| Photo: author |
Summer is my favourite time of year to gather stories for this blog. You travel to other countries and get a taste of other cultures. Those cultures aren't limited to good food, beautiful buildings, and friendly people. That's why a summer rarely goes by without me picking up something useful.
Take
this so-called fire hose. I found it quite remarkable – a fire hose at a
holiday home; I hadn't seen that before. Curious, I opened the fire hose
cabinet. Inside was a kit: a few metres of garden hose tied together, a nozzle,
and a couple of clips.
I can
picture it already. A pan catches fire. You remember that red cabinet, sprint
over, and discover that the “fire hose” is held together with three sturdy
plastic straps. You dash back into the now-burning house to grab a knife or
scissors. Coughing from the smoke, you manage to unroll the hose. You push the
nozzle into one end and stare forlornly at the other. Your hands search in vain
through the fire-engine-red cabinet for a coupling to connect the hose to the
tap. Meanwhile, this fire cabinet is the only thing left of your holiday home.
It all took too long. And around these parts, the fire brigade generally has a
somewhat longer response time than back home, I'd imagine. [A quick aside:
never attempt to put out a pan of oil or fat with water.]
Someone
bought the product but neglected to install it. The IT equivalent of that is
not (properly) configuring a product – that is, not adjusting the settings to
your needs. Or to the organisation's security policies. That can result in
every network port being wide open (creating a huge attack surface), or data
ending up unchecked in the cloud, or a product never receiving updates, to
sketch just a few doom scenarios.
Ah,
that's something for IT people, I hear you think. That doesn't concern me as an
ordinary user. But that's not entirely true – or maybe not true at all. Because
as an end user, you too sometimes make choices that can affect the
organisation. Because while a lot is locked down, plenty is still possible. And
“if something can be done” doesn't mean “it's allowed.” You might be able to
install an app for work use, but are you allowed to? And if you are, can you,
for instance, choose between storing data in the cloud or locally on the
device? And what's permitted in which situation? None of that is
straightforward.
Regulations
are constantly evolving, and sometimes they simply don't exist yet – for
instance with new technology. We saw that with the rise of the cloud, and it
happened again when consumer AI entered the stage. That obviously makes things
extra tricky. For an organisation, it's then important that not everyone just
does their own thing, because that gets messy (to avoid the word chaotic).
At home,
too, it's worth taking a look at your devices' settings. Change a factory-set
password to one of your own (which you naturally store in your password
manager). Can the thing do something you never use? Do you, for example, have a
NAS (a network drive) that's reachable from outside but that you never actually
use that way? Then check whether that function is switched off. Because the
fewer openings you offer hackers, the sooner they'll go looking for another
victim.
And in the big bad world…
- phishers used remote-support software and Canadian tax forms in an international campaign.
- this website tracks AI mishaps and jailbreaks.
- cybercriminals skipped their summer holiday.
- a hacker who made heavy use of AI also left an audit report behind for his victim.
- Google turns out to host thousands of misleading ads, researchers discovered using a Google tool.
- an ethical hacker who got no response sent an email from an account belonging to that vulnerable company.
- hackers used AI guardrails to disable AI-based security tooling.
- one company actually offers removing AI guardrails as a service.
- AI has actually hacked companies on its own quite a few times already.
- fake CAPTCHAs are being used for social engineering.
No comments:
Post a Comment