Category: Security Awareness

  • security vs. liberty

    Ben Franklin“He who sacrifices freedom for security deserves neither.” – Ben Franklin

    Security is important, but it should be done in wisdom not only fear and paranoia lest we forsake everything we seek to protect.

    The military is a good example of security versus liberty.

    A U.S. military installation is one of the most secure places you can be in. Depending on the resources therein, there can be fencing around the installation, mobile forces, and only a few active entry points. Entry points are controlled by armed guards, barriers, and sometimes even machine guns and “man traps”. Only authorized personnel may enter and even “authorized personnel” can only enter certain areas once on the base. The installation is controlled by the base commander whose laws are MUCH more strict on the base. Entering the base means you give up things like the right to protest. You can be searched at anytime and you can be shot for going certain places… such as the flightline. All in all, it is the safest place to be in the event of civil unrest off base because on base there are law enforcement, security forces, and back up ready reserve forces capable or mobilizing in a matter of minutes.

    All the security, with very, very controlled liberties. Such a controlled environment requires very controlled personnel.

    This is why as a security professional I understand what it means to have more security and lose liberties. Although many Americans are willing to give up some liberties for more National Security, I fear that most don’t really realize how much they are really giving up. Perhaps the bigest loss is privacy and in this day and age personal data has become our most valuable asset. No one is going to protect it like you. Certainly not the government. It is such a large entity that it can only summarize you and your family into numbers, statistics.

    U.S. servicemen and women are numbers and statistics to the federal government. They are (to some extent) owned by the federal government while serving under oath. Their dedication includes their life, if service calls for it. They service is no trivial event. All the more reason liberty must be preserved… to honor the sacrifices of a few. True American patriotism is the preservation of every remaining freedom at any cost.

  • How I got into Security

    Martin McKeay over at the Network Security Blog asks “How did you get into Security?”  That is a good question.  Its something that I’ve been asked and what I like to ask others in the business.

    Up until recently, I’ve done security my entire adult life very reluctantly.  I started off in the military as Security Policemen (now called security forces).  I was a security specialist and was groomed into law enforcement.  The description sounded like special forces.  And even though security forces do some pretty cool stuff its NOT usually doing anything even close to what combat controllers, pararescue, Force Recon, Navy Seals and Delta Force do.  Instead its like the Air Force version of infantry (when I was in we even trained with the Army infantry at Ft Dix).

    I had about five years learning every aspect of physical security.  I later “cross trained” into communications expecting to do some hardcore technical stuff.  And I did, but while I wanted Routers I got the help desk and later pure security (firewalls, IDS, C&A packages, COMSEC, EMSEC) a little of everything.  My experience in the military made it easier for me to pass the CISSP which covers a little of everything.

    These days I teach certification classes and do auditing, policies, consulting as well as certification and accreditations. 

  • 17-year-old accused of hacking into school computers

    JEFFERSON COUNTY – A 17-year-old student at Golden High School has been arrested after police say he hacked into the school’s computer system and changed grades.

    Police say charges could include forgery, computer crime and use of forged academic records.

    Police believe the student hacked into the campus portal system, which is meant to give parents access to grades, schedules and attendance records.”

    Everytime I hear about a kid trying to hack the school records I am reminded of Ferris Bueller’s Day off. 

    read more | digg story

  • There is no such thing as Security

    I’ve noticed that there are two types of security people: anal “type A personalities” who live every moment by the rules, and those that realize that there is no real security.  Please understand that these two mindset don’t seem to have anything to do with talent.  I’ve met talented people with both mindset.  A talented security professional is mindful, aware, and always pays attention to detail.  The very best seem almost psychic in their ability to spot wrong doing, security breaches and even malicious intent.

    Type A security people seem to thrive on “catching bad guys”.  Its like they are kids playing cops & robbers.  These people thrive on structure, order and regulations.  In information security they know how important it is to have lots of centralized control and a stardard configuration for all systems.  In the Meyers-Brigg’s personality test, these people are ESTJ’s (Extraverted Sensing Thinking Judging).  The thought of any getting away with breaking the law (ANY LAW) is unacceptable.  These guys make great Directors of Security, CSO’s and other policy creators as long as they don’t micromanage their people.  Their employees will either love them as a great mentor or hate them with every fiber of their being.

