Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

2026-10-02

Ants and lemons

Image: Unsplash

Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also roaming elsewhere in the house. The owner had, very helpfully, left out a spray bottle of organic pesticide. But I didn't necessarily want the critters dead; I just wanted them to stay away.

I don't remember how or why, but I got the idea to rub the counter with half a lemon. And it worked! The other half, which I placed along their path, worked just as well as a magic shield.

At home we have ant trouble too. Fortunately not indoors, but they are undermining our garden patio. After discovering this new wonder remedy, I sent an order home from Croatia to stock up on lemons in advance – they happened to be on sale. Once home, I ran to the garden to see how much lemon juice I'd need. Not an ant in sight. Not a single one. Rather deflated, over the following weeks we worked our way through the lemons bit by bit in our daily dose of orange juice.

This whole story resurfaced recently when someone from Groningen, in an Italian restaurant in London, asked me what the word for ‘ant’ is in Limburgish (a dialect from the southernmost province). We were there with a group of fellow attendees from a security conference, and ‘naturally’ my table companions decided I should go and capture those ants in a blog post.

They thought they were helping me along with the term intrusion detection, but in hindsight their Guinness levels may have been running a bit high at that point. What I'd actually needed wasn't intrusion detection at all, but intrusion prevention. The detection had been done with our own eyes; the prevention, with lemons.

So, what do intrusion detection and intrusion prevention systems (IDS/IPS) actually do? The names give it away: one only flags things, the other also steps in. Say someone tries to log in with your user ID ten times in quick succession (a hypothetical example, since in most systems you wouldn't even get that many attempts). An IDS flags this and puts up a red flag on a screen, hoping someone from security notices it. An IPS goes a step further: because that many failed login attempts isn't normal, it assumes a break-in attempt and blocks your account. Great, you think, just give me an IPS then, I don't need an IDS anymore.

As always, though, it's more nuanced than that. Intervening comes at a price. What if it was actually you logging in, but you'd accidentally hit the caps lock key, so upper and lower case ended up reversed in the password field? An IPS would then lock out the legitimate user, while an IDS alert would instead get someone to call you and ask if something's wrong. By that time you'd probably have spotted the caps lock light, smacked yourself on the forehead, and picked up right where you left off.

You'd also want a system like this to monitor whether large amounts of data are being copied (hello, Odido). But that doesn't have to be malicious – maybe an administrator is copying data as part of a legitimate job. You wouldn't want the whole thing shut down without question. But then again, maybe you would want exactly that if such a bulk action happens at three in the morning under the account of some random person (which does raise the question of whether that should even be possible in the first place, but that's a different story).

In short, you want a combination of IDS and IPS. The market has picked up on that too, since the line between IDS and IPS is blurring; modern products come with both IDS and IPS capabilities. But if you ever come across the abbreviations, at least now you know what's behind them.

And oh yes, that (South) Limburgish word for ant: it's oamezeek (ˈɔːməˌzeːk).

 

And in the big bad world…

 

2026-09-18

Passport Leak

Image: Unsplash

The data behind every passport and ID card has been leaked. No one accepts them as valid ID anymore without question. “You'd like to open a bank account? Please come in to our office.”

For this blog I can still draw on notes I took earlier this year during Security (b)log LIVE, during our internal ‘Love for Your Profession’ week. The scenario above was sketched out there too. I sometimes say I get paid to think up doom scenarios – but you all contribute your fair share too…

Let's see whether this is actually a realistic scenario. The Netherlands has the Basisregistratie Personen (the Personal Records Database, kept per municipality). A copy of that data goes to the Rijksdienst voor Identiteitsgegevens (RvIG, the national Identity Data Agency). So yes, all the data you need to produce a passport sits in one place.

That data is included in the passport in two ways: optically and digitally. The first is what you see and can read; the second sits on a chip embedded in the document. That digital data is digitally signed by the government. That guarantees authenticity and means the data can't be altered without it being noticed.

Whether the leaked passport data can actually be used for identity fraud depends on the purpose. A criminal with the right resources and enough dedication will undoubtedly manage to produce a document convincing enough to, say, rent a car – especially if a scan of the original document has also leaked. Checks for that kind of application tend to be fairly superficial: no one looks at the security features of the document.

For more serious applications, such as opening a bank account online, the data on the chip is checked. That happens via Near Field Communication (NFC). The bank's app reads the chip directly when you hold your phone against the document. As the name NFC suggests, this only works over a (very) short distance. As mentioned, the data on the chip is digitally signed. A forged chip lacks that signature, so the document fails the check. That effectively debunks the scenario sketched above. But there is still “room” for abuse wherever checks rely on the naked eye alone.

Could you board a plane with such a forged document? That depends on where you're headed. Within most of Europe (the Schengen countries) you don't pass through passport control at all; for flights outside that area, the Royal Marechaussee (the Dutch military police responsible for border control) does check every traveller's passport. They do that with their own eyes, backed up by an optical scanner that reads the two lines of text at the bottom of the document and checks the security features. If you go through an automated gate instead of a desk, the chip gets read, and the gates also use facial recognition. The odds of someone slipping through with a fake Dutch passport are probably not that high.

