<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: independent]]></title>
    <link>http://securityratty.com/tag/independent</link>
    <description></description>
    <pubDate>Sat, 09 Aug 2008 10:57:40 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[PCI V1.2, a good start but still not enough]]></title>
      <link>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</link>
      <guid>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</guid>
      <description><![CDATA[Blogger: Randall Gamby
Two weeks ago the PCI Security Standards Council released the preliminary details of the PCI Data Security Standard (DSS) V1.2 thats due out in October. While many Analysts and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>Two weeks ago the PCI Security Standards Council released the preliminary details of the <a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">PCI Data Security Standard (DSS) V1.2</a> that’s due out in October.&nbsp; While many Analysts and Reporters have already written on the topic (I’ll be releasing an extensive update on Burton Group’s PCI coverage around the October release date), they really haven’t commented on what’s still not been addressed by the standard for enterprises still working on attaining compliance.</p>

<p>While I applaud the PCI Security Standards Council in further clarifying and adjusting the standard, a lot of work still needs to be done.&nbsp; I receive about one or two PCI questions a week from our clients and they seem to revolve around a couple of topics I’ve yet to see addressed:</p>

<ul><li><strong>Guidelines for selecting a Qualified Security Assessor (QSA)</strong> – while there are a large number of QSA organizations listed on the PCI Security Standards Council web site; they can’t really recommend a particular QSA for an individual organization.&nbsp; This leads a lot of organizations to struggle with determining what criteria they should use in selecting a QSA for their certification.</li>

<li><strong>The role of the QSA</strong> – organizations are also still trying to understand the role of a QSA.&nbsp; Should they get a QSA involved in the gap and remediation process in advance of certification?&nbsp; If so, should it be the same QSA that will do their certification (knowing there’s a risk that the QSA will be pre-disposed to only care about certain vulnerabilities)?</li>

<li><strong>Industry-specific best practices</strong> – while each organization may have different infrastructures, in general, most industries try to be consistent with the major functions they perform.&nbsp; So are credit card transactions handled differently between say, a major retailer with 10,000 POS systems and an insurance company that has hundreds of independent agents receiving remittances? Probably, so what are best practices around these industry-specific configurations?</li>

<li><strong>Virtualized environments</strong> – while the PCI Security Standards Council recognizes that some organizations have moved to virtual services for consolidation and management, the DSS really doesn’t provide guidelines for QSAs to evaluate and certify these environments.</li>

<li><strong>Monitoring and audit</strong> – while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?&nbsp; With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.&nbsp; So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>

<li><strong>PCI as part of an overall security model</strong> – what are the best practices around merging PCI security requirements into an enterprise’s overall security model?&nbsp; Should it be maintained separately? Should some components be integrated with similar security mechanisms?&nbsp; Should PCI be at the top of the security model and other configurations be based upon its requirements?&nbsp; There are really no answers coming forth on this topic and the other question is where will they come from? Surely enterprises won’t expect the PCI Security Standards Council to tell them how to run their security services.</li></ul>

<p>I will be providing Burton Group’s perspective on most of these questions in my upcoming report, but rather than relying on third parties to resolve these, I’d hope that the PCI Security Standards Council will be able to continue to provide answers to the questions they can in future updates, and releases, of the PCI DSS.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/382655858" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security assessor">security assessor</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/dss">dss</category>
      <category domain="http://securityratty.com/tag/pci security requirements">pci security requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/qsa">qsa</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/382655858/pci-v12-a-good.html">PCI V1.2, a good start but still not enough</source>
    </item>
    <item>
      <title><![CDATA[Web Services and XML Security Training at OWASP]]></title>
      <link>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</link>
      <guid>http://securityratty.com/article/6d12835067b0b2251fdc4b658b6928cc</guid>
      <description><![CDATA[I am teaching Web Services and XML Security training at OWASP's AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application...]]></description>
