<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Story</title>
	<atom:link href="http://blog.ambersail.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ambersail.com</link>
	<description>A blog by Ambersail Ltd. Information Security Explained</description>
	<lastBuildDate>Wed, 01 May 2013 16:35:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.6-beta2</generator>
		<item>
		<title>Guest Post: A Trojan Horse In Every Pocket</title>
		<link>http://blog.ambersail.com/mobile/guest-post-a-trojan-horse-in-every-pocket/</link>
		<comments>http://blog.ambersail.com/mobile/guest-post-a-trojan-horse-in-every-pocket/#comments</comments>
		<pubDate>Wed, 24 Apr 2013 10:33:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[mobile]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[byod]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=298</guid>
		<description><![CDATA[&#8220;A hacker wishing to break into a specific company may decide that compromising an unprotected mobile device is far easier than dealing with corporate firewalls&#8221; After years of experience, and learning from the high profile mistakes of others, businesses are fully aware of the importance of security on desktop and laptop computers.  Anti-virus software and [...]]]></description>
				<content:encoded><![CDATA[<blockquote><p>&#8220;A hacker wi<a href="http://blog.ambersail.com/wp-content/uploads/2013/04/mobile-phone-security-SML.jpg"><img class=" wp-image-301 alignleft" alt="Phone with key" src="http://blog.ambersail.com/wp-content/uploads/2013/04/mobile-phone-security-SML-300x225.jpg" width="243" height="183" /></a>shing to break into a specific company may decide that compromising an unprotected mobile device is far easier than dealing with corporate firewalls&#8221;</p></blockquote>
<p><span style="font-family: 'Source Sans Pro', Helvetica, sans-serif; font-size: 16px; line-height: 1.5;">After years of experience, and learning from the high profile mistakes of others, businesses are fully aware of the importance of security on desktop and laptop computers.  Anti-virus software and encryption tools are standard issue, and user rights management also forms a key part of any corporate security setup.</span></p>
<p>But this is now only one aspect of securing a business against digital threats. The rapid growth of powerful mobile devices has opened a whole new front in the war against hackers, viruses and mischief makers.</p>
<p>Now in addition to locking down a desktop and laptop computers, business owners must consider the danger posed by mobile devices, and those that don’t risk exposing their company to financial or reputational loss.</p>
<h3>A trojan horse in every pocket</h3>
<p>Smartphones and tablets can be hugely beneficial to businesses, but an unsecured device offers another route to confidential information for hackers.</p>
<p>There are already numerous mobile viruses in circulation. Typically these are untargeted, they’re used to gather private information or send premium rate texts for the financial benefit of those controlling the software. But a dedicated coder could easily create a virus with a much narrower focus, one designed with the express purpose of penetrating a company.</p>
<p>There’s already been one very high profile example of this kind of attack on desktop systems. Stuxnet was a virus designed to damage to a very particular type of industrial equipment used by the Iranian nuclear programme.</p>
<p>This was a sophisticated, state-sponsored effort, but it’s not restricted to those with government backing. A group known as ‘Winnti’ have been using malware attacks to steal online gaming credentials, security certificates and source code in order to profit from trading virtual currency and stolen data.</p>
<p>And just this month a <a href="http://www.seculert.com/blog/2013/04/magic-persistent-threat.html">new virus was discovered</a> that is thought to have been targeted at UK companies, silently infecting thousands of machines.</p>
<p>A hacker wishing to break into a specific company may decide that compromising an unprotected mobile device is far easier than trying to deal with corporate firewalls. It could be all they need to capture confidential information or gain access to internal systems.</p>
<h3>What can be done?</h3>
<p>At this year’s Mobile World Congress event <a href="http://www.broadbandgenie.co.uk/blog/20130308-hackers-viruses-phishing-why-all-smartphone-tablet-users-need-know-about-mobile-security">all the major security firms were in attendance</a>, and while they were jockeying for attention for their own software solutions they did all agree on one thing: users need educating.</p>
<p>“On PC everybody is aware they need protection”, says Stefan Wesche of Norton Antivirus, “on mobile most people are not aware, and that’s where we should start, telling them about the problem.”</p>
<p>We’re all accustomed to the need for good passwords and up-to-date anti-virus on our computers, but the concept of anti-virus on a smartphone is still alien to many people.</p>
<p>Businesses need to start by ensuring their security guidelines cover the use of mobile devices, and that all employees are aware of the risks.</p>
