Thursday, June 13, 2019

BlueKeep.... the new silent killer affects thousands of Canadian Internet facing systems

Surely you must have heard that the next wave of attacks will come through a newly minted and named vulnerability called BlueKeep.  

BlueKeep

Lets keep the cool names coming.

So as part of a research project, the 70+ million Canadian IP addresses were scanned by someone I know... cough cough.... for port 3389 which hosts the progressively more famous and exploitable Microsoft RDP service.   

Now keep in mind that many have multiple RDP services scattered across numerous ports, so 3390, 3391,....  but only 3389 was tested.  It is a certainty that many move RDP services are exposed on the Internet

For RDP3389: 102,434 systems responded and are facing the Internet today.

Just sitting there, handing over valuable information.

As an example, just grabbing an RDP screenshot can give you pictures, but more importantly usernames and OS versions.


 

So obviously giving away your OS version along with usernames isn't ideal, but having an exploitable operating system that has not been patched sitting on the Internet is even less ideal. 

So I asked my "friend" to test out the 102 thousand IP addresses to see how many would be exploitable.....

Drum roll please

Over 10,000 Internet facing systems in the Canadian IP range remain exploitable even after significant media coverage.

These devices will more than likely be hit by malware in the coming weeks since finding them does not require ANY real technical skill, and the exploits for BlueKeep are being weaponized as we speak.

Here are the actual statistics:


            IP ADDRESSES IN CANADA: 71.9 Million
            PORT 3389 IN CANADA: 102,434    
            * Note:  RDP can be found on other ports, we only tested 3389
            SAFE: 66,758 
            * But still shouldn't be open on port 3389 facing the Internet
            UNKNOWN: 17,116
            * Tests did not conclude
            VULNERABLE: 10,351

Even the NSA is pushing news articles about how bad these attacks will be.  After all, they don't want everyone using the exploit now that they can't be the exclusive user of the attack.



And Microsoft, who knows that many enterprises are still using aging systems like Windows XP actually pushed out updates for systems that haven't been supported in years.  That should be a sign that this update is worth investigating and acting on.  They even published numerous warnings.



So once again we are faced with the same age old issue of patching.

But keep in mind that when I tested Heartbleed in 2014, I found over 40,000 systems unpatched and exploitable within the Canadian IP range.  When I tested in 2018 about 10,000 remained.  This was for a vulnerability that literally spat out confidential information in 64k blocks.





So using this trend, BlueKeep will be around for awhile.

And also, corporate "America" is going to focus on patching the external facing systems while ignoring the internal ones which means that when Jenny the new less than bright CSO that was put in place to give that traded company plausible deniability clicks on that juicy phishing email, the lateral movement across the internal network is going to be easy for years to come.

So, once again, two lessons to learn here:

1) Patch all your systems for critical exploits

2) Know your inventory so you get them all

3) Place RDP behind a VPN, because password guessing and other attacks on RDP still exists or will surface!

4) Don't hire fake paper security experts to fill in a role and help shovel IT risks under the rug so that the shareholders feel all cozy

Wait.... that was four.... damned Thursday morning Jello shots.

I have to go, my phone is ringing with yet another Ransomeware victim who had to find $60,000 in bitcoins before midnight ;-)



_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies


www.eva-technologies.com

Wednesday, June 12, 2019

Will the CBP have to report to the Canadian Privacy Commissioner?

I haven't written in awhile, not for lack of options or subjects, mostly lack of time.

The last few months have been riddled with new business relations who are being hit with advanced Ransomwares.

Something has changed in the last year, and these attacks have clearly gone from fully automated to hybrid and manual.

So be warned, the bad guys will outsmart you.  They will figure out how your backups work and remove them.  They will take their time to figure you out and find the weakest link.  One attack replaced the backup systems DLL file and continued writing backups... with all zero bits.... which compared correctly at verification so the backups seemed to work fine.  The attackers waited over a month to deploy their ransomeware.

But on another subject, Will the US Customs and Border Protection agency (CBP) be above the law?

Will our privacy commissioner impose our new disclosure law on the CBP?

You see, turns out the CBP has been tracking our vehicles and our faces at border crossings.  Also turns out that security was weak and hackers got into all that information and left with it.

Since November 1st 2018, Canadian law dictates that breaches impacting privacy be reported to the privacy commissioner and that EVERY affected person be notified if there is a risk of harm to the individual.

