For those of you who are unfamiliar with the concept of ‘Disruptive Innovation’ (like me until 5 days ago), it is defined as;

a process by which a product or service takes root initially in simple applications at the bottom of a market and then relentlessly moves up market, eventually displacing established competitors.” (http://www.claytonchristensen.com)

For decades, the card schemes (Visa, Mastercard, Amex, Discover etc.) have ruled the non-cash payments space, despite the fact that the technology behind the credit card; the card number, is now over 60 years old. There have been few alternatives proposed because:

  1. There were none that did not rely on some other form of number or separate device to authenticate. For example, bio-metrics has never been 100% free of false positives or false negatives, and therefore is not accurate enough for the payments space. Yet.
  2. Credit cards worked, the infrastructure is pretty much global, and they are still expanding.
  3. The card brands themselves are very aggressive in protecting their empires.

Even the PCI Standards (PCI DSS, PA-DSS, and PTS) can be seen as innovation stiflers, because it’s so difficult to achieve compliance that most organisations have little time or money left to experiment. Also, no-one wants to be the first to stray from the established norm as there’s simply too much to lose, and recovery is increasingly difficult given the globalisation of competition in almost every industry sector.

But, with the massive amount of innovation that AVOIDING PCI has spurned, the number of non-card-brand options has increased to the point where only the most naive of organisations are not looking around for alternative payment methods. Why use a credit card when consumers can obtain lines of credit directly from their banks and access this from their mobile device faster, more securely, and without the outrageous fees the card brands have charged all these years?

The Internet is more distributed and available than the card brands can ever be, and mobile devices already outnumber card payment terminals by orders of magnitude. There will soon be more smartphones than PEOPLE in the world, so the demand for efficiency and functionality will only increase.

And what of chip and PIN (a.k.a. EMV)? Why would anyone bother buying the expensive payment terminal (PED) models currently provided by the Ingenico’s, Verifone’s, and Micros’s of the world, when a simple software ‘fix’ on ANY terminal will provide the same functionality? Functionality that is portable to every form of transaction, from card present, to eComm, to mobile (e.g. myPinPad).

OK, so the last paragraph assumes you’re still using a credit cards, but it just goes to show the knock-on effect that the demise of credit cards will engender. PED manufactures will move into something else that requires hardware, encryption and centralised management (B.Y.O.D perhaps?), most QSA companies will fail (or start doing security properly for a change), and the banks will be held fully accountable for the security of their customer’s payment transactions.

So PCI, which started out as an attempt to keep the US Fed off the card brand’s backs, has, through its complexity, expense, and inflexibility, driven the type of innovation from which there is no turning back. The card brands will either spend all of their money buying companies that provide credit card alternatives in order to future-proof themselves (like Visa buying a stake in Square for example), or they will fail.

I’d say they have 5 – 10 more good years, you simply can’t replace something as ubiquitous as the credit card until the new payment methods have worked out all the kinks. That said, it’s the Internet again that will provide the platform, and software applications that will provide the function, so global distribution is as simple as going online.

I can’t wait to see what’s next.

Imagine being able to turn the oven on 20 minutes before you get home so it’s ready to start cooking… or taking a quick remote peek into your fridge/cupboards/bread bin to see if you need anything at the supermarket … or re-programming your air conditioning / heating while you’re on Holiday.

All of the above is simple, and already possible, just go here for a bunch of others; http://postscapes.com/internet-of-things-examples/. Some are incredibly far reaching, not to mention awe inspiring.

Along with the exponential increase in convenience, efficiency, and entertainment, is an equal increase in the cost to your privacy, security, and in some cases, your actual well-being. For example, this site http://www.vitality.net/glowcaps.html is about reminding you to take medications. What happens if you start to rely on this with your critical meds and someone ‘hacks’ it?

This blog is in no way a criticism or a doomsday prediction of the trend. I love this stuff and cannot wait until every aspect of my life is a blink, gesture, or eventually a thought away. However, whereas previously our lack of knowledge in basic self-defence principles related to the Internet could have caused embarrassment or the loss of a few quid, the Internet of Things could, quite literally, put your life in danger.

If YOU let it.

As a previous article If You Want More Privacy, Stay Off the Internet stated, the conveniences you crave have a price, and the price is only going to go up the more you expect from it. The Internet is like gambling, only bet what you can afford to lose.

It’s not about the RIGHT to privacy, we all have that as a basic Human Right, it’s that you cannot EXPECT privacy given the inherent insecurity of the medium, the criminal element, and good old fashioned stupidity.

You are not owed security, or perfection, so the due diligence is entirely yours, as is the ongoing maintenance and security monitoring of your new functionality. The things you will be able to do will be unbelievably tempting, but keep these points in mind:

  1. Start Small – don’t sign up for every new thing when it becomes available, you will never be able to track them all, let alone secure them.
  2. Keep it Simple – automated notification of the need for milk is harmless, automating insulin doses is not.
  3. Rely on Nothing – especially when your physical well-being is concerned. Always, ALWAYS have a back-up if your primary mechanism fails.
  4. Minimise the Impact – expose only what you don’t mind losing. Insure everything, especially your finances.
  5. Take Responsibility – blame yourself if things go wrong, don’t waste your time pointing fingers at others. This was YOUR choice, live with it.