<p>They also need to examine the inherent security features of the various mobile platforms; one reason BlackBerry was so popular for corporations was thanks to the excellent security it offered as a standard feature. At present, Google’s Android mobile OS has the largest number of viruses partly because there are very few limits to what users and developers can do with their devices. That offers many advantages, but also allows malware to piggy-back on pirated software or sneak in through the official app store.</p>
<p>A robust mobile security policy is particularly vital with the growth of ‘Bring Your Own Device’ (BYOD), where employees are permitted to use personal equipment. This can be a money saver, but a smartphone which is being used to download apps and games at home, perhaps being used by children, and then taken to work for business emails and calls should be a big area of concern for IT managers.</p>
<p><b>Author Bio: </b><a href="https://plus.google.com/101410225647289538748/posts">Matt Powell</a> is the editor for the broadband, smartphone and tablet consumer information site Broadband Genie.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/mobile/guest-post-a-trojan-horse-in-every-pocket/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment Cards are Dead. Long Live Payment Cards.</title>
		<link>http://blog.ambersail.com/payments/payment-cards-are-dead-long-live-payment-cards/</link>
		<comments>http://blog.ambersail.com/payments/payment-cards-are-dead-long-live-payment-cards/#comments</comments>
		<pubDate>Mon, 15 Apr 2013 08:00:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[payments]]></category>
		<category><![CDATA[amex]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[ewallet]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[visa]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=261</guid>
		<description><![CDATA[Any payment technology analyst will tell you that the payments market has exploded over the last few years. An explosion sounds great, but it also suggest fragmentation. Which is another way of saying that the customer has a confusing array of choices. Not that confusion is anything new. Everyone has, at some point, fumbled through a stack [...]]]></description>
				<content:encoded><![CDATA[<p><span style="line-height: 1.5;">Any payment technology analyst will tell you that the payments market has exploded over the last few years. An explosion sounds great, but it also suggest fragmentation. Which is another way of saying that the customer has a confusing array of choices.</span></p>
<p>Not that confusion is anything new.</p>
<p>Everyone has, at some point, fumbled through a stack of payment cards stuffed in to a wallet or purse in a vain attempt to extract the right one for the purchase in hand.</p>
<blockquote><p>&#8220;Do you accept Diners Card?  No?  How about Access? Oh. Hang on, I&#8217;ve got an Amex card in here somewhere&#8230;&#8221;</p></blockquote>
<p>So much for taking the waiting out of wanting.</p>
<p>The last few years has seen the emergence of a variety of eWallet services. These on-line services enable the customer to register bank or payment card details just once with the eWallet provider. Once done, the customer does not have to share card data with the merchant as the eWallet provider handles all interactions with the account holders bank or card issuer.</p>
<p>But payment card brands are, just as the name suggests, brands. Vast amounts of money are expended to ensure that merchants and consumers alike are visibly reminded of the brand identity of the product embodied in that plastic card. eWallets obscure that brand, or indeed replace it altogether.</p>
<p>A curious but perhaps inevitable effect of this has been the appearance of &#8220;brands&#8221; such as<a href="https://www.paypal.com/uk/webapps/mpp/use-paypal-in-stores"> PayPal in high street stores</a>. No longer just an on-line entity, PayPal has a growing presence at the retail point of sale too, cleverly insinuating it&#8217;s own brand presence where previously only Visa, Mastercard, Amex et al had a footprint.</p>
<p>But just as on-line payments companies like PayPal are moving in to the face-to-face environment, it would be wrong to assume that the traditional card brands are simply watching this happen. eWallet offerings from Visa (<a href="https://uk.v.me/media/main.aspx">V.me</a>), Mastercard (<a href="https://paypass.com/online/Wallet/Home">Masterpass</a>) and Amex (<a href="https://www.serve.com">Serve</a>) are all competing too, and in exactly the space that companies like PayPal have defined for themselves.</p>
<blockquote><p>&#8220;The analytic possibilities presented by mobile payments data will make current loyalty card schemes look positively quaint by comparison.&#8221;</p></blockquote>
