Showing posts with label @bcs. Show all posts
Showing posts with label @bcs. Show all posts

Friday, July 05, 2019

Mozilla is an ‘Internet Villain’?

https://ift.tt/eA8V8J
The original article was published at https://ift.tt/2L2nNiT

ZDNet yesterday reported (https://www.zdnet.com/article/uk-isp-group-names-mozilla-internet-villain-for-supporting-dns-over-https/) that an industry group of ISPs (Internet Service Providers – the companies that make money selling you your broadband or other Internet connection) voted The Mozilla Foundation, developers of Firefox – one of the most private and secure web browsers available – this year’s “Internet Villain“

What?

To the increasing number of people concerned about the large scale abuses by governments and corporations of surveillance, tracking and data harvesting tools, Firefox is seen as “one of the good guys” – a product with built-in ad-blockers and technologies that automatically block spying technologies like single pixel tracking images and automatic collection of browser finger-printing (a method of identifying you and your machine by collecting details of its hardware and software configuration.)

So, why is Mozilla suddenly a villain?

Because like Google’s Chrome browser Mozilla Firefox has plans to introduce DoH protocol – DNS-over-HTTPS.

A little background

DNS (Domain Name Service) is the mechanism that turns a URL (like www.biznik.co.uk) into the IP address (the ‘dotted’ addresses – in this case 5.196.141.21) that are actually used to route traffic over the Internet. The ‘thing’ that performs this translation is called a DNS server of which there are thousands of public and private examples spread all across the Internet. In order to resolve (translate) the URL of an unknown external domain into an IP address, a public IP server must be found that knows that domain and consulted to obtain the IP address. There’s a bit more involved than that (actually, quite a bit) but that explanation tells you all you need for this discussion.

The highly significant factor is that since the dawn of the Internet, DNS has operated in plain text – out in the open allowing anybody who can see the requests flying back and forth (like your ISP) to monitor every request made – and therefore track everywhere you go on the Internet. A clear abuse of privacy which becomes clear that most ISPs sell this information to data brokers who use it to help build the profiles these shady operators try to build on every one of us.

The public DNS server that you use is set by your ISP – unless you have taken steps to set your router (and possibly your workstations or laptops) to specifically use a DNS server of your choice.

Even this is not enough to stop your ISP listening in or simply diverting your DNS requests to its own servers regardless of which server you intend them to go to. This is because all DNS requests travel through the same port (port 53 – think of an Internet port being like a radio channel that you can “tune in” to or choose to listen to). Simply by programming the router at the ISP’s end of your Internet connection, the ISP can either listen in to all traffic flowing through port 53, recording the request and response regardless – or go further and ignore where you want the traffic to go (say, Cloudflare’s public DNS servers) and force the DNS request to its own servers anyway.

Either way, the ISP still gets to record all your DNS requests and may interfere with them.

An example may help.

caA number of years ago I moved to rural France. The village in which I live has no fibre Internet – in fact it is so disconnected that I cannot even obtain a telephone landline (the local telephone exchange has no spare lines left) and even if I could, the poor quality of the cables used to carry telephone signals would prevent even a very slow speed ADSL – around 512Kbps – the speed of an old fashioned dial-up modem). In effect, the village is cut off from the outside world of the Internet.

So, I installed an expensive satellite connection that, for around 4 times the price of the gigabit fibre connections available in towns as close as 5Km away, claims to provide 26Mbps download rate (2.6% of a fibre connection) and 6Mbps upload (outgoing). In practice the actual performance ranges between 0% and 60% of these headline figures. On top of this, the amount of data is capped at just 50GB per month – in both directions. If this figure is exceeded the ISP (Eutelsat) clamps the transfer rate (speed) of the connection to sub-dial-up rates – think 100Kbps in practice. In effect, the Internet gets turned off. As the radio signal has to travel several miles into space to reach the satellite then make an equivalent journey back to earth the “round trip” time is over 3.4 second – where a more typical ADSL or fibre timing would be a few milliseconds. On to of which the connection exhibits so much jitter (a technical term which measures the variance of time it takes one packet of data or the next to arrive at its destination) – being so bad that it is impossible to stream simple audio – like a telephone conversation.

But, needs must.

The satellite hardware was installed before we moved in (work was ongoing to adapt the house to my needs). But I installed the satellite modem/router and connected a laptop to perform a quick test that all was working. That done, everything was switched off. So imagine my surprise when I received an email the following morning telling me the whole month’s 50GB of data had apparently been used in a few hours. As the connection is uncapped between midnight and 06:00 even had the equipment been turned on and the line operating flat out at its claimed rate it would have been impossible to consume so much data in the time that had passed.

The company stuck to its guns and over several months similar sudden alleged spikes in traffic occurred – each causing effective cutoff of service.

After about 6 months of wrangling during which I patiently repeatedly insisted the company provide proof of the consumption they claimed I eventually received a spreadsheet containing a list of all the IP addresses and data consumed during that first, disputed night.

Take a moment to understand what just happened – my ISP produced a list of all the websites and other Internet based services (eg; streaming services, VOIP telephone services, email, cloud storage …) I had allegedly contacted and a measure of the amount of data allegedly passed between here and each of them.

It being the work of moment to do a reverse DNS lookup (the opposite of normal – translate an IP address into the URL it relates to) I could see that the vast bulk of the traffic was downloads from one of the big CDNs (Content Delivery Networks – in short companies that exist to deliver popular files like Netflix or YouTube videos from servers they operate around the globe – so that the content is delivered in a timely and responsive manner – and the load doesn’t all fall on one server behind a single Inernet connection).

To add to the fun, in an effort to “prove” that I was responsible for the traffic, the spreadsheet had been falsified (if we assume that any of it was true) as some idiot had clearly been watching my actual traffic over the six months it took them to produce the spreadsheet and had inserted a few rows showing alleged connections to the cluster of web and email servers (including the one that hosts the biznik website) which are located in a data centre in Strasbourg.

The problem is – several of the IP addresses quoted in the spreadsheet were not in use until 4 months after that first night as I had purchased an extra block of addresses as part of a reorganisation of server use months after contracting for the satellite service.

Great bunch of crooks. And technical idiots.

When I followed up the spreadsheet provided with the innocent question of exactly HOW the company could even produce a detailed list of all the alleged connections as all my machines are configured to use specific public DNS servers far away from the ones the ISP owns I eventually learned that the company diverts all traffic on port 53 (the DNS port, remember) to its own DNS servers regardless of the address that traffic was intended to go to.

Hence, not only was the ISP recording every single connection made from my premises and the amount of data flowing over those connections, it was taking control of where that traffic actually went.

