tag:blogger.com,1999:blog-53580572359024862842008-09-03T09:30:01.147-05:00Security Karma"because no good deed goes unpunished..."Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comBlogger56125tag:blogger.com,1999:blog-5358057235902486284.post-56817564885470370482008-09-03T09:30:00.000-05:002008-09-03T09:30:01.334-05:00IT pros name security top concern, security pros say huh?<p><a href="http://www.informationweek.com/news/security/management/showArticle.jhtml?articleID=210300074">Ahem</a>.</p> <blockquote> <p>The Computing Technology Industry Association (CompTIA) announced this week that its Web poll, conducted from June 3 through Aug. 25, showed that one-third of IT professionals believe that securing their networks and data is their biggest concern.</p> </blockquote> <p>I don't want to seem skeptical and perhaps the IT pros I have dealt with are the exceptions... but are these the same IT pros that push poor design, complain about preventative security measures, argue about how their app is different, tell me "it's ok, really", and slash my budget? Not that I'm complaining... I'm just sayin'.</p> <p>But then again, security was the top concern of 33% of those surveyed; so perhaps I just deal with the other 66% 99% of the time. ;)</p> Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-63349190240276033502008-09-01T09:30:00.001-05:002008-09-01T09:30:00.655-05:00Happy Labor Day<a href="http://lh3.ggpht.com/djglass/SLmPppI7q3I/AAAAAAAAD_U/_uij_Anj-88/s1600-h/LaborDay%5B5%5D.gif"><img align="left" alt="Labor Day" border="0" height="239" src="http://lh4.ggpht.com/djglass/SLmPqNZiQiI/AAAAAAAAD_Y/qU0csfAdSyk/LaborDay_thumb%5B3%5D.gif?imgmax=800" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" title="Labor Day" width="244" /></a> Happy <a href="http://en.wikipedia.org/wiki/Labor_Day_(United_States)">Labor Day</a> weekend for all my American readers. For all my foreign readers, happy <a href="http://en.wikipedia.org/wiki/May_Day">May Day</a>… sorry I’m a four months late. Now get back to work.<br />
In the US we use the day to catch up on napping, outdoor activities (it’s the last holiday of summer), American football, and eating. In much of the rest of the world May Day is a day of <a href="http://en.wikipedia.org/wiki/Taksim_Square_massacre">celebrating workers rights</a> and is often filled with protests, marches, speeches, and the <a href="http://en.wikipedia.org/wiki/Taksim_Square_massacre">occasional massacre</a>.<br />
That being said: enjoy the day, comrades!Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-46961966103866160362008-08-29T10:30:00.000-05:002008-08-29T10:30:00.552-05:00Password reset unsafe! Personal information easy to discover!Ok, I admit... the typical reader of <a href="http://www.sciam.com/">Scientific American</a> are probably not the most Internet-savvy folks out there and I actually loved Herbert H. Thompson's article "<a href="http://www.sciam.com/article.cfm?id=anatomy-of-a-social-hack&print=true">How I Stole Someone's Identity</a>." Mr. Thompson does a good job explaining how to footprint a person online and begin compromising account after account of theirs simply by using the password reset feature and "security questions" that are used to validate identity.<br />
<blockquote>For many of us, the abundance of personal information we put online combined with the popular model of sending a password reset e-mail has our online security resting unsteadily on the shoulders of one or two e-mail accounts. In Kim's case some of that information came from a blog, but it could just as easily have come from a MySpace page, a sibling's blog (speaking of their birthday, mom's name, etcetera) or from any number of places online.</blockquote>To someone that has been around information security for a while now, none of this is news. This is actually a little old-school footprint and crack. The problem is: in the old days, the hacker would have to go through great lengths to investigate their marks. As this article shows, those days are gone and now with a simple web search we can find out almost everything about a person. All of our digital shadows are getting longer and keeping track of every account we've signed up for is getting more and more difficult.<br />
<blockquote>It's also critical to remember that once you put data online, it's almost impossible to delete it later. The more you blog about yourself, the more details you put in your social networking profiles, the more information about you is being archived, copied, backed up and analyzed almost immediately. Think first, post later.</blockquote>Great article and well worth the read.<br />
<br />
I'll be posting more about the new risk model in the 2.0 world soon.<br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-58757932001008278712008-08-28T09:30:00.000-05:002008-08-28T09:30:00.450-05:00TSA takes security to the slopes, travelers run into treesMichael Chertoff must have gone skiing and thought of this little beauty. If you have flown through DFW and a handful of other airports across the country you may have noticed that there will soon be three lines to pass through airport security. Taking a queue from ski resorts travelers will now have to decide between black diamonds, blue squares, green dots, and purple horseshoes.<br />
<br />
<div class="separator" style="clear: both; text-align: center;"><a href="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLYWDPv5jfI/AAAAAAAAD_A/yaqx78RSH4E/s1600-h/Picture+1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLYWDPv5jfI/AAAAAAAAD_A/Oh6j-3SfE1o/s400-R/Picture+1.png" /></a></div><br />
Now I won't chide the TSA too much for trying... but let's be honest for a second here. Like skiing, how many blue square travelers will think they're good enough to take on the black diamond line only to clog things up by forgetting their liter of water in the carry on and a pen knife in their pocket. What then? Blue square folks holding up the black diamond line, black diamond travelers in the green dot line because it's empty, and green dot travelers wondering where the lift is. So... basically... what we have now. Now go hit the slopes!<br />
<br />
More info about black diamond program <a href="http://www.tsa.gov/approach/black_diamond.shtm">here</a>.<br />
<br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-22713878168489064942008-08-27T15:30:00.002-05:002008-08-27T21:23:44.391-05:0010 < 8,000,000<a href="http://www.bestwestern.com/">Best Western</a> has let it be known that the <a href="http://www.securitykarma.com/2008/08/over-8-million-best-western-records.html">compromise</a> <a href="http://www.sundayherald.com/news/heraldnews/display.var.2432225.0.revealed_8_million_victims_in_the_worlds_biggest_cyber_heist.php">that</a> <a href="http://www.dailymail.co.uk/news/worldnews/article-1048861/Eight-million-people-risk-ID-fraud-credit-card-details-stolen-hotel-chain-hackers.html">was</a> <a href="http://blogs.pcworld.com/staffblog/archives/007555.html">widely</a> <a href="http://www.telegraph.co.uk/news/uknews/2613095/Hackers-steal-details-of-millions-of-Best-Western-hotel-guests.html">reported</a> was contained to only 10 guests that stayed at one of the chain's many hotels in Germany.<br />
<blockquote>That's three fewer than the 13 customer records that Best Western International Inc. initially said had been exposed, and a far cry from the 8 million stolen records reported by the Glasgow Sunday Herald, a Scottish newspaper that broke the news of the breach on Sunday.</blockquote>So not so bad... this is great news (unless you are one of the ten people about to get letters and free credit monitoring).<br />
<h3>Original Story</h3><ul><li><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9113499&source=NLT_SEC&nlid=38">Best Western says data breach even smaller than first thought</a><br />
</li>
</ul><blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-91634073756108203202008-08-27T10:00:00.001-05:002008-08-27T10:00:02.285-05:00The Internet is broken<div class="separator" style="clear: both; text-align: center;"><a href="http://3.bp.blogspot.com/_YM_k6IgTR7E/SLTJCGa8ffI/AAAAAAAAD-4/fewPlCgA8ck/s1600-h/gateway.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_YM_k6IgTR7E/SLTJCGa8ffI/AAAAAAAAD-4/F_P_uh01wTI/s200-R/gateway.jpg" /></a></div>This isn't exactly a "vulnerability" and has been around for years... but it is starting to get used more and more and is begging to get some press. <a href="http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.html">Threat Level</a> over at <a href="http://www.wired.com/">Wired</a> has a nice summary and explanation of <a href="http://en.wikipedia.org/wiki/IP_hijacking">IP Hijacking</a> and how it's getting more play today and there isn't much anyone can do about it.<br />
<blockquote>That's what occurred earlier this year when Pakistan Telecom inadvertently hijacked YouTube traffic from around the world. The traffic hit a dead-end in Pakistan, so it was apparent to everyone trying to visit YouTube that something was amiss.<br />
<br />
Pilosov's innovation is to forward the intercepted data silently to the actual destination, so that no outage occurs.</blockquote>This hack is a symptom of a much bigger issue. The real problem is that the Internet is built and depends on protocols that were created in <a href="http://tools.ietf.org/html/rfc791">1980 (IPv4)</a>, <a href="http://tools.ietf.org/html/rfc821">1982 (SMTP)</a>, <a href="http://tools.ietf.org/html/rfc920">1984 (DNS)</a>, <a href="http://tools.ietf.org/html/rfc1771">1995 (BGP)</a>, etc. and we (the IT community) have been stacking more complexity on top of very simplistic and insecure infrastructure.<br />
