Search
Pete Silva - Daily Dose of Pete
You are here: DevCentral > Weblogs

posted on Thursday, July 30, 2009 12:57 PM

The crew at DevCentral has a great series called A to Z, which goes through various technologies including Social Media, PowerShell, Networking and the most recent NSM (Network and System Management) and gives tips, tricks and technical info on the topic. 

I decided to build upon (or steal, however you see it) the idea with ‘26 Short Topics about Security.’  Yes, I’m a Simpsons fan (22 Short Films About Springfield) and got some inspiration.  This blog series is actually an altered version of a presentation I did a few months back that I always thought of turning into a blog series.  The idea is that there is so much going on with Security in so many different places that I figured it might be good to cover 26 of those over the next few weeks.  Not too technically heavy or all encompassing but definitely areas of concern for IT.  So, then – let’s get on with it!

First, Security (and not just Information Technology) is all about Risk and Threats.  There’s a whole industry based on Risk Management, Risk Assessment, Risk Mitigation, Risk Analysis and so on.  Risks, in my view, are based on actions that we (you/I) either take or don’t take while Threats are actions (or attacks) coming from other entities.  We take risks while we try to reduce threats.  ‘That’s a risky move you’re making’ and  ‘don’t you threaten me.’   Certainly they are intertwined.

shark

What’s the risk if I don’t respond to this threat?  The 12ft shark might threaten my life if I risk swimming with it.  We deal with risks & threats every day and make quick decisions if it is worth it – you get it.  But this is just the set up (think slides 2-3).  :-)

[Theme song]

We begin with Authentication. Authentication has never been more important to users, corporations and web applications at large.  We’ve been confirming our digital identity against user stores for a while, particularly in our work domain environment & financial web applications.  Just about all the ‘my.public/portal’ sites that offer any sort of customization requires us to enter a username and password and much of today’s malware is targeted toward capturing someone’s credentials.  Once someone gets a hold of your ‘secret,’ they can pretend they are you and access information that only you should be viewing.  In the physical world, a doorman or ticket agent can check a photo ID against your real face and determine if you are who you say you are and hopefully, you’re the only one with that laminated picture.  In the digital world, all the system can go on is whether or not you know the stored secret so it’s important to keep those in the vault and not taped to the top of your laptop.  Plenty has been written about the security implications of ‘Forgotten Password,’ ‘Email password,’ and ‘Password Hint’ retrieval so won’t get into that but Alan Murphy does a have an interesting blog on ‘How to create strong, dynamic passwords.’

Strong Passwords (requiring letters, numbers, caps, special characters, rotation, etc), Two-factor auth (additional password or token) and OTP (one-time passwords) are all ways that IT can enhance their authentication scheme.  Biometrics (thumb print, iris, facial, voice, keystroke, etc) were supposed to be somewhat mainstream by now and can help in determining a user’s authenticity but can be very cost restrictive.  Fingerprint is appearing on many notebooks now and even the keystroke style, which is probably one of the least costly, isn’t completely solid since if I break my finger, the admin can revert to text password or lessen the sensitivity.  I’ve seen ‘What if I’m drink,’ as part of keystroke vendor questions. I understand that alcohol can influence my typing style but does my employer really want a sloshed, uninhibited employee accessing sensitive info?  There are also authentication systems that use pictures and shapes.  Instead of remembering a set of characters, you remember a shape and whatever the random numbers that comprise that shape is your OTP.  Or you do remember a set number password but the numbers appear in different locations every time.  There are also virtual keyboards where you ‘type’ your password by mouse clicking on a little keyboard screen on the log on page.

  sematrix

Oh, there are many ways.

