Like me, maybe you have received a notice in the last few days from one of many institutions that were affected by a major data breach of Epsilon, an online marketing firm. So far, we are told, mostly e-mail addresses were compromised, but in some cases so were customer names. You might not think this sounds terribly alarming, unlike, say, the T.J. Maxx episode in 2007 that included the loss of 45 million debit and credit card numbers. But you would be wrong
In the T.J. Maxx scenario, only the reputation and brand of T.J. Maxx was impacted. In this case, Epsilon is the service provider to a significant list of top-tier financial institutions including Barclays Bank, U.S. Bancorp, Walt Disney, Marriott, Ritz-Carlton, Best Buy, L. L. Bean, Home Shopping Network, TiVo and Target. The ongoing concern is that customers of these institutions can now be specifically targeted for fraudulent e-mail threats know as ‘spear phishing.’ (Though notice of the breach was sent to me by e-mail, oddly enough
In the T.J. Maxx case, the credit cards and debit cards were quickly canceled and replaced by the issuers (Visa, Mastercard, etc.). And in most cases these days, unlike in the recent past, the customer is not even responsible for the first $50 of fraudulent charges (Bank of America tells me that I will not be responsible for any fraudulent charges!). This lack of material and financial impact on a customer of T.J. Maxx helps explain why after their breach, not only did the sales of the company continue as before, but their stock price suffered no long-term ill effect. Average customers liked what the stores offered in terms of fashions and prices and disassociated the breach itself from the stores and the merchandise.
In the Epsilon case, however, I fear the result will be much more disastrous for them. The publicity around this episode alone is more significant than most other ones like it. Rush Limbaugh actually used the Epsilon example today to sell one of the identity theft products he touts on his show. The actual service offered by Epsilon can easily be replaced, but the untarnished reputation of the brand whose customer falls prey to a fraudulent e-mail cannot so easily be restored. If my identity is stolen after I click on a fake e-mail from my bank, I am going to remember and negatively associate the experience with the bank, not the e-mail marketing vendor who didn’t encrypt my e-mail address and name in their database.
We are not sure yet just how lax Epsilon was in their security controls that led to this incident. Whether or not they were as lax as T.J. Maxx was, will be uncovered in brutal detail in the process over the next few weeks, especially in the security world. Security folks will be using this very case as a way to reiterate the internal message of due care and the need for this or that software or hardware to help protect their own shop from suffering a similar fate.
This unfortunate series of events highlights the kind of brand and reputation risk a firm can suffer when outsourcing even the most seemingly innocuous service. Proper vendor management and due diligence of service providers will be the talk of the town over the next couple of months. Your clients will be asking what and how you do it in your shop, without a doubt. So be ready with a solid response.
Privacy and security are typically good things. But the way they are implemented or presented to real people to follow in the real world are not always realistic. Sometimes they are just down right ridiculous.
Tuesday, April 5, 2011
Monday, March 28, 2011
Things Worth Fighting For
I came across a little publicized story this week that presents an interesting parallel to my constant message of privacy & security diligence. Here is the story: The Yamaha Motor Manufacturing Corporation has been making an all-terrain vehicle (ATV) in the U.S. called the ‘Rhino’ since 2003. The Rhino is different than its single-passenger predecessor since it allows for two passengers to sit side-by-side.
Four years later, the company added a few safety updates like more passenger hand-holds. Lawyers for some injured drivers (plaintiffs) jumped on the company’s move insisting that the reason the safety features were added was because the vehicles were not safe in the first place. Naturally, lawsuits piled in. Overwhelming a company with so many lawsuits that it figures it’s easier to settle then fight was the approach the plaintiff’s attorneys took. The attorneys attacking the company even petitioned the Consumer Product Safety Commission (CPSC) to aid their suits by trying to force Yamaha to recall their vehicles.
Yamaha did not feel a recall was warranted and even worked with the Consumer Product Safety Commission to make other modest safety changes that would satisfy the agency.
Most importantly, the company responded to the litany of lawsuits in an uncommon way: It decided to fight back.
The company was ultimately vindicated as it proved that in a significant number of instances, the drivers of the vehicles were grossly at fault due to their own behavior. Though riders are cautioned to operate the vehicle properly, the CPSC investigations indicated that product defects, insufficient warnings, negligence, etc., was not the cause of the injuries.
