Translate

Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Monday, April 15, 2013

Cryptography Brakes Big Data

No, that's not a typo, it's pithy commentary!

So, what do brakes have to do with cryptography and Big Data?  Actually quite a bit.

People forget that, in the litany of technological safety advances that have been added to cars, brakes weren't there from the beginning.  Although horse and steam-powered transportation had used a wooden block that would press against a wooden wheel, internal combustion engines also ushered in the use of rubber tires, for which wooden brakes were useless.  Looking through the history books, it wasn't until Renault invented the first drum brake in 1902 that internal-combustion engine automobiles got a viable braking system.  When brakes were added to cars, they could actually go faster... in the decade before drum brakes were added to automobiles, your speed was regulated by your sense of how long it would take for you to coast to a stop if something stepped in front of you.  Once brakes were added, automobiles could go 10, 15, even 20 miles per hour!  This is a perfect example of a control, that would literally control the speed of the car.

I'd contend that appropriate uses of cryptography, anonymization and tokenization permits confidential and private data to be used in Big Data and Cloud repositories, enabling the business to go faster.  Without the right controls to provide safe use of sensitive information, Big Data and Cloud are both hampered by how much private and confidential data can be analyzed.  By adding controls, we enable the business to maximize the level of value, without increasing the risk.

There you have it - you can now tell the business you want to allow them to go faster, by applying controls in much the same way as their car.

Wednesday, April 03, 2013

Cops reinstated as drug testing using hair follicles tossed out

Just when you thought it couldn't get any stranger:

In short, hair samples rejected as drug test process, 6 cops reinstated.  Among the excuses by cops who had originally been suspended due to positive drug samples:
  • Gosh, I brushed white powder off the seat of my squad car, I thought it was powdered sugar from donuts.
  • Well, my apartment shares an HVAC system with some serious meth smokers
  • Ya know, I regularly put seized drugs in my pocket.  Where I also regularly store cookies.  Then I eat cookies.
Not making those up.  The mind reels at the hubris.

Tuesday, August 19, 2008

Security Social Engineering Hack


My buddy Hugh Thompson (star of HBO's Hacking Democracy) just posted a pretty cool write-up of a social engineering hack. Admittedly, this isn't rocket surgery, but he did tie together several logical leaps, intuition, and knowledge of open sources to achieve the compromise. The devestating nature of this isn't that it's some twisted bit of fiendishly difficult code that creates a compromise (though Hugh does have 1337 ninja gung fu). Nope, the frightening aspect of this was how simply Hugh stripped his friend naked (digitally, of course) through this attack.

I know lots of professionals that either publish gmail/Yahoo/Hotmail accounts, or redirect through their public websites (jon.public@jonpublic.com) that still goes to a webmail account. I'm also reminded of the cluelessness of a prior employer, who didn't want me to tell people where I was employed when I was speaking in public, which is pretty dumb, since a 10-second Google search readily found my resume, and it's on Monster.com. However, in their naive perspective on our wired world, my true identity was undiscoverable. Pfffft. Anyone with a dot.clue knows that Google is the Sauron of the Internet, the all-seeing eye, particularly when coupled with archive.org and the WayBackMachine. 1 2 3 4

Why pick the lock on the front door when the back porch just has a screen door?

Perhaps we should all take a page from GunBroker.com that requires your account to be initiated through an ISP account, and remember that at least your ISP knows where you sit. Er, or, at least where your open WiFi network is parked. ;-)

Painfully obvious lesson time here:
  • Seemingly innocuous data about your life posted to a blog or social site can readily be used against you. Blogging anonymously is a good idea if you simply must mention specifics.
  • Using web-based e-mail carries certain risks that are glossed over by the majority of Internet users in the presence of a compelling usability model.
  • Password reset risks and the use of webmail remains ill-addressed by the banking industry, and flies in the face of the FFIEC guidance for multi-factor authentication.
  • Password reset components should always be treated equivalent to passwords themselves.
  • Even more generally, access to a resource and access to the access to the resource are equivalent, though often not protected equally.
The readily analogy here is keeping your safe deposit box key on your keyring. You know, the same keyring you put in your shoes on the beach?