The key thing, is that they worded the law in a way that gives a lot of room for wiggling out.  They used the term "significant harm".

Now it gets worst (or at least more interesting), it was actually a subcontractor who had the breach, but the CBP doesn't want to name the contractor.   Well not to worry, it looks like the friendly hacker community is taking care of that and it is a company called Perceptics

Turns out:  "Initial information indicates that the subcontractor violated mandatory security and privacy protocols outlined in their contract," CBP said in a statement.



So back to my overwhelming ransomeware events.  When someone calls me in the middle of a panic because of a ransomeware, I already know what the bad news is:

1) Turns out our backups didn't work since last June... 2018
2) Turns out our malware detection system was not configured correctly
3) Turns out we have to pay the ransom and have no idea what a Bitcoin is

But here is the kicker, 9 out of 10 times, it was a subcontractor that had the most contributed to the breach and failure of IT systems.

a) We thought the backups were good

b) We thought the backups were running

c) We thought our systems didn't have 6000 Shekels of exploitable vulnerabilities

d) We didn't know that a Shekel was an ancient measure of mass equally as old as our IT infrastructure and capacity to be resilient to failure

e) We didn't realize that we opened up our network across all protocols to a third party because management pushed the IT guys to open up the firewall because the F'n project must be delivered on time

f) We didn't realize that our really good IT guys are actually really good IT guys based on the perception that they keep the lights on and as far as security goes they do not have the knowledge or luxury to handle security adequately

Anyways, you get the point.   Everyone is always surprised when they get hit by a Ransomeware but the security experts are certainly not surprised and often your own IT staff aren't either because it dawns on them that their technology debt equates to a security debt which therefor results in large security exposures.

So lessons learnt here.....
1) Trust but verify your third parties

2) Do not blindly prioritize projects and ensure you have security oversight and firm checkpoints

3) Have VERIFIED and OFFLINE backups

4) Have storage technologies that are not integrated at the OS level (no AD integration, completely isolated like iSCSI) and ensure that snapshotting features are in place (with adequate storage you cheap bastards)

5) And while we are at it, make sure your security countermeasures have all their features turned on, because that my friends is really really embarrassing.

Now, I'm still curious.... and would certainly love to hear our privacy commissioner on this CBP breach of data.

Silence......  crickets......  and soon forgotten data breach....

Visit databreachtoday.com 
It isn't called data breach this month folks !

_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com



Friday, December 21, 2018

For Christmas, don't be Equifax or Donald Trump

All I want for Christmas is to not be an Equifax.  That should be the chant of any VP of IT or even any CEO.

But in the current period of humanity we are in, where diehard claimed christians support an orange lunatic that builds walls instead of protecting refugees, feeding the homeless, or taking care of the countries veterans pretty much violating anything that any version of any bible says.  We must obviously face the facts that humans are mostly hypocrites.   

The Donald after all has been confirmed to have made over 6000 false claims over the last 600 days (link here) including locking down the government because he is not getting the funding to pay for that great wall the Mexicans where supposed to pay for.  Yet the diehard Trump supporters are all behind him, because no one needs to be telling the truth, no one needs to be accountable, and no one needs to be a decent human being because America is great, we are all hypocrites and only care about ourselves.    After all, almost not a week goes by that I cross a company that mentions security a dozen times yet have absolutely no security in place.  So lies are now the golden standard.

So.....

Take a look at the latest claim from Equifax:




https://www.cloudmanagementsuite.com/equifax-blames-one-it-guy

YOU READ THAT RIGHT !

They are blaming a single person for every single one of their failures !

We should call this the Donald from this point forward.  It is a pretty bold move to blame that one IT guy for a long list of failures that cannot possibly be attached to this one poor soul.

Sure, a patch was mis-applied...  but the architecture still remains terrible, nothing is checking their systems for exposed and exploitable vulnerabilities, no lateral movement detection or advanced threat detection is in place, and for this single security issue... no one noticed for months.....

Lets not mention that some of the other divisions of Equifax had open databases visible on the Internet that a chimpanzee could access and see PII data for an entire countries population.

And here is the real kicker, after the breach, Equifax reviewed their security posture and immediately made changes and added technology to the tune of over 100 million dollars to bring their current cyber security posture to what they declared as "modern" and "Acceptable".  

What this means is that they realized that everything they had in place was far behind and needed to have 100 million $ injected to bring it up to "acceptable".

How the heck can that be blamed on that one IT guy.