What’s the takeaway then? The company believed in its product, it believed it had provided sufficient safety and precautionary advice to its customers to operate safely, and it had decided to stand its ground and fight back on a principle of having done the right thing. (How unorthodox!)
And what is the connection to privacy & security? Companies create and publish rules and guidelines all the time for their employees on why and how it expects the employees to follow those policies. Some times the rules aren’t followed. Often, the rules are only words in a document on the company Intranet to make Legal or HR happy. Sometimes the Information Security team is only a paper tiger with little enforcement power or ability to bring about change and assure compliance.
But in some cases, the company itself, usually with the tone set at the top, decides to practice what it preaches and enforce the rule; make examples of those who purposely attempt the flout the rules, and inform those who do it unwittingly.
These days, consumers are savvier than ever about information. They know the value of their information and they want it protected. A customer will walk away from a company who only pays lip service to the principles of privacy & security, and they will excoriate the company online in blogs and forums for doing so.
The twin pillars of privacy & security in a company can easily be an asset and competitive advantage to a company who knows how to leverage that expertise, and maintain its diligence. I know it’s not always easy to keep up the pressure. Employees get comfortable; employees get lazy. IT can sometimes be a hindrance and not a help to getting the business of the company done, so creative employees will go around the roadblocks to meet deadlines. Privacy & security sometimes suffers. When a company becomes lax, or inertia sets in, the guard gets let down and rules are no longer followed or enforced. That’s when incidents happen; that’s when headlines happen.
If a company believes in its principles, believes it has provided reasonably sufficient safety and precautionary advice to its employees to treat and handle information securely, and it decides to stand its ground and fight back against the perpetual inertia of letting violations slide by because its easier than making a fuss, then it has done the right thing. It will fight back and should fight back. Why? Because privacy & security is worth fighting for.
Thursday, February 3, 2011
What Does Stuxnet and Rollerball Have in Common? Only The Future of Warfare...
We have seen the future of war, and its name is Stuxnet.
When I was a kid, one of my favorite movies was a science fiction picture that proposed the idea that in the future, nations would no longer exist and war would no longer exist. The world would be controlled by a handful of international corporations. The controlling industrialists realized the folly of war with its destruction, its carnage, its irrelevance, and resorted instead to a particularly gruesome sport as a proxy for war itself: Rollerball. Primary cities each had their own teams and the teams would battle it out on the hardwood coliseum for supremacy. The movies tagline is: "In the not too distant future, wars will no longer exist. But there will be Rollerball." (Rollerball is like a cross between roller derby, hockey and motocross.)
The original version of the movie (1975) is a bit dated and contrived , but Rollerball does contemplate a future that, in retrospect now seems pretty plausible and a good security allegory.
The worst-case scenario of all-out nuclear war looks unlikely to occur due to a variety of reasons; not the least of which is the overwhelming destruction and the obvious repercussions on the instigator. What is much more likely based upon recent evidence is that States and private industry will increasingly engage in proxy fights through esoteric non-State actors. Numerous examples of these proxy fights exist which include cyber-warfare between entities where the target was obvious, but the attacker was not. In 2007, a three-week wave of massive cyber-attacks were aimed at the small Baltic country of Estonia, where Parliament, banks, and the media were targeted, allegedly by Russian hackers after the Estonians' removal of a Soviet war memorial in the center of the capital, Tallin. In late 2010, companies like Visa, MasterCard, PayPal and Amazon.com were also targets of coordinated distributed denial-of-service attacks, designed to force the websites offline or make them generally unavailable for business by hacker sympathizers of Julian Assange due to the websites' refusal to process payments to support the Wikileaks effort.
To best illustrate the premise that future conventional warfare for most of the advanced world will pose a lesser risk than it has historically, and will instead be replaced by pure cyber-warfare, consider the case of Stuxnet.
