Showing posts with label snowden. Show all posts
Showing posts with label snowden. Show all posts

Monday, 18 January 2016

Back to the future

With the comeback of the turntable might the typewriter be hot on its heels ?

As security concerns regarding the Internet start to penetrate more deeply into people's thinking might very confidential documents be kept "off the grid" all together ?

Encryption algorithms are not 100% secure - but effective enough for most applications - leaving a space when total technical security is required and a device which cannot be networked cannot be hacked in the technical sense. This does not eliminate the human factor in security (the typist for example) but narrows the attack surface.

The type of language used in the security industry is also pretty hard to fathom sometimes  for the non expert which would make a return to a simple solution such as a type writer even more understandable when absolute confidentiality is required. If Snowden had tried to wander out with 50 box loads of paper files he might well have been spotted.

An example of this hard to penetrate language is below from the OWASP top 10 pro active controls for 2016 (all of which are very sensible if you can understand them);

1. Verify for Security Early and Often
2. Parameterize Queries
3. Encode Data
4. Validate All Inputs
5. Implement Identity and Authentication Controls
6. Implement Appropriate Access Controls
7. Protect Data
8. Implement Logging and Intrusion Detection
9. Leverage Security Frameworks and Libraries
10. Error and Exception Handling

Wednesday, 6 January 2016

European VPN market to grow at 13% per year to $15 billion by 2020

Recent research and analysis  from Frost & Sullivan suggests that the current European MPLS / IP VPN market is worth just over $7 billion. This is forecast to grow to just under $15 billion by 2020 at a compound annual growth rate of 13%.

If true this shows that the genie is well and truly out of the bottle regarding internet security post Snowden.

In the corporate market increased use of cloud based storage requires greater focus on secure connections to that storage and use of the open internet for confidential data / communications starts to look negligent. If proposed Data Protection legislation is enacted fines of up to 4% of turnover will be in place which will focus attention (especially around the time when bonuses are trousered).

In the consumer market innovative products like the Shellfire VPN box developed in Germany allow the non tech savvy to notch up security levels on the home network across multiple devices. Whether all the new flavours of OTT subscription based video streaming services (which may require an IP address) will integrate OK with a system of this type remains to be seen. If not can you imagine the calls to the helpdesk ?

That said it may prove to be the case that there is a significant correlation between users of VPN's and those who wish to watch unlicensed content and avoid ISP blocks on pirate or unlawful websites.

When it comes to the really "bad guys (and girls)" the VPN / encryption debate could prove a red herring as they will probably hide in plain site on the open internet using steganography based techniques which are as old as the hills and will not be picked up by the automated systems and machines that go "ping".





  

Monday, 14 December 2015

Top Hack of 2015 ? Tesla Model S

In the past I have been referred to as a "bit of a hacker" but that was before Edward Snowden decided to be a hero / villain (delete as preferred) and change the landscape & narrative completely.

Some of the hacks of 2015 can be listed as worthy of mention - here goes - Ashley Madison, V tech, Vodafone, Talk Talk, JD Wetherspoon, Office of Personnel Management, Anthem, Premera, IRS, Slack, the FBI portal, Car Phone Warehouse, Samsung and Hilton. This does not include the long running media company hacks of live feeds by sites such as CricFree.

Without a clear definition of Hack it is very difficult to identify a winner. The OED defines hacker as below

This leaves a lot of room for manoeuvre and does not necessarily suggest that hacking breaks the law.

With that latitude my favourite is the hack of the Tesla Model S by Marc Rogers and Kevin Mahaffey - watch the video below.