Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

Monday, 31 August 2015

Cloud services, Multi-factor authentication and the death of the security question

Mainstream news has covered many compromises of internet facing services over the last five years.  This has included compromises of email systems, retail outlets, Internet auction sites and last year Apple's iCloud service, which led to a number of private photographs being exposed to the public.  The first assumption was that iCloud was hacked or compromised, which Apple denied.

Accounts Compromised

Rather than iCloud in its entirety being compromised, the compromise was to individual accounts.  It is assumed that the celebrity accounts were compromised with a brute force attack, allowing multiple tries of various passwords to each account.  This meant with the right software toolset which could be acquired cheaply, meant that numerous passwords could be tried against each account.

Simple Passwords

Despite education from service providers and IT departments, the most commonly used passwords in a recent 2014 survey are "123456" and "password"!  With relatively simple passwords or common words, the password can easily be compromised quickly using a dictionary attack in a matter of seconds.

Security (?) Questions

There are many ways to recover a password.  It may be to request a new password and the service delivers the new password or asked for confirmation via an out of bound method, such as the registered email address or registered mobile number via SMS.  There may be a need to telephone a call centre and provide details over the telephone to reset your password.  The least secure is the ability to answer security questions that the user has the answer. 

It may seem like a secure way of resetting a password, as how many people would know your mother's maiden name, where you were born, what your favourite football team is, etc?  The internet and social media has been great in many respects, but it exposes a lot of information about an individual out into the wild.  Once it's out there, there is no way to control, edit or delete it.  Bear this in mind if you have to use to methodology for any website or application.

It would seem that this current compromise is a new thing, but something very similar happened over ten years ago when Paris Hilton's mobile phone was hacked in 2005.  How was this done?  The T-Mobile Sidekick device had an internet facing dashboard.  If you forgot your password, you could answer some security questions including date of birth and your pet's name.  All the security questions could be answered with an internet search engine.

Even before then, hackers were wise to how to gather this sort of personal information.  Around 15 years ago, there were email chains on how to generate your pornstar name.  You took your first pet's name and combine it with your mother's maiden name.  Information such as "Fido Jones" would have been very useful!

Complex Passwords, hard to remember?

As the levels of security have to rise, so this can only make it more difficult to use the services or applications.  There is always a balance between usability and complexity.  We can encourage people to use a mixture of upper and lower case, special characters and numbers, but will only mean more password resets these complex passwords will be forgotten more easily.

Also common advice is not to use the same password over multiple applications and services.  This only increases the users capacity to forget a password!

Phishing

Even with strong and complex passwords in place, the user can still be a victim of a phishing attack.  We are reminded to check the legitimacy of an email before acting on it, and if it seems fishy (excuse the pun) to ignore it or delete it. Many people have fallen for one of the simplest tricks, as the email looks so legitimate.

The bad guy sends out emails that looks like an email from the service provider.  It tells the user that there is some sort of issue with the account that requires a password reset/change/confirmation.  The user will enter their password which is stored by the bad guy.  The user will be presented with either a failed message screen, a confirmation all is OK and if they were clever, even synchronise the password with the service provider, so all seems right for the user.

Multi Factor Authentication

There are various ways or factors, when authenticating users.  So one form this can take is "Something you know", where the information is known, such as username, password, PINs and patterns.  

Another form this information can take is "Something you're given", where the information is provided to the user through technology, such as a passcode from a token, a passcode from a device such as a smartphone or computer, or a passcode set via SMS to a known mobile telephone number.  If the known information and the provided information are different types of information, or factors, it becomes clear where the term two factor authentication comes from.  

Other factors can include "Something you are" through the use of biometrics, through iris scans, fingerprint readers, voice recondition and other forms tied to the physicality of the user.  There also ways of analysing "Somewhere you are" through the use of geolocation, thereby allowing or denying access by the users location.

A combination of these authentication methods, or factors create Multi Factor Authentication (MFA)

Proof and compliance

With the factors of authentication described above, it would be harder for a hacker to access the service or website, but would also make it hard to deny an action.  Many online banking systems uses a combination of passwords, PINs, tokens, SMS and unique codes to ensure transactions are genuine.  By using multi factor authentication, the processes within compliance processes can be tied to specific users and the actions cannot be denied.

