Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, September 17, 2007

Design and Change in Highly Secure Corporate Settings ( a brief reflection )

The question posed was how do you design and develop in highly secure corporate settings, are there standards? what do you do when the corporate environment makes it too difficult to meet these standards?

As consultants we took standard security measures that went one step farther - everyone was required to lock computers (all laptops) upon leaving even briefly for a biobreak, all texts closed, printed matter of any kind was turned face down or placed in locked cabinets or shredded, no forwarding of internal email, text or images to external addresses, and use of Pretty Good Privacy encryption for FTP or transferred files over the Web to 3rd parties

When leaving for the day, all printed materials were removed from tables and desks, and all laptops went with the users. The building itself was cell dead, because it was a Faraday cage basically. As a scrum/agile team we shared a single phone which eliminated all but the most important and direct calls, such as arranging to be picked up from work.

This was not only the norm in the environment but specified in our contracts. Developers were required to perform a urinalysis (commonly called a 'pee test') prior to getting hired - but as it turned out that was not a requirement of the main company. A lead coming in refused on legal/privacy/moral grounds, and was transferred to another subcontracting firm where invasion of privacy was not promoted. Even better than that, the new subcontracting firm was honest, with the transfer came a $5 an hour raise. (He converted to full time almost immediately).


As PM/ team lead I requested everything be removed from all public and private working spaces which worked well. No casual public discussion of design / dev topics outside of our working environment and team members.

In prior orgs (which go unmentioned here) I encountered extreme difficulty explaining why one should use security, what the role of PGP was, and why use it (they had regulations against using any kind of encryption!) I insisted on testing Web security in application design. Finally my request went to an internal review board (Audit committee), and it gained backing for the spend (about a million to fix back end problems), using the following logical statement - "How many years do you want to have your CEO in jail for breaking privacy laws under HIPAA because the UI allows mal-use. " etc.

Some corporations are so far behind the curve on technology it is a struggle to work with them. I found shared terminology (language), and a safe phrase which worked - to a point - in convincing them to change, it was: "As your consultant I would not be doing my job if I neglected to point out X..."



A large part of being successful involved getting others onboard, through explanation and education of what is reasonable security (security audits in test, for Webapps and applications) and what isn't (pee tests for one class of workers), through associated risk assessment.

The first time an employee told me that he was doing a 'pee test' I thought it was some kind of software test for backend stuff I'd never heard of. He had to repeat himself - it was embarrassing. Then several others stepped up to say they had undergone urinalysis too.

No one even wants to say "pee test" much less do it - it just does not seem professional. If the level of what you are doing is highly specialized, you handle other people's lives, such as being a Space Shuttle Pilot, and need security, such as coding landing software for planes, and/or there are some really good reasons, such as you are observed coming to work apparently stoned, etc, ok that makes sense. But for designers and developers working on software projects, for the most part it's a scary and unnecessary invasion of privacy, with a questionable effect on security.

Usually fighting against established business practices that no longer make sense is a waste of time because the wave of change itself seems to swamp the environment eventually flattening all prior concepts of what should be used, done, or what standard processes and procedures are.

The natural quality of change in secure environments should be practical, do-able, applied uniformly for good reasons, not because "we have always done that" or "it's the rule" or "I am just following orders" - but for logical reasons that work to provide the level of security needed, even if it needs to change or be set as a standard in the future. I have found that the topic of change and security is an especially difficult one, which people resist for many reasons.

(photos in this article shot by Linda Lane, 2007)

Tuesday, March 13, 2007

Using Semantics in an Academic & Business Environment to Build Support

(Final Section to "A Case Study...")

Author: Linda M. Lane, (UW Candidate MSIM 2008) March 15, 2007

In "A CASE STUDY OF COLLABORATIVE, ENTERPRISE WIDE, INFORMATION SECURITY C-LEVEL MANAGEMENT AT THE UNIVERSITY OF WASHINGTON" problems statement we concluded that the second most prevalent problem is:

(2) - Risk Calculation at UW
"With the increasing sophistication and complexity of security attacks, developing a solution of the addressed problems should take a high priority in the university risk management plan."

