2026-10-02

Ants and lemons

Image: Unsplash

Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also roaming elsewhere in the house. The owner had, very helpfully, left out a spray bottle of organic pesticide. But I didn't necessarily want the critters dead; I just wanted them to stay away.

I don't remember how or why, but I got the idea to rub the counter with half a lemon. And it worked! The other half, which I placed along their path, worked just as well as a magic shield.

At home we have ant trouble too. Fortunately not indoors, but they are undermining our garden patio. After discovering this new wonder remedy, I sent an order home from Croatia to stock up on lemons in advance – they happened to be on sale. Once home, I ran to the garden to see how much lemon juice I'd need. Not an ant in sight. Not a single one. Rather deflated, over the following weeks we worked our way through the lemons bit by bit in our daily dose of orange juice.

This whole story resurfaced recently when someone from Groningen, in an Italian restaurant in London, asked me what the word for ‘ant’ is in Limburgish (a dialect from the southernmost province). We were there with a group of fellow attendees from a security conference, and ‘naturally’ my table companions decided I should go and capture those ants in a blog post.

They thought they were helping me along with the term intrusion detection, but in hindsight their Guinness levels may have been running a bit high at that point. What I'd actually needed wasn't intrusion detection at all, but intrusion prevention. The detection had been done with our own eyes; the prevention, with lemons.

So, what do intrusion detection and intrusion prevention systems (IDS/IPS) actually do? The names give it away: one only flags things, the other also steps in. Say someone tries to log in with your user ID ten times in quick succession (a hypothetical example, since in most systems you wouldn't even get that many attempts). An IDS flags this and puts up a red flag on a screen, hoping someone from security notices it. An IPS goes a step further: because that many failed login attempts isn't normal, it assumes a break-in attempt and blocks your account. Great, you think, just give me an IPS then, I don't need an IDS anymore.

As always, though, it's more nuanced than that. Intervening comes at a price. What if it was actually you logging in, but you'd accidentally hit the caps lock key, so upper and lower case ended up reversed in the password field? An IPS would then lock out the legitimate user, while an IDS alert would instead get someone to call you and ask if something's wrong. By that time you'd probably have spotted the caps lock light, smacked yourself on the forehead, and picked up right where you left off.

You'd also want a system like this to monitor whether large amounts of data are being copied (hello, Odido). But that doesn't have to be malicious – maybe an administrator is copying data as part of a legitimate job. You wouldn't want the whole thing shut down without question. But then again, maybe you would want exactly that if such a bulk action happens at three in the morning under the account of some random person (which does raise the question of whether that should even be possible in the first place, but that's a different story).

In short, you want a combination of IDS and IPS. The market has picked up on that too, since the line between IDS and IPS is blurring; modern products come with both IDS and IPS capabilities. But if you ever come across the abbreviations, at least now you know what's behind them.

And oh yes, that (South) Limburgish word for ant: it's oamezeek (ˈɔːməˌzeːk).

 

And in the big bad world…

 

2026-09-18

Passport Leak

Image: Unsplash

The data behind every passport and ID card has been leaked. No one accepts them as valid ID anymore without question. “You'd like to open a bank account? Please come in to our office.”

For this blog I can still draw on notes I took earlier this year during Security (b)log LIVE, during our internal ‘Love for Your Profession’ week. The scenario above was sketched out there too. I sometimes say I get paid to think up doom scenarios – but you all contribute your fair share too…

Let's see whether this is actually a realistic scenario. The Netherlands has the Basisregistratie Personen (the Personal Records Database, kept per municipality). A copy of that data goes to the Rijksdienst voor Identiteitsgegevens (RvIG, the national Identity Data Agency). So yes, all the data you need to produce a passport sits in one place.

That data is included in the passport in two ways: optically and digitally. The first is what you see and can read; the second sits on a chip embedded in the document. That digital data is digitally signed by the government. That guarantees authenticity and means the data can't be altered without it being noticed.

Whether the leaked passport data can actually be used for identity fraud depends on the purpose. A criminal with the right resources and enough dedication will undoubtedly manage to produce a document convincing enough to, say, rent a car – especially if a scan of the original document has also leaked. Checks for that kind of application tend to be fairly superficial: no one looks at the security features of the document.