Free protection

Service providers such as Apple's iCloud, GMail, eBay and Facebook give the option to switch on two-step verification, where if you try to login from a new device, a new browser or a different country, the user will be prompted to enter a code that is sent to the registered mobile phone number.  The security is there and it's free.

The use of multi factor authentication is accepted as commonplace and widely used for by users for personal services, such as email and banking.

Consumerisation

Recent technology adoption within a corporate environment has been driven by domestic technology.  The rise of wireless, tablet and mobile computing has been driven from the use of these technologies within the domestic environment.

There is often a concern that the user community with an organisation struggles with new technology, but it's often the enforcement of unfamiliar technology that causes the user to become disengaged.

The use of multi factor authentication can only strengthen a network or website, and with this technology used for personal consumption, the use corporately will offer less resistance from the user community, especially if there is a familiarity with the technology.

Cloud Support

As more corporate applications move to the Internet, cloud security becomes the concern of every IT Manger, IT Director, CSO, CISO, and in fact every member of an executive team.

As cloud based applications such as Salesforce and Microsoft Office 365 become popular, it is essential to remember these applications are the very lifeblood of an organisation.  The need for security and multi factor authentication become more apparent when looking to protect these web based applications. There are protocols such as SAML designed to support cloud applications, and offer multi factor authentication.

Impact to the business

A poorly designed or poorly designed solution will impact the user adoption of any technology, but a familiar system will offer acceptance and executive sponsors.  Security is high on the executive boards agenda, so the impact of a compromise or a disgruntled employee is greater than financial considerations such as return on investment. 

Multi factor authentication is not new, but is an obvious solution the the many security challenges for organisations, whether the data and applications are located on premise, in data centres, in public cloud, in private cloud or a hybrid approach.  Security is no longer the concern of technical sponsors, but of the Executive Board.

Familiar security solutions such as Multi Factor Authentication, can only increase the security posture of an organisation, protecting the data and reputation of an organisation. 

Thursday, 4 September 2014

iCloud Compromise...

The mainstream news has covered the compromise of iCloud, which led to a number of private photographs being exposed to the public.  The first assumption was that iCloud was hacked or compromised, but Apple denies this.

Accounts Compromised...

Rather than iCloud in its entirety being compromised, the compromise was to individual accounts.  It is assumed that the celebrity accounts were compromised with a brute force attack, allowing multiple tries of various passwords to each account.  This meant with the right software toolset which could be acquired cheaply, numerous passwords could be tried against each account.

Simple Passwords...

It would seem that celebrities are very much like the general public when it comes to passwords.  There are commonly used passwords, the top 25 of 2013 can be found here.  From that article you see the commonly used passwords are "123456" and "password"!  With relatively simple passwords or common words, they can easily be compromised using a dictionary attack

Security (?) Questions...

There are many ways to recover a password.  It may be requested a new password which the site or application will ask you to subsequently change.  There may be a need to telephone a call centre and provide details over the telephone to reset your password.  The least secure in my opinion, is the ability to answer security questions that the user has the answer.

This would seem like a secure way of resetting a password, as how many people would know your mother's maiden name, where you were born, what your favourite football team is, etc?  The internet and social media has been great in many respects, but it exposes a lot of information about an individual out into the wild.  Once it's out there, there is no way to control, edit or delete it.  Bear this in mind if you have to use to methodology for any website or application.

It would seem that this current compromise a is new thing, but something very similar happened over nine years ago when Paris Hilton's mobile phone was hacked in 2005.  How was this done?  The T-Mobile Sidekick device had an internet facing dashboard.  If you forgot your password, you could answer some security questions including date of birth and your pet's name.  All the security questions could be answered with an internet search engine.

Complex Passwords, hard to remember?

As the levels of security have to rise, so this can only make it more difficult to use the services or applications.  There is always a balance between usability and complexity.  We can encourage people to use a mixture of upper and lower case, special characters and numbers, but will only mean more password resets these complex passwords will be forgotten more easily.

Also common advice is not to use the same password over multiple applications and services.  This only increases the users capacity to forget a password!

Phishing...

News has come to light this morning that rather than a brute force attack, it may have been a phishing attack.  We are reminded to check the legitimacy of an email before acting on it, and if it seems fishy (excuse the pun) to ignore it or delete it.  Some celebrities may have fallen for one of the simplest tricks.