Not only should the university develop a security solution in the university risk management plan, the document should be framed within the academic semantic sensibility to insure greater chances for adoption and success. The semantics of the business language used within the university risk management plan will contribute to its success both inside and outside its environment by appearing to make every attempt for appropriate risk management while conforming to recognized social and academic norms. Evidence shows no relationship between the adoption of security policy and breaches of security. Moreover, even careful planning processes may produce worse strategic plans rather than better ones.

So what value does the risk management plan have? The language used can influence the appearance in order to gain cooperation and acceptance, build support and insure legal compliance. Effective use of language is a solution in itself to ensure success, regardless of the business management techniques actually applied to plan, enforce policies, and compliance.

According to one study there appears to be "no statistically significant relationships between the adoption application of security policies and the incidence or severity of security breaches." [i] The reason for semantically appropriate security policies is for appearances sake both with the university's environment, a "decentralized yet collaborative entity with an energetic, entrepreneurial culture" and outside, when courts seek evidence of best practices any time the university is held liable for security (PII) breaches.

Dessler [ii] writes that Knowing Your Business is an extremely important aspect of planning and further presents evidence that the best laid strategic plans can go astray. "You have to be able to answer the question "what business are we in? before you do any business planning. You need a strategy for your company…" Strategic planning is "in a class of its own…. It's often highly subjective. Tom Peters… reportedly offered $1,000. to the first manager who could demonstrate that he or she had created a successful strategy from a planning process. His point was that a careful planning process many produce worse – not better – strategic plans."

The language used by the Board of Regents description of the University's goals is "…committed to maintaining an environment for objectivity and imaginative inquiry and for the original scholarship and research that ensure the production of new knowledge in the free exchange of diverse facts, theories, and ideas." [iii] The language used in describing the policy and practices the university is recommended to act upon is," to ensure that the UW creates an excellent compliance model built on best practices, while protecting its decentralized, collaborative and entrepreneurial culture." [iv] These are the university's facets of value, and how it views itself. Both statements show insight into the fact they know who they are and what they do.

That terminology is in stark contrast to the best practices language used for "…the management of information security (Barnard & von Solms, 1998), by defining: "the broad boundaries of information security" as well as the responsibilities of information resources users (Hone & Eloff, 2002b, p. 145). More specifically, a good security policy should: "…outline individual responsibilities, define authorized and unauthorized uses of the systems, provide venues for employee reporting of identified or suspected threats to the system, define penalties for violations, and provide a mechanism for updating the policy." (Whitman, 2004, p.52)." (Doherty, Fulford, 2004)

In the first heading of Information security: management's effect on culture and policy , authors Knapp, Marshall, Rainier and Ford, on page 28, state:
•"Top management support is positively associated with a security culture." They follow with explanations that security cultures are built from the leaders,
"Without top management support the creation training and enforcement of the organizations security policies would not occur or would not be taken seriously by the employees."
•"Without executive level support even a robust security comprehensive documented security policy does not guarantee enforcement across the enterprise." [v]
To prevail in creating a security culture within an environment dedicated to the free exchange of ideas, the university leadership must choose it's wording with care to obtain commitment from all the schools and campus leaders.

Even the responsibility of the CISO is to direct, not enforce, security and privacy policies, as stated in the UW CISO job description draft [vi], under the Duties section:
"Direct the development and enforcement of information security and privacy policies in compliance with federal and state regulations and standards."
These university policies must be written in a way to semantically reflect both the values of the university and to appear that it complies with all laws through best practices.

Taking these issues together, it does not appear to matter which business management methods it uses to accomplish these tasks as long as it uses appropriate language to obtain a committed security culture. Due to the culture, the language being used is a key issue for success, because the law requires the appearance of effort in doing security and risk management, and does not specify ways to apply compliance (HIPAA for example), while the university values objectivity, imagination, and a free exchange of ideas which applies to policy as well.

The academic environment only requires that such management fit its social norms, and the institution's goals, and the management style may be outside of its concerns or relevance, while the semantics and language used are relevant for appearance and cooperation.

The business of the academic and educational environment semantics of using "risk management as a service", "distributed management," and "voluntary compliance" sounds like the university. When contrasted and compared with the terminology and phrases used in traditional risk management planning language such as "unauthorized uses," "define penalties for violations," "reporting suspected threats" -- this language does not hit the mark.

