Wednesday, May 12, 2010

Some quotes from my first 200 posts

My 200th post was sent the No Tricks blog yesterday, and to celebrate here are 30 or so quotes I quickly selected out of those posts.

The No Tricks Blog Name
The American basically asked "Why are you guys doing so much better than us?". The Japanese businessman is shown extending his fingers and counting off as he says "Your managers are greedy, your workers are lazy, and ...". But before he can finish even just the most obvious reasons, the American interrupts impatiently and says "I know, I know! But what's the trick?"
Excel is your new best friend
We can also stop beating ourselves up on the point that the weakness of IT Risk is the absence of data - the real weakness is poor modelling, and the decisions based on the output of such models.
Mr. Egerstad has stated that there is no security flaw with Tor - the real threat comes from user expectations that their message contents are being protected end-to-end by Tor, when in fact encryption is only applied to internal Tor network communication.
Flaws related to encryption always make good copy, and on occasion, strike at the heart of our fundamental beliefs in security. When encryption falters the whole edifice of security seems shaken.
This may seem an odd question given that since the mid 70's discussions about cryptographic keys have been mainly concerned about their potential shortness.
The Princeton team asked Nature the simple question of whether DRAM is cleared on power loss, and the simple answer is no.
A5/1 has operated unchanged for the last 21 years but it has now reached its cryptographic end-of-life, engulfed by the march of Moore's Law.
Intel's leading chip line, the x86, has steadily progressed from 286, 386, 486, Pentium and so on, but quantum computers will not be "1000-86" devices - unimaginably faster versions of what we have today.
Kapersky has decided to make AV scanning more efficient not by making it faster but by doing less, as determined by risk-based criteria.
It is common that once the torch of enterprise risk management is kindled in the higher corporate echelons, it is passed down the ranks and settles with IT Security people to assume responsibility for the management of IT Risk. And these people are ill-equipped to do so.
Perhaps this reasoning prevailed at Adobe when they recently upgraded their document encryption scheme from AES-128 in v8 to AES-256 in v9. However Adobe later had to announce that v9 in fact offers less security against brute force attacks as compared to v8. What went wrong? They forgot about the spin.
Risk management is about making decisions today that will protect us from the uncertainty of the future. We are not looking for one in a million (the expert) but rather a million and one (the power of many).
We feel more informed, more empowered, and more enamoured with the promise of the omnipotent web. The web 2.0 narrative has worked its magic and we tacitly commit into a seemingly virtuous circle of information inflation.
Navigation and search are just for people who don't have any friends.
Disconnect from Twitter when you are receiving more than one tweet per second.
The AV blacklisting industry has reached a point of diminishing returns - the marginal value of producing additional signatures is minimal, but the underlying model can offer no more advice than to simply keep doing exactly that.
It could be said that PageRank is one part brilliance and two parts daring.
Often business has the “snappy intuitively appealing arguments without obvious problems” - plus Excel … Snappy and plausible usually wins out over lengthy, detailed and correct.
The observation here is that the security function is no longer called upon to critically underwrite the security risks of a project, with the option to reject.
Compound this disconnect between management and technical people over hundreds of thousands of projects at the corporate, national and international levels, spanning the last 3o years, and you have the disaster Ranum is describing (and lamenting).
The worst case scenario for Web 2.0 is that we are heading for a singularity, precipitated by dividing our attention into informational units effectively rated at zero content.
Imagine you posed the following question to a group of top physicists. You asked them to present you with ideas for new research projects where they could assume that the budget included all the money that we have, all the money that has ever been, and the total financial assets of the world for the next 10 million years. Would the resulting proposals be credible?

AES-256 puts cryptanalysts on the same research agenda.