      <content:encoded><![CDATA[<p>I am teaching <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">Web Services and XML Security training</a> at OWASP&#39;s AppSec conference in NYC, Sept 22-23. Web services provide the backbone that integrates many things in the enterprise from application servers, databases, ERP, and CRM. &#160;Increasingly we are seeing Web services in more B2C roles with Rest, Federation and other technologies. The class looks at how Web services applications are built, what are common threats and vulnerabilities in Web services, and how to build your Web services application to defend against them.</p><br /><div>I have often said that OWASP conferences are my favorite ones because they are in depth technically and very practical. I always look forward to teaching at OWASP and the speaker lineup for this conference looks excellent.</div><br /><div>Here is a quick list of tools we have used in past classes<br /></div><br /><div><span style="color: #333333; line-height: 19px; "><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Web Services frameworks</strong><br /><a href="http://incubator.apache.org/cxf/" style="text-decoration: underline; color: #003366; ">Apache CXF</a>&#160;- very interesting open source Web services framework with support for JMS, SOAP, and Rest<br />Apache&#160;<a href="http://ws.apache.org/axis/" style="text-decoration: underline; color: #003366; ">Axis</a>&#160;&amp;&#160;<a href="http://ws.apache.org/axis2/" style="text-decoration: underline; color: #003366; ">Axis2</a><br /><a href="http://en.wikipedia.org/wiki/Windows_Communication_Foundation" style="text-decoration: underline; color: #003366; ">.Net</a><br /><a href="https://metro.dev.java.net/" style="text-decoration: underline; color: #003366; ">Metro</a>&#160;- interesting framework from Sun for interop with WCF</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Identity</strong>&#160;<br /><a href="http://www.pingidentity.com/products/pingfederate.cfm" style="text-decoration: underline; color: #003366; ">PingFederate</a>&#160;- leading federation tool, we&#39;ll look at browser based SSO with SAML<br /><a href="http://www.pingidentity.com/products/web-services.cfm" style="text-decoration: underline; color: #003366; ">PingFederate Web Services</a>&#160;- we&#39;ll look at how to implement a STS in Web services<br /><a href="http://www.bandit-project.org/index.php/Welcome_to_Bandit" style="text-decoration: underline; color: #003366; ">Bandit</a>&#160;-&#160;<a href="http://en.wikipedia.org/wiki/Windows_CardSpace" style="text-decoration: underline; color: #003366; ">Cardspace</a>, authorization, and auditing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Security Services</strong><br /><a href="http://www.vordel.com/products/vx_gateway/" style="text-decoration: underline; color: #003366; ">VordelSecure</a>&#160;- XML gateway, comprehensive web services security policy creation and enforcement, deploying decentralized security services<br /><a href="http://ws.apache.org/axis2/modules/rampart/1_0/security-module.html" style="text-decoration: underline; color: #003366; ">Apache Ramparts</a><br /><a href="http://www.modsecurity.org/" style="text-decoration: underline; color: #003366; ">modecurity</a></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Testing</strong><br /><a href="http://www.vordel.com/products/soapbox/" style="text-decoration: underline; color: #003366; ">Soapbox</a>&#160;- web services security testing<br /><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" style="text-decoration: underline; color: #003366; ">WebScarab</a>&#160;- web services fuzzing</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "><strong>Static Analysis</strong><br /><a href="http://www.fortifysoftware.com/products/sca/" style="text-decoration: underline; color: #003366; ">Fortify SC</a>A - how to scan your web services code for security bugs *before* you deploy</p></span><br /><div><span style="color: #333333; line-height: 19px; ">This is just a quick list, new tools are added periodically. If you are using tools of these types in your company you may find it interesting <a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference_Training#T3._Web_Services_and_XML_Security_-_2-Day_Course_-_Sep_22-23.2C_2008">to attend</a>.</span><br /></div><br /><div>Testimontials on past classes<br /><br /><div><span style="font-family: Times; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">&quot;High quality detailed overview of SOA security standards and approaches. Well thought-out and structured presentation.&quot;<br />- Sr. IT Architect, Fortune 10 enterprise<p>&quot;The knowledge and transfer was a great baseline and with the additional resources Gunnar made available, made this one of the best one day classes I&#39;ve taken.&quot;<br />- IT Security Lead, Fortune 10 enterprise</p><p>&quot;This class was a thorough and well-organized trek through the current Web Services Security landscape. Going beyond just describing the standards and the options available in the Web Services Security world, this class discusses real-world use cases and offers implementable solutions, best practices, even vendor choices in several key areas. &#160;This class provided me with actionable tasks that I took back to my project teams the very next day!&quot;<br />-Jesse Aalberg, Sr. Enterprise Application Architect, United Healthcare</p><p>&quot;The class was distinctly focused on Security requirements and the strength and weaknesses of the various solution approaches we could consider. The result of the course was actionable approaches to providing security in our SOA environment.&quot;<br />-Brad Sillman, Director IT Security, Deluxe Corp.</p><p>&quot;Anyone who wants up-to-date information on SOA Security, security standards and best practices should take this class.&quot;<br />-Kevin Beam, Senior Systems Engineer, Union Pacific Railroad</p><p>&quot;Good comprehensive overview of subject, standards, and threats&quot;&#160;<br />- Sr.Security Consultant, Ubizen</p><p>&quot;The class helped me get my head around what &quot;SOA&quot; and WS-Security is really all about&quot;<br />- Mike Zusman, Independent consultant</p><p>&quot;Topics addressed are timely and relevant. Labs are hands-on and help see concepts in action&quot;<br />- Jerry Tan, Systems Analyst, DTCC</p><p>&quot;This class was concise and covered a majority of the problem set my company is looking at and dealing with.&quot;&#160;<br />- Steve Reilley, Technical consultant, Commerce Insurance</p><p>&quot;Excellent two day overview of security topics as related to Web Services.