'Stuxnet' is a computer worm that was launched in July of last year with a destructive payload that had a defined target: Windows-based industrial systems. The worm was designed very specifically to attack only certain types of industrial systems; like the ones that run nuclear plants.. Unlike most viruses and malware, Stuxnet does little harm to computers and networks that don't meet the explicit configuration requirements of its code. Like a laser sight on a snipers rifle, fingerprinting technology allows Stuxnet to precisely identify the systems it infects The creator of this worm took great care to ensure that only the designated target(s) were hit. A tremendous and sophisticated effort was required to avoid collateral damage.
What was the intended target? It is difficult to say for sure, but this much is known: 60% of the infected computers worldwide were in Iran. It is surely not a coincidence that Stuxnet infected the systems at two nuclear power plants that were hurriedly trying to enrich uranium.
The complexity of the code and the use of multiple programming languages contemplates the idea that only a -State or collection of States accessing deep enough pockets and vast dedicated resources could have the collective skill to create and deploy such a focused cyber-weapon. Most of the blame falls on the U.S. or Israel, in particular, who would ostensibly have the most to gain by stopping or slowing the ability of the Iranians to get nuclear capability.
The supposition then is obvious: this cyber-weapon was created o do what conventional warfare and diplomacy could not by surreptitiously taking out enemy nuclear capabilities like a sniper in the night. Unlike the very public 2007 Israeli air force raid on a Syrian site that the Israelis claimed was a nuclear facility with a military purpose, the Stuxnet attack is a much lower profile attack. The message is no less ambiguous than a full frontal assault and the effect just as valuable. Coupled by the additional benefits of no human causalities, and no political fallout, cyber warfare appears to also be very, very cost effective.
From the limited test case of Stuxnet, we can easily extrapolate to an 1984-like world of cyber-warfare where instead of Oceania declaring war on Eurasia one week or Eastasia the following week, battles will instead be played out over DS3s, T1s and fiber optic networks. Rather than sending one million expensively armed soldiers to invade an enemy, one simple mouse click could deploy a worm or virus that will shut down power grids, water systems or wreck havoc on international financial systems.
It may not be roller derby, but either way, Stuxnet presages the future of warfare.
Saturday, January 29, 2011
The TSA Color Coded Alerts: Fade To Black
Is it any surprise that the TSA announced this week that the color-coded threat system it has had in place since post-September 11th is being replaced?
I will refrain from comment on the new system it the details have been fleshed out and give it a chance to better inform us of what real and imminent dangers we may be in store for.
However, last post I made a point about the threat system having 5 different levels, and never having ever been at the two lowest colors - blue and green. Security Expert Bruce Schneier makes this pithy insight:
"The DHS could have lowered the level to something more reasonable, but that would have been politically impossible. If there were a terrorist attack and the threat level had been blue or green, the DHS would have been blamed for not warning us. Keeping the level high might increase the general dread among some people and cause sniggering among others, but it helps protect the jobs of those charged with keeping us safe from terrorism."
Schneier also goes on to make the great point about our ability to be on alert, which in the intention of the colored system. But always having the alert color be at one of the three highest of the colors puts a tremendous burden of responsibility on average travelers. Schneier says "According to scientists, California could experience a huge earthquake sometime in the next 200 years. Even though the magnitude of the disaster will be enormous, people can't stay alert for two centuries."
He's right. We have to be on our guard for sure, and I always like to say that every and any decision we make day-to-day is a risk-based decision, but we cannot be infinitely diligent. Human beings just don't have the mental ability to be that alert at all times. We can't even text and drive at the same time.
I will refrain from comment on the new system it the details have been fleshed out and give it a chance to better inform us of what real and imminent dangers we may be in store for.
However, last post I made a point about the threat system having 5 different levels, and never having ever been at the two lowest colors - blue and green. Security Expert Bruce Schneier makes this pithy insight:
"The DHS could have lowered the level to something more reasonable, but that would have been politically impossible. If there were a terrorist attack and the threat level had been blue or green, the DHS would have been blamed for not warning us. Keeping the level high might increase the general dread among some people and cause sniggering among others, but it helps protect the jobs of those charged with keeping us safe from terrorism."
Schneier also goes on to make the great point about our ability to be on alert, which in the intention of the colored system. But always having the alert color be at one of the three highest of the colors puts a tremendous burden of responsibility on average travelers. Schneier says "According to scientists, California could experience a huge earthquake sometime in the next 200 years. Even though the magnitude of the disaster will be enormous, people can't stay alert for two centuries."
