Wednesday, 26 August 2009

Microsoft's EPIC FAIL

Probably everyone has seen it already... It hit reddit.com yesterday getting to the top of the front page, BBC wrote about it, it was all over Twitter, and got even it's own video clip/mockup, etc. Simply the best FAIL!

BBC did a great job in capturing it (see BBC link above for full article) - I was too slow to do a screen shot this time :-/ I have removed the image from here - don't want to upset BBC by copying their content without permission (although probably I might call it on fair use policy - anyway just see the links above and that's it).

Funny enough link on reddit.com that points to dropbox.com is no longer valid (404 win!) and Microsoft has replaced the image to be as the original one (oops - forgot to resize orange bar below the text - that happens if you have rocket a up your ****), but no worries, you have faithful users on the Internet :-D

Sunday, 7 June 2009

Are TFL top-up machines secure?

Another day, another FAIL.This becomes my daily routine it seems, but that's another story.
This time TFL - operating London's public transport network that covers undergound, overground, DLR, buses and whatever else comes.



During one of the Security Now! podcasts (#193 was about Conficker so it was somewhere between #194 and #196) one of the main discussion topics was (to no surprise) why Windows shouldn't be used in places like ATMs, hospital equipment (MRI scanners, heart monitors, etc) and most of other control
systems we have and use today.

In fact it's really hard not to agree with that. The arguments were very clear and sound:
  • Most if not all of those systems are "consumer grade", not any kind of "industry type" things
  • They are connected to the network
  • They are not patched in general (it works so don't touch it)
  • Most don't run any antivirus/firewall (not related to business function?)
  • Many were not planned to be put on-line in any way (but we know they are)
The machine above takes cash or card - can we trust it then? Does it run anti-virus software and firewall (it's networked - it should)? How can I be sure it won't do what some ATMs in eastern Europe did? We can't be sure of anything if they end up like above, so feel free to add those to a 'Windows no-go list' if you wish and do top-ups on-line at the TFL website - I think it will be safer than at those machines - in general they don't reinforce any trust I might have had for them some time ago.

T-Mobile (U.S.) got owned?

Few minutes ago I came across a full disclosure post saying no more no less than

Like Checkpoint Tmobile has been owned for some time. We have
everything, their databases, confidental documents, scripts and
programs from their servers,
financial documents up to 2009.
If that's true... Ouch!

Just few hours ago I was thinking "what a nice and quiet weekend evening", hmmmm... seems it was just a quiet time before the storm hits. I guess that news coming from the world may be very interesting, so let's wait and see what happens.


Saturday, 6 June 2009

EC-Council courses certified by NSA

Chris Riley brought up a good post on his blog...something I totally missed in the news :-o

Following (literally) the press release from EC-Council we read "EC-Council Courseware certified to have met the CNSS Standards by the
United States National Security Agency (NSA) and the Committee on
National Security Systems (CNSS)
". Shocked? I am!

What does it change or prove?
From my point of view it says that EC-Council knows how to do marketing, which obviously they do a lot. My impression when meeting EC-Council people at different expos and conferences were like, uhmmm... security? WTF? Business is business, most important part is to keep it going. Create a business model (hey - I don't blame you for that, good you succeeded!), build brand, loyal user base, make some media stir and here you go. It's simple - if I see someone talking about security with $$$ signs in his eyes, that's a sign for me to back off and go elsewhere. That's my personal impression regarding EC-Council as an organization - full stop.

My thoughts on standards and compliance
Chris has raised in his post some really good points about material quality. I would add, that conforming to standards and requirements (be it well known old friend ISO 9001 or any other ISO-based, PCI-DSS, etc - you name it) is just a matter of proper wording in the marketing materials and in some internal paperwork. I used to work in this area for some time (ie. standards, certification, implementation, paperwork - I've been on both sides of the process, from the bottom to quite high in the chain) and I can tell you that there are two ways to achieve so called "compliance" with any "standard" I came across so far - make damn sure you do what you say you do and do it very well and that conforms to requirements... or make sure auditors don't bother reading :-) and "OK" what they got. First impression method, social engineering, etc - great place to apply those!

Paper will accept anything you want, but this doesn't change in a bit what people know, what they do, how they work, use their knowledge (how much are they worth), etc.

Nothing has changed... exactly nothing!


Thursday, 30 April 2009

The good, the bad and the ugly - Infosecurity Europe

Quick summary of Infosecurity Europe 2009, based on a bit more than a day I've spent there...

THE GOOD

There is always some good stuff at the conferences like Infosecurity. This one is no exception!

  • EDR was more than happy to show us how their data destruction really works

... and after that you are left with a disk... almost like new :-) Thanks for the demo!


This would be all good so far... so let's move on...

Wednesday, 1 April 2009

DIY cloud computing - it is easier than you may think!

It seems that the weather forecast for the Internet is a bit "cloudy" nowadays and it will stay this way at least for some time. The "clouds" are a very hot topic right now and more and more companies try to get on the bandwagon as soon as possible - some just run tests while others go into production. You can run "your own" cloud environment for peanuts, the costs are so marginal that it made me laugh when I got my last bill from Amazon AWS, but nevertheless it doesn't always calculate to run your stuff on commercial cloud, especially if you have hardware at hand. The DIY approach is easier than it seems to be. Here is how I've built my own, small "cloud" to solve a problem I was facing at work. It's not a rocket science, it's not full blown management system with hundreds of machines... it works for me and I believe anyone can build similar system - hopefully much better than I did with mine.

Staying away from terminology like HPC/cluster/cloud/grid and meanings of those I use the term "cloud" because I think it's the closest to what I've got now in my prototype - it's still work in progress and it gets even more "cloudy" or change shape otherwise. There won't be any code this time - maybe when I finish it properly and have some proper performance stats - so far it's just a running and usable PoC I describe here :-)

Wednesday, 25 February 2009

Is that me or is the Internet down? Ahhh... Google Mail is!

As we all know Google had a rough day yesterday - massive "outage" on one of their products... actually a key product - Google Mail. Both, Gmail and Google Apps users (including paid ones) had problems accessing their mail via web interface, but ONLY via web interface. SMTP/POP/IMAP all seemed to work - at least for me - alongside calendars, docs, etc.

Leaving the media hype surrounding this situation (and people saying that google is evil) there is a few things to keep in mind... The situation that happened yesterday leaves no doubt that even the best brains and the best people money can buy, they DO MAKE MISTAKES - as we all do. It happened to Google this time, it may happen to your company tomorrow (or has already happened but you don't want to talk about it).
Yes - I got my part of 'grief and complaints' from my own users, it's perfectly normal situation I would say, so I wasn't even annoyed. I've called Google Support Team, got connected immediately to a very nice guy that confirmed that they have a wide-spread problem running for about 20 minutes now... and that all engineers are already on it (sounds like 'all hands on deck') and offered a callback when it is sorted. As a matter of fact, about 30-45 minutes later webmail access was quite slow but was working again.

Now let's wrap it up:
  1. they had a problem - big deal, who hasn't?
  2. they admitted it - there was no fooling around
  3. they got really good response time and fixed the problem
  4. ... and I would say they will have no problems keeping up to their SLAs (only one access channel was down - webmail, IMAP/POP/SMTP worked for me all the time), so can we say that Google Mail was down? Not really!
So if you are crying/moaning about the situation yesterday, then think again and get over it - it could be much worse! To get you in a better mood - think about calling one of those big telecoms and speaking to 5+ consultants before they put you through to the right department, where you will hear it's a problem on your side, not theirs. How does that sound? Did I hear "8 phone calls, hours wasted on the phone and then 2 weeks to get it fixed"?