&quot;<br />- Daniel Reznick, Information Security, ADP</p><p>&quot;Issue affecting&#160;<span style="text-decoration: underline;">most</span>&#160;of us today &amp; for those that don&#39;t - will soon. Very necessary education and technology.&quot;<br />Aaron Delashmutt</p><p>&quot;Great class! Effective and relevant teaching in an area without much guidance.&quot;<br />- Mark DiSabato, Senior Information Security Architect, Roche</p><p>&quot;The class cut through jargon to communicate concepts and implementation details.&quot;<br />- Developer, Fortune 100 insurance company</p><p>&quot;Good overview regarding SOA Security. Contains new technology like AMQP and REST&quot;&#160;<br />- Lars Loland, Statoil</p><p>&quot;The course covered what I had to learn about Web services&quot;<br />- Sven Vetsch, Dreamlab Technologies</p><p>&quot;Very good, eye opening especially for websecurity noob.&quot;<br />-Michael Brandon</p><p>&quot;Presenter has very broad and deep technical knowledge on subject. Content: good overview and comparison of SAML and WS-*&quot;<br />- Security consultant, ING</p><p>&quot;Good to learn where our application is vulnerable to attacks and how we can avoid them.&quot;<br />- Application Development Programmer Lead, Fortune 100 Insurance company</p><p>&quot;Entirely thorough overview of technology surrounding the use of web services with a 1 day presentation&quot;<br />- Technical consultant Contextis</p><p>&quot;Gave a good overview of the Web services security environment&quot;<br />- Francesco Degrassi, Emaze Networks</p><p>&quot;A great entry point for securing your web services&quot;<br />- Stig Kluver</p><p>&quot;Lots of good technical information about an emerging area that&#39;s very useful&quot;<br />- Rory McClune, HBOS PLC</p><p>&quot;This class reinforced the importance of software security assurance to me as it lucidly demonstrated why being &#39;behind the firewall&#39; is an outdated concept.&quot;<br />-Senior Support Engineer, Software Security vendor</p><p>&quot;The area of SOA Security is complicated and youg. A course such as this helps bring it into focus.&quot;<br />-Jayme Frye, System Engineer, Union Pacific Railroad</p><p>&quot;Web services security class provided application security concepts valuable for applications audits.&quot;<br />- Mary Ma, IT Auditor, DTCC</p><p>&quot;Very knowledgeable coverage of security requirements for Web services.&quot;<br />- David Libershal, Network Security Engineer, Johns Hopkins University Applied Physics Laboratory</p><p>&quot;WS/XML security is not a &quot;black art&quot;, but you do need to know about it to be able to take it into consideration.&quot;<br />- Applications Specialist, Global 500 manufacturer</p><p>&quot;Good overview of techniques worth considering when planning secure apps&quot;<br />- EAI Specialist, Leading Mobility company</p><p>&quot;Brought concepts in very easily understood terms.&quot;<br />-Glenn Bernard, Systems Engineer</p><p>&quot;Gives ideas about the latest Web services security standards in the industry&quot;<br />- Security Coordinator, Global 500 manufacturer</p><p>&quot;Class cleared up various WS-* standards and gave great concrete examples of how to build a message using each standard. Very good general thoughts on security groups&#39; role in IT.&quot;<br />- Matt Kasselman, UP Systems Engineering</p><p>&quot;I found this very useful as an IT architect in a &quot;security critical environment&quot;.&quot;<br />- Mika Pullinen, IT Architect, Finnish Defense Forces</p><p>&quot;Lots of useful information packed in a small amount of time. Good overall picture.&quot;<br />- Jari Pirhonen, Security Director, Samlink</p><p>&quot;Gunnar is very knowledgeable about security topics and has a great ability to explain complex ideas using simple, appropriate, and amusing language and analogies.&quot;<br />- Scott Redd, Sr. Project Engineer, Union Pacific</p><p>&quot;Excellent instructor who had a good pace to go through the presentation&quot;&#160;<br />- Anna Vaahtokan, Specialist, Nordea</p><p>&quot;Good application security principles.&quot;<br />- Tuomas Kivinen, IT Security Specialist, Nordea</p><p>&quot;I liked the class quite a bit. I took it in a &quot;survey mode&quot; where I wanted to learn about topics at a high level, and this was accomplished. It was good to listen to those in the class that were much more familiar with SAO than I.&quot;<br />- John Glazeski, Senior Systems Engineer</p></span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 28 Aug 2008 04:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/soa security standards">soa security standards</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/soa security">soa security</category>
      <category domain="http://securityratty.com/tag/soa">soa</category>
      <category domain="http://securityratty.com/tag/security critical environment">security critical environment</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/application security principles">application security principles</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/web-services-and-xml-security-training-at-owasp.html">Web Services and XML Security Training at OWASP</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hack shows security hasnt improved in 10 years]]></title>
      <link>http://securityratty.com/article/ee3aa28f50e375a8f21a3a812bc96c25</link>
      <guid>http://securityratty.com/article/ee3aa28f50e375a8f21a3a812bc96c25</guid>
      <description><![CDATA[One of my old L0pht collegues, Peiter Mudge Zatko, is featured in Mass High Tech today in anarticle titled Bay State hackers find security holes in defibrillators, RFID
Hackers getting a free T pass...]]></description>
      <content:encoded><![CDATA[<p>One of my old L0pht collegues, Peiter &#8220;Mudge&#8221; Zatko, is featured in Mass High Tech today in an article titled <a href="http://www.masshightech.com/stories/2008/08/18/weekly15-Bay-State-hackers-find-security-holes-in-defibrillators-RFID.html">Bay State hackers find security holes in defibrillators, RFID.</a></p>