<br />
Problems such as <a href="http://en.wikipedia.org/wiki/E-mail_spam">spam</a>, <a href="http://en.wikipedia.org/wiki/Ip_spoofing">IP spoofing</a>, <a href="http://en.wikipedia.org/wiki/DNS_cache_poisoning">DNS cache poisoning</a>, <a href="http://en.wikipedia.org/wiki/Arp_poisoning">ARP poisoning</a>, etc. are very effective and hard to detect or stop because the protocols themselves have little to no built-in security mechanisms. Why hasn't the industry fixed this? There is too much money in <span style="font-weight: bold;"><span style="font-size: medium;">not</span></span> fixing the problem. Network hardware vendors such as <a href="http://www.cisco.com/">Cisco</a>, <a href="http://www.juniper.net/">Juniper</a>, <a href="http://www.3com.com/">3Com</a>, <a href="http://www.nortel.com/">Nortel</a>, <a href="http://www.alcatel-lucent.com/">Lucent</a>, etc. have no incentive to fix the inherent problems since they make too much money on selling security devices, software, and services that slap band-aids on the problems, slowing down but never stopping attacks. Once the attacks pick up again or a new threat emerges the vendors are ready with more devices, software, and services... more band-aids.<br />
<blockquote>ISPs... have been holding their breath, "hoping that people don’t discover (this) and exploit it."</blockquote>How do we fix this? We need the users of these products big and small to start demanding fixes to the fundamental security issues. Without monetary incentive these companies will continue to push their "fixes" upon us and leave the core infrastructure of the Internet vulnerable to attack. Until then? Keep buying band-aids, check DNS and eBGP periodically to ensure proper resolution and routing and cross your fingers.<br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-34892705982429647282008-08-26T13:00:00.003-05:002008-08-27T11:26:01.253-05:00Seriously now, we're starting to spoil them<div class="separator" style="clear: both; text-align: center;"><a href="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLRGQdhmHfI/AAAAAAAAD-w/nSIBodL-gt0/s1600-h/hard-drive.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLRGQdhmHfI/AAAAAAAAD-w/wVMydr4KJzg/s200-R/hard-drive.jpg" /></a></div><a href="http://www.theregister.co.uk/2008/08/26/more_details_lost/">Hackers are going to get lazy at this rate in Britain</a>.<br />
<span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; border-collapse: collapse; font-family: Helvetica;"><blockquote>A computer hard disc containing one million sets of bank details was bought on eBay for just £35.<br />
<br />
The secondhand PC contained details of customers from American Express, NatWest and Royal Bank of Scotland. The files included names, addresses, sort codes, account numbers, credit card numbers, mobile phone numbers, mothers' maiden names and even scans of signatures - more than enough for an identity thief.<br />
</blockquote></span><br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-77190088694852790212008-08-26T10:30:00.002-05:002008-08-26T10:30:00.919-05:00Why Red Hat should be ashamed<div class="separator" style="clear: both; text-align: center;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLDQngiEopI/AAAAAAAAD9o/z6eOw1i7Khc/s1600-h/log-in_corner_shadowman.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLDQngiEopI/AAAAAAAAD9o/cLd07KrtZmY/s200-R/log-in_corner_shadowman.gif" /></a></div>This is big. Real big. As a former <a class="zem_slink" href="http://www.redhat.com/" rel="homepage" title="Red Hat">Red Hat</a> Enterprise <a class="zem_slink" href="http://en.wikipedia.org/wiki/Linux" rel="wikipedia" title="Linux">Linux</a> (RHEL) admin and dabbler in things <a class="zem_slink" href="http://fedoraproject.org/" rel="homepage" title="Fedora (operating system)">Fedora</a> I find this news very disturbing. I'm not upset that servers at RH got compromised... that happens. What shouldn't happen is a breach of the infrastructure servers that manage your package signing. When trust is a key part of your business model (who is going to purchase an OS let alone download and install packages they can't trust?) keeping encryption management servers protected as much if not more than your financial databases.<br />
<br />
Certificate Authority (CA) servers, key management systems, and certificate management systems should among be the most difficult systems on your network to access, no exception. They shouldn't run web servers or the public Internet (or your Intranet for that matter). The NIDS/NIPS systems should be cranked up and watching for the baddies and your firewalls should be blocking all inbound and outbound communication other than only what is absolutely needed to function in the environment. Many businesses keep these servers off the grid (no network connectivity) in a secured room and all package signing is done via sneakernet (carrying data to be signed on physical media into the room). <br />
<br />
<div class="separator" style="clear: both; text-align: center;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLDQtyAvdFI/AAAAAAAAD9w/QzFsM675Eig/s1600-h/fedora.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLDQtyAvdFI/AAAAAAAAD9w/WnJMKRMX9T8/s200-R/fedora.jpg" /></a></div>Red Hat has recreated the keys for Fedora packages but there was no mention if they are creating new RHEL keys. If I were running RHEL servers I would be compiling <a class="zem_slink" href="http://en.wikipedia.org/wiki/OpenSSH" rel="wikipedia" title="OpenSSH">OpenSSH</a> from source at this point. This is coming from someone who doesn't typically fall into the "Henny-Penny" category of infosec professionals. I like to temper my paranoia with a healthy dose of reality. However, on this one I think I am upset that Red Hat's infrastructure is architected in such a way as to let this happen and can't trust they aren't still rooted in some way. I have a feeling many security-conscience system administrators will be looking sideways at any and all new packages from Red Hat and Fedora for the next few months.<br />
<br />
I am harsh because I love. I have run Red Hat since 1998 (5.2) and still run a Fedora laptop at home and use my RHEL 4 VM a few times a week at work. I have fought long and hard to get management sign-off at various jobs to bring Linux into the datacenter and hate when the community gives Microsoft ammunition for white papers.<br />
<br />
<h3>Related Articles</h3><a href="http://www.infoworld.com/article/08/08/22/Red_Hat_admits_breach_of_its_servers_Fedora_1.html?source=rss&url=http://www.infoworld.com/article/08/08/22/Red_Hat_admits_breach_of_its_servers_Fedora_1.html">Red Hat admits breach of its servers, Fedora</a><br />
<a href="http://www.hackaday.com/2008/08/23/red-hat-confirms-security-breach/">Red Hat confirms security breach</a><br />
<a href="http://news.cnet.com/8301-1009_3-10023565-83.html?hhTest=1&part=rss&subj=news">Red Hat, Fedora servers compromised</a><br />
<a href="http://www.theregister.co.uk/2008/08/22/red_hat_systems_hacked/">Red Hat hack prompts critical OpenSSH update</a><br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-24753760501407514782008-08-25T15:30:00.001-05:002008-08-25T15:39:07.783-05:00Best Western refutes breach claims<a href="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLMYI5LFRvI/AAAAAAAAD-Q/tJoCgbRcjq0/s1600-h/oops.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLMYI5LFRvI/AAAAAAAAD-Q/ij2Wr3h0m9U/s200-R/oops.jpg" /></a>As a follow up to my post yesterday "<a href="http://www.securitykarma.com/2008/08/over-8-million-best-western-records.html">Over 8 million Best Western records stolen and sold to Russian mob</a>," <a href="http://www.bestwestern.com/">Best Western</a> is reporting that only 13 records (not 8,000,000) may have been exposed. A company spokesman states:<br />
<blockquote>There was one instance of suspicious activity at a single hotel with respect to 13 guests, who are being notified. We are working with the FBI and international authorities to investigate the source of the other claims, which were never presented to us for investigation prior to publication of the Herald story. We have found no suspicious activity to support them.</blockquote>Best Western points to their compliance with the PCI DSS as further proof that the allegations aren't true. Now everything they are saying may be true, only one hotel was involved in the breach, and only 13 records were compromised, and that they are fully PCI DSS compliant. However, with statements such as<br />
<blockquote>... our most recent internal review was conducted in August 2008, as was our most recent external test and review. Both evaluations showed Best Western to be compliant with PCI DSS. </blockquote>... it sounds as if they are relying on the fact they are PCI compliant as proof that such an audacious hack (the 8 million, not 13) can not happen. It can. Hannaford was "compliant" with the DSS but there were 4.2 million credit card numbers involved in that breach. That brings up the larger topic of compliance vs. best practices... which will have to wait for a different post.<br />
<br />
In the end, I hope BW is correct in their investigation and the reports were wrong. I've stayed at numerous BW hotels over the past few years myself so I'm a stakeholder of sorts in all this.<br />
<br />
