ISNow – Insider Threat

The following article was originally published in the BCS Information Security Now Magazine, Winter 2007/2008 issue (Volume 2, Issue 2), which was on the topic of Emerging Threats:

“Last year provided plenty of news stories about lost laptops and CDs containing masses of personal data. Confidential data wasn’t exposed by corporate systems being compromised by outsiders (foreign or otherwise) but by insiders doing dumb things, like sending unencrypted data in unregistered post.

With all the focus on complex and emerging threats it is sometimes too easy to overlook the simple threats that are still with us. Take, for example, the insider threat – not even a malicious employee or contractor, but the naïve, careless or overly helpful ones that disregard the policies designed to protect your business.

With the continuing revelations related to how the HMRC has managed our personal information over the years, and the ongoing review into breaches of data protection, I will try to avoid adding too much to the mass of speculation as to the detail of what went wrong, and take a look at some of the broader issues.

Protection of data?
Recent data losses by the HMRC, including CDs (ironically sent for audit purposes) containing some 25 million records, secured only by a password, provide excellent examples of how not to process and protect personal data. If they were a business, would they still have our custom and revenue?

Recent data losses by the HMRC, including CDs (ironically sent for audit purposes) containing some 25 million records, secured only by a password, provide excellent examples of how not to process and protect personal data. If they were a business, would they still have our custom and revenue?

Unfortunately, these losses only highlight weaknesses in internal controls and the powers and sanctions available to the Information Commissioner’s Office (ICO).

They could be fined or have their ability to process personal information curtailed, but to what gain and who would ultimately pay? Prevention is better than cure.

I welcome the Poynter Review into this fiasco and hopefully the government responds positively and swiftly to its initial recommendations on the urgent measures needed to strengthen data security at the HMRC and any further recommendations given in the full report when it comes out in the spring.

Hopefully the lessons will be learned before the launch of the new database of every child in the country – ContactPoint. This will feature name, address, gender, date of birth and a unique number for every child, as well as information about parents, carers, schools, doctors and other relevant organisations.

One of the benefits (no pun intended) this fiasco may bring is the introduction of stronger legal remedy with respect to data protection breaches and new powers for the Information Commissioners’ Office to an effective right of audit and to be able to conduct spot checks on government data security. We can but hope.

Oh Calamity!
As for the impact – well, the sky isn’t falling; fraudsters can’t suddenly empty your bank account (unless you use personal details for authentication); identity thieves can’t steal your identity (not that they ever truly could); your children are as safe as they were before. Breathe deeply, count to 10, and continue.

That’s not to say that mislaying such personal information isn’t a concern and potentially of value to would-be fraudsters, if they were to get hold of it, as it is likely that much of their legwork would have already been done, with a large volume of fairly accurate information presented in a ready-to-use form.

The information contained on the mislaid HMRC CDs included our children’s names and dates of birth, our addresses, National Insurance numbers and the bank or building society account details used for Child Benefit payment. Not in itself a total disaster, but combined with other data bad things could happen.

Imagine, for one instance, that it wasn’t a fraudster that got hold of this sort of information, but a paedophile.

They could identify children of a particular age and gender in a local area, and know things that could be of use in grooming, such as parents’ names, address and potentially figure out what schools they attend and so on.

I don’t for one moment suspect that this is something that has happened with the CDs lost last year, but the same information is held on the HMRC database and it has already been adequately demonstrated that this has not been effectively controlled, with overly broad outputs and information retained by contractors.

Policy, schmolicy
Simply having policies in place is clearly insufficient. It may be enough to placate a disinterested auditor, but unless the policies sit within an effective framework of governance, compliance, education, authorisation and controls, you will not be able to manage your risk in an acceptable or consistent manner and be exposed.

If the information handled by a government department has an official classification, restricted or confidential, then there are clear rules governing its storage, access, transfer and destruction. The classification, sensitivity, relates to the impact if the information is lost or compromised.

