The information security sector is rife with negativity and pronouncements of doomsday, and while this title is no better, this blog is not meant to scare, but to provide an alternative view of the worst case scenario; a data breach and resulting forensics investigation. The fact remains that if your data is online, someone has the necessary skill-set and wants it badly enough, they are going to get it. So the sooner you prepare yourself for the inevitable, the better you will be able to prevent a security event from becoming a business-crippling disaster.

By the time you make your environment as hack-proof as humanly possible, the chances are you have spent far more money than the data you’re trying to protect was worth, which in security equates to career suicide. Instead, you are supposed to base your security posture on the only thing that matters; a business need, then maintain your security program with an on-going cycle of test > fix > test again.

Unfortunately what happens in the event of a breach is that you are told what was broken and how to fix it from a technical perspective. This is analogous to putting a plaster / band-aid on a gaping wound. You’re not actually fixing anything. A forensics investigation, instead of being seen as the perfect opportunity to re-examine the underlying security program, is seen as an embarrassment to be swept under the carpet as soon as possible. Sadly, valuable lessons are lost, and the organisation in question remains clearly in the sights of the attackers.

For example, let’s say a breach was caused by an un-patched server. The first thing you do is fix the server and get it back online, but all you have you have done is fix the symptom, not the underlying cause;

  1. How did you not KNOW your system was vulnerable? – Do you not have vulnerability scanning and penetration testing as an intrinsic part of a vulnerability management program?
  2. How did you not know your system wasn’t patched? – Is not patch management and on-going review of the external threats landscape also part of your vulnerability management program?
  3. Did the breach automatically trigger a deep-dive examination of your configuration standards to ensure that your base image was adjusted accordingly?
  4. Did you fix EVERY ‘like’ system or just the ones that were part of the breach?
  5. Did your policy and procedure review exercise make ALL necessary adjustments in light of the breach to ensure that individual accountability and requisite security awareness training was adjusted?
  6. Were Incident Response, Disaster Recovery and Business Continuity Plans all updated to incorporate the lessons learned?

And perhaps the most important part of any security program; Is the CEO finally paying attention? Ultimately this was their fault for not instilling a culture of security and individual responsibility, so if THIS doesn’t change, nothing will.

If the answer is no to most of these, you didn’t just not close the barn door after horse bolted, you left the door wide open AND forgot to get your horse back!

Most breaches are not the result of a highly skilled and concerted attack, but by those taking advantage of the results of  systemic neglect on the part of the target organisation. i.e. MOST organisations with an Internet presence! Therefore, organisations that can work towards security from the policies up, and the forensics report down, have a distinct advantage over those who do neither.

[If you liked this article, please share! Want more like it, subscribe!]

Before I can answer that questions, I need to define what I think Identity is. Too often authentication is used interchangeably with identity, but that’s like saying a bank account and money are the same thing.

In its most basic terms, authentication is the what-of-you, identity is the WHO-of you. You can authenticate via password to log into your computer or buy a cup of coffee, but if you want a mortgage, considerably more background information is required. I could give you 5 usernames & passwords, 5 forms of biometrics, and have 5 different hardware tokens and you would still not know to any degree of certainty if I’m good for a loan.

Example: Two people are standing in front of you, one’s a stranger and one’s a close friend. You know [for the sake of this hypothetical] that they are both who they say they are, but do you feel equally comfortable lending them your car?

I would assume the answer is no, you would NOT be comfortable loaning a stranger your car, so what’s the difference? Trust, pure and simple. You trust your friend because you know WHO they are, not WHAT they are.

Unfortunately you will never be able to know everyone on the planet as well as your friends, so how can you assure a sufficient level of trust to do business of any sort? Currently, authentication is enough, but it’s almost entirely one way. If you want to buy something on the Internet YOU have to complete the login details (often including a permanent account), you have to enter all of your payment details, and you have to accept the risk that the merchant will send the goods as promised.

With an identity, built over the course of time and receiving input from many sources, every individual and every organisation can build a demonstrable level of trust so that both sides have the assurance they need to conclude the transaction. Fraud in e-commerce is rampant because we simply don’t have this 2-way assurance.