So for complex decisions that potentially have the greatest impact in terms of costs and/or reputation, in exactly the circumstances where a thorough risk assessment is required, transparency rather than rigour is the order of the day.
Doctorow remarks that the surprising outcome of this process was the realisation that we are missing a well-known service for handling key escrow in an era of military grade encryption being available to home users.
I don’t really think that there is a cult in operation over Bruce Schneier, but rather a hero was found when security as an industry needed to believe in heroes.
When I look back at crypto now it seems of similar consequence to the proportions of the Sun and Antares - not merely because my professional interests have changed, but in the vast equation that constitutes ERM, crypto is a variable with minor weighting. Its gravitational force is largely exerted on specialists, and rapidly declines (much faster than the inverse square law) beyond that sphere. It's just a pixel on the football-field sized collage of ERM.
So that’s 1,000 years of computation by a cluster that would envelope the earth to a height of one metre.
There are many posts and news articles of late on the TLS Renegotiation Attack. I had hoped that just by skimming a large number of these that some process of web osmosis would magically transfer an understanding of this vulnerability to me.
In the short term (and maybe the longer term as well) Diffie sees the cloud as a matter of trust. He advises to pick your supplier like you pick your accountant.
For each of us the web is a noisy channel, which we express through the need to search, subscribe, aggregate, recommend, post, tweet – in short a great cull of what finds its way onto our screens.
And while the traits of detail, accuracy and correctness are necessary for IT activities, they are fundamentally at odds with the type of messages and opinions that senior managers are expecting.
Some articles and posts have focussed on verifying passwords in software as the culprit, which is partly true, but the real issue is not software but insecure programming of software.
Gentry has estimated that building a circuit to perform an encrypted Google search with encrypted keywords would multiply the current computing time by around 1 trillion.

Tuesday, May 11, 2010

The Tab Power Law for Firefox

Mozilla has released its 2010 Q1 analyst report on the state of the internet. The report was created to "provide a high-level view of key metrics on an ongoing basis and to share some interesting insights". Well, its a little short at 12 well-spaced pages, and the summary bullets are not that exciting
  • Firefox’s worldwide market share hovering near 30%
  • Firefox adoption is growing most dramatically in Russia
  • People start their work day earliest in Hawaii and Wyoming; latest start to the day is in New York
  • People in South American like applying Personas (themes) to their browser; people in Antarctica love add-ons
For me the most interesting observation was the number of open tabs people work with in FireFox, as shown in the graph below.

image
Most people use 2 to 3 tabs, however the maximum observed value was over 600! Also, since the median is 2.9, over half the people use almost 3 or more tabs. The graph above clearly has a power law structure, and in this case, quite a long tail.

Monday, May 10, 2010

Elliptic Curves in ASCII

There is a new Internet draft on Fundamental Elliptic Curve Cryptography Algorithms by D. McGrew of CISCO and K. Igoe of the NSA. The NSA author might seem out of character for that particular 3-letter agency, but it's no secret that elliptic curves are the NSA’s preferred form of public key system over RSA. It is somewhat impressive that the authors would even attempt to write up such a complex mathematical topic using the ASCII formatting that the Internet Society has insisted on for several decades now. ASCII used to be the lowest common denominator for formatting in the 70’s, but surely now it is HTML or PDF.

Be that as it may, the document is well written and builds up elliptic curves from the basics of modular arithmetic, groups, finite fields before defining elliptic groups. Of course not all types of curves are examined – the document would need to be much longer than 20 pages – but it is self-contained. The section on the security of elliptic curves is a quite short however. After developing the required terminology and background, the authors focus on defining a method for elliptic curve signatures based on the work of two Japanese researchers Koyama and Tsuruoka. This signature variant was probably chosen to avoid any intellectual property issues with more well-known methods that are heavily patented, particularly with respect to efficient implementations.

An interesting read as long as you can handle sustained Courier font. If you are looking for some more background on elliptic curves for security please take a look at Luther Martin’s posts at Voltage, and 4 are listed below ASCII girl

image
Reblog this post [with Zemanta]

Sunday, May 9, 2010

What are the CISO's most useful instruments?

Matthew Hackling, provider of outlandish security punditry from an Australian perspective, has posted a suggested list of artefacts that a CISO should have to act as the conduct of the information security symphony in an organisation,
  1. Audit issue register (lead violin, sometimes a bit too screechy)
  2. Enterprise risk register
  3. Significant business unit risk registers
  4. Compliance requirement register (the timpani)
  5. Mapping of compliance requirements to your Information Security Management System (ISMS)
  6. Control testing management reports and database
  7. Management reporting template
  8. Existing enterprise security plan and perhaps security plans of significant business units
  9. List of business units by criticality
  10. List of business processes by criticality within business units
  11. List of business applications by criticality with function descriptions
  12. Current security budget
  13. Business case template and submission procedures
  14. Document map of ISMS with status of documents within it (approved, under review, drafted, not started)
  15. Organisation chart
  16. List of security projects with budget and status
  17. List of business projects by criticality to business success
  18. Enterprise security architecture ( well at least the "zone model" with zones mapped to examples in the existing environment )
  19. Data classification scheme
Reblog this post [with Zemanta]

Saturday, May 8, 2010

Infographic on Afghan scenarios with Prezi

I, like quite a few other people, posted on the recent NYT article which showed a horrendously complex PowerPoint slide created to depict the situation in Afghanistan, and the challenges facing US military decision makers.

