Pages

Sunday, July 29, 2012

Political Happenings

So, I'm not sure if anyone has been following this ridiculous chain of events that has been flooding the news lately, but if you haven't, don't worry, I don't think you are missing much. Apparently it started with the CEO of the restaurant chain Chick-Fil-A being quoted as against gay marriage. There has been a flurry of support and a move to boycot since. The latest round apparently involved their Facebook page being shut down for twelve hours and a resurrection with a plea for support set for August 1. While I don't eat there, and won't be rushing to do so anytime soon, I'm finding it very hard to stay quiet on the issues, which is very out of character for me as I'm not usually for or against either politics or religion.

Let me try to break down the issues here. There are two main issues here, one political, one religious. Then there are the side issues, namely of free marketing and private industry terms of service. First, the political.

The first amendment of the Constitution of the United States grants the right of free speech. The CEO exercised that right by expressing his own opinion on a public matter. Somehow it got tied to the opinion of the company he runs, which is unfortunate, but ultimately happens when people in the public eye are linked to their affiliations. I'm not one to do this, but the CEO rolled with this one, so now it IS fact, where it probably wasn't initially. I'm not a lawyer, but I believe that the Constitution covers the company's rights in this regard as well, so any attempt at suppressing this right could lead to a challenge by the company in a court of law.

The second major issue is religious. Ok, so any formalized religion that names the specific verse in the Bible as the word of their deity and bans homosexual relationships would support the CEO. It follows that anyone against this position would be offended by his words. Both sides are exercising their first amendment rights here, and neither is more justified than the other in terms of a court case since no foul has been committed according to the law. There is separation of church and state here in the US, so the two sides can argue for as long as they have breath to do so, and neither should be disparaged in their right to do so, nor suppressed, forced to be silenced, or in any other way repressed. My view here on the specific issue is irrelevant as I stand on the right of free speech as well as the freedom of religion, thus so far, nothing has been said or done that violates these rights, I have remained silent.

Here's where it gets a bit tricky. The sub-issues have muddied the waters, and I do have an opinion here. Let's start with the free marketing. While I see that the CEO has the right to promote and support the planned show set for this Wednesday, I believe he is using it unduly to line his pockets. I don't even really blame him, I blame the people that are supposedly supporting him. Sure, they have the right to do so, but I just don't see how making this show of support means more than just giving him money, which would happen in the normal course anyway. To me, this has zero moral value, and no significant influence on the topic at all.

As for the fourth issue, Facebook, in it's terms of service, retains the right to perform any action it deems necessary including denial of service to any entity it sees as in violation to the terms it sets forth. While I don't know the specifics of why the page was shut down, nor the reasoning behind its resurrection, I can not find any fault with the action. Facebook, after all, is another private company, any their users are bound to its terms of service. Whether the action violated the first amendment or not is irrelevant because the terms of service prevail here, not the Constitution. Facebook is not a Government run institution, nor public forum, as such, the Constitution has no power to enforce the right of free speech to the users of this private service. Those that don't understand this need to go back to school and start reading all agreements that they sign.

So, bottom line here is that no law has been broken, and the debate has not been settled religiously, privately, or otherwise. Business as usual, and in my opinion, not worthy of so much media attention as has been given.

Thursday, May 31, 2012

Hazards of corporate takeovers in Information Security

The best practice taught by computer security experts everywhere is diversification across your security products.  This is different than the practice of establishing a common baseline and acquiring the same make and model of component equipment for that component function in the environment.  The idea is simple, but the explanation is complex.  Your security architecture is made up of many different components doing different things in order to accomplish a mission function.  In the same way a house is built, a computer system is built.  Many different components to make up the whole.  On the surface, you have a resilient barrier to keep the outside out (IT system: boundary protection, House: stucco, brick, weather-resistant wood, roofing material).  Inside of that, you have a buffer zone to insulate the interior from the impact of extreme penetrating elements (IT system: DMZ, honeypots, externally facing servers, House: wood framing, insulation).  Inside of that, you have another barrier between the buffer zone and the interior (IT system: internal firewalls, authentication servers, House: interior drywall).  At protected points, you have controlled access to the inside (IT system: VPN, privileged functions, House: locking doors and windows).  And at unprotected points, you have holes that can be used to gain access to the inside (IT system: weaknesses expressed as vulnerabilities, House: various vents and weak points such as the garage door).  Just as a house, an IT system should be fitted with security measures to mitigate the possibility that an intruder could gain access to the inside.  An alarm system is analogous to audit monitoring and reporting and IDS devices.  Additional reinforcements like window bars and sticks in the tracks of windows are comparable to IPS devices and two-factor authentication.
So, what is the problem?  It’s with those holes, the weak points.  A house built with the standard equipment used in all the rest of the houses in the neighborhood may experience a common fault, like a particularly weak locking mechanism, that if known, can be used again and again to gain access to any house using that mechanism.  Furthermore, if security devices bought from the same company are used for multiple layers for protection, they may experience a common weakness, making it that much easier for an intruder to penetrate to the warm comfort of the interior.  Business is business, and corporate policy dictates the way that business is conducted.  A corporate takeover may introduce a weaker policy structure than what existed previously, plus you have the possibility of layoffs that may introduce an out of work expert in the technology used that is now disgruntled.   This guy knows all your secrets, knows the back doors, and knows the products.  You’ve just made him mad and unemployed, and in an act of desperation, he could sell what he knows, or even take an active role in a penetration attempt.  At the very least, he is subject to a social engineering attempt that he is now more susceptible to because he is no longer subject to any sanctions that existed when he was employed.
Another aspect to consider is with the components themselves.  A single manufacturer supplying multiple levels of protection devices with a common vulnerability or method in the design poses significant risk to an intruder because the same exploit will work at multiple layers.  Take our house as an example again, it has a door with an added security door as the main entry point, but both doors are fitted with a lock from the same manufacturer.  It is well known that there exists a vulnerability in certain locks that a simple application of a hammer is able to break and allow the door to be opened.  Two swings, and the intruder gains access to the house.  In our IT system, let’s say that both the exterior and interior firewalls are made by the same company and have a back door installed in them from the vendor.  The same hard coded default password is able to open those firewalls and an intruder is in the network within seconds.
 