So, we get to the point

DoH (DNS-over-HTTPS) uses the same encryption that is used to safeguard your connection and flow of data when you do your online banking or pay for some shopping with your credit hard. The same encryption used by this (biznik) web site and every other that runs inside the anadigi.net umbrella and being heavily promoted by groups ranging from the Electronic Frontier Foundation (https://www.eff.org/) to Google and browser addons like HTTPS Everywhere (https://www.eff.org/https-everywhere).

Just as no ISP can see inside the traffic flowing between you and a secure, encrypted HTTPS website (the traffic appears as a meaningless pile of gobbledygook while on route) the forthcoming adoption of DoH denies them the ability to see which URLs are being looked up – and therefore deprives them of the ability to tap this rich stream of data and turn it into revenue by selling it to data brokers we never gave permission to have it in the first place.

So there we have it. As the ZDNet article explains, everybody from the British Government through the self-appointed censors of the Internet the “Internet Watch Foundation” (https://www.iwf.org.uk/ to read what they say about themselves and https://en.wikipedia.org/wiki/Internet_Watch_Foundation to read a little background on the howlers committed and criticism of the organisation’s operations and methods) to the ISPs who are looking at the loss of a very lucrative , if questionably legal, revenue stream want to put a stop to DoH – just so they can continue spying on and monitoring us.

The arguments against DoH

As the ZDNet article reports, DoH is being attacked by governments and private organisations alike using the same worn out arguments that taking back the privacy of our communications will allegedly prevent censorship of “banned” Internet resources, prevent the blocking of child pornography and make it more difficult to catch criminals and allow GCHQ and the NSA to spy one everyone on the planet unhindered.

Couple of points:

  1. Anyone who wants to engage in criminal or terrorist activities or access perverted materials already has plenty of options to carry out their activities using commonly available technologies from a simple VPN to use of the Tor network (https://www.torproject.org/ – in short, a way to go complete “dark” on the Internet – whether motivated by a wish for privacy or to access the so-call “dark-web”). Please listen, idiot politicians and law enforcement people – you can howl at the moon as much as you like – you are not going to stop bad people from doing unspeakable things by abusing the privacy and rights of the 99%+ of the world’s population who simply want to go about their business without being spied on or told what they can and can’t do.
  2. I am in no way condoning or defending anyone’s ability to commit crime or engage in child pornography nor any other form of abuse. But DoH does not prevent the kind of censorship embraced by the IWF and British Government. The fundamental DNS mechanism itself allows for domain registrations (the “biznik.co.uk” part of the “www.biznik.co.uk” website URL you are possibly reading this on) to be struck off where it is shown that the domain is hosting illegal material – such as child pornography. Removing a domain entry from the public DNS record doesn’t just block access to a web site (by diverting attempts to visit it to the “naughty bin”), it removes the site completely from any access. Also, a site shown to be illegal can have its IP address removed or blocked at the Internet level – and as truly illegal and repugnant websites don’t even use the DNS system – they are accessed directly by IP address requiring no name lookup at all this is a far more effective way of putting paid to illegal behaviour. As a simple example, if you type the IP address 5.196.141.22 into the address bar of your web browser you will find yourself presented with the test site for our “The Primary Channel” children’s learning platform – normally accessed via the URL https://ttpc.anadigi.net – don’t worry there is no actual child information or child produced content there – the site is full of test guff we use to try out functionality before release – though do feel free to play the video on the home page!

The arguments for DoH

The current plain-text DNS system that dates back to the pre-dawn of the Internet has long been recognised as open to abuse and attack.

Abuses can include the fact that anybody with access to DNS traffic can record and use the information openly revealed – and that means more than just your ISP. The Internet’s resilience comes from its ability to direct traffic via any available route – cut the big cable that connects Asia to the United States and all the traffic it normally carries simply gets routed via Europe. An individual Internet user has no control of the route any message takes over the Internet – and any reply may come back via a completely different route and, to make matters worse two messages sent even simultaneously might take completely different routes.

For example, here’s the result I got when I looked into the route traffic might take from my workstation to Cloudflare’s public DNS server at IP address 1.1.1.1

mtr -r -c 5 1.1.1.1
Start: 2019-07-05T06:31:54+0200
HOST: gpws.anadigi.loc Loss% Snt Last Avg Best Wrst StDev
1.|– 10.0.0.254 0.0% 5 0.9 0.8 0.8 0.9 0.0
2.|– 192.168.254.251 0.0% 5 1.1 1.3 1.1 1.9 0.3
3.|– ??? 100.0 5 0.0 0.0 0.0 0.0 0.0
4.|– 89.234.160.161 0.0% 5 96.6 89.2 66.3 111.3 17.2
5.|– te1-8-1064.par-p1.as39886 0.0% 5 92.3 91.8 70.7 111.0 14.3
6.|– ae0-4102.par-th2-crluxpe0 0.0% 5 81.3 93.1 81.3 109.4 12.3
7.|– ae1-10.par-th2-crluxpe01. 0.0% 5 100.1 80.7 69.2 100.1 13.8
8.|– equinix-paris.cloudflare. 0.0% 5 78.7 95.4 78.7 109.4 12.0
9.|– one.one.one.one 0.0% 5 60.3 72.6 60.3 96.9 15.3

Looking at the results we can see that our message passed through EIGHT different servers before arriving at Cloudflare.

  • Of these, the first is my ISP’s router sitting at the other end of my connection to the Internet
  • the second has a private IP address so is probably inside the data centre used by the ISP (yes, I’m guessing as I have no way of knowing who operates it).
  • The third is a server running in full stealth mode – it returns no IP address so cannot be looked up in the DNS system to give any clue as to where it is or who operates it and the 100% packet loss shown doesn’t mean that it just gobbles up my message without passing it on – it just doesn’t respond to queries asking who it is, where it is or even how far away it might be – a bit of a concern, maybe?
  • The fourth has no domain name associated with it but just returns its IP address. Fortunately another quick query tells me that it is run by Odpop.net in Paris
  • The next four all return a named identity that I can look up to see who operates them

The key thing to note, however, is that a DNS query sent to Cloudflare’s servers in plain text (as is the current practice) allows ALL or ANY of these intervening services to record the content of the request – including where it came from (my IP address) and the URL I am looking for. Valuable information that any of these servers could harvest and sell on.

DoH arose from this need to plug a technical hole in the way the Internet works

Plain text DNS is very insecure. For example, having seen that our DNS request passes through many servers (some of highly dubious provenance) on its way to the server we want to answer us, any one of those intervening servers could choose to answer our DNS query itself – or pass it on to a spoof server that takes our request for the IP address of (say) our bank then instead of returning the correct IP address of the real bank’s server sends back the IP address of a web server that delivers an exact replica of the bank’s welcome page, invites you to login as normal, perhaps rejecting your attempts to type in just a few of your password letters as is common … so that within a couple of attempts your entire login ID and password have been collected. This kind of “DNS hijack” (or “man-in-the-middle” attack) is increasingly common and results in $billions of bank fraud each year.