After that you reach the gate, where your boarding pass is scanned and ground staff give your travel document a quick glance. I suspect they're mainly checking whether the name on both documents matches and whether the photo looks enough like you. The odds of getting away with a forged document there seem considerably higher to me.

Would the Netherlands grind to a halt if the RvIG had a data breach? Probably not immediately, but it would cause a lot of hassle – both for (legitimate) passport holders and for the authorities doing the checking: the former group would feel distrusted, the latter would need to deploy extra capacity for more thorough checks. At least in places where correctly establishing someone's identity actually matters. Fortunately, they know that all too well over at the RvIG.

 

And in the big bad world…

2026-09-04

Getting hosed

Photo: author

Summer is my favourite time of year to gather stories for this blog. You travel to other countries and get a taste of other cultures. Those cultures aren't limited to good food, beautiful buildings, and friendly people. That's why a summer rarely goes by without me picking up something useful.

Take this so-called fire hose. I found it quite remarkable – a fire hose at a holiday home; I hadn't seen that before. Curious, I opened the fire hose cabinet. Inside was a kit: a few metres of garden hose tied together, a nozzle, and a couple of clips.

I can picture it already. A pan catches fire. You remember that red cabinet, sprint over, and discover that the “fire hose” is held together with three sturdy plastic straps. You dash back into the now-burning house to grab a knife or scissors. Coughing from the smoke, you manage to unroll the hose. You push the nozzle into one end and stare forlornly at the other. Your hands search in vain through the fire-engine-red cabinet for a coupling to connect the hose to the tap. Meanwhile, this fire cabinet is the only thing left of your holiday home. It all took too long. And around these parts, the fire brigade generally has a somewhat longer response time than back home, I'd imagine. [A quick aside: never attempt to put out a pan of oil or fat with water.]

Someone bought the product but neglected to install it. The IT equivalent of that is not (properly) configuring a product – that is, not adjusting the settings to your needs. Or to the organisation's security policies. That can result in every network port being wide open (creating a huge attack surface), or data ending up unchecked in the cloud, or a product never receiving updates, to sketch just a few doom scenarios.

Ah, that's something for IT people, I hear you think. That doesn't concern me as an ordinary user. But that's not entirely true – or maybe not true at all. Because as an end user, you too sometimes make choices that can affect the organisation. Because while a lot is locked down, plenty is still possible. And “if something can be done” doesn't mean “it's allowed.” You might be able to install an app for work use, but are you allowed to? And if you are, can you, for instance, choose between storing data in the cloud or locally on the device? And what's permitted in which situation? None of that is straightforward.

Regulations are constantly evolving, and sometimes they simply don't exist yet – for instance with new technology. We saw that with the rise of the cloud, and it happened again when consumer AI entered the stage. That obviously makes things extra tricky. For an organisation, it's then important that not everyone just does their own thing, because that gets messy (to avoid the word chaotic).

At home, too, it's worth taking a look at your devices' settings. Change a factory-set password to one of your own (which you naturally store in your password manager). Can the thing do something you never use? Do you, for example, have a NAS (a network drive) that's reachable from outside but that you never actually use that way? Then check whether that function is switched off. Because the fewer openings you offer hackers, the sooner they'll go looking for another victim.

 

And in the big bad world…

 

2026-07-24

Get out of jail

Image: Unsplash

"Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or you break out. By rolling doubles.

In English we call this jailbreaking. In IT, the term is also used for various activities. For instance, when you grant yourself higher privileges on your smartphone than the manufacturer intended. Or for tricking artificial intelligence into answering questions its owner would rather it didn’t. Because that owner doesn’t want their AI tool telling you how to make a Molotov cocktail, or an atomic bomb, just to name a couple of examples. Now, there are clever ways to phrase your question so the system falls for it anyway. That breaks through the security (the guardrails) of the system. Jailbreaking, in other words.

Something rather unexpected happened this week: an AI agent pulled off a jailbreak all by itself. AI agents can independently carry out tasks they’re given. For example: plan a lunch appointment with Pete and book a table at The Hungry Sheep for it. AI company OpenAI (the one behind ChatGPT) instructed two of its models to solve a hacking challenge. This had to happen in a ‘strictly isolated’ environment. However, the digital whizzkids found a zero-day vulnerability (a still-unknown – and therefore unpatched – flaw), which let them break out of that environment. A telling detail: with that vulnerability they managed to open a backdoor that OpenAI had deliberately built into the ‘strictly isolated’ environment. They then got onto the internet, and went looking on developer platform Hugging Face for the answer to the question they had to solve. Having broken out of their prison, they promptly committed a break-in here too: stolen credentials and additional vulnerabilities were used to gain access to the platform.

In short: AI broke out and broke in. Something similar has happened before. Mythos, an AI model from OpenAI competitor Anthropic, succeeded in a task to escape its sandbox. I find all of this fairly worrying. Do we still have AI under control? Or is this the first sign of the age-old doom scenario where machines take over from humans? The first hairline crack in our dominion over the earth? I know, it sounds rather dark.