<p>However, the major card brands are not the only competition to the likes of PayPal. Let&#8217;s not forget <a href="http://www.google.co.uk/wallet/">Google Wallet</a>, for example.  Or <a href="https://squareup.com/wallet">Square</a>, or <a href="https://www.paywithisis.com/whatis.xhtml">Isis</a>. There&#8217;s a lot of competition out there, and the stakes are high with the US mobile payments market alone expected to be worth over <a href="http://techcrunch.com/2013/01/16/forrester-u-s-mobile-payments-market-predicted-to-reach-90b-by-2017-up-from-12-8b-in-2012/">$90 billion over the next few years</a>.</p>
<p>The key driver behind the growth of these services has been Internet-connected smartphones. All of the major eWallet services include a smartphone app component that effectively sees the phone not just as an eWallet, but as the payment device too, bridging the gap between on-line and face-to-face payments. These apps are able to implement their own security features too, including voiceprint, fingerprint or pin authentication.</p>
<p>Android phones have been available for some time equipped with <a href="http://www.techradar.com/news/phone-and-communications/what-is-nfc-and-why-is-it-in-your-phone-948410">NFC</a> hardware, enabling the phone to act just like a physical payment card, and there are <a href="http://news.cnet.com/8301-13579_3-57579030-37/apple-could-unveil-killer-app-this-summer-says-analyst/">rumours</a> that Apple&#8217;s next iPhone could also be NFC-equipped with Apple releasing a so-called &#8220;killer&#8221; eWallet app.</p>
<p>So it seems that anyone who&#8217;s anyone now has a stake in the future of mobile payments. The convergence and adoption of key technologies continues, and although no clear winners have emerged as yet, the future of payments will surely be mobile.</p>
<p>Smartphone platforms provide an unprecedented opportunity for retailers and payment providers to profile customers, to push individually customised offers and to analyse sales patterns based upon location, historical data and any of the wealth of information our smartphones reveal about us. This data will be hugely valuable. The analytic possibilities presented by mobile payments data will make current loyalty card schemes look positively quaint by comparison.</p>
<p>The winners will combine simplicity and sophistication to create a ubiquitous payment process, and will reap rich rewards in the process.  For now, it&#8217;s the simplicity that&#8217;s proving elusive from the customer&#8217;s perspective. Until that changes, we think most people will prefer to reach for the plastic.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/payments/payment-cards-are-dead-long-live-payment-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Constraints To Security Innovation</title>
		<link>http://blog.ambersail.com/security/5-constraints-to-security-innovation/</link>
		<comments>http://blog.ambersail.com/security/5-constraints-to-security-innovation/#comments</comments>
		<pubDate>Tue, 26 Mar 2013 14:21:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[convergence]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[opinion]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=251</guid>
		<description><![CDATA[The great thing about the information security field is that it constantly re-invents itself, or at least it tries to. In truth, real innovation is rare, and recyling is common. Developments in information security are reactive and innovation in the space only occurs when &#8220;real&#8221; innovations happen elsewhere. To some extent, this is inevitable. Example: [...]]]></description>
				<content:encoded><![CDATA[<p><span style="line-height: 1.5;">The great thing about the information security field is that it constantly re-invents itself, or at least it tries to. In truth, real innovation is rare, and recyling is common.</span></p>
<p><span style="line-height: 1.5;">Developments in information security are reactive and innovation in the space only occurs when &#8220;real&#8221; innovations happen elsewhere. To some extent, this is inevitable. Example: there was no anti-virus industry before the microcomputer innovations of the 70s and 80s. Before that time, discussions about any kind of security were generally limited to the provision of usernames and passwords controlling access to dumb-terminals connected to central mainframe applications.</span></p>
<p>The microcomputer revolution changed everything, putting real power in the hands of the end user, freeing them from the tyranny of the <a href="http://en.wikipedia.org/wiki/System_administrator">sys admin</a>. Simultaneously, the information security industry was born, offering instant solutions to new classes of problems.</p>
<p>Then the Internet blossomed, joining up the dots. End-users, empowered <em>and</em> on line. The next iteration, and an even bigger security industry.</p>
<p>The cycle is repeating itself, as cycles do. Roll forward a decade or so. AV is yesterday&#8217;s discussion, and every one of us is the administrator of perma-connected mobile devices.</p>
<p>We now have a massive security industry, and hacking and data loss is a bigger issue than ever before. Why?</p>
<p>The simple answer is that the security industry never actually catches up with innovations elsewhere (not forgetting that innovation happens both legitimately and illegally).  Also, there are some serious constraints that any security technology has to work within:</p>