Equifax, you continue to prove that you are a terrible company and that you only exist because of the strong lobby that is in place combined with the lack of spine from both your corporate customers (The banks) and our government.

So in this holiday period, am I disappointed in Equifax, indeed however the failure remains bigger for the banks and our government including our privacy commissioners who play the big boy game of politics and look the other way.

That is my holiday gift to you, the sad realization that our banks and government suck more then Equifax.  As for all my other friends who are not Equifax, the ones who provides quality and secure systems, I wish you all a merry Christmas.

And for 2019, may we see less Equifax, and lets remain wishful that senior executives who act willfully blind get some real fines that are paid out of their own pockets and not their share holders, and some jail time to serve as an attitude adjustment.

Hey, we can all wish for things under the tree.

Now for some positive comments ;-)

The private sector is booming and much more secure.  I have on-boarded several new clients, all privately owned and all of them listen to suggestions of optimisation based on risks.  So faith in human kind is restored.

So I guess my real wish for Christmas is simple.  Lets all work together to accurately describe risks in business terms and getting risk acceptance performed at the appropriate management level.  Lets call fat...fat... lets call something blue... blue.... stick to the facts, and work to be better as each day goes by.

_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com






Tuesday, December 4, 2018

We've got the best people, the best product

This post is going to be more serious.  cough cough...

So the flower site 1-800-FLOWERS just realized that they got hacked years ago (4 years ago) and everyone that came by and entered their credit card numbers had all their information exposed.

But.... it is only Tuesday!  This is supposed to be Friday stuff!

https://techcrunch.com/2018/12/03/credit-card-stealing-malware-flowers-four-years/

For all we know, 800-Flowers may have been doing a great job and simply been a victim of a numerous list of other issues that led up to this.  What we do know is that they relaunched an entire new website claiming to have added security.  That kind of implies that something was fundamentally bad with the old one, or it could simply mean they want a fresh start from a PR perspective.  Time will tell especially if the actual breach details make it out into the open.

Back when Ashley Madison let themselves be hacked end to end because of a complete absence of anything related to security (see my humorous blog entries on this), 1-800-Flowers actually showed some really witty marketing by offering a special flower arrangement for anyone who got called out for having an account on a cheating website.



I have yet to meet someone who will admit ordering the prestigious "Ashley Madison" flower arrangement, so I still do not know the price.


I had a realization today.  Technology companies have long adopted the DJT (Donald J Trump) approach to cyber security.


"They have the best people, really the best, and the best words."

When a potential vendor I am evaluating gives me this type of response...  I get alert.  nothing focuses my attention more than hearing "we have great developers", or "our dev team is the best",  Both statements are actually dead wrong.

Here is why.  

A dev team is put together to deliver technology on a predetermined set of parameters such as a delivery date and a budget.  Sure "features" and "functions" are in there, but security rarely is present in these items.

When the CEO says his dev team is the best, this means they deliver on-time and within budget.  From a security point of view, this could spell trouble.

So why exactly would a CEO think his dev team is awesome?

I'm looking at it from the point of view of security.  The senior executive is looking at it generally from delivering a product that works, looks good, didn't cost a kidney, a limb or your first born, and was done within a reasonable time.

So the word "Awesome" means two completely separate things.

Here is the generally accepted truth about a software development team.

They rarely get the luxury to include a strict security testing methodology within their SDLC (if they even have an actual software development lifecycle process in place).

So I do not disagree with a CEO that says their dev team is the best.  I just place that information into the correct bin.  Bin #46:  Dev team is nimble and generally delivers what is asked of them within a reasonable amount of time/budget.

However, as the Chief of Security Officer, my questions and my priority Bin is #1 to #10 and all touch security, non of it touches short delivery times and limited budgets.

The fact is that dev teams are not trained to be cyber security testing experts, so obviously security should be integrated somewhere in the process with someone who does master this area of expertise or with a trusted third party who provides guidance, or testing with the maturity required to do it for real.

Keep in mind, that outsourcing security in no way affords you the ability to think everything is fine, because in the "services" area, we find plenty of folks who know how to make a buck yet offer very mediocre services (read here... sub par).

Security is a philosophy that needs to be infused across all players.  This takes the right talent, patience and a reasonable investment.

Outside of this, thinking that the lowest bidder, or the really inexpensive web development company we met last week is doing great security is simply beyond crazy.

Most enterprises simply aren't there.