<h3>Related Articles</h3><ul><li><a href="http://www.marketwatch.com/news/story/best-western-responds-sunday-herald/story.aspx?guid={A87F9682-AC67-4803-A135-B6ACF42C0956}&dist=hppr">Best Western Responds to Sunday Herald Story Claiming Security Breach</a></li>
<li><a href="http://computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9113402&taxonomyId=17&intsrc=kc_top">Best Western refutes story claiming 8 million customer records were breached</a><br />
</li>
<li><a href="http://www.informationweek.com/news/security/attacks/showArticle.jhtml?articleID=210200550">8 Million-Record Data Breach Claim 'Grossly Unsubstantiated,' Says Best Western </a><br />
</li>
<li><a href="http://www.securitypronews.com/insiderreports/insider/spn-49-20080825BestWesternHackWorstExaggerationInHistory.html">Best Western Hack Worst Exaggeration In History?</a><br />
</li>
</ul><blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-42819875489069678482008-08-25T10:00:00.004-05:002008-08-25T10:05:03.476-05:00Congress to DHS - Terror Watch List needs major overall<div xmlns="http://www.w3.org/1999/xhtml">Interesting story in <a class="zem_slink" href="http://www.wsj.com/" rel="homepage" title="The Wall Street Journal">the Wall Street Journal</a> regarding a Congressional report finding that the TWL is:<br />
<blockquote>...hobbled by technology challenges, and the $500 million program designed to upgrade it is on the verge of collapse, according to a preliminary congressional investigation.</blockquote>Interesting fact I didn't know... the TWL DB was built by <a class="zem_slink" href="http://www.lockheedmartin.com/" rel="homepage" title="Lockheed Martin">Lockheed Martin</a> (I know when I think database I think Lockheed... WTF?) back in 2001 and is unable to do keyword searches... they have a person build a query. I'm not kidding. I'll repeat. The <a class="zem_slink" href="http://en.wikipedia.org/wiki/United_States_Department_of_Homeland_Security" rel="wikipedia" title="United States Department of Homeland Security">Department of Homeland Security</a> builds the <a class="zem_slink" href="http://en.wikipedia.org/wiki/No_Fly_List" rel="wikipedia" title="No Fly List">Terror Watch List</a> by running a friggin' query.<br />
<br />
<h3>Related Articles</h3><ul><li><a href="http://online.wsj.com/article/SB121937117186362585.html?mod=googlenews_wsj">Flaws Found In Watch List For Terrorists - Wall Street Journal</a></li>
<li><a href="http://www.securitymanagement.com/news/congress-finds-critical-failures-affecting-terror-watch-list-004511">Congress Finds Critical Failures Affecting Terror Watch List - Securty Management </a><br />
</li>
<li><a href="http://science.house.gov/press/PRArticle.aspx?NewsID=2289">Technical Flaws Hinder Terrorist Watch List; Congress Calls for Investigation - House Science and Technology Committee</a></li>
<li><a href="http://democrats.science.house.gov/Media/File/AdminLetters/bm_InspectorGeneralMaquire_terrorwatchlist_8.21.08.pdf">Miller letter to Inspector General Maquire Regarding Technical Flaws in Terrorist Watch List [pdf]</a></li>
<li><a href="http://democrats.science.house.gov/Media/File/Commdocs/Staff_Memo_toBM_terror_watch_8.21.08.pdf">Memo to Subcommittee Chairman Miller [pdf]</a><br />
</li>
</ul><span id="ArticleDetailsCtrl_LongVersionLabel"></span><a href="http://democrats.science.house.gov/Media/File/Commdocs/Staff_Memo_toBM_terror_watch_8.21.08.pdf"></a><br />
<blockquote></blockquote></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-22312225537648459242008-08-24T19:30:00.003-05:002008-08-24T20:11:10.957-05:00Over 8 million Best Western records stolen and sold to Russian mob<div class="separator" style="clear: both; text-align: center;"><a href="http://3.bp.blogspot.com/_YM_k6IgTR7E/SLIEbTQ1JXI/AAAAAAAAD-I/I3WZc0TMtf4/s1600-h/best_western_logo.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_YM_k6IgTR7E/SLIEbTQ1JXI/AAAAAAAAD-I/_SlFEUnrpqk/s200-R/best_western_logo.gif" /></a></div>Looks like this one is going to be up there with the <a href="http://www.tjx.com/">TJX</a> and <a href="http://www.hannaford.com/">Hannaford</a> breaches. The <a href="http://www.telegraph.co.uk/">London Telegraph</a> is <a href="http://www.telegraph.co.uk/news/uknews/2613095/Hackers-steal-details-of-millions-of-Best-Western-hotel-guests.html">reporting</a> that over 8 million customer accounts have been stolen from <a href="http://www.bestwestern.com/">Best Western</a> and sold to the Russian mafia. This story is still breaking but from the article:<br />
<blockquote>It is believed an Indian hacker succeeded in bypassing the security software and placing a Trojan virus on one of the firm's machines used for reservations.<br />
<br />
The next time a staff member logged in, his or her username and password were collected, stored then put up for sale on a website operated by a branch of the Russian mafia.<br />
<br />
The stolen data includes a range of private information such as home addresses, telephone numbers, credit card details and place of employment.<br />
<br />
Best Western fixed the security breach on Friday after being alerted by a Sunday newspaper, which had discovered the crime.</blockquote><br />
A Sunday newspaper discovered the crime? Jeez. I'm sure there will be much, much more to come about this one.<br />
<br />
Original Story: <a href="http://www.telegraph.co.uk/news/uknews/2613095/Hackers-steal-details-of-millions-of-Best-Western-hotel-guests.html">Hackers steal details of millions of Best Western hotel guests</a><br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-57621361311084591072008-08-24T11:30:00.007-05:002008-08-25T10:06:11.783-05:00They have the technology, but no security<a href="http://4.bp.blogspot.com/_YM_k6IgTR7E/SLGTDvnOjTI/AAAAAAAAD-A/09b5T_MdptE/s1600-h/mod_logo.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://4.bp.blogspot.com/_YM_k6IgTR7E/SLGTDvnOjTI/AAAAAAAAD-A/dPCmV6ILyZA/s200-R/mod_logo.jpg" /></a>Great article in the London Times this morning entitled "<a href="http://www.timesonline.co.uk/tol/comment/columnists/guest_contributors/article4592322.ece">We have the technology, but no security</a>." Author <a class="zem_slink" href="http://en.wikipedia.org/wiki/Simon_Davies_%28privacy_advocate%29" rel="wikipedia" title="Simon Davies (privacy advocate)">Simon Davies</a> goes through the laundry list of compromises that have hit the British government over the past year and correctly comes to the conclusion that it is a lack of standards, policy, and understanding about data security that lead to a culture of carelessness.<br />
<br />
Hackers in Britain don't need to scan servers for vulnerabilities nor do they have to prepare "spear phishing" attacks to compromise desktops within the government... they just need to walk around the street and look for discarded DVDs and USB key drives. Their problems are definitely on the people and process side of the security triad (people, process, technology).<br />
<br />
I hope someone in the British government takes control of the situation and institutes an educational program coupled with a strong encryption and data access policies with the necessary technical controls to help enforcement.<br />
<br />
<h3>Related Articles</h3><ul><li><a href="http://politics.guardian.co.uk/homeaffairs/story/0,,2233519,00.html?gusrc=rss">Britain 'worst in Europe for privacy'</a></li>
<li><a href="http://www.iwr.co.uk/information-world-review/news/2224554/information-thousands-prisoners">Information on thousands of prisoners missing</a></li>
<li><a href="http://www.boingboing.net/2008/08/22/uk-govt-loses-4-mill.html">UK gov't loses 4 million citizens' personal info</a></li>
<li><a href="http://www.guardian.co.uk/technology/2008/aug/23/security.justice?gusrc=rss">Pitfalls of miniaturisation as PA Consultancy loses prisoners' details</a></li>
<li><a href="http://www.pcworld.com/businesscenter/article/150219/uk_government_spills_personal_data_of_millions.html">UK Government Spills Personal Data of Millions</a> </li>
<li><a href="http://www.telegraph.co.uk/news/newstopics/politics/2608805/Thousands-of-personal-records-lost-each-month.html">Thousands of personal records lost each month</a> </li>
<li><a href="http://www.guardian.co.uk/politics/2008/aug/24/justice.conservatives">Tories call for data loss prosecutions</a></li>
<li><a href="http://www.computerworld.com.au/index.php/id;50110485">UK gov't loses personal data on 4M people in one year</a><br />
</li>
</ul><blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-53657864909512814962008-08-23T22:00:00.004-05:002008-08-24T13:49:44.433-05:00a wii haiku<div class="mobile-photo"></div><div style="font-family: Helvetica; font-size-adjust: none; font-size: 12px; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; margin: 0px;"><div style="text-align: center;"><span style="font-size: x-large;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="color: #666666;">a cord pulled too hard<br />
</span></span></span></div></div><div style="font-family: Helvetica; font-size-adjust: none; font-size: 12px; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; margin: 0px;"><div style="text-align: center;"><span style="font-size: x-large;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="color: #666666;">the wii falls down </span></span></span><span style="font-size: x-large;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="color: #666666;"> crashes breaks </span></span></span></div></div><div style="font-family: Helvetica; font-size-adjust: none; font-size: 12px; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; margin: 0px;"><div style="text-align: center;"><span style="font-size: x-large;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="color: #666666;">my heart sinks to floor</span></span></span></div><div style="text-align: center;"></div></div><div style="font-family: Helvetica; font-size-adjust: none; font-size: 12px; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; margin: 0px;"></div><br />
