Thursday, April 14, 2016

Week 5. Hey Uncle Sam... Step back a bit.

An issue has arisen that I hope does NOT become a trend.  Eduard Kovacs (Securityweek.com) wrote the following article, “Grey Hat Hackers Helped FBI Hack iPhone”, the title says it all in my opinion.  This is a troubling concept in a lot of ways in that the Government of the United States is (allegedly) actively soliciting the help of hackers to break into an American company’s product in order to gain access into the device.  Not just one device, but all of them.   “At least one of the people who helped the FBI access the information on the San Bernardino shooter’s phone without triggering Apple’s protections is a grey hat hacker who provided the law enforcement agency a previously undisclosed software vulnerability”, says Kovacs.   I believe we all know the scenario, terrorists attack innocent Americans, Police and FBI find terrorist phone, FBI demands that Apple give them a back door into the product, Apple balks and a whole host of opinions, both pro and con, start to flow across the news wire.  The FBI said they paid “Researchers” to find the solution for them but a known hacker is not a researcher.  Sorry I am running off the rails here.  I understand the national security issues and the ramifications concerning this case, but isn’t there a legal process set up in this country to follow?

It seems that Uncle Sam feels they have a right to this back door and they use scare tactics and bullying under the guise of, “Keeping you safe” in order to justify their actions.  Here Uncle Sam, take a little bit more of my freedom from me so I can feel a little safer.  How about playing by the rules and abiding by the laws you have passed and not pretending that you are only looking out for our best interests.  No Uncle Sammy, you are looking out for your best interests and American industry be damned.


                                                                                  (Play.google.com and me)

I ranted today because I feel that it is important for all of us who care about National Security, Cyber-Security and about personal freedoms, to voice our concerns, we should be outraged that our government would demand such access then pay someone to come up with a solution and NOT give the solution to the company who is in charge of the vulnerability so they can fix it.  Keeping intellectual property secure and out of the hands of someone who will exploit it for gain is a major concern for every company in existence today or at least it should be.  Apple and thousands of other companies spend millions if not billions of dollars on Research and Development to perfect and supply a product to the masses and enlist the best and brightest minds to make sure those products meet strict security standards, so to have the government (Our government) knowingly compromise Apples intellectual property is mind boggling to me.

The Federal government could have gotten the data they desired and I even bet that Apple would have supplied it to them if the proper legal channels had been followed.  Put the Feds wanted more than the data, they wanted CONTROL!!.


That is not what our country stands for.




Sunday, April 10, 2016

Week 4. Do security threats change over time?

Do Security threats change over time? 

The answer to the question is yes, threats change constantly.  Every new application, device, OS etc. will have some sort of vulnerability associated with it, known and unknown, so the sooner you accept this premise the happier you will be.

Vulnerabilities, such as, a security hole that wasn’t tested or even thought about, to back doors intentionally made in the device or system, to security issues that were intentionally created by nefarious actors, will be present to some degree.   With these holes in security come avenues in which attackers can gain access and compromise your organization, once inside, the attacker can exploit Elevation of Privilege (EoP) flaws or plant whatever time bombs he or she wants.  These bombs may prove disastrous and may even cripple your network if not addressed. 

Elevation of Privilege (EoP) occurs when an attacker is granted more authority or permissions within a network system.  An example may be; an attacker gains access into a device or system and only has “Guest” (read only) access, but by manipulating the system in some manner, he or she is able to “Elevate” the permissions to a “Standard” (read-some write) account or even worse, an “Administrative” account (Full Read-Write), thus giving themselves the ability to perform actions that can compromise the software, device or network.  What the attacker is looking for is a way to manipulate the system in some manner to gain full access, or just enough to perform nefarious deeds.  Check out Testing for Privilege escalation (OTG-AUTHZ-003) at owasp.org, good data for your security toolkit…

As technology changes, so do the vulnerabilities and threats, some are benign and do not pose a big problem while others present an enormous risk to the bottom line of any organization.  Devices we use every day that were once thought of being impermeable to threats, or to some degree, have their flaws too.  In an article in Trendmicro.com (March 22, 2016) titled, Researchers Uncover iMessage Encryption Flaw,  it’s stated that Researchers at John’s Hopkins University have allegedly found a security flaw in Apples encryption techniques with iMessages.  “The Baltimore-based institution shared details of a flaw in iOS and OSX in transmitting messages via the instant messaging application, iMessage—one that could allow an attacker to decrypt sent photos, videos, and messages”.  It’s a good read, check it out.