So here is something to think about.


  • Car manufacturers have great engineers
  • NASA has the "best people"
  • Pharmaceutical companies have bio geniuses 
  • I could go on....


They all have something in common.   Good processes that includes formal testing worthy of the asset they are producing.

So we can learn something from these types of enterprises by realizing that if the technology we are deploying is not critical or does not (cannot) expose sensitive data, then sure, the lowest bidder or whatever service is fine.  However, when the service or data is sensitive, an appropriate amount of testing AND oversight is required to ensure that everyone delivers the quality expected.

One of the biggest dangers in the technology industry is the belief that a big company, or an old company, or a company that says the word security eight times on their website.... delivers quality.

Things in the technology world change at an extremely fast pace.   Security professionals that do "real" testing is a rare commodity.  

This means you have to ask the right questions.

First off, prioritizing your assets or your systems at any level is an important part of the puzzle.  You need to know how critical something is so you can handle it accordingly.

Knowing that you are about to outsource to a SAAS or Cloud provider a piece of your business has to mean knowing what value that piece has for you.

So what are the right questions to ask:

With any service that someone delivers, you want to know that they are delivering something reasonable.

My favourite example, is web application development.  In the last months, I have had to deal with several such providers, who all claim to do a great job, yet cannot answer even basic questions about how they achieve this.

Some examples (and the answers I got from a prestigious company): 1) How is security integrated into your software lifecycle?  We test monthly
2) Who does the testing? Our developers
3) What are their qualifications? Senior developers have worked for us for over 10 years
4) What triggers a retest?  We always test monthly
5) What types of tests are performed (provide a list)? Web tests
6) Are these tests automated or manual? Automated every month
7) Who is vetting the test results? Our senior developer 
8) What secure development training has your dev team received?  They are senior developers and have been trained as such
9) What where the last three significant security issues identified during testing? We have not had any significant security issues

That last one is a real kicker.....  they have to provide you with something, and statistically it should be something real, and juicy.  Yet, nothing.  So they have never event had an XSS on a forgotten form field.  Impressive indeed!

Bottom line, these questions should be like the questions you get asked when clearing customs.  The question itself is not that important, it is the response that we are looking at and gauging the maturity of the answers.  The answers above.... simply suck and show no maturity at even a basic level.

You simply cannot just hand off your critical data to any third party that claims they develop secure applications and assume this is all good.

Once you have identified someone that gives you reasonable answers, you should still perform your own testing (or mandate someone to do quality testing for you) assuming the system in question is valuable to your business.

This is the sanity check to ensure that the wonderful rainbows promised to you have been delivered.

The old adage, TRUST BUT VERIFY always applies. 

One thing you can trust me on, is that statistically, most companies claim to provide the absolute best security, and just like Donald J. Trumps hands, come in a little too short. 


_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com





Friday, November 30, 2018

The era of lies - Always vet your vendors

I often am faced with corporations that ignore obvious security issues to favour short term gains and protect their management structures ego.

This week, MARRIOTT surfaced with one of the largest breaches of the year exposing everything from passports to room service preferences.  At first light it seems like a full compromise of just about everything.



https://www.businessinsider.com/marriott-data-breach-500-million-guests-affected-2018-11


This is a large multinational corporation with resources.  The breach appears to have gone on for years.  In the next few weeks we will see the same list of errors that have been made time and time again by all these corporations that get hit hard.  I will take any bets on the presence of some basic fondamental issues being a large contributing factor.  They had some great security in place, but a lot of it was tuned down because they don't understand the technology they bought.  They have a great big security team, so they feel so great about  their security posture yet senior management didn't listen to them.  Some of their partners may even have mentioned some significant issues, but the messenger was shot and the message died a slow death.  You name it, they fit the profile.

In parallel to this, in my role as CSO for one of my clients, I am evaluating two potential vendors for a sensitive data processing service.

I use a single one pager security questionnaire to get the ball going.

I like to give a potential vendor the chance to either lie to me or provide clarity at their lack of competence.

Something I observe overtime is that everyone claims these basic characteristics:

1) They claim to have been doing whatever they are doing.... for ages.....
2) They have the words security dropped on their websites and in their presentations
3) If you ask, they provide secure software, or secure services, or secure anything
4) Of course they test things
5) Of course their developers are qualified and have security experience.

This week, I had the chance to challenge two potential vendors and the delta between the two was shocking, which led to me writing this blog entry.

