2025-05-23

Miscellaneous

Image from Pixabay

A few weeks ago I was at a conference. I took a lot of notes and I can watch the recorded sessions. What is the best thing to do with all that? After some browsing I made a decision: I am going to treat you to some quotes and let my own thoughts loose on them.

As a warm-up, here’s an obvious one: “If you have only met someone online, then that person is always a stranger.” This comes from a presentation on resilience against scams. You’ll have to agree with this statement, but do you also act accordingly? Or do you still want to believe that this nice person is also honest? That is very difficult. In the last century, when the internet was not yet mean, I met someone in an online forum (does anyone still remember CompuServe?). We had nice conversations about the state of the world and about observations in daily life. Later we started emailing directly, and at my wedding I met him in real life for the first time. If I had taken the above quote to heart, I would have missed out on this friendship. Back then, cybercrime did not exist and online life was a lot easier.

A handy tip to avoid becoming a victim of scammers: never pay to get paid. In other words: if someone promises you the moon but needs your money up front to make that happen, then something is wrong. It started with that Nigerian prince who wanted to share a fortune with you but needed some money to release that fortune, and nowadays you may be offered a job where a little effort will be richly rewarded – but certain costs have to be made first. Don't fall for it.

Then there’s this nice tip that you can immediately benefit from: change the name of your guest network to “faster wifi”. All your guests – and especially your children’s guests – will want to be on that network. And that is exactly where you want them. Because your guest network is separate from the network that provides access to your private data. At odds with this is the idea of connecting all your Internet of Things (IoT) devices to the guest network. The idea behind this is that IoT devices can be hacked relatively easily and that you would rather not have a hacker have access to your data. But do you want all your guests to have access to your dishwasher, dryer and solar panels? Difficult choices.

Sometimes a statement from one speaker ties in with that of another. Like these two: “8% of the users in your organization cause 80% of the risk” and “New employees are the biggest threat: they easily click on links because they do not understand the risks.” I would mainly link the first quote to employees who are in the “cannot & do’nt want to” quadrant: they don’t know how to behave safely and they are also not willing to adjust their behavior, which makes them difficult to reach. But according to the second speaker, the danger lies mainly in new employees. You can do something about that. That is why we have been involved in the onboarding program for new employees for years now. We treat the new colleagues to a presentation in which we playfully guide them through the most important aspects of information security, business continuity and privacy. And we advertise the Security (b)log, so that they will come back to our important message.

If there was one subject that ran through all those hundreds of presentations, it was artificial intelligence. One speaker thought that 90% of so-called AI experts have no idea what they are talking about, and that the other 10% know very little. And that is normal, he argued, because AI consists of many sub-disciplines and it is important that experts know a lot about their own sub-discipline. Just as you wouldn’t go to see a brain surgeon with heart problems, you should also seek out the right specialist in the field of AI.

Finally, a quote that stuck with me because it hits home so well: “ Generative AI is autocorrect/type ahead on steroids.” Let me break it down for you. Generative AI is the form of artificial intelligence known to the general public, which generates something on its own; you know it from ChatGPT, for example. You know autocorrect mainly from your phone; on the one hand, it protects you from typing errors, but sometimes it causes embarrassing situations because the “correction” turns out to be annoying (in my case, “Hi Nick” was once replaced by “Hi pig”). Type ahead is its cousin, and you also know it from your email program that, while you’re still typing an address: I know who you mean! Well, and all this on steroids, that is generative AI. With all the conveniences that come with it, but also with an amplification of all the inconveniences. I stopped the message to Nick in time, but if genAI is happily hallucinating and telling us a story that makes no sense, that’s a lot harder to discover.

There will be no Security (b)log next week.

 

And in the big bad world…

 

2025-05-16

Dangerous by (de)sign

Picture by author

Take a good look at the photo and try to figure out why I shot this picture with only one purpose: to write a blog about it.

