If you are reading this while on public transportation, at a bus stop / train station, look up, and look around. How many people are looking at a mobile device of some kind? 40%? 50%?

Now, how many of those are children? Or if you’re a parent, does your child have a smartphone? A PS3/Xbox? And finally, how much time do you think these kids are spending on those devices?

It’s bad enough that I, a 46 year old ‘technology professional’ spend an inordinate amount of time plugged-in and not exercising, it’s quite another to see a 10 year old who’s overweight and completely disconnected from the world around them.

So, whether you are proponent of the Internet of Things or not, I see it as a perfect opportunity to ensure that children see technology as the privilege it is, and not as an expectation, and certainly not as something to be taken for granted. No child has earned the right to waste away in front of an electronic device, they can do that later if the wish, and once they are out on their own paying their own bills. Like me.

The proposition: With innovations around micro-sensors, geo-location and a whole host of other inputs, it should be relatively trivial to measure the amount of exercise your child is getting on a daily basis, and tie that directly into the amount of ‘play time’ they get on their smartphones or video games. The more exercise they do, the more time they have, and when your time is up, the video games are locked out, and your smartphone reverts to phone only.

You could even build in an ‘management station’ where parents could set tasks, chores, grade requirements etc, and the more the child does, or the better they perform, it all works its way into more time playtime on their electronics. Of course, this will all need to be fun as well, there’s no point in teaching the next generation that exercise is itself a boring chore, but every child has to learn that everything has a price, even if that ‘price’ is something that’s actually good for them.

It would however, be very important not punish a child that finds a way to beat the system. Any creative method they have to ‘cheat’ is an indication of a burgeoning talent. For example, a child who..:

  • …gets their friends to wear their sensors to exercise on their behalf shows someone with creativity, influence, and leadership skills.
  • …works out how to ‘double up’ on their sensor input shows skills in problem solving, efficiency generation and engineering.
  • …hacks the system and re-wires either the input mechanism or the underlying application is going to start the next Google.

While you clearly can’t allow their breaking of the rules to continue, gearing their e-playtime bonuses to rewards for solving similar challenges is a way to make the whole thing not only fun, but a learning lesson as well.

Children are extraordinarily creative when not suppressed by adults, so why not let them have at it while at the same time ensuring that they stay healthy?

Obviously this technology would have just as many benefits to adult health as well, and I have literally dozens other ideas for its application, but I’ll leave that to people with a little more time on their hands. I think a company name of e-PlayTime would work very well…

Over the last 6 months since leaving a 12+ year career at one company, my thoughts come consistently back to one concept; innovation. Making positive change in terms of process and efficiency has always been a passion of mine. Nothing is perfect, and anyone using the phrase; “We’ve always done it that way!” should be fired immediately for gross misconduct.

In much the same way that to someone with a hammer every problem looks like a nail, my natural inclination as a security ‘expert’ is to assign the lion’s share of importance to my area of expertise. While I most likely go too far in this, I think that I have at least some justification for my assertions, if only in the context of this blog.

Innovation is defined as; The act of introducing something new. This is therefore one of the most critical concepts for the human race since it first achieved sentience (couldn’t use the word ‘intelligence’, I think that’s still pending). Whether you believe that was millions of years ago, 6,000-ish year ago, or it was a present from aliens, the speed with which we evolved from hunter-gatherers into what we are now is astonishing (couldn’t use the word ‘civilised’ either, and for the same reason). In just the last 100 years or so we’ve gone from the first flight to the moon, and from computers the size of a room, to mobile devices with more computing power and capacity per unit than existed on the planet just 60 years ago.

All of this was done with one thing as the foundation; information. Yes, that information must be correctly applied to become knowledge – and hopefully in time, wisdom – but everything that has ever been invented, and WILL ever be invented, has information at it’s core. Invention starts with a need, and it does not matter what that need is, someone will feel the urge to fill it. Only a few people create things of no use (we’ll leave Apple and Modern Art out of this), they do it to make money, make a difference, or better the human condition.

The need, in and of itself, is a sort of information; how to take an idea and make something out of it is information; how to build / market / sell / distribute / improve the idea is information; and yes, how to USE the results of the idea is also information.

So why isn’t information better protected?

Why isn’t information seen at the definitive crown jewels in EVERY organisation, especially now that almost every aspect of business is digital, and online? Why don’t CEOs include those in CHARGE of protecting information in the process of business transformation and innovation?

Can’t answer those questions, I’m not smart enough, but seeing as I’m a security expert the why is irrelevant, it’s my job to ‘just get it done’. But that’s the challenge, unless the people ultimately responsible for innovation within a business understand and care about this concept, no-one else is going to care (yes, I’m blaming the CEO …again).