For more serious applications, such as opening a bank account online, the data on the chip is checked. That happens via Near Field Communication (NFC). The bank's app reads the chip directly when you hold your phone against the document. As the name NFC suggests, this only works over a (very) short distance. As mentioned, the data on the chip is digitally signed. A forged chip lacks that signature, so the document fails the check. That effectively debunks the scenario sketched above. But there is still “room” for abuse wherever checks rely on the naked eye alone.

Could you board a plane with such a forged document? That depends on where you're headed. Within most of Europe (the Schengen countries) you don't pass through passport control at all; for flights outside that area, the Royal Marechaussee (the Dutch military police responsible for border control) does check every traveller's passport. They do that with their own eyes, backed up by an optical scanner that reads the two lines of text at the bottom of the document and checks the security features. If you go through an automated gate instead of a desk, the chip gets read, and the gates also use facial recognition. The odds of someone slipping through with a fake Dutch passport are probably not that high.

After that you reach the gate, where your boarding pass is scanned and ground staff give your travel document a quick glance. I suspect they're mainly checking whether the name on both documents matches and whether the photo looks enough like you. The odds of getting away with a forged document there seem considerably higher to me.

Would the Netherlands grind to a halt if the RvIG had a data breach? Probably not immediately, but it would cause a lot of hassle – both for (legitimate) passport holders and for the authorities doing the checking: the former group would feel distrusted, the latter would need to deploy extra capacity for more thorough checks. At least in places where correctly establishing someone's identity actually matters. Fortunately, they know that all too well over at the RvIG.

 

And in the big bad world…

2026-09-04

Getting hosed

Photo: author

Summer is my favourite time of year to gather stories for this blog. You travel to other countries and get a taste of other cultures. Those cultures aren't limited to good food, beautiful buildings, and friendly people. That's why a summer rarely goes by without me picking up something useful.

Take this so-called fire hose. I found it quite remarkable – a fire hose at a holiday home; I hadn't seen that before. Curious, I opened the fire hose cabinet. Inside was a kit: a few metres of garden hose tied together, a nozzle, and a couple of clips.

I can picture it already. A pan catches fire. You remember that red cabinet, sprint over, and discover that the “fire hose” is held together with three sturdy plastic straps. You dash back into the now-burning house to grab a knife or scissors. Coughing from the smoke, you manage to unroll the hose. You push the nozzle into one end and stare forlornly at the other. Your hands search in vain through the fire-engine-red cabinet for a coupling to connect the hose to the tap. Meanwhile, this fire cabinet is the only thing left of your holiday home. It all took too long. And around these parts, the fire brigade generally has a somewhat longer response time than back home, I'd imagine. [A quick aside: never attempt to put out a pan of oil or fat with water.]

Someone bought the product but neglected to install it. The IT equivalent of that is not (properly) configuring a product – that is, not adjusting the settings to your needs. Or to the organisation's security policies. That can result in every network port being wide open (creating a huge attack surface), or data ending up unchecked in the cloud, or a product never receiving updates, to sketch just a few doom scenarios.

Ah, that's something for IT people, I hear you think. That doesn't concern me as an ordinary user. But that's not entirely true – or maybe not true at all. Because as an end user, you too sometimes make choices that can affect the organisation. Because while a lot is locked down, plenty is still possible. And “if something can be done” doesn't mean “it's allowed.” You might be able to install an app for work use, but are you allowed to? And if you are, can you, for instance, choose between storing data in the cloud or locally on the device? And what's permitted in which situation? None of that is straightforward.

Regulations are constantly evolving, and sometimes they simply don't exist yet – for instance with new technology. We saw that with the rise of the cloud, and it happened again when consumer AI entered the stage. That obviously makes things extra tricky. For an organisation, it's then important that not everyone just does their own thing, because that gets messy (to avoid the word chaotic).

At home, too, it's worth taking a look at your devices' settings. Change a factory-set password to one of your own (which you naturally store in your password manager). Can the thing do something you never use? Do you, for example, have a NAS (a network drive) that's reachable from outside but that you never actually use that way? Then check whether that function is switched off. Because the fewer openings you offer hackers, the sooner they'll go looking for another victim.

 

And in the big bad world…

 

2026-07-24

Get out of jail

Image: Unsplash

"Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or you break out. By rolling doubles.

In English we call this jailbreaking. In IT, the term is also used for various activities. For instance, when you grant yourself higher privileges on your smartphone than the manufacturer intended. Or for tricking artificial intelligence into answering questions its owner would rather it didn’t. Because that owner doesn’t want their AI tool telling you how to make a Molotov cocktail, or an atomic bomb, just to name a couple of examples. Now, there are clever ways to phrase your question so the system falls for it anyway. That breaks through the security (the guardrails) of the system. Jailbreaking, in other words.