Generally vendors (especially the ones offering SAAS or cloud based crap) all fit that previous list above and their TRUE reality is that they have negligible security in place since they completely lack cybersecurity competence.

1) Who cares if you have been doing this a long time, who cares if you are a large organization.... have you evolved ?
2) Dropping the word security everywhere does not ensure anything is secure
3) How can you prove you are delivering secure xyz ?
4) They are not testing much if anything
5) Their developers are perhaps great, old, experienced developers, but they do not have security training and no secure SDLC is in place.

So I wanted to talk about TESTING today, because I frequently am faced with evaluating the tests that vendors claim they do with the real world requirement to do a reasonable amount of testing.

THE #1 OBJECTIVE:  When doing security testing, the first objective is not to find bugs, but to find root causes and fix the behaviour that leads to exploitable vulnerabilities.    This way when you come back and test down the road, everything hasn't regressed.

Doing a full set of tests on a web application may require 10 to 15 days of well orchestrated testing.  When management comes back with a comment along the lines that this is expensive, this means they seriously lack comprehension on what delivering a quality service entails.  

Performing quality testing pays large dividends.  The things you identify lead to your operational staff and your development staff learning from their mistakes, they add to their knowledge and start producing better quality systems and code.


ILLUSION OF SECURITY

So if you are doing business with someone who is providing you with a report that something was tested.... you need to know if this is provided as an illusion of security or was something really truly tested with an adequate testing initiative.

That is why I always ask to see the work order, the bill, the number of hours invested.  I especially love asking after a vendor has navigated their ship into the lies that are so typical of incompetence.  We have big clients, look at my client list.  And they never asked us all these questions.  

Well guess what buttercup, the let you assume a level of responsibility based on your bold statements that someone with more maturity and experience (little old me) is not going to let you do.  I do not adhere to the transfer of responsibility trend that traded companies so enjoy.  When something gets violated, I know that my client will look bad, and I will look bad if everyone did not do their job with quality in mind.

So ask your vendors if they deliver quality service, than ask them if they perform quality tests.   Once you have had your bullshit answers for both those questions, ask for the test report and make sure that includes the man hours to perform the tests, or the bill if done externally.  

But brace yourself, you will see a lot of $2500 and $5000 full blown application security tests.

Don't be too insulted when you realize that this quality service that is being presented to you has only invested a few days of security oversight across their entire product line.

Do remember this however, when something goes terribly wrong and a real expert looks under the hood.... that couple days of security is going to make you look like the biggest idiot this side of the white house.

Remember Equiflop.  I mean Equifax.  After they got violated they actually reported that in order to bring their security up to the expected level that it should be... they invested $170 million if I recall.

SOME BASICS

Simply running an automated VA (vulnerability Assessment scan) across a system does not test the application.

Simply running a web application testing tool across an unauthenticated web page does not test the application.

Investing a couple days of security on a system is NOT SECURITY TESTING

If your vendor is telling you that they do great secure work and this is the types of tests they are providing you, than you are being provided a false sense of security, they are not learning from their mistakes, and the application provided has not been tested.

Enterprises frequently try to stay competitive by not increasing their level of service or the quality of the service they provide.  This is extremely dangerous in IT.  Things have changed dramatically in the last decade, and companies who use the word SECURE are starting to get sued when it turns out to have been a gross exaggeration amounting to negligence.

I love my job.  I love being the acting CSO for my clients because I get to ask these really good questions.  And as an added perk, when I walk into a room with a vendor and they have done their homework I can hear their butt cheeks tighten up.  That means I'm doing a great job and they are not.

You should always work with vendors who have relaxed butt cheeks.

So back to my two vendors.  The first one was a disaster of lies and lack of competency.  The second one had stunning responses, had hired a full time security person with adequate credentials and they do real testing using methodologies that actually exist and wasn't simply made up.

Moral of the story is that some vendors are providing quality services and do invest to ensure that this is the case.

Ask questions, don't be the type that assumes that everything is ok just because someone said they test things or that they deliver secure services.

Figure out if your vendor LIES or is INCOMPETENT.  

Huge difference between the two really.  Very hard to work with lies.   Lack of competency however you may be able to work with.  If the vendor is willing to learn and work transparently and continuously getting better.

So it is really your call.  Do you want to be willfully blind, work with liars, work with negligent incompetence or take the time to find the vendor that will actually deliver on their promises of security.