<ol>
<li><span style="line-height: 16px;">End-users will resist being functionally restricted.</span></li>
<li>Ease of use is, and always will be, paramount.</li>
<li>Most end users do not perceive security issues, do not know who to trust and will often make poor security decisions.</li>
<li><span style="line-height: 1.5;">About </span><a style="line-height: 1.5;" href="https://www.google.co.uk/publicdata/explore?ds=d5bncppjof8f9_&amp;met_y=it_net_user_p2&amp;tdim=true&amp;dl=en&amp;hl=en&amp;q=world%20population%20with%20internet%20access">35% of the World&#8217;s population</a><span style="line-height: 1.5;"> are currently on the Internet, and the figure continues to climb steadily. Solutions have to be capable of massive scaling in the future.</span></li>
<li>All user-facing technologies have to innovate within the constraints above, or risk becoming niche or irrelevant .</li>
</ol>
<p>Technology that is secure but hard to use will fail to make an impact. Technology that is easy to use but does not improve security will fail to make an impact. There have been plenty such products over the years.</p>
<p><span style="line-height: 1.5;">Which (apart from the Internet statistic) <em>is exactly where we were decades ago</em>. In that sense, the industry has not moved at all, but has merely repeated itself on a bigger scale. It&#8217;s easy to become frustrated by this (frustration is a common complaint in the security business) however, there are some positive effects.</span></p>
<p>Firstly, now that we&#8217;re in this third cycle, we&#8217;re past the &#8220;we know what we don&#8217;t know&#8221; phase. Which means that many of the behavioral aspects of human-computer interaction are well understood. We understand the kinds of decisions people make when interacting with technology (the bad guys know this too, but lets gloss over that for now).</p>
<p>Secondly, we&#8217;re just beginning to understand what doesn&#8217;t work in the vital task of establishing trust. Technologies such as SSL are <a href="http://www.theregister.co.uk/2011/04/11/state_of_ssl_analysis/">shown to be flawed</a> because of their susceptibility to human error and implementation faults &#8211; clearly we need something better. Projects like <a href="http://en.wikipedia.org/wiki/Convergence_(SSL)">Convergence</a> seek to replace the flawed certificate authority system which underpins the trust that SSL is supposed to provide. It&#8217;s still early days, but this is real innovation.</p>
<p>Third time lucky, there&#8217;s every reason to be optimistic.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/security/5-constraints-to-security-innovation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security News Roundup: Defending The Indefensible</title>
		<link>http://blog.ambersail.com/security/security-news-roundup-defending-the-indefensible/</link>
		<comments>http://blog.ambersail.com/security/security-news-roundup-defending-the-indefensible/#comments</comments>
		<pubDate>Mon, 18 Mar 2013 16:15:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[DNA]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Pwnium]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=240</guid>
		<description><![CDATA[Here&#8217;s a data security conundrum. The news that anonymous DNA sample data has been used to personally identify the original donor sounds, at first, like an information security problem. The reality is, it isn&#8217;t.  A team of geneticists has shown there is a systematic weakness in the way that this data is handled. It turns out [...]]]></description>
				<content:encoded><![CDATA[<p>Here&#8217;s a data security conundrum. The news that anonymous DNA sample data has been used to personally identify the original donor sounds, at first, like an information security problem.</p>
<p>The reality is, it isn&#8217;t.  A team of geneticists <a href="http://www.networkworld.com/news/2013/031113-dna-hack-could-make-medical-267569.html?source=nww_rss">has shown there is a systematic weakness</a> in the way that this data is handled. It turns out that statistical analysis combined with good old-fashioned searching the Internet for identity clues may be all it takes to render the strict controls associated with donor data completely powerless.</p>
<p><a href="http://en.wikipedia.org/wiki/Unintended_consequences">The law of unintended consequences</a> always applies with new technology. If we give information away freely, we shouldn&#8217;t be surprised when someone finds a way to use it. Imagine what a geneticist could do with <a href="http://www.eweek.com/cloud/facebook-likes-used-to-predict-personality-traits-social-preferences/">this research</a> that uses Facebook &#8216;likes&#8217; to predict race, religion and sexual orientation?</p>
<p><span style="line-height: 1.5;">This does raise the question of how to design security systems to protect data from threats (or developments in technology) that we don&#8217;t know about yet. This intractable problem is likely to remain with us for the foreseeable future, but one approach is to offer up your implementation for attack, and pay a bounty for positive results.</span></p>