DoH eliminates this security problem (as well as many others I could explain) by simply preventing any of the servers that sit on the route a DNS query takes from the requesting machine to its intended DNS server from seeing that the content of the message being transmitted is a DNS message at all. And, even if some clever clogs says “Ah ha! If this message is going to Cloudflare’s DNS server then it MUST contain a DNS query” – so what? That knowledge helps them not one bit as the encryption would need to be broken before they might see the DNS query itself.

Here we go round the same broken record again

So, is DoH “bad” and an obstacle to preventing criminal activity on the Internet?

Of course it isn’t. As I have explained, anyone with serious criminal or perverted aims in mind doesn’t use the DNS system to begin with.

As for the secretive, shadowy, self-appointed and technically incompetent Internet Watch Foundation, while its stated objective (removing all child pornography from the Internet) is laudable, DoH does precisely nothing to stop their work (though I would argue that work should be conducted in a more open and transparent manner and certainly not in the control of a single government).

The global DNS system is jealously guarded by a multi-national group of sensible trustworthy elected people who will remove the DNS entry of any domain shown to be hosting illegal content of any sort and help to block the IP address from being accessed as well..

The question that begs an answer is whether a shady group of self-appointed guardians (who have made some horrendous mistakes in their time) and a single government should be allowed to control what an entire population is allowed to see or watch. Or, as there is broad agreement between at least democratic societies on what constitutes “illegal” material IF such a mechanism is to exist it should exist at a supra-national level.

To explain the dangers very simply. There is no technical difference whatever between the actions and laws being put in place by western democratic governments and “the Great Firewall of China”. Both simply apply a blocklist to routers carrying Internet traffic in and out of the country.

The ONLY difference is the contents of the blocklist used. In the UK example cited by ZDNet the blocklist (purportedly – nobody knows as the websites on it are neither explained nor told that they are being blocked and users of the list must either use it in full or be forbidden to use it at all.)

In China the population is denied from obtaining Google search results, stream their news from CNN, Fox News, the BBC or Al Jazeera and are forbidden from reading the London Times, the New York Times or the Straits Times – so being forced to hear only the news, information and religious views approved by the Chinese government – because if the Chinese Government wants to block CNN (as an example) all it needs to do is add “cnn.com” and the associated IP address(es) to its blocklist and, hey presto!, CNN does not exist in China.

In the same way, there is nothing to stop someone telling the IWF in the UK to add an allegedly Muslim jihadist site to the blocklist (in fact there is an additional, mandatory blocklist in force for just that purpose).

So, here’s the problem

If I want to visit a web site promoting “extreme” views – whether far-right, far-left or religious based – in order to educate myself, decide whether the people behind the site have reasonable grounds for whatever grievance or action they are espousing or gain a better understanding of how young people are persuaded to travel half-way round the globe to pick up weapons and suicide vests and give up their lives … then I expect to be able to do that.

And, I expect to be able to do that without my government or shady, unaccountable, private organisation either blocking my access to that information or adding me to some watch-list because their self-delusional paranoia tells them that anyone searching for or looking at such material is of course a supporter of the cause.

Sigh! I’m an adult who has been on this planet for over 60 years. I am entirely capable of “being exposed to” extremist material from any direction without feeling the need to run off to learn how to fire weapons and set off bombs. That’s just not me. What is me is a curious individual who wants to know what motivates such groups so that I might better understand how to moderate whatever motivates them – and, as the father of three sons (way too sensible to be swayed by extremists of anypersuasion as tyey are) I would quite like to understand anything that their younger minds might have taken to in order – as a responsible parent – to hold a sensible, informed conversation with them.

When the UK Government (just as they’re the example we’re talking about here – I suspect the U.S, French and other governments act in similar ways) blocks a website because they consider it too extreme to be seen by the sensitive eyes of their citizens there is NO difference between their action and that of the Chinese Government blocking access to BBC, CNN or other sources of news and information.

And as for monitoring and recording every Internet connection I make I’ll just ask a single question.

If it was considered reprehensible that the East German Stasi police employed people to sit in postal sorting offices noting the sender and recipient of every letter passing through the post, why is it acceptable that democratically elected governments record the time, date originator and destination of not only every email or simple text message we send but every single Internet web page, image and service we connect to.

Just because governments have the technical means to do this does not give them the right to do it.

Bring it on, Mozilla!

To the good folks beavering away at Mozilla I say “Bring it on – more power to your elbow”.

As I have explained, there are very good technical reasons for the replacement of plain text DNS with DoH technology. It’s a weaknesss in the structure of the Internet that has been left unattended for too long.

And why pick on Mozilla? Google’s Chrome browser is used by many times more people than use Mozilla’s Firefox browser and Google is an equally staunch supporter of DoH. So – UK Internet Service Providers – why not point your arrogant tongues at Google? Anything to do with the fact that upsetting the Internet’s biggest player could hurt your business in oh so many ways – while taking a pot-shot at Mozilla (a non-profit foundation) lets you mouth off with no fear of retribution?

Do I really have to say it again?

None of us signed up to be spied on. None of us signed up to have our right to privacy removed. None of us signed up to have some unaccountable do-gooder or civil servant decide what we can look at, see or read. None of us should expect to come under the watchful eye of a secret service just because we happen to have sneaked a peek at some “suspicious material”.

As I have said many times, any technology is as equally capable of use for good or evil. The Internet and all the technologies that comprise and surround it were designed for good,

So just stop using them for evil. OK?

Tuesday, July 02, 2019

Windows 10: Yet another problem (another reason to ditch it today)

https://ift.tt/eA8V8J
The original article was published at https://ift.tt/321uzdU

If you use Windows 10 (why?) you will be familiar with the almost constant succession of disastrous updates and flaws Microsoft pushes out to all users of the operating system.

One of the latest to be found is that Microsoft disabled Registry backups in Windows 10 some time around October last year.

Apparently Microsoft disabled this very important feature intentionally but didn’t think it worth telling any of the ~800 million users of the operating system about it. Even worse, the operating system continued to report that the backups had been completed satisfactoriy – even though only an empty backup file had been written!

The problem was first spotted by Ghacks (https://www.ghacks.net/2018/10/31/windows-10-bug-prevents-registry-backup-creation/) who gave the full technical background.

A non-technical explanation that still explains the import of the issue can be found at Forbes (https://www.forbes.com/sites/gordonkelly/2019/06/29/microsoft-windows-10-upgrade-registry-warning-upgrade-windows/) – which also contains links to some of the other malware vulnerabilities, dead computer, data loss and unannounced disconnection of previously working peripherals (like a mouse or keyboard, for example) that have resulted from “updates” and “improvements” pushed out by Microsoft.

Microsoft has issued an explanation (er … the change was made to reduce the amount of disk space taken by the operating system!! Since when was a backup a disk storage problem?) which you can read on the Ghacks site (https://www.ghacks.net/2019/06/29/microsoft-explains-the-lack-of-registry-backups-in-windows-10/) – along with instructions to restore the function “if you want to”.

