Sunday, November 28, 2010

Have a 'pat down' this holiday season? Don't be afraid to invoke the "P" word for better security.


As the holiday travel schedule ramps up, so does the fervor and objections over pat downs and invasive screenings at airports in the United States. People recently subjected to these "love pats," as a Senator from Missouri innocuously (and ridiculously) referred to them, are in for quite a shock if they fly anywhere where else in the world except, say, Cincinnati or Des Moines.

 As any frequent international traveler can corroborate, very intense and 'hands on' searches occur in almost every other international airport in the civilized world. Try flying through Frankfurt and not be subjected to a body search that even your family care doctor would find comprehensive. And these are not new procedures; I can remember the same thoroughness in place at Frankfurt, Heathrow and every Indian airport I have flown through for the last 5 years.

Why are Americans so indignant about the new procedures? Since when is flying a constitutional right? This is not healthcare; if you don't like the scrutiny you are subject to, you are welcome to use a car, train bus or boxcar. Inconvenient? Sure. But so is political correctness, it appears.

In this country we are so terrified to offend any person of any race, creed, religion or origin that we will go out of our way to inconvenience an almost total majority to show how fair and even-handed we are to any minority. This approach to security is 180 degrees different than the one the Israeli's take. You won't see any nuns, 80-year old grandmothers or 4-year olds being body searched. What you will see is a laser focus of their resources on the most likely and foreseeable risks to the safety of their citizens and the airlines. As I love to say, every decision you make is a microcosm of risk management.

 In American and European airports, in particular significant volumes of traffic moving through them have required their associated security procedures to rely mainly on technology for screening luggage and detecting passengers with ill intent. Israel’s security philosophy, however, is based on a blend of advanced detection devices and personal interaction with the passengers. Granted, the primary airport in Israel, Ben-Gurion International, handles only about 12% a year of what U.S. airports handle annually, yet here are still some lessons we can learn.

Passengers are questioned from the time they drive up to the airport, until they are ready to board the plane. Usually, each person is questioned two or three times by different security agents, to ensure the story is consistent. Arab or Muslim passengers get extra-thorough screening, as do non-Jewish tourists. The Israeli method does not limit itself to only the profile of the 'typical' terrorist (if they exist anymore), but instead spend time questioning or searching anyone who appears nervous, flustered, inconsistent or just not right.

No airplane has ever been hijacked from Ben Gurion since the Israelis are not shy about deploying the "P" word - profiling. In the U.S. that word is such a hot button since it is typically associated with another taboo word - 'racial.' So when you add 'racial' and 'profiling' together, you have the most volatile term in the American lexicon - racial profiling.

For very good reasons, racial profiling is wrong, and more importantly for security and safety reasons, it is inefficient. Terrorists are not stupid; they have started recruiting other willing accomplishes who are not the once, tried and true terrorist profile: young, middle-eastern, Muslim males. If we continue to focus efforts solely on this cliché of a potential threat, we will always be chasing yesterday's news - with disastrous consequences.

Ironically, since early January of this year, the United States has in fact introduced new requirements based on a travelers’ country of origin or citizenship. Citizen's from 14 countries — including Afghanistan, Nigeria, Pakistan, Saudi Arabia, Yemen and Syria — are now required to undergo an extra search before getting on planes bound for the U.S. America. Profiling? Probably. Racial profiling? Definitely! I would argue that even enunciating and singling out these 14 countries is short-sighted and will ultimately be unproductive. If I was Al Qaeda, I would make sure that all of my next 100 recruits did not have passports from any of these countries. How easy would that be?

So what are your options this travel season? You can subject yourself to the patdowns or get your revealing full body scans (with you assuming the "I surrender" hands position), and "Say nope to the grope." Or, you can start to demand that we drop the inefficient, ineffective and politically correct way of American security screening: treating every traveler as if they were a possible terrorist. And instead, start to incorporate better and more efficient techniques from others who have learned and incorporate the art and techniques of risk management.

Sunday, November 14, 2010

India Gets Into The Identity Race


I have spent the last 10 days in India concluding my 12th visit in 7 years. I have seen quite a noticeable  progress in the rickety infrastructure each and every time I go, as India walks away from the past and races to the future. However, this time I saw progress in a different, less obvious way.

