Friday, August 14, 2009

The Encryption Dance

S-s-s-s  A-a-a-a  F-f-f-f  E-e-e-e  T-t-t-t  Y-y-y-y

You can make the Big S while you sing along.*
Data goes where it wants to, It can leave your trace behind.

Cause the web don’t care and if it don’t care, Well it’s exposing time.

I say, data can go where it wants to, A place where they will never find.

And we can act like we come from NSA, Leave the eavesdroppers far behind.

And we encrypt.  Those things.









We can surf where we want to, Data’s masked and so am I

And we can hide real neat from our hats to our feet,

And surprise ‘em with a ‘Ha Ha’ cry.

Say, they can crack if they want to, if they don’t somebody will.

And if they do break in, the data is encrypted

And they’ll look like an imbecile.









I say, we got data, we got data, Everything’s in our control

We got data, we got data, encrypting it wall to wall

We got data, we got data, everyone check their systems.

We got data, we got data, everyone’s taking a chance

Encryption Dance.



Encryption is a key element in security – both for data in transit and data at rest.  It doesn’t necessarily need to be highly sensitive data either.  Just something you want to keep secret.  I’ve written about encryption a few times, especially in context surrounding high profile image breaches like TJX and Heartland since both those might have been avoided if the data was encrypted.  It’s not as simple as the lyrics depict as Lori points out in this blog.  Sure, there is SSL, HTTPS, IPSec and encrypted drives but it’s difficult to encrypt every piece of data, especially for the enterprise.  In fact, there’s probably some data that doesn’t need to be encrypted.  Which is where a Access Control Policy can come into play.  Depending on the context of the user/device, remote and mobile workers should be connecting via an encrypted tunnel using your VPN – that’s a no brainer.  Depending on the host inspection check, your policy might only allow access to certain resources depending on the device’s posture and hopefully all that traffic is encrypted.  Internal LAN’s are no longer the ‘safe haven’ that they used to be.  Partner’s, contractor’s and even unauthorized employees might have visibility to certain restricted information.  Here again, a policy could be enforced to first, restrict access to certain areas of your network (which many do already) and second, if an authorized employee is grabbing sensitive data, why not encrypt that specific file transmission even on the internal network to thwart any prying eyes or sniffing agents.

As for PCI, there’s already plenty of articles and opinions about it’s current state and effectiveness so I won’t dive in here.  What I will point out is an upcoming deadline that many might be unaware of: The unattended, PIN entry, Point-of-Sale devices.  While the deadline for PCI-DSS has passed, the deadline for PA-DSS entry terminals is next year – July 2010.  That means that most gas station pumps that you use your debit with, are unencrypted today.  There will be a mad rush next year for Fuel Retailers to either deploy an encrypted PCI-compliant PIN entry device inside or an encrypted keypad outside.

Finally, we continue to see data exposures due to stolen or lost laptops.  Here again, depending on your policy, the type of user/device and information accessed (plus other criteria) encrypting the drive to protect against inadvertent exposure is certainly a good idea – along with strict and potential severe consequences if someone does not comply.

ps

*Sung to the tune 'Safety Dance' by Men Without Hats.

#5 out of 26 Short Topics about Security

Wednesday, August 12, 2009

Bit.ly, Twitter, Security & You

..or, what I did on my twitter vacation the other day.  This brief break from 26 Short Topics about Security is brought to you by bit.ly, twitter, security and You.  I’ve been using bit.ly for a little while both to shorten links and be able to track clicks placed on twitter (and other social sites) – as many of you do.  When the twitter outage hit last week, and many folks found themselves ‘lost’ without it, I decided to review my stats on the bit.ly links I’ve sent and found something interesting; or frightening.  :-)  (Incidentally, there was a another DDoS attack yesterday that took twitter down for about 20 minutes)

To set this up: as you might know, I cover Security within the Technical Marketing Team (Lori, Alan & Ken round out the TMM group – and we’re all interested in Security) at F5 and usually find 1 or 2 interesting ‘security’ stories that I actually tweet.  In recent weeks it’s been things like Texting Hacks, Hacking Parking Meters, and The Weak link in Security:People, along with my blog, and F5 video and audio updates.  Sometimes I find a slightly weird story like the poor guy who fell into a vat of chocolate.  Now, many of my followers/I’m following are security folks and the exchange of information is awesome.  I often see stories that I probably wouldn't have gotten to as we all try to read the entire internet on a daily basis.

