Imagine being able to turn the oven on 20 minutes before you get home so it’s ready to start cooking… or taking a quick remote peek into your fridge/cupboards/bread bin to see if you need anything at the supermarket … or re-programming your air conditioning / heating while you’re on Holiday.

All of the above is simple, and already possible, just go here for a bunch of others; http://postscapes.com/internet-of-things-examples/. Some are incredibly far reaching, not to mention awe inspiring.

Along with the exponential increase in convenience, efficiency, and entertainment, is an equal increase in the cost to your privacy, security, and in some cases, your actual well-being. For example, this site http://www.vitality.net/glowcaps.html is about reminding you to take medications. What happens if you start to rely on this with your critical meds and someone ‘hacks’ it?

This blog is in no way a criticism or a doomsday prediction of the trend. I love this stuff and cannot wait until every aspect of my life is a blink, gesture, or eventually a thought away. However, whereas previously our lack of knowledge in basic self-defence principles related to the Internet could have caused embarrassment or the loss of a few quid, the Internet of Things could, quite literally, put your life in danger.

If YOU let it.

As a previous article If You Want More Privacy, Stay Off the Internet stated, the conveniences you crave have a price, and the price is only going to go up the more you expect from it. The Internet is like gambling, only bet what you can afford to lose.

It’s not about the RIGHT to privacy, we all have that as a basic Human Right, it’s that you cannot EXPECT privacy given the inherent insecurity of the medium, the criminal element, and good old fashioned stupidity.

You are not owed security, or perfection, so the due diligence is entirely yours, as is the ongoing maintenance and security monitoring of your new functionality. The things you will be able to do will be unbelievably tempting, but keep these points in mind:

  1. Start Small – don’t sign up for every new thing when it becomes available, you will never be able to track them all, let alone secure them.
  2. Keep it Simple – automated notification of the need for milk is harmless, automating insulin doses is not.
  3. Rely on Nothing – especially when your physical well-being is concerned. Always, ALWAYS have a back-up if your primary mechanism fails.
  4. Minimise the Impact – expose only what you don’t mind losing. Insure everything, especially your finances.
  5. Take Responsibility – blame yourself if things go wrong, don’t waste your time pointing fingers at others. This was YOUR choice, live with it.

Like everything that’s coming in the future, innovation has benefits matched equally by the downside. ‘Government’ will do its best to protect us through laws and regulations, but they will fail to keep up with OUR demand for functionality. Security experts will do their best to protect us, but they too will fail to keep up with the competitive rush to fulfil OUR demand.

Enjoy it, just be careful.

Personally I’m going to be interested in what ‘butt-dialing’ will look like in the next decade. You’ll probably come home to find your vacuum cleaner ordering pizza and watching porn.

Internet of THings

I am very pleased to be able to post a guest blog from a very good friend of mine who is a non-security expert, but still very ‘computer savvy’ compared to most.

This is in response to my post; “If You Want More Privacy, Stay Off The Internet“.

If someone as ‘privacy aware’ as this still has these issues, you can image how bad things are for the majority.

Finally, thank you so much for this [friend who will remain anonymous] 🙂

As a parent of three (20, 19 and 17) who live and die on their smart phones and tablets, and play games on the TV using the internet via their X-box 360s and PS3’s I suppose, as a non technical person, I’ve probably given more thought to Personal Information Security than most.  Add into that mix the fact that I am married to a Military Man, that I, myself was a serving member of HM Forces and worked for the Government overseas, then I should be able to sit here and say, hand on heart, that I take all reasonable measures to protect my personal information and understand easily what failing to follow basic guidelines can lead to.  So imagine my displeasure when a few simple Google searches both reassured, and horrified me. 

 
First, I tried my name – this returned results of a Swedish glamour model and her twitter accounts, and there in 6th place my LinkedIn profile – that’s OK, I actually WANT that audience to find me.  I added my middle initial to the search and down near the bottom of my page is a www.192.com listing from an address lived in previously.  Should I worry about this? Perhaps, perhaps not, I mean after all it is information that is publicly available via the Electoral Roll and the Census, it lists my husband as a co-habitant at that address, but on this page, it is a generic listing that gives only the town location – to get further details and to see if I have any county court judgements against me, you have to sign up and register. Thanks but I’ll pass.
 
So that’s not so bad is it? 
 
OK – take my daughter, she is heavily into her computer technology, her gaming community and live bands and gigs.  She routinely uses twitter, Facebook, Google plus, YouTube and many other forms of social media, the list is endless.  Again a simple Google search with our town name tagged on the end of her name returns nothing of great surprise and she’s actually got a 192.com listing at our current location which shows us all as co-occupants in the house (me, my husband and her two sisters).  Again its generic info, but we are all there.  Also returned are her YouTube channel, her Facebook and twitter accounts etc.  
 
My eye is drawn half way down the search results, in the image table of the six photos that appear on the search result, three of them are of my daughter.  Hmm interesting,– so I follow the images link to see what else I can recognise as hers.  And there I am, with my husband, in London on a day out – how the heck did that get there?, the hyperlink says it’s a plus.google.com image.
 
