Security Info Links^3

The internet is full of great, original content. There is also much derivative material and then of course all the crap.

(this blog aspires to be in the first category, but this post will be a exception : )

Cybersecurity is an interest of mine and several of the feeds in me feedly feed are about that subject. Friday there was an item about “50 InfoSec Blogs You Should Be Reading”. Good, effective title and I followed the link to a list at Digital Guardian with, indeed, 50 security blogs that all looks read-worthy.

Now, where to start?

It is easy to get lost in that much quality content but I hope to apply a MuSCoW scheme in order to find the InfoSec Blogs I Must be reading, those I Should be reading, some I Could be reading and get rid of those I Won’t be reading. Until then at least I got improved content for procrastination.

Thanks to Roger for sharing the link on his Information Security Blog and to Digital Guardian for compiling the original list

So this was me writing a post that links to a post that links to a post that links to many posts. That must be third order derivative content, but good stuff is worth pointing out.

Digital Ethics and the IT-worker’s Nuremberg Defense

I just watched an inspiring webinar from Gartner about “Digital Ethics: How Not to Mess Up With Technology”.

The philosophical background was introduced and some real-life cases discussed, including collection and selling of user data and the moral dilemmas phasing driverless cars. At the end the audience was asked to consider our own stance on digital ethics, with options for being black, gray and white hats:

  • Black: Main goal is “try to make a buck,” there is no place for ethics in business.
  • Gray: Just doing my job, try to avoid the discussion, and when needed, make it up as you go along.
  • White: Think through the ethics of technology, and your position. Ethical responsibility outweighs business responsibility.

Food for thought. Once soldiers may just have been following orders and yuppies may have a mortgage to pay. Is it OK for a software developer to claim that all they did was implement the requirements and deliver on time, budget, scope?

The Software Engineering Code of Ethics and Professional Practice from ACM and IEEE does not provide a lot of help on this issue: “Software engineers shall act consistently with the public interest.”. Well, who is “public” and what is the public’s interest really?

A good example from the webinar: GPS software manufacturer collects (and anonymizes) data about users’ driving habbits. It is sold to ministry of infrastructure so that roads can be improved, public interest, no doubt. Then it is sold to the police who can analyse both where traffic is slow (public is clearly interested) and where people are speeding (public interest more ambiguous).

A more the dramatic example is software for defense and security industry – digital guns and bullets. It may be people that kill people, not guns (or software), but still developers play a role in creating the (more or less obvious) weapons used. Social networks and communication technology play a central role in bringing people together in peaceful demonstrations for popular viewpoints (positive public interest) and the same technologies serve counter demonstrations representing less popular viewpoints (which is of more ambiguous public interest), as well as enabling authorities to infiltrate and disrupt the events (degree of public interest very dependent on your point of view).

Looking in the Company Values isn’t an alternative to the professional code. Justifying actions with Company Values places one at the soldier level and in any case, few companies would have anything ethically ambiguous written into their published Values (but “shareholder value” may lead to flexibility and most companies have mortgages as well).

The only thing left is personal values and the will to stand up for them, which is not always easy, but one’s personal integrity may be worth paying for a too good too be true job offer.

Windows 10 and me (part 2)

Apr 28, 2015 Update: Obviously: If one wants to join the choir of bloggers writing about a major and hyped upcoming tech event, then updating every 5-6 months aren’t good enough…

At first I didn’t intend to write any immediate followup to my previous Window 10 post: “Part 1” should just mark it as a first impression, with a long time relationship coming up with the final release. However, interesting and shareworthy news will be coming, and I will compile and re-post them here.

Windows 10: release date, price, news and features: Everything we know about the future of Windows (Techradar)

New security features, including 2FA: Microsoft beefs up security features in Windows 10 (Techradar)

A new way to update the OS: Windows 10’s very different way of updating (Ars Technica)

In-built support for MKV media files: Watching movies on Windows 10 just got a whole lot easier (Techradar)

Snap! [Updated]

Yesterday [Oct 10] news broke that Gigabytes’ worth of Snapchat photos and videos had been posted on the Internet. Yet another hack with personal info stolen, but what makes this different is that confidentiality was breached at several levels. Not only was data stolen from an insufficiently protected service, but the fact that data was there to be stolen in the first place, goes very much against the point of a service that should destroy messages after few seconds.  It has now reported that the material did not come from Snapchat itself, but from SnapSaved – a third party app used to save the shared files online (detailed report from Ars Technica ->here and comment from the app developer ->here). According to the reports the leak was caused by a webserver that was not configured correctly.