So, as I looked through my entire list of links, one jumped out: Fancy Fast Food.  Makeovers of fast food and as the site says: ‘Yeah, it’s still bad for you – but see how good it can look!’  This bit.ly link, by a decent margin, was my most popular.  Even the ‘out of’ stat (which is the total of all bit.ly’s going to that long URL) was close to 8000 clicks!  Conclusion?  Folks want fun fast food, not security.  (tongue in cheek) In seriousness, I think there is a really good piece in the fact that, on a day to day basis, people would rather see what some chef can do with a Wendy’s hamburger or Dunkin Donuts that about security.  That doesn’t mean we’re not interested in security but when you’re immersed in it all the time, a little Daily Distraction is a welcome change.  Helps us clear out those PCI headaches, bloodshot breaches and endless string of Identity Theft incidents.  At first I was a little miffed that what I found interesting wasn't so much to others, but then I realized I had actually found something that everyone found interesting not just the security minded.  And it started conversations – true social media.

ps

  • * No bit.ly links were used in this blog as to not artificially increase stats

  • * If you’re so inclined – F5 can be followed @f5networks and me @psilvas


bit.ly, a simple url shortener
http://bit.ly/ [more]

Friday, August 7, 2009

Decade old Data Centers

Most data centers are now hitting their teens when it comes to age.  How do I know this?  I used to work for Exodus, The Data Center Company back at the turn of the century (actually wearing an old EXDS t-shirt as I write this.)  The ‘heyday’ of the Co-Location.    ‘Daddy, what was the datacenter like when you were a kid?’  Well, we’d find a somewhat remote location and build these massive non-descript buildings, some more that 200,000 sq.ft. all over the world.  The walls were Kevlar lined.  We had multiple internet carriers dropping fiber at all sides of the building along with power from distinct sub-stations.  

exodusvig There were multiple, huge CAT power generators that would kick in to keep the place running during a outage – even had contracts with fuel vendors to replenish the diesel for non-stop service.  We had racks and racks of DL380’s & Sun Sparcs humming throughout the facility, along with the F5 logo lit up in various cages handling load balancing.  The temperature was a constant 72 degrees, with low humidity to keep all that equipment cool.  We had special triggers for the fire spouts, biometric pods (that checked hand print, pulse & weight) to enter the facility, raised floors, guards 24/7, NOC engineers 24/7, off-site tape storage, cameras all over and used to deliver many of the top visited websites.  As many of you know, Exodus collapsed during the dot bomb and the assets were picked up by Savvis, after a brief stint as a Cable & Wireless company.  Many former colleagues still work there and I have a fond memories of that time – plus I learned a ton.  Heck, Disaster Recovery was a huge topic back then!

Today’s data center needs have changed as the requirements have over the last decade.  While Co-Lo and hosting is still big business the data center itself is going through some transition.  Power and cooling that were perfect for the type of equipment being used back then, is no longer sufficient.  While servers have gotten more efficient, they’ve also become more powerful, capable of running multiple virtual instances on a single unit.  Remember when we used to try to put the web server and a database partition on the same server?  Cost/ROI/TCO is much more important now when discussing the data center footprint.  Today Enterprises can choose between housing their own, using a pure hoster/co-lo along with the newly emerging Cloud Centers – or more likely, a mix.  Each has their plus’/minus’ but you can basically go from a fixed price/CapEx/owned facility to a variable pricing/Opex lease.  Some choices are made for SLA’s while others for time to market.  The data center is changing with fewer sites but a more energy efficient, modular design that focuses on consolidation and virtualization that scale.  There are even data center containers being offered by the likes of Sun, IBM and HP.  These ‘pods’ are like those storage units that sit in someone’s driveway except it’s ready to house IT infrastructure.

One of the biggest challenges is the management and administration of the data center.  During my time at Exodus, each server was pretty much a single instance and administration was 1 admin:some servers.  Even though consolidation is happening, now with virtual machines, each of those ‘some servers’ now have 5-8 instances on them.  Admins can face the task of managing more servers (virtual add) than ever before.