The bad guy sends out emails that looks like an email from Apple.  It tells the user that there is some sort of issue with the account that requires a password reset/change/confirmation.  The user will enter their password which is stored by the bad guy.  The user will be presented with either a failed message screen, a confirmation all is OK and if they were clever, even synchronise the password with Apple, so all seems right for the user.

Two Factor Authentication...

I have written a few blog posts in the past regarding passwords and multi-factor authentication, but it's relevant to re-cap it.  It we look at the different types of information that can be used to log a user in, we can take different types of information in order to increase security.  So one form this can take is information the user knows, such as username, password, PINs and patterns.  Another form this information can take is information a piece of technology gives the user, such as a passcode from a token, a passcode from a device such as a smartphone or computer, or a passcode set via SMS to a known mobile telephone number.  If the known information and the provided information are different types of information, or factors, it becomes clear where the term two factor authentication comes from.

Free protection...

I've mentioned it before, but service providers such as Apple's iCloud, GMail, eBay and Facebook give the option to switch on two-step verification, where if you try to login from a new device, a new browser or a different country, the user will be prompted to enter a code that is sent to the registered mobile phone number.  The security is there and it's free!

Increase your security posture

Be aware of the security questions you choose to to use.  Are the answers to your security questions available from the likes of Facebook and Twitter?

Be aware of emails asking for password changes.  Double check with the service provider.

If you want to use more complex passwords, but are worried about remembering them all, use a password vault to store these passwords securely.

Although two factor authentication may add a slight delay to using the service, it gives a level of protection that will make it a lot more difficult to compromise your personal information, your data and in this case, your personal photos.

Sunday, 23 March 2014

The Myths and Reality of the "Cloud"

As an Information Security Professional, I am often asked by people “What is the Cloud?”  My answer depending on the audience is that it’s a marketing term to cloud (please excuse the pun) the technology that is used, where your data or application is held on someone else’s computer.

The term cloud was popularised in general culture, thanks to Apple and their iCloud to allow your Apple devices to be backed up into an offsite location.  Terms such as cloud computing have been used by Google, Microsoft and Salesforce, who give application access without having to connect to servers within your organisation.  We hear of terms such as Cloud Backup, where your data much like the Apple iCloud principle, is held in an offsite location.

As I say, I believe Cloud is an all-encompassing marketing term, rather than the saviour to all our IT woes.  In the not too distant past, there were terms like, Software as a Service (SaaS), Infrastructure as a Service (IaaS) and Platform as a Service (PaaS), which described the solution being provided.

With the popularity of the term Cloud, a number of solution providers have jumped onto the bandwagon, leveraging the good work and good name form the likes of Apple, Google and Microsoft, and using it for their own gain.  Let me explain…

Cloud technology should deliver the following:

Uptime
Delivered via multiple servers and multiple datacentres, with the various failovers in place.
Security
Meeting a number of compliancy regulations, delivered through processes, procedures, physical security, virtual security, encryption, firewalls, etc.
Environmental
Reducing the environmental impact of their datacentres, utilising renewable energy sources, or local environment resources, such as geothermal cooling in Iceland.
Reduce Costs/Change Payment Models
Delivering true lower TCO or real ROI, as well moving from a CAPEX payment model to an OPEX payment model helping company cash flow.
“A La Carte” Approach
It should not be an “all or nothing” approach to moving services to the Cloud.  With any technology that breaks from the norm (and Cloud technology is that to most people), there have to be easy transitional steps, moving only the solutions that make sense.

This is the reality for a number of the larger brands or organisations with integrity and the mission to deliver a quality solution.  The issue will come when less reputable or companies with less integrity want to join the Cloud bandwagon, and the above points are compromised or neglected.

I have heard of Cloud organisations running applications on single servers, in a single datacentre.  I use the term datacentre loosely, as under-stair cupboard may be a better description.  Data security is often compromised, as it’s seen as a cost with no visible or immediate benefit.  Some providers insist the movement for all applications and infrastructure, whether it’s appropriate or not.  There are many providers who struggle with incremental billing, insisting that one, two or even three years are paid upfront prior to implementation.

There have also been examples of service providers going out of business where the Cloud technology was shut down or even held to ransom.  With the importance of the application and more so your data, what contingencies would you have in place if this were to happen.