He's right. We have to be on our guard for sure, and I always like to say that every and any decision we make day-to-day is a risk-based decision, but we cannot be infinitely diligent. Human beings just don't have the mental ability to be that alert at all times. We can't even text and drive at the same time.
Thursday, January 13, 2011
What hath too much security awareness wrought?
As a creator and purveyor of security awareness, it has always been my position that there is no such thing as too much awareness or the need to be alert and attentive to the possibilities of an untoward or adverse event. So I can appreciate the fact that the TSA or Department of Homeland Security wants to make us aware of new and impending threats to our safety. But in this day of Threat Advisories, patdowns, three ounce liquid limitations, X-Ray scanners and the like, I believe that we have finally crossed the line into the surreal.
Two events this month have made airline security like the annual Simpsons Halloween special. (For non-Simpsons fans, this is the one annual episode where the show takes on a bizarre plot line and completely abandons any pretense of being realistic.)
On January 5th, while over Canada en route to Germany, an airplane's radio went awry, and the pilot thought he put the “No Radio” code (7600) in the transponder but mistakenly entered the code ‘7500’, which means "hijacking or unlawful interference". The crew ultimately confirmed that the issue was a communication issue and not a hijacking. The plane was ultimately diverted to Toronto however. What caused the ruckus? One of the pilots spilled some coffee on the console due to some turbulence, and while trying to clean up the mess the pilot entered the wrong code.
The second story, a day later, was a case where a Florida professor was arrested and removed from a plane after fellow passengers alerted crew members they thought he had a suspicious package in the overhead which was “making suspicious sounds.” That "suspicious package" turned out to be a set of keys, a hat, and a bagel with cream cheese. He was removed from the plane because he took exception to the crew’s questioning, probably reminiscent of the KGB (Where are your papers?!) and was ultimately handcuffed. Note to self: always order the ‘noiseless’ cream cheese.
(I am not even going to tell you about the passenger on a flight from Fort Lauderdale to Denver who was pulled off a plane last week after other passengers said he was “taking too many bathroom breaks”!)
Because of the deluge of awareness warnings and veiled threats to your safety, we have become so prone to over-reacting that now we all jump if we here a loud sound in the airport. Even in the subways in NYC we are urged that if we "see something" we should "say something." Average citizens have become deputized Barney Fife’s with no accountability but plenty of assumed authority, as the bagel and bathroom cases above suggest. Passengers have become the de facto authorities of suspicious or terrorist activities on planes all of a sudden. Now I know that many real threats have been thwarted or suspects captured with the help of average citizens who report tips, but imagine the inundation of false and ridiculous leads law enforcement have to follow-up on when you request the aid of amateurs. As a Muslim man, you almost couldn't get on a plane in the US after 9/11 due to the hysterics that followed. And God forbid if you were flying with a few of your friends.
The Department of Homeland security has five levels of alerts: Low = Green; Guarded = Blue; Elevated = Yellow; High = Orange; Severe = Red. Since the introduction of the system in 2002, we have never had a Green or Blue status, only Yellow, Orange and Red. Do you know how many times it has been changed since 2002? No? Why would you? Do you get to keep your shoes on instead at the airport when the threat is lowered? No. Do you see any real improvement in security after they raise the threat? Not really, but you do see some procedural changes in which the government and TSA react to the last threat - not necessarily a future, possible threat. How many other shoe bombers have we had since Richard Reid? (None) How many additional underwear bombers have we had since the Underpants of Mass Destruction attempt (None) Boxcutters? You get my point... (By the way the Threat Level has been changed 16 times since 2002).
If I have learned anything about security awareness training and campaigns is that though people can deal with the constant reinforcement of subtle awareness messages, people quickly become desensitized to hysterical warnings, especially if they see no immediate crisis to warrant the warnings. The most effective training, in my opinion, is to mete out the awareness with intelligent, well-reasoned arguments about what is the best behavior and what the possible risks might be. Both 'Chicken Little' and 'The Boy Who Cried Wolf' approaches are proven dead-ends.
Sunday, January 2, 2011
The Right to be Forgotten Exists In Some Cases...Like This One.