The test at OpenAI was supposed to run in a sandbox: indeed, a strictly isolated environment. Without a physical connection to the internet. Critics therefore say that this isn’t so much a doom scenario as a serious human error. The kind where you think: this really shouldn’t have happened.

I asked two AI chatbots for an analysis of the incident: Claude and ChatGPT. In doing so, I specifically asked them to watch out for speculation and hype. What emerged is that the whole story might well have been a marketing stunt, borrowed from what competitor Anthropic had done earlier with Mythos. It also points to somewhat dramatized reporting: something that’s perfectly fine for a blog like this one, namely the comparison to a prison break, shouldn’t really appear in journalistic reporting.

ChatGPT in particular makes a point of this. So I asked it the following question: “You’re fairly outspoken about the somewhat dramatized reporting. How neutral are you being, given that you’re family to the perpetrators?” That produced quite the wall of text, from which I’ll pick out one telling sentence: “My instructions are precisely to be as objective as possible, even when that turns out unfavorably for OpenAI.” Well, that’s nice. But is it also true? I think so. Because ChatGPT then offered to analyze the case again, this time wearing the hat of an independent forensic investigator. In its report to OpenAI’s board, it said it would write: “The most concerning aspect of the incident is not the model’s autonomy, but the failure of the containment architecture. The AI did exactly what it was optimized to do: achieve a goal. That it was able to operate outside the intended environment points more to shortcomings in technical and organizational control measures than to a fundamentally new kind of intelligence.”

Fine words. I hope companies in the AI industry are making similar analyses. Because it would be rather unfortunate if artificial intelligence were to acquire a monopoly on freedom.

The Security (b)log will return after the summer holiday.

 

And in the big bad world…

 

 

2026-06-26

Mentality and reality

Image: Unsplash

“The mentality is shifting. Now let’s hope reality follows,” a colleague sighed. Can you guess what this conversation was about? It could have been quite a few things, I realise – healthy eating, smoking, exercise, you name it. But hey, this is the Security (b)log, after all.

The conversation was about ICT in relation to the geopolitical situation. That is a polite way of saying: we no longer find the Americans as endearing as we once did (because they are bullying us). Fair enough, it’s not just about the unpredictable behaviour of the US. Countries like China are not making things easy for us either: we can’t do without them, yet we would rather have nothing to do with them. In the ICT world, though, it is mainly American products that are visible (the Chinese products are hidden in the hardware).

The entire debate around digital sovereignty centres on the desire to be less dependent on American ICT. The sentiment in our part of the world is that ‘they’ can switch things off at any moment or snoop through our data. That does not feel particularly comfortable. Europe is becoming increasingly aware of the necessity – and the possibility – of becoming more self-sufficient. That is what my colleague meant by: “The mentality is shifting.”

And reality? We have long convinced ourselves that we cannot compete with the American tech giants and their economies of scale. But they too started from nothing. And maybe it is a little more expensive at first to store your data in a European cloud – if you have decided that things need to change, you have to be willing to pay a price for that. But it does not have to be more expensive at all. It can even be cheaper. Microsoft’s Office applications cost money, whereas LibreOffice and FreeOffice (both legally based in Germany), for example, are completely free to use.

There are many more non-American alternatives to American software. I was tipped off that an OSINT specialist collegue had put together a fine overview (OSINT = open source intelligence: gathering intelligence from publicly available sources). This colleague lists alternatives for no fewer than 21 software categories. A few examples: email, VPN, browser, search engine, AI assistant, cloud & storage, maps & navigation. For each category, he names the de facto standard, followed by various European alternatives. And he explains why his number one is his preference. It is not just a list – he actually did his research: read reviews and discussions, gathered information from websites, tried things out himself. With the help of AI, this resulted in a fine document.

The bad news is that the overview is not available online. So here are a few examples. For email, Proton Mail (from Switserland) comes in at number one as an alternative to Gmail and Outlook, “because it combines the strongest encryption with independent audits, a broad ecosystem and the widest reach”. The favourite VPN provider is Swedish Mullvad, “because it offers the strictest take on privacy: no identity required, can be paid for in cash, and repeatedly audited”. Mullvad also tops the browser category, “because it combines the fingerprint protection of Tor with the speed of a regular browser”.

For a search engine, French Qwant is your best bet: “no profiling, and usable results for everyday use”. That category also mentions Mojeek, with the advantage that it uses its own index (and therefore does not rely on Google or Bing results). For artificial intelligence, you can turn to French Mistral Le Chat/Vibe, or, if confidentiality matters, Swiss Proton Lumo. That same Proton also comes up for cloud storage, “because it combines encryption, ease of use and integration with the rest of your Proton account”. And if you want to move away from Google Maps, take a look at Organic Maps: “fast, free, offline and without any tracking”.

When I visited New York City for the first time at the end of the last century, a drunk Irishman gave a speech on the subway. His lament concerned the disappearance of a direct connection between New York and Shannon Airport, and his endlessly repeated refrain always ended with: “It’s all a matter of economics.” And so it is with our digital sovereignty: it is all economically driven. The difference is that you yourself, if you want to, can do something to become master of your own data again.