From the individual side: Credit score, confirmation of available funds, payment history, and any number of other factors can build a Trust Assurance Score (TAS), and it will be up to both the buyer and the seller to agree on the level of score required to complete a purchase. e.g. on a scale of 1 – 100 (100 being a perfect TAS) the merchant needs a score of 5 to buy the ubiquitous cup of coffee, but a score of 50 to rent a car, and a score of at least 75 to get a mortgage.

From the merchant side: Time in business, corporate credit rating, ratings and reviews and so on can build their TAS, so you can decide up front the level of risk you are prepared to accept to conduct the business at hand.

Clearly there are many challenges with this; How do you build a rating in the first place (the young and new businesses should not be unfairly advantaged)?; How do you provide instant access to this rating without exposing all of the detailed information behind it?; How do you tie in the level of authentication required to even request a TAS? And so on.

I’m not proposing a way to fix this, I’m simply trying to demonstrate that the reason we don’t HAVE identity built into transaction authentication is that these issues have not been addressed yet. And until we have identity built into transactions, we won’t have the levels of trust required to make significant change. Payments for example will move from plastic to mobile, but authentication (even multi-factor) is not enough to significantly reduce fraud.

I suspect block-chains (the technology behind crypto-currencies) has a big chunk of the answer, but I can’t even conceive on how this will be done. I just know it needs to.

[If you liked this article, please share! Want more like it, subscribe!]

I don’t necessarily mean faith as it pertains to religion, although that is by far the best example of how faith can completely negate ever having to think for yourself. Ever again.

When I talk about faith, as defined by; “A complete trust or confidence in someone or something.” you can perhaps see where faith can be a force of tremendous good, or horrific bad. When you remove the need to question something, you remove any reason for that thing to change. When your most valuable asset; your ability to reason, is subsumed into a concept not of your making, you have lost your individuality, your uniqueness. You have lost your sense of self.

When humans first became self-aware (estimated at around 60,000 years ago), the number of things to fear rose exponentially. Animals don’t fear an eclipse, but humans managed to attribute countless negative interpretations to this natural phenomenon. With self-awareness comes both the need for rationality (a reason for something), and the trait that I think truly defines us most as human;

Curiosity.

When you are absolutely certain of something, you can effectively ignore it; I have absolutely faith the sun will rise tomorrow or why would I bother getting out of bed? I have absolute faith that my wife loves me or why would I be with her?

The difference between the above paragraph’s examples, and faith in religion (for example), is both tangibility and direct experience. The sun has come up every day I’ve been alive (except the few days I spent in Scotland), and I’ve been with my wife for 10 years. That’s proof enough for me. But what if I base my faith on a concept that has only been passed on by others? Or out of a book? What does that do to our thinking? In some cases clearly not much, but some of the worst horrors in history have been perpetuated based on interpretations of words written centuries before.

And what happens when such thoughts becomes mandatory? When not having the same thoughts becomes a valid reason to violate the rights of others. Again, this is not just religion, but science and even sports aren’t immune from unshakable faith. Scientists and fans alike have committed atrocious acts because in their mind the victims were so wrong that their very lives were forfeit.

It’s a combination of things that keeps this destructive force self-perpetuating; from bigoted parents teaching their kids to hate, to inflexible older generations unable or unwilling to adapt, to a general unwillingness to admit when you’re wrong. Hiding bigotry against sexual orientation behind the bible, racial bigotry behind past atrocities, and murder behind a God all have their roots in the natural byproduct of misplaced faith; ignorance.

I have no answer for this, all I can do is not be part of the problem. Life is not fair, life just is, and YOUR life is what you make of it. That fact remains that it is already difficult enough to find sufficient happiness to make the life you have worth living without making it difficult for yourselves by hating, and hurting everyone around you by your selfish actions.

Believe in whatever you want to believe, just leave the rest of us out if it.

[If you liked this article, please share! Want more like it, subscribe!]

In October of this year, any merchant in the US who does not demonstrate the ability to accept EMV transactions can be deemed liable for the fraud associated with counterfeit cards.

That’s only 5 months from now.