To provide one example, "Sense and Sensibility" is a semantically different way of saying "Information and Aesthetics" or "Perception and Guiding Principles" but the semantic meaning differs. Aesthetically Sense and Sensibility is a graceful, elegant, polished way of saying those same things; but it is more poetic, cultured and sophisticated, and self-reflective. In a similar fashion compliance is what the CISO office wants and needs to produce and project - but "compliance" and the related terms "unauthorized uses," "define penalties for violations," "reporting suspected threats" are full of forced implications, inferences of power, and totalitarian references that do not fit with a university's urbane sensibility, raison d'être and social norms.

The business terms the university draws upon to include all the schools and campuses are likely to attract light critical attention if chosen with careful semantic intention, they will fit the academic environment. The university has no choice-- it needs to protect its people, service, reputation and brand. However, it is in the interest of the university to allow risk management to match its academic framework semantically.

An example of their semantic thinking is demonstrated in mentioning "disciplinary actions" the entire phase used is "disciplinary actions and incentives" which keeps in mind the appropriate semantic tone of university writing by including "incentives."

The university's CISO compared himself in his job to a junkyard dog - but that does not fit the semantic model for cooperation at the university. Junkyard dogs are mongrels generally found in junkyards, and not in ivory citadels of academia, with their land grants, traditions, and loyalty. CISOs in academic business environments are more like highly trained, prize winning dogs; never the less like any dog potentially dangerous when threatened. At the UW the image of a husky, their mascot, in drawing references may suit his position semantically better.

Creating culturally sensitive written policy is not just appearance outside the university it is a semantic tool which lends social cohesion inside the university. Using the correct terminology is likely to actually obtain willing, successful compliance in risk management issues because the university knows their business and how to speak in a language that will be heard and understood by managers and employees alike, in their decentralized, collaborative, and entrepreneurial culture. This same language will be understood outside of the university by courts and attorneys to be erudite, cooperative, displaying every attempt to deploy best practices within the school.

________________________________________
Resources Used

[i] Doherty, Neil . (2005) Do Information Security Policies reduce the Incidence of Security Breaches, An Exploratory Analysis. [Electronic Version] , Information Resources Management Journal, 18, 21 .

(Do Information Security Policies reduce the Incidence of Security Breaches, An Exploratory Analysis. Neil F. Doherty and Heather Fulford, Loughborough University UK, Information Resources Management Journal; Oct-Dec 2005; 18, 4; ABI/INFORM Global pg. 21 Copyright Group Idea 2005)

"The findings presented in this paper are somewhat surprising because they show no statistically significant relationships between the adoption application of security policies and the incidence or severity of security breaches."

[ii] Dressler, Gary. (2004). Management, Principles and Practices for tomorrow's leaders. Upper Saddle River, New Jersey: Prentice Hall.

Chapter 5, Strategic Management, Knowing your business, discusses organizational goals and ways to align the organization and culture to achieve them.

[iii] Warren, V. (March-10-2007) Collaborative Enterprise Risk Management, Final Report.

http://www.washington.edu/admin/finmgmt/erm/ermsummary021306b.pdf

(COLLABORATIVE ENTERPRISE RISK MANAGEMENT, Final Report, University of Washington , by V'Ella Warren, Vice President, Financial Management, vwarren@u.washington.edu 206-543-8765, and David C. Hodge, Dean, College of Arts and Sciences, hodge@u.washington.edu 543-5340 , February 13, 2006)

"The University of Washington (UW) is a decentralized yet collaborative entity with an energetic, entrepreneurial culture. The community members are committed to rigor, integrity, innovation, collegiality, inclusiveness and connectedness."

"The UW's excellence is reflected in the institution's reputation, "the bottom line" which links us to the community."

"The objective of this paper is to ensure that the UW creates an excellent compliance model built on best practices, while protecting its decentralized, collaborative and entrepreneurial culture. This paper lays out a conceptual framework for thinking about risk management. The framework is followed by information on models used by other universities, including four case studies. An evaluation of the UW's current situation comes next. Finally, the paper argues that a collaborative, institution-wide model works the best, and proposes recommendations for implementing that approach."

