Tuesday, August 18, 2009

The same TJX hacker?

How many more breaches were perpetrated by Albert Gonzalez? According to new charges, he is saddled with TJX (from before) and now with Heartland as well as Hannaford! The guy has been busy, no doubt.

What was it that made these breaches similar? And what did we not learn from the first ones that we let Albert and gang do it again and again? Obviously there are many theories - but my view is, at the end of the day, infrastructure protection can get you only so far.

We need an information-centric approach to protection where the focus is not on the pathways, perimeters and devices, but on the data itself. Imagine if this were the case in the above breaches, where data was stripped of networks, or from servers. If that data were protected at rest and in flight, it would not have mattered if the data were copied outside the company - it is protected! It remains encrypted!

Better, more logical and more effective security. But seems like folks are still in the rush of "protect the infrastructure"...

Thursday, July 30, 2009

Persistent, information-centric protection, PCI and the Network Solutions breach

The more news I see regarding various breaches, the more I am convinced of the superiority of persistent and information-centric security. For example, take the latest breach at Network Solutions - a PCI compliant organization. Over half a million cards stolen.

Comments galore:
Here is what they say "The company determined that the unauthorized code may have been used by cybercriminals to capture transaction data, including customer names, addresses, and credit card numbers, and transfer it to servers outside of the company...."

Now look at the statements below from industry experts:

"...many enterprises are behind in security protection efforts such as anti-virus updates due to shrinking IT budgets, which results in unpatched vulnerabilities that are easily exploited"

Seems like anti-virus and unpatched systems are the main culprit - long live infrastructure protection!

"...the incident illustrates the risks of cloud computing."
A broad general statement - not clear what the implication is :)

The point:
My point is that the industry is so wrapped around protecting the infrastructure - i.e. protecting dat aby proxy, that they forget what it is they are really trying to protect. With an information-centric security solution, the credit card data would be protected persistently. Even if the data were to be "..transferred over to servers outside the company..", it would still remain encrypted thus making it much harder for criminal organizations to obtain any value from the data.

The last and best line of defense is the data - this is how layered security should be.

Friday, July 24, 2009

Where does a £3M fine hurt?

Not sure, but we will know. Regulatory bodies are becoming increasingly tough on lax organizations for not protecting sensitive data - HSBC was recently fined £3M for not adequately protecting customer records.

The interesting part to notice is the fine was applied even though no customer had an unfortunate incident after the breach - I presume like a lost identity, stolen money from their bank etc.

And even more interesting was that HSBC got a 30% discount for cooperating :). Good boy!

Thursday, July 23, 2009

It's the Vision Thing, Stupid!

Let's face it: "It's the software, stupid!" gets almost a million hits
on Google.

And I don't want to belittle software. Software is important.
Software is what processes your data, and unfortunately, software
is horribly badly designed and rushed to marked long before it is
ready. Your data is at risk? Blame software. It's easy, and you
can be 99% sure you are right. Those are pretty good odds.

But think about where you were when "ILOVEYOU" hit. When
I wrote "JustBeFriends", we assumed that Microsoft would blame
the victim, as they had every previous time. Instead, Microsoft
changed direction and started caring about security. Bad news for
me, good news for Microsoft.

This is a blog post. It will not answer all your questions. But it
will make the following points:

(1) virtualization is important,
(2) your data is what matters,
(3) the world is changing,
(4) there are no time machines or magic wands.

We now return you to your regularly scheduled blog.

-Tim

Wednesday, July 22, 2009

Virtualization security - presentation at the OpenGroup Security Conference

Just presented on virtualization security and some of my thoughts on how an information-centric security approach will be absolutely essential - this is at the OpenGroup Security Conference in Toronto. I am putting up the slides I presented in this post.

This is my first attempt at sharing slides via Slideshare - lets see how it works:

The new Missouri breach law

Looks like we have state number 45 - Missouri passed a new breach law recently and will be applicable by the end of August. Nothing earth shattering in the new law - follows pretty much the standard ones.

the interesting part is they decided not to go the Nevada and Massachusetts way and look at prescribing a solution - i.e. encryption. Does this mean there is less perceived value in what MA law is? Or are legislators are unwilling to go the extra step to enforce protection for fear of pushback?

Monday, July 20, 2009

The UCSD and Kaiser breaches

Have not talked much about any specific breach in a while, but this one caught my eye. Apparently the hotline for a hospital that had a breach was swamped with folks trying to understand what happened and whether they were at risk. UCSD had a breach of about 30,000 records, when an external attacker was able to pry through the defenses.

I was beginning to get concerned that folks were not in the least (concerned that is)! Apparently they still do care when their personal information gets out there - but, as is the case all the time, it has to get personal. In fact they were concerned enough to swamp the hospital with calls!

Which brings me to the benefits of small amounts of money, spent judiciously on the right security programs. Even if the cost of losing 30K records was a minimal of $30 bucks per record (including the costs of notification, credit monitoring, legal fees etc), its still nearly a whopping million dollars! A lot of moolah to be sure..

Which brings me to the Kaiser breach - the judge saw it prudent to smack the hospital on its wrists with a fine of $187K. Not a large fine in the context of a hospital, but something to say it is serious about preventing lax management of records.