
7:04 PM

Justin
, Posted in
security culture
,
0 Comments
Recently I've been involved in some security awareness training for business users, and in some discussions around the effectiveness of such training, including the question "should we even bother?".
Funnily enough, as I was contemplating this post, I came across PCI Guru's post on the why you should do awareness training which was a response to David Aitel's article on 'Why you shouldn't train employees for security awareness'.
I'm on PCI Guru's side of the fence on this one. Just because awareness training isn't 100% effective (or perhaps even close) is no reason to stop doing it completely. In my view awareness training is one of the ways to get a message across, to present the information contained in all those organizational security policies no one reads and most importantly - communicate to the end users what is expected of them. Will they always do what you ask? Probably not, but there will be those who do internalize the message and alter their behaviour as a result. I can recall genuine surprise on the faces of some employees when I explained that email is not 'private' - scoff if you like, but to the non-IT or non-Security folks out there the fact it's not private may have never occurred to them - same as they don't expect their cell phone calls or SMS messages to be intercepted. The 'revelation' altered end user behaviour as they understood they may have been doing the 'wrong thing' because of their previous belief. Without security awareness training, how would the message have even reached them?
I also think that good security awareness training should also be aimed at the individual, explain how they can address risks to themselves and their family through altering their behaviour and then explain how this can carry on to their behaviours in the office.
I don't disagree that Dave's alternatives to training are also very beneficial to a company, and like so many other areas of security, are part of a defence-in-depth strategy, but one that should include awareness training:
One thing that isn't mentioned is the use of security awareness training to alter the end users opinion of the information security department. Too often the security team is seen as 'the cops' or a roadblock (and I think some of them like being seen that way) and part of that reason is the threats and risks we are trying to address are unknown to the general audience. Through awareness training we can give end users a glimpse of the world from our point of view and (hopefully) start to find some common ground when it comes to working together to addressing information risks.
I don't believe we can solve our security problems with technology alone, people need to be part of the solution (and more people than just us security propeller-heads). Security awareness training may be far from perfect, but for now, it beats not doing anything to educate your workforce.

7:13 PM

Justin
,
0 Comments
This is probably the most interesting account of an employee sneaking into work after being fired that I've ever heard!
Although it is the exception rather than the rule - so make sure you're removing departed user access and maintaining your physical security controls!
I'm sure Apple now has stricter security....except when it comes to losing prototype iPhones. Speaking of which, isn't it about time for an iPhone 5 to get left in a bar soon?

1:51 PM

Justin
, Posted in
biometrics
,
security
,
0 Comments
A new twist in multi-factor authentication..Bio-Soles!
The concept is based on research that shows each person has unique feet, and ways of walking. Sensors in the bio-soles check the pressure of feet, monitor gait, and use a microcomputer to compare the patterns to a master file for that person. If the patterns match the bio-soles go to sleep. If they don't, a wireless alarm message can go out.
A good thing my company doesn't use these. I twisted my ankle last week and would still be setting off alarms...
Still, interesting concept. Up there with the
Inner Ear Biometrics (pdf
here) or the "
Butt Biometrics".
Interesting, yes. Practical? Hmmm
There is speculation floating around the net that at least one of the recent disclosures of passwords was a SQL Injection attack (my bet would be several), I this find equally as disturbing as the fact that the passwords weren't even hashed. Seriously people SQL Injection? It's 2012...

11:18 AM

Justin
, Posted in
security
,
security culture
,
0 Comments
DNS changer has been big in the news of late. News.com.au even ran a headline featuring a nuclear explosion!
The Australian government has a DNS changer check page -
http://dns-ok.gov.au/ - to help you determine if you are affected. With the impending shutdown of the DNS changer servers, some are estimating 30,000 - 40,000 devices will be affected - really a drop in the ocean of the millions and millions (
billions?) of devices connected to the internet.
I figure some people will find their internet isn't working, shrug their shoulders as they assume it's another 'computer gremlin' and get someone to help fix it. No Cyber-Armageddon of Internet Doomsday.....

7:41 PM

Justin
, Posted in
forensics
,
Legal
,
0 Comments
I've been quiet on the blog since relocating to Japan, and had started a bunch of posts that I never finished. Rather than finish them all, I'm going to start recapping on the stuff I found interesting over the last few months, and then move on to hopefully a more regular schedule.
The
Megaupload fisasco, where the site was shut down for illegal filesharing and owners arrested under US law even though the site was located in Hong Kong and the owners non-US nationals in other countries. All this despite NZ's extradition agreement with the US requires the crime to have been committed in US territory. An interesting article
here on the legality of it all and what it may mean in the future.
It raises all the old questions in regards to 'cyberspace' - who 'owns' the internet? Is it a transmission medium or a place? This case will be one to watch...