We are in a hotel. At the bottom of the screen there’s a staircase going down. Above it there’s this warning sign: “Caution – watch your step”. How many people have fallen down these stairs because they were looking at the sign? It draws your attention, distracting your focus from the danger itself: the stairs. You’ll walk into the pitfall with your eyes wide open. Literally.

Sometimes security measures are abused to make you feel safe while you are in a dangerous situation. For example, there are phishing emails that warn you about phishing. If you click on the 'for more information' link, you will be taken to the phishing information page of the real company. This can give you the false sense of looking at a legitimate email. Because criminals wouldn’t point out the existence of crime to you, would they? They are not going to give you a clue that something could be wrong, they don't want you to think about that, do they?

Cybercrime is all about trust. If you can gain your victim’s trust, you’re in. You can gain their trust by presenting yourself as a reliable party who, as an extra service, warns you of dangers. In doing so, they sneak into your world and together you look at the big bad world. That creates a bond. And with that, trust.

However, that same email will undoubtedly contain another link, that will take you to a fake website. Because the email seems so trustworthy, you are more likely to click on that as well. Gotcha!

The question remains: why on earth would they put a warning sign above a staircase? That must have something to do with the American claim culture. “It’s very unfortunate that you fell down the stairs, but hey, we warned you, so you can’t sue us.” Everybody knows that you have to be careful with stairs – even without a sign. Moreover, this was the only staircase in the hotel with a warning sign. Someone must have fallen into the depths at that spot at some point, after which this staircase was designated as a Dangerous Area.

 

And in the big bad world…

 

2025-05-09

Meeting the stars

Image from Pixabay
 

I've met stars. Bruce Schneier gave a speech, Adi Shamir and Whitfield Diffie were on a panel, Ron Rivest was an arm's length away and Dave Maasland was sitting next to me in the pub.

You probably only know these names if you are in my line of business – although Dutch readers might know Dave Maasland from his tv appearances. Keep reading anyway, because even without knowing these people you can learn something here.

Ron Rivest and Adi Shamir are the 'R' and the 'S' in RSA. You may know that name from your two-factor authentication, the extra security step you sometimes have to take to log in somewhere. RSA is now a company that makes these (and other) kinds of tools, but originally RSA is a cryptographic algorithm that is important for the encryption of our data exchange. The 'A' is for Len Adleman, by the way, but I didn't see him at this conference – the RSA Conference! Whitfield Diffie, who was on the same panel as Adi Shamir, is known for another cryptographic algorithm (Diffie-Hellman).

In that panel, a number of cryptographers gave their view of the world. Shamir sneered at bitcoin and its ilk: the world would be better off without cryptocurrencies. Diffie noted that consumer products are apparently considered good enough for high-security applications – Signalgate, the affair in which high-ranking American officials were using Signal, was still fresh in the memory. Incidentally, Diffie agreed that Signal's security is well put together. The panel also discussed the threat of quantum computing, which in short means that the security offered by RSA, among others, can be cracked in the future. Moreover, foreign regimes are already stealing our data, in order to run it through the quantum computer in due course. That is why it is important to develop replacement crypto algorithms as quickly as possible, but that is not easy. Diffie: "It's like having to develop an algorithm in 1945 that still works today." Shamir advised, in line with a European recommendation, to use double encryption for the time being.

Bruce Schneier is also famous in our world. He has been distributing his free newsletter all over the world for years, providing insights and opinions on new developments. His speech was about trusting artificial intelligence. Trust is a complicated concept, he argued, especially when it comes to trusting strangers ('social trust'). We tend to considering AI as a friend, but it is a service. Moreover, it is a double agent: it serves both you and its provider. But we have no choice; we have to entrust ourselves to AI. The era of agentic AI is dawning: you’ll have a personal assistant who arranges things for you. The AI agent has access to your email and your calendar and knows everything about you. You do want this, because that way it can support you best. Schneier used a dining reservation as an example. In the past, you called the restaurant, nowadays you make a reservation via their website and soon you let the AI agent find a restaurant and make a reservation. It knows what food you like and when you have time.