<div class="mobile-photo"><div style="text-align: center;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLAxu2-jnxI/AAAAAAAAD9U/PxAVv05WLTQ/s1600-h/photo-719552.jpg"><img alt="" border="0" id="BLOGGER_PHOTO_ID_5237741047733526290" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLAxu2-jnxI/AAAAAAAAD9U/PxAVv05WLTQ/s400/photo-719552.jpg" /></a></div></div><div style="text-align: center;"></div><br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-76205610452696506852008-08-22T09:30:00.003-05:002008-08-24T13:57:06.116-05:00TSA ninja strikes, renders nine planes helpless.<div xmlns="http://www.w3.org/1999/xhtml"><div style="text-align: center;"></div><div style="text-align: center;"></div><div style="text-align: center;"></div><div style="text-align: center;"><a href="http://3.bp.blogspot.com/_YM_k6IgTR7E/SK428N7KsmI/AAAAAAAAD9I/E2ITvAp4XBE/s1600-h/TSA-NINJA.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_YM_k6IgTR7E/SK428N7KsmI/AAAAAAAAD9I/xTnP3CiS-XQ/s400-R/TSA-NINJA.png" /></a></div><div class="separator" style="clear: both; text-align: left;"></div><div style="text-align: left;">From the National Security Ninjas Desk:</div><a href="http://www.abcnews.go.com/Blotter/story?id=5624381&page=1">ABC News: TSA Fires Back: Blames Airline for 'Security Violation'</a><br />
<br />
I'll start with a summary from the article:<br />
<blockquote>A TSA inspector, as part of a spot security check, used a sensitive aircraft probe as a handhold to gain access to parked <a class="zem_slink" href="http://www.aa.com/content/footer/eagleOverview.jhtml" rel="homepage" title="American Eagle Airlines">American Eagle</a> planes at <a class="zem_slink" href="http://flychicago.com/Ohare/OhareHomepage.shtm" rel="homepage" title="O'Hare International Airport">Chicago's O'Hare airport</a>.</blockquote>The TSA ninja caused AE to ground nine Eagle commuter jets, causing 40 flights to be delayed, maintenance costs to repair the broken parts (they ain't cheap folks), and loads of pissed passengers.<br />
<br />
To top it off:<br />
<blockquote>TSA, however, strongly defended its inspector's actions, noting in a<br />
statement that he was able to gain interior access to seven of the nine<br />
aircraft he inspected, which was an "apparent violation of the<br />
airline's security program."</blockquote>The kicker is that the TSA is considering fining AE for the "violations." I'd like to deconstruct the argument that AE was in "violation of the airline's security program." Airplanes aren't cars and the airport tarmac isn't a Wal-Mart parking lot, in order to get onto the tarmac you must pass through... you guessed it, TSA security check-points.<br />
<br />
Furthermore, you need specialized badges, passcards, and need to be recognized by sight to get into the secured areas. Trust me... it ain't easy. So if you look like you belong, you're a familiar face, and you are out on the tarmac, most likely people will let you go on with your day because the airport is a busy, busy place and they all have things to do.<br />
<br />
I can understand if the guy bribed an Eagle shift worker for a uniform, knocked out a sleeping American Eagle security henchman standing guard outside the plane, and got inside the plane without breaking anything. Where exactly did the TSA agent gain unauthorized access in "apparent violation of the airline's security?" What they did do was walk through security checkpoints, walk into areas they are allowed to go, broke several planes so they couldn't take off, and wasted the time of a lot of hard working people.<br />
<br />
If you are reading this blog you most likely understand that insider threats are one of the largest problems facing information security today. But seriously, this is like the IT security guy complaining that he was able to hit a server with a hammer when he has badge access to the datacenter and keys to the cage and rack where the server was located... it's just not a fair assessment.<br />
<br />
The TSA should stick to what it's best at: <a href="http://www.flickr.com/photos/cjd/1418632004/">frisking nuns</a>, <a href="http://consumerist.com/5039530/tsa-martinet-claims-her-unpublished-rules-trump-real-ones">making up rules as they go along</a>, <a href="http://www.tsa.gov/blog/2008/05/you-asked-for-ityou-got-it-millimeter.html">peeking straight through our clothing</a>, and <a href="http://www.boingboing.net/2008/01/09/tsa-searches-detains.html">detaining five year old children</a>. </div><br />
<fieldset class="zemanta-related"><br />
<legend class="zemanta-related-title">Related Articles</legend><br />
<ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.gadling.com/2008/08/20/tsa-inspector-damages-planes-and-causes-major-flight-delays/">TSA inspector damages planes and causes major flight delays</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/21/TSA.american.eagle/index.html?eref=rss_latest">TSA investigating possible violations by American Eagle</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/21/TSA.american.eagle/index.html?eref=rss_travel">TSA investigating American Eagle at O'Hare</a></li>
<li class="zemanta-article-ul-li"><a href="http://abcnews.go.com/Blotter/story?id=5619046&page=1">Pilots Outraged Over TSA's Botched Security Check</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/20/grounded.jets/index.html?eref=rss_us">Inspector's method grounds 9 aircraft, TSA says</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/20/grounded.jets/index.html?eref=rss_latest">Jets grounded after inspector grabs sensitive equipment</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/20/grounded.jets/index.html?eref=rss_travel">Jets grounded after inspector grabs instrument</a></li>
<li class="zemanta-article-ul-li"><a href="http://abcnews.go.com/Blotter/story?id=5613502&page=1">TSA Snafu Damages Nine Planes at O'Hare Field</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.schneier.com/blog/archives/2008/08/tsa_follies.html">TSA Follies</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.boingboing.net/2008/08/20/tsa-inspector-breaks.html">TSA inspector breaks airplanes by climbing on them using instruments as handholds</a></li>
</ul></fieldset><blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-43988956510599998972008-08-21T10:00:00.001-05:002008-08-24T14:24:27.799-05:00To cert, or not to cert, that is the Question:<div xmlns="http://www.w3.org/1999/xhtml"><a href="http://abovesecuritytraining.com/resources/Certification.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="35" src="http://abovesecuritytraining.com/resources/Certification.gif" width="200" /></a>Mike Rothman wrote an interesting article titled "<a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1323863,00.html?track=NL-430&ad=654062&asrc=EM_NLT_4270974&uid=7868131">Security certifications: Are they worth the trouble?</a>" at <a href="http://searchsecurity.techtarget.com/home/0,289692,sid14,00.html">SearchSecurity.com</a>. His take was pretty close to the one I have and his expierence is in line with what I have experienced in my years within the IT field. From the article:<br />
<blockquote>I've never really been a fan of certifications for two reasons: some of the smartest security folks I know don't have any, and some of the least capable do.</blockquote>I don't have a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Certified_Information_Systems_Security_Professional" rel="wikipedia" title="Certified Information Systems Security Professional">CISSP</a>, nor have I earned a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Certified_Ethical_Hacker" rel="wikipedia" title="Certified Ethical Hacker">CEH</a>, <a class="zem_slink" href="http://en.wikipedia.org/wiki/Certified_Information_System_Auditor" rel="wikipedia" title="Certified Information System Auditor">CISA</a>, Security+, etc. Quite honestly I am too busy to study for any of them. I have found a few types of "certified" folks out there:<br />
<ul><li>Smart, dedicated professional looking to expand knowledge and become an expert in their chosen field spending hours studying texts, reading white papers, etc.<br />
</li>
<li>Smart, dedicated professional that went to training and took the exam at the end because... "why not?" <br />
</li>
<li>Poor soul sent to a boot camp training course to take on new technology / responsibility that they have no experience in, took the test on Friday afternoon after getting their free travel mug and polo shirt.<br />
</li>
<li>Sales engineers and the ilk that need certifications to "prove" expertise... I still remember the CISSP, CEH, LMNOP vendor dude that didn't understand basic routing issues and insisted that eBGP could NOT be run on an internal network.</li>
</ul>I am, of course, taking a light-hearted job at my certified security bretheren out there. Seriously though, I have not impressed with some of the <a class="zem_slink" href="http://en.wikipedia.org/wiki/Cisco_Career_Certifications" rel="wikipedia" title="Cisco Career Certifications">CCIE</a> (I helped one write an ACL on a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Cisco_PIX" rel="wikipedia" title="Cisco PIX">PIX firewall</a> once... no joke), CISSP, CEH, etc. that I have been meeting and interviewing lately.<br />