Another more informative view of the Afghan predicament can be found at a German site called The Afghan Conflict, which appears to be the result of collaboration between Marc Tiedemann and several colleagues to produce a visual map of possible scenarios in the conflict. From the site
When we started researching this topic we very quickly saw, that the debate whether to pull out the troops, staying or even enforcing is not too much about arguments, it’s a battle of possible scenarios. Every side seems to have their own positive and negative visions of how things will happen in the future if certain steps are done. The resulting map The Afghan Conflict - A Map of Possible Scenarios is the attempt of a summary of the most popular possible scenarios around the afghan conflict, according to a pullout or stay of the Allied troops. And is based on interviews with journalists, politicians and political foundations.
The resulting scenario map is quite large and the authors have not tried to compress it onto a single PowerPoint slide for convenience of presentation (double click the image below to see a larger version).

image

The scenario map is available as a poster but also as a Prezi animation which allows you to navigate across the scenarios and zoom in and out of detail (I cannot find a way to link to the Prezi animation directly so you will have to view it from the The Afghan Conflict site). I will have more to say about Prezi in future posts, and it appears to be a good navigation tool for complex “infoscapes” like the Afghan situation. In the meantime please take a look at the showcase presentations at the Prezi site.

OpenSAMM Assessment Spreadsheet v0.4 available

OWASP has a project called OpenSAMM, or the Open Software Assurance Maturity Model (SAMM). There is an audit framework for OpenSAMM, implemented as a spreadsheet with about 80 questions, grouped into collection of business functions and security practices. You can get the spreadsheet here.

image

Friday, May 7, 2010

Cute Cloud Computing graphic

image
(source)

Projection: Firefox overtakes IE by Christmas 2012

It has been widely reported that the global market share for Microsoft’s Internet Explorer has fallen below 60%. While pundits, commentators and technologists discuss the future of IE, Zack Whittaker at ZDNet has done “a bit of maths” and produced the following extrapolation, showing FireFox passing IE market share around December 2012.

image
Assuming Zack has done his Excel sums correctly, the prediction is still pure data extrapolation. The last year has been extremely unfavourable for IE with its security flaws and the playing out of the European anti-trust case against Microsoft. Redmond may still be able to turn the prediction around.

Thursday, May 6, 2010

When we understand that slide, we’ll have won the war

The title is a comment reported in the NYT by Gen. Stanley A. McChrystal, the leader of American and NATO forces in Afghanistan, when shown the PowerPoint slide below (see a larger version here)

image

The slide was meant to depict the complexity of American military strategy in Afghanistan, and it seems to have over-succeeded. Apparently PowerPoint is not just an obsession with business managers but also with senior military commanders as well. But behind all the PowerPoint jokes are "serious concerns that the program [PowerPoint] stifles discussion, critical thinking and thoughtful decision-making”. The following observation is quite insightful
[PowerPoint] slides impart less information than a five-page paper can hold, and that they relieve the briefer of the need to polish writing to convey an analytic, persuasive point. Imagine lawyers presenting arguments before the Supreme Court in slides instead of legal briefs.
But even with mounting reservations over the ability of PowerPoint to usefully represent military situations, no one is forecasting any change – it is just too embedded in the military, as it is elsewhere. And while “no one is suggesting that PowerPoint is to blame for mistakes in the current wars”, it takes a great deal of time with PowerPoint to keep a war going, let alone end it.

Wednesday, May 5, 2010

The power limit of Cloud Computing

In February I posted on Lew’s law, a prediction by former SUN CTO Lew Tucker stating that IT expenses will increasingly track to the cost of electricity. Tucker gave a keynote presentation on The Ultimate Cost of Computing at the recent Cloud Connect conference, where he gives some more insights into his views on the evolving cost model for cloud computing.