And in the big bad world…

 

 

2026-06-12

Leaky cruise

Image: Unsplash

They had just completed yet another cruise. This time too, they had managed to keep their feet dry, but as it turned out afterwards, there had been a leak after all. A data leak. And just like in the days of the Titanic, everyone acted as if nothing had happened.

They had not received a personal notification that their data had been exposed. They only found out by pure chance. In Europe, our first reaction is often to start waving the GDPR around indignantly: surely they have to tell me if my data has been leaked?! But it is not quite that simple. To begin with, the organisation responsible for the leak must determine for itself whether the incident has to be reported to the Dutch Data Protection Authority (AP). That is not required if “it is unlikely that the personal data breach will result in a risk to the rights and freedoms of data subjects”, as the AP explains. The leaked information did contain personal data (including that of my seafaring colleague), so they would probably not get away with that argument.

The next step is for the leaking party to notify the victims, and here comes the catch: only if the breach is likely to result in a high risk to them. Once again, the organisation must make that assessment itself, of course based on the GDPR rules. If personal data has been stolen by a hacker, the risk is fairly obvious, according to the AP.

And that is exactly the situation we are dealing with here. Last month, Carnival Corporation, the parent company of Carnival Cruise Line, sent letters to customers about a cybersecurity incident (though not to all customers, obviously). A month earlier, an attacker had gained access to Carnival’s IT systems through social engineering and copied customers’ personal data. The information involved includes names, email addresses, dates of birth, gender, and several Carnival-specific data elements.

Carnival Corporation’s headquarters are located in Miami. Aha, I can hear you thinking gloomily, that is well outside the EU, so that wonderful GDPR is of no use to me. Wrong! The GDPR has what lawyers like to call extraterritorial effect: if a company outside the EU also targets the European market, it falls under the GDPR. And when I add everything up, it seems to me that a personal notification to the affected individuals would indeed be appropriate here.

Unless... Yes, unless the data was encrypted, the breach was stopped before anything could be done with the data, or informing all victims would require a disproportionate effort on the part of the company, for example because it no longer has their contact details. In that last case, publishing a notice in a newspaper or on social media is sufficient.

In short: it is not as straightforward as it may seem. We do know how this particular case played out: it didn't. That is why my data-breached colleague asked me what you can do yourself in such a situation. The AP has put together a useful overview (in Dutch). Among other things, it states that you should change any leaked passwords; that is indeed the very first thing you should do. They also recommend changing the passwords for other accounts and apps if they use the same password as the compromised one.

This immediately shows why you should never reuse passwords: after a breach, it creates a lot of extra work. Criminals will simply take the password from website A and try it on websites B through Z. And of course, you should already have enabled multi-factor authentication wherever possible.

After a breach, you should also be extra alert to phishing attempts. Those phishing messages may be far more sophisticated than the run-of-the-mill phishing emails, because the attackers now have much more than just your email address. With all that additional information, they can make their messages look highly personal.

According to the AP, a criminal cannot do much with just a bank account number (IBAN) or a citizen service number (BSN) on its own. But be careful with combinations of data — a copy of your identity document can be a real game changer when it comes to identity fraud.

In summary: stay alert...

And in the big bad world ...

2026-05-29

Frankenstein's AI

Image: Pixabay

My timelines are overflowing with it right now. And then there was that insistent nudge from a colleague: surely I wasn't going to let this go with just a link from the big bad world? I'd have to write a whole blog post about it. We're talking about Mythos, the AI that might just be too clever for its own good.

Mythos is Anthropic's latest AI model; its full name is Claude Mythos Preview. This model is so good at finding ICT vulnerabilities that the company doesn't dare release it to the public. And Mythos goes much further than that: it doesn't just find vulnerabilities – it can immediately produce ready-to-use exploits for them, and then go ahead and use those exploits as well. All without any human involvement. You can quite reasonably think of it as a weapon.

To give you an idea of the scale: in open-source projects, the model found over 23,000 vulnerabilities, of which around 6,200 were rated as high or critical. Independent security firms confirmed ninety percent of the reported vulnerabilities as legitimate. And more than ten thousand high or critical vulnerabilities were found in the world's most important software. Mythos is seriously impressive, and blindingly fast.

The comparison with dynamite springs to mind once again. Alfred Nobel never intended it to be used to blow up safes or people; he was simply looking for a tool for mining. We know how that turned out. Mythos, too, could do wonderful things for humanity – it marks an enormous leap forward in artificial intelligence. But that intelligence is, for now, kept on a leash because of what they euphemistically call its offensive cybersecurity capabilities.

Only a few dozen companies currently have access to Mythos, as participants in Project Glasswing. You'll find the big names from the software world there: Amazon Web Services, Apple, Google, the Linux Foundation, Microsoft, to name just a few. Security firm CrowdStrike is also a founding participant. I mention them separately because I suspect they play a somewhat different role. The goal of Glasswing is twofold: on one hand, participants get the opportunity to test their own software; on the other, the aim is to look at open source as well. Anthropic handles that part itself, but I hope that security firms keep their focus there too. So that everyone benefits from the extraordinary security capabilities of Mythos.