<br />
I think what is beginning to happen with security certifications is what has happened with <a class="zem_slink" href="http://en.wikipedia.org/wiki/Cisco_Career_Certifications" rel="wikipedia" title="Cisco Career Certifications">Cisco certifications</a> and college degrees... so many unqualified, uninterested, and incompetent people have been attaining the high level certs that they are becoming almost worthless as a selection criteria of value or knowledge.<br />
<br />
That being said, I would actually consider a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Certification" rel="wikipedia" title="Certification">certification</a> that still meant something like the CISSP (but that is changing by the day) or a newer, lesser known <a class="zem_slink" href="http://en.wikipedia.org/wiki/SANS_Institute" rel="wikipedia" title="SANS Institute">SANS</a> certification (management or technical tracks... I still haven't decided which direction I want my career to go). Of course that would put me in the first type of certified professional I listed above ;)<br />
<blockquote></blockquote></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-48068356318132784062008-08-20T22:45:00.001-05:002008-08-24T13:40:24.165-05:00Squirtle: squirting browser-based NTLM site on your intranet<div class="separator" style="clear: both; text-align: center;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SKzpeJmu26I/AAAAAAAAD9A/SsoybPVwA0I/s1600-h/squirtle.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SKzpeJmu26I/AAAAAAAAD9A/aylXYQ3XJwg/s200-R/squirtle.gif" /></a></div>Just a quick note about something interesting I ran across out at <a class="zem_slink" href="http://code.google.com/" rel="homepage" title="Google Code">Google Code</a>. <a href="http://code.google.com/p/squirtle/">Squirtle</a> uses <a class="zem_slink" href="http://en.wikipedia.org/wiki/Internet_Explorer" rel="wikipedia" title="Internet Explorer">Internet Explorer's</a> use of trusted zones and grabs <a class="zem_slink" href="http://en.wikipedia.org/wiki/NTLM" rel="wikipedia" title="NTLM">NTLM</a> hashes when a user browses to a site that is running squirtle. No muss, no fuss, just pure Windows credential hashes. After glancing through the code I honestly can't imagine why it took so long for this to come along. Personally, I think <a href="http://en.wikipedia.org/wiki/Cross-site_scripting">XSS</a> and <a href="http://en.wikipedia.org/wiki/Social_engineering_%28security%29">social engineering</a> are your most likely attack vector and that deploying squirtle is dead simple... and NTLM is just dead (FD: I have never liked nor thought NTLM was effective and was a MS lock-in trick to make people feel better... but not make them more secure (like SMB signing). More info <a href="http://grutz.jingojango.net/exploits/pokehashball.html">here</a> and <a href="http://oss.coresecurity.com/projects/pshtoolkit.htm">here</a>.Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-6547009474326335572008-08-20T09:30:00.001-05:002008-08-24T13:57:06.118-05:00Continental expands paperless boarding pass effort<a href="http://upload.wikimedia.org/wikipedia/commons/thumb/6/67/Continental.airlines.b757-200.takeoff.arp.jpg/800px-Continental.airlines.b757-200.takeoff.arp.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" height="139" src="http://upload.wikimedia.org/wikipedia/commons/thumb/6/67/Continental.airlines.b757-200.takeoff.arp.jpg/800px-Continental.airlines.b757-200.takeoff.arp.jpg" width="200" /></a><br />
<div xmlns="http://www.w3.org/1999/xhtml">Continental has expanded their pilot program for paperless ticketing as <a href="http://www.kxan.com/Global/story.asp?S=8865017&nav=menu73_2">reported on KXAN</a> (Austin, TX NBC affiliate). The program allows passengers pass through airport "security" and board planes with electronic <a class="zem_slink" href="http://en.wikipedia.org/wiki/Boarding_pass" rel="wikipedia" title="Boarding pass">boarding pass</a> barcodes that are sent to the passengers and can be downloaded and viewed on devices such as <a class="zem_slink" href="http://en.wikipedia.org/wiki/Mobile_phone" rel="wikipedia" title="Mobile phone">cell phones</a>. The <a class="zem_slink" href="http://www.tsa.gov/" rel="homepage" title="Transportation Security Administration">TSA</a> will have scanners at checkpoints that can scan the <a class="zem_slink" href="http://en.wikipedia.org/wiki/Barcode" rel="wikipedia" title="Barcode">barcode</a> on the device, eliminating the need for paper. I can't comment in too much detail since I have been involved in the architecture of this program for my employer. I will post about this again as the more information becomes public regarding the security of the program. For now, I will list a few articles that give more details regarding the program. You can piece together a good amount of information regarding the program by reading them (Be warned... some of them are re-posts and article amplifications and don't offer much anything new... sort of like this post :) ).<br />
<blockquote></blockquote></div><fieldset class="zemanta-related"><br />
<br />
<legend class="zemanta-related-title">Related articles </legend><br />
<ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.cbsnews.com/stories/2007/12/04/travel/main3573858.shtml?source=RSS&attr=_3573858">TSA Greenlights Paperless Boarding Passes</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.msnbc.msn.com/id/22100817/">TSA, Continental initiate paperless boarding</a></li>
<li class="zemanta-article-ul-li"><a href="http://mobilecrunch.com/2008/06/04/continental-airlines-offers-mobile-boarding-passes/">Continental Airlines offers Mobile Boarding Passes</a></li>
<li class="zemanta-article-ul-li"><a href="http://www10.nytimes.com/2008/03/18/technology/18check.html?_r=5&ex=1363579200&en=706a3325091fa7f8&ei=5088&partner=rssnyt&emc=rss&oref=slogin&oref=slogin&oref=slogin&oref=slogin">Itineraries: Paper Is Out, Cellphones Are In</a></li>
<li class="zemanta-article-ul-li"><a href="http://gizmodo.com/gadgets/cellphones/paperless-boarding-passes-coming-to-cellphones-330178.php">Paperless Boarding Passes Coming To Cellphones [Cellphones]</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.news.com/8301-10784_3-9896859-7.html?part=rss&subj=news">Cell phone as boarding pass</a></li>
<li class="zemanta-article-ul-li"><a href="http://venturebeat.com/2008/07/14/sojern-gives-airlines-a-new-way-to-make-money-your-boarding-pass/">Sojern gives airlines a new way to make money - your boarding pass</a></li>
<li class="zemanta-article-ul-li"><a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=204701111">Paperless Boarding Pass Program Kicks Off</a><br />
</li>
<li class="zemanta-article-ul-li"><a href="http://www.news.com/8301-10784_3-9931866-7.html?part=rss&subj=news">iPhone as electronic airplane boarding pass</a></li>
</ul></fieldset><blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-7850004085561981042008-08-19T16:25:00.004-05:002008-08-24T14:25:04.576-05:00PCI DSS update (1.2) pre-released and boy howdy it's about time!<div xmlns="http://www.w3.org/1999/xhtml"><a href="http://2.bp.blogspot.com/_YM_k6IgTR7E/SKs_wwjZoqI/AAAAAAAAD8Y/_kmm2wltwuE/s1600-h/credit_card_alternative.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://2.bp.blogspot.com/_YM_k6IgTR7E/SKs_wwjZoqI/AAAAAAAAD8Y/PMI66mQwyY8/s200-R/credit_card_alternative.jpg" /></a>The <a href="http://www.pcisecuritystandards.org/">Payment Card Institute</a> (PCI) Security Standards Council has <a href="http://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">pre-released</a> it's highly anticipated <a href="http://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">Data Security Standards</a> (DSS) version 1.2. The standard is due to be officially released in October of this year (2008) but the PCI wanted to give businesses a chance to examine the changes and begin re-architecting half the stuff they hurriedly put in place this year in order to meet the June 30 deadline for 1.1. Enough of my babbling, onto the good stuff:<br />
<br />
<ul><li>Relaxed firewall configuration review from three months to six.</li>
<li>Language changes to include routers into the fold (not just firewalls).</li>
<li>Clarified the requirement applies to wireless environments “attached to cardholder environment or transmitting cardholder data.” </li>
<li>Got rid of WEP language... long live WEP! (just kidding of course)</li>
<li>Finally got rid of the silly SSID hiding requirement... I got in some very intense arguements here about the futality of hiding the SSID... so that's a big ITYS to my colleagues (except you Ryan).</li>
<li>Clarified the local user accounts databases need to be encrypted but the DB in my secure data center sitting behind eight layers of security devices need not go through the hassle... not that they shouldn't be encrypted... maybe I won't share that new requirement with management ;)</li>
<li>Wireless networks must follow industry best standards (whatever that means... more ambiguity!) for encryption, AAA, and transmission.</li>
<li>New WEP projects must be implemented by the end of March 2009 (hear that PM's... better hurry) and all WEP must die by June 30, 2010</li>
<li>AV is now required to all operating systems and must be updated and protect against <span style="font-style: italic;">known</span> attacks</li>