There is an ages old concept in information security; that of Confidentiality, Integrity, and Availability. Some say it’s obsolete and needs refreshing, others try to change the names or add a 4th so that they can be seen to be radical thinkers, but the concept is every bit as valid as it’s ever been:

Confidentiality: If everyone has the information you have, you’re probably not innovating, you’re doing what everyone else is doing. Maybe you’re doing it slightly better than everyone else, but you aren’t going to stay in the lead for long.

Integrity: Not much point innovating if you’re doing it for the wrong reasons, in the wrong place, at the wrong time, or badly. If your information is not accurate and relevant it’s just data.

Availability: You can have all the information in the world, but if you can’t get to it WHEN you need to get to it, it as much use as a politician.

The whole point of IT Security is to take care of confidentiality and integrity, IT Operations takes care of the availability, but it’s the combination of IT Operations,  IT Security and the BUSINESS side to put information into context for ongoing innovation.  That’s what the Governance committee is supposed to be doing; take a business need, help gather the necessary information to devise a solution, measure the business risk, and either move forward with the solution, or move on to the next.

Big data, data mining, predictive analytics and even the much mis-understood ratings and reviews fields would not be experiencing exponential growth if information was not seen as crucial to maintaining competitive advantage. That’s probably why it’s almost incomprehensible to me that organisations don’t take information security more seriously.

Almost.

Apparently an announcement was made at the PCI SSC ‘s Community Meeting in Nice that “European Payment Services (EPS), [is] the first company to have a solution listed…“, this according to Tenable’s Jeffrey Man in his new article ‘What’s Wrong with P2PE‘.

I’m not going to go into why P2PE is dead from a PCI perspective, Jeff covered that better than I can, instead I’ll cover it from an innovation and real-world perspective that the SSC simply cannot / will not include in their presentations.

Why P2PE is pointless, and dead before it reached the gate:

  1. If you have read the P2PE assessment procedures (which were about 2 years too late in being released), you’ll know that they make the PCI DSS look like a nursery rhyme. EXTREMELY complicated, and ENORMOUSLY expensive to achieve certification. I was, however, very surprised that PED / payment terminal companies with significant resources (like VeriFone and Ingenico) didn’t get into a race to corner the market early, but now it makes sense;
    o
  2. P2PE done the SSC’s way still requires PTS and SRED compliant payment terminals, which are massively expensive, and whose days are numbered. Mobile payments, and whatever comes next will, thankfully, kill retail’s reliance on payment terminals and bring secure, non-cash, payment capability to every merchant world-wide, no matter how small, or large and distributed;
    o
  3. Chip & PIN (EMV) technology is tied to the terminals and to the use of credit cards, which along with payment terminals, are dying technologies. Credit cards are 60+ years old, and EMV was a very poor patch to fill a gaping hole in credit card security, so innovation will, and in some cases already has, replaced the need for both;
    o
  4. Retailers are simply not going to make the massive investment in replacing their payment terminal estates before they end of life (EoL) just because of a possible reduction in PCI scope. And why would they then spend a fortune in expensive devices, tie themselves into a single service provider, as well as limit themselves to credit card transactions? Answer; they wouldn’t, not unless they’re irretrievable stupid;
    o
  5. The entire payment space is finally recognising the fact that it’s bloated, inefficient, enormously outdated, and complex. Innovation will simplify it back to its basics, which it that it’s not ABOUT payments, it’s about authentication. I don’t care how I access my funds, whether they be debit or credit (both of which are provided by the bank anyway), I just want to do it whenever I want, wherever I want, and without risk.

Any protection the card brands provide related to fraud and consumer protection can be provided cheaper and probably better by the banks, and this, along with the demand for better customer service, will drive the banks to compete for our business as never before. Gone will be the days that they can act as though they are doing US a favour.

As for the SSC’s announcement, I can’t blame them for wanting to announce any kind of success, God knows the DSS v3.0 is nothing to write home about.

[If you liked this article, please share! Want more like it, subscribe!]

[blank] as a Service. There are so many XaaS services available now that we are running out of letters:

  • AaaS – Authentication as a Service
  • BaaS – Back-End as a Service
  • CaaS – Communication as a Service`
  • DaaS – Desktop or Data as a Service
  • EaaS – Encryption as a Service
  • FaaS – Failure as a Service [I know, couldn’t believe this one myself]
  • …and so on.

As much as I have an issue with buzz-words and inventing acronyms, I cannot deny the trend that; Unless it’s a core function, don’t do it yourself.