Like everything that’s coming in the future, innovation has benefits matched equally by the downside. ‘Government’ will do its best to protect us through laws and regulations, but they will fail to keep up with OUR demand for functionality. Security experts will do their best to protect us, but they too will fail to keep up with the competitive rush to fulfil OUR demand.

Enjoy it, just be careful.

Personally I’m going to be interested in what ‘butt-dialing’ will look like in the next decade. You’ll probably come home to find your vacuum cleaner ordering pizza and watching porn.

Internet of THings

Let’s just start with the basics, money;

There are ~1.5 BILLION credit cards in the US, and a replacement card is between $3 – $5. So you’re looking at an expense between $4.5 and $7.5 billion for that alone.Now add into that the cost of replacing ~10 million payment terminals to ACCEPT the new cards, at a cost of ~$50 – $100 each (at the VERY minimum), and that price-tag goes up by another $0.5 – $1 billion. Finally, every bank must replace / upgrade their back-end systems to PROCESS these new transactions, and I’m not even going to try to guess the cost (it’s a lot).

Yes this will be spread out of a number of years, but that’s like saying you’d like to get punched in the mouth a little bit at a time. No alternative is pleasant.

Cost aside, why would the banks make this expense when the main driving factor behind EMV is being negated on a daily basis by innovations in payment technology? Innovations such as mobile payment applications, and far more secure alternatives to the Chip & PIN itself, will drive the US to abandon their plans for EMV in favour of solutions that have a far longer shelf-life, are more secure, include Card-Not-Present (CNP) transactions (e.g. e-commerce), AND are not just a patch/fix to a 60+ year old technology.

The EMV concept itself was first put into real-world practice in France in 1992 – yes, 21 YEARS ago – and is now the de facto standard in over 100 countries globally. Except the US of course, who still rely on the magnetic strip first introduced by IBM in the 1960s.

This mag stripe method is the major cause of card-present (CP) fraud globally, which is why the US has been under increasing pressure to make the change. The issuing banks in the US, however, are very powerful in their own right, and have managed to delay things long enough to now have a valid reason to stop the plans altogether.

Good for them.

The need for PIN authentication will not go away any time soon, but the need for any payment terminal or payment application to ever SEE that number will. This is an enormous game-changer for both the banks, and the end users.

Chip & PIN transactions are cheaper than magnetic strip transactions for one reason; less fraud. However, you can’t use chip & PIN for e-commerce, where things like the CVV code, Verified by Visa, or 3-D Secure are used to similar, though limited, effect.

This restricts their usage to specific card brands, but this brave new world of innovation where the card brands are no longer the only game in town, a more ubiquitous PIN method is required that’s not only secure, but seamless, portable to legacy technologies, and affordable. Something like this; www.mypinpad.co.uk.

Suddenly:

  1. Expensive card-not-present transactions become cheaper card-present transactions saving millions for e-commerce;
  2. Legacy payment terminals that are not yet End of Life (EoL) can be kept, saving brick & mortar merchants millions;
  3. ATM payments become far less prone to fraud (under certain circumstances);
  4. Mobile payments become far more secure; and
  5. Liability shift is now firmly with the issuing banks

All of this is great stuff, and makes me wonder what’s next!

[If you liked this article, please share! Want more like it, subscribe!]

19-Dec-19: Clearly I was way off the mark here, but I still think it was a mistake!

For those expecting a Terminator-esque diatribe warning you about the evils of ‘machine’ autonomy you’re in the wrong place. For a security professional, I am perhaps the least suspicious and prone-to-conspiracy person I know. Even my Sister and Brother-in-law are worse, but they are a lawyer and Scottish respectively so their paranoia is expected.

After reading Daniel Burrus’s articles ‘Big Data Is Already Producing Big Results‘ and ‘Create an Integrated Big Data Strategy To Increase Sales Now‘ it occurred to me that while Big Data has no place in security beyond forensics (in my opinion), the security OF the big data itself is critical. So is the integrity and availability of it.

The concept of Confidentiality, Integrity and Availability (CIA) has been around almost as long as I have, but only with the advent of big data and real-time analytics does it truly come into its own.

Everyone trying to sell you something – which is everyone – is looking at big data, or more specifically, how to collect the data in first place, and what to DO with it once they’ve got it.

Scenario: You’re out shopping with your wife when suddenly you are barraged by lingerie offers, as your spending habits over the last few months have been recorded and instantly regurgitated by hopeful vendors. Your wife has no lingerie…

Morality aside, this is a gross invasion of his privacy (loss of confidentiality). Now image if that data was actually inaccurate (loss of integrity), I’m sure his wife would be very understanding, right? As for availability, that’s the vendor’s problem so I don’t care much.