<li>Thankfully loosened patching requirements to allow a risk-based prioritization of patches.</li>
<li>6.6 is mandatory! All Internet facing websites have to either be behind a WAF or have vulnerability assessment tools pointed their direction or a rubber-glove code review</li>
<li>You have to test and verify that passwords must be unreadable both at rest and in motion.</li>
<li>They did something surrounding the 2FA requirement for access but I guess we'll have to wait to get the actual requirement (bummer)</li>
<li>Passphrases join passwords as acceptable forms of authentication (another ITYS)</li>
<li>Must visit all off-site storage facilities at least once a year. (Ugh!)<br />
</li>
<li>Added some flexibility surrounding cameras to allow other access control types.</li>
<li>Finally clarified what "secure media" meant. It applies to electronic AND paper media and how to destroy it.<br />
</li>
<li>Logs for external devices must send logs to <span style="font-style: italic;">internal</span> logging servers (well DUH!)</li>
<li>Relaxed audit trail requirements to three months and that they can be archived but quickly restored.</li>
<li>More guidance surrounding wireless analyzers and WIDS/WIPS, ASVs must be used in quarterly external scans and internal and external pen tests but you don't have to use a QSA or ASV for those!</li>
<li>This one I don't get: 'Expanded list of examples of critical employee-facing technologies to include “remote access technologies, wireless technologies, removable electronic media, email usage, internet usage, laptops, and Personal Data Assistants (PDAs)”' (Big WTF?!?!?!)<br />
</li>
<li>Security policy must be reviewed by all employees annually.</li>
<li>Cleared up language regarding service provider account access and hygiene.</li>
<li>Generally cleaned up language for consistency and clarity (we'll see about that!)</li>
</ul>All-in-all I am glad to see some of the clarifications and new requirements but there is still enough ambiguity and confusing language in the "clarifications" to keep security professionals busy and QSA's well employed over the next few years.</div><blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-55758919292168769552008-08-18T20:41:00.005-05:002008-08-24T13:37:59.332-05:00Hack the Vote<span style="display: block; float: right; margin-bottom: 1em; margin-left: 1em; margin-right: 1em; margin-top: 1em;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SKoolHlAdoI/AAAAAAAAD8Q/R5AJsTmawlQ/s1600-h/2766529482_81992de053.jpg"><img border="0" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SKoolHlAdoI/AAAAAAAAD8Q/gU1PKVM8mhw/s200-R/2766529482_81992de053.jpg" /></a><span style="display: block; font-size: xx-small; margin-bottom: 0pt; margin-left: 0pt; margin-right: 0pt; margin-top: 1em;">Image by <a href="http://www.flickr.com/photos/theamarand/">Amarand Agasi</a> via <a href="http://www.flickr.com/">Flickr</a> </span></span><br />
<div xmlns="http://www.w3.org/1999/xhtml">Christopher Beam wrote a short article for Salon last week with an attention-getting title: <a href="http://www.slate.com/id/2197502/">Hack the Vote - Five ways hackers could tamper with the 2008 elections</a> over at <a href="http://www.slate.com/id/2197502/" target="_blank">Slate</a>. After wasting five minutes of my time reading the article I thought I would waste another five minutes of my time writing a short summary of how "hackers" can "tamper" with the elections this fall. Please note that Mr. Beam has the word "hackers" in his title but consistently refers to them as "tricksters." Mr. Beam's short list of ways hacker-tricksters (hicksters?) can sabotage the vote are:<br />
<ol><li><span style="font-weight: bold;">Fake e-mails.</span> Seems that some hicksters (I'm starting to like it... I'm slapping a trademark on it) are actually politically-savvy phishers. He offers defending against phishers with "rapid response" getting the word out about the scam to the people most likely to get duped. I do love this little bit of genius from the article: "...Obama's <a href="https://donate.barackobama.com/page/contribute/2millionD?source=20080813_2M_ND_R" target="_blank">donation page</a> has a security seal at the bottom designating it an "authentic site." Notice, also, that you can easily copy the seal and post it on your own site." I actually did LOL when I read the last sentence.</li>
<li><span style="font-weight: bold;">Dummy Web sites.</span> I'm not sure how this one made it in but Mr. Beam spends a good amount of screen real estate rambling about: <a href="http://www.wired.com/politics/onlinerights/news/2007/11/spoof_forums">fake content</a>, <a href="http://www.misspelledtraffic.com/index.htm">misspelled domain names</a>, the <a href="http://blogs.zdnet.com/security/?p=1042">Obama-Clinton XSS incident</a>, the <a href="http://www.securityfocus.com/news/11526">recent DNS flaw</a>, and finally <a href="http://en.wikipedia.org/wiki/SQL_injection">SQLi</a>. His solution? Well, not much since every security professional I know is struggling with the exact same issues day-in day-out... but I'll give Mr. Beam credit for bringing some of these vulnerabilities to the general public's attention.</li>
<li><span style="font-weight: bold;">Social networking.</span> I see this potentially being an issue for Obamanics but for McCainites? Not so much. Unless you count the golf course or barbershop.</li>
<li><span style="font-weight: bold;">Robo-calling.</span> Um. Yeah, weren't they cold calling my parents to sling some serious mud back when it was Nixon vs. McGovern? <br />
</li>
<li><b>Search-engine deoptimization.</b> Potentially could be a problem if the hicksters are very very motivated and very very organized but his scenarios are too localized to be effective (buying ads to mislead people where to vote?). <a href="http://www.google.com/" target="_blank">Google</a> (and the other search engines) have gotten much better about rooting out "<a href="http://en.wikipedia.org/wiki/Google_bomb">google bombing</a>" and other <a href="http://en.wikipedia.org/wiki/Search_engine_optimization">SEO</a> tricks and hacks (hicks?). <br />
</li>
</ol>Ultimately the article closes out with the statements that it should have started with: <br />
<blockquote>That's not to say these Internet tricks will upset the election—or even dent it. There are <a href="http://www.nytimes.com/2008/08/03/magazine/03trolls-t.html" target="_blank">plenty of bright mischief-makers</a> out there, but how many of them want to screw up elections? (Elect John McCain for the <a href="http://en.wikipedia.org/wiki/LOL" target="_blank">lulz</a>!) And it may turn out that traditional methods of voter manipulation—such as, say, <a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/11/07/AR2006110700740.html" target="_blank">paying busloads of homeless people to pass out inaccurate sample ballots</a>—will prove more effective. Plus, one <a href="http://my.barackobama.com/page/content/fightthesmearshome" target="_blank">smear campaign</a> probably equals a thousand polling-place misinformation campaigns.</blockquote><blockquote></blockquote></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-79421037343118840492008-08-09T10:17:00.012-05:002008-08-24T14:32:11.829-05:00Using credit cards at airport kiosks is as safe using them anywhere else... which isn't saying much.<span style="display: block; float: right; margin-bottom: 1em; margin-left: 1em; margin-right: 1em; margin-top: 1em;"><a href="http://commons.wikipedia.org/wiki/Image:International_airport_toronto_pearson.jpg"><img alt="The Terminal 3 Grand Hall" src="http://upload.wikimedia.org/wikipedia/commons/thumb/7/77/International_airport_toronto_pearson.jpg/202px-International_airport_toronto_pearson.jpg" style="border: medium none; display: block;" /></a><span style="display: block; margin-bottom: 0pt; margin-left: 0pt; margin-right: 0pt; margin-top: 1em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:International_airport_toronto_pearson.jpg">Wikipedia</a></span></span><br />
<div xmlns="http://www.w3.org/1999/xhtml">Bob Sullivan wrote a post titled "<a href="http://redtape.msnbc.com/2008/07/airline-travele.html">Are airline kiosks safe?</a>" for <a href="http://redtape.msnbc.com/">The Red Tape Chronicles</a> at <a href="http://www.msnbc.msn.com/">msnbc.com</a> last week that made me frown when I first read it. (Note: I'll give Bob Sullivan credit... at least he tried to be balanced, read on). On July 24th the <a href="http://www.thestar.com/News/Canada/article/467012">The Toronto Star</a> broke a story titled "<a href="http://www.thestar.com/News/Canada/article/467012">Airports a natural target for credit card fraud: Expert</a>." Ok, airports are a target... so are <a href="http://www.washingtonpost.com/wp-dyn/content/article/2007/02/21/AR2007022100940_pf.html">discount retail chains</a> and<a href="http://www.nytimes.com/2008/03/23/us/23credit.html"> grocery stores</a>... what's with the title? It turns out that <a class="zem_slink" href="http://www.visa.com/" rel="homepage" title="Visa Inc.">Visa</a> was investigating "isolated fraud incidents" that were occurring when people used the cards to check in to their flights and get their boarding passes. What drives me nuts is that the article spends almost 500 words scaring the bejeebus out of people when right in the middle of the article there is this gem of a quote:<br />