So we need trustworthy AI. Integrity will be the main issue, according to Schneier, because most attacks on AI are about the correctness of data. He gave the example of stickers placed on lampposts to trick self-driving cars. Legislation is needed to achieve trustworthy AI, but current legislation (such as the European AI Act) regulates the AI itself instead of the people behind the AI, and that is the wrong way to go, Schneier says. He advocates a public AI model with political accountability, as a counterbalance to corporate AI.

Information security officers are only human, which is why the organization also brought a number of 'real' stars on stage. Such as filmmaker Ron Howard (Apollo 13 and A beautiful mind (two Oscars), just to name two), who was interviewed by his daughter and colleague. Or basketball legend Earvin “Magic” Johnson, who won over the audience with his openness and a motivating story. And finally there was actor/singer/comedian Jamie Foxx, who provided a comical closing note. But he also gave us a pat on the back: “What you do is perhaps the most important job in the history of mankind.” According to him, community is the magic word.

After that, my three colleagues and I, and 44 thousand other conference attendees, returned to our own time zone. Together we made it an interesting and fun week. And the bond between our team and the SOC has also become closer. You did a good job there, JW.

 

And in the big bad world…

2025-04-18

Fatbike brakes

 

Image from bol.com

Fatbikes. Even the word gives me the creeps. I'll stay away from the broad discussion about this young phenomenon on the road (see here why this is a problem in the Netherlands). But I do want to talk about something that I see associated with riding one of these things: braking à la Fred Flintstone.

You know how Fred slows down his car, don’t you. Literally by digging his heels in. And lately I see more and more young fatbikers trying to stop their two-wheeler just like Fred by putting both feet on the ground. Often they swing back and forth dangerously. Eventually they come to a stop just in time.

Is there anyone in the audience who has experience riding one of these things? Are the brakes really so bad that you have to do like Fred to stop in time? Or are we talking about tuned-up models, where the brakes, which barely meet the regulations, fall short as soon as the bike goes faster than intended and allowed?

Something else now; you'll soon understand why I'm bringing this up. Earlier this week I was passing through Gouda by train. At the station my eye was caught by the open-air bike parking place. On either side of the place – which is only two bike lengths plus an aisle wide – there were security cameras set up about every ten meters (roughly 30 ft). I didn't count them, but there were an absurd number of them. You'd almost think the cameras were myopic.

Here are two examples of security measures that are taken in situations where the actual measures – brakes and locks – have proven insufficient in practice. We also have measures like these in information security. Usually, this involves technology that does not fully deliver what you hope for. For example, a virus scanner that still lets that very latest virus through, or that mail scanner that does not recognize a particular phishing mail. In these situations, the problem becomes an end user thing.

And that is why we need your commitment, dear reader. You are the brake shoe that can intervene at the last moment, when all else has failed. You are our last line of defense. And that is exactly why I put so much energy into keeping your knowledge of my field up to date. You don’t have to know all the ins and outs, but you do need to know the things that can be – literally – of vital importance to the organization, such as recognizing phishing email.

I know, it can be difficult. I can't ask more of you than alertness. Help us to bring our fatbike to a stop in time.

There will be no Security (b)log for the next two weeks.

 

And in the big bad world…


2025-04-04

On deaf ears

Image from Pixabay

“Have you ever written a blog about the tension between security and usability?”, a colleague asked. “Probably,” I replied, “but what’s your reason for asking about it?” “My wife.”

I understood what he meant straight away. Not that my family doesn’t understand it all, mind you. But we recently had some people over, including a couple whose ages sum up to my age. She asked for the wifi password, and I told her our guest network password. That is easy to remember and therefore not very complicated (something like bicycle3oven) – it is just the guest network and you can’t access our data with it. To my surprise, she responded with: “ Wow, that’s a complex password!” And she spontaneously mentioned their own wifi password, which I would classify as “20th century”.