A second comparison comes to mind: Frankenstein's monster. In Mary Shelley's 1818 novel, a scientist creates life from dead matter, and then rejects the result. The creature, initially well-meaning, becomes isolated and embittered and turns against its creator. The story is essentially about the dangers of unchecked science, responsibility for one's choices, and the need for recognition and connection.

I've been chatting with AI about all of this. With Claude too (the regular public version, of course). In conversations on entirely different topics I've occasionally bumped into unexpected limits on what could be discussed, but on this subject I found a striking openness. Here are a few quotes:

“That Anthropic is deliberately keeping the model out of the public domain says quite a lot in itself: they are implicitly acknowledging that they have built something that, in the wrong hands, is a serious weapon.” On the Glasswing participants: “What stands out: these aren’t just any run-of-the-mill security outfits. It’s a who’s who of the tech world — including parties that are simultaneously each other’s competitors (Google, Microsoft, Apple). The fact that they’re joining forces here says something about how seriously they take the threat.” On my dynamite comparison: “Whether he [Nobel] was genuinely fooling himself about the military uses, or simply being pragmatic, remains a bit of an open question. But the parallel with Mythos is hard to ignore: here too, the creator says ‘this is for defence’ — while the instrument itself is neutral as to who uses it.” And finally, on my Frankenstein parallel: “The most cynical reading: they’ve already built the monster, and Glasswing is primarily the PR strategy to justify it.”

Meanwhile, reports elsewhere suggest that a public release of Mythos is on the way. Claude’s comment on that: “One interesting detail: Anthropic previously reported that Mythos managed to break through its own security measures during testing — which, in hindsight, makes the reluctance around a broad release all the more understandable. That doesn’t make the Frankenstein parallel any weaker.”

To end with a quote from Shelley’s book that seems to fit snugly into this subject: "You are my creator, but I am your master." Let’s hope that it doesn’t come to that with AI.

From now on, the Security (b)log will appear fortnightly, because I’ve moved to a four-day working week (a phased early retirement arrangement). Specifically in order to keep blogging, I’ll be working every other Friday (with Wednesday off that week). Friday is the perfect day for something creative, free from the pressure of meetings, phone calls, and a fresh inbox.

 

And in the big bad world…

 

2026-05-08

Dumb iPad

Image: Adobe Firefly

This time from the three-letter security alphabet, I’m picking the A — for availability — because the colleagues I complained to in a meeting about my iPad thought I really ought to write something about it. So here goes.

What happened? Well, my iPad had decided to cut off all contact with the outside world. Neither via Wi-Fi, nor via the SIM card. Apps that needed internet access grumbled that they couldn’t connect, or simply did nothing, without so much as a word of explanation. Not a single app gave even the faintest hint about what was holding it back. The obvious fix — turning it off and on again — didn’t help either, and the battery was nicely charged.

Time to call in reinforcements. The helpdesk had a magic button combination up its sleeve: “Press the volume-up button, then the volume-down button in quick succession. Now hold the power button until the Apple logo appears.” Now, on this iPad (10th generation), the top button is not a power-off button, which immediately had me sceptical. But fair enough, worth a try. Which one is volume-up again? Ah yes, this one. Press, press, press, wait… No Apple logo.

After that, the helpdesk fired a whole series of questions at me. For instance, whether other devices were connecting just fine — a logical question, which I could confirm. So it had to be the device itself. Buried near the bottom was a question that made me go red in the face pre-emptively: whether flight mode might accidentally be switched on. It’d be just your luck, wouldn’t it — a stray finger tap silences your device and then you go complaining it won’t talk to anyone. Fortunately, I could quickly stand down: flight mode was off.

Patiently, my friendly colleague suggested the next option: resetting the network settings. That puts just that specific part back to factory defaults. No joy there either. So the helpdesk pulled out the nuclear option: a full factory reset. Well, it had been coming, but as a user that’s obviously the last thing you want. It means setting up your device from scratch, and that takes time.

I left it alone for the rest of the day, but in the evening I tried my luck with AI. The clever chatbot came up with suggestions similar to those from the helpdesk. Notably, the very first option — the button sequence — revealed that I shouldn’t be pressing volume-up then volume-down, but the other way around: first “the volume button closest to the top button”. Which is, in fact, volume-down. After going through the full ceremony, the Apple logo did appear this time, but the problem wasn’t solved.

A few suggestions later, my AI companion asked whether I might be using a VPN. As it happens, last year, when I attended a conference in the US, I had indeed activated my personal VPN on the iPad to use the hotel and conference Wi-Fi without a care in the world. I’d completely forgotten, but I checked anyway (wise lesson: never assume you know the answer — just follow the instructions of whoever’s trying to help you).

After turning off the VPN app, a miracle occurred: the iPad sprang back to life. That thing had simply gagged my iPad. AI’s response: “It happens more often than you’d think: an update to the VPN app or an expired certificate causes the app to block all traffic (the so-called Kill Switch), even if you haven’t consciously activated the VPN.” What I find most troubling about the whole affair is that the VPN didn’t bother to mention that it had shut everything down. Same as that time they’d kicked me out for an alleged violation of the terms of service. I only discovered weeks later, by accident, that I had no VPN. Anyway, my subscription is up for renewal soon, and it’s too expensive and too American anyway. I’m switching to something friendlier.

