Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

Saturday, June 16, 2018

Change the Way You Talk Change the Way You Think

Quick, think of a word that describes a combination of letters and numbers that can be used to login to your system...

What came to mind? Was it "password"?

One of the greatest problems in our industry may be the use of the word "password." The origination and proliferation of this word has led us to believe that we must construct this security device using such things as words rather than by some other means. 

If you really think about it the paradigm of a passphrase is better in almost every way. After all, many common passwords can be rapidly and effortlessly cracked with a simple dictionary. If we simply take the first letter of each word of a phrase and modify them slightly we have exponentially increased the difficulty of breaking that passphrase.

Having said this let's talk for a moment about how the words we say and what we do affect our thinking. Aristotle said this, "Excellence is an art won by training and habituation. We do not act rightly because we have virtue or excellence, but we rather have those because we have acted rightly. We are what we repeatedly do. Excellence, then, is not an act but a habit."

Whether you look for positive or negative occurrences of this, you don't have to look too far to see the practical examples of how this manifests itself. Self-realizations, self-fulfilling prophesies, and liars who believe what they have repeated so many times all attest to this. However, we have seen that the fact of the matter is that passphrases are without question more secure. So, why should we not reinforce this truth by using the appropriate term in our speech and login interfaces?

Stay Secure!


Monday, April 16, 2018

Not a conference conference

This week many people are at RSAC for the week gaining knowledge and a ton of vendor swag.
Believe me when I say I am not bitter about not being there. But watching from the sidelines got me thinking...    What if we took all the time and resources we spend on conferences and put them into security improvements? 

What would that look like? Well, surely you've been to working meetings where everyone brings their gear and talents and you collaborate on tasks. Sometimes this doesn't happen until a "crash team" is needed. Other times it more proactive. 

Food for thought.

Tuesday, September 20, 2016

Baking in security

There's a long-standing synicism around development not taking security into account and security picking up the pieces. In fact it's lead to memes like this:

Author Unknown

For many this cynicism may be hard to take seriously but in light of recent research below it takes on a different real-world perspective. Security is serious business and has serious real-world implications in safety, identity, finance and other areas. It pays to think through what and how you are doing day-to-day life and business. Invest early and enjoy the rewards of that investment for a long time to come!

Wednesday, August 31, 2016

Cyber Panel at Nashville Business Journal

A while back I participated in a Cyber panel with the Nashville Business Journal.

Read the article here.

Wednesday, May 18, 2016

Moving from RansomWare to LeakWare

One of the trends I have observed on the Cyber Security threat landscape is the movement from "Ransonware" like CyrptoLocker, TeslaCrypt and CryptoWall to a new category of malware I am calling "LeakWare." This is a distinct category of malware that needs its own category, defenses and and special attention.

Simply defined, we can expect LeakWare will hold a user or company's data for ransom (maybe, probably) and if the ransom is not paid the data will then be leaked to the world via sites like pastebin, wikileaks, and others. The aim here is to up the ante beyond merely data loss to data exposure. Imagine the Sony-like impact of this potentially life/business-ending exposure. This will merit new and special attention to defense and prevention further driving the market for new and innovative technologies to guard against this and previously-seen  similar threats.

Wednesday, January 14, 2015

O365 for the InfoSec win!

O365 appears to be a huge improvement in Cyber Security over on-prem on a few points:

  • Better vendor visibility of threat surface -  Microsoft’s more than 300 person security staff has improved visibility to the threats posed to users of office products. They are able to see trending threats and react faster with fixes, patches and bulletins to customers.
  • Higher patch compliance rates. Microsoft can patch O365 in the cloud all-at-once. In fact they re-build from "gold image" each time they implement a fix! This improves the overall security posture of the Office threat surface since the wait times are lower thus lowering zero-day exposure.
  • Greater vendor support - Microsoft is able to provide significantly greater support in a managed service such as O365.
  • O365 uses a no-trust model not offered in on-prem Office that improves security greatly.
  • Encryption in the cloud further secures data.


This is not to say there are not security drawbacks to O365 (I am sure there are) but these are some of the major improvements I am aware of based on independent cyber research and the MS CISO’s keynotes from the MID-TN ISSA conference in September 2014.