Tucker begins by stating that the driving forces of cloud computing are technology and the market, symbolised by Gordon Moore and Adam Smith (the author of the invisible hand of the market). He shows that Moore’s law, the doubling of computing power every 1 – 2 years, continues to be achieved by the microprocessor industry as a whole, with computing power increasing by a factor of one million over the last 40 years.

image

In the last few years these gains have been supported by multi-core processors, issues with power consumption, chip cooling and production costs invalidate the assumption that smaller components are the most cost effective strategy to increase processing capability. The future probably then lies with more chips of a given complexity rather than with chips of increased complexity. So Moore's Law may actually be maintained but not for the reasons that Moore predicted (increased chip density).

A key question for Lew is whether cloud service providers can pass on the benefits of Moore’s law to customers. Already the cost per hour of a CPU (instance) has dropped from $1 to less than two hundredths of a cent over the last 15 years.

image

But what are the real costs of cloud computing? Are faster computers the deciding factor? Apparently not - it's administration and power consumption.

image

Cloud computing wins by leveraging automation, virtualization, dynamic provision, massive scaling and multi-tenancy, which all lead to power becoming the dominant cost (mainly for scaling and cooling). And data centre power consumption has already doubled in the last 5 years

image
So Lew’s law can now be started as
In the cloud, the cost of computing will continue to fall bounded only by cost of energy
Being an ex-SUN man, Lew must take some delight in this final slide

image

Reblog this post [with Zemanta]

Tuesday, May 4, 2010

Conficker and your health

image
A USB stick inserted into a terminal in one of its car parks is being blamed for a massive Conficker infection of Waikato hospital in New Zealand that broke out last December. Over a 3 day period this incident infected 3,000 computer on the hospital network, impacting around 5,000 hospital staff. A full report on the incident is still forthcoming, but a USB-borne strain of Conficker is expected to be named as the culprit. A similar incident occurred in the server of the NHS in Leeds earlier in the year.

Monday, May 3, 2010

A look back at posts from April 2009

As April has just passed by, let’s take a quick review of what I was blogging about in that month last year

There were a couple of posts on entropy, the first NIST, Passwords and Entropy a review of NIST’s approach to specifying password policies based on entropy and the second On the Entropy of Fingerprints, which found some research to indicate that password entropy is much lower than fingerprint entropy.

I also had a bit to say about a “rant” in Marcus Ranum and the Points of No Return where Ranum stated that the cumulative effect of many business-driven IT decisions taken over the last three decades have rendered a grand IT failure all but inevitable. I followed that post up with The Relegation of Security to NFR Status which examined the weakened position of security, and IT in general, in decision-making processes.

There was a wonderful post by Julian Sanchez on his Climate Change and Argumentative Fallacies blog where he coins the term “one way hash” arguments, by which he means the asymmetric amount of effort required to pose a plausible argument as opposed to the effort required to debunk it. I think we face the same problem in IT risk and security as I said in “One Way Hash” Arguments.

I also reposted The Data Centric Security Model (DCSM) with a link to the full document on Scribd, as the old link stopped working. The document remains very well read with about 3,000 views in total today. Some security documents on Scribd gave links to other documents I uploaded, and you can see all the categories here (called collections by Scribd).

I announced in ENISA and Security Awareness that I would be speaking at an upcoming ENISA conference, which was a very successful get together. My slides can be found here and let me point you to a great awareness presentation from Robert Hadfield of British Airways, which has just over 1700 views on Scribd.

Zero Knowledge Proofs was a longish non-technical introduction to this complex topic, and it has remained one of my posts that has a steady number of readers. I also started Password Roundup #1, with my intention to create a series of posts on password issues, which always figure regularly in security news. I got around to a second round-up about a month later but have stalled since then – not due to lack of material. Instead of waiting for me, please take a look at the Reusable Security blog by Matt Weir which is devoted to password issues and analysis.

Finally, I started to post some of the FreeMind maps I create to gather my thought son more detailed posts in Three Security maps in FreeMind and Flash. Since then I have published all my FreeMind maps, including some that don’t relate directly to articles.