Retailers should outsource payment acceptance, insurance companies should outsource cyber due diligence, and every business should outsource some of its security risk management.

Sure you can change the oil in your own car, you may even be able to perform some basic plumbing, but why would you? There’s an excellent chance that a professional can do it better, and in the long-run cheaper, than you. What’s more important; saving money, or saving your time? I guess the answer is different for everyone, but a business does not have the luxury of experimentation to the degree we do. False economy, while relatively trivial for us, can be make or break to a business.

I see a time where the economies of scale, combined with the abundance of competition will enable service providers to give far better service at a much lower price-tag that you could possibly hope to achieve in-house. Doing one thing and doing it well should automatically provide the necessary scalability of service, appropriate innovation and business transformation capability necessary to run a competitive venture in the 2010s and beyond.

Even in the cybersecurity industry, there is significant confusion on how to choose the right vendor or technology, and this will only increase exponentially in the era of The Outsourcing of Everything. Inevitably there will come along a new type of service provider; the Service Provider Integrator. In the same way you cannot manage your security if you have 15 different management stations, you cannot run your business if your service providers are not performing seamlessly, and in full support of your business goals.

In the Information Age, where entire businesses can be run in the virtual world, a competitive edge lasts weeks, not years, and only the organisations who can effective balance risk and innovation, and then transform their business processes in support of that innovation, will succeed. And with everything outsourced, only the companies who are best able to chose, then integrate the most effective and flexible services, can hope to compete. The best Service Provider Integrators will be able to create entire white-labeled businesses from any concept.

In one of my earlier blogs; How Information Security Enables Transformational Change, I made the statement; “Information in context is knowledge, success however is in the correct application of that knowledge.”. The drive towards specialisation will accelerate in every service to be provided. It will be the organisations that are best able to correlate both the management information gathered over years of providing a specific services to multiple organisations, along with the ability to apply those skills to prospective clients, who will run away with the business. This will eventually create new Googles and Amazons, but they are where they are for a reason;

Good service.

[If you liked this article, please share! Want more like it, subscribe!]

========================

Update 22-Oct-13 09:23: Don’t normally add bad language to my posts, but this is too funny not to; www.foaas.com. My thanks to Steve R!

Everyone has heard of Wi-Fi (Wireless Fidelity), but fewer I suspect have heard of Li-Fi (Light Fidelity), a new(ish) standard for the transmission of data over a light source. ANY light source …almost.

The theory is that Wi-Fi is both congested and bandwidth limited, so in areas where you have high concentrations of people (airports, train stations, hospitals etc.), the use of the existing light sources could be a way to supplement the Wi-Fi. You can also expect much higher bandwidth rates, as light has 100,000 times the frequency of radio waves, which is Wi-Fi’s major limiting factor (even for Wi-Max).

Li-Fi has its limitations too; it only works indoors, you must stay in the room(s) it’s available or make it available in EVERY room/corridor/stairwell; and naturally, you need line of sight.  These limitation are why it will only ever supplement Wi-Fi, not replace it altogether, but the combination of the two should alleviate most of the limitations of both.

However, these are the major drawbacks, the first of which is VERY significant:

  1. Every mobile device in the world will need a special light sensor and emitter in order to take advantage of it. It’s early days yet, and the existing sensors are hardly what you’d call mobile-friendly, so these would need to be reduced so that they are no more bulky, and obtrusive, than your existing camera sensor
  2. It extends the access of data transmission capability dramatically, and as light wave are more secure than radio waves, it becomes much harder to detect in areas where there should not BE any bandwidth other than that provided. Even the PCI DSS has a requirement to perform rogue wireless access point detection, but that’s easy, Li-Fi is going to prove much more difficult to detect (I assume)
  3. If ANY lightbulb can be turned into a data transfer device, there are going to be significant privacy issues, and every conspiracy theorist will be now be working in the dark, or using a gas-lamp. OK, so this is only a drawback if you’re one of the paranoid minority, for the rest of us it’s funny.
  4. The incidents on ‘bandwidth-rage’ will increase; “Oy, sit the f%$# down, you’re blocking my upload!”

Anyone who’s read my blog before knows where I stand on this; as a lover of innovation and convenience, I can’t wait for the technology to be introduced in the mainstream, but as a security practitioner I will want to see security built in from the ground floor, and not retro-fitted like it usually is.

Innovation and technology around providing always-available bandwidth is approaching national infrastructure levels of importance, right up there with water and electricity, so while I can’t wait to turn my bedside table into a super fast modem, I’ll be doing so only when I’m sure what happens there, stays there.