<blockquote><p>Hackers getting a free T pass may be the least of our worries — local hackers-turned-security experts suggest RFID keycards, wireless networks and medical devices implanted in the body are also vulnerable to hacks.</p>
<p>At last week’s Defcon hacker convention in Las Vegas, a team of researchers showed it was possible to get information such as Social Security numbers and medical diagnoses, and change the settings on an implantable defibrillator by impersonating the computer it communicates with wirelessly. By doing so, a hacker could send a fatal shock to a patient’s heart, said <a href="http://www.masshightech.com/search.html?q=William%20Maisel&amp;t=2">William Maisel</a> of the <a href="http://www.masshightech.com/search.html?q=Beth%20Israel%20Deaconess%20Medical%20Center&amp;t=1">Beth Israel Deaconess Medical Center</a>.</p></blockquote>
<p>It is almost like things haven&#8217;t changed since the 90&#8217;s when the L0pht worked to change the mindset of security:</p>
<ol>
<li>Don&#8217;t trust vendor claims around security</li>
<li>Attacks aren&#8217;t &#8220;theoretical&#8221;</li>
<li>Security by obscurity is no security</li>
</ol>
<p>The L0pht worked as an independent security research think tank.  For us it was non-profit side job researching and publishing vulnerabilities in software and hardware.  We did it for our love of technology and published what we found out because purchasers and users of the vulnerable systems deserve to know.</p>
<p>It&#8217;s 10 years later and the situation hasn&#8217;t improved much.  Mudge talks about the vulnerabilities the L0pht found in highway transponder systems that are still in systems being fielded today.  But more important than the vulnerabilities themselves is the nature of how these vulnerabilities are coming to light.  They are being found by hobbyists, students, and IT people working in their spare time.  How can something as important as the security of public fare collection systems and medical equipment not have a standard process for security acceptance testing? </p>
<p>As we become more reliant on digital systems, with some even keeping us alive, it is high time for security testing to move beyond student papers and part time IT work.  Security testing needs to become a formal part of the process of purchasing and fielding digital systems.  Our lives are starting to depend on it.</p>
]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 16:46:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security holes">security holes</category>
      <category domain="http://securityratty.com/tag/security acceptance">security acceptance</category>
      <category domain="http://securityratty.com/tag/security testingneeds">security testingneeds</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/digital systems">digital systems</category>
      <category domain="http://securityratty.com/tag/independent security research">independent security research</category>
      <category domain="http://securityratty.com/tag/highway transponder systems">highway transponder systems</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hack-shows-security-hasnt-improved-in-10-years/">MBTA Hack shows security hasnt improved in 10 years</source>
    </item>
    <item>
      <title><![CDATA[Reputation Damage & Measurement]]></title>
      <link>http://securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</link>
      <guid>http://securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</guid>
      <description><![CDATA[Reputation damage can be one of the most difficult concepts to build measurements around. In fact, it can be difficult to develop the actual metrics for the measurements, as well. Damage to things...]]></description>
      <content:encoded><![CDATA[<p>Reputation damage can be one of the most difficult concepts to build measurements around.  In fact, it can be difficult to develop the actual metrics for the measurements, as well.  Damage to things like &#8220;corporate reputation&#8221; and &#8220;goodwill&#8221; and &#8220;brand equity&#8221; can be difficult to wrap even reasonable dollar estimates around (When I use FAIR, I really only care to use one metric when describing loss magnitudes - the almighty currency).</p>
<p>Complicating factors is the impact (or lack thereof) of incidents on stock price.  Many researchers who identify themselves with the <strong><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787">New School of Information Security</a></strong> (yours truly included) want to immediately look at stock price as a bell-weather metric for incident impact.  I think this stems from our days of slinging FUD, back when we could scream &#8220;Buy a firewall or we&#8217;ll have an incident and you&#8217;ll be on the front page of the paper and the stock price will go down!&#8221;  But these days notable incidents seem to suggest that the impact on stock price for an incident is short lived.  <em><strong>With qualifications, of course.</strong></em></p>
<p>So what would/should we make of this from <a href="http://www.money.co.uk/article/1001229-12-million-wiped-off-helphire-stock-after-malicious-gmail-sent-to-clients.htm">Money.co.uk</a>?</p>
<p style="text-align: center;"><strong>£12million ($24m) Wiped off Helphire Stock after Malicious Email Sent to Clients</strong></p>
<blockquote><p>Car hire firm Helphire have taken Google to court after a malicious email sent from a Gmail account saw their shares plummet £12million in a single day.</p>
<p>The Bath-based business who specialise in providing replacement cars to &#8216;no-fault&#8217; drivers involved in accidents on behalf of car insurance companies, initiated legal proceedings against the search engine giant as part of their attempt to find out who is responsible for sending the defamatory mailing.</p>
<p>Google are now known to have complied with the court order and have controversially supplied details of the email account and ISP used by the meddler.</p>