There are some real benefits to moving to the Cloud, if done appropriately and with due diligence.  Just be aware there are some less than reputable organisations selling Cloud solutions, being delivered by “smoke and mirrors” rather good infrastructure, good processes and procedures, good security and a company is good financial standing.

Don’t be afraid to ask questions and if it doesn't feel right, don’t use them, your organisation depends on it!

Thursday, 26 January 2012

Is Two-Factor Authentication a commodity?

The complexity with passwords

We all know we need secure passwords, or at least keep them secret.  The problem is that we are asked to increase the complexity of passwords, either with the addition or inclusion of upper case characters, lower case characters, special characters or numbers.    Making the passwords more complex must increase security… or does it lead to users writing the passwords down or recycling the same passwords for a number of environments?

“Something you know, Something you are given, Something you are”

Obviously one of the downsides with passwords is that they can be passed from person to be person, but you lose the accountability of the actions from the user who has logged in.  This is where the requirement for multi-factor authentication arose, so there would be a number of elements to confirm the validity of the person and action.

Multi-factor authentication is said to be made up with two of the follow three elements.  “Something you know”, such as passwords and PINs, “Something you are given”, such as one time passwords, and “Something you are”, such as iris and fingerprint scans.

Some people will such that using multiple of the same type of authentication, such as the use of multiple passwords and PINs, would make it multi-factor.  I disagree, and would call that “Strong authentication” or I’ve heard of it referred to as “1.5 factor authentication”. 

Two-Factor Authentication requires a specialist?

In the past, there was a high level of complexity associated with two-factor authentication and should only be tackled by specialists within the field.  In the past, there were complicated multi-server implementations to build resiliency, administering more databases, managing a variety of tokens and that even before anything is deployed or secured!!

Hacked… June 2011!

Undoubtedly, most people reading this will be aware of a compromise that was reported in June 2011, where one of the world’s largest token vendor had (reportedly) 40 million tokens compromised.  Suddenly all that hard works seems to have been for nothing.  What did all the complexity bring, other than complexity for complexities sake?

Commoditised market?

There are a number of vendors offering two-factor authentication, but most organisations see it as a must have, rather than a want to have.  The barriers to entry were not only complexity, but security, administration time and in the current economic climate, cost.

Cloud or On-premise?
A cloud service will reduce the hardware cost, the running cost, power, energy, and all the other benefits associated with moving to a host solution.  There is always a concern about physical security, so ensure the provider meets the right criteria and standards.  There will be concerns around uptime, so ensure there is a good SLA in place.  With data security, ensure data is encrypted and not sent to the internet in clear text.

If these concerns are insurmountable, then look at an on-premise solution, but ensure the solution is highly available, if the access is business critical.  Ensure that the administrators looking after the solution can manage it correctly, or have the relevant support contracts to provide this.

It would be useful to have a choice of platforms, whether it is cloud or on-premise.

Ease of use?
In most IT environments we have to manage multiple systems, so we all want an easy to use system.

An intuitive, simple to use management console, with good help features, as well platform parity between the cloud and on-premise solution would be the way forward.

Token options?
Some providers will only offer hardware tokens, some will offer software tokens, some will offer tokens to run on mobile devices, some will offer SMS and/or email tokens, some will offer OATH tokens, and some will offer grid tokens.

What does your user base need?  What mix of tokens is required?  Will there be a company policy to define the type of tokens that will be offered?  What sort of mobile phones need to run tokens?

The preference would be to have all the token types available, but have them at an attractive price point.

Event or Time-based?
To simplify the way a one-time password is generated.  With time based, it take the time, encrypts it using a seed and an algorithm, to generate the one-time password.  With event base, it takes a pseudo-random value encrypts it using a seed and an algorithm, to generate the one-time password.

There are arguments for both solutions, with the time-based potentially going out of sync, or event-based where the password is valid until it is used.  More of a concern is the seed that are pre-populated onto the token, as if that were compromised; someone with it can potentially generate your one-time password!

Ideally, you want to ability to choose either time-based or event-based authentication, and have the ability to generate your own seeds, so even the two-factor authentication vendor would not know it.