Of course, security is a concern in the old white label facilities where walking out with someone’s gear is a great fear.  The newer buildings are becoming even more isolated with lights-out management and no office space.  At Exodus, we used to all have our desks just on the other side of the data center & even had a conference meeting room in the data center.  Ahhh, those were the days.  Network security is also becoming even more important as these facilities tie back to corporate assets, users and a whole host of sensitive information.  Even storage and backup, which used to be done via DAS, SAN or NAS might now be sent over a private cloud or even the public networks.  There’s also the basic security worry of putting critical data in the cloud especially if it is bound by regulatory compliance.   Disaster Recovery is even more critical as more content, tools and systems get pushed to the web.  And lastly, Fast, Available and Secure is always a concern when placing any application on the internet no matter where they reside.

ps

#4 out of 26 Short Topics about Security

Tuesday, August 4, 2009

Remember when we drew big Clouds on whiteboards…

…with the Ace Frehley lighting bolts flying out?  We still draw those clouds but now they are smaller, there are more of them and sometimes hover over a single, private entity.  Well, the Clouds have accumulated and an umbrella isn’t going to help.

Nicholas Carr (author of Does IT Matter and The Big Switch) talks about the notion of the Internet (or Computing power) as a Utility and has compared the cloud transition to the birth of power utilities from the 19th to 20th centuries. Back then, manufactures had to provide their own energy source and many used huge water wagon wheels to generate power. In fact, the top manufacturer at the time had built the world’s largest waterwheel and had a competitive advantage.  Soon, things changed when Westinghouse came on the scene in 1886 and pioneered long-distance power transmission.  As soon as these self-generating sources could now ‘plug-in’ inexpensively, all assumptions changed. The assumption was that this (power) was something you had to buy/build and maintain yourself.  Carr feels Information Technology is next and going thru a similar transformation due to the collapse of efficiency. He notes that, Server Capacity has 80% waste, Storage has 60% waste. and upkeep/maintenance has around a 70% waste. Clouds give the ability to share assets and move to a new level of efficiency, if done right. While the notion of Utility Computing is new; disruptive technologies can move quickly, especially if it’s working well.  There is, of course, alternative views to this idea offered in this article.  It’s an interesting read on the difference between pushing/sharing electrons VS. data along with the ‘trust’ factor.  I don’t think James Urquhart is necessarily disagreeing with Carr but being more specific as to what Computing as a Utility would look like and he correctly points out that, “some have taken electricity as an analogy to cloud adoption to an extreme…” I tend to agree since an industry blessed definition of cloud computing is still evolving & Nick wrote his book over a year and a half ago when ‘Cloud’ was still a nebulous term.  Even today we’re starting to parse parts – Platform, Software and Infrastructure – all as a Service and many are jumping in.

cloud According to IDC, CIO’s choose Cloud services primarily for Ease, Fast Deployment and Lower payments. They avoid Clouds due to Security concerns, Dependability (availability/performance) and Control. Security (or Trust) is usually at the top of surveys (for good reason) but there’s also a sense of not wanted to give up control of specific applications, particularly ones that are tied to certain regulatory governance. The growth anticipated over the next couple years will be in IT Management Apps and Collaborative applications which makes sense.  Cloud is about sharing and collaborative apps are making their way to the cloud, plus IT must have a way to manage all those instances.  The goal, of course, is to Consolidate (reduce costs/improve quality), Virtualize (simplify access/improve end-to-end management) and Automate (speed/predictability & reduce labor) IT into service orientated delivery.

Clouds are not going to replace the old IT model but become another choice for sourcing to IT departments. There will be a mix of on-premise and off/cloud delivery, depending on the application (and several other factors) but performance level assurances (SLA) are very important to the buyer.  Also attributed to ISC, Cloud spending looks modest from 4% of overall IT spending to 9% in 2012 but will account for $42.3 billion with business applications taking 52% of that.

ps

Number 3 out of 26 Short Stories About Security

Friday, July 31, 2009

BREACH is the Word, is the Word, is the Word that you Heard….

…to the tune of $6.6 Mil per-r-r Breach.  Yup – according to Ponemon Institute the average cost of a data breach is $6.6 million and they also report that it costs about $215 per compromised record (pdf).  McAfee estimates $1 trillion in losses yearly, due to data theft – that’s 10 to the 12th dollars.  Imagine if IT budgets could get that back?

The past two years saw a significant increase in large scale attacks with the January 2007 TJX breach starting the massive flurry.  As of October 2007, TJX said that more than were 94 million accounts affected at a cost of over $256 million.  At the time it was the largest data loss incident to date.  The crooks kept it up, however.  Hannaford Grocers was hit Dec 2007 but they didn’t discover it until February 2008 and announced in March 2008 that 4.2 million cards had been exposed  leading to over 1800 cases of fraud.  In both cases thieves were able to capture the data, in clear text, as it traveled over the network.  December 2008, at the height of the economic crisis, both Checkfree.com (online bill pay) and RBS Worldpay (payment processor) announced they had been infiltrated.  Checkfree with a DNS switcheroo and RBS Worldpay with a straight up ‘they broke in.’  RBS had 1 million accounts compromised and Checkfree, 5,000,000.  Payment card data was the top target in 2008.