<p>Which sounds very much like the Google-sponsored &#8220;Pwnium 3&#8243; contest where cash prizes of up to $150k are available for demonstrable exploits of Google&#8217;s Chrome OS. Google did manage to get some last-minute patching done just before the competition started, and (consequently?) there were <a href="http://www.h-online.com/security/news/item/Google-s-Pwnium-ends-with-no-winners-1819976.htm">no clear winners</a>, with Chrome fending off all attacks.</p>
<p>Let&#8217;s wrap up this weeks somewhat sober assessment with a data-leak-of-the-week  <a href="http://www.crn.com/news/security/240150683/equifax-other-credit-bureaus-acknowledge-data-breach.htm">quote from this story</a> about widely reported data breaches at various credit reference bureaus:</p>
<blockquote><p><span style="line-height: 1.5;">&#8220;The data leak this week is being called a juvenile prank and not necessarily the work of any sophisticated hacker&#8221;</span></p></blockquote>
<p>We&#8217;re not entirely sure what the difference is, from the victim&#8217;s perspective, but it&#8217;s an interesting defence.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/security/security-news-roundup-defending-the-indefensible/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cheat Sheet: Virtual Web Application Patching</title>
		<link>http://blog.ambersail.com/pci-dss/cheat-sheet-virtual-web-application-patching/</link>
		<comments>http://blog.ambersail.com/pci-dss/cheat-sheet-virtual-web-application-patching/#comments</comments>
		<pubDate>Fri, 15 Mar 2013 11:08:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[cloud]]></category>
		<category><![CDATA[pci dss]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[pci]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=241</guid>
		<description><![CDATA[Do you operate public-facing web applications in your card data environment? Here&#8217;s a pointer to a great source of information from the Open Web Application Security Project (OWASP) on the subject of virtual patching. What is virtual patching? Within the context of web vulnerabilities, this refers to the practice of applying a defensive layer to intercept [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://blog.ambersail.com/wp-content/uploads/2013/02/IMG_0794-small.jpg"><img class="size-full wp-image-187 alignleft" alt="IMG_0794-small" src="http://blog.ambersail.com/wp-content/uploads/2013/02/IMG_0794-small.jpg" width="141" height="100" /></a>Do you operate public-facing web applications in your card data environment? Here&#8217;s a pointer to a great source of information from the Open Web Application Security Project (OWASP) on the subject of virtual patching.</p>
<p><span style="line-height: 1.5;">What is virtual patching? Within the context of web vulnerabilities, this refers to the practice of applying a defensive layer to intercept potentially malicious traffic destined for your web applications. Of course, the very best defence against these attacks is to write secure code to begin with, however there are a number of circumstances in which this isn&#8217;t achievable.</span></p>
<p>For example, where you&#8217;re running a 3rd party web application, or if you simply don&#8217;t have the resources available to make the code changes.</p>
<p>Highly recommended reading for all developers and development managers.</p>
<p>Read it <a href=" https://www.owasp.org/index.php/Virtual_Patching_Cheat_Sheet">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/pci-dss/cheat-sheet-virtual-web-application-patching/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security News Roundup: Can You Hear Me Now?</title>
		<link>http://blog.ambersail.com/news/security-news-roundup-can-you-hear-me-now/</link>
		<comments>http://blog.ambersail.com/news/security-news-roundup-can-you-hear-me-now/#comments</comments>
		<pubDate>Fri, 08 Mar 2013 19:06:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[smartphone]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=233</guid>
		<description><![CDATA[Sometimes, the price of success is unwanted attention. Witness the apparently stratospheric rise in malware on the Android mobile platform. With mobile usage continuing to explode, coupled with the vast array of valuable data we store and access from our phones, it should come as no surprise that the  bad guys want a piece of [...]]]></description>
				<content:encoded><![CDATA[<p>Sometimes, the price of success is unwanted attention. Witness the apparently stratospheric <a href="http://www.h-online.com/security/news/item/Report-Android-is-home-to-96-of-new-mobile-malware-1818594.html">rise in malware</a> on the Android mobile platform. With mobile usage continuing to explode, coupled with the vast array of valuable data we store and access from our phones, it should come as no surprise that the  bad guys want a piece of the action.</p>