Last month, the Indian government rolled out the first country-wide AADHAAR ('foundation' in Hindi ) to an Indian resident. This will be a unique 12-digit identification number, like a social security number that ultimately all Indians will possess. The government hopes to complete and issue at least 600 million IDs to its 1.2 billion citizens by 2014.

Currently, there exists a limited quasi-social security number in India, however the government is intending to reach out to the rural and less connected masses as part of the program. Formalizing and documenting the 'official' identity of millions of the rural poor will, among other things, help them bypass more expensive money-lenders and tap into the formal banking system. What is unique about this initiative though is the format and approach to the effort, and how it dramatically differs from the similar process in the United States.

In the US, as you know, all babies at birth are issued social security numbers, along with a snappy little bluish-white paper card (that some people still bizarrely carry around with them!?) printed with a unique nine-digit number. As easy as it is to counterfeit or replicate it, some places, believe it or not, still ask for the card as some legitimate proof of identification – think of the DMV as you try to renew your driver's license. No surprise there.

The AADHAAR, however, will be printed on a smartcard or other official document that will include 3 factors of identification unique to the person: an iris scan, a photograph and all ten fingerprints. To get a number, Indians will have to physically go to an enrollment agency and submit their credentials that will ultimately be collected in a central repository.

Orwellian fears and privacy concerns aside, what this will mean to the Indian economy is monumental. Soon, millions of Indians who are otherwise prevented from participating in the growth of the sizable economy will now be plugged into the system and able to leverage money and services that were never available to them before. In turn, millions, maybe billions of rupees in revenue that would have gone to the black market or otherwise unreported (and untaxed) can now be put to better use. Think of the number of new jobs that will be created to both implement and support this system once it is effected.

These new jobs won't all be the classic government-teat-sucking positions that you might think they'd be. Software has to be developed and supported; card readers will have to be created and deployed. All areas of the private sector will be prodded to build new ways to accommodate and authenticate their customers across a number different mediums. The US should take note here as the rest of the world moves to smartcard technology, while we stick with traditional magnetic strip technology and easily forged driver's licenses.

India will face many challenges as it attempts to implement a process like this, as it does with almost everything else that happens in that country. What will be most interesting to watch is how and if it is  ever able to play catch-up and issue every citizen an AADHAAR.  With a target rate of 10 million cards issued every four months, and a population growth of 4 million new people every quarter, it will be a very tough race to win.

Tuesday, October 12, 2010

Privacy & The Risks of Visibility

True story: a woman in New York tried to sue the manufacturer and distributor of an allegedly defective office chair after she fell out of the chair, claiming "serious permanent personal injuries." She alleged, among other things, that she had "pain and progressive deterioration with consequential loss of enjoyment of life."


Lawyers for the chair company were naturally suspicious because a recent photo of the Plaintiff on the internet showed her smiling and standing, without apparent assistance, instead of living the pain-filled existence she was asserting in her lawsuit. (She claimed she was confined largely to her bed and house.) Seems like she also took a recent trip to the Sunshine State, and appeared to be generally enjoying life. So then, where did the lawyers dredge up this seemingly damning evidence? Private investigators? GPS satellite photos? CSI? No. Where else? Facebook.

With good reason, lawyers for the chair company trying to determine if the case had any merit and if the injuries sustained were as severe as the plaintiff made them out to be, had trolled the internet. Finding evidence on Facebook (D’oh!) that the claim may not have as much merit as initially asserted, the chair company pressed a local NY judge to allow the company more access into the woman’s social media sites(!), Facebook and MySpace.

Essentially, the judge - Acting Justice Jeffrey Spinner of Suffolk County Supreme Court - told the plaintiff that she must allow the chair company access to her social media sites since “in light of the fact that the public portions of Plaintiff's social networking sites contain material that is contrary to her claims and deposition testimony, there is a reasonable likelihood that the private portions of her sites may contain further evidence….all of which are material and relevant to the defense of this action." Again, since someone posted something online contrary to their best interests, notwithstanding whatever privacy settings she thought she had on the sites, she now has practically incriminated herself.