<p>Written under the psudoname Peter Franks, the 1200 word email is know to have been sent from a gmail account that was opened specifically for this purpose and closed a few minutes after the damage had been done&#8230;</p>
<p>&#8230;The misdemeanour couldn’t have come at a worse time for the struggling firm who have undergone a £45million rights issue and seen a 75% drop in the value of their stock already this year.</p></blockquote>
<p>That last paragraph, for me, explains some of the difficulty in tying reputation damage to stock decreases.  It&#8217;s like when you read the headlines from Bloomberg about why the days stocks (or commodity) prices are up or down.  You know, the &#8220;Oil closes $3 higher on news that a notable South American dictator has a rather unpleasant boil in a very uncomfortable area&#8221; type of headlines.  You really do have to question the causality and correlation.  So in the Helphire case above - is this new drop in stock really because of the email sent?  If so, should we view that $24mil number as an independent data point to describe this sort of attack on reputation, or is the magnitude aggravated due to the long-term trend of stock price?</p>
<p>Even when we have &#8220;Objective Data&#8221; (an in-joke for Adam S.) like this decline in stock price, it is really difficult to provide any sort of precise estimate or measurement - about the future, present or past.  The best we can do is use ranges, distributions, that are reasonable based on evidence and observation.</p>
<p>So it&#8217;s worth filing away this sort of datum for future use - while dutifully acknowledging the qualifiers we might place around it.</p>
<p>So the questions I ask here - what should we make of this new information, and how should we view the $24million drop - they&#8217;re not rhetorical.  I am very interested in your views and welcome your comments!</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:33:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stock">stock</category>
      <category domain="http://securityratty.com/tag/helphire stock">helphire stock</category>
      <category domain="http://securityratty.com/tag/reputation damage">reputation damage</category>
      <category domain="http://securityratty.com/tag/reputation">reputation</category>
      <category domain="http://securityratty.com/tag/stock price">stock price</category>
      <category domain="http://securityratty.com/tag/damage">damage</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email account">email account</category>
      <category domain="http://securityratty.com/tag/malicious email">malicious email</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=387">Reputation Damage &amp; Measurement</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hack - Is it really this easy?]]></title>
      <link>http://securityratty.com/article/f6ec916b224830aa520ce767a8418965</link>
      <guid>http://securityratty.com/article/f6ec916b224830aa520ce767a8418965</guid>
      <description><![CDATA[A lot of the focus of the MBTA vs MIT case has been discussion of the CharlieCards . These are MiFare classic cards which have been known to be broken earlier this year . There is also a paper...]]></description>
      <content:encoded><![CDATA[<p>A lot of the focus of the MBTA vs MIT case has been discussion of the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieCards</a>.  These are MiFare classic cards which have been <a href="http://en.wikipedia.org/wiki/MIFARE#Security">known to be broken earlier this year</a>.  There is also a paper disposable card called the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieTicket</a> that uses a magnetic stripe.  The MIT students presentation states that these are cloneable and forgeable using a $150 magnetic stripe reader/writer.</p>
<p>From the <a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf">Confidential Memo Prepared for the MBTA</a> which was publicly disclosed by the MBTA is court filing:</p>
<p><a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf"><img class="alignnone size-full wp-image-241" title="memo-excerpt" src="http://www.veracode.com/blog/wp-content/uploads/2008/08/memo-excerpt.png" alt="" width="678" height="127" /></a></p>
<p>This seems to break all the rules of integrity of sensitive data storage. How could someone store money on a magnetic stripe in 2008 and not store an identifier that references the account in a central database?</p>
<p>The tickets do have a unique identifier generated when the card is initially purchased so a fraud detection system could be in place or is planned. But this would require tracking the value on the ticket or the usage of the ticket centrally so it isn&#8217;t clear why the value is stored on the card in the first place.</p>
<p>There are so many question about the security of this public system.  Fraud costs the Massachusetts taxpayer money and refitting an insecure, ill-designed system costs the Massachusetts taxpayer money. [Disclosure: I am a Massachusetts taxpayer.]</p>
<p>It should be a requirement that the current system or the (hopefully) upgraded system be tested by an independent organization that specializes in cryptosystems.  If the independent testing uncovers vulnerabilities, they need to be fixed before the system is fielded. Then the system should be retested to verify the fixes.  Once the system is deemed secure by an independent organization, a summary of the test document should be published for public inspection.  It should include the types of testing conducted and the results.</p>
<p>The public trust requires inspection of taxpayer funded projects to make sure they meet acceptible standards and vendors held responsible for deficiencies.  Projects that use computers and software should not get a free pass. It will be interesting to see if the CharlieTicket system is ever held up to public scrutiny.</p>