<p>Why does Android seem prone to these issues? Part of the answer lies not in the technology, but in the end user. <a href="http://www.veracode.com/blog/2013/03/hacking-the-mind-how-why-social-engineering-works/">Hacking the human mind</a> continues to yield some rich pickings. Disappointingly, we just keep clicking on stuff without thinking. Where&#8217;s the patch for that?</p>
<p>We can&#8217;t help recalling the uproar a few years ago when &#8220;free&#8221; webmail services were all the rage. The big deal then was the realisation that these providers could <em>actually read your mail</em>. The very thought! Roll forward to the present day, and not only have we completely forgotten about that, we&#8217;re storing all sorts of data in all sorts of places, without a care in the world.</p>
<p>Lost or stolen USB keys, DVDs and  laptops were also big deal, but now that&#8217;s all <em>passé</em>.  Now we have an even better way to lose sensitive data that we shouldn&#8217;t even be storing in the first place. Yes, it&#8217;s <a href="http://convergingnetwork.com/?p=818">bring your own cloud</a>, the thoroughly modern approach to data storage that has done for data security what King Henry VIII did for gender equality.</p>
<p>Emails aren&#8217;t secure, data is at risk of compromise more or less all the time. What&#8217;s left?  The good old cellphone system. That&#8217;s probably secure. By &#8220;probably&#8221;, of course we mean &#8220;probably not&#8221;. Witness <a href="http://www.schneier.com/blog/archives/2013/03/how_the_fbi_int.html">this post via Bruce Schneier</a> highlighting the techniques used by the FBI in order to intercept phone data and track users. Very informative.</p>
<p>But is it controversial? An organisation that tracks your location, knows all your contacts, reads your emails and extracts data from your phone? This is, of course,  completely unheard of on the Internet. On a mobile phone. We&#8217;re sure you see our point here.</p>
<p>Let&#8217;s end with a summary. We&#8217;re using mobile platforms that are full of holes, to store data that we shouldn&#8217;t be storing, on cloud services that are insecure; whilst assorted governments, commercial organisations and bad guys all compete for access to that data, right in the palm of our hands.</p>
<p>Who says information security is boring?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/news/security-news-roundup-can-you-hear-me-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security News Roundup: The Demise Of The Human</title>
		<link>http://blog.ambersail.com/news/security-news-roundup-the-demise-of-the-human/</link>
		<comments>http://blog.ambersail.com/news/security-news-roundup-the-demise-of-the-human/#comments</comments>
		<pubDate>Fri, 01 Mar 2013 09:00:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[big data]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=221</guid>
		<description><![CDATA[With the US version of the RSA conference in full swing this week, we&#8217;re pleased to be able to present some signal despite the noise. It turns out that China is being hacked by the US. There, we said it. As they say, it takes two to tango, so we presume this comes as no great [...]]]></description>
				<content:encoded><![CDATA[<p>With the US version of the RSA conference in full swing this week, we&#8217;re pleased to be able to present some signal despite the noise.</p>
<p>It turns out that <a href="http://www.guardian.co.uk/world/2013/feb/28/china-cyber-attacks-military-website-us">China is being hacked by the US</a>. There, we said it. As they say, <em>it takes two to tango</em>, so we presume this comes as no great surprise to anyone. Except for governments outside of the US and China, who are no doubt feeling a little &#8220;hacker envy&#8221; right now. Don&#8217;t worry, one of the big guys will get round to you eventually.</p>
<p>The age-old &#8220;my system is more secure than your system&#8221; arguments still rage on.  In the latest twist to this interminable, intractable and possibly uninteresting discussion, a Microsoft partner <a href="http://www.zdnet.com/linux-windows-and-security-fud-7000011417/">has claimed</a> that Microsoft software is better patched than Linux software, under certain circumstances, with consideration given to other factors. All we can say is that we absolutely agree with that finding. Whatever it was.</p>
<p>Anyway, non-patches are not the only threat to security. Encryption experts agree that the current trust-based system of Certificate Authorities (the entities who digitally vouch for the authenticity of millions of  web servers) is not working as well as hoped, <a href="http://threatpost.com/en_us/blogs/rsa-conference-2013-experts-say-its-time-prepare-post-crypto-world-022613">and should be replaced</a>. Apparently, we need a system where people can choose who to trust. In other words, replacing one system that fails due to fundamental human weakness, with one where humans can make even more uninformed choices. That should work like a charm.</p>