Let me try to explain the significance. Windows stores ALL its settings (including those affecting security, the operating system itself and individual application programs) in something called its Registry. This is not a plain text file but a pseudo database which can only be edited with a program – regedit.exe – provided with the operating system. Microsoft issues dire warnings that the Registry should NOT be edited by users who do not fully understand the consequences of doing so or the thousands of arcane settings it contains. I would agree – one wrong click of the mouse or a slip of the keyboard when using regedit can make your computer completely inoperable.

Now – Microsoft issues instructions to those very same uncomprehending users to go ahead and edit the Registry to restore a function that should never have been removed!

Why are Registry backups so important?

If you are a Windows user living within a corporate environment in which your security and the mundane – though vitally essential – matter of backing up the state of your machine and its data is taken care of by “the IT Department” then you can (I certainly hope) ignore this problem (at least … the other ones that have happened are a little more bothersome – like finding your work reports or spreadsheets have suddenly disappeared). Peace be with you!

BUT … if you are one of the millions of people who simply purchased a PC or laptop pre-loaded with Windows or fell for the free upgrade offer that Microsoft ran to encourage users of earlier Windows versions to “upgrade” to Windows 10 I very much doubt that you have an effective backup routine in place, let alone know what a “roll-back” is or even have enough security to keep malware and “bad guys” from getting at your machine and its data.

My evidence for that statement is the number of friends who have come to me over the decades clutching their machine or hard drive, holding it out like some form of offering while uttering the time-worn phrase “Please get my data back for me” or “It just stopped working, I don’t know why and all my life and work history is on it!“

Unless the cause of failure is an irrecoverable hard disk failure or ransomware style encryption of the entire storage the cause is probably malware (computer virus), hardware fault or just turning the machine off the wrong way. All of these causes (and more) can corrupt the Registry.

And Windows usual response to finding a corrupt Registry is to refuse to boot up at all – ie; your machine is as good as dead.

However, if the Registry has been backed up then even in the case where no System Restore points have been made a Registry Backup can usually be used to restore the machine to an earlier state, allowing Windows to boot and data to be recovered or copied even if program settings and operating system updates or configuration changes must be performed once again.

So … a Registry backup is just about the last line of defence when it comes to restoring a dead Windows machine to life.

But if the Registry backup file is empty … you are out of luck.

Let’s hope you have a friend like me who is able and willing to at least take the machine apart, take out the storage drive(s) and get your data somewhere safe.

I only do it once per close friend – recovering their data can take anything from a few hours to over a day of my time. I give them a sheet of instructions describing an effective backup procedure and send them away with instructions never to darken my door with a dead PC again – owning a computer is just ike owning a car – you don’t have to know how it works BUT YOU DO HAVE TO KNOW HOW TO USE IT SAFELY!

Thursday, November 22, 2018

Internet Security – Part 5: Installing better locks

https://ift.tt/eA8V8J
The original article was published at https://ift.tt/2PJjlZ0

What can be done to improve security?

So far this article has focused on the problems with the security of Internet facing IT systems. I hope it is obvious to all that much needs to be done to improve the entire landscape from the way that users authenticate their access to sensitive systems through to the responsibilities of companies and organisations to respect and safeguard personal data and possessions with which they are entrusted.

So, the truth is that much can be – and arguably should ready have been – done to improve data security on the Internet.

When reading the outlines below, please bear in mind that the information is presented back-to-front. The reality is that no single software developer – or even a company’s IT director – can implement a “security first” systems design and operation approach as is needed to deliver secure systems operable on the Internet.

The impetus and instruction for the changes necessary to improve the security landscape must come from the top. For smart companies that means the boards and directors taking the time and trouble to learn this “difficult techie stuff”to at least the level necessary to know the questions to ask and how to evaluate the responses received. Personally, I believe there is commercial advantage to be had to companies that can promise true security to their customer base.

Ultimately, the final top-down effectors of change are governments, both national and supra-national. If companies and organisations fail to get their acts in order to prevent the current volume and scale of abuse of personal data seen on the Internet then they must expect that laws will be enacted to enforce the necessary changes. Complaining about such legislation has all the effect and moral rectitude of arguing that of course you don’t have a driving licence after being involved in a traffic accident – after all you are entirely competent to decide for yourself your competence to drive a car as other road users reasonably expect. In the same way, arguing that you should be left alone to safeguard and do whatever you want with your customers’ personal data carries no more weight.

In simple terms, change must be driven from the top. In an ideal world, company boards would become proficient in IT matters and enact the necessary changes. In the real, practical world we inhabit I suspect that companies will only change when external forces – market expectations or a legal framework carrying truly painful penalties – force change.

Technical changes

The design, construction, deployment and operation of commercial IT systems is such a diverse and complex area that it is impossible to do more than cover some general principles in an article such ast his. There is, I believe, one principle that should be kept in mind by anyone responsible for the design or implementation of a complexIT system – that principle is the concept of control.

What do I mean by “control”? Simply the degree to which you can retain control over components of the system being deployed. There is a modern trend to treat complex IT systems as mere collections or assemblies of building bricks – the idea being that a complex system is built by combining the “best in class” component specialist sub-systems.

So, we see systems constructed out of some supplier’s accounting system, another’s inventory system, another’s customer support system, another’s marketing and customer relations system, an off-the-shelf customer engagement system based perhaps on a blogging platform “repurposed” for the need …. and so on.

Systems that are cobbled together like this represent the worst examples of expediency over long-term usability and control. Actually more expensive to put together (every component must have individual interfaces to other components with which it must share data or processes). Data is spread around like confetti between different, competing databases – each of which must be updated and kept instep with one another in real-time if anarchy is not to quickly arise. More purpose-written processes to develop, test and maintain. In production, such systems quickly become a nightmare to maintain as different components develop and require interface changes to schedules determined by their developers – the alternative being to continue use of now outdated versions with the security and reliability implications that involves.

It should be obvious that the costs and complexity of managing such systems destroys reliability while harming control enormously.

Put simply, organisations that use this approach to complex systems have no effective control – they are entirely reliant for the reliability and security of the overall system on the individual component suppliers – and their own ability to keep pace with changes required to the purpose-written interfaces between the components.

A simple piece of advice – understandable by the least technically proficient company director – complexity is the enemy of control. If you seek a system whose security and reliability you can control –keep it simple.

System design

The lesson here is simple – the design of systems must be driven by a “security first” culture. Every function, operation and change to the design of the system must be subject to consideration of its impact on the security of the system and the data it holds and processes.

It is important to understand that prioritising security need not negatively impact either the usability of the system or its flexibility and ability to adapt to an organisation’s developing needs.

