Saturday, March 26, 2011

Freehaven papers on Anonymity

I have not looked at the Freehaven site for some time, but just a reminder that there is a huge collection of research papers sourced, tracing the history of anonymity systems, MIXES and other PETs. The collection was well-attended to up till the end of last year but is missing updates for 2011 so far. I am sure that they will come. BibTeX references for the papers as well.

Trust and security in the cloud

The Register has published a new 16-page whitepaper on trust and security in cloud computing, with the key findings being

  • Many companies could do much better when it comes to in-house security
  • SaaS adoption is limited currently, but there is increasing interest from the business
  • The biggest impediment to SaaS adoption is a perception of security issues
  • Companies with experience of SaaS are positive about provider security
  • SaaS is likely to help with shortcomings of on-premise security capabilities

The whitepaper was written from data gathered in an online survey with over 500 participants. Amongst the many tabulated responses to the survey there is an interesting list of the ways data can exit from corporate boundaries.

image

Saturday, March 12, 2011

iPad Competition is Toast

Business Insider recently reported that the iPad is outselling the competition about 4-to-1. So as security professionals the iPad is the platform to focus on for risk assessments.

image

An example of redundancy in English

After I apologized too often for my bad typing, my sister-in-law sent me the following text to demonstrate that our brain can understand words even if only the first and last letters are correct
Yet aoccdrnig to a sudty at Cmabrigde Uinervtisy, it deosn’t mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht the frist and lsat ltteer be at the rghit pclae. The rset can be a ttoal mses and you can sitll raed it wouthit a porbelm. Tihs is bcuseae the huamn mnid deos not raed ervey lteter by istlef, but the wrod as a wlohe.
Apparently this text is well-known to language people!

Saturday, January 29, 2011

24 minutes with Bill Gates on career choices

In April last year Bill Gates addressed a collection of students at Harvard for 24 minutes on the topic of where to devote your talents. It is well-known that Gates dropped out of Harvard in the mid 70’s to develop his fledgling software company. He was returning as a philanthropist on this occasion, armed with the following question “Are the brightest minds working on the most important problems?”. And clearly he does not think so, as it appears many of top minds in the US are going into sports, entertainment or finance. In fact, “The allocation of IQ to Wall Street is higher than it should be.” You can find the video of the talk here.

Thursday, December 23, 2010

Calculus vs. Probability

I am trying out listening to podcasts on my – yes – iPod, during what was figuratively described to me as my “downtime”. In Zurich for me this means being on trams and trains, and walking between them or to them. So I went looking for captivating podcasts and of course ended up at the TED site, where you can download any number of interesting speakers and topics. I came across a short and poignant talk by mathematician Arthur Benjamin's on his formula for changing math education.

image

His simple approach is to switch from calculus being the pinnacle of math education to actually probability and statistics, because while the former is beautiful yet little used, the latter two topics are in fact very practical and in high demand. In short we need to better understand risk. Below is the full text of his short talk, where I have highlighted a few phrases in bold

Now, if President Obama invited me to be the next Czar of Mathematics, then I would have a suggestion

The mathematics curriculum that we have is based on foundation of arithmetic and algebra. And everything we learn after that is building up towards one subject. And at top of that pyramid, it's calculus. And I'm here to say that I think that that is the wrong summit of the pyramid ... that the correct summit -- that all of our students, every high school graduate should know -- should be statistics: probability and statistics. (Applause)

I mean, don't get me wrong. Calculus is an important subject. It's one of the great products of the human mind. The laws of nature are written in the language of calculus. And every student who studies math, science, engineering, economics, they should definitely learn calculus by the end of their freshman year of college. But I'm here to say, as a professor of mathematics, that very few people actually use calculus in a conscious, meaningful way, in their day to day lives. On the other hand, statistics -- that's a subject that you could, and should, use on daily basis. Right? It's risk. It's reward. It's randomness. It's understanding data.

I think if our students, if our high school students -- if all of the American citizens -- knew about probability and statistics, we wouldn't be in the economic mess that we're in today. Not only -- thank you -- not only that ... [but] if it's taught properly, it can be a lot of fun. I mean, probability and statistics, it's the mathematics of games and gambling. It's analyzing trends. It's predicting the future. Look, the world has changed from analog to digital. And it's time for our mathematics curriculum to change from analog to digital. From the more classical, continuous mathematics, to the more modern, discrete mathematics. The mathematics of uncertainty, of randomness, of data -- and that being probability and statistics.

In summary, instead of our students learning about the techniques of calculus, I think it would be far more significant if all of them knew what two standard deviations from the mean means. And I mean it. Thank you very much. (Applause)

I could not agree more. The world is discrete for me, and very few of the problems that I encounter succumb to integration.

Protecting Your Information in the Age of WikiLeaks

This is the title of a webcast invitation that I recently received from Symantec. The Wikileaks saga is quickly impacting the infosec landscape, probably because the issue is so visible to all levels of senior management. The webcast is described as follows
In the wake of the intense media attention around the WikiLeaks disclosures, you may be asking yourself, "What steps can I take to help my company avoid this same fate?"

