prepare 6 FLOPPY DISKS to install the operating system on systems that did not have a CD-ROM drive.
- By January 2006 over 400 Million copies had been sold.
- Microsoft Officially ended sales of Windows XP on June 30th 2008 -- over 5 and a half years ago!
- Microsoft has released 3 newer Operating Systems after Windows XP
- Even in 2014 Windows XP is being used on nearly 30% of the world’s computers. Many of these sytems are ATMs, and Point-of-Sale devices.
- Microsoft will end support of Windows XP on April 8, 2014 (Less than 60 days away)
Why should you care?
If you, your friends, or your family run Windows XP know that after April 8th these systems should no longer be considered secure. Microsoft will no longer release security patches or updates for Windows XP. These updates are like vaccines and Microsoft ending support means no more vaccines will be made to keep your system healthy. (note: Microsoft is offering some level of continued patching suport for businesses, but the pricepoints are punitive. No such support has been planned for individual consumers to my knowledge).
Sadly there are no easy solutions. The only options available are to update to a new operating system or purchase a new computer if your current one cannot run a newer version
Sunday, February 16, 2014
Blinded (and Bitten) by Compliance
Wednesday, December 4, 2013
Millions of Gmail, Yahoo, Twitter, and Facebook Passwords Stolen
Hackers have stolen usernames and passwords for nearly two million accounts at Facebook, Google, Twitter, Yahoo and others, according to a report released this week.
The massive data breach was a result of keylogging software maliciously installed on an untold number of computers around the world, researchers at cybersecurity firm Trustwave said. The virus was capturing log-in credentials for key websites over the past month and sending those usernames and passwords to a server controlled by the hackers. You can read the details of the breach here but you should change your passwords as soon as possible. on these services. Spread the word!
Sunday, December 1, 2013
Security Tips for Cyber Monday
- Patch Your Systems. Sounds simple, doesn't it? Still many personal computing devices and applications remain unpatched and vulnerable (as this year's data breach reports point out Again.). Patch the O/S. Patch applications. Update your virus software definitions...and run a thorough scan of the system before your start surfing.
- No-App Monday. Cyber Monday is not the day to download new apps or ringtones onto your personal device. Expect an onslaught of "new" or "discounted" apps to hit the app sites, offering you every convenient phone functionality you can think of. While many of these might be legitimate, a significant percentage will not be. Remember that the easiest way for the bad guy to get into your systems is for you to willingly let him in. Downloading an app opens your front door to the cyber crook.
- Ignore Pop-Ups. Do not respond to any pop-up window offering your additional discounts/savings/deals simply by clicking on the window.
- Know Your Retailers. If you are going to shop online on Cyber Monday, do so with retailers that you know and have done business with before. Cyber Monday is not the day to "try out" a new online retailer or a known retailer's new online functionality. Also, remember to check the URL of any known retail site that you visit by hovering over the link or inspecting the full URL in the browser windor. Look at the beginning of the string and make certain that the site you are on is the correct one (e.g.: amazon<dot>com versus amaz0n<dot>com). Do not assume that you will recognize a phony website just by surfing it; scammers have become quite proficient at creating professional-looking sites.
- Manage Your Risk. Limit the amount of risk you incur when shopping online by controlling the dollar amount that the bad guys are exposed to. Using credit cards is the most popular method of mitigating this risk, but not the only way. PayPal is, by its design, a risk-limiting method of payment and is also effective. You can also get creative with your banking instruments and designate one checking account/debit card for online shopping and only populate that account with the monies necessary to pay for your online purchases.
- Password Sunday. Scammers are looking for access to your accounts and data as well as your financial instruments. If you shop online on Cyber Monday, consider doing a full-fledge password update and lockdown the day before. Most individuals use the same password for multiple accounts...and (as recent breaches continue to show) most of these passwords are extremely weak. If a scammer utilizes Cyber Monday activities to gain access to your system, having strong individual passwords stored in a secure offline container may slow down the potential damage that can be done. Given the plethora of passwords that most people need to remember, it would be foolish of me to tell you not to capture them somewhere; be smart/prudent re: where and how you store them, though. Personally, I am a fan of KeePass which I store on an IronKey that I keep in my firebox...though there are less-paranoid and less technical solutions.
- Remember Barnum. P. T. Barnum is often credited with saying that "There's a sucker born every minute." Scammers and criminals live by this philosophy. If something sounds too good to be true, it probably is. Be skeptical of "dream" deals and discounts. Do not go down the rabbit hole of exploring such deals, regardless of how tempting they are. Remember, it only takes a nanosecond to compromise a system.
(Historical note: for the purists out there, I am aware that Barnum never said the aforementioned maxim; go here if you want the correct reference. Yes, I have friends who will obsess over that point [squirrel!])