Friday, May 25, 2012

Web 2.0

Wow, it's been a while since I have been up here.  I do see that I've updated my certificate, or was that automatic?  Hmm...this Web 2.0 stuff (or is it cloud) has me a bit confused sometimes.  I know that I can link accounts, and sometimes it surprises me what that actually accomplishes.  I have actually cut the links between certain sites just because of that reason.  I don't fully trust the links are doing what I think I want them to do.  The Internet is going the way of Microsoft in that it is anticipating things for you.  Not necessarily a good thing.  Granted, it can be useful, but think about what that may mean for some of you.  No more secrets in your life, everything is out there for millions to see just by clicking through a few links or typing a few key words in a search engine.  I had actually LOST this blog, didn't remember which engine I used, so I went to Google and typed in Phaldor blog, and found it on the second link.  Talk about big brother...

Thursday, January 6, 2011

Attack last night

There I was, happily playing World of Warcraft and looking up a quest line in thottbot.com when up pops Norton and tells me it just blocked an intrusion attempt.  Naturally, I want to investigate, so I left my toon hovering off the deck of the ship on his bronze drake and went to work looking into the situation.  The first piece of information is the nature of the attack along with an IP and the details.  Here is the excerpt:

Severity:  High
Activity:  An intrusion attempt by 91.204.48.50 was blocked.  Application path \DEVICE\HARDDISKVOLUME3\USERS\[myusername]\APPDATA\LOCAL\GOOGLE\CHROME\APPLICATION\CHROME.EXE
Status:  Blocked
Date & Time: 1/5/2011 8:52:24 PM

Looking up the IP on ip-lookup.net reveals that it belongs to somewhere in the Ukraine.  It's output is below:


# Query terms are ambiguous.  The query is assumed to be:
#     "n 91.204.48.50"
#
# Use "?" to get help.
#
 
#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=91.204.48.50?showDetails=true&showARIN=false
#
 
NetRange:       91.0.0.0 - 91.255.255.255
CIDR:           91.0.0.0/8
OriginAS:       
NetName:        91-RIPE
NetHandle:      NET-91-0-0-0-1
Parent:         
NetType:        Allocated to RIPE NCC
NameServer:     TINNIE.ARIN.NET
NameServer:     NS-PRI.RIPE.NET
NameServer:     SUNIC.SUNET.SE
NameServer:     SEC3.APNIC.NET
NameServer:     NS2.LACNIC.NET
NameServer:     SEC1.APNIC.NET
Comment:        These addresses have been further assigned to users in
Comment:        the RIPE NCC region. Contact information can be found in
Comment:        the RIPE database at http://www.ripe.net/whois
RegDate:        2005-06-30
Updated:        2009-05-18
Ref:            http://whois.arin.net/rest/net/NET-91-0-0-0-1
 
OrgName:        RIPE Network Coordination Centre
OrgId:          RIPE
Address:        P.O. Box 10096
City:           Amsterdam
StateProv:      
PostalCode:     1001EB
Country:        NL
RegDate:        
Updated:        2004-12-13
Ref:            http://whois.arin.net/rest/org/RIPE
 
ReferralServer: whois://whois.ripe.net:43
 
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html

The referal (www.ripe.net/whois) database reveals the following:


 Information related to '91.204.40.0 - 91.204.51.255'

inetnum:         91.204.40.0 - 91.204.51.255
netname:         S-Point
descr:           S.Point
country:         UA
org:             ORG-SA613-RIPE
admin-c:         BD1979-RIPE
tech-c:          BB3347-RIPE
status:          ASSIGNED PI
mnt-by:          RIPE-NCC-HM-PI-MNT
mnt-lower:       RIPE-NCC-HM-PI-MNT
mnt-by:          S-Point-MNT
mnt-routes:      S-Point-MNT
mnt-domains:     S-Point-MNT
source:          RIPE # Filtered
organisation:    ORG-SA613-RIPE
org-name:        S.Point
org-type:        OTHER
address:         Ukraine, Kyiv, 02140, Grishka st. 3-A
e-mail:          belov.dmitriy@point-host.net
mnt-ref:         S-Point-MNT
admin-c:         BD1979-RIPE
tech-c:          BB3347-RIPE
mnt-by:          S-Point-MNT
source:          RIPE # Filtered
person:          Belov Dmitriy
address:         02140, Grishka st. 3-A
phone:           +380975935244
nic-hdl:         BD1979-RIPE
source:          RIPE # Filtered
person:          Barkov Boris
address:         Ukraine, Kyiv, 02140, Grishka st. 3-A
phone:           +380936456384
nic-hdl:         BB3347-RIPE
source:          RIPE # Filtered
% Information related to '91.204.48.0/22AS24965'
route:           91.204.48.0/22
descr:           S.Point
origin:          AS24965
mnt-by:          S-Point-MNT
source:          RIPE # Filtered
Well, I happen to have done some spot research a while ago regarding the installation directory of Google's Chrome browser and didn't get good vibes about the install location then.  See, when a program installs itself, it's supposed to be a good neighbor and install to the applications folder on the OS that it's running on.  Google has deemed this unnecessary for some reason and decided to make it nearly impossible for Chrome to be installed anywhere but the USER folder.  This is not only rude, but very bad security practice.  Among other things, this means that only the user that initially installed the application has access to it, but more importantly, the application runs without having the benefit of being in a protected folder and runs with whatever user rights the user happens to have.

I suspect someone has learned of a specific vulnerability related to Chrome and was attempting to exploit it, so I immediately uninstall Chrome and search for a way to put it where it belongs.  I do like the browser because it's faster than any of the others.  It happens that you can install it with a package of Google apps and that will install it properly.  For those interested, here is the link:  http://pack.google.com/intl/en/pack_installer.html  in addition to Chrome, I grabbed the PC Tools Spyware Doctor with AntiVirus, thinking that more protection is warranted at this point until I can figure out why my hardware router didn't kill this.

After I got home today, I looked into the matter further, and lo and behold, up comes my new tool telling me I have tracking cookies.  Well, those I really don't care too much about, especially after looking through the report.  As far as my hardware router goes, it was doing what it was told to do, but I did manage to find a couple of things to modify it in the interests of security.  Unfortunately, one of them disabled my ability to autosave this blog entry....go figure.  After undoing that problem, I found a way to hopefully increase my online gaming speed by adding a QoS port range for World of Warcraft and Ventrilo.  We'll see if that works.  In case you are interested in doing something similar, here are a couple of links to get you started:

http://us.blizzard.com/support/article.xml?locale=en_US&articleId=21015
http://www.ventrilo.com/setup.php
As for your router setup, I'll leave that up to you, as they differ widely.

Tuesday, December 21, 2010

Wordpress vulnerability

So, my sister came into town today and she mentioned that she was having a strange problem on her web site.  After discussing the particulars with her, I made the standard suggestions and since I wasn't in front of a computer at that time, waited until I got home to do some more pertinent research on the topic based on our conversation.  (This is a developing article that is actively being used to house my thoughts and research.)  I found this link:  http://ocaoimh.ie/did-your-wordpress-site-get-hacked/ that seems to be the problem.  I will be looking at the site more closely to see if this is indeed the problem.