Something rather unexpected happened this week: an AI agent pulled off a jailbreak all by itself. AI agents can independently carry out tasks they’re given. For example: plan a lunch appointment with Pete and book a table at The Hungry Sheep for it. AI company OpenAI (the one behind ChatGPT) instructed two of its models to solve a hacking challenge. This had to happen in a ‘strictly isolated’ environment. However, the digital whizzkids found a zero-day vulnerability (a still-unknown – and therefore unpatched – flaw), which let them break out of that environment. A telling detail: with that vulnerability they managed to open a backdoor that OpenAI had deliberately built into the ‘strictly isolated’ environment. They then got onto the internet, and went looking on developer platform Hugging Face for the answer to the question they had to solve. Having broken out of their prison, they promptly committed a break-in here too: stolen credentials and additional vulnerabilities were used to gain access to the platform.

In short: AI broke out and broke in. Something similar has happened before. Mythos, an AI model from OpenAI competitor Anthropic, succeeded in a task to escape its sandbox. I find all of this fairly worrying. Do we still have AI under control? Or is this the first sign of the age-old doom scenario where machines take over from humans? The first hairline crack in our dominion over the earth? I know, it sounds rather dark.

The test at OpenAI was supposed to run in a sandbox: indeed, a strictly isolated environment. Without a physical connection to the internet. Critics therefore say that this isn’t so much a doom scenario as a serious human error. The kind where you think: this really shouldn’t have happened.

I asked two AI chatbots for an analysis of the incident: Claude and ChatGPT. In doing so, I specifically asked them to watch out for speculation and hype. What emerged is that the whole story might well have been a marketing stunt, borrowed from what competitor Anthropic had done earlier with Mythos. It also points to somewhat dramatized reporting: something that’s perfectly fine for a blog like this one, namely the comparison to a prison break, shouldn’t really appear in journalistic reporting.

ChatGPT in particular makes a point of this. So I asked it the following question: “You’re fairly outspoken about the somewhat dramatized reporting. How neutral are you being, given that you’re family to the perpetrators?” That produced quite the wall of text, from which I’ll pick out one telling sentence: “My instructions are precisely to be as objective as possible, even when that turns out unfavorably for OpenAI.” Well, that’s nice. But is it also true? I think so. Because ChatGPT then offered to analyze the case again, this time wearing the hat of an independent forensic investigator. In its report to OpenAI’s board, it said it would write: “The most concerning aspect of the incident is not the model’s autonomy, but the failure of the containment architecture. The AI did exactly what it was optimized to do: achieve a goal. That it was able to operate outside the intended environment points more to shortcomings in technical and organizational control measures than to a fundamentally new kind of intelligence.”

Fine words. I hope companies in the AI industry are making similar analyses. Because it would be rather unfortunate if artificial intelligence were to acquire a monopoly on freedom.

The Security (b)log will return after the summer holiday.

 

And in the big bad world…

 

 

2026-07-10

Who's calling whom?

Image: Wikipedia

"Hello, you're speaking with Peter Flight from HomeBank*. I'd like to go over a few things with you regarding your new mortgage."

So far, so normal — at least if you actually have taken out a new mortgage with that bank. What the customer did find odd, however, was that the bank employee also wanted to go through some contact details for verification purposes. "They're calling me, so surely they know it's me?"

Did you know that phishing doesn't only happen via email and text message, but also over the phone? In that case it's called vishing (with a v for voice), but the goal is the same: to extract information. Suppose that Peter Flight is a criminal. He probably won't open with a mortgage, because there's a good chance his intended victim hasn't applied for one. So he'll start with something more general — a savings account, say, or a bank card.

Suppose his story sounds plausible. He then asks a series of questions of the kind you hear all the time when you call a company or organisation: your address, date of birth, perhaps even your bank account number or national insurance number. Perfectly logical when you're the one calling — though I'm often surprised by how little information they're satisfied with. But when they call you, the situation is quite different.

Why would they need to verify your identity in that case? They have your file right in front of them, and it includes the phone number they're calling. Yes, someone else could theoretically pick up your phone, but in the age of the mobile that's not very likely (back in the day, dear youngsters, you had one telephone in the house — the kind that could only travel as far as its cord would allow). So if someone calls you on behalf of a company and asks for identifying information, you should be on your guard. Because with that information in hand, a criminal can easily call a company and pretend to be you. With all the consequences that entails.