How a business looks at threats will determine how successful they will be going into this new Cyber Security threat future we are heading full steam ahead into.  Gone are the days where you can do just enough to get by, or even worse, nothing at all because the “capital can be used more efficiently elsewhere”. These old school mindsets must be stopped and these people fully educated about what business (Security) life has evolved into.   


 “Cyber-security threats have become much more organized and industrialized. There’s been an entire ecosystem that’s been established around the industrialization of cyber threats. It’s almost become a service offering and, as the real and perceived value of cyber targets increases, we’re seeing a corresponding increase in the investment being made in new and innovative cyber threats”.  Bill Ross, Director, Cyber Mission Assurance Systems,
General Dynamics C4 Systems. (2015).

Saturday, April 2, 2016

Week 3 - How do you explain Internet Safety to your 12 year old child? Can you?

Last week I had the opportunity to discuss Internet safety with my daughter… and 97 of her closest friends, I’ll explain… Last term I had an assignment in my White Collar Crime class that discussed Child Internet Safety concerns, you know, the DO’s and DON’TS of using the Internet.  The assignment was to create a Power Point presentation about this topic that a child could understand and not fall asleep through.  I finished and submitted the assignment and received a very good grade… I was pleased, so much so that I thought I would actually present it to my daughters 7th grade class, that is of course, if they would have me.  To my joy (dismay?) The school agreed, then asked if the 6th and 8th grades and their parents could join too. I smiled, took a big gulp and said, “Absolutely”… My daughter said “I’m going to die, dad!”


I practiced my Preso for a few weeks in front of a mirror, in my car (pretending to talk to someone on a Bluetooth) and finally the day came.  It went great … for me.. My daughter? She is still recovering.  Teachers and parents alike praised the information I discussed and the kids didn’t seem too glossy eyed.  Ahhh, sweet success.  

My topics were:
  1. Importance of creating and using strong passwords.  
  2. How to create a strong password.
  3. Wait! Don’t click that link or attachment!
  4. Keeping your reputation intact.  The importance of being a good online citizen.
  5. “The Internet is forever”, what to post and what not to post.
  6. THINK before you post…
  7. Cyber-bullying. How to protect yourself and what you should do if you are a victim.
  8. Pitfalls of an active Social Media life.  (Refer to points 4, 5, 6, 8, 9 and 10).
  9. Friending. NEVER friend anyone you do not know! Period.
  10. Online predators.  The Boogeyman exists.


Talking to kids about this stuff can be painful sometimes, if not a chore.  I hope that my daughter understands how important this info is, she said she does, time will tell….  I hope her schoolmates get it too. 

Now to work on the boy. he'll be the real challenge, I can fell it.

A synopsis of my presentation material.  Some, not all:

Creating a sound password, two different techniques:
       Create a phrase like "I hope the Giants will win the World Series in 2016" Then, take the initials of each word and add numbers and symbols to create your password.
       The password might result in this: IhtGwwtWS!16.
BTW.. It is an even year… GO Gigantes!!

Combining two words:
       Fish + Shoe = F1$hsH0e - Unique and not a word from the dictionary. 

Useful website

Your reputation is everything!
       Never post anything online that will embarrass yourself or others.  This includes..
       Risky pictures…
       Rude or disparaging words about someone or something.
       Negative content, like off color jokes… Rumors about classmates.
       Never post anything you would never tell someone in person!!
       Rule of thumb: Would your Grandmother approve?