<p><img src="file:///C:/DOCUME~1/cwysopal/LOCALS~1/Temp/moz-screenshot.jpg" alt="" /></p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:19:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer">massachusetts taxpayer</category>
      <category domain="http://securityratty.com/tag/taxpayer">taxpayer</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/fraud detection system">fraud detection system</category>
      <category domain="http://securityratty.com/tag/system costs">system costs</category>
      <category domain="http://securityratty.com/tag/public system">public system</category>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer money">massachusetts taxpayer money</category>
      <category domain="http://securityratty.com/tag/charlieticket system">charlieticket system</category>
      <category domain="http://securityratty.com/tag/charlieticket">charlieticket</category>
      <source url="http://www.veracode.com/blog/?p=238">MBTA Hack - Is it really this easy?</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hack: Is It Really This Easy?]]></title>
      <link>http://securityratty.com/article/1b9874427cf921ef00de8a56a8a8cab9</link>
      <guid>http://securityratty.com/article/1b9874427cf921ef00de8a56a8a8cab9</guid>
      <description><![CDATA[A lot of the focus of the MBTA vs MIT case has been discussion of the CharlieCards . These are MiFare classic cards which have been known to be broken earlier this year . There is also a paper...]]></description>
      <content:encoded><![CDATA[<p>A lot of the focus of the MBTA vs MIT case has been discussion of the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieCards</a>.  These are MiFare classic cards which have been <a href="http://en.wikipedia.org/wiki/MIFARE#Security">known to be broken earlier this year</a>.  There is also a paper disposable card called the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieTicket</a> that uses a magnetic stripe.  The MIT students presentation states that these are cloneable and forgeable using a $150 magnetic stripe reader/writer.</p>
<p>From the <a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf">Confidential Memo Prepared for the MBTA</a> which was publicly disclosed by the MBTA is court filing:</p>
<p><a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf"><center><img class="alignnone size-full wp-image-241 photoborder" title="memo-excerpt" src="http://www.veracode.com/blog/wp-content/uploads/2008/08/memo-excerpt.png" alt="" width="576" height="108" /></center></a></p>
<p>This seems to break all the rules of integrity of sensitive data storage. How could someone store money on a magnetic stripe in 2008 and not store an identifier that references the account in a central database?</p>
<p>The tickets do have a unique identifier generated when the card is initially purchased so a fraud detection system could be in place or is planned. But this would require tracking the value on the ticket or the usage of the ticket centrally so it isn&#8217;t clear why the value is stored on the card in the first place.</p>
<p>There are so many question about the security of this public system.  Fraud costs the Massachusetts taxpayer money and refitting an insecure, ill-designed system costs the Massachusetts taxpayer money. [Disclosure: I am a Massachusetts taxpayer.]</p>
<p>It should be a requirement that the current system or the (hopefully) upgraded system be tested by an independent organization that specializes in cryptosystems.  If the independent testing uncovers vulnerabilities, they need to be fixed before the system is fielded. Then the system should be retested to verify the fixes.  Once the system is deemed secure by an independent organization, a summary of the test document should be published for public inspection.  It should include the types of testing conducted and the results.</p>
<p>The public trust requires inspection of taxpayer funded projects to make sure they meet acceptible standards and vendors held responsible for deficiencies.  Projects that use computers and software should not get a free pass. It will be interesting to see if the CharlieTicket system is ever held up to public scrutiny.</p>
<p><img src="file:///C:/DOCUME~1/cwysopal/LOCALS~1/Temp/moz-screenshot.jpg" alt="" /></p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:19:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer">massachusetts taxpayer</category>
      <category domain="http://securityratty.com/tag/taxpayer">taxpayer</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/fraud detection system">fraud detection system</category>
      <category domain="http://securityratty.com/tag/system costs">system costs</category>
      <category domain="http://securityratty.com/tag/public system">public system</category>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer money">massachusetts taxpayer money</category>
      <category domain="http://securityratty.com/tag/charlieticket system">charlieticket system</category>
      <category domain="http://securityratty.com/tag/charlieticket">charlieticket</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hack-is-it-really-this-easy/">MBTA Hack: Is It Really This Easy?</source>
    </item>
    <item>
      <title><![CDATA[Fog of the Future: Cloud Computings on the Horizon]]></title>
      <link>http://securityratty.com/article/b0444080036cffd2f313acaf1bcf9b99</link>
      <guid>http://securityratty.com/article/b0444080036cffd2f313acaf1bcf9b99</guid>
      <description><![CDATA[If you trust the media and are looking to the future, you might be thinking a good deal about Cloud Computing according to ComputerWorld, this could be the next big movement
Ive heard the buzzwords...]]></description>
      <content:encoded><![CDATA[<p>If you trust the media and are looking to the future, you might be thinking a good deal about <a rel="nofollow" target="_blank" href="http://blogs.computerworld.com/forecast_calls_for_clouds_are_we_ready">Cloud Computing</a> &#8212; according to ComputerWorld, this could be the next big movement.</p>