I couldn’t avoid a disapproving look, but then I made a cautious, extremely friendly attempt to explain that a password like theirs is not a good choice. And I’m really not inexperienced or clumsy in explaining those things. But in this case, my explanation fell on deaf ears. “Oh, nothing ever happens to us anyway,” said the young lady. But it was her look that spoke volumes: what is this man so worried about? I took another run-up and started talking about passwords for other, perhaps more important accounts – knowing that people who act unwisely on the left side, usually do so on the right side as well. However, the wall of incomprehension was so high that, despite all my experience, I couldn’t tear it down. And I realized that I had to leave it at that; these people were here for fun & family, not to be lectured.

My wife and daughter, who had witnessed all this, didn’t know where to look. Apart from the fact that teenagers can't stand it when their father does something like that, the two ladies had realized much faster than I had that I was on a mission impossible. Their relief was great when I dropped the subject and we switched to small talk.

Security and ease of use are at odds with each other. Just think: if you lock your house, you will be standing in the rain a little longer when you get home. However, everyone understands that this measure is intended to keep outsiders out – there’s a reason they’re called that. It works the same way with information security: you don’t want to put any obstacles in the way of legitimate users, but because most systems are simply not intended for everyone, there has to be a lock on the door.

Some of these locks are more annoying than others, and sometimes they can be downright annoying, for example because they lock often. When it becomes annoying, people tend to circumvent security measures. It should be clear that the organization does not appreciate such creativity. That is it is important to me that people understand why a certain measure is in place. And so I have made inquiries for two measures I was wondering about.

In both cases the answer was: it shouldn’t be like that. Followed by technical explanations stating that there is no security measure at all in play, or at least: no measure that explains what I experience. There is probably just something wrong. That’s always a possibility: you think that something is a crooked security measure, but meanwhile something else is going on.

Hopefully that colleague can convince his wife that some measures are important. And hopefully he recognizes situations where something is simply broken and the behavior is not on security.

 

And in the big bad world…

2025-03-28

The phone isn't working

Image from Pixabay

My grandparents' phone number was 1331. Those four digits were all you needed to reach them. If you called from further away, there was also the area code 04454.

In those days you knew the numbers of family and friends by heart. Other numbers were kept in a special telephone directory: you set a slider to the first letter of the surname, pressed a button and the thing popped open and showed a card with all the names and numbers that belonged to that letter. Handwritten.

At home we didn't have a telephone at all for a long time. You could live with that in the seventies. And the one time you really had to call someone, you knocked on the neighbours' door and gave them a quarter (of the old Dutch currency, the guilder). Or you went to the telephone box in the village. You needed quarters there too. Those were important coins. Too bad they don't exist anymore.

When we finally got a phone, four digits were still enough. Ours were 4006. PTT was the monopolist and everyone had the same device: the T65, with a rotary dial and a curly cord. It sat in the living room and if you were busy in the kitchen, with the door closed, you would sometimes miss a call. And you only knew that when the caller tried again later ("Weren’t you at home?"). That's why my parents had that same PTT install an extra bell in the hall. You paid rent for that, just like for the T65.

Many years later I bought – hesitantly – my first mobile phone. A Panasonic, with an antenna that stuck out about two centimeters above the device. The device had a small LCD display and physical keys. You could call and text with it. Compared to the T65, the number of functions was doubled. Wow!

Look where we are now. Almost everyone walks around all day with a computer in their pocket, which you also happen to be able to make phone calls with. This can be done in various ways. Via your SIM card (the old-fashioned way of calling, with a phone number of ten digits nowadays), but also – with or without live video – via other apps. You can even use it to hold meetings, as we know since the covid pandemic – if necessary with people in all corners of the world. Most people have thrown their landline out the door. Or never had one.

But what if all of that suddenly stops working? No one is reachable anymore, at least not by phone. You can only communicate with each other indirectly. By email or via chat apps. What impact would that have on our social and professional existence? Many subjects benefit from live interaction; if they have to be done via email, the 'conversation' can easily go the wrong way because one person misunderstands the other.

If telephony and video conferencing were to fail for a long time, we would undoubtedly go back to the office more often. Then it would be like it used to be: working from home for a maximum of one day. Everyone has their own personal preference, but I cherish working from home. One day a week in the pandemonium (and, admittedly, also joining in the chatter) is enough for me.

