Showing posts with label information. Show all posts
Showing posts with label information. Show all posts

Thursday, July 5, 2012

How Well Do You Know The Internet?

I am old enough to remember the days when the internet new technology. A 33kbs modem provided speed o' plenty for surfing the new fangled World Wide Web. The internet was touted as an annymous place where people could surf and access information. Stores had yet to launch websites, local governments weren't online, Google wasn't king, and porn sites were few. But after years of using the internet, I have found out some things most people don't know, and I'm going to share ;).

DARPA Invented The Interwebs

That's right. The Defense Advanced Research Projects Agency developed it. The interwebs roots stemmed from a project to build a computer network that could not be taken down by catastrophic events.

Internet Privacy

The internet has never been based on privacy. Quite the opposite. Computers require unique addresses in order to communicate with each other. This makes perfect sense when you consider who developed it (Wouldn't it be nice to know which node suddenly went offine?). ISPs keep records of which customer uses a particular address, even static addresses.

Port Scanning?

Even though port scanning is illegal in this country (and many others), your modem is scanned hundreds of times per day. Who's scanning you? Everyone from hackers to your ISP.

Back Doors

The internet is full of software (useful and otherwise) that allow back door access to your computer. The US government requires them to be built into all software used for communications (like email and chat clients).

Online Information

Whatever you put online, stays online. Why? Backups. Most people know the risks of storing online data, but what you may not know is your information is most likely stored in several different locations (virtual or otherwise) each with their own risk of attack.

Free Speech

No such thing. Every website owner is responsible for the content on their websites and can modify or delete content to suit their needs.

Social Networks

These sites are nothing more than data farms. Wanna know something about someone? Make a friend request or follow them ;).

Spammers

Reporting a spammer to his ISP will result in an ocean of spam.

Public Internet Access

Logging into your accounts on a public access point is dangerous stuff. Freely available software (like Firesheep) can hijack http sessions with a click of the mouse, giving the attacker full access to your account.

Disinformation

There are websites built specifically for this purpose on every subject imaginable. Some of it is used to propel sales, put competitors at a disadvantage, push bad software, or to skew facts.

Wednesday, July 4, 2012

Insecurity Of Information

I don't want this post to be misconstrued as a dump on system administrators. They have a difficult job with many different facets that limit control over their networks. They are charged with keeping information flowing, not slowing it down. The job can be a stressful one. One hiccup with internet service is met with a flood of angry calls and emails. They have to deal with support issues, employee issues, vendor issues, security issues, budget issues, the list goes on. It really is a difficult and thankless job in many ways, But........

IMHO, security boils down to one simple thing: standard (or "best") practices. The industry is based on them, therefore bound to them. Most system admins were taught from the same curriculum, inherit practices from their predecessors, and tend to utilize only what they understand. Very few want or need to be more. Hackers are not bound to any protocol, learn as they go, and aren't burdened with long term data integrity, shareholders, or profits. They are fluid creatures limited only by their imagination and sheer technical ability. In short, there isn't a contest.

For example: If I but three red cars, you could assume with reasonable certainty that my fourth car would be red, too. A lot of protocols that corporations follow are similar in estimation. It's very predictable. Some system admins are happy to place Youtube at a higher priority level than reading logs or checking equipment. A breach can happen anytime, and a network device sending an email isn't going to cut it. It's difficult to stay vigilant when that critical moment will seemingly never arrive. I'm sure there a few admins that take pride in their security knowledge and implement it well, but many don't have a good grasp of attack vectors (both virtual and physical) or how to secure them.

In fact, employee information is the easiest to obtain. It's not very well guarded and is made available for the asking. Try calling a company and asking to speak with a salesman. Mr. John Smith will happily assist you. Visit us on the web at http://mycompany.com, here's my email jsmith@mycompany.com if I can assist you further. That's more than enough to begin planning the stage of attack, and no elaborate trickery was involved. It was all given for the asking (or completely volunteered), and even more can be obtained with a little imagination.

Contrary to popular belief, customer information isn't very high on the security food chain. It's usually stored in a database server accessed by a surprising number of people often from different segments. Salesmen, managers, data entry clerks, IT personnel, customer support, as well as outside contractors have direct, or indirect, access to that information. I often asked myself why they bother using passwords or securing the server room, other than to protect hardware configuration. In comparison, only a select few have access to proprietary or sensitive information pertaining to the company or R and D.

Corporate networks are compromised because they are a wealth of profitable information with plenty of soft targets. These networks are constantly hacked, but reported very little. Every American that has used a debit or credit card can rest assured that their financial information has been in the wrong hands quite possibly more times than you want to know. Can more be done to stop it? Not without rethinking everything we know about networking and doing business.

Controlling Online Information

Most people never give a second thought about their information. They disclose, store, and use it as they need it. This practice can literally lead to ruin. In today's connected world, email addresses are used as user names, recycled passwords, addresses and phone numbers are stored everywhere, and financial information abound. There are some steps you can take to better protect your information and even use disinformation to combat faceless threats.

  • Use multiple email addresses - Never use the email you receive from your ISP for things such as your social networking, downloading software, or signing up for news letters. Use a free account. Sign up for several accounts and use one for everything, one for friends, one for networking, etc.
  • Don't willingly divulge information about yourself - Only people who truly know you should know your true address, email, phone number, friends, and any other information that could be sensitive in the wrong hands. Never string together this type of information in one place.

  • Don't store your financial information on any website - Even though it may be inconvenient, remove this information from your profile after every purchase, especially if you rarely use the account.
  • Use an encrypted removable drive to store sensitive information - Chances are you don't use that information everyday. Why store it on your computer? Unplug it when you don't need it. This will lessen the likelihood of your information getting pilfered by malware, or even the technician that works on it. On the plus side, if your system crashes, you have a secure backup of your information.
  • Use multiple social networking accounts - One for family and close friends that have a legitimate reason to contact you, and one for everyone else. After all, if you meet online, do they really need to know how to contact you?

These are a few simple ways to begin to take control of your information. Feel free to improvise and create new ways of storing your information. A big fat lie never helped the enemy. Rome wasn't built in a day, and any plan to steal your identity isn't either. Identity theft is constructed by research. A string of good information stored in one place makes any attacker's job that much easier.