    Those who realize that there is no such thing as security are hackers.  They are many times INFP’s (Introverted iNtuitive Feeling Perceptive).  Unlike the ESTJ’s they don’t care about structure and rules because the realize that rules are only suggestion to keep an acceptable level or order.  For them the most important rules are in a persons heart.  ESTJs will usually see these people as lazy and don’t really care but these people are just trying to find an easier way to do things.  If they don’t enforce certain rules or cut corners, it because the sincerely believe that the rule or enforcement (in that particular situation) is not needed.  Employees will usually love INFP’s unless they happen to be ESTJ’s.

    I am a bit biased because I am in the second camp, INFP.  I don’t believe there is a such thing as “security”.  No one is ever completely safe.  All a malicious intending person needs is the element of surprise, time, and pressure an they can get away with anything they want.  Further, anyone at anytime can have malicious intent: employees, kids, bosses, friends, family not just random strangers.

    Security is just an illusion.  The one good thing security does is ensure you are faster than the slowest person, organization, network or whatever on the block.  Those with malicious intent will typically go for the easiest target. 

    Since many crime happen from people that the victims know all we can really do is not worry about it.  Life is too short to waste too much time fretting about every possible thing that can happen to you.     

    I guess that is what Ben Franklin meant when he said:

    “Those Who Sacrifice Liberty For Security Deserve Neither”  

    If you worry so much about security that you can’t enjoy the fruits of your labor, then what is the point of the living and if you can’t enjoy living whats the point of protecting ANYTHING. – elamb

  • Information Security Gurus: Say Goodbye Mr. Network Geek

    “Information Security workers have found themselves caught up in this wave of change. Originally, it was an important and vital job to track down the current virus threats, manage the Service Packs in [Pick your Windows flavor here], install the few hotfixes needed and call it a day. The rest of our time was spent on the important matters – defining”

    The “wave of change” keeps me employed, but I must agree with Karn at Security-Guru.blogspot. There is a lot of times that I’m just playing “wack a mole” with security problems. The root of the problem needs to be taken care of.

    There is a movement of more proactive security instead of the old losing reactive security:


    – At Defcon Rick Wesson of Support Intelligence, LLC introduced a method of tracking botnets, and black listed malware server globally and in real-time.
    – Microsoft is heading up a proactive security project called Strider HoneyMonkey Exploit Detector. It is a kind of active honeypot that follows the links of malicious sites to find new exploits.

    read more | digg story

  • Security Forums Directory

    Easily locate forums and newsgroups related to security. Why isn’t elamb.org on there? Oh, well.

    read more | digg story

  • Security Geek Fired By Suits: For Doing His Job?

    “A security geek is fired by executive management after the company is broken into by thieves and lose nearly $100k in equipment. The security geek had previously recommended safety measures that would have presented this, but they were shot down by those same executives! Who should have been fired in this story?”

    Looks like they used this security guy as a scape goat to protect their own asses.  Doesn’t documentation mean anything?!  Ultimately, it is that company that will suffer from keeping incompetent and untrustworthy people (if that is the case.)

    read more | digg story

  • Security Testing on my Window 2000 system

    I've surfing on my Windows 2000 system while completely exposed to the Internet on my DMZ.  No firewalls, no anti-virus, not even a pop-up blocker.  The box is exploited immediately. 

    Many of the default configuration on a fresh Windows 2000 box are just plain ridiculous.  For example, the C$, and parts of the root are shared out on earlier versions of Windows 2000.  Message services, port 139 and other very easy to exploit applications and services are turned on by default on Windows 2000. 

    It is no wonder Windows systems are always getting taken down.  Just turning off some of those services do quite a bit to close some of the holes on Windows boxes.  With broadband getting more popular, the combination of unprotected systems and the viral marketing of malicious code are creating a storm on the Internet.  An unprotected system is rendered completely useless in a matter of weeks (days and hours if you surf porn or serial sites).

    Here are some of the vulnerabilities on Windows systems at SANS.org.

    In all honesty, if you have a good firewall, virus protection, maybe a pop-up stopper and a good security configuration you could have a Windows 98 machine and NEVER get a virus.  

  • Experts: Computer Crime Down But Caution Still Needed

    CSI/FBI Computer Crime and Security Survey, Richardson noted that the average loss per cybercrime incident in 2005 was about US$250,000. That compares to $500,000 in 2004 and more than $3 million in 2001

    I guess Computer Crime has gone up comparing the begining of the year to the end of the year but overall more people (especially companies) are taking security much more seriously.  And it is about time, but industry security still has a ways to go… home security has barely started.

    read more | digg story