Then at the start of 2009, instead of hitting individual retail chains, hackers decided to go after the big score – and boy was it.  Heartland Payment Systems, which processes about 100 million credit card transactions a month was compromised and it unseated TJX as the largest breach ever in the US.  This too was a case of malware planted on the network and thieves able to capture clear text data in transit.  In addition to Heartland, initially over 220 issuing banks were affected by the breach and that grew to 656 by June 2009.   The total number of accounts compromised is still unclear.  The common theme in many of these breaches is that the hit companies were PCI compliant.  Currently, PCI  does not require encryption during transmission of sensitive data on internal networks – where most of these occurred.  Ignoring the lawsuits, fines and bad press, the bright spot in all this is Heartland has instituted end-to-end encryption of all data (although some question the overall effectiveness) and has developed new equipment in the wake of the fiasco.  This one is still playing out.

dilbert

One stat I remember but can’t remember the source (sorry for forgotten reference) is that 60 percent of companies had experienced a data breach in last year. However, only a minority of six percent could say with certainty that they had not experienced any such breaches in the past two years.  Yikes.

ps

Previous blogs covering some of these:

The 'lost' paragraph - added Aug 2:
I meant to include this thought in the original post but forgot.  The other silver lining in all this is that the companies that have been breached, and the above just got the most press, are probably more secure than they ever were.  The breaches have made them more aware of their vulnerabilities and they have taken additional measures to ensure it doesn't happen again.  While brands can suffer after public disclosures, one could argue that the experience & knowledge gained - post breach - actually puts them in a better, more secure position moving forward.  ps

Thursday, July 30, 2009

26 Short Topics about Security: Stats, Stories and Suggestions

The crew at DevCentral has a great series called A to Z, which goes through various technologies including Social Media, PowerShell, Networking and the most recent NSM (Network and System Management) and gives tips, tricks and technical info on the topic. 

I decided to build upon (or steal, however you see it) the idea with ‘26 Short Topics about Security.’  Yes, I’m a Simpsons fan (22 Short Films About Springfield) and got some inspiration.  This blog series is actually an altered version of a presentation I did a few months back that I always thought of turning into a blog series.  The idea is that there is so much going on with Security in so many different places that I figured it might be good to cover 26 of those over the next few weeks.  Not too technically heavy or all encompassing but definitely areas of concern for IT.  So, then – let’s get on with it!

First, Security (and not just Information Technology) is all about Risk and Threats.  There’s a whole industry based on Risk Management, Risk Assessment, Risk Mitigation, Risk Analysis and so on.  Risks, in my view, are based on actions that we (you/I) either take or don’t take while Threats are actions (or attacks) coming from other entities.  We take risks while we try to reduce threats.  ‘That’s a risky move you’re making’ and  ‘don’t you threaten me.’   Certainly they are intertwined. shark What’s the risk if I don’t respond to this threat?  The 12ft shark might threaten my life if I risk swimming with it.  We deal with risks & threats every day and make quick decisions if it is worth it – you get it.  But this is just the set up (think slides 2-3).  :-)

[Theme song]

We begin with Authentication. Authentication has never been more important to users, corporations and web applications at large.  We’ve been confirming our digital identity against user stores for a while, particularly in our work domain environment & financial web applications.  Just about all the ‘my.public/portal’ sites that offer any sort of customization requires us to enter a username and password and much of today’s malware is targeted toward capturing someone’s credentials.  Once someone gets a hold of your ‘secret,’ they can pretend they are you and access information that only you should be viewing.  In the physical world, a doorman or ticket agent can check a photo ID against your real face and determine if you are who you say you are and hopefully, you’re the only one with that laminated picture.  In the digital world, all the system can go on is whether or not you know the stored secret so it’s important to keep those in the vault and not taped to the top of your laptop.  Plenty has been written about the security implications of ‘Forgotten Password,’ ‘Email password,’ and ‘Password Hint’ retrieval so won’t get into that but Alan Murphy does a have an interesting blog on ‘How to create strong, dynamic passwords.’