<blockquote>"<a class="zem_slink" href="http://www.westjet.com/" rel="homepage" title="WestJet">WestJet</a> has cautioned against pinning the blame solely on the kiosks until the investigation is complete."</blockquote>Eh? They didn't really know where the fraud was originating from, the banks (which do not usually have detailed information regarding POS (<a class="zem_slink" href="http://en.wikipedia.org/wiki/Point_of_sale" rel="wikipedia" title="Point of sale">Point of Sale</a>) location or IT infrastructure of organizations) were guessing that the kiosks was a logical place to start looking. Makes sense to me. But then the <a href="http://www.upi.com/">UPI</a> picked up on the story with the albeit better title "<a href="http://www.upi.com/Top_News/2008/07/24/Toronto_airport_credit_card_scam_probed/UPI-94451216909711/" title="">Toronto airport credit card scam probed</a>." Unfortunately, this article also takes the tact that it's better to scare people about swiping your card than emphasize that the banks were investigating whether there was something to investigate.<br />
<br />
Well, not long after the UPI story came out the security and travel blogosphere grabbed the ball and ran. With titles like these who wouldn't be scared about checking in at a kiosk?<br />
<blockquote><ul><li><a href="http://www.usatoday.com/travel/flights/item.aspx?type=blog&ak=53166670.blog">Does using your credit card to check-in expose you to fraud?</a></li>
<li><a href="http://www.networkworld.com/community/node/30360">Airport kiosks may be stealing your credit card info</a></li>
<li><a href="http://www.tripso.com/today/beware-of-credit-card-fraud-at-torontos-airport-ticket-kiosks/"> Beware of credit card fraud at Toronto’s airport ticket kiosks</a></li>
<li><a href="http://www.doubledeckerbuses.org/nuttinbut/index.php/2008/07/26/credit_card_fraud_at_the_airport">Credit Card Fraud At The Airport</a> (with authority FTW!)</li>
</ul></blockquote><ul></ul>Ok, ok, I know what you're thinking, it's better to spread the word about possible fraud than to keep it quiet and let people continue to be at risk. Fine. I agree... although I think by upping the hyperbole you spread FUD (<a class="zem_slink" href="http://en.wikipedia.org/wiki/Fear%2C_uncertainty_and_doubt" rel="wikipedia" title="Fear, uncertainty and doubt">Fear, Uncertainty, Doubt</a>) and damage the airports, the kiosk owners, and the airlines. Let's stick to the facts and leave the outrageous headlines out (except for the last one I listed above... if a reader of "Nuttin' But Pimp" takes anything on that site seriously... well then send me an email because do I have some offers for you!<br />
<br />
Why am I picking on this particular news item? Well, just a few days after the initial story broke (five (5) days to be exact) <a href="http://www.cbc.ca/">cbc news</a> reported that "<a href="http://www.cbc.ca/consumer/story/2008/07/29/airport-kiosks.html">No fraud linked to Toronto Pearson airport kiosks</a>." Yes, that's right... they did an audit and found that there are "no confirmed cases of fraud currently at [Pearson] airport kiosks."<br />
<br />
I scoured the blogosphere for follow-up articles giving the "all clear" to let people use credit cards in addition to their passports or PNR numbers to check into their flight. I could only find a few stories in the Canadian press about it. At least there will be one article out there spreading the good news. Swiping your <a class="zem_slink" href="http://en.wikipedia.org/wiki/Credit_card" rel="wikipedia" title="Credit card">credit card</a> (CC) at an airport kiosks is just as dangerous as storing your CC information online, swiping it at the <a class="zem_slink" href="http://en.wikipedia.org/wiki/Grocery_store" rel="wikipedia" title="Grocery store">grocery store</a>, handing it to a waiter at a resteraunt, etc. In other words, not really all that safe at all but convenient.<br />
<br />
Shout out to Howard for sending me the msnbc post.</div><br />
Related Articles<br />
<ul><li><a href="http://www.thestar.com/article/466406">Airport's self-serve kiosks tied to fraud</a></li>
<li><a href="http://www.nationalpost.com/nationalpost/story.html?id=675085">WestJet to pull credit card readers at check-in kiosks</a></li>
<li><a href="http://www.canada.com/topics/news/national/story.html?id=a6818ae8-bad6-4ac2-914b-87bf5efef244">WestJet shutters credit card kiosks</a></li>
<li><a href="http://www.canada.com/calgaryherald/news/story.html?id=a6818ae8-bad6-4ac2-914b-87bf5efef244">Stop that card</a></li>
<li><a href="http://www.canada.com/topics/news/national/story.html?id=2d4dc8ef-4ea1-4b5c-b0bc-8a9e4e091b0d">No fraud at Pearson kiosks: Ottawa</a></li>
<li><a href="http://www.ctv.ca/servlet/ArticleNews/story/CTVNews/20080727/airport_kiosks_080727/20080727?hub=QPeriod">Ottawa preparing report on Pearson airport kiosks</a></li>
<li><a href="http://www.thestar.com/article/468256">Ottawa to probe possible airport kiosk fraud</a></li>
<li><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9110642&source=rss_topic82">Credit card firms investigate fraud at Canadian airport kiosks</a></li>
<li><a href="http://www.thestar.com/article/466225">WestJet suspends credit-card check-in amid fraud fears</a></li>
<li><a href="http://www.ctv.ca/servlet/ArticleNews/story/CTVNews/20080724/pearson_probe_080724/20080724?hub=Canada">Expert warns travellers in wake of Pearson probe</a></li>
<li><a href="http://www.cbc.ca/consumer/story/2008/07/29/airport-kiosks.html?ref=rss">No fraud linked to Toronto Pearson airport kiosks</a></li>
<li><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9110642&source=rss_topic82">Credit card firms investigate fraud at Canadian airport kiosks</a></li>
</ul><span style="font-size: x-small;">Edit: Fixed some spelling and cleaned up the language a bit. </span><br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-12318785047678119692008-07-29T12:58:00.002-05:002008-08-24T13:57:06.123-05:00Airlines warn customers of infected ticket invoices<div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"><a href="http://farm2.static.flickr.com/1194/542145956_efae4854b1.jpg?v=0" imageanchor="1" style="background-color: transparent; border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px; clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img height="133" src="http://farm2.static.flickr.com/1194/542145956_efae4854b1.jpg?v=0" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" wc="true" width="200" /></a></div><div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;">I haven't blogged in a while because work has been unbelievably busy lately but I wanted to pass on an <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9110883&source=NLT_VVR&nlid=37">article</a> on <a href="http://www.computerworld.com/">Computerworld</a> that falls right into my wheelhouse: information security and airlines. <a href="http://www.delta.com/">Delta</a> and <a href="http://www.nwa.com/">Northwest</a> have put out warnings regarding malicious ticket invoices that are being emailed to unsuspecting people. The malicious email contains a trojan-packed zip file and instructs the reader to open the zip in order to see the invoice for a $400 ticket. From the article:</div><div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"></div><div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"><span style="font-size: xx-small;">Photo by Flickr user: caribb</span> </div><blockquote>However, the .zip file format attachment is a Trojan horse that steals information, including keystrokes, from the infected Windows PC and transmits that data to a server hosted in Russia, according to McAfee threat researcher Craig Schmugar. McAfee has pegged the malware as "Spy-Agent.bw," but other security firms have given it different names. For example, Symantec Corp. has labeled the same Trojan horse as "Infostealer.Monstres."</blockquote>It doesn't appear that the message hasn't been directed at <a href="http://www.aa.com/">American Airlines</a> yet but I wouldn't bet against seeing them withing a day or two if the spam campain is successful. I'll update this blog if more details become available.Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-85347699987750887292008-07-14T10:30:00.001-05:002008-08-24T14:24:27.804-05:00Preaching to the choir<a href="http://www.computerweekly.com/blogs/stuart_king/">Stuart King</a> wrote an <a href="http://www.computerweekly.com/blogs/stuart_king/2008/07/reducing-security-costs.html">excellent post</a> at <a href="http://www.computerweekly.com/">computerweekly.com</a> regarding how to reduce the cost of information security. His points are spot on and very similar to things I have been bringing up at work over the past few months. My organization in particular is being hit particularly hard due to current economic conditions so it is imperative that I show value for every dollar I spend, perform thorough risk analysis on new projects, and evaluate existing security projects, services, and infrastructure for cost savings. Of course I have to do all this while maintaining (or improving) the current security posture of the enterprise. <br />
<br />
