donderdag 29 augustus 2013

Ditch Cyber campaign

A few weeks ago I started my #ditchcyber campaign, or #wegmetcyber in Dutch. The reason for doing this is that in my opinion the word cyber is misused a lot. Right now cyber is connected to almost every event that is happening on the internet, in the cloud, in datacenters, at home and in the office. In many cases cyber, followed by another term, has a very negative meaning, if someone uses the word Cyber it's about trouble. War, crime and we need cyber security, a cyber army and cyber police to help us against these cyber threats.
And now this means that the audience only knows about cyber where it has this special negative meaning. Cyber requires special cyber forces to guard us from risk.

And what is really the case? It's about information security. It's about professionalism. It's nothing more than managing bits and bytes. But we are just too lazy to do it right, or we just spend too little money to make it secure. And then when something bad happens, a data leak, or a ddos attack, or whatever crosses your mind, then there is the big CYBER excuse.

Well excuse me, you don't hide stupidity in empty words.

I don't want to be rude, but most incidents are of our own doing, they are human errors. Nothing new. Data leakage, like Manning's, happen because of lousy access control and bad logging. Hack attempts because of lacking configuration and patch management. Ddos because of bad architecture. Priviliged account misuse because of social engineering. Identity theft because of lacking awareness. Fraud because of lacking segregation of duties, lack of governance. Foreign intelligence acting hostile? Because of our own lacking governance and our being pennywise.

Did I mention cyber? Sorry, no way. Nothing new, just the same old errors. But since we call everything Cyber, we obfuscate our own lack of responsibility and lack of accountability. Makes it so easy...

So here I am, a lonely cyber warrior, ditching cyber. Feel free to join the campaign.

And please lookup the real meaning of cyber everything on wikipedia.

#ditchcyber (@alcyonsecurity came up with this translation, thanks!)
#wegmetcyber

zaterdag 30 maart 2013

Identity Fusion, a study from 2009

For the Identity.Next advisory board we are studying several new topics that may be of interest for the identity management community. Somehow my name popped up for the topic Identity Fusion. I must have mentioned it some day, but I really forgot about it.
It seemed that this subject has been studied before, or at least the title Identity Fusion was defined in 2009, although in a different context than our regular identity management topics.
The abstract of the article by William B. Swann, Jr, D. Conor Seyle, Ángel Gómez J. Francisco Morales and Carmen Huici states:

The authors propose that when people become fused with a group, their personal and social identities become functionally equivalent. Two hypotheses follow from this proposition. First, activating either personal or social identities of fused persons should increase their willingness to endorse extreme behaviors on behalf of the group. Second, because personal as well as social identities support group-related behaviors of fused persons, the 2 forms of identity may combine synergistically, fostering exceptionally high levels of extreme behavior. Support for these hypotheses came from 5 preliminary studies and 3 experiments. In particular, fused persons were more willing to fight or die for the group than nonfused persons, especially when their personal or social identities had been activated. The authors conclude that among fused persons, both the personal and social self may energize and direct grouprelated behavior. Implications for related theoretical approaches and for conceptualizing the relationship
between personal identities, social identities, and group processes are discussed.

Here is the link to the full article.

donderdag 31 januari 2013

Lessons from the Diginotar drama: We need Trust Governance

In the summer of 2011 the Dutch Certificate Service Provider Diginotar collapsed due to a hack of the back-end systems by an Iranian hacker. Since then many analysis were published. Most indicating plenty problems at Diginotar or about the inadequacies of PKI as we know it. But in my opinion the problems are more severe than just technical issues.
In 2012 the Dutch Magazine Informatiebeveiliging published my analysis (I should mention that I am one of the editors of the magazine, so there is no full independency there...). By request I translated the article.

You can find the English language version of article via this link.

(I wish to thank Jacoba for reviewing the translation)

Feel free to react.

vrijdag 11 januari 2013

Responsible Disclosure


These days in The Netherlands several initiatives pop-up around the issues of ethical hacking and Responsible Disclosure.

What's all the fuss about?
Last year a hacker reported a vulnerability and a data leak in a back-up server of a Dutch hospital. He claimed that he found a lot of confidential information on a server that was readily accessible from the internet. The report was made through a Dutch journalist, +Brenno de Winter.
After publishing the incident we learned that the hospital sued the hacker and for us, the security community, this was unheard of: why sue someone who reports a vulnerability? Who are the amateurs responsible for this leak and do they really think they can get away by suing a security researcher?

In the mean time the minister of Internal Affairs published his guidelines for ethical hacking. And in those guidelines a hacker might be exempt from prosecurtion if he acted conform.

So, we, the Dutch security community, were puzzled. Then rumors came in that the hacker had installed malware on the hospital's server. Sentiment changed, but despite the new guidelines, trust of the hacker community in the authorities, like the DA responsible for cyber crime, vanished. Trust was gone and so was the willingness to co-operate. And right after, some critics of the official guidelines raised their voices and it looked like the guidelines were no longer valid for the people that were addressed in the guidelines.