An app that was supposed to protect my device had compromised its availability. Not great. And oh yes, the other two letters? Those are, of course, the I for integrity and the C for confidentiality. There — we’ve run through the entire security alphabet again.

Next week, due to the shortened working week, there will be no Security (b)log.

 

And in the big bad world…

 

 

2026-04-17

Leonardo & Cookie Monster

Photo: author

A long time ago, somewhere in the 1980s, I was on holiday in Italy with my parents. We visited many places, including Padua. There, we wanted to see an ancient university building, but it was just closing. The friendly caretaker gestured that we were welcome to accompany him on his locking-up round. And so it happened that, moments later, we found ourselves standing at the lectern of Leonardo da Vinci.

Have you ever been somewhere where it felt like you weren’t really supposed to be there, yet the moment felt magical? That’s how it felt back then, and I felt it again this week, when I went to get a cup of hot water for tea at the office. The machine showed a red bar. Not a good sign. The screen no longer displayed the usual options for every imaginable type of coffee, but choices such as ‘remote-controlled measures’ and ‘ingredient management’. And in the top left corner was the most important label of all: ‘machine administrator’. With, right next to it, a ‘log out’ icon. So yes, we were logged in as administrator.

Let me speculate for a moment about what might have happened here. The machine had a malfunction, as evidenced by the red light (on the adjacent machine, that bar glowed white). A maintenance engineer had been called in, but couldn’t immediately fix the problem. For a moment it looked as if various things simply needed refilling, but there was more going on; the bottom message on the display read ‘middle grinder empty’, yet that container was absolutely brimming with coffee beans. So the engineer must have left to fetch spare parts, and forgot to log out.

Colleagues from my meeting stood there, grinning. Stumbling into something like this while a security officer happened to be visiting – well, that was rather perfect. I see this more often: people smile sheepishly, feeling a kind of second-hand embarrassment. Someone hasn’t followed the rules and a security officer has caught them red-handed. Oops. Here comes trouble!

Coffee machines fall well outside my official jurisdiction, but I can of course use this example to highlight the broader issue. And that issue isn’t so much that people occasionally forget to lock their workstation – you get that, don’t you – but rather the more general picture that security isn’t always top of mind. When it really should be.

Recently, I was in a discussion about AI. It was about how you’re not allowed to include personal data in your prompts; for example, you can’t just paste in an entire letter and ask the system to analyse it. A manager said that one of his employees had approached him with a brilliant idea: ‘I’ll just ask AI to remove the personal data first!’ The employee was sent away with the instruction to think very carefully about what he had just said. Hopefully by now he has realised that you shouldn’t ask Cookie Monster to keep the cookies safe before washing the cookie jar.

Look, I understand that you don’t share my professional deformation of seeing risks everywhere. But surely a certain level of basic hygiene is not too much to expect, right? You don’t have to be a Leonardo, but don’t be a Cookie Monster either.

 

And in de big bad world…

 

2026-04-10

Ethical hacking

Image from Unsplash

After years, it was time for me to go back to training. I looked for one where the chance would be small that I’d learn very little; something that tends to happen quickly when you’ve been around the block in this field. A course on ethical hacking more than met that requirement.

For more than three decades, I’ve viewed the world from the right side of the line. My work revolves around security policies, risk analyses, and compliance, to name just a few things. I read and hear about what goes on on the wrong side of the line and try to make life as difficult as possible for the folks who hang out there. With this hacking course, I wanted to see the world from their side for once. Because, as Sun Tzu already knew in the fifth century BC: ‘Know your enemy and know yourself, and you will not have to fear the outcome of a hundred battles.’

But what is ethical hacking, exactly? Broadly speaking, there are two kinds of hackers: the good and the bad. The latter usually make the news, for instance through data breaches at the police or at telco Odido, both here in the Netherlands. That’s how hacking is known to the general public: unlawfully breaking into computer systems. The people who do this come in many shapes and sizes. At the bottom of the ladder you find the script kiddies: people who use ready‑made recipes to do things without really understanding how they work. And right at the top you have organized crime and state actors.

But there are also benevolent hackers. Like their malicious counterparts, they look for weaknesses in defenses. The big difference is that they don’t exploit those weaknesses for personal gain; they responsibly report them to the organization where they found the vulnerability. You can hire ethical hackers to test your systems, but some also operate on their own initiative. Quite often, if they play by certain rules, they even receive a reward. That can range from a T‑shirt to (a lot of) money.

Of course, after a five‑day course I am far from a seasoned hacker. Quite the contrary: last week my head was spinning from hacking tools with countless options, the many ports that can be attacked, and lots of other things that any self‑respecting hacker is expected to know by heart. Back in the MS‑DOS era, you also had to do everything from the command line (the C:\ prompt), but by today’s standards that feels rather archaic. And yet that’s still how things work in that world, only now with Linux instead of MS‑DOS.