I run a couple more searches based on old email prefix’s and avatar nick names that I used in the late 90s when I was actively involved in  MSN communities helping women world wide (and maybe no so security savvy as the internet was a brand new, shiny and unknown beast to me back then).  I thought that MSN had scrapped all the pages, they certainly told us they were doing so, but no, lo and behold, there are a few of my old rambling posts for all to see, and all the other alternatives sites that we used that we tried to use to substitute for MSN Communities, yup – I’ve found all my old user names and some hilarious posts from back in the day when I was trying to learn graphics in Photoshop and PaintShopPro.
 
This got me thinking, if little old me, with my very limited IT knowledge can find all this stuff out in 10 minutes from mucking about in Google, what can someone do if they find this limited information and actually see tenable links.  If they had a clever programme that linked me and my family, and then actually got a proper account at 192.com and worked out that as a family we have had three homes in the last 5 years – that’s very powerful information.  If that person then thought a little bit (and not much) deeper and interrogatedancestary.com looking for family ties, they would soon have my mothers maiden name…. well we all know how powerful that information is when put with addresses of the last 5 years.
 
This is not new news to the probable audience of this blog, but I bet my children haven’t thought about it in this way, despite me and my hubby imploring them to share nothing personal on the internet.  Indeed, I ‘thought’ I had deleted all those old accounts.  I was fairly certain there was harmless stuff out there on the web, but really who is interested in me? Is there anything more I could do?
 
Well I supposed I could rid myself of the technology around me, but would it make a difference? Of course it wouldn’t. I could become paranoid and withdraw from the social media arena, but I like it, and then if I do that the bad guys who would be unscrupulous and mean with my information have won – and I don’t like the little man being persecuted.  
 
My employer, the tax man, DVLC, my bank, none of these organisations are going to walk away from using IT in the day-to-day, and in my opinion, nor should I.  So I can be cautious, and not put things like the obvious out there for the bots to find, but I also have to put my trust in the system, and hope that my Government is arming itself and doing all the things the bad guys are doing, not to exploit my citizenship and be big brother, but to protect me.  I will continue to shield my personal info online using the means available to me, and trust that the clever buggers out there with the know how on the good side of the fence, will outsmart and learn new ways to stop those toe rags on the bad side of the fence in their tracks.
Anyone have any their own thoughts on this?

That may seem like an aggressive statement, but the only way you will ever get the privacy you want is if you don’t put anything out there. No mobile phone, no email, no Facebook, no Twitter, and no browsing. Nothing. Shop at brick-and-mortar, do your banking in person, and if you want to talk to someone, call from a land-line. Maybe you can write them a letter, if you can trust the Post Office.

As I have already said in a number of posts, if you want ANY of the convenience that your mobile phone or the Internet provides, you pay a price in loss of personal privacy. Did you really think it was free? Or worse, do you actually EXPECT it to be free? You want all the benefits and none of the downside?

We have an expectation that it’s the government’s responsibilities to protect its citizens, from either external aggressors, or internal threats. How do you expect them to do that if they don’t at least TRY to do the same things the bad guys do? It’s called testing. As far as I am concerned, they can take whatever data of mine they like, as long as they do nothing with it other than work out how to plug the holes.

And if you’re worried that the government might use your data against you, what exactly are you doing?

Should there be more oversight? More transparency? Probably, but do you WANT to let the bad guys know how we’re catching them?

Question: Whom would you rather find a cancerous tumor in your body, a doctor, or a coroner? The doctor will be every bit as invasive, but will do so to save your life. You trust them, right?

OK, so that’s a little dramatic, and the other side of the analogy is excessive, but I think it makes the point. I WANT the government to find the holes before the bad guys do, because the bad guys have no rules whatsoever. They will steal from you, ruin your life, or whatever takes their fancy, and then not give you another thought unless it’s to laugh about how you made things so easy for them.

Businesses hire ‘bad guys’ all the time to test their systems, they are called ethical hackers. Same mind-set as a bad guy with one twist; they are there to help fix the problem, not exploit it.

Was Prism so different? They have no choice BUT to sift through everyone else’s data to find the ones who are doing bad things. Can you think of a better way of doing it? Seriously, if you can, I’d love to hear it, it will have far-reaching impact on the way security professionals think / work and should be heard.

It’s fairly clear which side I’m on, and this really is a issue with only 2 sides; for, and against the monitoring our private information. What’s needed now is a guest post from someone who is on the other side of the fence, maybe even a lawyer, and that’s all I can tell you about them or they’ll beat me up.

Let the debate begin!!

[If you liked this article, please share! Want more like it, subscribe!]

Yes …mostly.

Not that the question is even relevant, like it or not, cyber insurance is already here and will only continue to grow.  The number of regulations that reserve the right to levy  fines – some potentially astronomical – is growing to the point that they will feature large on any list of business risks. Or at least they should.

The challenges bringing this to market are numerous, but mostly on the insurance company side.  Security is almost the definition of risk, it’s incredibly diverse, and forever changing and expanding.  And not important enough yet.