Tuesday, December 14, 2010

Linkback: Discussion on Verbophobia

http://verbophobia.blyon.com/wikileaks-whos-really-at-fault/

Repost: Initial Frustrations, a discussion of DoD shortcomings

Background:  I've been in the IT industry for well over 13 years now, and a computer enthusiast since my parents first put a Commodore VIC-20 in my hands as a child.  I avidly watched the industry grow up, mature, and start to diversify.  In my adult life, I continued to learn all I could about computers and their application in life.  Approximately 9 years ago, I got my first "real" IT job.  I had been working in a call center environment for 4 years at that point doing tech support work, but this new job was working for a contractor at a DOE facility.  This proved to be my first taste of what we now call Information Security (IS) or Information Assurance (IA).  I currently work for a DoD organization where my primary job responsibilities are IA.
Over the last 9 years, I became increasingly aware that the IT field was undergoing a split, or had split into two distinct areas, that of administration of computer systems, and securing computer systems.  They were integrated in such a way that it was very difficult to tell the two apart.  About four years ago, a program was implemented where I was working for at the time that led me into the IS field.  While there, I experience how IS should be implemented as far as personnel and policy.
I left that position in 2008 and re-entered the field in 2009 working as an IT Systems administrator for a different government agency.  At this new position, I found that although the regulations and policy were in place, and an implementation strategy was well thought out, that only existed at the root or direct subordinate level.  Below that level, especially for non-centralized sub-organizations, the structure fell apart and was very poorly implemented.
The incumbent in the position I held had been working towards getting the organization up to speed, and I began to assist him in this effort.  One would think that with the regulation in place, and pressure from members internal to the organization, that an effective IA shop would be instituted.  This did not happen.  After the incumbent left, the task fell to me to get this done.  It has now been over two years since this was brought to the attention of all levels of the organization and still, there is not a resolution in sight.
Problem:  The basic problem seems to be that of manpower denying critical billet positions.  That, and procrastination on the part of several parent organizations to dictate how an IA shop should be setup at a remote location.  In addition, there are some specific cases where this policy fails to clarify how an IA shop should be run.
Disclaimer:  In order to maintain some obscurity, I won't name specific organizations or people, but will try to define the problem in sufficient detail so that the community can recognize the problems and hopefully discuss possible solutions.  I ask that anyone posting comments please adhere to these stipulations and do not try to guess at names or organizations involved.
If you are familiar with regulations within the DoD branch specific to IA, you will know that in order to successfully execute a C&A package, you must have, at a minimum, the following roles:
  • DAA – Designated Accrediting Authority
  • SIAO – Senior Information Assurance Official
  • CA – Certifying Authority (or Certifying Agent) (typically the SIAO)
  • PM – Program Manager
  • IAM/IAO – Information Assurance Manager/Information Assurance Officer
  • UR – User Representative
In a typical organization of mid to large size (100+), these roles are very easy to fill, but for a smaller organization, two of these roles become increasingly difficult to fill.  Specifically, the DAA and SIAO/CA roles.  From the US Code down, these must be filled by government civilians or military personnel and both carry heavy responsibility and authority, meaning upper organization management positions.  The DAA is required to be at the GS-15/O-6 level while the SIAO is the single policy maker for the entire IA department.
What I have discovered, and inferred from multiple sources as well as my own experience, is that neither of these individuals would be comfortable signing off on a system that they cannot either virtually or physically see and touch.  This makes perfect sense to me as they are, in essence, assuming the risks and responsibility of any system they approve.
This wouldn't be a problem if a small organization is physically located at or near their parent organizations HQ, but, as is typical for DoD organizations, there are many sub-organizations that are physically separate from their parents.  Most of these sub-organizations are located on military installations where they get their network connectivity from.  While this isn't a problem if they are affiliated in some way to the military base/post/station that they are located at (as they would simply use the DAA/SIAO that services that location), it does pose a problem for MAJCOM organized units.  These units are typically not affiliated with a single branch of military service, therefore, the DAA/SIAO that services that location is not operationally aware of the mission of these outlying units.
In an ideal world, and I acknowledge that DISA is trying to effect this change, the hosting base would simply accept the systems that belong to the MAJCOMs as is, even though they might not be able to fully understand the mission, they can at least see and touch systems attached to their network.  This, at least, I have witnessed, and it seems to work.
There is one type of system though that this cannot work for and it is the hardest system to run through the C&A for.  Standalone Enclave systems are a bear to work with.  Many units ignore these systems, or fail to acknowledge DoD's specific instruction that "All DoD owned systems will be accredited."  The problem is that the only entities that can virtually or physically see and touch these systems exist within the sub-organization itself.  This, by inference, means that all DoD roles must exist within the sub-organization.
Well, I can tell you that simply can't happen for every organization out there.  Some organizations don't even have a GS-15/O-6 to throw a DAA appointment to, much less second position able to take on the SIAO/CA role.  The sticking point is not the DAA, interestingly enough, it is the SIAO/CA role.  This position, given the standalone enclave system, requires a CISSP or equivelent certification per DoD 8570-M. 
I've not found a person in a current position of authority to entertain the idea of obtaining a CISSP certification just to satisfy this requirement.  The most common answer I've gotten is that they are just too busy.  I can understand this stance, as we are talking small shops, and the workload is typically piled on deeper than a larger organization for each person.
So, where does that leave the situation?  A small shop, not co-located with their parent organization with a need to C&A a standalone system is left out in the cold.  DAA's don't want to touch these systems, and the small shop can't requisition the proper billet to get the right IA personnel into the organization to do it in house.

This is my frustration, as I know it needs to be done, but I can't change the minds of the people over my head.