Authentication Methods?
Most solutions support RADIUS; some will support Windows logon; some will support integration with OWA, SharePoint, IIS, Apache; some will support Citrix; and occassionally support SAML.
You don't want to be limited with what you can authenticate with, but want a solution that will support standards such as SAML, as this will be used more and more as cloud application usage increases.

Longevity?
With so many new start-ups and small organisations now around, and the largest two-factor authentication vendor being compromised, it is difficult to know who to trust!

We want a vendor with a good security history, but with the foresight to innovate, develop and implement solutions for the future.

Cryptocard
Offering a cost effective solution, with large variety of tokens, with the ability to choose either a cloud-based or on-premise platform, with an easy to use interface, the ability to have either time-based or event-based tokens, the ability to populate the tokens with your own seed, support a large number of applications and standards, from a company that has been around for over 21 years, makes Cryptocard the solution that should be considered first.

Thursday, 20 October 2011

“To The Cloud…”


For the last year or so, it seems marketing people have moved away from terms such as “... as a Service”, and replaced the words with Cloud.

We are seeing hosted applications, hosted infrastructure, hosted servers, hosted platforms, managed services, VPNs, MPLS networks, distributed networks, hosted virtual servers, remote VDI solutions, all termed with the phrase Cloud.

I understand the drivers that are used to move services out of your own server room, by lowering infrastructure costs, moving capital expenditure to operational expenditure, upgrading or downsizing by modifying your service plan, removing running costs (such as air conditioning, trained server administrators, etc.), having your systems monitored and changing applications on the fly.

I have a few issues with Cloud offerings, which include:

Authentication
  • How do users connect to the solution? 
  • Are they using a username and password?  

There are many issues around authentication, such as weak or insecure passwords, using common words, using easy to guess words (such as favourite bands, football teams, children’s names, car, etc.) and that’s before the fact the password can be told to someone else. 

People often talk about multi-factor authentication, but to surmise it, the factors are “something you know” such as passwords and PINs, “something you’re given” such as a one time passwords from a token, or “Something you are” where biometric devices are used to read fingerprints or iris scanners.

A combination of two of these will be known as two factor authentication, where passwords are coupled with a token generated one time password, offering much improved security.

Encryption
  • How is your data protected?
  • Who has access to your data?

With the Information Commissioner’s Office issuing fines of up to £500,000 for the loss of personal data, it is more critical than ever data is encrypted. 

I would expect the data to be encrypted with to a minimum level of 256-bit AES, although another consideration who has access to your data.  It may be encrypted, but if the key is held by the service provider, then they will have the ability to decrypt your data.

Backup and Archive
  • Is the data backed up?
  • Is the data archived?

Your data should be backed up regularly, giving a point in time that the data can be restored to.  The issue with back up is that it will back up current data, but the ability to roll back and restore can be more destructive and time consuming than working round the missing/lost/corrupted data.

If your data was archived, then it would offer the ability to manage and archive all versions of the data.  Archiving is driven by compliancy and traceability, rather than disaster recovery.

Access to the service
  • Where can you access the data from?

It would be great to be able to access your service from anywhere in the world, wouldn’t it?  A concern is that although this great for remote users, should everyone be able to have access?  Data security may dictate that the service or data should not be access from non-trusted IP addresses, or by specific users or during specific times.  If this level of control is required, ensure your provider is able to deliver this.

Disaster Recovery
  • Are there multiple servers hosting your service?
  • Are there multiple datacentres hosting your service?

One of the draws with a Cloud offering include having your applications and services available from anywhere, so there perfect disaster recovery solution.

The issue will be when the provider has a server failure.  Will they be able to move your service to a new server in a timely fashion?  Whether the services are being run on virtual or physical servers, ensuring your service up time is vital. 

Another concern will be if the provider only has one datacentre or one WAN connection, so if there service is delivered well I would expect multiple datacentres, with multiple links running an active/active configuration, along with an active/active or active/passive server configuration.

Conclusion
My concern with Cloud solutions is the number of providers who are “jumping on the bandwagon” offering cloud services as quickly as possible.  The issue is that some providers offer very favourable pricing, but the infrastructure may not be in place until there is some uptake.  This can only be a bad thing for the early adopter, especially if it is not making money and they stop the service or become bankrupt.

My advice is to proceed with caution, check the provider thoroughly and try not to be price driven.