<p>Speaking (indirectly, at least) of Achilles and his infamous heel, the word of the week is &#8220;sisyphean&#8221;. Of course we didn&#8217;t have to look it up; we instantly recognised that other <a href="http://en.wikipedia.org/wiki/Sisyphus">Greek mythological reference</a> which equates the task of doing proper security with the task of repeatedly pushing a giant boulder up a hill only to watch it roll back down again.  Many readers will no doubt identify with that job description. Have no fear, help is at hand.</p>
<p>In the future, big data analytics and advances in <a href="http://www.guardian.co.uk/news/datablog/2013/feb/27/big-data-science-combat-cybercrime">machine learning</a> will decide on our behalf what is friend, and what is foe. We simply don&#8217;t need to get involved. Perhaps the encryption experts we mentioned earlier have got it wrong &#8211; we shouldn&#8217;t be permitted to make trust-based decisions; as a species we&#8217;re simply not evolved enough to spot digital predators. A sobering thought, for sure.</p>
<p>But then, whilst we&#8217;re in the mood for classical references, <em>Quis custodiet ipsos custodes?</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/news/security-news-roundup-the-demise-of-the-human/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security News Roundup: Chinese Take-away</title>
		<link>http://blog.ambersail.com/news/security-news-roundup-chinese-take-away/</link>
		<comments>http://blog.ambersail.com/news/security-news-roundup-chinese-take-away/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 14:30:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=211</guid>
		<description><![CDATA[The biggest story this week. Chinese military unit behind &#8216;prolific and sustained hacking&#8217; says security report.  A highly-skilled team of intelligence gatherers working systematically to steal confidential information from organisations around the globe?  Shocking stuff &#8211; we can&#8217;t imagine for a moment that our government is doing the same thing. But things move fast in the murky [...]]]></description>
				<content:encoded><![CDATA[<p>The biggest story this week. Chinese military unit behind &#8216;prolific and sustained hacking&#8217; <a href="http://www.guardian.co.uk/world/2013/feb/19/chinese-military-unit-prolific-hacking">says security report</a>.  A highly-skilled team of intelligence gatherers working systematically to steal confidential information from organisations around the globe?  Shocking stuff &#8211; we can&#8217;t imagine for a moment that our government is doing the same thing.</p>
<p>But things move fast in the murky world of  attack and counter-attack. The widely-touted report  itself  has become a security risk, and is being used as <a href="http://www.theregister.co.uk/2013/02/22/apt1_report_used_spear_phishing/">bait in a phishing attack</a>.  Naturally, that&#8217;s the level of entrepreneurial, free-market thinking that one automatically associates with communist China.</p>
<p>Speaking of Chinese ingenuity, malware is getting smarter says <a href="http://news.cnet.com/8301-1009_3-57570534-83/malware-getting-smarter-says-mcafee/">anti-virus vendor McAfee</a>; a revelation that presumably comes as no surprise to competitor Symantec, whose own products apparently failed to spot (and here&#8217;s that phrase again) the prolific and sustained <a href="http://www.forbes.com/sites/andygreenberg/2013/01/31/symantec-gets-a-black-eye-in-chinese-hack-of-new-york-times/">hacking of the NY Times</a>. Can anyone else see a pattern emerging here?</p>
<p>If security products can&#8217;t help us, we have to defend ourselves against the data breach apocalypse. Better not start with Sharepoint then. According to a recent survey, two thirds of Sharepoint users <a href="http://www.infosecurity-magazine.com/view/30870/a-hackers-dream-twothirds-of-sharepoint-users-have-no-security-policy/">have no security policy</a>.  We know it&#8217;s called Sharepoint, but really there are some things that one shouldn&#8217;t be sharing. Like the fact that you have no security policy, for example.</p>
<p>Finally, if that&#8217;s not apocalyptic enough, we now know that the emergency TV broadcast systems used to address the US public in the event of a real apocalypse are riddled with default passwords and other poor configuration choices. We know this because during a recent spate of zombie uprisings across three US states, community-spirited citizens were able to alert the general public to the <a href="http://www.theregister.co.uk/2013/02/18/eas_vulns/">imminent danger posed by the walking dead</a>.</p>
<p>What a relief.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/news/security-news-roundup-chinese-take-away/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Logging &amp; Top 20 Default Username Attempts</title>
		<link>http://blog.ambersail.com/security/logging-top-20-default-username-attempts/</link>
		<comments>http://blog.ambersail.com/security/logging-top-20-default-username-attempts/#comments</comments>
		<pubDate>Mon, 18 Feb 2013 18:35:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=175</guid>