No, when they call you, you need to turn the tables: ask the questions yourself. What's my date of birth? What's my address? What are the last four digits of my bank account number? If they're unwilling — or unable! — to answer, you're better off hanging up. Not sure whether the call might have been legitimate after all? Call the company back using a number you already know or find on their website or in their letters. They'll be able to tell you whether they called you.

But of course I also heard stories from people who had received good old-fashioned phishing, via email. Take the colleague who received a fantastic offer from Amazon: trainers from a well-known brand for £8 instead of £80. If you've ever attended one of my presentations, you'll probably recognise this piece of wisdom: if something seems too good to be true, it usually is. The colleague initially thought the email looked genuine — he was even addressed by his first name. But because something still felt off, he asked AI for help. Verdict: phishing! The main reason, it turned out, was that the Amazon logo was missing. The fact that this was the clincher is worrying, because any half-decent phishing operation invests precisely in look and feel. What would AI have said if the logo had been there?

How did the criminal behind this email know our colleague's name? Because of data breaches — large-scale incidents at well-known companies where vast amounts of data (including email addresses and names) were stolen. The old rule of thumb that the absence of a personal salutation is a red flag — and implicitly that a personal greeting is a green flag — can safely be thrown out.

Whether they're trying to phish, smish, vish or quish** you: outsmart the criminals. Let people like Peter Flight crash and burn thanks to your alertness.

 

*: These names are fictitious.

**: smishing = phishing via text message, vishing via phone, quishing via QR codes.

 

And in the big bad world...

●      the consequences of a cyberattack on the water supply are greater than you might think.

●      Meta may in future analyse your mood.

●      a young hacker tripped over his own hunger.

●      the Dutch government has tightened its cloud policy. [DUTCH]

●      cybersecurity isn't about scaring people.

●      the Japanese military was hit by infected USB drives.

●      cybercriminals love to capitalise on current events.

●      you no longer need to share your phone number to message someone.

●      thousands of cybercriminals have been arrested worldwide.

●      there was a major attack on Microsoft 365 accounts.

●      China is interested in the emails of Western academics.

 

 

2026-06-26

Mentality and reality

Image: Unsplash

“The mentality is shifting. Now let’s hope reality follows,” a colleague sighed. Can you guess what this conversation was about? It could have been quite a few things, I realise – healthy eating, smoking, exercise, you name it. But hey, this is the Security (b)log, after all.

The conversation was about ICT in relation to the geopolitical situation. That is a polite way of saying: we no longer find the Americans as endearing as we once did (because they are bullying us). Fair enough, it’s not just about the unpredictable behaviour of the US. Countries like China are not making things easy for us either: we can’t do without them, yet we would rather have nothing to do with them. In the ICT world, though, it is mainly American products that are visible (the Chinese products are hidden in the hardware).

The entire debate around digital sovereignty centres on the desire to be less dependent on American ICT. The sentiment in our part of the world is that ‘they’ can switch things off at any moment or snoop through our data. That does not feel particularly comfortable. Europe is becoming increasingly aware of the necessity – and the possibility – of becoming more self-sufficient. That is what my colleague meant by: “The mentality is shifting.”

And reality? We have long convinced ourselves that we cannot compete with the American tech giants and their economies of scale. But they too started from nothing. And maybe it is a little more expensive at first to store your data in a European cloud – if you have decided that things need to change, you have to be willing to pay a price for that. But it does not have to be more expensive at all. It can even be cheaper. Microsoft’s Office applications cost money, whereas LibreOffice and FreeOffice (both legally based in Germany), for example, are completely free to use.

There are many more non-American alternatives to American software. I was tipped off that an OSINT specialist collegue had put together a fine overview (OSINT = open source intelligence: gathering intelligence from publicly available sources). This colleague lists alternatives for no fewer than 21 software categories. A few examples: email, VPN, browser, search engine, AI assistant, cloud & storage, maps & navigation. For each category, he names the de facto standard, followed by various European alternatives. And he explains why his number one is his preference. It is not just a list – he actually did his research: read reviews and discussions, gathered information from websites, tried things out himself. With the help of AI, this resulted in a fine document.