All design / change decisions must pass a security review to assess what impact may occur to either/both the attack surface of the overall system and the potential to open exploits to directly affected system parts or – indirectly – by granting access to other privileged data or functions. Only after this security assessment is successfully passed should the design be passed forward for development.

Such an assessment should never allow an authentication system such as that deployed by Credit Agricole to ever be developed, let alone deployed for live use. Equally, had Facebook conducted full and proper assessments of the developer interfaces it introduced (driven by the desire to gain more users by enabling outside developers to develop widgets that would drive user engagement on the site …which inevitably involved exposing at least some user data to the interface) the ability to abuse the interface to elevate permissions in order to gain access to personal data sets that were not part of the intended design should have been recognised and the detailed design altered to prevent such abuse before development began. A day of consideration and reflection saves weeks of a CEO having to testify before government committees and courts.

When considering the security implications of any design decisions itis essential that he normal developer mind-set of “this will be great/exciting/fun” must be put aside in favour of a mind-set that puts the assessor in the mind of someone trying their hardest to attack or abuse the system. While the role requires a level of technical proficiency at least as high as that of a good developer the role should go to someone versed in “white hat” hacking –ie; trying to penetrate a system in an ethical manner in order to identify and report flaws capable of exploit in order that they can be addressed before being released to public risk.

System change management

All systems must be capable of change and adaptation over time to continue to meet the evolving needs of the organisation they serve.

However it is vital to recognise that the area of system change presents perhaps the greatest risk to the reliability, safety and security of a running IT system.

I have seen organisations where the marketing department has been allowed to simply demand that the IT department (and its system developers) implement or install some new function or technology that the marketing department “needs” – usually right now! The result quickly becomes a web site full of third party originated scripts whose working nobody can explain and after only just a few weeks nobody can remember why they were implemented or what purpose or internal process within the organisation they enable. To say that this way of working presents an enormous security risk is an understatement of such proportions I shouldn’t need to be writing it. Yet the practice can be seen plainly by anyone capable of calling up the code behind any web page and scrolling through counting the number of such scripts and odd code included. In the worst cases I have seen organisations that have deployed session replay technology (the most invasive personal spying technology currently easily available to web site operators) presumably because the marketing department “needed” to see how users were interacting with the website … quickly implemented without a single thought given to the harm caused to site visitors and the exposure to legal risk the organisation was being put to.

No matter how great the “need” or how urgent the desire to support / release some new product or service might be, system change is system change. ALL system changes must be subject to the “security first” mantra and be put through the same assessment process as any other change proposed to the system.

System operation and management

As already described, having even a perfectly secure system design gains precisely nothing if the system is then operated in a slap-dash way.

Many people (board directors, time to perk up – I may have you in mind here) fail to realise the amount of work required to keep a system up and running on the Internet 24/365. The absolute need for company boards and directors to understand how these complex IT systems work is covered below. For now just understand that even a simple website compromises an underlying operating system, web server software, database management software, and a panoply of web, server and client-side programming languages – oh, and let’s not forget the code that actually makes a web page display on a web-site visitor’s device.

All these layers of software and data are individually complex and all must be regularly backed up, maintained, occasionally restored both as individual components and as a whole.

When, say, the underlying operating system must be upgraded (see the section “System maintenance” that follows) the likelihood is that the server running the entire system must be rebooted –meaning that the website goes “off air” while the machine is restarting and, more importantly, any customers or visitors using the site will experience service interruption. In practice modern websites do not run on a single machine but on closely connected clusters of (usually virtual) machines that distribute the load placed on the service being provided, place sensitive services (such as the database) inside a network inaccessible from the Internet and allow individual machines to be updated or otherwise serviced without interrupting continuity of service to visitors.

It is important to understand that the majority of Internet services (eg; web-sites as being discussed here) are actually run on “virtual machines”. A virtual machine (“VM”) is simply one instance of a“machine” that is running (usually) alongside other virtual machines on a single physical computer server. Several technologies (which are outside the scope of this article) can be used to deploy virtual machines but the benefits of VM technology are several and bring many benefits including:

  • Cost reduction – a single physical server can run a number of virtual machines and make better use of the processing power available
  • Backup – the “state” (ie, a snapshot of everything the VM is processing and all the data it possesses) can be taken in a very short time and without interrupting the machine’s operation
  • New VMs can be created or destroyed at whim – if more processing power is required for example or a replica of a machine is required to test an upgrade or other new software a new VM can be created or copied very quickly – then used and destroyed when it is no longer needed
  • The individual functions required to operate a website (eg; a web server and a database server) can be placed on separate VMs and segregated so that access to the web server is possible from the Internet while access to the database is only possible from the internal network – helping to prevent bulk data loss or breach
  • In case of physical hardware failure or upgrade need the VMs running on that piece of hardware can be quickly or even seamlessly be moved to another physical machine allowing the first to be maintained

Like all technologies VM technology can be a double-edged sword. The same ease that allows a VM to be replicated, backed up or new VMs to be created at whim if not properly managed can lead to major problems.

Many cases of software update or change involve structural changes to configuration files or entire database structures. One of the (so far unsaid) benefits of VM technology is the ability to easily roll back a system to an earlier state – something that may become desirable in the even of data loss, system corruption or upgrade failure for example. But sometimes this alone is not enough to allow a security blanket in case something goes wrong during or after an upgrade. Take the example of a software upgrade that requires structural change to a large database. Sensible practice would be to take a complete copy of that database before making the structural changes – that way, should the upgrade fail in some way the original database can be restored and the state of the VMs that use it can be rolled back, restoring the use of the system while the problem of diagnosing and correcting what went wrong can be dealt with.

The next thing to understand is that many of the physical servers that run all the VMs are no longer present in data centres on an individual company premises. With the rise in popularity of cloud computing the likelihood is that these VMs exist “in the cloud”. In real word terms this means that a VM may as easily exist in a datacentre in Phoenix as Strasbourg, Dublin or London.

Data storage can also be virtualised in a similar way to a machine. So that database – which might occupy several Terabytes of storage is just another instance located somewhere in the cloud. And whereas in the days of real machines and proprietary company data centres a company would have to invest in some multiple of the actual storage capacity it needed to operate its IT services in the age of the cloud if a quick copy of a database is required during a system upgrade the answer is to simply create (a possibly better term here is “rent”) another storage instance of the required size, duplicate the data tot hat and just destroy it as soon as it is no longer needed – much more cost-effective.

Here comes the cutting edge of the sword. If the operator who creates the new storage instance omits to secure it (by setting passwords and ensuring it is inaccessible from the Internet for example) … then the entire database contents become publicly available.

As organisations right up to the super-secret American NSA have discovered to their cost this kind of simple, human error makes all the work put into securing operational systems worthless as the data is gratefully hoovered up by “the bad guys” in an instant. And a major data breach just occurred.