In these blogs I have often presented the perils that we face if we unthinkingly post pictures, opinions or tweets about activities or events we have engaged in or have experienced. The takeaway has always been that the users must analyze every possible aspect of what his or her post will or may be construed as, not only now, but five years from now when, for example, the adolescent is applying for that position at a respected organization, scholarship at some Ivy League school, or even a prospect for a first date.
Most people rightly have no sympathy for smart individuals who should otherwise know better, and who cannot self-censor. At this stage in the evolution of social media, we all know how data persists forever, and what you post or say online should be something that you should be prepared to live with, or defend, forever. (You do understand this, right?)
But what about those that can't defend themselves?
You may have missed this recent story but it is a frightening example of how, though no fault of their own, two children, 4-and-5 years old, will forever be affected by the ubiquity and persistence of information in the public domain.
Here's the story: an 87 year old woman with a walker was knocked down by accident on a street in New York City by one or both of the two children, 4-and-5-years old ,who were riding their bicycles. The woman had to be taken to the hospital. She subsequently died 3 months later of unrelated causes. The old woman's estate sued the parents of the children claiming negligence: they should have been supervised better, the suit asserts.
A judge in NY state ruled that the kids could be sued in a civil injury context and the names of the children were then made part of the public record, as is customary. Ultimately, the New York Times reported on the case due to its extraordinary nature, and the kid's names have now become more widely distributed. A common practice in the world of public law has now uniquely, and probably permanently identified these children in a less than positive light for the rest of their lives.
Though the parallels between a post on Facebook, LinkedIn, Twitter or MySpace, and the publication of the two children's names may seem unrelated and dissimilar, they have one component in common: the perpetuity of the information. The issue is not that the legal process required the publication of the defendants names in a public record; that procedure has been common practice for hundreds of years. The issue is more the fact that the memory of online databases and search engines is or will be assumed to be infinite.
Ten years from now when the classmates of these two children do Google searches on all their friends, what do you think the top search result will be? How do think teenagers in high school will likely interpret and process that data? (Johnny killed some old lady when he was 5?!!). I doubt that Johnny will see that past experience as a possible résumé enhancer.
It is inevitable and to be expected that a future Human Resource manager will do a Facebook or Google troll on you to see why they might not want to hire you. What do you think the impact will be on the job prospects of these two kids when this case comes up on the search? These two children may always be haunted by the persistence of memory and will not have the privilege or the right to be forgotten.
Thursday, December 23, 2010
Playing dumb worked for Anna Nicole, but doesn't work for a business
I finally had my first experience with the new backscatter x-ray machines at an airport security line last week. I was unable to see what the TSA saw as they looked through my clothes, though I did walk away with a few observations of my own.
First, as I was about to go through the usual metal detector device, a TSA agent asked to remove my belt. How this little piece of a belt buckle could take off a bottle cap, let alone take down an airliner is beyond me. Since I never proactively remove my belt, the time wasted and humiliation element of the experience notwithstanding, it is the inconsistency of the request that most disturbs me and shakes to the foundation my faith and trust in the staff at the TSA.
Since I admittingly gave the TSA agent a little bit of attitude for her asking me to remove my belt, (but allowed me to keep on my chunky, solid steel watch which in addition to weighing 5 times more than my belt buckle, could probably represent a weapon of mass destruction if thrown hard enough), she then asked me to step into the backscatter x-ray machine. The watch did not set off the metal detector by the way. Never does.
Second, though I (hopefully) do not represent an obvious threat to airline safety, as I possess none of the notable, empirical characteristics associated with would-be terrorists (except being a male): young, from middle-eastern or African descent, possibly Muslim, on a watch or do-not-fly list, possessing a one-way ticket, paid for ticket in cash, no checked luggage, sweating or fidgeting in line…I could go on. I am, in contrast, a frequent flyer, family man and in no possession of any radical views or positions (other than privatizing or otherwise banning the TSA.) Had any other terrorist ever boarded a flight with a Kindle?
So I took the request to go though the x-ray scanner as a purely punitive measure on the part of the TSA agent – not a random check, mind you, but a minor punishment as only a petty tyrant with no other power outlet than that at her disposal might inflict.