<p>I&#8217;ve heard the buzzwords but wasn&#8217;t exactly sure what they meant&#8211;luckily, when there&#8217;s media hype, there are definitions, too. According to <a rel="nofollow" target="_blank" href="http://www.thestandard.com/news/2008/08/04/quicker-path-clouds">this article</a>, cloud computing is exemplified by Software as a Service &#8212; outsourced, hosted platforms and software that perform services for companies. </p>
<p>Another <a rel="nofollow" target="_blank" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9111689">article </a>puts it slightly differently:</p>
<blockquote><p>OK, let us look at what form of computing in being provided via the cloud. In this model, all IT applications and facilities (i.e. compute, storage and network) are provided as a service rather than dedicated infrastructure. This is intended to allow any user, independent of client platform, to access IT services without knowledge or concern of their location or form. Sound familiar &#8212; it&#8217;s a service-oriented architecture (SOA)!</p>
<p>In addition, cloud computing incorporates almost every computing manifestation within the IT world: distributed, grid, utility, on-demand, open-source, Web services, P2P, Web 2.0 and, last but not least, software as a service.</p>
<p>It also accommodates thin, thick and mobile clients and allows integration of corporate, commercial and service provider cloud-accessed resources. As an example, in this model, storage is a service resource that is accessed via the cloud, not a dedicated user resource.</p></blockquote>
<p>Honestly I read that last one first and found the definition a bit dense. It sounds like a summation of everything that makes up our Internet infrastructure already, so how is that different than the Internet itself? Well, cloud computing isn&#8217;t about what service or devices are being supported &#8212; it&#8217;s more about how it&#8217;s being provided&#8211; it is a location-independent style of computing. The first article calls it &#8220;platform as a service.&#8221;</p>
<p>Have you heard better definitions of what cloud computing is and does? Share them in the comments below. Thanks!</p>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 08:56:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service resource">service resource</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/perform services">perform services</category>
      <category domain="http://securityratty.com/tag/web services">web services</category>
      <category domain="http://securityratty.com/tag/internet infrastructure">internet infrastructure</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/365101308/">Fog of the Future: Cloud Computings on the Horizon</source>
    </item>
    <item>
      <title><![CDATA[New J2ME Security Vulnerabilities Affect Nokia S40 Phones]]></title>
      <link>http://securityratty.com/article/fb22e6526eaae2f3dc3f2351c7b6ee41</link>
      <guid>http://securityratty.com/article/fb22e6526eaae2f3dc3f2351c7b6ee41</guid>
      <description><![CDATA[An independent security research firm has announced several new mobile Java(J2ME) security vulnerabilities. Two of the vulnerabilities affect the Java virtual machine(JVM) on mobile phones and the...]]></description>
      <content:encoded><![CDATA[An independent security research firm has announced several new mobile Java(J2ME) security vulnerabilities. Two of the vulnerabilities affect the Java virtual machine(JVM) on mobile phones and the other 14 are specific to Nokia Series 40 phones. Series 40 mobiles are not Symbian smartphones and only run J2ME MIDlets.
The security research company has produced a 170+ [...]]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 11:01:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/phones">phones</category>
      <category domain="http://securityratty.com/tag/j2me">j2me</category>
      <category domain="http://securityratty.com/tag/vulnerabilities affect">vulnerabilities affect</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/mobile phones">mobile phones</category>
      <category domain="http://securityratty.com/tag/j2me midlets">j2me midlets</category>
      <category domain="http://securityratty.com/tag/security research company">security research company</category>
      <category domain="http://securityratty.com/tag/series">series</category>
      <category domain="http://securityratty.com/tag/java virtual machine">java virtual machine</category>
      <source url="http://cyberinsecure.com/new-j2me-security-vulnerabilities-affect-nokia-s40-phones/">New J2ME Security Vulnerabilities Affect Nokia S40 Phones</source>
    </item>
    <item>
      <title><![CDATA[Amber Alerts As Security Theater]]></title>
      <link>http://securityratty.com/article/0d6125e22aa5c6863e853fa8ae428cf9</link>
      <guid>http://securityratty.com/article/0d6125e22aa5c6863e853fa8ae428cf9</guid>
      <description><![CDATA[Interesting analysis : Since its birth 12 years ago after a fatal kidnapping in Texas, Amber Alert has quickly become one of the best-known tools in the national law enforcement arsenal. The warnings...]]></description>
      <content:encoded><![CDATA[<p>Interesting <a href="http://www.boston.com/bostonglobe/ideas/articles/2008/07/20/abducted/">analysis</a>:</p>

<blockquote>Since its birth 12 years ago after a fatal kidnapping in Texas, Amber Alert has quickly become one of the best-known tools in the national law enforcement arsenal. The warnings are familiar to anyone who watches cable TV news, especially during the summer, when the drumbeat of abduction stories seems to increase. Last year, 227 alerts were issued nationwide, each galvanizing interest in the local community and flooding police with tips. While the particulars of the state systems differ, the goal is the same: to disperse news of a kidnapping as widely and quickly as possible, in the hope that someone will spot the kidnapper before a child is harmed.