As for Marriott, you can bet that every level of management is pointing the finger at each other, you can also bet that several third parties are in the loop and probably contributed to this failure.  And you can bet that the vetting process was terribly weak, mostly based on inbreed decisions.

What you can also bet on is that you won't hear about them.  All you will remember this time next year is how Marriott got the shit kicked of the them in an embarrassing breach.

Remember that next time you deal with weak vendors that if you fail to vet  them adequately it is your reputation that will pay the price.

Ask questions folks, and choose to work with quality staying far away from illusions of quality.

For now, I'm going to get myself a nice Cognac, throw some wood in the fireplace and watch the Marriott story unfold.  They won't admit it, but they will lie through their teeth for the next month. 

Always a great way to end a week for me.

And yes, I still refuse to participate in the illusion of security.  I don't do 2 day intrusion tests so that some jackass has a report to hand in that says that "something" has been done.


_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com







Tuesday, July 3, 2018

WTH: We left personal data exposed for months to catch "the" hackers.

I often mention that not a week goes by that someone doesn't give me something juicy to blog about.

Some weeks are just amazing.




So this will be an opinion piece since everyone is entitled to an opinion ;-)

If you want the short version, here it is: 


Short version:  Company exposes personal data of over 130,000 citizens is now considering hiring a security firm to test their sub-par application, says that they knew of the security issue for months and is convinced it was only there for 2 months and confirms they left it open to catch "the" hackers.

Short analysis:  They didn't know. and they couldn't have caught "the" hackers since most are in foreign countries and even law enforcement can't catch them.  Conclusion, they are clueless on security, and the cities who outsourced their services to these clowns is to blame for not doing ANY security due diligence.

The longer funny version: 

I blogged about this issue last week (see previous entry).  What has changed is a newspaper article was written on the subject, and it seems that the company in question has no idea how to handle a security incident (like most companies).  They are just opening their big mouths and the vomit that is coming out is so telling on their security maturity, that I will now be using this example as I teach to my students.

Strike 1:  for months "we left the site vulnerable so we could catch the hackers".

Comment 1: Stupidest thing I heard this month (but in their defence, it is only the first week of the month).  The hackers you could catch are the local ones checking out the vulnerability for the fun of it, and that wouldn't do much as they probably have no criminal intent.  The real ones are smart enough to route from another country or are actually from another country.  The fact that they think they will catch someone proves that their maturity is rock bottom.  The simple idea of leaving REAL data exposed in order to catch someone that they can't possibly do anything about is just wow.  This confirms a complete lack of understanding of both security and privacy regulations.  Also, let's see the police report since you obviously contacted law enforcement as soon as you knew someone was hacking you since you wanted to "catch" them.... oh wait... you didn't know about any of this until the journalist called...


Strike 2: Only a few accounts had Social Security Numbers.

Comment 2:  This seems to imply two things; first not much valuable data was exposed and secondly birthdates, home addresses and medical conditions aren't important.  It is important to note that the video I saw seemed to pick out accounts randomly and they all seemed to have Social Insurance Numbers, so I'm not even conformable with the declaration that only a few accounts have a SIN.  In fact, this entire story is a SIN  ;-)


Strike 3: We are looking into hiring an external security firm to test out our application.

Comment 3: What ?  Out of 200 municipalities, no one put this as a requirement! And why are you only looking at it now?  Haven't you proven without a shadow of a doubt that you desperately need adult supervision!?  When reporters started calling you... this didn't strike you as a great time to do this....


Strike 4:  We know exactly when the "bad code" was introduced and it has only been a few months so we know exactly which account have been breached and we are going to contact them.

Comment 4:  Yeah, you have clearly demonstrated that you are in full control of your ecosystem, and I feel confident that you actually "know" everything, had in place detailed logging that goes back years, that your software development lifecycle is solid to the point of finding other major issues in the past that have been introduced at other revisions.  I also feel very confident that you will take immediate action without a journalist calling you up to point out that your exposing all your customers data.  Is it beer time yet.....

UPDATE !:  La Presse just published an article giving even more ammunition to my rant.....




Strike 5 (Because this is that type of ball game):   They are claiming that only 30 personal records have been accessed.... yet an anonymous source sent me a series of videos containing a number way north of 30.

Comment 5:  This means that they have no clue who has accessed what or when.  For all we know, everything may have been scrapped by a bot and all the data ingested by a malicious actor.   Oh yeah... they could also be lying because that seems to come up a lot!