"Clearly, the creation of a culture of compliance needs to be driven by our core values and commitment to doing things the right way, to being the best at all we do. …we need to know that the manner in which we manage regulatory affairs is consistent with the best practices in existence."

"As a core value to serve its purpose "the University is committed to maintaining an environment for objectivity and imaginative inquiry and for the original scholarship and research that ensure the production of new knowledge in the free exchange of diverse facts, theories, and ideas" (Board of Regents 1998)."

[v] Knapp, Kenneth . (2006) Information security: management's effect on culture and policy . Information Management & Computer Security . Retrieved March 10, 2007, from Emerald Group Publishing Limited 0968-5227.

(Information security: management's effect on culture and policy
Kenneth J. Knapp, US Air Force Academy, Colorado Springs, Colorado, USA and
Thomas E. Marshall, R. Kelly Rainer and F. Nelson Ford
Department of Management, College of Business, Auburn University, Auburn Alabama, USA
Information Management & Computer Security
Vol. 14 No 1, 2006, pp. 24-36 @ Emerald Group Publishing Limited 0968-5227)

[vi] Unknown Group Author. (March-10-2007) UW Chief Information Security Officer job description, 2003-2004 .
www.washington.edu/president/tacs/utac/meetings/2003-04/materials/security.officer.description.pdf

Additional Resources

Bailey K. (2007). Personal Interview. University of Washington, Seattle. February 22, 2007

"A CASE STUDY OF COLLABORATIVE, ENTERPRISE WIDE, INFORMATION SECURITY C-LEVEL MANAGEMENT AT THE UNIVERSITY OF WASHINGTON"
Written by "The Documents":
Dany Dahler
Linda Lane
Joel Larson
Michael Paulsmeyer

for more on Semantics see:
http://ocw.mit.edu/OcwWeb/Linguistics-and-Philosophy/24-903Spring-2005/CourseHome/index.htm

Friday, March 02, 2007

Utmost attention will be paid to secure personal privacy

Densely typed in, nearly 2,000 words over four pages, the policy statement of The University of Washington’s Electronic Information Privacy Policy on Personally Identifiable Information lays out in clear terms what PII is at the University and who can provide exceptions to the rules. The document requires familiarity with technical information and communication systems and at least some knowledge of the University -- how it is structured and administered.

The document regulates the ideas behind the University’s goals in relationship to Personally Identifiable Information (PII), to be “in full compliance with all related federal and state statutes and regulations, and demonstrate a rigorous commitment to core values of maximizing trust, integrity, and respect for privacy.” It is a statement of clear commitment which using the methods outlined in this case study can be accomplished through a collaborative, enterprise wide community commitment to the ideal, so that the insurance costs do not escalate beyond the UW’s ability to pay, and to maintain a sense of respect, responsibility, and dedication to humanity.

There can be no doubt that the tone of this document is intended to protect people, enumerating who “they” are in some detail. The document outlines the exceptions for control of information, by detailing which executives may take responsibility for PII.

In contrast to the stated commitment and ideal, the reality is more difficult to practice because “60% to 80% of consumers' PCs are infected with spyware”, as Kirk Bailey, UW’s Chief Information Security Officer told MSIM2008 interviewers, “But much, if not all of any individual’s Personally Identifiable Information (PII) is already available through other online sources. In fact if an organization looses control of someone’s PII, it would be very difficult to prove who the source really was.”

The truth is most if not all PII is already publicly available. This was demonstrated by Kirk Bailey’s study reported in the New York Times and Seattle Post Intelligencer, in which his valid birth certificate was obtained with little difficulty, and leveraged to gain control of bank accounts. By cross referencing a number of sources, such as databases, and search behaviors other information may be inferred.

There are several motivating factors underlying the reasons to protect Personally Identifiable Information, but the primaries are reputation and risk management. Reputation and cost are inextricably linked, because it is the law to remediate each case as applied to individual people.

Organizations and individuals have been successfully sued for millions of dollars in privacy claims. Common practice is to settle out of court in class action and group lawsuits, to avoid further degradation to the organization, reputation, tarnishing of their brand, and disturbing influences on the business in terms of compliance and audits. The expense really never ends; the costs are ongoing in the form of insurance.