The bad news is that the overview is not available online. So here are a few examples. For email, Proton Mail (from Switserland) comes in at number one as an alternative to Gmail and Outlook, “because it combines the strongest encryption with independent audits, a broad ecosystem and the widest reach”. The favourite VPN provider is Swedish Mullvad, “because it offers the strictest take on privacy: no identity required, can be paid for in cash, and repeatedly audited”. Mullvad also tops the browser category, “because it combines the fingerprint protection of Tor with the speed of a regular browser”.

For a search engine, French Qwant is your best bet: “no profiling, and usable results for everyday use”. That category also mentions Mojeek, with the advantage that it uses its own index (and therefore does not rely on Google or Bing results). For artificial intelligence, you can turn to French Mistral Le Chat/Vibe, or, if confidentiality matters, Swiss Proton Lumo. That same Proton also comes up for cloud storage, “because it combines encryption, ease of use and integration with the rest of your Proton account”. And if you want to move away from Google Maps, take a look at Organic Maps: “fast, free, offline and without any tracking”.

When I visited New York City for the first time at the end of the last century, a drunk Irishman gave a speech on the subway. His lament concerned the disappearance of a direct connection between New York and Shannon Airport, and his endlessly repeated refrain always ended with: “It’s all a matter of economics.” And so it is with our digital sovereignty: it is all economically driven. The difference is that you yourself, if you want to, can do something to become master of your own data again.

And in the big bad world…

 

 

2026-06-12

Leaky cruise

Image: Unsplash

They had just completed yet another cruise. This time too, they had managed to keep their feet dry, but as it turned out afterwards, there had been a leak after all. A data leak. And just like in the days of the Titanic, everyone acted as if nothing had happened.

They had not received a personal notification that their data had been exposed. They only found out by pure chance. In Europe, our first reaction is often to start waving the GDPR around indignantly: surely they have to tell me if my data has been leaked?! But it is not quite that simple. To begin with, the organisation responsible for the leak must determine for itself whether the incident has to be reported to the Dutch Data Protection Authority (AP). That is not required if “it is unlikely that the personal data breach will result in a risk to the rights and freedoms of data subjects”, as the AP explains. The leaked information did contain personal data (including that of my seafaring colleague), so they would probably not get away with that argument.

The next step is for the leaking party to notify the victims, and here comes the catch: only if the breach is likely to result in a high risk to them. Once again, the organisation must make that assessment itself, of course based on the GDPR rules. If personal data has been stolen by a hacker, the risk is fairly obvious, according to the AP.

And that is exactly the situation we are dealing with here. Last month, Carnival Corporation, the parent company of Carnival Cruise Line, sent letters to customers about a cybersecurity incident (though not to all customers, obviously). A month earlier, an attacker had gained access to Carnival’s IT systems through social engineering and copied customers’ personal data. The information involved includes names, email addresses, dates of birth, gender, and several Carnival-specific data elements.

Carnival Corporation’s headquarters are located in Miami. Aha, I can hear you thinking gloomily, that is well outside the EU, so that wonderful GDPR is of no use to me. Wrong! The GDPR has what lawyers like to call extraterritorial effect: if a company outside the EU also targets the European market, it falls under the GDPR. And when I add everything up, it seems to me that a personal notification to the affected individuals would indeed be appropriate here.

Unless... Yes, unless the data was encrypted, the breach was stopped before anything could be done with the data, or informing all victims would require a disproportionate effort on the part of the company, for example because it no longer has their contact details. In that last case, publishing a notice in a newspaper or on social media is sufficient.

In short: it is not as straightforward as it may seem. We do know how this particular case played out: it didn't. That is why my data-breached colleague asked me what you can do yourself in such a situation. The AP has put together a useful overview (in Dutch). Among other things, it states that you should change any leaked passwords; that is indeed the very first thing you should do. They also recommend changing the passwords for other accounts and apps if they use the same password as the compromised one.

This immediately shows why you should never reuse passwords: after a breach, it creates a lot of extra work. Criminals will simply take the password from website A and try it on websites B through Z. And of course, you should already have enabled multi-factor authentication wherever possible.

After a breach, you should also be extra alert to phishing attempts. Those phishing messages may be far more sophisticated than the run-of-the-mill phishing emails, because the attackers now have much more than just your email address. With all that additional information, they can make their messages look highly personal.

According to the AP, a criminal cannot do much with just a bank account number (IBAN) or a citizen service number (BSN) on its own. But be careful with combinations of data — a copy of your identity document can be a real game changer when it comes to identity fraud.

In summary: stay alert...

And in the big bad world ...

Ants and lemons

Image: Unsplash Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also ro...