What do we do to prevent a company-wide blackout? Diversity plays a key role. In the Netherlands, there are three mobile networks (Vodafone, Odido (elsewhere still known as T Mobile) and KPN (the heir to PTT!)). All other providers piggyback on these networks. It is financially and from a management perspective attractive for organizations to place their telephony with one provider. But if something goes seriously wrong there, the entire organization immediately has a blackout. So it would be better to spread your chances. You should even make sure that the employees of a team are not all with the same provider. I see a nice administrative challenge…

But is it worth it? We never have long-term failures, do we? In the current climate, I no longer dare blindly assume that it will remain that way. There are strange forces at work in the world. At some point, those forces could benefit from a country becoming paralyzed. We would rather not think about that. And that is precisely why we have to do it.

 

And in the big bad world…

 

2025-03-21

Number 2

Image from Pixabay

“Up for number 2? Please do it at home, because our toilet gets clogged quickly.”

On our way home from a short vacation we stopped at a cafeteria close to home, because we had no food in the house. And there, on the otherwise neat toilet, I spotted that note. The text reminded me of Belgian roads. Instead of repairing the sometimes abominable road surface, they put a sign next to it: degraded road.

Of course, placing a sign is much cheaper than fixing the problem. At least, at first glance. Perhaps hungry guests will avoid this cafeteria in the future, because after a long walk in the area they still have to go somewhere with their number 2 before they eat their fries. That means loss of turnover. And in Belgium, cars wear out faster. Moreover, I can imagine that a bad road surface causes more accidents: you lose control of the steering wheel when you drive through a pothole, or you try to avoid the pothole and collide with another car. All of that causes extra costs, and perhaps even human suffering.

And if our southern neighbours were to halve the excessive lighting of the country's roads, wouldn't they have any money left to repair those same roads? That's a bit more complicated. My physics teacher from a long time ago once explained why the Belgians have so many street lamps. That was due to the construction of nuclear power stations. They gave the country overcapacity. You have to go somewhere with that electricity, and that's why all those lamps were planted. Even then, there was already talk of grid congestion; the generated electricity had to be used up immediately. By the way, I have no idea whether that argument still holds true decades later, but I always liked this fascinating - because unexpected - connection.

If you have a problem, you want to solve it. For example, by removing the cause. If that isn’t possible, because you have no influence on it, you can take measures to compensate for the negative consequences. And if that isn’t possible either, for example because you do not have the money for it, then… Well, then you can always put up warning signs.

An example where it is difficult to remove the cause is cybercrime. Sure, these criminals are arrested with some regularity – just like their analogue colleagues – but there are simply too many of them and they often operate from safe foreign countries, where the Dutch strong arm has little control over them (although there are rare cases known in which the Russian justice system cooperated with foreign requests for assistance, for example in the case in which a meter-long file, translated into Russian, was delivered to Moscow).

Because eliminating the cause is so difficult, we have all kinds of measures to detect and neutralize malicious actions. Think of virus scanners, mail filters and people who keep an eye on things. But because all that is not enough, we have to ask everyone to be alert. Phishing is the number 1 point of attention, because one wrong mouse click can ruin an entire organization. That sounds dramatic, but it’s still true. And there are more subjects that all users need to know something about to ensure healthy business operations.

Fortunately, there is a hunger for information about this. In the coming period, I will again be a guest speaker at various organizational units that have asked me to treat their employees to a presentation. I always ask the organizers what is on their minds, what they want to hear about. Such a conversation sometimes provides surprising insights into the success of awareness efforts. Like earlier this week, when I spoke to a colleague about a presentation in their team. The team members are loyal readers of the Security (b)log. Nevertheless, even there, very occasionally someone forgets to lock their workstation when they walk away for a moment. And then their colleagues shout: “Oh, if Patrick sees this…!” It is nice to see that the message is getting across.

 

And in the big bad world…

 

Get out of jail

Image: Unsplash "Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or y...