Unfortunately, as far as government is concerned, the impact of the loss of a single record of an ordinary citizen is zero. Multiplied by 25 million it still doesn’t add up to enough to encrypt it or send it by recorded delivery. Clearly this must change if we are to trust HMG with more critical data, such as our biometrics.

What has been amusing to watch is the security vendors popping out of the woodwork espousing how their product would encrypt / authenticate / secure / audit everything and all would be well. Technology doesn’t offer a silver bullet to systemic failures to properly enforce policies, procedures and controls.

Rather, users need a modicum of common sense, to realise that our policies are there for a reason, have an understanding of the implications of their actions and to admit, and learn from, any mistakes. Security education is an absolute must, and should include coverage of any legal obligations, such as data protection.

Your information is out there
In an amusing aside to a talk at a recent BCS Information Security Specialist Group seminar on industrial security, Ken Munro of SecureTest gave a worked example of how much information on an individual can be readily gleaned from freely available online sources. For his example, he chose one Richard Thomas.

Well, the job (Information Commissioner) was easy, and so too was date of birth, place of birth, address, mother’s maiden name, email address, education and career history, work and travel arrangements, where he banks and types of accounts, plus plenty of other background information including details on his family.

Our Information Commissioner is not alone in revealing information about himself online; Alex Allan, the new head of the Joint Intelligence Committee (JIC), reveals his home address, phone numbers, private interests and photos of himself, friends and family – he oversees MI5, MI6 and GCHQ – and he’s not alone.

All our information, to a greater or lesser extent, is available online. It could be in government or business populated information repositories – such as registers (births, marriages, deaths or electoral roll) and directories (telephone or business) – or it is information we have actively provided or put online ourselves.

What have you put online on social or business networking sites, photo galleries, blogs, websites, newsgroups, forums – directly or indirectly? What inferences can be made? This is on top of any private communications or photos that someone could forward or post online. You have only yourself to blame.

As future employers, and even educational establishments, make more use of online information, past comments or indiscretions may come back to haunt you even years hence. Seen in context, name, address, National Insurance number and bank details may seem like small change versus employment problems.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-winter08.pdf

ISNow – Emerging Threats

The following introduction was originally published in the BCS Information Security Now Magazine, Winter 2007/2008 issue (Volume 2, Issue 2), which was on the topic of Emerging Threats:

“I’m sure we all have a perspective on what threats we expect to see come to the fore over the coming year(s). If we listen to the vendors, all manner of dooms await us around each corner and we should buy their latest technology to cure our ills. I too have a few ideas of what might cause us some pain in 2008…

Individuals

  • Not allowing policy, procedure, technology or common sense to get in the way of doing daft things (like exposing customers’ personal information)
  • Not understanding the value of personal information, and putting it online or leaving it lying around – for others to make use of
  • Continuing to click on attachments and links which expose them to increasingly effective malicious software

Virtualisation

  • Moving from a physical to logical architecture will complicate security and resilience if not properly considered and catered for in (re)design
  • Responding to incident will need to recognise that logical system can be collocated on shared hardware, or distributed (even internationally)
  • Legally admissible forensics will be hampered by ephemeral nature of virtual machines, combined with jurisdictional problems if off-shored

Applications

  • Developing becomes more rapid, with less focus on a robust software development lifecycle methodology than get the latest beta online
  • Attackers will increase their focus on finding vulnerabilities in applications, rather than at systems and networks, which are now more security aware
  • Web 2.0, mash-ups and other haphazard application development will make interesting targets for those wishing to expose weak security

May I wish you a happy, safe and secure 2008.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-winter08.pdf

ISNow – Phishing

The following introduction was originally published in the BCS Information Security Now Magazine, Autumn 2007 issue (Volume 2, Issue 1), which was on the topic of Phishing:

“Although not about whiling away a lazy afternoon, and coming home with stories about the ones that got away, phishing is about hooking unwitting victims and reeling them in. With its etymological nod to phreaking, phishing is a criminal enterprise looking to subvert a user’s system, personal or financial details.