Most people in the EU can’t really understand the confusion this has generated – we’ve had chip & PIN for well over a decade – but for the population of the US, swipe & signature is as natural as handing over cash. Retailers are rightly concerned that adoption will be a slow and painful process, but that may not be their biggest concern.

Estimates of the cost of transition from magnetic stripe to chip range from 12 (mine) – 33 (the press) billion USD, and the lion’s share of this will fall to the retailers who must replace their existing payment entry devices (PEDs) with chip compatible ones. The chances are good that this expense was not in their long-term costings, and bringing forward the end-of-life of their PED infrastructure is simply not an option in an industry where profit margins are razor thin.

But the thing that few people realise is that while the chip alone is a positive factor in fraud reduction (anti-counterfeit), the greatest benefit of the roll-out of EMV is only achieved when in conjunction with the use of a 4 digit Personal Identification Number (PIN). This effectively adds a second factor of authentication (the card is something you have, your PIN is something you know) making card present transactions significantly more secure. PIN alone would have significant positive impact as well.

It follows therefore that while organisations scramble to comply with the letter of EMV, there already exists in almost everyone’s pocket the capability to provide not just a PIN, but multiple forms of authentication and value-add services that far exceed the benefits of the chip; the mobile phone.

Even the loss of the Primary Account Number (PAN), which is the largest cause of card related fraud, is meaningless if the thief can’t complete the transaction. Add to this the numerous benefits of instant coupons, loyalty programs and even ratings & reviews, and the retailer now has the capability to enhance the customer journey while meeting the intent of EMV.

Neither the card issuers or even the card schemes themselves are fixated on EMV itself, they are only truly interested in reducing fraud. Retailers share this goal, even if they do not entirely agree with the way to get there.

It is up to authentication vendors to provide alternatives, and get those alternatives tested, real-world proven, and on the table. This will not be authentication vendors alone, or mobile device manufacturers alone, and the result will not be a decision made by card schemes alone. This will be a collaboration between ALL players, and will only work if everyone comes away a winner.

Especially the consumer.

[If you liked this article, please share! Want more like it, subscribe!]

I had the honour of presenting at an ISC2 London Chapter meeting a little while ago, and my chosen subject was ‘Mobile: Changing the Face of Identity Management (IM)’. What I thought was going to be half an hour of me espousing my ideas (or ranting, depending on your point of view), turned into the most lively debate I have ever had in front of an audience.

Initially I wondered if my 10 slides was going to be enough (although I never actually read to the material), but I didn’t even make it past slide 7. By the time I was on slide 5 the questions started, then the dissenters chimed in, and by the time I reached slide 7 the presentation was forgotten. My 30 minute slot was over before I knew it, and it was clear a lot of people had a LOT more to say, which they did over beers afterwards.

The culmination of this discussion was when I heard the following; “I don’t agree with ANYTHING you are saying!”, which for a lot of people (especially ‘expert’ presenters) can be the cause of anger, considered a challenge, or can even cause outright panic. To me it should only ever be the cause of curiosity; WHY am I wrong? I certainly don’t think I am, and probably still won’t after I hear your explanation. I’m curious nonetheless.

But what I will do is hear what you have to say as objectively as I can, and respond as neutrally and I can. Usually without much success mind you, we are all very attached to our opinions, but I will at least try.

Presenters are supposed to be experts in their fields, otherwise why the Hell are they on stage, but that does not [necessarily] make them right, especially when the subject is focused on future-state concepts as opposed to subjects which are long established. I have no idea where Identity Management will be in 5 years, but I have a rough idea. Also, my ideas are also right for ME, but I am decidedly on one side of the privacy challenges that surround the field of identity and privacy like a miasma.

I guess in the end you must decide for yourself if you want to be a lecturer, where your subject is not really up for debate (like when I train groups in PCI for example) or a presenter, when your ideas must be open to not only comment, but potentially ridicule. I have to admit, it makes presenting is a lot more fun, and if I only have to produce 7 slides to get an audience engaged, then I have a lot less work to do! 🙂

The lessons I learned in that presentation will stand me in very good stead for the next one, and who knows, maybe I’ll even finish all 10 slides.

[If you liked this article, please share! Want more like it, subscribe!]