At this moment this is the status:

And that's not all, there is at least one more initiative, but that's not yet ready for prime time yet.

Anyway a lot of activity in interesting times. Please have a look at Floor's site and feel free to react!

I will try to publish some more about all activity and invite you to join the discussion.



maandag 19 november 2012

I shared an email with you

Twitter introduced an interesting new feature, emailing a tweet that you think might be of interest to someone else. Twitter lets you send an email straight from the Twitter web interface. If you choose so, up pops a browser window that lets you enter the email address of the recipient and enter some text next to the tweet. Press a button and Twitter takes care of sending the tweet.

Why does this bother me?
Some time ago I wrote a blog entry about Behavior centric identity management. I said that my Identity is constructed using several components, one of which is my behavior. You may know my name, or my interests, my relations, my work, whatever, but the more aspects of me you know, the better you know the real me, the closer you come to the real me. In order to be in control of the real me, for me this means seperating these components as much as possible. That's why I use netvibes rss aggregator (that knows about my areas of interest) instead of iGoogle (that will disappear anyway).

My Twitter handle is one of my identity components, just like my email relations. And the tweeps I follow are not randomly chosen, no, they are part of my identity too. But Twitter is just an instrument for me to use and Twitter has got nothing to do with my other identity components.

But now that they started offering an email facility, they have to possibility to combine my separate identity components. They can combine my areas of interest (the tweet that I want to share) and my non-Twitter relations (this function is obviously meant to reach non.tweeps, otherwise a simple RT would do). It's an effective interest aggregator.  The email sent contains lots of information, but most important is that Twitter owns the mail server. And Twitter is the owner of the sent email message.

Twitter could of course offer the email button and start my email client, just as easy, and they would never know to whom I would like to send a tweet. But by implementing the email facility like they did, they are in the middle of my communication channel with a non-Tweep. They know that my Twitter ID is interested in informing a non Twitter identity about a certain subject.

Since Twitter is becoming the on-line memory for our thoughts, I don't think that Twitter will remove all emails and temp files, do you?

maandag 8 oktober 2012

Confirmation e-mail shows password vulnerability

This week it happened again: I received an e-mail with a confirmation of creating an account for a webshop. Yes, it is very comforting to know that you have an account. But apart from the fact that I created yet another account somewhere in the cloud, I noticed that the email showed my account credentials in full text. Reading my accountname was not that special, but seeing the password I entered on the site was less reassuring.
If the mailserver sends an email with a readable password it means that my password is accessible for the mailserver in a readable format. And that means that the password is unencrypted somewhere between the website and the mailserver. In most cases a content management system (with a user database) or a webshop system (with some kind of CRM database) are familiair with my account. And both these systems use the emailserver to inform me about all transactions. Including account creation. The same can happen if you click a link to the forgotten password function. Some systems resend you the password for your account. So they must be able to read the password from your account in the database.
For me this implies that the CMS and/or CRM system do not store the password in encrypted form, otherwise how can the mailserver get the content for the email? I don't suppose these systems use a brute-force attack to discover your password...

In this case I informed the webshop owner that I suspect that there is a vulnerability in the user management function. 

Best practices:
  • Use third party identities (Oauth, OpenID etc.) to create customer accounts, that way you don't store passwords;
  • Use a hashing function for passwords in the database (and please pick a secure algorithm);
  • If your CMS or CRM doesn't support encryption of passwords, change to a secure system.
And never ever send an email with the password in readable form. Better send an email with a link to the password reset function.

If you encounter sites that email your password (either at create time or at password reset), please inform the webmaster of this vulnerability.

donderdag 27 september 2012

Identity Management and CRM

The use of digital identities for internet users has been discussed in many places. And plenty solutions have been developed. There are lots of identity providers that offer (open) standards based digital identities that can be reused.
For companies the use of digital identities is only part of the problem, the use of external identities is just becoming a necessity.

Apart from offering access for external identities, organisations also have to cope with the internal identities of their customers. The more (legacy) backoffice systems organisations use, the more difficulty they have in identifying the value of their customers. Nothing new here: this problem is solved in Customer Relation Management (CRM) and Master Data Management (MDM): we create a 'Golden Record', a unique internal representation of a customer, that is related to all coupled internal backend systems.

Master Data Management is an area with specific problems. How do you connect customer accounts in different backend systems with different identifiers. Backend1 customer A1 can be the same as Backend2 customer R2D2 and may not at all be Backend3 customer A1, but ASDFG9 instead. Master Data Management uses intelligent rules engines to connect Id's and knows some trics, like deduplication. I will not go into detail (I don't know this kind of process well enough).

In a sense both identity related problems look alike, although they are mirrored. Let me show it in a simple picture and await your reactions...: