2022-12-16

Dear manager

 

Image by author

Dear manager, I have received some complaints about you. You are said to dismiss signals about non-compliance with security regulations, or to devise a rationale that makes it look like those regulations are being complied with. Because I like to help people fulfill their responsibilities , we need to talk about this.

You are not one specific manager, nor do you work for a specific part of our large organization. Your level also does not matter: this phenomenon can occur anywhere in the organization at team, department and board level. In fact, I am convinced that you also exist outside my own organization. And furthermore: if the shoe fits, wear it.

The most misused word in information security has been dropped once again (and it’s translation from Dutch isn’t straightforward): actually, really, fundamentally. The manager who listens to an employee's complaints and then says that he is "actually/really/fundamentally" right, but that he can't do anything about it, or that that’s the way things are. Undoubtedly some managers will say that they can decide on this deviation, because they are managers. Yes, managers are indeed here to make decisions, but not all managers can decide on all matters. And sometimes someone goes out of his way on this difficult subject, possibly without realizing it. Think about whether a particular decision fits within your mandate.

But most complaints that come to my attention are not that difficult at all. These concern, for example, key boxes of which the key is on top of the box, or the code of which is written on a sticky note within one metre from that box. A physical key is indeed difficult if you have to share it with several people, but everyone can easily record the code of a number lock in (surprise!) their password manager. I am not in favor of mandatory periodical password changes, but codes of physical locks should be changed regularly, because otherwise worn-out keys will reveal the code.

Our internal mail offers the possibility to encrypt sensitive messages. One easy-to-place check mark ensures that the e-mail and any attachments can only be viewed by the addressee(s); delegates only see a white screen. Consider this option when sending personal data about customers or employees, for example, and bear in mind that the GDPR is a pretty strict law. This tip is of course for everyone, but I expect managers to propagate it.

Sometimes it is useful to immediately include the relevant documents in a meeting invitation. No problem, as long as those documents do not contain confidential information. Because in my organization most calendars are accessible to all colleagues, they can also read the attachments. But you just don’t want an appointment for an employee interview to contain an assessment form, do you? So don't put confidential information in the invitation, but send a separate email. In the invitation you can then include something like “see my email from 16-12-2022 09:56”.

As you can see, it's often the little things that you as a manager can do, without having to perform major deeds. When managers show that they take security seriously, this also has an effect on their employees. If the manager takes it less seriously, many employees will also shrug their shoulders.

Let's help the managers. For example, if you are a business security officer or a data coordinator (a role linked to the GDPR) and you see that something is not going well, then talk to management about it. If necessary, skip levels, while making sure that you have a well-founded story. In short: take your responsibilities seriously and make sure that management does too.

Our own manager gave us a Christmas bauble (thanks, Ton). An unbreakable one, he added explicitly. We must be equally unbreakable when it comes to complying with security rules – and that is not the same as rigid. Another team manager brought me a Christmas bauble from a conference in London (thanks, Robin). Managers who think about security even far beyond their work – that’s the kind we need.

The Security (b)log will return after the Christmas holidays.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

2022-12-09

Dicey ticks

 

Image from Pixabay


It was cold, dark and wet when I left the house before seven yesterday morning to travel to Amsterdam. On the way to a congress that started at nine and would not close until half past five. I considered leaving a bit early, especially since the last part was a panel discussion, which I rarely find interesting. Luckily I didn't.

The panel included information security professionals from the banking and insurance world. The facilitator asked his first question: “What do you see as the biggest threat to information security?” You would expect the standard answers: ransomware, phishing, budget. But no. One participant took the floor firmly and said: “Compliance is our biggest threat.” Boom! The room didn't react that way, but inside I did. That man spoke straight from the heart. Let me explain.

Simply put, compliance is complying with laws and regulations. Don't get me wrong – of course we have to comply with laws and regulations, especially since we are a government organization. However, we have gone too far, because we no longer do many things to optimally secure the organization, but to tick all the boxes and thus satisfy the auditors.

For example, we must comply with the BIO, the  Dutch Government Information Security Baseline. The BIO consists of about 250 controls (based on ISO27002). You must comply with every rule, unless you have a good reason not to (comply or explain). You have to go through all those controls anyway, if only to determine whether you have to comply with them. You must then either explain why you do not have to comply, or you must provide proof that you comply. You look for the gaps between the rules and the actual situation – you do a gap analysis.

And then you can also look at three different stages: set-up, existence and operation. Set-up means that a control has been documented, for example in policy or a design. Existence means that the documented measure has actually been taken, and for operation the control must have proven to be effective several times. Actually, "stage" isn't the right word. It’s not necessarily first set-up, then existence and finally operation. I know of countless situations where a control has worked fine for years without ever being documented. Operation then earns a green tick, while set-up scores red.

In recent years, we have performed this exercise at our data center. Not for the data center as a whole, but for each individual service that data center provides to its customers: networks, mainframe hosting, endpoints (for example your laptop) and countless other things that I never even suspected existed before. Apart from the fact that this operation has provided us with a lot of insights, it was also a huge job.

Our organization is of course much more than just a data center. And what do you think: the entire organization must comply with the BIO. A higher level of abstraction is needed for that. A few years ago we divided all those BIO controls among the organizational units. In a number of major meetings, responsibility and accountability were determined. The IT department, which also includes the data center, garnered 42 measures (I can't suppress a nod to The hitchhiker's guide to the galaxy here on my bookshelf). The other controls fall under the responsibility of other organizational units. And despite the limited number of measures that we have to implement, it is a hell of a job. Tough work too, because it is often difficult to retrieve the necessary information. Despite the higher level of abstraction, you still need detailed information to substantiate your statements.

And all this compliance, the panel sighed at the congress, swallows up all the time and money, leaving nothing left to actually improve security. In the hunt for green checkmarks, the heart of the matter is overlooked and the illusion of security is created. We are so busy polishing the car that we don't get around to solving shortcomings under the hood. While that is much more important than the outside.

Let's use lists like the BIO primarily to address and solve security issues in a practical sense. Compliance then follows naturally – not as a goal, but as a by-product.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2022-12-02

Passwords once more

 

Image from Pixabay

Last week's Security (b)log titled Passwords – yes, again raised a number of questions worth answering for a wider audience. So here we go, passwords once again!  

A remarkable password system came along, which in weighty language could easily be labeled zero knowledge. If a site asks for a password, the user clicks on “forgot password” every time. Usually the site then sends a recovery message to the e-mail address on file. The link in that email will take him to a page to set a new password. There, the user randomly hits a bunch of keys, making no effort to remember the new password. Because next time he will just do the same thing again. If I could please share my thoughts about this.

My first two thoughts are: “hey, how creative” and “wow, how laborious”. The combination of those two thoughts is: perfectly usable for accounts that you rarely visit. Like when you're ordering a gift from a site you've never been to before and probably won't need to be for a while, but they insist that you create an account. I think it's fine to use this system in that case. But for accounts that you need more often, it seems less useful to me; it’s just too cumbersome to get in. Another tip: you should first type the password in Notepad or in a new Word document and copy it from there to the password fields, as otherwise you will have a challenge to enter the same password in the second password field. Then close the file without saving it. By the way, do you know who is really good at coming up with those kinds of passwords? Password managers… (see below).

This system also makes it clear that it is very important to properly protect your email. After all: if an attacker has access to your mail, he can also click on “forgot password” everywhere and then gain access to all those sites via the recovery message – under your name.

Some people are skeptical about password vaults. Are those apps safe? Wouldn't there be a back door after all? The honest answer: we don't know, at least not with certainty. You see, a password manager is software, and software by default contains errors. Some of those errors affect the security of the product. Moreover, such an app usually does not run in isolation on your device, but synchronizes the data via the cloud, so that you can use your vault on all your devices. In other words, your passwords are usually not on your device, but on a computer somewhere in the world. By sheer accident, I just received an email this morning from LastPass, the password manager I used before. There was "unusual activity" in the cloud service they used. Hackers could view user information. But, they insist, the passwords are encrypted and because you're the only one who knows the key, they're not at risk. They leave it open whether those encrypted passwords have been captured. But I don't believe in deliberately installed back doors, as long as you don't use password managers that come from suspicious countries such as Russia or China. Some products are open source, which gives anyone the opportunity to turn the program inside out (whether that actually happens is another matter). And perhaps a malicious person will find a vulnerability fist.

The mandatory use of a mix of upper and lower case letters, numbers and other characters also raises questions. The most important element of a good password is its length, but the number of characters you can choose from also makes a difference. If you only use lowercase letters, an attacker trying to guess your password has a 1 in 26 chance per character of getting it right. If you also use capital letters, the chance decreases: 1 in 52. If you also add numbers and other characters, the chance of guessing correctly becomes even smaller. This then works nicely into the length of the password: with a password of 3 characters with only lowercase letters, the number of possibilities is 26*26*26 = 17,576. If you also use capital letters, you can already create 52*52*52 = 140,608 different passwords. With password length 8, you go to nearly 209 billion and nearly 53.5 trillion possibilities, respectively. Note that expanding the number of possible characters in this example gives only eight times as many possibilities, while making the password longer gives twelve million times as many possible passwords. That seems crazy, but remember that attackers often put a lot of computers to work to crack passwords. Many hands make light work!

In summary: use long passwords, preferably generated by and stored in a reliable app. And as always: turn on two-factor authentication/two-step verification wherever possible.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2022-11-24

Passwords - yes, again

 

Image from Pixabay

It's National Check Your Passwords Day today (in the Netherlands). This is an initiative of tech website Tweakers and the Public Prosecution Service, and the intranet editors asked me to dedicate an extra blog to this day. I am always open to special requests, which I then give substance to in my own way.

First let’s take a look at the website of initiative. It states the following: As an internet user you are confronted with many websites that require you to create a user account and choose a password. Many people find it difficult to come up with and remember all those different passwords. Unfortunately, this means that many Dutch people do not handle their passwords securely, for example by choosing passwords that are easy to guess, or by reusing passwords. Through the National Check your Passwords Day, we want to make people aware of this and explain that coming up with and remembering good passwords does not have to be difficult.

The password tips page, to my surprise, only contains four tips. Let's take a look at those tips. Number 1: Use a password of at least eight characters. Well, eight characters is an echo from the past, I’m afraid. Today, twelve is considered a safe minimum. Maybe they are afraid that passwords that long would be too difficult to remember? There’s an app for that; see below.

Tip #2: Never set a single word as your password. Agreed, because then your password would be in the dictionary and hackers are very good at automatically checking captured password files against a dictionary. So a password like bungalow doesn’t stand a chance. It’s just as bad as bung@l0w, by the way, because that trick is also in the hacker dictionaries.

The third tip is: use at least one word and a number combination that only you know. So something like bungalow2022? This will at least make the password longer, and length is really the most important factor. Unfortunately, the recommended number combination tends to be a year, birthday or the pin code of your bank card, which does not really make the password stronger and may even introduce a risk (yes, I mean that pin code).

But luckily they state in tip #4: don't use dates of birth, addresses or anything else that is easy to guess. I totally agree with that. This tip is mainly intended to avert targeted attacks. If an attacker has his eye on you instead of just anyone, he will use everything he can find about you for his attack. All personal information, even if it is far fetched, is therefore taboo for use as (part of) a password.

After the numbered tips on the website, there are still a few extra tips. Like you shouldn't write your password on a post-it note. And about security questions - there still exist sites that require you to provide your first pet/school teacher/ sweetheart's name, or similar questions - they tell you not to choose questions that others know the answer to. Let me express this a little stronger: Lie! What is your place of birth? Banana. What was your first school teacher's name? Government. Of course you have to save those lies somewhere, otherwise they are of no use.

And that brings me to the promised solution to remember all those secrets: the password manager - an app that remembers your passwords and other secret information for you, while you only have to remember the password of that app. According to research commissioned by Tweakers, only 7% of the Dutch use such an app. That’s a very low percentage. So here's a call to the other 93%: download a password manager now and start using it. See which one suits you best; the website lists only three, but there are many more (pssst: my favorite is Bitwarden). And an extra tip: password managers are also great at coming up with strong passwords.

This is a Security (b)log special. That's why there is no news from the big bad world this week.

2022-11-18

Protecting the universe

 

Image from Pixabay

It's not a fair fight. A hacker only needs to find one tiny hole to break into a system, while we have to protect the entire universe. If the hacker manages to find a system where the latest security patch is missing and he can exploit this vulnerability, he is in. We have so many systems that run so much software that there is always a vulnerability somewhere. It's not fair. I have thrown this lamentation at my audience during countless presentations.

Do you know MythBusters , the often spectacular show with Jamie Hyneman and Adam Savage, which aired on the Discovery Channel? Last Wednesday I felt like I was in a special episode of it, when Etay Maor gave a keynote at ISACA's Risk Event entitled “Busting cyber security myths”. The very first myth, which he busted, was exactly what is stated in the paragraph above. Ouch.

He used the MITRE ATT&CK matrix to make his point (I’m sorry, but the MITRE Corporation thinks you should write “attack” that way). That matrix is fourteen columns wide, and the last one lists the types of impact an attack can have: data manipulation and destruction, data encryption (ransomware) and denial of service, to name a few. And all other columns list things an attacker can do to achieve the desired impact. It starts in the first column with all kinds of reconnaissance, followed by finding the necessary resources, gaining access and then all kinds of steps aimed at owning the intended system. Each column is a kind of drop-down menu. Not that an attacker will use this matrix to determine how to proceed - this matrix focuses on analysts, who can gain a better understanding of an attack.

To make his point, Etay Maor has mapped REvil ransomware to the MITRE ATT&CK matrix. That was actually quite easy, because that ransomware has already been completely dissected on the MITRE website; Maor only had to colour the corresponding boxes in the matrix. This resulted in no less than fourteen red squares in seven different columns. Many of those boxes contain sub-items. The last column, with the impact, contains another four red boxes. So the maker of REvil had to do a lot more than find just one hole. The complete table of activities for REvil is forty rows long. By the way, REvil is not just ransomware, but ransomware-as-a-service (RaaS). This means that REvil is a service that can be hired by others. Yes people, the underworld has service providers, too.

Back to the allegedly unfair fight. My starting point was a ratio of one to infinity – one hole compared to the entire universe. Maor's example brings the ratio to forty to infinity. I still think that it is unfairly distributed, although I now look at it in a more nuanced way.

The question is: what do you do about it? How do you protect the universe, or more specifically: the cyber universe? It starts with security by design, including security from the outset in the design of your application and your infrastructure. Because if the design of a new car is already completely finished and you only then find out that it still needs brakes, then you’re looking at a quite difficult – and expensive – job. Later on in the process, during the realization, it is important to maintain that security mindset. This is where craftsmanship comes into play. The brake lines must be properly connected and testing for leaks is always a good idea. And once the product is running, it is important to maintain it properly (in the car analogy you take that for granted). That includes understanding that hardware and software by definition contain errors, and that some of those errors not only can be harmful to the security of the product itself, but also can have an impact on other products. You must keep looking for this as long as the product is in use, and any defects found must be remedied in a timely manner. Before someone else finds them and uses them unfairly.

On Thursday 24 November, a special will be published on the occasion of Check-your-passwords-day. That week’s regular Security (b)log is cancelled.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2022-11-11

Solutions seeks problem

 

Image: Reviver

In California, Arizona and Michigan everyone can now equip their car with an electronic license plate. When I read this my first thought was: what could possibly go wrong?

First let's take a look at the (alleged) advantages of such a screen on your car. It's hip, and California is certainly a state where a lot of hip people live. And what can such a screen do for those hipsters? Well, to start with, of course, the obvious: display the license plate of the car. Furthermore, Americans have to renew their registration annually and that can be done automatically with that plate. After that it gets a bit more frivolous: you can choose between light and dark mode and add a personal line of text. And of course the screen can also show advertisements.

The company Reviver, the patent holder, attributes several possibilities to its product, the RPlate, that can improve public safety. For example, the screen can show a notification if the vehicle has been stolen, or if an amber alert has been issued for a missing child. And you can manage it very conveniently with your smartphone, via Bluetooth. And of course it has 5G connectivity and the more expensive version has GPS, so you can always find your car.

Of course, the manufacturer has also thought of the security of this device: “encrypted TLS/SSL communication, advanced data encryption, zero hardware data storage”. So – reading backwards – no data is stored, but that data is encrypted with advanced technology (whatever that means). Communication is secured in the same way as between your browser and a website.

Well. Leaving aside the obvious questions about usefulness and necessity, I would like to take a look at the security and privacy aspects of this solution without a problem (a characterization of security guru Bruce Schneier). Another celebrity in my field, Mikko Hyppönen, always says: when it's connected, it's vulnerable. You should assume that this license plate can be hacked. An obvious 'use' for a hacked license plate is, of course, forging it. But how about a false report that a car has been stolen? Especially in America, where cops quickly raise their hands to their hips, I don't think it's fun to drive around with a car that shouts that it's been stolen, or that displays "HELP!". The inventors also envision applications for paid parking (where the license plate replaces the receipt behind the windscreen) and for the disabled (displaying a wheelchair). If you can influence that, then an dishonest life of free parking – even in reserved spaces – lies ahead.

In terms of privacy, the obvious questions arise: who can follow me? Where you are and when can reveal a lot of information about your life. How comfortable do you feel with that thought? Of course, we don't need digital license plate for that at all – depending on your settings, your phone, which you have with you even more often than your car, knows all that too, and shares it with advertising companies like Google and Apple. The privacy aspect does not even seem that exciting with this product.

The question remains: why would you? The marketing focuses on two spearheads: lifestyle and automatic license plate renewal. The first point is reflected in the reviews, which mainly show cars that you and I cannot afford. And on the second point, commenters are being rather cynical: like it would be so hard to renew your license plate the old-fashioned way. And why you shouldn’t buy such a thing? Perhaps because of the security risks, and otherwise because of the price: the cheapest version costs $19.95 per month.

I don't see us driving around with a gimmick like that so quickly in the Netherlands. Should it ever happen, then you don't have to be afraid of coarse language on the personal banner. You can only show texts that have been approved by the authorities. Without this restriction, the plates would of course fly over the counter in the Netherlands.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2022-11-04

A day at the zoo

 

Image from Pixabay

Last Tuesday, accompanied by a bright autumn sun, I walked with a teammate through the Dinosaurs department of the zoo in Amersfoort. Crazy, isn't it, that a zoo, which generally collects living creatures, has also furnished a piece of forest with statues of long-extinct animals. Just as crazy as the presence of a playground, by the way. Did you come to watch animals or to seesaw?

If you think our presence there, during working hours, is even stranger, then you have to consider that zoos also have spaces that they rent out for gatherings. And so that afternoon we had a meeting of our organizational unit, the CTO Office, responsible for the optimal and effective use of technology throughout the organization. After a clear talk from our director (the chief technology officer, or CTO) we had to split up into groups to talk about a certain theme. You know the drill: the groups are composed in advance in such a way that you do not sit together with your own teammates, so that you also come into contact with other people. I was, however, in a group of which I already knew two IT architects; one through work, the other through a chat at the coffee machine. The others, a license manager and a contract manager, I knew by sight.

The theme to be discussed te was called: fast, better, safer. Technology must be made quickly available to our employees. Apparently the quality can also be improved a bit and well, the realization that it has to be safer has fortunately also penetrated the higher echelons. In many organizations this means little more than comfortably abstractly shouting that everything must become safer, leaving the workplace behind in a despairing "Yes, but how?" Because the gap between the acknowledgment that it has to be safer and the practical implementation of such an ukaze soon has canyonesque dimensions. Welcome to the field of tension between 'that is not allowed' and 'but otherwise it won't work'.

The fact that they put us to work with this theme shows both guts and the need to actually give substance to it. The first thing we wrote down was that you should not only be fast, better and safer, but also flexible. That is, as it were, the catalyst that lends a helping hand to the other three properties. Flexible in combination with safer means that you do not strive for maximum security, but for optimal security. That also means that you can be more flexible in certain situations – I am thinking of test environments, for example. However, security policies and standards do not provide for this; such documents seem to be blind to the complex environment of a large ICT organization.

This brings us to risk appetite. How much risk is an organization willing to take? A company that produces things with a short time to market will generally have a greater appetite for risk than, say, a government agency. After all, that product has to arrive in the shops quickly and then you can't afford an overly frivolous security overhead. Just look at smart devices such as baby monitors, security cameras and toasters, which turn the Internet of Things into a dangerous mess.

Our conclusion was that we need to differentiate between the risks we face. An inextricable part of this is the unambiguous determination of who is responsible for what. One of the architects wanted to keep that responsibility as low in the organization as possible. I was able to convince him that it should at least lie at the level of a department head, because otherwise self-interest might weigh too heavily: if a team has to achieve a goal, a team manager will generally accept risks more easily. However, risks tend to have a broader impact than one team and must therefore also be weighed in that broader context. Some distance from the work floor helps with this.

Yesterday I spoke to a department head who often deals with risk treatment. We have set up a process that regulates that when someone wants something that is not allowed according to the rules, but is (at that time) necessary to ensure progress, they must write down what that means and what risk the organization runs. And that form must be submitted to the head of department. Because things have been getting out of hand lately, he is actively engaging with his peers to bring about change. In many cases, taking those risks is not really necessary, provided that some effort is made to work on a robust solution. This head of department clearly takes responsibility for security, while not losing sight of the importance of the operation. Because security is also about availability.

Another zoo group, which was also discussing of the 'fast, better, safer' theme, had written down: read the Security (b)log! That is of course a great always-good action.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

Get out of jail

Image: Unsplash "Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or y...