Social media has really become the third rail of identity in the last 5 years. We have our professional online identities (and even places to post pictures of us in suits and ties – LinkedIn, Plaxo), our online personal identities (Friendster), and now the two big ones, Facebook and Twitter, that ever increasingly blur the line between personal and professional lives. Look at how sales people create Facebook pages, for example. The really good ones make it hard to differentiate who their friends are and who their customers are. Either way, they make it very convenient for other people to find them with lots of freely disclosed information.

Back in the old days, when you wanted publically available information on someone, you had to take laborious steps such as going to a county courthouse, or some other house of public records and spending the day looking up details in big, dusty official books. Each individual had to be investigated one by one. However, today, the internet, and specifically social media sites have now become the new public record. Instantly someone can search for info about you, not only across most public databases, but across other sites that you have voluntarily input data to be collated and analyzed, usually to your detriment.

Think about how human resource departments typically work. They get a hundred resumes for one job opening. In theory, they are looking for the right person; in reality, they are looking to weed out the wrong people. Though they could not admit it, they use social media tools and Google searches to build or justify a hunch, prejudice or bias against you as a candidate. It makes sense from their perspective. You cannot really blame them; it is just their way of doing a risk assessment on an unknown risk, you.

Thursday, September 9, 2010

Security through stupidity.....still! Thank God!

Did your company suffer through the "Here you have'' virus, as it is now being called?  It was one of the few exciting security events to happen to us guys in a number of years.

Good news: these inconveniences are becoming fewer and farther between as our technological defenses are getting better and smarter.

Bad news: we still are relying on the human element as the last bastion of protecting ourselves against basic  attacks like this.

Worse news: even at the human level, the reason that many attacks don't make it is because the attackers are still seemingly unable to both spellcheck and put proper punctuation in sentences...the dead giveway to a bogus e-mail....still.

Look at an excerpt from the 'Here you have' example:

"This is The Document I told you about,you can find it Here."

See the mistakes? Capitalized words in the middle of a sentence, sloppy and incorrect punctuation, etc. Either the bad guys in this situation are either not native English speakers, or they were just stupid or lousy students who goofed off in English class.

Either way, we will only have a short period of time until these types finally get their act together and learn how to use that super-sophisticated advanced technology tool known as 'spellcheck.'

Monday, September 6, 2010

The Social Engineering Attack: Men vs. Women.

As summer fades to a close, and we mentally resign ourselves to getting back into work, I am interested in a recent contest that was just held about social engineering and how men and women fare differently against social engineering attacks.


For those of you who don’t know what social engineering is (it also called ‘pretexting’), think about when you have ever used any degree of charm, persuasion, eyelash batting or a glimpse of excess cleavage to get yourself bumped up to first class in an airplane, get into a crowded event, get out of a speeding ticket or just generally get something that you may not on the surface deserve. That is, you have ‘engineered’ your audience into doing your will. This is what the most skilled and devious thieves do to us – get information from us that helps them do bad things. It is the toughest attack to fend off and against, as our nature is to be helpful and help a brother out.

This recent social engineering contest consisted of calling 135 employees from Fortune 500 companies, including Google, Wal-Mart, Symantec, Cisco Systems, Microsoft, Pepsi, Ford and Coca-Cola to be targeted by social engineering hackers, trying to get the employees to divulge or reveal they information that could be misused by the attackers, such as what operating system, antivirus software, and which browser the companies used. The ’bad guys’ also tried to talk the ‘victims’ into visiting unauthorized web sites. Most of the information compromised in the contest was gotten by the hackers pretending to be insiders who were doing audits or consultants filling out surveys.

But here is the really interesting part: only five of the group of 135 refused to give up any corporate information at all. And all of the five were women.

The team that held the contest was unsure as to why it was only women who failed to reveal any data, but there are some other common traits. Three of the five women who shut down contestants were managers, and female managers are generally the least likely to fall for social engineering attacks. A security consultant who commented on the contest stated that the findings make sense, as female managers are “going to be the least trusting, the most suspicious."

This contest also points out another important factor: when it comes to the social attack, you cannot simply train for a particular attack, like getting a flu shot for a specific strain, for example. You must constantly train on the need for heightened awareness and alertness by your employees. The possible scenarios that bad guys could come up with to get your employees to divulge information is infinite and impossible to thoroughly prepare them for. You have to simply make them aware of the possibility of these kinds of attacks and get them to keep thinking strategically and out of the box. Because the bad guys will as well.