SSO (single sign-on) and Federation take focus in many IT departments.  SSO allows users to log in to a system once and then be able to navigate (gain access) to the other related but independent systems.  For instance, a user would log in (or authenticate against a domain) to their corporate intranet and one of the links available might be a salesforce.com application.  Typically, the user would have to re-enter their credentials, but SSO passes identity (usually cached) which allows access without the additional UN/PW entries.  Federation is essentially trust between networks or domains and can be a part of a SSO solution.  Federated trust is usually a system, server or network trust between two businesses or private systems.  The user probably doesn’t have full reign but can access specific resources on their partner’s network.  With SSO it is usually just the user’s info that is passed to each system, with Federation, the entire (or groups of) infrastructure is trusted.  SAML, Kerberos and WS-Trust/WS-Federation services are all enablers of federation.  SSO can be achieved thru a host of vendors but things like Kerberos, smartcards and client certificates can all play a role.  For public web applications, especially social media sites OpenID is becoming a method for users to ‘claim’ they are themselves at various web portals.  There’s still some hesitancy for enterprise IT to adopt but many web facing applications support OpenID.  Many portals that do support OpenID, however, are reluctant to be that ‘3rd party vouch,’ especially if it’s for a competing portal.

That’s it, nothing groundbreaking just a point in time pertaining to Security topics.  To give you a little taste of what’s next [sung to the tune of GREASE]: BREACH is the word, is the word, is the word that you heard, to the tune of $6.6 Mil, per-r-r-Breach.

ps



Feedback

8/7/2009 3:31 PM
Gravatar Decade old Data Centers
Pete Silva
8/12/2009 12:12 PM
Gravatar Bit.ly, Twitter, Security
Pete Silva
8/19/2009 10:01 AM
Gravatar Yelling
Pete Silva
8/24/2009 4:14 PM
Gravatar Be Our Guest
Pete Silva
9/3/2009 11:36 AM
Gravatar Dumpster Diving vs. The Bit Bucket
Pete Silva
9/9/2009 12:36 PM
Gravatar The Threat Behind the Firewall
Pete Silva
9/16/2009 4:05 PM
Gravatar Keys to the Kingdom
Pete Silva
10/28/2009 11:03 AM
Gravatar Social Media
Pete Silva
11/13/2009 9:14 AM
Gravatar You
Pete Silva
12/14/2009 2:07 PM
Gravatar It all comes down to YOU - The User
Pete Silva
12/2/2009 1:24 PM
Gravatar Windows Shopping
Pete Silva
12/7/2009 3:48 PM
Gravatar Pearl Harbor, Punchbowl and my Grandparents
Pete Silva
12/8/2009 1:39 PM
Gravatar X marks the Games
Pete Silva
4/7/2010 12:57 PM
Gravatar CloudFucius Says: Blog Series, Good Idea
Pete Silva
7/5/2010 3:50 PM
Gravatar Yes, security is very important in all course of actions. It is good that you are discussing tips on how to intensify this method.
Dumpster
11/18/2010 11:28 PM
Gravatar thanks a lot!
ugg boots sale

Let Me Know What You Think


Please use the form below if you have any comments, questions, or suggestions.

Title:
 
Name:
 
Email: (so we can show your gravatar)
Website:
Comment: Allowed tags: blockquote, a, strong, em, p, u, strike, super, sub, code
 
Please add 5 and 4 and type the answer here:

Blog Stats

Posts:285
Comments:97
Stories:0
Trackbacks:111
  

Post Categories

  Cloud Computing
  Security
  SSL VPN
  Information security
  pci
  PKI
  application attacks
  malware
  mitigation
  client security
  compliance
  notification laws
  social media
  social networks
  twitter
  facebook
  youtube
  digg
  peter silva
  social media stats
  ipv6
  ipv4
  2012
  context
  contextual aware
  user centric
  decision
  game show
  granular
  control
  identity
  cloud security
  virtualization
  sys-con
  cloud expo
  virtual
  glenn brunette
  sun microsystems
  Bruce Schneier
  Schneier on security
  research
  2009
  blog
  2010
  threat
  pci dss
  regulations
  espionage
  pentagon
  crown jewels
  tower of london
  health care
  banking
  prediction
  cybercrime
  cybercrime kits
  dyi
  dnssec
  dummies
  l0pht
  2600
  breach
  privacy
  breaches
  web security
  spam
  trojan
  gogrid
  blogger
  personal
  business
  H1N1 flu
  emergency preparedness
  disaster recovery
  network security
  oracle
  sso
  single sign on
  big-ip
  oracle access manager
  f5
  personal devices
  mobile devices
  mobile security
  windows
  microsoft
  windows 7
  desktop
  games
  gaming
  online games
  DDoS
  scams
  consolidation
  data center
  tech sector
  single purpose
  dedicated
  management
  access security
  policy enforcement
  utm
  processing power
  video
  audio
  multi-media
  dns
  webinar
  interview
  ioactive
  kaminsky
  dan kaminsky
  partner
  rsa
  xml
  splunk
  instructional
  in 5
  education
  training
  idc
  smart city
  smart grid
  infrastructure
  web 2.0
  standards
  inter-cloud
  interoperability
  application mobility
  peering
  confusion
  cloud confusion
  cloud survey
  edge gateway
  v10.1
  history
  words and meanings
  lists
  fun
  patent
  intellectual property
  trade secrets
  confucius
  cloudfucius
  series
  blog series
  a-z
  law
  constitution
  court
  fourth amendment
  gps
  government
  legal
  vmotion
  vmware
  case study
  interop
  v10.2
  database
  csrf
  asm
  adc
  arx
  data manager
  netapp
  storage
  WAN optimization
  application delivery
  optimization
  compression
  whitepaper
  statistics
  cloud research
  cloud stats
  LTM VE
  travel
  firepass
  encryption
  music
  humor
  uptime
  cloud outage
  SLA
  availability
  customer
  vmworld
  yankee group
  sports
  NFL
  performance
  acceleration
  peoplesoft
  rman
  recovery manager
  oow
  openworld
  replication
  integration
  apm
  wi-fi
  numbers
  firepass
  risk
  open source
  authentication
  smart card
  kerberos
  Business Challenges
  evidence
  SSL
  SSL offload
  NIST
  2048-bit
  certificate
  rss
  blog analytics
  web traffic
  e-cards
  hardware
  support
  diagnostics
  iHealth
  apple
  iPhone
  iPad
  iOS
  itunes
  smartphone
  v10.2.1
  citrix
  vdi
  parody
  satire
  entertainment
  andriod
  virus
  google
  mac
  comscore
  ID theft
  social security
  ssn
  synthetic ID theft
  credit report
  data privacy
  cyber threat
  reports
  50 ways
  2011
  trade show
  silva
  emc
  emc world
  ixia
  viprion
  ssl tps
  vCMP
  outtakes
  acting
  theatre
  tokens
  vpn
  remote access
  intrusion 2.0
  toys
  v11
  ajax
  SANS
  devcentral
  whitehat
  sentinel
  waf
  scanner
  grossman
  iApps
  wan op
  file virtualization
  hawaii
  emea
  ipexpo
  london
  UK
  human behavior
  risk managment
  tech center
  secure vault
  fips
  appliance mode
  copyright
  pearl harbor
  Dec 7
  punchbowl
  honolulu
  staffing
  jobs
  irules
  AppSec
  TradSec
  icsa
  v11.1
  community
  

82,243 Members in 102 Countries and Growing!

Join DevCentral Today!

About DevCentral

DevCentral has been a successful, thriving community for many years. We have always strived to bring you the best technical documentation, discussion forums, blogs, media and much more that we can.

So dive in, get familiar with DevCentral. We hope you like it, we hope it makes your job easier, and lets you get that much more power out of the community. To learn more, make sure to check out the Getting Started section. And if you have any problems, or think something could be easier to use, drop us a line to let us know.

Got It !

We've received your comment and transmitted it directly to DevCentral HQ.

Thanks for taking time to let us know what's on your mind. At DevCentral | Community Matters!

Get In Touch With Us

Have questions, suggestions or just want to get something off your chest?

Use our handy form below to Direct Connect with DevCentral Mission Control.

Send Us Feedback       or