A recommendation for the company in question:  Next time, shut up and hire a professional to handle your PR/security issue.  Also, stop considering security and actually do it.  And as a final recommendation, stop lying and making it up as you go along.

A recommendation for the municipalities handing our private data to contractors:  According to GDPR and many upcoming privacy regulations you are responsable for handing off business processes to QUALIFIED firms.  This doesn't mean what you think it means.  It means they understand their duties.  For a software development firm, this means training developers on security and including security testing within the SDLC (Software Development LifeCycle).  It also means never level an exposed system... exposed.... so you can look at logs.  Oh wait... that was a lie.... since you had no idea you had a breach until the phone rang.....

I guess that is why I always tell senior executives to SHUT UP and let the qualified folks take the microphone.  Blurting out a bunch of incoherent crap like this only proves that you are either lying or incompetent.  

Big trophy for them this week, because in only a few statements they proved both.  Good job !



_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com



Tuesday, June 19, 2018

Cross your fingers "security" the current gold standard.

It's mid week, not even a Friday and things are heating up.

Headline: "Enterprises take huge risks with our personal data".   Please.

Not a big surprise to security professionals as we are constantly "fighting" for adequate security.

By adequate, I mean normal, sensible, security.

I was contacted by several journalists this morning with regards to a services portal that operates in the municipal space as an SAAS provider. 

This "service" manages something to do with leisure activities.  I don't want to name them since I like my enemas handled by qualified doctors and not legal teams with an absence of comprehension of security hygiene means.

So this portal supports 100's of municipalities and has 100's of thousands of users, yet security was never addressed.

Why do I say "never addressed", simple.... I cannot say never reviewed, because I do not know if these things where simply ignored or judged not important at the time, or if they simply did not know.

I'm actually still on the fence with which I like best, someone who lies to me or someone who is incompetent.

The issue is simple (and multiple issues should have been identified by a qualified security expert).

For one, the site uses a sequential ID in the calling URL.  This means (you guessed it), changing the ID means accessing someone else's file.




That alone is already an issue, but it gets worst.

You don't need credentials to get to it.  Anyone can create an account without any email validation, so once you have created your fake account, you can read everyones file.

But wait !  There is more!

The personal data includes home address, phone number, birthdate, medical conditions and allergies !

But wait !  There is yet more!

Social insurance numbers are not only stored non hashed within the database but it is returned to your browser when you view your file (or anyone's file since you can change the ID number to "see" someone else's file).

Here is the awesome protection on that one field..... it is return with the awesome html type = "HIDDEN" so it doesn't display on your screen  ;-)




So what is the lessons learnt here....

1) Municipalities (and private sector) should not trust an SAAS provider just because they say "everything is fine.  "These are not the drones you are looking for" is not a security approach.

2) If the SAAS provider tells you they have awesome security because they are hosted as a CLASS 1 datacenter called AZURE, AWS, GOOGLE, etc.   run !  The means they do not grasp that the security of their hosting provider is only the plumbing section and it means nothing as far as the "quality" application that the provider is throwing on top of the certified infrastructure.

3) Security testing is a MUST and it must be performed by someone qualified.  

4) Account creation should be limited to valid email addresses

5) Authentication mechanisms should limit the sessions visibility into data (certainly no client side security)

6) Being a small unknown company in the wild and huge world we call the Internet doesn't mean you do not need security.  Crossing your fingers and hoping for the best is also not the best approach.

7) Logging and alerting when someone is leaching your entire client database is probably a good idea.

I'm going to stop, because I'm getting sarcastic again.  I really do need therapy.

On a very serious note.  When dealing with sensitive, regulated PIPEDA type data, perhaps some security is a fair expectation and a reasonable minimum.

From a GDPR perspective, everyone involved here is a potential winner of a multimillion euro grand prize.


_______________________________________________

Eric Parent is a senior security expert, specialized in coaching senior executives.  He teaches CyberSecurity at l'Ecole Polytechnique and HEC Universities in Montreal, and is CEO of Logicnet/EVA-Technologies, one of Canada's oldest privately owned security companies.

Follow Eric on:
Twitter @ericparent
LinkedIn :  EVA-Technologies

www.eva-technologies.com


What if the lowest bidder is always the most expensive option.

Reflection:   Perhaps we should start looking at the highest bidder and figure out what the lowest bidder isn't including.... In Quebec,...