System operation and management – the right way

Having looked at how modern web sites or services actually exist and are delivered in practice and having identified some of the horrific consequences of making simple human errors how does an organisation preserve its security and protect itself from such horrors?

The answer is to go back to lessons I learned at the dawn of commercial data processing when giant mainframes the size of power sub-stations (but with less processing power than the phone in your pocket) ruled the computing universe.

Answer: Procedure manuals and check-lists.

It really is that simple – backed up, of course, by management oversight that ensures those procedures and check-lists are followed and adequately recorded to enable every process to be audited … and a corporate policy enshrined in employment contracts that defines failure to follow a defined procedure and rigorously complete each check in an auditable manner as an example of gross misconduct possibly leading to demotion or instant dismissal.

If that sounds simplistic and drastically harsh may I suggest you spend a day as a ‘fly on the wall’ inside a modern IT operations centre – and observe the young techies fingers fly over keyboards connected to multiple machines behind which lie dozens or hundreds of VMs gleefully displaying their advanced skills by “spinning up”and destroying VMs at whim and moving major datasets around with no more effort than offering a toffee from a jar.

All unrecorded and all subject to a single finger-slip that either destroys the live dataset – or puts a copy out on the Internet with no protection at all.

The experience should suffice to illustrate the need for procedure manuals, check-lists and good old-fashioned accountable management.

At the same time, adequate emphasis must be given to staff training.

  • Training on the essential need to follow procedures
  • Training on understanding the relationship of trust between an organisation and its customers – and just how important and valuable that trust relationship is to both parties
  • Training on adopting a “security first” culture – to both customer data and the organisation’s own data. No organisation should have a single member of staff that might fall for a human exploit – whether fake email phishing scam, phone call from IT support or click of a link on a dodgy (or, sadly, even reputable) web site.

System maintenance

I understand and support a company’s decision to base its services on an enterprise class operating system (such as Redhat Enterprise Linux or its open source variant Centos) rather than a leading edge, frequently updated variant such as Fedora, I do not understand corporate IT policies that insist that every little operating system patch must be subjected to its own extensive testing before installing it on their live systems. Do they not understand that (especially in the open source world based around Linux) every patch and software update has been exhaustively tested thousands of times on thousands of different hardware configurations before it hits the live release channel?

In these times of increased security bugs and flaws – never mind the fact that other software that may be updated contains bug fixes and performance improvements this behaviour makes absolutely no sense.

For over a quarter of a century I have run a mix of enterprise class and leading edge systems. All my machines are updated at least once every day as new software updates become available. In over 25years I can recall two instances where a nightly update has caused a problem. I defy any corporate entity that operates a deferred patch deployment policy to tell me they have suffered as few outages over a similar time period.

Simple fact: by the time a security patch is released knowledge of the underlying bug is already public knowledge and hackers will be busy trying to find machines that have yet to be patched. Remember those tens of thousands of attack attempts our little network see off each day? They represent hackers trying to probe our network and servers for known vulnerabilities – windows and doors that have been left unlocked.

On a balance of risk-benefit the benefit is clearly in favour of installing at least security related patches as soon as they become available. Not to do so invites systems to be compromised, corrupted or taken over by malicious actors.

Keeping a system up-to-date is only part of the maintenance job. An equally important function is …

Keeping abreast of the technology

As the CA example shows it’s just not good enough to install the current “best-in-class” security and forget about it.

The technology and IT security landscape is constantly changing.

As an analogy, developing and operating a secure web-site today is more like building a physical bank – then knocking it down to rebuild a more secure version every few months. That is assuming that steps have been taken to avert urgent threats as soon as they arise.

An essential requirement of maintaining a complex commercial web-site is to remain abreast of the technology and threat landscape to ensure that the web-site remains both relevant to its users and its owner and as safe as it can possibly be from external attack.

Any company director, banker or accountant should be familiar with the concept of depreciation – in short, the recognition that any asset has a finite lifetime by which it must be replaced if the job it has been doing is to continue. IT systems are not immune from this concept. Yet companies insist on treating their IT systems – in particular their Internet facing systems – as if they were old fashioned bank buildings. A construct that is built and then expected to last 50 or 100 years with only a new lick of paint every 5 years,a change of locks every 10 and a new vault every 20.

Modern computer systems depreciate (their fitness for purpose) far more rapidly. Companies need to learn that their Internet facing IT systems should be completely rebuilt at intervals of between 3~4years within which period they must be constantly updated to remain safe and secure.

In the past ten years (a period which has seen no major improvement in physical door-lock technology that I am aware of) has seen

  • the fundamental way that Internet users view and interact with web-sites shift from desktop (or large screen) devices to new form factors – to the point that today most web-site visitors view those web-sites through tiny mobile phone screens – in portrait format rather than the landscape format of old. We are now seeing the rise of voice technology. Soon, users will expect to have no screen or display at all – they will simply ask a device in the corner of the room (or their car, their watch or their house …) to tell them their current account balance or to transfer money to pay a bill. The technology to do this is available now – the challenge for systems designers is to deliver the desired functionality while maintaining watertight security and proof of identity.
  • FAR, FAR more important changes happen on the technology plain.
  • Advances in computing power have meant that security algorithms and mechanisms that were considered safe a decade ago can now be cracked in a few seconds. Still the second most commonly used password in use is simply “password” (the most common in 2017 was – if you can believe it “123456”!!).
    • If encrypted using the still commonly used MD5 algorithm (supposedly one-way – ie; once encrypted with MD5 it should be impossible to decrypt the original text) “password” is cracked in less than 3 seconds (most of which is the time it takes to communicate back-and-forth with the website over my satellite based Internet connection) using the website https://crackstation.net/ – if you’d like to try yourself, the MD5 ‘hash’ (the encrypted form of “password”) is 5f4dcc3b5aa765d61d8327deb882cf99. Even a highly uncommon password within which certain letters had been replaced with numbers was cracked in no more time. In passing, this is because so many websites have leaked so many passwords alongside their encrypted hash values – so, saying that this website is ‘cracking’ the password is not at all true – it is simply looking up the hash value in a database that contains previously obtained hash values and their original values. But even where no database entry is available, current computer hardware can actually crack an MD5 encrypted password within times ranging from a fifth of a second to around 20 minutes for a complex, 12 character password.
    • Information on the current best-in-class encryption algorithms and even instructions on how to implement them with most common web programming languages can be found at https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet – so there really is NO excuse for not implementing or updating better security. Most encryption methods used to store login credentials are of the one-way kind – ie; the original password or other encrypted text cannot be recovered from the encrypted value as there is no key. Instead, at login, the credentials entered are encrypted anew and the encrypted values are compared to the stored values. The “penalty” when a one-way encryption algorithm is changed is that, as there is no way to recover a user’s original plain-text password, the user must be asked to choose a new password. This is good practice in any circumstances and allows the requirement for complex passwords to be imposed at the same time. For sensitive sites (such as on-line banking) this is far from an unreasonable step to take – far more reasonable than allowing the site to remain vulnerable where user credentials have been exposed by data breach (even by another site – users, despite all the warnings, will insist on using the same password to login to multiple sites) or the algorithm currently in use is likely to become unfit for purpose within a year or two.
  • The language in which web pages are written (HTML) is now at version HTML5 and operates in a totally different way from the version in use a decade ago.
  • The threat landscape (the number of “doors” through which an IT system might be attacked) has grown exponentially. Coupled with the equally exponential number of mechanisms “lock-picks”) that might be used the entire structure of a commercial web-site and the way its components are opened or restricted from the web has to be rethought and systems redeveloped to take these factors into account.
Simple steps to maintain system security