Symantec has been working with customers who are concerned about preventing these same issues and we’ve developed a set of best practices that can help defend against these types of breaches. We’d like to share with you some of the techniques that might be useful to help you uncover similar activity on your own systems. In this live webcast we’ll:
  • Discuss the threat agents and modes of data loss you should be most concerned about
  • Recommend counter-measures to protect your critical information against these risks
To learn more about how your organisation may be at risk and steps you can take to defend your information, register today.

2011 InfoSec Predictions from Zscaler Labs

Its not only the season of giving and but forecasting as well, and I recently received the following Information Security Predictions from Zscaler Labs
  • Flash mob hacktivism – we’ll see more attacks similar to Operation Payback, where like-minded strangers quickly organize and attack corporations or government entities in the name of a cause
  • Niche malware designed to harvest confidential information from IP-connected devices such as printers and SCADA systems will grow
  • Cloud-hosted botnets will grow
  • We’ll hear about more indirect data breaches, where not it’s the company affected that was breached, but rather a third-party vendor or organization
  • Social networks will become the main communication medium for attackers
  • The Information security market will continue to shrink
An interesting list - more about trends than fundamentals - and you can find more details on the Zscaler blog.

Over 1,000 visits this month to old AES-256 post

Just a note to say that my Are AES 256-bit keys too large? post from July 2008 has been visited over 1,000 times this month. For the last few years it has been my most popular post by far, and I once referred to it as one of my Pareto posts. Probably what happened this month is a link to the post found its way onto some social channel, like Twitter, and just mushroomed from there. It just shows that content really has no use-by date in Web 2.0.

Tuesday, December 14, 2010

Tutorial on Buffer Overflows

Nice tutorial on this perennial security problem from Patrick Schaller of ETH, Zurich.

Tuesday, December 7, 2010

Monday, December 6, 2010

Snakes in Suits – the risks from psychopaths in the workplace

A telling presentation from Holly Andrews at a recent IRM meeting on dealing with psychopaths in the workplace (and yes the boardroom), derived from the 2006 book Snakes in Suits: When Psychopaths Go to Work. The presentation describes how workplace psychopaths burrow into positions of power, and amongst other things, assume more risk than is sensible. There is a wonderful process chart which shows how such people operate

image

Transitional organisations can be seen as ideal “feeding grounds” for psychopaths since

  • There are fewer constraints and rules allow the psychopath freedom in acting out their psychopathic manipulation
  • The fast changing environment provides stimulation for the psychopath whilst serving to cover up their failings
  • There is the potential for large rewards in terms or money, power, status and control


Thursday, October 28, 2010

Just over 100,000 reads of my Scribd documents

Just a note to say that the total number of read of my documents on Scribd just passed 100,000! The categories are given below,  mostly PDFs and a few PowerPoint presentations.

Tuesday, September 14, 2010

BP and Trial by PageRank

Over at the NSIS, Alex has a post (downgraded to a rant?) which begins with berating Gideon Rasmussen for calling the BP Deepwater incident a Black Swan, and ends up discussing flaws in corporate governance. Alex correctly describes the incident as a “tail event”, both low probability and high impact but still “on the curve”. True Black Swans are events for which prior distributions are “completely uninformative”, and they belong on a totally different curve to expectations and models.

Even so, for me a Black Swan aspect of the incident has been the subsequent reputational damage to BP. This has not been a trial by public media, but trial by social media and ultimately, trial by PageRank. In web 2.0 there is no such thing as yesterday’s news, or yesterday’s newspapers wrapping up today’s fish and chips. Links are just as good today as they were yesterday, and continue to remain search-worthy far into the future as long as PageRank deems them to be so. Holding steady at approximately two thirds of the search market, Google via PageRank has become the default arbiter of Internet truth. 

A recent article called What Big Brands are spending on Google from Advertising Age showed that BP’s spending on Google Ads increased dramatically, to almost $3.6 million dollars in June, up from its regular budget of less than $60,000. 

image

That’s almost a 6000% increase in spending at the height of the BP counter-PageRank campaign, and such unpredictable jumps are the calling cards of Black Swans.  From the article

Before BP could stem the oil gusher at the bottom of the Gulf of Mexico, it unleashed $100 million in ad spending, largely on network TV, to stem the damage to its image. But it also started spending heavily where it had never spent much before: buying ads in Google's search results.

BP was essentially paying Google AdWords to distract Google PageRank - trial by PageRank and forgiveness by AdWords. What’s that saying about judges and juries again?

Friday, September 10, 2010

Keyword Spamming with Infographics

Infographics have become more popular, and BuzzFeed has produced an infographic describing how infographics are used to generate keyword spam. The trick to stopping the spam appears to be adding a NO FOLLOW tag in the html code of the embedded infographic.

image