Now, let’s take this even further. In ‘The Internet of Things‘, soon everything from your home security to your dog will be online. Your location, your travel plans, your favourite everything will be known by someone, or someTHING, somewhere. The amount of information being collected is growing, quite literally, exponentially. The trend is also to automate as much as possible, so for example, if no-one’s home, the oven should not be on. Do we really want ALL of these decisions made without human interaction?

I personally love the way things are going. Instant access, always-on, functionality, convenience etc. But I am prepared to pay the price for this, the currency of which is measured in terms of the loss of both my privacy, and potentially, my personal safety. The data is online, if someone really wants it, they can get it, then do things with it I don’t even want to contemplate.

Big Data is not evil, data just is, it’s the use to which the data is put that defines good or bad. Businesses have been very quick off the block to define the profit-making contexts within real-time data analysis, but so far I haven’t seen much in the way determining what’s right and wrong. Or whether or not we even have a choice to take part in it.

The generations born prior to 1990 are most likely the ones holding this trend back, so we’re the one’s who’d better write the policies, and put the checks and balances in place, because the Millennials are too busy posting pictures of their junk.

This is not going to be about the legalities, policy, or privacy issues surrounding BYOD, that has been covered many times over in articles like this one; “Why almost everyone gets it wrong about BYOD” by Brian Katz.  I would hope that you are fully aware that regular information security policies do not cover the use of personal devices, and have established appropriate policies accordingly.

What I will be focusing on is a) the risks based approach, b) some musings on current ‘solutions’, and c) my thoughts on a possible technology solution.

A lot of these so-called BYOD solutions focus on the communication channels, secure browsing, malware protection, and/or Mobile Device Management.  All of them miss the major point, which is the risk to data at rest.  Do you really expect your employees to VPN into some kind of proxy just to browse the Internet?  Or how do you expect people to sign up to having their phone entirely erased if they loose it?

The issue is that not one mobile application, I repeat, not ONE, works at an Operating System (OS) layer that prevents jailbreaking.  Any encryption of either  the data channels or the data itself is performed by software running on top of the underlying OS.  Jailbreaks work AT the OS layer, meaning that any functionality of the application is immediately at risk, including any encryption keys.

Charles Henderson says it better than me; “Is Your Mobile App Safe?

So BYOD is not about keeping your data from being stolen, you can’t, it’s about agreeing on what you are prepared to loose, and what to do if (when) that happens. So instead of throwing ineffective technologies at the problem, you have go back to basics and look at Role Based Access Control, data classification, retention policies and so on.  You should even question whether or not the cost savings and assumed productivity enhancements associated with it are really worth the effort.

In other words, if you do decide to proceed, assume that whatever your employees are downloading on their phones and tablets is now available to everyone, and implement your BYOD solution accordingly.

I would argue that you are probably better off educating your employees to never put confidential information in emails than you are trying to control how they use / abuse their personal phones.

I believe that there is currently only one way to perform BYOD securely; in a hardware module.  If you accept that you cannot perform authentication / encryption safely at the application layer, and that you will likely never have access to the underlying OS (iOS for example), then you are left with hardware.

The hardware module would perform several functions;

1. Authentication – Once the module is plugged into the mobile device, it establishes a secure channel back to home base to perform whatever form of authentication you choose (LDAP, username/password, certificate, even biometrics).  All encryption keys are kept on the hardware device.

2. Encryption – Seeing as the keys are on the hardware device (some form of mini-HSM perhaps), you can leave the encrypted data on the mobile device when not used for work related applications.

3. Storage – The hardware module could also be used to store all work related data, and the mobile device provides nothing more than  a communications channel.

The form factor for the hardware module could be something that is already very common, the phone case / battery charger.  Like this for example;
Screen Shot 2013-07-08 at 16.43.01

Or it could be something like this that has many connection types;

Screen Shot 2013-07-08 at 16.46.01

There are many things to work through, and perhaps the most significant is that this module would literally have to jailbreak / hijack the mobile device before it could have the kind of control needed to enforce the BYOD policies.  Easy enough on Android/Windows, but I’m fairly sure Apple would have issues, they have already totally screwed the ancillary device market with their lightning adapter. I know Apple are also working on an secure embedded SIM technology, but I really don’t see how it can perform he above functions in something so small, and they haven’t even seen fit to add Near Field Communications (NFC) chips to their iPhones.

Thinking ahead, this may not be a viable solution for all businesses, you still have to purchase hardware, and the centralised management station would have to perform everything an MDM does, but for the hardware modules, not the mobile device.  However, for government, government contractors, military and so on, perhaps the encryption aspect alone would be of interest?

Who is currently best placed to corner this particular market?  I think POS / terminal manufacturers like Verifone, Ingenico, or Micros would be contenders.  They already have manufacturing capability, HSM technology, small-form storage modules, OS and mobile communications expertise etc.

All they would really need is deep expertise in the specific mobile technologies covering the majority of the smartphone / tablet market; Apple, Android, Samsung, maybe even BlackBerry.  I’m guessing those skill-sets are not too hard to find.

Clearly there is a lot more to it that I have mentioned here, I do want to keep something back for collaboration opportunities 🙂

What are your thoughts?  What have I missed?  Is this viable?