In summary there are just a few simple steps needed to maintain the security of an Internet facing IT system:

  1. Apply software patches and upgrades as soon as they become available.
  2. Keep up-to-date with changes in at least the key technologies used to defend the system and its users from attack – at minimum these changes include encryption algorithms, programming languages, database engines and other key components.
  3. Regularly check all third-party scripts that are embedded in delivered web pages. Simple rule – the more third-party scripts you allow into your system the less control you have over its security and the safety of your customers – as you never know when a third-party changes their script to do something undesirable or is itself hacked with the effect that you now have a criminal exploit running inside your system.

Vulnerability assessment and Penetration testing

Good systems design, excellent operation and regular maintenance are not the end of the task list for operating a secure system. I have omitted testing as (I assume) everybody knows that software and configurations must be rigorously tested before being put into live production use.

All sensitive systems should be subject to constant vulnerability assessment and penetration testing by teams properly qualified to perform the roles. The aim should be to discover “open doors and windows”, bad design, inappropriate or improper use of external scripts or third-party supplied program code etc. Brief description of the aims and purposes of such testing can be found athttps://www.thesecurityblogger.com/defining-the-difference-between-a-penetration-test-vulnerability-assessment-and-security-audit/and here https://en.wikipedia.org/wiki/Penetration_test.

To understand why I will return again to Credit Agricole. In November2017 I had cause to write to the bank after discovering that confidential, personal information (eg; customer date of birth, eligibility for loans and other credit scoring flags and even the balance of funds held in savings accounts) was presented in every web page delivered after a user logged in. The only technical protection against this information becoming public knowledge was the use of the “secure” HTTPS protocol to deliver the web pages. As described earlier, this is a bank that ignored widely published advice dating from 2010 to stop using SHA-1 based certificates to authenticate and secure web sites (it actually only changed to an SHA-2 certificate on 17 January 2017 – in relative terms minutes before Internet browsers like Firefox and Chrome would have refused to display the bank’s site – even then failing to change to certificates for subsidiary sites – eg; those used to host and deliver the bank’s advertisements and technical assets causing browsers to issue warnings about site insecurity to every CA web-site visitor throughout 2017).

But regardless of the security of the particular flavour of HTTPS used by the bank, from a system design perspective three matters are relevant.

  • First, I can conceive no possible reason for publishing such confidential information within a web page – the bank may want to know the kind of information disclosed so that its staff can try to advise (sell products to) its customers, but it surely has internal IT systems that display that kind of information to its staff.
  • Second, the reliance on a single security layer provides a single point of failure. When technology fails, it tends to fail catastrophically and rapidly.
    • An example is the recent discovery of flaws in the design of almost all CPUs (the ‘chips’ that provide our computer’s processing power) that allow sensitive information such as logins and passwords to be leaked – provoking a massive effort from chip manufacturers, operating system developers and others to mitigate the problems. These flaws have lain undiscovered (and therefore exploitable by who-knows-who) for decades.
    • In similar fashion, the underlying algorithms that secure the HTTPS protocol could fail at any moment. A simple fact. Should such a failure occur – coupled with this system’s appalling authentication methods – customer data becomes exposed unnecessarily.
  • Third – though there is always a temptation to view IT systems and their operation in isolation … in a perfect world in which user only press and click what they are supposed to and computers and logins are never shared – in the messy real world all these factors and more come into play. Here, there has been a number of assumptions that, taken together, can be summarised as HTTPS provides a secure channel between the bank and its customer. It does not.
    • HTTPS (at best) provides a secure channel between a computer server delivering information (a web page) to a remote browser.
    • What the receiving browser and user does with that information once decrypted and displayed is for them to decide. This is not an excuse for systems designers to simply shrug their shoulders and say “Oh well, that’s out of our hands” – it is incumbent on designers to take the WHOLE system – which includes its users and the environment in which it operates – into account.
    • To take just two examples of how personal data might be disclosed. I should say at this point that all of the research I conducted on Credit Agricole was driven by personal interest (I was a customer) and none of the research involved any hacking or attempts to infiltrate the company’s computer systems – all I did was look at the information and documents (web pages) sent to me by the bank. To explain first, on almost any modern browser, typing the key combination ‘ctrl+u’ will open a new view showing the “insides” of the web page you were looking at – revealing all the code, internal and external programs and much else that when taken together “make the page work”. So, anyone can download a web page – hit ‘ctrl+u’ – and see what’s going on. This is schoolchild level knowledge – an IT professional (or a hacker) can be expected to have an entire tool-chest of forensic examination instruments available.
      • Example1: Messy world. A customer sits in his/her office using their break-time to do some on-line banking. While a page (perhaps one trying to sell insurance policies – something the user thinks is innocuous) is open a ‘crisis’ erupts and the customer is called away, leaving the page open. Someone else comes along, hits ‘ctrl+u’ and no amount of HTTPS stops them gaining access to the customers date of birth and savings and loan account balances.
      • Example 2: Technology is sometimes too useful for its own good: Internet browsers cache (technical term meaning “temporarily store”) whole pages and even windows containing dozens of tabs in order to speed display times by not having to download again data that is already available. So … here’s a neat trick. Open a web browser (Firefox, Chrome, Safari …) – open a second tab – within that tab, login to a web-site (CA’s will do) – now (typical user behaviour) do not log out but simply close the tab. Find the particular browser’s “Undo closed tab” (or equivalent) command and re-open the tab you just closed – it doesn’t matter if you open and close 5~6 other tabs and sites between closing the secure page and re-opening them – just keep executing “Undo closed tab” until the one you want reappears. Bingo! The page you were just looking at (perhaps showing bank account balances) will reappear. Hit ‘ctrl+u’ to see what may be “hidden” behind the page. Imagine for one moment that the trickster here was a person of bad intent … see how the system fails?
    • There are extremely simple solutions to both examples I just gave. Number 1 is that old “keep it simple” mantra – again in the form of “if you don’t give it, it can’t be lost”. The example problem is caused by CA inserting data entirely unnecessary to the working of the web page or site into the data sent. The solution is equally simple – send only the minimum data required for the web-site to work – and no more. Number 2 is a simple technical fix – it is possible to tell browsers which data may be cached – and which data must NOT be cached. Use this simple technique and the trick I explained doesn’t work … unless you also forget to limit the lifetime of the cookie that represents the customer’s login session to the lifetime of the window – meaning that the cookie and associated login session is destroyed as soon as the user closes a tab or window. Forget to do this and, regardless of the caching rules set, the browser will simply request data from the (still live) session on the server and redisplay the page. In CA’s case they had neither set caching restrictions nor proper cookie lifetime restrictions allowing the trick I described to be performed by anyone. Who would expect this of an upstanding bank?