The definition and legal application of privacy standards such as HIPAA are being tested in practice, due to recent enactment. Company executives have lost their jobs and organizations their reputations because they could not show they complied with best practices in relationship to securing PII data on systems, or worse yet, intentionally misused their customers PII by selling it to a third party without permission.

Loosing control of PII is expensive to remediate. By statute in Washington State, when a persons PII has been compromised they must be informed. At the University of Washington it is estimated last year it cost $187.00 per personal contact. The University’s reputation, as well as its brand is at stake, due to the lost of PII. And it is no fun for the people who have to make those calls. In order to assume responsibility and restore some faith that the organization’s intentions are good the senior staff speak with truly irate individuals.

At the current time security breaches and PII loss appears inevitable; as the University’s CISO Kirk Bailey takes a four fold method to reduce risk, and obtains insurance against such losses. Enterprise-wide, voluntary, even eager, compliance with regulations and statues is a best practice in terms of lost prevention. This is a major factor in the methods he applies.

Regarding how companies abuse privacy Kirk Bailey detailed in his Hackers PBS interview, he said unscrupulous companies do this with “The placement of "cookies" or the requesting of information when you log onto the site. Forms that are filled out and then that information is rolled up into databases, or tracking your activities on their Web sites to create a profile of what your interests might be, then using those conjectures and that real data and wrapping it within a profile and selling it that information. We know those things take place. I resent those kinds of things. I find that unacceptable. It's not necessary. . . .”

-Kirk Bailey, PBS interview, 2001 http://www.pbs.org/wgbh/pages/frontline/shows/hackers/interviews/bailey.html


Shukovsky, P. “’Good Guys’ show just how easy it is to steal ID” Seattle Post Intelligencer. March 5, 2005 (retrieved from the web March 19, 2005). http://seattlepi.nwsource.com/local/214663_googlehack05.html

Thursday, March 01, 2007

What is Privacy? It's Relative to Your Intention and Motivating Factors

Biological | Privacy
Safety and Security
One point of view may be called the biological view of privacy, it concerns safety, and security, and people generally consider privacy from this personal point of view. Even animals recognize the need for biological privacy. This may be tied to reproduction, as well as physical security.
Earning A Living
A view of medical data may also fit into this category because such information may be personally detrimental to individuals. For example if it is known that a person has a disease they may find it difficult to find or keep a job based on prejudices.

Motivational and Relational | Privacy
Unwanted Sales Attempts
Another is motivation and relational, so for example when companies document privacy statements, they are communicating to customers and staff their policies which protect from unwanted sales attempts, through such things as opt-in or out ‘contact me’ selections when providing their PII. Also from the business point of view, selling collections of PII through as databases then used for sales attempts is another kind of opt-in or out of choice businesses give to customers, and require their employees to respect their customers choices.
Stealing & Identity Theft | Privacy
In this view of PII, information such as credit card numbers are the target that thieves are most interested in. Why this is most important is because it can be reasoned that far more money is made in online transactions through illegitimate means, through evil doers conning the unwary, then by legal ecommerce according to Kirk Bailey.

Wanton Destruction | Information Private or Public
The idea here is to access or destroy information for egoistic reasons, such as fun, the thrill of overcoming security and so forth. Whether or not it is PII may unimportant to these culprits but exposing PII always is to those individuals who suffer the lost of their PII.

______

Although the United States constitution does not call out a “Right to Privacy” it can be inferred in the broadest sense by the people’s Declaration of Independence and their

“unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness”

Furthermore the US Constitution establishes the reasons the government will serve the people to

“establish justice, insure domestic tranquility, provide for the common defense, promote the general welfare, and secure the blessings of liberty to ourselves and our posterity”

Among these “Life, Liberty and the pursuit of Happiness”, “insure domestic tranquility, provide common defense, promote the general welfare, and secure the blessings of liberty” are drawn upon to provide the basis for laws regarding privacy in the United States.

Collaborative, Enterprise Wide, Information Security C-Level Management

“…distributed leadership requires shared values and a sense of community.”
- UW Provost Phyllis Wise

Executive Summary
The state supported University of Washington (UW) is faced with a Herculean set of information age problems to ensure its reputation, which may be viewed as risk management issues, framed within its own mission of providing educational excellence for the state, the region, and the nation. As limited economic resources are used to protect and manage information, paying for information management and security reduces the amount of funds remaining to serve the University’s primary mission, ”the preservation, advancement, and dissemination of knowledge.” (Board of Regents, 1998)

The University’s senior management strategy is that a collaborative, institution-wide model (Strategic Risk Initiative Review Committee, 2006) built on best practices will work best within their framework while reducing costs. Using this method will protect its decentralized, collaborative and entrepreneurial culture, and its information technology, including Personally Identifiable Information, and education information assets, while conforming to state and federal regulations.

Upon the request of UW President Mark Emmert a study was conducted, and, after an in-depth analysis and public comment period (Strategic Risk Initiative Review Committee, 2006), they chose to hire one executive as a C-Level manager, their Chief of Information Security, Kirk Bailey. Although he has no staff, he has the ability to summarily shut down any system. His objective is to advise and inform the three campus and sixteen colleges, and their information manage teams to secure sensitive and other information, and provide a clear direction for information risk management based on his expert knowledge domain, including dynamic social networking (Interview with Kirk Bailey, 2007).

Background
Founded on November 4, 1861, the University of Washington is comprised of three campuses: Seattle, with sixteen schools and colleges ranging from first-year undergraduates through doctoral-level candidates; and the Bothell, and Tacoma campuses, with upper-division undergraduates and graduate students.

As a core value to serve its purpose “the University is committed to maintaining an environment for objectivity and imaginative inquiry and for the original scholarship and research that ensure the production of new knowledge in the free exchange of diverse facts, theories, and ideas.“ (Board of Regents, 1998) In effect this means allowing colleges and schools a great deal of self-governance within the University, because those organizations are the best at understanding what they do.

As a large educational, research, and medical facility the UW acquires, stores, disseminates, and uses vast amounts of data, through its libraries and collections, courses, faculty scholarship, and publications. It advances new knowledge through research, inquiry, and discussion; and disseminates it through classrooms, laboratory, scholarly exchanges, creative practice, international education, and public service. As such the University itself can be considered both a consumer of vast amounts of data, and a source of information.

Some of this information is directly related to individuals – this essentially private data is termed “Personally Identifiable” and has broad implications in its use in credit, grades, tracking and membership, medical, and as related to other types of sensitive research, such as intelligence. Personally Identifiable Information (Executive Officers of the University of Washington, 2001) is regulated by state and federal laws, such as the Health Insurance Portability and Accountability Act (HIPAA) catching up to the ramifications of easily collectable, storable, and frequently transferable information (PII). As a best practice there is also a wealth of compliance issues related to private data housed within a public institution. (Strategic Risk Initiative Review Committee, 2006)

References:
Title: UW Role and Mission Statement
Author: Board of Regents
Publication: http://www.washington.edu/home/mission.html
Date: February 1981; revised February 1998, modified: November 5, 1998

Title: Collaborative Enterprise Risk Management
Author: Strategic Risk Initiative Review Committee, V’Ella Warren, Vice President, Financial Management, David Hodge, Dean, College of Arts and Sciences, co-chairs
Publication: www.washington.edu/admin/finmgmt/erm/ermsummary021306b.pdf
Date: February 13, 2006

Title: Enterprise Risk Management, University of Washington
Author: Strategic Risk Initiative Review Committee, V’Ella Warren, Vice President, Financial Management, David Hodge, Dean, College of Arts and Sciences, co-chairs
Publication: http://www.washington.edu/faculty/facsen/sec_minutes/05-06/sec_021306.pdf.
Date: January 9, 2006

Title: Privacy Policy, University of Washington
Author: Executive Officers of the University of Washington; the President, the Executive Vice President, the Provost, and the University's Privacy Officer, Vice President for Computing and Communications
Publication: http://www.washington.edu/computing/rules/privacypolicy.html
Date: October 6, 2001

Title: Interview with Kirk Bailey
Location: University of Washington, Seattle
Date: February 22, 2007

Thursday, February 15, 2007

You Can't Save the Stupid from Phishing attacks

Like many User Interface professionals I received the recent email notice from VeriSign about their new Secure Socket Layer Certificates which turn green when the site is secure - to make ecommerce and other information transfers through -

"Maximize customer confidence and sales with new VeriSign® EV SSL Certificates

In response to increasing consumer fear of online fraud, VeriSign has introduced *Extended Validation (EV) SSL Certificates*. The new certificates turn the browser address bar green, communicating to consumers that your site is secure."

