Showing posts with label online security. Show all posts
Showing posts with label online security. Show all posts

Sunday, March 7, 2010

More of the Initiative...Proactive versus Reactive

As I mentioned in yesterday's post, the Comprehensive National Cybersecurity Initiative was released by the White House late last week. The initiative is meant to be both proactive and reactive in nature.

Proactively, the government would like to have the most up-to-date anti-cyber terrorist actions in place to prevent a malicious group of users from accessing information or shutting down a grid of the internal infrastructure of the U.S. This basic goal is a large scheme project that is going to require a massive overhaul of several systems. Possible: yes! Probable: most likely. Expensive: you can bet on those $45 dollar hammers being part of that bill.

The Reactive aspect of the government is going to incorporate something known as counterintelligence (I know, government/military = counterintelligence, but that's not the point here). Counterintelligence in the cyber world is basically acknowledging a threat as soon as possible along with all of the affects of the threat and then finding a way to neutralize it. We would be "countering" an intelligent attack on the nation, hence counterintelligence. This is being spearheaded by a number of nerds, geeks, crackers, hackers and all around interesting people. As anyone that has worked in a specific area long enough with a keen sense of observation and a solid deductive skills can tell you, you start seeing trends. You see the results before they happen and you do what you can to react to those conditions.

Play any game, sport or puzzle long enough and you learn how the rules work and where they can be bent or broken. The same applies to a single computer, a network of computers or an entire infrastructure. The Internet follows the same rules and the malicious code that affects it tends to do the same. There is always an origination point. There are always a number of workstations that are used to deploy a code. The code tends to stay dormant in the recesses of a registry or folder on a workstation. The switch is activated and bam...a few million PC's start smoking, flashing red lights and spitting out bank account numbers. The Reactive people are meant to sniff this sequence of events out before the smoking, flashing and spitting happen.

My thoughts: might as well cover everything to prevent and stop all attacks. What are your thoughts?

Saturday, March 6, 2010

Too Much...Too Late?

Forewarning: The following topic may become a hot topic on this blog over the next few months.

On Thursday, the White House released a brief overview of the Comprehensive National Cybersecurity Initiative. Translation: this is  what we plan to do to prevent the recent cyber attacks against Google, Intel and multiple other major corporations.

The initiative is meant to be a protection plan for government agencies as well as the general population. Education may be the crucial point in the initiative. The amount of security that is and will be implemented behind the scenes will be near that "unfathomable" level, but the issue is that there is always a flaw.  What the flaw is has yet to be determined.

The initiative seems comprehensive because it does call on the population to start taking up an active role in their technological security. Antivirus, anti-malware and anti-spyware should be standard on your computer, regardless of if it's PC, Mac or Linux. Yes, even Mac and Linux users are and will become as frequently targeted as PC users. Market share has been increasing with each of these operating systems which has allowed crackers and hackers to start coding malicious code for all operating systems that are used.

All of that in mind, a self-awareness of what passwords are used across your online sites, where your accounts are in place and what information about you is on the Internet. I have been guilty of this until recently. The same set of passwords used across all sites and networks and that was it. I started testing out programs like KeePass and it's proven to be amazing. That comes highly recommended from me. Have a look and let me know if you have suggestions or questions.

As mentioned previously, I hope to be your source for the education mentioned in the initiative put out by the government. Not because the government says so, but because it's becoming a necessity for everyone quickly.

This was very brief opening to a complex topic so please let me know what you would like to hear about.

Have a great weekend!

Sunday, March 9, 2008

Are Hackers Good or Evil?

As always, news seems to filter in a little more slowly on the weekends when it comes to sites like Digg and Reddit. The majority of the news stories are from the major classic news sites like CNN and MSNBC. It makes sense right? People are enjoying time with their families, working out, watching a sporting event, reading a book, anything. They are simply decompressing from the previous week and re-energizing for the upcoming week that seems to move in too fast!

Well one of the major news site stories yesterday caught my eye. The reason it did so was the due to the way it was written and what it was written about. The story came from CNN.com and it was about a small group of hackers from China (also known as "crackers" for their ability to crack programming languages and code) who were making a bold statement by supposedly infiltrating several very secure mainframes and databases in the U.S., Germany, Britain and France.

Reports keep filing in that the a surprising amount of information has been lost or corrupt since several hits on the Pentagon last year. Now we come find that these hits aren't coming from one single hacker or a massive group of hackers, but rather a couple of young guys sitting in their apartment in China or any number of smaller hacking "units."

But the real question is: IS THIS A BAD THING?

This group of hackers has found "backdoors" and "loopholes" in government and private company firewalls and have been able to access this with little to no formal training. They simply know how a website works, how to do some simple coding for a vast number of program languages and that's it.

This should be the number one indicator for Fortune 500 companies and governments alike; YOUR SECURITY ISN'T GOOD ENOUGH!

So why not use this information and start working with the issue. If these guys can break what you spend millions of dollars on to sleep at night, you better start losing some sleep because they will keep breaking it until you fix. They are handing you opportunities left and right and you better be grabbing them now.

My suggestions:

#1. Take sensitive data offline. The last time I checked, I can't say that I've ever heard of anyone walking about the "TOP SECRET" basement at Langley or the White House with a cart full of files and never returning. (This is similar to the Windows notice this week about not putting a password on your machine to ensure no one hacks you.)

#2. You thought you had the "best" working for you; well you just found out you DON'T! These guys are doing this from their apartment for enjoyment and to make a name for themselves. Why not? I'm pretty if anyone could do it and get away with like they are, everyone would do it! I would!

#3. Take advantage and use common sense. These guys are doing that. They are thinking and behaving like anyone with some basic logical thinking capabilities would do.

I didn't view this article as something to be scared off, but rather as a great warning to the governments of the world, Fortune 500 companies and anyone with a website or blog.

Secure yourself online. Take the appropriate measures to make sure you aren't embarrassed. Be smart. Use common sense. No one is completely anonymous.

Think about it!

Have a great day!