Friday, 12 August 2011

De-bunking anti-virus vendor claims

Just in case you haven't seen it yet, I'd recommend you take a look at the paper put out by Tavis Ormandy discussing the findings from his reverse engineering of the Sophos anti-virus product; the paper's available from:

http://lock.cmpxchg8b.com/Sophail.pdf

It's clear from the tone of the paper that the author had a few issues with Sophos but I don't think the tone should distract from some of the serious weaknesses (particularly in the area of buffer overflow protection) that the paper describes.

What I'd really like to see now would be similar investigations of the claims of the other major anti-virus products out there - are Sophos alone in having these issues or is it endemic across the A-V industry?

It would also be helpful if Sophos put out a more technical response to Tavis' paper rather than the somewhat bland post to be found at:

http://nakedsecurity.sophos.com/2011/08/05/tavis-ormandy-and-sophos/

'til next time...

Friday, 22 July 2011

So, do we actually care?

One of the consequences of the recent rash of published hacking incidents is that we may now have a contemporary sample size that's almost big enough to draw some meaningful conclusions about how much the general populace (and business) actually cares about information security. Incidents associated with Anonymous, LulzSec, Sony, RSA, News International and others are all now in the public consciousness. But will there be any real long-term impact of these hacks? For example:

How many mobile phone users have now set unique PINs on their voicemail rather than relying on the default values?

How many organisations have ditched their RSA tokens in favour of competing technologies?

How many PS3 users have abandoned the PlayStation Network for good? Or have they all (like me :-) been bought off by a few free games and promises that it'll be better next time?

If consumers don't actually care about security, what are the real drivers for continuing to invest in it? Do we really have to fall back on compliance as the sole driver?

It's fortunate for the security industry that there are still financial services organisations, IP-centric industries, gaming firms etc where the security of their systems and data is necessary for their continued survival.

But hey, I could be wrong and perhaps the recent incidents will drive new and improved behaviours - guess we'll just have to wait and see...

Wednesday, 22 June 2011

LulzSec

LulzSec - doing it for the lulz. Looking at the attention and drama they've created, can anyone say that they haven't succeeded?

Friday, 3 June 2011

Time for RSA to come clean

Right. I've been patient. We've all been patient. But now I think it's time that RSA come clean about exactly what they lost when they were compromised earlier this year. We've now had reported attacks against Lockheed Martin, L-3 Communications and Northrop Grumman all of which have been linked with the use of SecurID tokens as an attack vector. Is the reporting correct? No idea. Is damage being done to RSA regardless? Oh yes.

What harm can come now from RSA posting details of what was compromised? I'm aware that RSA are in talks with their bigger customers but I don't think that this is enough. It certainly doesn't help me if I'm considering implementing a new two-factor authentication solution; why on earth would I consider SecurID at this time?

Final points to consider. It's probably fair to state now that whomever compromised RSA has used that information to attack their first tranche of targets. The surprise element is now gone and top tier targets should now be on the lookout for similar incursions. So what's the value now to the attackers in keeping whatever they got from RSA close to their chests? I daresay there'll be a bit of probing of some of their second tier targets (banks anyone?) before the attackers decide that they've realised most of the value of their initial RSA compromise. Depending on how mischievous they feel, I wouldn't necessarily be surprised to see the compromised RSA materials appear on the Internet in the near future - if only as a means to cause significant pain and disruption to the rest of the RSA user base. Do state-sponsored hackers still do it for the lulz? Guess we'll find out soon enough.

*********UPDATED************

Open letter from RSA to their customers:

http://www.rsa.com/node.aspx?id=3891

Still no real details though. Ho hum.

Tuesday, 10 May 2011

PSN hack

O... M... G...

http://www.eweek.com/c/a/Security/Sony-Networks-Lacked-Firewall-Ran-Obsolete-Software-Testimony-103450/

I'm surprised they weren't hacked sooner.

The content of the article does raise some really interesting questions about their compliance with PCI-DSS and how they got through the process...

Tuesday, 26 April 2011

Thoughts on Infosec and the AWS outage

I managed to sneak in a quick afternoon visit to Infosec last Wednesday. I'll admit the free (and, quite honestly, excellent) lunch that I'd been invited to by the chaps over at IRM was influential in making sure that I didn't miss the show completely this year. Good food, interesting conversation. Thanks Phil :-)

I'm not entirely sure what I made of this year's show. To my eyes, it seemed quite busy in terms of attendee numbers and a number of the brave souls manning the stands seemed to be losing their voices by the time I got there after lunch. Which means it's probably safe to assume that they'd been kept occupied pitching their wares and handing over the usual treasure trove of pens, t-shirts and cheap puzzles. However. Other than finding out some more positive details on the Forum Systems products and coming across a promising new cloud security vendor (CipherCloud - check 'em out!) I'm not sure that I got too much out of the exhibition. Primarily the same old(er) faces pitching the same old(er) solutions and, unfortunately, the same can probably said of the education streams. Can't help thinking that the information security scene needs an injection of new DNA to breathe some new life, enthusiasm and ideas into what seems to be becoming a somewhat jaded, self-serving and self-congratulatory sector. The irony of my posting that last statement on a blog has not escaped me :-)

Whilst I'm being a little negative, the big story from the cloud computing world has been the downtime over at AWS which even made it on to the BBC web-site: http://www.bbc.co.uk/news/technology-13160929. We're still awaiting details of the problem (other than that there was a problem with EBS volumes and dependent services) but the biggest surprise(?) was that the issue spanned supposedly isolated availability zones within the affected region. I'm really hoping that the promised "post-mortem" discussing this event provides sufficient detail to enable AWS customers to design for resilience with a full understanding of exactly how isolated availability zones really are...

Friday, 8 April 2011

Latest cloudy ramblings

See, I'm making the most of my recently discovered free(ish!) time by popping up in Computer Weekly talking about the adoption of cloud services by SMEs. Link below:

http://www.computerweekly.com/Articles/2011/04/06/246204/CW-Security-Think-Tank-Whats-holding-up-the-cloud.htm

Some interesting differences in tone and opinions amongst the contributors to this Think Tank piece. When it comes to the use of hybrid cloud models I think I tend more towards the opinions expressed by Christofer Hoff over at http://www.rationalsurvivability.com/blog/?p=3016 rather than the view expressed by the chap from Gartner that cloud providers should be targetting SMEs with hybrid cloud services.

Hybrid is fine if you're talking about mixing your delivery of capabilities across on-premise and cloud, I've always had more of a problem with Hybrid as a way of delivering increased capacity on demand in that it's always seemed the worst of both worlds from a security perspective, i.e. you need to worry about the security problems associated with both models rather than just the one!

And, as Hoff says, "If your Tier-1 workloads can run in a public cloud and satisfy all your requirements, THAT’S where they should run in the first place!"