Showing posts with label Information Security Industry. Show all posts
Showing posts with label Information Security Industry. Show all posts

Wednesday, June 13, 2012

Arguing FOR Security Through Obscurity

We should all be questioning the received wisdom and best practices of security. Why? Because aggregate spending on security expertise and products is now massive, but the bad guys are still getting away with it most of the time.


"Uphill battle" is not an apt way of putting it. You know, you can usually see the top of a hill.

Maybe we're fighting the wrong battles altogether.

Consider the great pejorative of infosec, "security through obscurity."

Everyone knows that security through obscurity is not just bad, but downright irresponsible. The canonical illustration of this comes from cryptanalysis: rolling your own crypto scheme is almost always a bad idea, with a result that is considerably weaker than what you get with a publicly known, well-understood encryption scheme. Kerckhoffs's principle, a rule of thumb for cryptosystems saying that your system should be secure even if everything but the key is public knowledge, first appeared in print way back in 1883.



But lately, when designing security for really hard-to-secure things -- like everyday things used by millions of regular people -- I've found myself saying about our defensive measures, "Let's not talk about this." What on Earth am I doing?

Economic warfare is what I'm doing. But not in the way you're thinking. There's an old principle in security that I'm sure you know: if you make a system more expensive (in time or resources) to break into than the reward gained from doing so, you've built a damn fine defensive barrier. And it's obvious that secrets take effort to unearth, through reverse engineering or intelligence gathering, for instance.

The reason this doesn't usually apply to crypto is that cryptanalysis is historically a game played by nation states, where the reward gained from undermining a system is so great that it justifies an extraordinarily expensive intelligence effort. 

But some of the R&D projects at Critical Assets Labs have been going even farther into the territory of economic warfare, in the service of practical security for everyday things. In today's world, riddled with security problems, we are continually applying the security principles of warfare and statecraft, like Kerckhoffs's, where they don't apply. At this place in history, we are really good at securing very special things, based on a security model perfected with the castle keep: we put the really big prizes behind the most layers of security. At the center of those rings of security, only specially authorized people, with special training, have access, and if they see a stranger, it's okay to stab him.


The problem today is that practically everyone has special access to something -- bank accounts, email accounts, corporate assets -- and we need to secure those things, but they're not really crown jewels. And we can't treat everyone like castle guards. If a castle guard doesn't follow the right security procedure, you throw him in the dungeon to teach him a lesson. Those rules don't apply to everyday security. Put in the jargon of the net: consumer security education doesn't scale.

Ultimately, consumer security solutions that require training are not solutions. They're actually security problems. (Does anyone really think that we can train a majority of people to look for the "green bar" on ssl sites? or that anyone on Earth is going to notice when their online banking login skips that step where they're supposed to look for their special photo? Seriously?)

Solving those training problems takes the defenders' money and time, so from an economic warfare standpoint, when you go down that road, the advantage actually shifts, by default...

 to the attacker!

As we make our research findings known, through this blog, papers, and conferences, and as our R&D comes to market (through product roll-outs and licensing to partners), we will be demonstrating how one of the ways in which we are raising the defensive bar is through uncertainty, the helpmeet of obscurity.

Today's most well-deployed defensive tools - antivirus, anti-malware, DLP, and application aware firewalls, present no uncertainty to attackers. It's easy to test your malware against every antivirus package before you release. It's easy to tell when you've penetrated a firewall.

We think that the next generation of defensive security will work by breaking the attack development cycle, and breaking the connections between exploit and payment.

Sunday, March 20, 2011

RSA: Who is the doctor's doctor?

[caption id="attachment_150" align="alignnone" width="348" caption="Some solid security logic."][/caption]

It's pretty clear at this point that there's a trending of attacks focused on security solution providers. The most recent victim in the post-HBGary landscape is RSA.

A lot of people seem to be talking about what they believe actually happened during the breach. The company has yet to officially comment on the details of the incident and seems to be wordsmithing any communication to the outside world pretty heavily. While I'm sure the technical facts will be interesting, and that they will make their way around the rumor mill eventually, I'd like to talk instead about something that I feel is more important - due and reciprocal care.

The medical industry seems to have this concept pretty well wrapped up. If you ask a psychologist, "who listens to your problems?" they will tell you that their psychologist does. This is because it is considered unprofessional, and in some cases a violation of ethics code to self-diagnose, self-prescribe, and self-medicate. Of course, this begs the question of who treats the psychologist that treated the first psychologist? Well, another psychologist of course. So, theoretically, as long as there are at least 3 physicians in the world who practice psychology, this model will continue to function, and we won't end up with a bunch of mentally disturbed psychologists.

I doubt anyone on the professional services end of the information security industry would argue that there's a shortage of proprietors offering security assessment and remediation. So then why do things like the RSA incident happen? It's because nobody is examining the physician. In fact, I'd be willing to bet that if you took a sample set of posture assessments from top 10 information security product and service vendors, the results of what's already left the building would be staggering. Further, most people close to the steam will tell you that things have not changed dramatically from the days when the entire Solaris source tree was essentially public domain in the hacker underground, and Larry Ellison's personal passwords were in a t-file.

Why? It's simple. Just because your company's primary business is security does not mean that you possess said security. What it does mean, however is that the risk you take is not only limited your standard business risk, but that your reputation is predicated on your ability to protect own your assets in the same manner that you would help the customer protect theirs.

So that you don't think we're calling the kettle black, we have in fact engaged an outside advisor to look at the company footprint, assess security, and make recommendations for remediation. If you're a security vendor, shouldn't you?