Sunday, May 2, 2010

Crowdsourcing CAPTCHA cracking

The NYT has reported on the practice of outsourcing the breaking of captchas to people in Bangladesh, India and China. The work is neither glamorous nor well-paid at 80 cents to $1.20 per 1,000 solved captchas, however there seem to be enough takers nonetheless. The work is farmed out through online exchanges like Freelancer.com, where for example an operator in Bangladesh runs an operation turning out captcha solutions 24 hours a day, seven days a week.

Macduff Hughes, an engineering director at Google says that “Our goal is to make mass account creation less attractive to spammers, and the fact that spammers have to pay people to solve captchas proves that the tool is working.” So we should see captchas as a deterrent rather than a foolproof way of distinguishing people from malware. In fact if people are being employed to break these little authentication puzzles then they are working as intended – to make sure that a person is behind the answer – unfortunately malware is masking a mechanical turk. The inventors of captchas probably did not expect that solving these puzzles could be farmed out so easily using Web 2.0 technology.

The bigger threat probably comes from the direct computer solution to captchas, which can be scaled and provide solutions in real time. I recently posted on the very thorough analysis of the Koobface botnet at abuse.ch, including a section on its captcha breaking network. The captchas are broken in at most 3 minutes, and in many cases just a few seconds. There is also evidence presented by Webroot that audio captchas are also being broken in real time by automated means.

Reblog this post [with Zemanta]

Saturday, May 1, 2010

1-in-300 Facebook accounts hacked, and now for sale

There are several reports stating that one and half million Facebook accounts are for sale on an underground forum by a hacker calling himself Kirllos, which equates to about 1 account in 300 being up for grabs. VeriSign's iDefense group estimates that almost half of the accounts have been sold already.

Kirllos' is asking $25 for 1,000 users with less than 10 friends or $45 for those with eleven or more. This is quite cheap given that e-mail IDs and passwords typically go for between $1 and $20 per account, and credit card and bank account credentials can go up to $30 for credit cards and $850 for bank accounts.

As usual, Facebook users should check their passwords.

What is the LINPACK rating of Conficker?

Rodney Joffe, senior vice president and senior technologist at the infrastructure services firm Neustar, gave a keynote presentation on Cloud Computing for Criminals at the recent Cloud Connect conference. Joffe presents some figures which show that the computational size of the Conficker botnet dwarfs the current commercial offerings, based on measuring the number of systems, the number of CPUs and available bandwidth. For Conficker these values are given (estimated?) as

  • 6,400,000 systems
  • 18,000,000+ CPUs
  • 28 Terabits of bandwidth

These corresponding measures for Google are 500,000 systems, 1,500,000 CPUs and 1,500 Gbps of bandwidth, with Amazon and Rackspace providing significantly less resources. So Conficker is a massive ad hoc computational structure. But is Conficker really like a cloud service? Joffe says yes because

  • It’s available for rent
  • Choose your geographies
  • Choose your networks
  • Choose your bandwidth
  • Choose your OS Version
  • Choose your specialty (DDoS, Spam, Data Exfiltration)

and further the vendor has good qualifications

  • Much more experience (1998)
  • Larger footprint (Millions of systems)
  • Unlimited new resources (New malware)
  • No costs
  • No moral, ethical, or legal constraints

This all reminds me of a mail post by Peter Gutmann from 2007 called, World's most powerful supercomputer goes online, referring to the Storm botnet

This doesn't seem to have received much attention, but the world's most powerful supercomputer entered operation recently. Comprising between 1 and 10 million CPUs (depending on whose estimates you believe), the Storm botnet easily outperforms the currently top-ranked system, BlueGene/L, with a mere 128K CPU cores. Using the figures from Valve's online survey

http://www.steampowered.com/status/survey.html

for which the typical machine has a 2.3 - 3.3 GHz single core CPU with about 1GB of RAM, the Storm cluster has the equivalent of 1-10M (approximately) 2.8 GHz P4s with 1-10 petabytes of RAM (BlueGene/L has a paltry 32 terabytes). In fact this composite system has better hardware resources than what's listed at http://www.top500.org.

This may be the first time that a top 10 supercomputer has been controlled not by a government or megacorporation but by criminals. The question remains, now that they have the world's most powerful supercomputer system at their disposal, what are they going to do with it?

And I wonder what the LINPACK rating for Storm is?

And I wonder what the LINPACK rating is for Conficker?

Reblog this post [with Zemanta]