Useful website: 

Cyberbullying.
       Cyberbullying occurs when a child or teen harasses, torments, or humiliates another using an online method.
       Cyberbullying is bullying that takes place using electronic technology such as computers, tablets and cell phones.
       Can harm the reputation of another.
       Is intended to hurt another person.
       It’s used to control someone..

Useful website: 

Online predators… THE BOOGEYMAN EXISTS!!
        Virtual Strangers.  Friending people you DON’T know.
       Assume these people want to do you harm.
       They try to friend you in social media sites like, chat rooms or online gaming sites.
       They will tell you anything you want to hear.
       They are bad people trying to do bad things.
       They pretend to be someone they are not.
       They target teens and young adults.

Useful website: 
FBI - Child Predators




Sunday, March 27, 2016

Week 2 - How can risk be managed? Can risk be avoided? Can risk be understood?

Risks in business usually occur when there is uncertainty, confusion and a lack of understanding of what risk is within an organization.  What I mean is this, if a company does not fully understand a subject such as employee theft and does not have a plan in place to educate, identify and control it, then the possibility of loss will be greater and end up costing the company much more in the end.  Therefore, it is important that every company have a clear and precise plan in place to educate and identify what risks are present and how to mitigate or avoid them. 

This isn’t always an easy endeavor though, businesses face ongoing challenges and new (Potential) threats crop up every day as new vulnerabilities get identified.  Investing in a comprehensive Risk Assessment will help keep the business and its stakeholders calm during these times of tumult.

Businesses can’t avoid risks, as a matter of fact; risks are inevitable and sometimes needed in a business plan, the more risk that a company takes, the more reward or profit can be realized, but risks must be clearly identified and understood before moving forward with the business plan.  Most Risk assessment plans will prioritize the threats as Minor, medium and critical in order to put significance to the vulnerability so actions plans can be put into play to deal with them. 

Risk Assessments ask;

What is the vulnerability?
How does it affect me?
What is the threat?
What is the impact of the threat?
What severity does this threat have?
Can we live with the threat?
Who needs to be involved and notified?
What can we learn from this threat.
What actions need to be put into play in order to mitigate or manage the threat?

Threat modeling is a great way that businesses can answer these questions.  Threat modeling is a way to identify vulnerabilities and then implement countermeasures to help lessen the impact of the threats.  A sad lesson we have learned is that not all companies use this type of analytical approach to deal with the issues they have within their networks..



Sunday, March 20, 2016

Week 1 - 2 1/2 years on this journey... Just hope I can finish strong.

Week 1 - Final term.

     It has been almost 2 1/2 years since I started this journey towards a Cyber Security degree.  In that time-frame, I have gained a great deal of knowledge in this field and feel very confident moving forward.  The threat landscape has changed as well.  Target, Home Depot and Anthem, as well as many others, were hit very hard, and we are still learning the extent of the breaches, well, as much as they will tell us anyway.  

      Almost every American was affected by one of those attacks in one way or another yet it seems to be business as usual for them and what did we get out of it? a whopping 2 free years of credit monitoring.  For those of us who were impacted by multiple or even all of them, we feel that we get monitoring from one of them and they pay the monthly costs but the other two don't have to pay a thing so in some way, they get off scot free.  

     So what happens after the 2 years? the hackers sell our data in the mean time and those that have it may act on it or they wait til the monitoring is over and pounce on us.  We can feel the burn from these acts for many more years to come, if not for the rest of our lives.  

     Hey Home depot, Target how about a 50% coupon that my family could use to buy essentials or a new lawn mower, (mine just gave up the ghost)... Anthem, how about extending the Olive branch and give my kids free doctors wellness checkups til they are 18???

Nope, Nada.. Nothing.. Zip.. Zilch, Goose egg for us.  They have moved on and don't pay a thing. Did anyone even get fired for this? I don't advocate that sort of tactic just to save face but someone had to have failed and failed big so "Where is my sacrificial Lamb!" 

Good fortunes to all.....