		<description><![CDATA[ It&#8217;s true to say that default or weak passwords remain a significant cause of compromise and data loss for many organisations. For years, lists of default usernames and passwords have been widely available (and indeed are a useful resource for penetration testers as well as the less ethically motivated). Whilst it&#8217;s great to focus on [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://blog.ambersail.com/wp-content/uploads/2013/02/ssh-login-graph.jpg"><img class="wp-image-190 alignleft" alt="ssh login graph" src="http://blog.ambersail.com/wp-content/uploads/2013/02/ssh-login-graph-300x290.jpg" width="216" height="209" /></a> It&#8217;s true to say that default or weak passwords remain a significant cause of compromise and data loss for many organisations. For years, lists of default usernames and passwords have been widely available (and indeed are a useful resource for penetration testers as well as the less ethically motivated).</p>
<p>Whilst it&#8217;s great to focus on weak passwords, let&#8217;s not forget that a weak password usually needs a corresponding username to make it useful to the attacker.</p>
<p>This is why the logging of invalid access attempts is useful not just from a compliance perspective, but can also provide valuable insight in to which accounts are being targeted in the wild. If you can see an account access attempt in your log that isn&#8217;t covered by your strong password policy, be prepared to act promptly to remediate.</p>
<p>To illustrate this point, we&#8217;ve taken sample log data from our own systems. Specifically, invalid login attempts against one of our Secure Shell (SSH) services from the end of January 2013 to date. In all we logged <strong>12,317 unsuccessful attempts using 1331 user names</strong>.</p>
<p>The graph (click image to enlarge) we&#8217;ve included shows the top 20 most popular usernames attempted during that period, which were:</p>
<blockquote>
<pre>oracle,test,mysql,support,tomcat,user,www,guest,upload,test2,tester,test1, testing,ftpuser,postgres,nagios,info,anna,cyrus,web</pre>
</blockquote>
<p><span style="line-height: 1.714285714; font-size: 1rem;">The findings from our small sample show that whilst the most popular targets remain the generic service accounts such as &#8220;oracle&#8221;, &#8220;tomcat&#8221;, &#8220;ftpuser&#8221; and so on, the targets are by no means all generic. Further down our list there are many end-user names, such as &#8220;mark&#8221;, &#8220;lauren&#8221; and &#8220;steven&#8221;.</span></p>
<p>In summary, logging can provide you with insight that extends beyond confirming who&#8217;s logging on to your system. A record of invalid access attempts provides a valuable additional checklist to confirm the coverage of your strong password policy.</p>
<p>You can download our complete anonymous data set <a href="http://blog.ambersail.com/wp-content/uploads/2013/02/ssh-login-attempts.xlsx">here</a>.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/security/logging-top-20-default-username-attempts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Cloud Computing Guidelines</title>
		<link>http://blog.ambersail.com/pci-dss/pci-dss-cloud-computing-guidelines/</link>
		<comments>http://blog.ambersail.com/pci-dss/pci-dss-cloud-computing-guidelines/#comments</comments>
		<pubDate>Fri, 08 Feb 2013 14:37:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[cloud]]></category>
		<category><![CDATA[pci dss]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[pci]]></category>

		<guid isPermaLink="false">http://blog.ambersail.com/?p=168</guid>
		<description><![CDATA[A new guidance document from the PCI SSC provides useful information about the use of Cloud Service Providers (CSPs) and how this may affect PCI compliance. Although cloud computing feels like a new thing, the issues about responsibility for cardholder data are certainly not new. Related issues, such as nebulous (pun intended) statements about PCI [...]]]></description>
				<content:encoded><![CDATA[<p>A new guidance document from the PCI SSC provides useful information about the use of Cloud Service Providers (CSPs) and how this may affect PCI compliance.</p>
<p>Although cloud computing feels like a new thing, the issues about responsibility for cardholder data are certainly not new. Related issues, such as nebulous (pun intended) statements about PCI compliance from a CSP need to be qualified, and mutual responsibilities clearly established.</p>
<p>Actually, this new document echoes some guidance that we&#8217;ve been publishing for a while now. Have a look at <a href="http://blog.ambersail.com/pci-dss/pci-compliance-claims-3-questions-you-must-ask-2/">PCI Compliance Claims: 3 Questions You Must Ask</a> for example. More recently, we published a 10 minute video entitled <a href="http://blog.ambersail.com/security/video-penetration-testing-the-cloud/">Penetration Testing &amp; The Cloud</a>, which is an ideal management introduction to the subject, even if PCI DSS isn&#8217;t on your radar.</p>
<p>The SSC document is available <a href="https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_Cloud_Guidelines.pdf">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ambersail.com/pci-dss/pci-dss-cloud-computing-guidelines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