Finally, I had to remove everything – literally everything – out of my pockets including my wallet and 3 small vitamins before the scanner would work. Isn’t the point of the device to be able to detect stuff in my pocket or in my person?!?
In theory, I am not opposed to security measures to prevent or thwart terrorism on airplanes. I am one of the primary beneficiaries of security since I travel so much and am statistically more likely to incur an incident than your average American. What I do always question however, and I’ve said this before in previous posts, is the seeming lack of consistency and reason behind much the decision and apparatus in place. The response is that it is done intentionally so as not to allow terrorists to get comfortable with the TSA technique’s. Playing dumb so as to allow the enemy underestimate you? Fine. Classic move from the Art of War. I would love that idea if it could ever be true of the TSA.
Playing dumb, however, should not be an operational strategy for a business. It doesn’t work for me at my job, at home or anywhere else in the real world. The market severely punishes any company in the private sector if that is their approach – it does it all the time to drug companies that fail FDA tests or mischaracterize the benefits or uses of their drugs. And these kinds of events kill more people than terrorists have ever done!
Let’s privatize the TSA and hold them to the same standards as a private company. Once we make them play by the same rules and standards of transparency as the private sector, then we can begin to peel away the layers of charade and concentrate on the real measures of security that will ensure flyer’s safety without having to frustrate us into submission. And let us keep our clothes on and our dignity intact.
First, as I was about to go through the usual metal detector device, a TSA agent asked to remove my belt. How this little piece of a belt buckle could take off a bottle cap, let alone take down an airliner is beyond me. Since I never proactively remove my belt, the time wasted and humiliation element of the experience notwithstanding, it is the inconsistency of the request that most disturbs me and shakes to the foundation my faith and trust in the staff at the TSA.
Since I admittingly gave the TSA agent a little bit of attitude for her asking me to remove my belt, (but allowed me to keep on my chunky, solid steel watch which in addition to weighing 5 times more than my belt buckle, could probably represent a weapon of mass destruction if thrown hard enough), she then asked me to step into the backscatter x-ray machine. The watch did not set off the metal detector by the way. Never does.
Second, though I (hopefully) do not represent an obvious threat to airline safety, as I possess none of the notable, empirical characteristics associated with would-be terrorists (except being a male): young, from middle-eastern or African descent, possibly Muslim, on a watch or do-not-fly list, possessing a one-way ticket, paid for ticket in cash, no checked luggage, sweating or fidgeting in line…I could go on. I am, in contrast, a frequent flyer, family man and in no possession of any radical views or positions (other than privatizing or otherwise banning the TSA.) Had any other terrorist ever boarded a flight with a Kindle?
So I took the request to go though the x-ray scanner as a purely punitive measure on the part of the TSA agent – not a random check, mind you, but a minor punishment as only a petty tyrant with no other power outlet than that at her disposal might inflict.
Finally, I had to remove everything – literally everything – out of my pockets including my wallet and 3 small vitamins before the scanner would work. Isn’t the point of the device to be able to detect stuff in my pocket or in my person?!?
In theory, I am not opposed to security measures to prevent or thwart terrorism on airplanes. I am one of the primary beneficiaries of security since I travel so much and am statistically more likely to incur an incident than your average American. What I do always question however, and I’ve said this before in previous posts, is the seeming lack of consistency and reason behind much the decision and apparatus in place. The response is that it is done intentionally so as not to allow terrorists to get comfortable with the TSA technique’s. Playing dumb so as to allow the enemy underestimate you? Fine. Classic move from the Art of War. I would love that idea if it could ever be true of the TSA.
Playing dumb, however, should not be an operational strategy for a business. It doesn’t work for me at my job, at home or anywhere else in the real world. The market severely punishes any company in the private sector if that is their approach – it does it all the time to drug companies that fail FDA tests or mischaracterize the benefits or uses of their drugs. And these kinds of events kill more people than terrorists have ever done!
Let’s privatize the TSA and hold them to the same standards as a private company. Once we make them play by the same rules and standards of transparency as the private sector, then we can begin to peel away the layers of charade and concentrate on the real measures of security that will ensure flyer’s safety without having to frustrate us into submission. And let us keep our clothes on and our dignity intact.
Subscribe to:
Posts (Atom)