Taking a quick look around Technorati I found this blog Cyber Top Cops Security http://cybertopcops.blogspot.com/2007/02/green-means-trust-but-does-it-mean.html
Cyber Top Cops Security Logo
an article which quickly pointed out that the average user could care less what color his/her browser turns for all they know it's just supposed to do that.

These Cyber Cops pointed the caring reader to Rachna Dhamija, a Postdoctoral Fellow at the Center for Research on Computation and Society at Harvard University; who besides an enviable career, including electronic commerce privacy and security at CyberCash, has done some interesting studies on scams and why they work on the Internet.

Replacing Rachna Dhamija's educated language with the vernacular, "you can't save the stupid people, because it doesn't really matter who you are, everyone is at risk."

Here's what Dr. Dhamija said -
"We discovered that existing security cues are ineffective, for three reasons:

1. The indicators are ignored (23% of participants in our study did not look at the address bar, status bar, or any SSL indicators).

2. The indicators are misunderstood. For example, one regular Firefox user told me that he thought the yellow background in the address bar was an aesthetic design choice of the website designer (he didn't realize that it was a security signal presented by the browser). Other users thought the SSL lock icon indicated whether a website could set cookies.

3. The security indicators are trivial to spoof. Many users can't distinguish between an actual SSL indicator in the browser frame and a spoofed image of that indicator that appears in the content of a webpage. For example, if you display a popup window with no address bar, and then add an image of an address bar at the top with the correct URL and SSL indicators and an image of the status bar at the bottom with all the right indicators, most users will think it is legitimate. This attack fooled more than 80% of participants.

We also found that popup warnings are ineffective. When presented with a browser warning of a self-signed certificate, 15 out of 22 participants proceeded to click OK (to accept the certificate) without reading the warning. Finally, participants were vulnerable across the board -- in our study, neither education, age, sex, previous experience, nor hours of computer use showed a statistically significant correlation with vulnerability to phishing."
See Fishing with Rachna
sounds friendly enough, na?
Dr. Rachna Dhamija
So, I believe, and catch me if I am wrong, that unless the Internet security industry comes up with better methods to prevent users from giving away their economic lives by mistake, eventually micro-public-Internets will spring up promising to provide enhanced security just like gated communities.

I know it's scary kids, but it is actually possible that AOL has a future in fear and security, if they can guarantee online safety for their stakeholder customers. It is possible that being an AOL member will mean you are richer and have more at stake than others, and we will have to forgive W because "The Internets" aren't so stupid after all.

Wednesday, July 06, 2005

Fuzzy Logic Set Theory

Thinking about set theory, "Always, never, nearly, sometimes in and out" not that it has to make anything but fuzzy logic sense, but it has applications when thinking about security, and came up with the following:

Number Set Status Name Condition Status
1 Always In Always Out AIAO Considered, logic conflict
2 Always In Last In AILI Set
3 Always In Never Out AINO Set member
4 Always Out First out AOFO Considered rejected
19 Always Out Last Out AOLO Considered, logic conflict
5 First In Always In FIAI Set member
6 First In Always Out FIAO Considered, logic conflict
7 First in First out FIFO stack
8 First in Last out FILO stack
9 First in Never out FINO Set member
10 First Out Never In FONI Considered, rejected
11 Last In Always Out LIAO Closed, logic conflict
12 Last In First Out LIFO stack
13 Last In Last Out LILO stack
14 Last In Never Out LINO Set member
15 Last Out Always In LOAI Considered, logic conflict
16 Last Out Always Out LOAO Rejected, Closed Set
17 Never In First Out NIFO Considered, rejected
18 Never In Never Out NINO Unconsidered, unqualified

AIAO
AILI
AINO
AOFO
AOLO
FIAI
FIAO
FIFO
FILO
FINO
FONI
LIAO
LIFO
LILO
LINO
LOAI
LOAO
NIFO
NINO