With car insurance for example, the more cars you have in the road, the slower everyone has to go, so you actually REDUCE the risk.  What once was a few very costly collisions, is becoming more fender-benders.  So, just up your no-claims bonus and even those claims will reduce.

The more computers and smart phones on the Internet, the more data you have everywhere, and the risks grow almost exponentially.

How do you insure that?  If you don’t know security well, how do you write the policies?  How do you perform appropriate due diligence on a concept that’s new to everyone?  How do you perform PROPER due diligence in the face of stiff competition?

There are policies out there already, but these have been driven by specific regulations (PCI, or HIPAA for example), are aimed mostly at the smaller organisations, and are very much off-the-shelf affairs with limited – in some cases VERY limited – due diligence.  In fact, the pressure is on to make it as simple as possible or you’ll lose the deal; if your insurance company has a 12 page questionnaire, and your competition has only 1 (assuming price and T&Cs are the same), where will the buyers go?

Of course, the competition may end up regretting their stupidity later, but new insurance types are a very rare occurrence, and no-one wants to lose out on a revenue stream.

But what happens when VERY large organisations wish to insure themselves against the potential fines of the General Data Protection Regulation (GDPR), where 2% of global revenue is at stake?  When multi-millions are on the line, a one page questionnaire that asks nothing about security will not suffice.  What does that due diligence look like?

I believe it will run the gamut from some limited external vulnerability scanning in the case of smaller e-commerce, to an onsite audit in the case of a Fortune/FTSE 500.  The better your security, the cheaper your policy.  This may save pennies for smaller organisations, but would be of real significance to the larger ones.

However, I have always compared selling security to selling insurance; no-one wants to spend the money where there’s no positive ROI i.e. MAKING money.  But the ‘negative’ ROI can be just as important, where not LOSING money on fines, forensics, reputational damage, client loss etc can be every bit as meaningful.

Now combine selling insurance FOR security, and you’ve lost almost before you start.  That is of course until the costs of loss far outweigh the costs to insure.

Poor security drives the need for regulation, the regulatory fines will drive the cyber insurance market, which in turn will drive the security market.  Eventually I would hope that organisation understand that they have brought this on themselves by not taking security and privacy seriously. Until they do, the burden of regulatory audit and the associated cost of mitigation will continue to rise in the face of public demand.

Regulation and cyber insurance are just symptoms of poor security, and as I have stressed many times, this is a cultural issue stemming from the senior managements lack of involvement and/or caring;

Let’s be very clear; The CEO sets the tone for the entire company: its vision, its values, its direction, and its priorities.  If the organisation fails to achieve [goal], its the CEOs fault, and no-one else’s.

Replace “goal” with “low security overhead”  and the rest is the same.

Sensing a theme here?

The CEO can single-handedly reduce the costs of security, I wonder why so few are paying attention…

Humans as an entire species are never going to agree 100% on anything, ever.  I don’t care if it’s religion, politics, privacy, or margarine over butter.  There will ALWAYS be people on either side of every fence.  Try to imagine the worst thing in the world, and there will be someone out there doing it, or cheering on those who do.

At best, we can come to a majority agreement, but that will only ever be regionalised by either geographic location, or racial beliefs and bias.

So why has Prism caused such a stir?  Are you actually surprised this was going on? There are those who want access to data, and those who want to protect it.  There are those who want to use the data for the common good, and those who want to use it for their own profit, or worse.  And “Some men just want to watch the world burn.”

I’m not overly interested in your opinion, just as you’re not overly interested in mine.  I’m OK with that.  The only time we have an interest in this stuff is either when people totally agree with us, or – in our arrogance – we feel like trying to change the opinions of others.  Like we’re the ones who are right.

In the end, the bad guys (in whatever form ‘bad’ is for you) only have access to what we gave them.  An exception to that rule is when an organisation loses stuff they should be protecting.  Like in a breach for example.  Preventing this from happening is what I, and many others, have devoted our careers to, but the most we can ever achieve is a slight reduction in the risk to your privacy, and possibly some form of compensation for you if your privacy is lost.

Yes they should protect data, and should be liable for not doing so, but if a thief wants it, it’s gone.

While you have every right to expect privacy, and I agree with the laws and regulations supporting that privacy, you cannot EXPECT privacy given the bad elements.  Analogy; the law protects me against being mugged, but I don’t put myself in places or situations where mugging is more likely.  I may be the victim, and have all the rights of the victim, but I’m still missing my wallet.

This will not apply to the Prism case, where there will be no class action suit against the government, and whatever smoke and mirrors they come up with to reassure you that it will never happen again, it’s just that, smoke and mirrors.

The key to your personal privacy has always, and will always, rest with you.  You are responsible for your data, and whinging about governmental abuse of power is not going to change the fact that you posted stuff on FB, you took inappropriate pictures, and YOU chose to share your bank account details to an online provider of services etc.

Do I think the NSA was right in what they did, or if that moron Edward Snowden was right in what HE did?  That’s irrelevant, because I have nothing online in any form that would embarrass me if it were revealed, or unprotected (by deferred lability) if it was stolen.

Can you say the same?

[If you liked this article, please share! Want more like it, subscribe!]