Finally, I thought I would end with this little, possibly relevant nugget: at my company, it is impossible to know everyone by name or face since we have thousands of employees, yet every time and any time I have ever been asked if I have my badge as I am trying to enter the side door on some morning, the questioner has invariably been a woman....

Wednesday, June 23, 2010

Update: Is this the Roe v. Wade of Privacy Cases?

To follow up on my post of April 16th about a police officer, Jeff Quon, in Ontario, CCalifornia who was suing his employer for reviewing his personal texts on a company-owned and issued pager, The Supreme Court, amazingly, ruled 9-0 in favor of the Ontario Police chief, claiming that because there was reason to believe a work policy was being violated, his search of Quon’s texts did not violate Quon’s 4th amendment right against illegal search and seizure; the court ruled that the search was reasonable. Did I mention that the texts were sexually explicit? And were to his girlfriend, ex-wife, and another colleague?! (Women must love a man in uniform.)

This case is interesting for two reasons: secondarily, it is reportedly the first case on record to involve privacy issues regarding texting at work on a company-issue device.

But the main reason this case strikes me as revolutionary is that I don't think people realize just how close to Armageddon we really were if the decision had gone the other way...can you imagine the nightmare for IT, and for Legal if they had to try and perform discovery on company-owned devices that were constitutionally protected? This is the very model of privacy that Europe has today where the employee's privacy takes precedence, as opposed to the U.S. where there is no expectation of privacy in the workplace (usually). If the decision were for Quon than we would have seen a slew of other cases that would have fundamentally changed the way IT and Legal administer hardware and access in the workplace.

I feel like Earth just dodged  a huge asteroid, but most people were distracted watching World Cup....

Sunday, May 9, 2010

One Step Forward...Two Backwards...

The Step Forward….


Based on how young people use the Internet these days and what they deem fit for universal public consumption and disclosure, I have believed that for a very long time that they do not fully understand the implications of privacy and what it might mean to their personal and professional lives in the near and long term. Like impetuous youth, many do not think beyond the 30 minutes their attention spans can handle most days.

However, a recent story I read in the New York Times gave me some renewal of faith in the ‘yutes’ of the world as they begin to realize that self-censorship might be one of the most beneficial actions they can undertake in the protection and advancement of their current and future professional lives.

What many of these young people are quickly realizing is that not only are future and prospective employers trolling social media sites like Facebook, MySpace and search engines like Google for evidence of the candidate’s character, or other activity that may be representative of action ‘unbecoming of an officer’, but college admission offices are doing the same as well.

As an employee, you publicly represent the company; as a student, you are also a public representative of a college too. And as any business, (with the possible exception of the Hell’s Angels, I would imagine), public relations is a key element in the continued success of the college as it aims to turnout fine, exemplary products who represent the best of what the institution has to offer. So in addition to removing from their social media profiles any incriminating or questionable pictures, links, group associations and even political affiliations, some very canny students are starting to change the names of their Facebook profiles as early as Junior year so as to throw off the scent of the college admission snoop who is trying to determine if little Suzy is a collegiate candidate worth of the Ivy League institution’s hallowed sheepskin.



The Two Steps Back part…

Obscuring the details of one’s online avatar seems like a lot of work and possibly hardly worth the effort considering the risk to your privacy that someone might actually find you online. If you think that you will fall way under the radar of such important and busy people to waste their time in trying to find out if you have any drunken Mardi Gras pictures on your Facebook page or not, consider this website: www.peopleofWalMart.com. This website features pictures of actual customers of Wal-Mart taken by other customers and then uploaded to this site – without their permission or knowledge. The site claims itself to be a “satirical social commentary of the extraordinary sights found at America’s favorite store”.

Forget worrying about if your online privacy is being encroached upon or used as a factor in deciding your future, what this site tells me is that you cannot even take a quick trip to Wal-Mart in your scurvy, old pajamas to pick up a box of Q-Tips or Shake ‘n Bake without escaping the Black Hole of the ‘public domain’.