Strong Passwords (requiring letters, numbers, caps, special characters, rotation, etc), Two-factor auth (additional password or token) and OTP (one-time passwords) are all ways that IT can enhance their authentication scheme.  Biometrics (thumb print, iris, facial, voice, keystroke, etc) were supposed to be somewhat mainstream by now and can help in determining a user’s authenticity but can be very cost restrictive.  Fingerprint is appearing on many notebooks now and even the keystroke style, which is probably one of the least costly, isn’t completely solid since if I break my finger, the admin can revert to text password or lessen the sensitivity.  I’ve seen ‘What if I’m drink,’ as part of keystroke vendor questions. I understand that alcohol can influence my typing style but does my employer really want a sloshed, uninhibited employee accessing sensitive info?  There are also authentication systems that use pictures and shapes.  Instead of remembering a set of characters, you remember a shape and whatever the random numbers that comprise that shape is your OTP.  Or you do remember a set number password but the numbers appear in different locations every time.  There are also virtual keyboards where you ‘type’ your password by mouse clicking on a little keyboard screen on the log on page.

  sematrix

Oh, there are many ways.

SSO (single sign-on) and Federation take focus in many IT departments.  SSO allows users to log in to a system once and then be able to navigate (gain access) to the other related but independent systems.  For instance, a user would log in (or authenticate against a domain) to their corporate intranet and one of the links available might be a salesforce.com application.  Typically, the user would have to re-enter their credentials, but SSO passes identity (usually cached) which allows access without the additional UN/PW entries.  Federation is essentially trust between networks or domains and can be a part of a SSO solution.  Federated trust is usually a system, server or network trust between two businesses or private systems.  The user probably doesn’t have full reign but can access specific resources on their partner’s network.  With SSO it is usually just the user’s info that is passed to each system, with Federation, the entire (or groups of) infrastructure is trusted.  SAML, Kerberos and WS-Trust/WS-Federation services are all enablers of federation.  SSO can be achieved thru a host of vendors but things like Kerberos, smartcards and client certificates can all play a role.  For public web applications, especially social media sites OpenID is becoming a method for users to ‘claim’ they are themselves at various web portals.  There’s still some hesitancy for enterprise IT to adopt but many web facing applications support OpenID.  Many portals that do support OpenID, however, are reluctant to be that ‘3rd party vouch,’ especially if it’s for a competing portal.

That’s it, nothing groundbreaking just a point in time pertaining to Security topics.  To give you a little taste of what’s next [sung to the tune of GREASE]: BREACH is the word, is the word, is the word that you heard, to the tune of $6.6 Mil, per-r-r-Breach.

ps

Thursday, June 4, 2009

CIA of Security II – Electric Buggaloo

A comment to my previous CIA blog

As a certified security consultant I appreciate your coverage of security issues. My experience was always that the "A" is availability and had never heard it described as authenticity. Here's where I come from on the subject.    Lawrence


Well, I can accept that & I guess I’m now promoting comment content into a full blown post, but this sounded interesting to explore: Different interpretations of Acronyms.  When you type CIA into Acronymfinder, you get over 109 definitions, 16 specifically related to Information Technology and ‘Availability’ is listed specific to Information Security, while authenticity appears a few down the list.  I had originally learned the ‘A’ in CIA to be authenticity but being an F5er, I always thought about availability, had heard some refer to the ‘A’ as availability and mentioned that in the post (albeit in parentheses).  I did see the Wikipedia link Lawrence referenced while writing the original, but also ran across this link talking about ‘A’ as authenticity.  It was more to understand if I had been mislead or confused somewhere along the way.

Then I pondered that maybe CIA has morphed over time? Authenticity might have been the original intent or used initially due to the 'security' aspect of it all. Now, in a 24/7 global, regulatory contained, highly competitive marketplace, Availability of the data has become more paramount. Two frames of thought along with two somewhat independent reference links - Gotta love the internet!  That got nixed when I ran across the Parkerian Hexad entry in Wikipedia indicating Authenticity was added after

I must admit, now that I've searched much deeper, I've found more references to Availability than Authenticity yet plenty of opinions so Thank you Lawrence, I stand corrected – or at least, clarified.  Even my boss said he learned it as availability.  I also found this blog that talks about taking availability out of CIA.  Interestingly, I also found an article that had two references for 'I.' Integrity, of course and 'Accordingly, the "I" in "CIA" is also taken to mean "Identification",' and getting ID'd is a form of authentication.  Finally, this article lists both Authenticity & Availability.  We all win!! 

image

Moral of the story, 3 letter acronyms can mean a lot of things so make sure you know the various iterations – especially if you’re writing about it.  :-)

ps