I want to continue looking at Credit Agricole – not because I have any personal gripe (though I confess plenty of professional frustration) against the bank nor wish to cause them harm but because their IT systems are like the gift that keeps on giving – a book could be written using just their public-facing systems to illustrate how NOT to design, develop and operate Internet connected IT systems.

In November 2017 I again entered into correspondence with a main-board director of Credit Agricole, wishing on my part to make him aware of the serious flaws in the bank’s IT systems security and potential for unnecessary disclosure of confidential, personal data. That was my wish. You can guess my expectation. And … my disappointment when the letter I received was a boiler-plate text full of platitudes such as “Credit Agricole is constantly strengthening and auditing its information systems …”.

If the constant auditing claim was true then the only conclusion reachable is that either the auditors were incompetent – or their findings and advice had been ignored by the bank’s management for years.

The“constantly strengthening”claim was certainly untrue to my direct knowledge. Having first written to disclose serious system security flaws in 2015 I had seen the bank’s system security worsening over the intervening period. To give just one, final (of many), example of what was wrong my reply contained this paragraph:

“Each and every page of the Credit Agricole web site incorporates common program code libraries which are up to NINE years out of date and which contain (in the versions used and in the case of just two of the libraries included in the CA web site) over 9,700 published and documented security flaws. In case you do not understand the implication – when a securityflaw is identified, it is first notified to the maintainer of the code library (as it is in this case) and time is allowed for the security flaw to be fixed. After the time has expired, FULL DETAILS OF THE SECURITY FLAW – INCLUDING SAMPLE PROGRAM CODE THAT CAN BE USED TO EXPLOIT THE FLAW is published. In simple terms, a teenager in a bedroom can look on-line, find and download program code designed to break into Credit Agricole online systems. As of today, your website contains over 9,775 such published security flaws.Think of them as 9,775 open doors into your bank vault through which any criminal could walk and help themselves to whatever they wished.”

That’s right – CA hadn’t bothered to update its underlying system software for at least nine years. During which time (all software contains bugs, remember) over 9,700 security flaws had been found, fixed,and published. But all 9,700+ were still open to the winds on the CA web-site.

How difficult is it to monitor such bugs and their impact? The first response is that, if the system is being kept up to date, it should only be necessary as a back-stop – a secondary check that nothing has been missed. Recall the mechanism: security researchers are constantly trying to find bugs in software exposed to the Internet –when a bug is found it is reported to the developer who is allowed time to develop a fix and deploy (at least, offer) that fix to all affected users. Only then are details of the bug published so that other researchers can learn from it. This mechanism and the eventual reporting is a well managed scheme. The bugs are called “CVEs” (“Common Vulnerabilities and Exposures”) and a full, searchable database is available on-line at https://cve.mitre.org/ and at https://www.cvedetails.com/ and at https://nvd.nist.gov/vuln/search and at https://oval.mitre.org/ and at …

Enough bashing of Credit Agricole!

 This article is not an excuse to bash or expose the failings of asingle French bank. Sadly, from experience I could have spread examples of appalling practice across a number of organisations that I have encountered in just the last few years alone.

It just so happens that Credit Agricole provides a case study in how NOT to operate an Internet-facing IT system.

Perhaps the lesson to be taken here is that companies and the directors and senior management must become much more aware of the risks posed by poor Internet Security and the relatively simple steps that can be taken to avoid the majority of security risks likely to expose personal or corporate data.

Wednesday, November 21, 2018

Internet Security – Part 4: Placing responsibility where it belongs

The original article was published at https://ift.tt/2Bo6fYe

Corporate and Board responsibility

Credit Agricole is far from unique in its implementation of on-line security measures that are inadequate by any reasonable assessment. While discussing why breaches occur I suggested that a crude, cold-hearted financial motive lies behind most of the data loss and fraud that occurs on the web.

Simply stated, it is cheaper for an organisation to ignore data security than to incur the costs associated with locking the doors and windows to keep it safe. As episode after episode has shown, even the most massive (and, on a personal level, catastrophically harmful) data breaches that have occurred (eg; Yahoo, Facebook) result in fines that are derisory in comparison to the scale of the companies’ profits. As for civil or criminal prosecution of the companies or their directors for their dereliction of duty – forget it. The legislation isn’t there to support such prosecutions.

OR … it wasn’t.

On 23rd May 2018 a change occurred that has massive ramifications for companies that hold and process personal data. That was the date that the EU’s GDPR (“General Data Protection Regulations”) came into force. Finally, legislation with real teeth exists. Companies that allow or enable data breaches similar to those I have described or companies like Credit Agricole that employ inadequate security and inevitably enable personal data loss can now be fined the larger of 20 million euros or 4% of their worldwide turnover (not profit, their income before expenses).

Companies must now look hard at how they protect their customers from data breaches. The old risk-benefit ratios (which determined it was cheaper to let data be lost and pay for any clean up afterwards) are replaced by the potential of fines that can impose material damage to the bottom line of any organisation – perhaps even do existential damage to (ie; put out of business) the worst offenders.

Itis early days with GDPR. The big tech companies who gain most from harvesting and combining personal data fought hard to stop the legislation coming into being – and failed. So far most have responded to the data privacy requirements of the legislation – in most cases by amending privacy and cookies policies and, in some case, providing some description and control over how personal data can be harvested and used by the sites. I see this as just a misguided attempt by companies whose business modelrelies on the abuse of customer data. It will be interesting to see what happens the first time a Facebook or a Google is confronted by acomplaint of data breach – and faces fines on a scale never before seen. Watch this space with interest.

The situation for companies that have grown up in an environment that allows them to abuse the Internet and its citizens in a fashion akin to the way outlaws in the old Wild West used to terrorise and abuse the citizens of remote towns and communities is changing as users and governments begin to realise the scale of privacy invasion and personal harm that is being perpetrated. Because worse(for those companies) is yet to come. GDPR is only a part of something called the European Data Privacy Framework and, while the details of this legislation this have yet to be finally agreed the legislation is likely to come into force in late 2019. At which point the tables should really be turned and I expect that both companies and the directors who control them will face criminal penalties of sufficient magnitude to make even the most adventurous and care-free among them think twice about their attitude to keeping the doors and windows locked shut.