Good times.Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-26159714655185117202008-07-11T16:45:00.004-05:002008-08-24T14:28:18.013-05:00NIST releases three new security guidelines<div xmlns="http://www.w3.org/1999/xhtml"><a href="http://upload.wikimedia.org/wikipedia/commons/thumb/e/ee/NIST_logo.svg/180px-NIST_logo.svg.png" imageanchor="1" style="background-color: transparent; border: 0pt none; clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img src="http://upload.wikimedia.org/wikipedia/commons/thumb/e/ee/NIST_logo.svg/180px-NIST_logo.svg.png" style="border: 0pt none;" /></a><a href="http://www.gcn.com/">Government Computer News</a> (GCN) <a href="http://www.gcn.com/online/vol1_no1/46628-1.html">reported</a> that the <a href="http://www.nist.gov/">National Institute of Standards and Technology</a> (NIST) recently released three draft guides for public comment before their official publication. From the article:</div><blockquote><a href="http://csrc.nist.gov/publications/drafts/Draft-SP-800-107/draft-SP800-107-July2008.pdf" target="_blank">SP 800-107</a>, titled “Recommendation for Applications Using Approved Hash Algorithms,” is in its second draft release. It provides guidelines for achieving the appropriate level of security when using approved hash functions. </blockquote><blockquote><a href="http://csrc.nist.gov/publications/drafts/800-121/Draft-SP800-121.pdf" target="_blank">Draft SP 800-121</a>, titled “Guide to Bluetooth Security,” describes the security capabilities of Bluetooth technologies and gives recommendations on securing them effectively. </blockquote><blockquote><a href="http://csrc.nist.gov/publications/drafts/800-41-Rev1/Draft-SP800-41rev1.pdf" target="_blank">Draft SP 800-41 Revision 1</a>, titled “Guidelines on Firewalls and Firewall Policy,” updates the original publication released in 2002. It provides recommendations on developing firewall policies and selecting, configuring, testing, deploying and managing firewalls. The publication covers a number of firewall technologies, including packet filtering, stateful inspection, application-proxy gateways, host-based and personal firewalls.</blockquote>I have begun reading and intend on commenting on the Firewall draft. From my first peek inside it seems very thorough and covers not only firewall policies and requirements but also architecture, rule selection, and life-cycle management.<br />
<blockquote></blockquote>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-74688654564648549352008-07-10T10:30:00.004-05:002008-08-24T14:28:18.014-05:00Are Security Devices Making Us Lazy? : Part 1 : Introduction<div class="separator" style="clear: both; text-align: center;"><a href="http://bp3.blogger.com/_YM_k6IgTR7E/SHVys5bxgVI/AAAAAAAADxM/3N8kCtH5-jM/s1600-h/100_6486.JPG" imageanchor="1" style="background-color: transparent; border: 0pt none; clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img src="http://bp3.blogger.com/_YM_k6IgTR7E/SHVys5bxgVI/AAAAAAAADxM/5nO9JE_WMQ4/s320-R/100_6486.JPG" style="border: 0pt none;" /></a></div><div xmlns="http://www.w3.org/1999/xhtml">Let me clarify before I begin... by "us" I mean IT as a community, not information security specifically. Now that I have that out of the way let's discuss how our reliance on network firewalls, application firewalls, VPNs, encryption, etc. have caused system administrators, architects, programmers, and yes, even us security-type-folk lazy. Let me explain a bit.</div><br />
Let's pretend for a moment that we didn't have AV, network firewalls, SSL, IDS, or any other security-specific solutions available to us. How would we design our information systems? How would we protect resources? How could we possibly defend our networks against attack? These are the questions I like to ask myself when I have to design a new security architecture, review a proposed design, or audit an existing system.<br />
<br />
I am not saying we should design all of our systems with these questions in mind. I understand the fact that we have these wonderful network and system security tools at our disposal. Thus, we can adapt our architectures, designs, and programs to include these solutions. The problem I see is an over-reliance on these tools. As an industry we have moved away from pushing most of the security work to the system administrators and programmers. We have told them (implicitly) "Don't worry about it... we've got it covered."<br />
<br />
So how do we fix it? How do IT professionals stop relying on “things” and start building security from the ground-up? How do we do this while increasing functionality, ease-of-use, and speed? In future installments of this series I will attempt to look at where IT professionals can focus their energies to begin “spreading the gospel” to the developers and administrators and have them buy into the idea of secure system from the start.Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comtag:blogger.com,1999:blog-5358057235902486284.post-8846658460451393692008-07-08T13:30:00.001-05:002008-08-24T14:30:29.620-05:00Should the Airlines be Forced to Fingerprint Passengers?<b>...and should they have to pay for it? </b><br />
<br />
<div class="separator" style="text-align: center; clear: both;"><a href="http://bp1.blogger.com/_YM_k6IgTR7E/SHO0PjKOJbI/AAAAAAAADw8/hbe9OW0bMH8/s1600-h/US-VISIT_L.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: right; margin-bottom: 1em; float: right; margin-left: 1em;"><img src="http://bp1.blogger.com/_YM_k6IgTR7E/SHO0PjKOJbI/AAAAAAAADw8/qrV7R-c7XDk/s320-R/US-VISIT_L.jpg" style="border: 0pt none ;" /></a></div>
The <a href="http://en.wikipedia.org/wiki/Presidency_of_George_W._Bush">Bush Administration</a> and the <a href="http://www.dhs.gov/index.shtm">Department of Homeland Security</a> <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/06/21/AR2008062101466.html?hpid=moreheadlines">have told the airline carriers</a> that they will <a href="http://www.abcnews.go.com/Travel/Weather/story?id=5292826&amp;amp;amp;page=1">collect biometric information</a> such as <a href="http://www.fcw.com/online/news/152315-1.html">fingerprints from foreign travelers </a>on their exit from the United States. I will refrain from discussing the political and social aspects of this request and instead will focus on the financial and technological aspects of such an idea.<br />
<br />
The US-based airline carriers are facing <a href="http://news.google.com/news/url?sa=t&amp;amp;amp;ct=:ePkh8BM9E8K0A2x8BsQ2VqAdBkxCslrSSo65qUWZyYl5Co6ZRTmZeUDtCrrOqXklqUVCYloimXlp-UW5iSWZ-XkKxanJpUWZJZUwd2kwGgk4v_1-a6-jKc_Cq6fkL6nlFv5iYy5KTQYA7Fkj6Q/4-0&amp;amp;amp;fp=487320a733886e09&amp;amp;amp;ei=e55zSIyqLYqWyASmhbXhCQ&amp;amp;amp;url=http%3A//online.wsj.com/article/SB121547453054734059.html%3Fmod%3Dgooglenews_wsj&amp;amp;amp;cid=1226414171&amp;amp;amp;sig2=wyslKK_ThDwH_3H8k1dwGw&amp;amp;amp;usg=AFQjCNGOYZSjynqEzVDtIvWBVKAaR6wF2w">record fuel prices</a>, <a href="http://www.brookings.edu/testimony/2008/0424_airlines_winston.aspx">increased competition</a>, <a href="http://www.dallasnews.com/sharedcontent/dws/fea/travel/thisweek/stories/DN-airlines_22bus.ART0.State.Edition1.4d42bb7.html">price elastic demand</a>, and a <a href="http://www.huffingtonpost.com/2008/05/20/airline-customer-satisfac_n_102586.html">volatile customer base</a>. If the administration forces the airlines to also fingerprint passengers, the additional infrastructure, storage, networking, and security costs would <a href="http://www.fcw.com/online/news/152835-1.html">kill IT budgets.</a> It could also cause the airlines that are close to the edge financially to either further pull back operations or perhaps file for bankruptcy.<br />
<br />
Beside the financial burden this would place on the airlines another question that must be asked is: why? Why should the airlines collect and maintain biometric records of their passengers? We currently have the federal government stopping to check for both citizen/visa status as well as customs inspection at all ports of entry. Why can't we just turn some of those booths around the other way? <br />
<br />
The DHS is already collecting fingerprints and taking pictures of people that visit the country. Why should the airlines duplicate the entire infrastructure costs that are associated with this program? The costs would include the purchase of fingerprint scanners, computer systems, programs, databases, and storage as well as an interface into the federal government system. The cost for putting these systems into each international airport will be huge, and will have to be duplicated by each airline.<br />
<br />
This is the ultimate "pass the buck" program. The Bush administration and the DHS shouldn't place this undue burden on the airlines who will, in turn, pass the costs onto the consumer... that is, if the airline stays in business and continues to fly internationally.<br />
<br />
<b>Reference Links:</b><br />
<a href="http://www.fcw.com/online/news/152938-1.html">http://www.fcw.com/online/news/152938-1.html</a><br />
<a href="http://www.dhs.gov/xtrvlsec/programs/editorial_0525.shtm">http://www.dhs.gov/xtrvlsec/programs/editorial_0525.shtm</a><br />
<a href="http://en.wikipedia.org/wiki/US-VISIT_%28United_States_Visitor_and_Immigrant_Status_Indicator_Technology%29">http://en.wikipedia.org/wiki/US-VISIT_(United_States_Visitor_and_Immigrant_Status_Indicator_Technology)</a><br />
<a href="http://www.smartbrief.com/news/gtg/storyDetails.jsp?issueid=A917B6BE-4A3A-4AA2-8BA1-CC8DD722D6AB&amp;amp;amp;copyid=3082D538-D0AE-403E-973B-C434F4C20BA3">http://www.smartbrief.com/news/gtg/storyDetails.jsp?issueid=A917B6BE-4A3A-4AA2-8BA1-CC8DD722D6AB&copyid=3082D538-D0AE-403E-973B-C434F4C20BA3</a><br />
<a href="http://federaltimes.com/index.php?S=3597239">http://federaltimes.com/index.php?S=3597239</a><br />
<a href="http://www.isn.ethz.ch/news/sw/details.cfm?ID=19140">http://www.isn.ethz.ch/news/sw/details.cfm?ID=19140</a><br />
<a href="http://biometrics.gov/">http://biometrics.gov/</a>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com