<p>The program's champions say that its successes have been dramatic. According to the National Center for Missing and Exploited Children, more than 400 children have been saved by Amber Alerts. Of the 17 children Massachusetts has issued alerts on since it created its system in 2003, all have been safely returned.</p>

<p>These are encouraging statistics -- but also deeply misleading, according to some of the only outside scholars to examine the system in depth. In the first independent study of whether Amber Alerts work, a team led by University of Nevada criminologist Timothy Griffin looked at hundreds of abduction cases between 2003 and 2006 and found that Amber Alerts -- for all their urgency and drama -- actually accomplish little. In most cases where they were issued, Griffin found, Amber Alerts played no role in the eventual return of abducted children. Their successes were generally in child custody fights that didn't pose a risk to the child. And in those rare instances where kidnappers did intend to rape or kill the child, Amber Alerts usually failed to save lives.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=rZkbpK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=rZkbpK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=e2lugK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=e2lugK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 03:59:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alerts">alerts</category>
      <category domain="http://securityratty.com/tag/amber alerts">amber alerts</category>
      <category domain="http://securityratty.com/tag/child custody fights">child custody fights</category>
      <category domain="http://securityratty.com/tag/child">child</category>
      <category domain="http://securityratty.com/tag/abduction">abduction</category>
      <category domain="http://securityratty.com/tag/abduction stories">abduction stories</category>
      <category domain="http://securityratty.com/tag/successes">successes</category>
      <category domain="http://securityratty.com/tag/team led">team led</category>
      <category domain="http://securityratty.com/tag/local community">local community</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/amber_alerts_as.html">Amber Alerts As Security Theater</source>
    </item>
    <item>
      <title><![CDATA[Sorry CharlieCard, Your Security Model Is Broken]]></title>
      <link>http://securityratty.com/article/f11af6f7a39f4309ead15fadb8a610f7</link>
      <guid>http://securityratty.com/article/f11af6f7a39f4309ead15fadb8a610f7</guid>
      <description><![CDATA[It sure seems like the CharlieCard , which is used by the Boston subway system, has a serious security weakness. The MBTA has sued 3 MIT students to stop them from giving a planned talk at DEFCON...]]></description>
      <content:encoded><![CDATA[<p>It sure seems like the <a href="http://www.mbta.com/fares_and_passes/charlie/">CharlieCard</a>, which is used by the Boston subway system, has a serious security weakness.  The MBTA has <a href="http://www.theregister.co.uk/2008/08/09/defcon_speakers_sued/">sued 3 MIT students</a> to stop them from giving a planned  talk at DEFCON.</p>
<p>Doesn&#8217;t this seem backwards to you?  Shouldn&#8217;t the MBTA be suing the vendor who sold them the flawed system?  Security problems go away by mandating independant security testing before a product is accepted, not by trying to get security researchers to be quiet.  This is a good example of how the reactive approach doesn&#8217;t work.  The flaws are still in the system and suing researchers has just <a href="http://en.wikipedia.org/wiki/Streisand_effect">shined a bright light</a> on them.</p>
<p><strong>Update 08/09/2008 6:00pm EST:</strong></p>
<p>The <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9112160&amp;intsrc=news_ts_head">EFF is appealing the injunction</a> which is blocking the students from speaking about the results of their testing.</p>
<p>A telling quote from Kurt Opsahl, staff attorney at the EFF gets to the heart of the issue:</p>
<blockquote><p>&#8220;Courts have found that the First Amendment covers these things. We believe that this is a protected speech activity. When you discuss security issues, if you are telling the truth, that is something that should be protected.&#8221;</p></blockquote>
<p>Apparently the MBTA has known about this problem since at least March, 2008 when a graduate student from the University of Virginia announced <a href="http://www.boston.com/business/articles/2008/03/06/t_card_has_security_flaw_says_researcher/">he was able to break the encryption system</a>.</p>
<p>The U of VA researcher gave an interview where he described why security by obscurity is not a valid security approach for a cryptosystem:</p>
<blockquote><p><strong>Q:</strong> What are your thoughts on security by obscurity? Is NXP using this method of protection?</p>
<p><strong>A:</strong> Security-through-obscurity hardly ever works. The lack of proper peer-review often even hurts the security of the system. Our Mifare work discovered several vulnerabilities that could be fixed without increasing the cost of the cards. NXP did for a long time rely on obscurity for the security of some of their products, but now decided against this outdated design approach and instead bases the security of newer RFID cards on publicly scrutinized cryptography and independent evaluations.</p>
<p><strong>Q:</strong> Can you explain &#8220;Kerckhoffs Principle&#8221; and why it applies to your work?</p>
<p><strong>A:</strong> Kerchoff, who lived in the 19th century, observed that keeping anything secret is really hard. So instead of relying on the secrecy of your whole system, it would a lot easier to only rely on the secrecy of a small secret key. Security systems should hence be publicly known and analyzed, and only the key should be secret. When properly realised for RFID cards, Kerchoff&#8217;s principle means that by analyzing their own cards, thieves cannot compromise your cards. This is contrary to our Mifare work, where we only analyzed a few copies of the the secret algorithm that is found in all cards and were consequently able affect the security of all the other billion cards out there.</p></blockquote>
<p>The MBTA not only accepted a security system which relied on security by obscurity but once accepting this flawed model must try to maintain this obscurity with the court system.</p>
<p>The documents detailing the presentation are <a href="http://www.tgdaily.com/content/view/38817/108/">here.</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 Aug 2008 10:57:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/valid security approach">valid security approach</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/encryption system">encryption system</category>
      <category domain="http://securityratty.com/tag/boston subway system">boston subway system</category>
      <category domain="http://securityratty.com/tag/discuss security issues">discuss security issues</category>
      <category domain="http://securityratty.com/tag/court system">court system</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <source url="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">Sorry CharlieCard, Your Security Model Is Broken</source>
    </item>
  </channel>
</rss>