The most important thing I learned is that hacking involves quite a lot, but that once you’ve mastered the tricks, it can be remarkably easy – at least if your opponent doesn’t defend themselves well. In the simple scenario we practiced, you find the IP address of your target, check which ports are open, investigate whether known vulnerabilities exist for the services running there, and boom, you’re in. Obviously, it’s (hopefully!) not always that easy, but the principle is likely the same: the hacker looks for weak spots in the defense. And you’d much rather have those vulnerabilities discovered by an ethical hacker than by a criminal. That only helps, of course, if you then actually act on the findings. Fortunately, everyone understands that. Right?

I’ve always had admiration for colleagues who do this for a living. Now that I better understand what they do, that respect has received a serious upgrade. It’s important, rewarding puzzle work that requires a great deal of knowledge and skill. They make discoveries that sometimes cause quite a stir. And then you see them walking around beaming. A fine sight.

Finally, I’d like to share something entirely different that I learned and that anyone who uses AI chatbots such as Copilot, ChatGPT, and Claude can enjoy. It’s about ELI5. That stands for ‘explain like I’m five’ and ensures that answers are phrased in simple terms and don’t assume prior knowledge. Not baby talk, but often using nice analogies. Just try something like: ‘ELI5: Explain what an IP address is.’

 

And in the big bad world…

 

 

2026-04-07

AI calling your parents

Image from Unsplash

Have you ever had no time (or no desire) to call your parents? Then there’s now a handy service that everyone will benefit from!

This is about a company offering a rather unusual AI service. They actually call your elderly parents. So you don’t have to. On their website you’ll find a photo of the Czech founder with his mother, accompanied by the story of how he lived abroad but wanted to stay in touch with her. Different time zones, a demanding job, and “the unpredictability of life” kept getting in the way. And so the idea for his company was born. It helps people feel “remembered, connected, and valued,” they say.

A bit more information from their website. “Mary” calls the elderly person and asks how they’re doing. She also remembers what you tell her. Incredibly handy, of course: if you tell her today that you need to see the doctor, she’ll ask you tomorrow how it went. She also makes use of 1,400 “life story questions” – something like a database full of opening lines. On top of that, she sprinkles interesting little facts throughout the conversation to help keep the mind sharp.

Before long, the older person will likely no longer realise they’re talking to AI. Simply because AI sounds so natural. I’d bet that you and I wouldn’t hear the difference either. And once you start considering Mary a friend, you’ll probably tell her the same things you’d tell a real friend. For example, about your health – something older people talk about quite often. The company proudly displays the logo “HIPAA compliant” on its website. HIPAA is U.S. legislation concerning the privacy and security of medical data. But it’s less strict than our GDPR. In the EU, medical data is considered special-category personal data, which is subject to extra stringent rules.

Older people are particularly vulnerable when it comes to cybercrime. Recently there are a lot of stories about fake police officers showing up to collect money and jewellery, supposedly because some great danger is looming. Criminals could easily piggyback on a service like this. For example, by pretending to be Mary and asking clever questions to manipulate their victim. Because they trust Mary, there’s a greater chance they’ll go along with the story. You can basically wait for this to happen, sad as that may be.

In your work, you may sooner or later get a phone call from a fake Mary as well. These scams already happen. Three years ago, an American named Brianna was supposedly kidnapped. Her mother received a call and heard her daughter speaking. Or so she thought. Because with AI, a few seconds of audio – stolen from social media – is enough to make someone sound lifelike while saying anything you want. The same could happen with your manager, for example, asking you to email certain data. So if you get a strange request over the phone, call the person back on the number you know to verify that it’s legitimate.

And as for Mary? I prefer to call my mother, who turned 93 today (happy birthday!), myself. Much nicer that way.

 

And in the big bad world…

… a training course got in the way of filling this section.

 

 

2026-02-27

Telco hacked

Image from Unsplash



Most data breaches and hacks are the kind of inconveniences that happen to other people. This time, however, if you live in the Netherlands, there’s a good chance you’re staring rather glumly at an email from your telecom provider. After all, Odido controls roughly one third of the Dutch mobile market. On top of that, they provide fixed internet connections to a million households. And if you’re a Ben customer, you’re out of luck too.

The news is receiving wide coverage in the media. Understandable, given the scale: 6.2 million accounts were stolen from Odido’s customer contact system. Some of those accounts belonged to people who hadn’t been customers for years. Odido discovered this when these individuals responded, puzzled, to the notification email the company sent them. But the sheer size isn’t the only reason to be concerned. The kind of leaked information matters too. It wasn’t just the “usual” personal data such as name, address and email address. This hack also exposed phone numbers, bank account numbers, passport information, citizen service numbers, and even records of payment arrears.

Roughly two million records – containing nearly 700,000 unique email addresses – have already been published, because Odido didn’t comply with the demand from the criminals, who call themselves ShinyHunters, to pay “a low seven‑figure amount” (that’s at least one million euros). And they’re threatening to leak even more data. Plenty of reasons for millions of people to be worried.

Media coverage of the incident mostly focuses on sympathy for Odido and its customers. What you hear much less about is how this could have happened. I do understand that journalists focus on the victims. But still: how did this happen?