Monday, February 24, 2014

12 weeks of blogs and how many different subjects?


Week 1:  Social Media and what you can do to protect your kids.
Week 2:  Social Media and what not to do and Privacy protection.
Week 3:  Blocking stuff on the internet and keeping your kids away from it.  
               Updating our Knowledge.
Week 4:  Government wants you to spy on your neighbor.  Privacy issues.
Week 5:  Old habits and making security changes to stay safe and secure.
Week 6:  Staying informed and educating yourself about network security.
Week 7:  Cyber command unit funding.  Can the government really run it?
Week 8:  Password security and what to do and not to do.
Week 9:  Social Engineering and the importance of knowing what it is.
Week 10:  The new Blackphone and privacy concerns.
Week 11:  Educating friends about the importance of personal security via social 
media.
Week 12:  Privacy concerns and phone apps.

It looks like my main concerns or topics were staying safe when using any social media, keeping kids safe on the web, the importance of education, staying educated and privacy concerns.  Any one of these topics are crucial to a free and safe society.  In order for us to keep ourselves out of harm’s way, we first need to know what to look out for, how to detect it, how to fix it and what NOT to do.  But the biggest is to STAY INFORMED!!  Keep reading books and articles that explain the importance of network and personal security, take a class, talk to a friend or if you know good information, pass it along and help out your brethren. 

Keep your personal data just that… PERSONAL. Never willingly give it out unless you are absolutely sure who you are dealing with and what the impact will be.


I used several sources for my blogs including CNET.com, PCWorld, McClatchy report, Informationweek.com, homelandsecuritynewswire.com, SplashData.com, McAfee as well as others.  All of these sites have a common interest and goal and that is to educate and give us information about certain security issues and needs.  Hey just like one of my blog concerns…. EDUCATING YOURSELF…

Say NO to their terms.... YES to privacy.

Last week I received my new work phone and decided to download a very popular app (Game) to it.  Like all apps, before you download it, you have to accept the terms of the app and of course allow certain permissions for the app.  I went through the list of the permissions and saw the ones I have below.  I was a bit concerned though after reading through them.  Needless to say, I didn’t download it.

Phone Calls:
Allows the app to access the features of this device. This permission allows the app to determine the phone number and device ID’s, whether on a call is active, and the remote number connected by a call.

It needs to know what the phone is capable of, what the phone number is and all the phone numbers of people you call and call you? Why?

Approximate Location:
Allows apps to access your approximate location using location services based on network sources, such as mobile phone towers and Wi-Fi Aps. When these location services are available and enabled, this permission allows apps to determine your approximate location.

The app company needs to know all the hotspots and cell towers that the phone comes in contact with, why?

View Wi-Fi Connections:
Allows the app to view info about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices.

Why does any of my Wi-Fi networking and devices need to be passed along to the app company?

View Network Connections:
Allows the app to view info about network connections such as which networks exist and are connected.

Again, why do they need to know about the networks I come in contact with? It isn’t just that they want to map out hotspots is it?

According to several articles I read, all of these can easily be explained by “Well we just don’t want to send too many of the same ads to the customer etc.” or “We need to be able to target our customers more effectively”.  I get it, if you download a “FREE” app, the company needs to make money somehow, but how much of my personal information, the information of those calling me or those that I call, are they allowed to have?  Am I asking the wrong questions? Am I just on old fuddy duddy, an 8-track tape guy living in a Blu-Ray era?

Parting Shots:

We live in a data centric era now where everything about anything is put out on display.  People use social media to show off or worse find out personal information about others and either laugh at them to feel better about themselves or use it in a dark manner.  We have allowed ourselves to become numb to the importance of privacy and the importance of anonymity but why? In these days of reality TV and instant fame, everyone has to be seen if not heard.  But by doing so, you always seem to show a little more of yourself than you need to or should.  We as a society need to start pulling back the reins and forcing our privacy and NOT blindly “Accept their terms”, accept your own terms and say no to the slow incrementalism of privacy loss.