Tuesday, September 30, 2014

Further flaws in Bash Require Further  More Patching

Google security researcher Michael 'lcamtuf' Zalewski says he's discovered a new remote code execution vulnerability in the Bash parser (CVE-2014-6278) that is essentially equivalent to the original Shellshock bug, and trival to exploit. "The first one likely permits remote code execution, but the attack would require a degree of expertise to carry out," Zalewski said. "The second one is essentially equivalent to the original flaw, trivially allowing remote code execution even on systems that deployed the fix for the initial bug," he added.

ISMS Defined in terms of security

ISMS can be defined as the processes used by management to organize and coordinate security activities like governance, risk management, continuous improvement, internal audit, record keeping, document management, compliance management, communications, and awareness training. ISMS is defined in detail within mandatory clauses 4 - 10.

ISMS mitigates a series of common risks to information management but applying an internationally set of control objectives listed in Annex A. Annex A is an appendix of ISO 27001. Annex A control objectives are discretionary and can be risk justified in or out of scope.

There are over 140 contributing countries and thousands of information security professionals over a period of two years that rationalized and contributed to the latest version ISO 27001:2013. Since its inception in 1995 as BS7799 and then ISO 17799 there have been thousands more to establish ISO 27001 as the only internationally accepted information security management framework standard.

Monday, September 29, 2014

Is that true NSA Patents are available to buy

There's a new article on NSA's Technology Transfer Program, a 1990s-era program to license NSA patents to private industry. I was pretty dismissive about the offerings in the article, but I didn't find anything interesting in the catalog. Does anyone see something I missed?
My guess is that the good stuff remains classified, and isn't "transferred" to anyone.

Quest to Open-Source Cancer Research

Isaac Yonemoto is a chemist, but he’s been writing software code since he was a kid. He calls himself a “semi-recreational” programmer, and now, he’s running an experiment that combines this sideline with his day job. In short, he’s using open source software techniques to kickstart the world of cancer research.

 

Sunday, September 28, 2014

Security Concern with icloud

This is a good essay on the security trade-offs with cloud backup:
iCloud backups have not eliminated this problem, but they have made it far less common. This is, like almost everything in tech, a trade-off:
  • Your data is far safer from irretrievable loss if it is synced/backed up, regularly, to a cloud-based service.
  • Your data is more at risk of being stolen if it is synced/backed up, regularly, to a cloud-based service.
Ideally, the companies that provide such services minimize the risk of your account being hijacked while maximizing the simplicity and ease of setting it up and using it. But clearly these two goals are in conflict. There's no way around the fact that the proper balance is somewhere in between maximal security and minimal complexity.
Further, I would wager heavily that there are thousands and thousands more people who have been traumatized by irretrievable data loss (who would have been saved if they'd had cloud-based backups) than those who have been victimized by having their cloud-based accounts hijacked (who would have been saved if they had only stored their data locally on their devices).
It is thus, in my opinion, terribly irresponsible to advise people to blindly not trust Apple (or Google, or Dropbox, or Microsoft, etc.) with "any of your data" without emphasizing, clearly and adamantly, that by only storing their data on-device, they greatly increase the risk of losing everything.
It's true. For most people, the risk of data loss is greater than the risk of data theft.

Shellshock Vulnerability Gone Wild

It's a big and nasty one.
Invariably we're going to see articles pointing at this and at Heartbleed and claim a trend in vulnerabilities in open-source software. If anyone has any actual data other than these two instances and the natural human tendency to generalize, I'd like to see it.

Patient Record Worth More Than Credit Card Value

There's a Reuters article on new types of fraud using stolen medical records. I don't know how much of this is real and how much is hype, but I'm certain that criminals are looking for new ways to monetize stolen data.