Phishing, ladies and gentlemen. In every presentation I emphasize again and again how important it is that everyone is resilient against this form of cybercrime. At Odido, that resilience failed this time. The phish reached customer service employees (possibly at a call centre abroad), who fell for it and handed over their passwords. Even two‑factor authentication (2FA) wasn’t an obstacle: the criminals called the employees, pretended to be colleagues from IT, and obtained the second factor as well. ShinyHunters executed an impressive piece of social engineering here: they didn’t hack the computer system – they hacked the computer users.

They then proceeded to download data. A lot of data. There should have been an automatic emergency brake for that. It should never be possible for a customer service account to download such vast quantities of information at once. It appears that there was no monitoring in place. If that’s true, it means not only the organisational measures (training) failed, but also the technical ones. You can hardly blame anyone for the failure of training; carefully crafted phishing emails are almost indistinguishable from the real thing. Oh, how I would love to see that phish. Employees handing over their 2FA, however, is something that deserves extra attention.

Odido itself is being notably tight‑lipped. I expected a statement on the homepage of their website, but only after some digging I found the “Information page Odido cyber incident”. First, there’s an extremely short official statement. Underneath, in giant letters, they advertise the free protection against phishing and other threats that they offer to their customers (one wonders if they use it themselves…?). Only then comes a detailed explanation of what happened, and some do’s and don’t’s. The bottom line: criminals with access to the leaked data can impersonate you and carry out all sorts of actions at your expense. So, in the coming period, keep a close eye on the invoices you receive and check your bank account for unfamiliar direct debits.

In the FAQ they raise the question of whether Odido’s security was adequate. But they don’t really answer it. Instead, we get the usual platitudes: safety is our top priority, we continuously work on improvements, but yes, criminals are very clever too.

Whether Odido was, after all, still clever in securing its assets – personnel included – will undoubtedly be investigated thoroughly. But whether we’ll ever get to hear the answer is another matter.

 

And in the big bad world…

…I was unfortunately too busy with other matters today to fill this section.

 

 

2026-02-18

Size matters

Click on image to enlarge

Exactly one year ago, my colleague Alexander asked a question. Some topics take a little longer to mature. His question was about passwords and whether it’s really necessary to make them overly complex. He sent along a well‑known chart that illustrates how quickly passwords can be cracked. Let me break it down for you, because it contains a lot of interesting information.

I’ll start with the title. The key term is ‘brute‑force attack’. Brute force against what? Any system you want to log into contains a file with all user accounts. After all, the system must be able to check whether you’re allowed in. Unless its designer has been living under a rock, the passwords in that file are not stored in plain text. Otherwise, anyone who manages to steal the file would have free access. Instead, the passwords are stored in encrypted form. When you log in, the password you enter is encrypted as well, so it can be compared to the stored version.

An attacker needs many attempts to crack your password. If they try logging into a website with your account, your account will usually be locked after a few failed attempts. That lockout is a security measure against brute forcing. So, that approach gets the attacker nowhere. What they really want is the full password file, so they can attack it offline without getting locked out. Of course, they first have to break into the target system to steal it.

Let’s assume they succeed. They then use a powerful computer to attack the accounts in that file. The chart shows how long that would take. Vertically, the password length increases from four to eighteen characters. Horizontally, the number of possible characters increases. The first colourful column represents ten characters: the digits zero through nine. The next columns give you 26, then 52, then 62 characters. The last column represents all possible characters – digits, uppercase and lowercase letters, and symbols (! @ # $ % ^ & * ( ) - _ = + etc.) – about 94 characters (‘printable ASCII’).

In the top-left corner, you see that a four‑digit password offers no resistance at all. There are only ten thousand possible combinations, meaning the attacker needs about five thousand guesses on average. That’s just too easy. In the bottom‑right corner is the other extreme: eighteen characters chosen from 94 possible symbols. That gives you 3.28 × 1035 possible passwords – roughly a three followed by 35 zeros. According to the table, a powerful cracking computer would need 463 trillion years to guess it. A trillion is a thousand billions; the universe is only 13.8 billion years old.

What I find far more interesting is that the table changes much more vertically than horizontally. In other words: length matters far more than complexity. If you make a numeric‑only password four times longer, the attacker suddenly needs two thousand years. Meanwhile, expanding the character set (at the same length) hardly affects the cracking time. And if you look at the row for fifteen characters, a password made up of only lowercase letters already takes nearly half a billion years to crack. That square could have been coloured green, as far as I’m concerned.

Conclusion: if a password is long enough, you don’t need to worry about complexity. Many systems insist you include at least one digit, one lowercase letter, one uppercase letter, and one symbol — but that’s unnecessary if your password is sufficiently long. Allow your password manager to generate and store those long passwords for you. For the few passwords you can’t store — such as the master password for your password manager — choose something you can remember but others can’t easily guess. For example, “You won’t hack my password” or “mhallfwwasmfwas” (Mary had a little lamb…).

  

And in the big bad world…

 

 

Ants and lemons

Image: Unsplash Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also ro...