… the corrupt DEA agent in Luc Besson’s great movie “Léon (The Professional)”.
I’m sure quite some of you, dear readers, know the plot…
Just before the final shootout, when sending the first men of the NYPD ESU team
into Léon’s apartment, he tells them to “Be careful!”. After learning those men
got killed he just comments: “I told you”.
[btw: before yelling to bring “EEEEEEEVERYONE!!!!”, as those familiar with the
piece will certainly remember ;-)].
Misc
Appstore security: 5 lines of defence against malware
A few days ago the European Network and Information Security Agency (ENISA) published this quite interesting document with the exact title. Here’s what it covers:
“The booming smartphone industry has a special way of delivering software to end-users: appstores. Popular appstores have hundreds of thousands of apps for anything from online banking to mosquito repellent, and the most popular stores (Apple Appstore, Google Android market) claim billions of app downloads. But appstores have not escaped the attention of cyber attackers. Over the course of 2011 numerous malicious apps were found, across a variety of smartphone models. Using malicious apps, attackers can easily tap into the vast amount of private data processed on smartphones such as confidential business emails, location data, phone calls, SMS messages and so on. Starting from a threat model for appstores, this paper identifies five lines of defence that must be in place to address malware in appstores: app review, reputation, kill-switches, device security and jails.”
Continue reading Continue readingRoss Anderson on Responsible Disclosure and Academic Freedom
Hi,
just a short, somewhat non-technical, post today: I really like this response Ross Anderson gave to the “UK Cards Association” asking Cambridge University for taking offline a thesis of one of their students. It (the letter) pretty much summarizes how security research should be treated and backed by those interested in a more secure world we live in.
On a personal note I’d like to add that Ross’ main volume “Security Engineering: A Guide to Building Dependable Distributed Systems”, initially published in 2001 and updated in the interim with a second edition in 2008, has been the most influential security book for me on my long way in the infosec space (which started back in 1997, with some workshops on firewalls I gave for IT auditors). If I could take only one infosec book to a lonely island, it would be this one.
Continue reading Continue readingCloud needn’t be daunting | Guide to legal aspects for non-legals
The British Standards Institution recently published “Cloud Computing. A Practical Introduction to the Legal Issues”. I ordered an electronic copy yesterday (I did that here, for GBP 30) and after a first glance can say there’s lots of valuable information in it.
Merry christmas to everybody, have some peaceful and relaxing days
Enno
Continue readingThe OSSTMM 3 – What I like about it
Given the upcoming public release of ISECOM‘s
Open Source Security Testing Methodology Manual (OSSTMM)
version 3, I took the opportunity to have a closer look at it. While we at ERNW
never adopted the OSSTMM for our own way of performing security assessments
(mostly due to the fact that performing assessments is our main business since
2001 and our approach has been developed and constantly honed since then so that
we’re simply used to doing it “our way”) I’ve followed parts of ISECOM’s work
quite closely as some of the brightest minds in the security space are
contributing to it and they come up with innovative ideas regularly.
So I was eager to get an early copy of it to spend some weekend time going
through it (where I live we have about 40 cm of snow currently so there’s
“plenty of occasions for a cosy reading session” ;-))
One can read the OSSTMM (at least) two ways: as a manual for performing security
testing or as a “whole philosophy of approaching [information] security”. I
did the latter and will comment on it in a two-part post, covering the things I
liked first and taking a more critical perspective on some portions in the
second. Here we go with the first, in an unordered manner:
Trust & Control in the Age of Virtualization and the Cloud
Two days ago I gave the keynote at an industry event, reflecting on the changing role of traditional security controls in the age of virtualization and the cloud. As this was an updated version of the stuff distributed in the conference proceedings, some people have asked for it. Voilà, here we go.
have a good one,
Enno
Continue readingERNW to contribute to government sponsored research project on telco security
Today we dare to (mis-) use the blog for a shameless self promotion 😉
We’re happy to announce that ERNW will contribute to a government sponsored
research project called ASMONIA (which stands for the
German title of the project that is Angriffsanalyse und Schutzkonzepte für
MObilfunkbasierte Netzinfrastrukturen unterstützt durch kooperativen
InformationsAustausch [Attack analysis and Security concepts for MObile
Network infrastructures, supported by collaborative Information exchAnge].
those readers familiar with that kind of projects will have an idea of the
importance of such acronyms ;-).
Intel’s <i>Known Good</i> Approach — Chances for a Paradigm Shift?
During the keynote of the Intel Developer Forum, Intel’s CEO Paul Otellini explained their motivation for the acquisition of McAfee. Basically, Intel wants to provide a possibility to shift computer security from a known bad model to something that is a known good model.
Coming back to some of our recent blog posts, we think that a reliable and working approach to implement application whitelisting would increase security in corporate environments — especially when thinking of the latest vulnerabilities with exploit code in the wild that could not be catched up by any AV solution. As covered by this article, the possibility that such an approach succeeds depends heavily on the critical mass that would use it. The widespread x86 architecture therefore is the perfect plattform for accomplishing a widely used known good model. Presuming the possibility for flexibel and secure operation, Intel’s efforts could be the chance to shift the paradigm of corporate security from a reactive to a preventive model.
Continue readingThat “new worm”…
Recently I noticed
this news
titled “New email worm on the move”. At roughly the same time I received an
email from a senior security responsible from a large customer asking for
mitigation advice as they got “hit pretty hard” (by this exact piece of
malware).
Given I’m mainly an infrastructure and architecture guy usually I’m not too
involved in malware protection stuff (besides my continuous ranting that – from
an architectural point of view – endpoint based antivirus has a bad security
benefit vs. capex/opex ratio). So I’m by no means an expert in this field. Still
I keep scratching my head when I read the associated announcements (like
this,
this
or
this)
from major “antivirus”, “malware protection” or “endpoint security” vendors – to
save typing, in the remainder of the post I call them SNAKE vendors (where
“SNAKE” stands for “Smart Nimble APT Kombat Execution”… or sth equally ingenious
of the valued reader’s choice… 😉
The Emperor’s New Security Indicators
Interesting research from Stuart Schechter et.al.
here.
They evaluated the effect that the removal or modification of online banking
sites’ security features had on the users’ behavior (as for entering or
withholding their passwords). Maybe for some of you not too surprising it turned
out that the vast majority of users entered their passwords even if obviously
alarming clues were present on the websites.
This, again, shows how important it is to understand how users behave, what
their motives and incentives are and how to build environments that help them
acting securely. This even more applies to corporate space. At times, bringing
an industrial/organizational psychologist in might be a much better investment
than writing yet-another-ignored-piece-of-policy.