In its simplest form, a user would receive an email requiring them to confirm account details for an online service – from an ISP, through banks and now onto ecommerce and auction sites. Through the use of social engineering techniques (lying) the sender would hope to stumble across a gullible and compliant user.

Over time, techniques have developed, with the use of cleverly counterfeited websites masquerading as the official site of bank X, the use of malware to infect the user and install monitoring software, exploiting browser weaknesses (Unicode encoded URIs, Java overlays and actual vulnerabilities) and so on.

Advances in targeting have created a spin-off technique, which is specifically targeted, called spear-phishing. This targeting could be on an individual, organisational or sector basis and can very precise and convincing. Often the information required is available from online sources or compromised systems.

Company websites, online forums and social networking sites can provide a ready-made target list and all the necessary information required to execute a convincing social engineering attack. Posting your name, age, location, interests, company, holidays, family and friends can aid an attacker in targeting you.

Defence needs a sensible level of paranoia (as someone may be out to get you) –

  • challenge everything;
  • don’t respond if you are unsure;
  • repeat.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-autumn07.pdf

ISNow – Information Privacy

The following introduction was originally published in the BCS Information Security Now Magazine, Summer 2007 issue (Volume 1, Issue 4), which was on the topic of Information Privacy:

Watching big brother
The government is your friend. If you are doing nothing wrong, you have nothing to fear. We only want to help keep you safe. Big brother knows best. If only it were that simple.

We have more CCTV cameras per capita than any other country along with automatic number plate recognition for congestion charging and alerting police to infractions.

We are building a massive centralised national ID database that will store more than is necessary for us to prove who we are, and offer little in way of consumer benefits.

Our national DNA database has records on over four million people and growing. Police can indefinitely retain the DNA data of anyone they arrest – even if they are never charged or convicted of an offence.

Not only do we fingerprint suspects and criminals, but schoolchildren, without proper guidelines, parental communications or informed consent. Before long, you will need to be fingerprinted to obtain a UK passport.

Soon there will be a mandatory regime of data retention for telephone calls, text messages, mobile location, internet access, emails and web logs. Retained data can be requested by many organisations, for a variety of reasons.

Combined with interception of communications, RFID passports, facial recognition, suspicious behaviour heuristics, satellite car tracking, personnel vetting and dubious data sharing practices you may wonder where the real benefits are and whether we are in a surveillance society.

Work life
Life at work can be ruled by policies on the use of company resources. Your activity and communications may be recorded, archived and monitored for disciplinary or compliance reasons. You leave any expectations of privacy at the door when you arrive.

Unfortunately, work cannot always be left behind when you finish for the day. Employers may respond (negatively) to something you say in your online diary or are seen doing in a picture on a photo sharing website. Recruiters may also conduct a search on you.

Personal life
It may be personal, but life is becoming less private, with profiling (of searches and purchases), sharing (of financial, insurance and health information), tracking (of journeys, transactions and communications), monitoring (of the rubbish in your bins) and enforcement (of TV licences and road tax) and much more besides.

Things can only get better?
I hope so. Hopefully, the opposing forces of security and privacy will come to a happy equilibrium, without one negating the other. More efforts need to be made on privacy enhancing technologies, breach notification and setting standards (for security, retention period, format, quality and so on) where data is kept and disclosure.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow_summer07.pdf

Sun launches Secure Data Retrieval Server (SDRS)

I was quoted by Sun Microsystems in an press release covering the launches of their Secure Data Retrieval Server (SDRS). I both helped with the initial development of this compliance solution and was an early user, leading to the UK’s first deployment compliant with the full scope of the EU Data Retention Directive (EU DRD) – fixed and mobile telephony, Internet access, e-mail and VoIP (and web-browsing, which is beyond EU DRD), although it was at the time done under the UK Voluntary Code for Data Retention.

The full press release is available online at:

http://www.sun.com/aboutsun/pr/2007-06/sunflash.20070607.1.xml

The Blog of Gareth Niblett