Category Archives: Security

Encryption and NV SB 227

Nevada’s Senate Bill 227 came into effect January 1, 2010. It sets a new pace for regulations by defining encryption as “protection of data in electronic or optimal form, in storage or in transit”

(b) “Encryption” means the protection of data in electronic or optical form, in storage or in transit, using:

(1) An encryption technology that has been adopted by an established standards setting body, including, but not limited to, the Federal Information Processing Standards issued by the National Institute of Standards and Technology, which renders such data indecipherable in the absence of associated cryptographic keys necessary to enable decryption of such data; and

(2) Appropriate management and safeguards of cryptographic keys to protect the integrity of the encryption using guidelines promulgated by an established standards setting body, including, but not limited to, the National Institute of Standards and Technology.

Strange that they leave it open-ended what an established standards setting body might include. They will leave it to lawyers to decide, I suppose.

Also strange is that this is far more specific than the Nevada state breach law, SB 347, which requires data only to be made unintelligible (based on the definition in NRS 205.4742).

The law forbids the transfer of personal information or data storage device containing personal information without the appropriate encryption. Devices that must use encryption include cell phones, computers, computer drives and magnetic tape. Compliance with other standards such as PCI DSS, HIPAA, GBLA or FISMA will not be considered sufficient for SB 227.

Step in the right direction? Yes. Perfect? No.

Silent Patches

I wrote about undisclosed or silent patches earlier, with regard to Microsoft and Google.

Another consulting firm now has made a public announcement about the same issue.

Microsoft silently patched three vulnerabilities last month, two of them affecting enterprise mission-critical Exchange mail servers, without calling out the bugs in the accompanying advisories, a security expert said today.

Two of the three unannounced vulnerabilities, and the most serious of the trio, were packaged with MS10-024, an update to Exchange and Windows SMTP Service that Microsoft issued April 13 and tagged as “important,” its second-highest threat ranking.

I still give Microsoft credit for improving its practices significantly over the years. This is only a slight twist on that same issue. The risk determination is what the consulting firm is complaining about, rather than a patch with no evidence or notice as in the case of Google. The firm contends that Microsoft “‘misrepresented’ and ‘underestimated’ the criticality” of a patch. Microsoft has countered that the fixes were documented and would have been installed within the larger group of released patches.

The Zeldon Morris Worm

Computerworld reports an IT contractor gets five years for $2M credit union theft

A man named Zeldon Morris was hired as an IT contractor by four credit unions. Instead of just helping them he also set himself up to receive unauthorized deposits.

In all Morris admitted to stealing about $1.2 millions from First Family, about $82,000 from Alpine, about $635,000 from Deseret and $93,000 from First Credit.

According to court documents the thefts are likely to have gone unnoticed for some time if it had not been for Morris’ partner who alerted Family First of unusually large ACH deposits being made into the joint business account.

The thefts would have gone unnoticed if his partner had not turned him in?

I was asked the other day by a reporter why fraud still happens when so many people know it exists. Great question. My answer may be published in the Sunday paper.

Power(less)Point and Security

SIEM (or SEM or SIM) vendors surely cringe when they read articles like yesterday’s NYT piece called We Have Met the Enemy and He Is PowerPoint

PowerPoint makes us stupid, Gen. James N. Mattis of the Marine Corps, the Joint Forces commander, said this month at a military conference in North Carolina. (He spoke without PowerPoint.) Brig. Gen. H. R. McMaster, who banned PowerPoint presentations when he led the successful effort to secure the northern Iraqi city of Tal Afar in 2005, followed up at the same conference by likening PowerPoint to an internal threat.

It’s dangerous because it can create the illusion of understanding and the illusion of control, General McMaster said in a telephone interview afterward. Some problems in the world are not bullet-izable.

Ouch. Although true, McMaster has himself just boiled down the problem into a bullet-ized sound bite. Hypocritical? No, the difference really is in quality versus quantity. Illustration is essential when done properly. Tufte has made this very point for many years in his books:

Tufte on PowerPoint

Keep this in mind the next time you are asked by a vendor to look at a dashboard or a report, especially for a product that includes the word management in its title (e.g. SIEM, SEM, SIM).

Does a management or presentation tool really save time or clearly illustrate the point(s) you need to know?

The best way to find out is to perform some simple tests. Prop open a door and then ask to see the alarm on the system. Run a scan, not even a stealthy one, and ask to see the alarm on the system.