This week I stayed some days in Zurich, to give a workshop and to meet both
clients and fellow researchers (kudos again to C. for the awesome office tour
@Google). In the course of one of those dinners somehow Troopers was mentioned
and a guy asked: “I’ve heard of the conference. What’s so special about it?”
Funnily enough I didn’t even have to respond myself as a
2011 attendee
coincidentally present at the table jumped in and started praising the event
(“best con ever. great spirit, great talks”). Obviously this gave me a big grin…
but it reminded as well me that some of you might ask themselves the very same
question.
After the basic iCloud discussion in
this post, I would like to
add some more technical information. The following items are just a loose
compilation of facts about the mentioned controls which allow the restriction of
iCloud usage. The basic iCloud usage, consisting of backup, document sync, and
photo stream, can be deactivated using the most recent version of the
iPhone Configuration Utility:
Since there are no default settings for these values, it is necessary to include
the disabled entries in existing configuration profiles.
… the corrupt DEA agent in Luc Besson’s great movie “Léon (The Professional)”.
I’m sure quite some of you, dear readers, know the plot…
Just before the final shootout, when sending the first men of the NYPD ESU team
into Léon’s apartment, he tells them to “Be careful!”. After learning those men
got killed he just comments: “I told you”.
[btw: before yelling to bring “EEEEEEEVERYONE!!!!”, as those familiar with the
piece will certainly remember ;-)].
A few days ago the European Network and Information Security Agency (ENISA)
published
this quite interesting document
with the exact title. Here’s what it covers:
“The booming smartphone industry has a special way of delivering software to
end-users: appstores. Popular appstores have hundreds of thousands of apps for
anything from online banking to mosquito repellent, and the most popular stores
(Apple Appstore, Google Android market) claim billions of app downloads. But
appstores have not escaped the attention of cyber attackers. Over the course of
2011 numerous malicious apps were found, across a variety of smartphone models.
Using malicious apps, attackers can easily tap into the vast amount of private
data processed on smartphones such as confidential business emails, location
data, phone calls, SMS messages and so on. Starting from a threat model for
appstores, this paper identifies five lines of defence that must be in place to
address malware in appstores: app review, reputation, kill-switches, device
security and jails.”
just a short, somewhat non-technical, post today: I really like
this response Ross Anderson
gave to the “UK Cards Association” asking Cambridge University for taking
offline a thesis of one of their students. It (the letter) pretty much
summarizes how security research should be treated and backed by those
interested in a more secure world we live in.
On a personal note I’d like to add that Ross’ main volume “Security Engineering:
A Guide to Building Dependable Distributed Systems”, initially published in 2001
and updated in the interim with a second edition in 2008, has been the most
influential security book for me on my long way in the infosec space (which
started back in 1997, with some workshops on firewalls I gave for IT auditors).
If I could take only one infosec book to a lonely island, it would be this one.
The British Standards Institution recently published “Cloud Computing. A
Practical Introduction to the Legal Issues”. I ordered an electronic copy
yesterday (I did that
here, for
GBP 30) and after a first glance can say there’s lots of valuable information in
it.
Merry christmas to everybody, have some peaceful and relaxing days
Given the upcoming public release of ISECOM‘s
Open Source Security Testing Methodology Manual (OSSTMM)
version 3, I took the opportunity to have a closer look at it. While we at ERNW
never adopted the OSSTMM for our own way of performing security assessments
(mostly due to the fact that performing assessments is our main business since
2001 and our approach has been developed and constantly honed since then so that
we’re simply used to doing it “our way”) I’ve followed parts of ISECOM’s work
quite closely as some of the brightest minds in the security space are
contributing to it and they come up with innovative ideas regularly.
So I was eager to get an early copy of it to spend some weekend time going
through it (where I live we have about 40 cm of snow currently so there’s
“plenty of occasions for a cosy reading session” ;-))
One can read the OSSTMM (at least) two ways: as a manual for performing security
testing or as a “whole philosophy of approaching [information] security”. I
did the latter and will comment on it in a two-part post, covering the things I
liked first and taking a more critical perspective on some portions in the
second. Here we go with the first, in an unordered manner:
Two days ago I gave the keynote at an industry event, reflecting on the changing
role of traditional security controls in the age of virtualization and the
cloud. As this was an updated version of the stuff distributed in the conference
proceedings, some people have asked for it. Voilà,
here we go.
Today we dare to (mis-) use the blog for a shameless self promotion 😉
We’re happy to announce that ERNW will contribute to a government sponsored
research project called ASMONIA (which stands for the
German title of the project that is Angriffsanalyse und Schutzkonzepte für
MObilfunkbasierte Netzinfrastrukturen unterstützt durch kooperativen
InformationsAustausch [Attack analysis and Security concepts for MObile
Network infrastructures, supported by collaborative Information exchAnge].
those readers familiar with that kind of projects will have an idea of the
importance of such acronyms ;-).
During the keynote of the
Intel Developer Forum,
Intel’s CEO Paul Otellini explained their motivation for the acquisition of
McAfee. Basically, Intel wants to provide a possibility to shift computer
security from a known bad model to something that is a known good model.
Coming back to some of our
recentblog posts, we think that a
reliable and working approach to implement application whitelisting would
increase security in corporate environments — especially when thinking of the
latest vulnerabilities with exploit code in the wild that could not be catched
up by any AV solution. As covered by
this article,
the possibility that such an approach succeeds depends heavily on the critical
mass that would use it. The widespread
x86 architecture therefore
is the perfect plattform for accomplishing a widely used known good model.
Presuming the possibility for flexibel and secure operation, Intel’s efforts
could be the chance to shift the paradigm of corporate security from a reactive
to a preventive model.