I haven’t tried Snapchat myself – I am probably too old with too boring interests to try out something that looks like a digital doctor game (with opportunities for mature flirting and nasty “your Mommy and Daddy will never know”) – but as long as no laws are broken and noone abused, it ain’t my business [Update: I am definitely too old, but there is plenty of business for some]. However, I feel bad for everyone who has shared private photos and videos with friends, lovers, spouses in good faith that the other part was also using the service in the way it was intended. Now all Snapchatters must wonder if their partners in fun can be trusted

The initial coverage in here Denmark focused on how people are naive and way too trusting on the Internet (plus the inevitable sensationalism), hinting that everybody getting their pictures exposed only got themselves to blame (ha!). And while I do not disagree that people should take web security more seriously, I think it is wrong. First of all, that is blaming the victim, ignoring the criminal hacking/leaking and the negligent hosting. Second, considering the data breaches from major corporations and from public institutions where you have little or no choice of having your data registered, anyone can become a victim at some point. Third, even if the victims have done all the right things to protect them selves online, they would not be protected when the people they shared with stored data that was supposed to be destroyed.

The nature of the incident does not change the usual advice about safe conduct on the internet:

  • Use strong passwords
  • Don’t use the same password on several sites
  • Use two-factor authentication when possible
  • Be careful what services you use and what you install (keep an eye on permissions)
  • Remember you never know who will see content you share on Web (apart from NSA and colleagues),

but this story adds another point to the list:

  • consider if the people you share with understand safe conduct as well and whether you can trust them at all

(actually, this is nothing new and perhaps a painful reminder was due).

In a world fighting global warmth, international terrorism and ebola, this may not seem like a big issue. But when such broken trust takes away the kind of things that makes life  bearable, it is serious.

Windows 10 and me (part 1)

As expected and heavily rumoured, the new Windows 10 was announced on Sep 30 and the Technical Preview made available for anyone interested. Since then IT news sites have filled with hands-on tales, previews and opinions.

Here’s my story. I downloaded the 3.8Gb iso file with the preview overnight, and back from work, I started up VirtualBox and created a virtual machine for the install.  The first attempt failed and I soon learned that one must pick the right type of Windows VM  for this (‘other x64’ doesn’t work, ‘win 8.1 x64 does’ – thanks to betanews for posting the solution : ).

20 minutes and a couple of restarts later  and I could login. There is an option to copy settings from a Windows 8 installation or set up as new. I choose to set up as new. I think the only time I have done such a settings export was from win 3.1 to Win 95 and I wasn’t happy with the result. Now many years later it probably works fine (I should grab a VM and try : ), but with this first install I wanted to see the stock setup.

I enable OneDrive integration (that will make the install actually usable on a small VM disk) and then the installer takes care of a few things and my apps. Windows 10 starts up and my desktop opens, and well, it looks just like the Windows 8.1 desktop on the host.on my Windows 8.1. Then I open the Start menu – the big change that is expected/hoped to redeem Windows – and…

First of all: When I had hit the start button 2 or 3 times, a notification message was shown with the question how hard was it to use start?” (quite unobtrusive and no need close it manually). Well, thanks for asking, I appreciate it. Really. Regardless how this ends, you can’t say MS didn’t ask for feedback. And it is hard to come back later and complain that Win 10 sucks and MS never listens to the users (then again, time will tell if it is an empty gesture to appease critics…).

…and I can see what MS is trying to do here and this hybrid between the newer Start screen and older Start menus may work. I need to play around some more (and let MS know what I think). Probably try first configuring the new menu into something similar to the 8.1 screen which I actually like, then into something like the Win 7 version and finally find whatever middle ground is just the right thing for me.

Apart from the Start menu, it all looks very familiar, in just the same way that every other Windows version has looked a lot like the previous one, while there is probably lots of new stuff under the surface (again, like always).

Update: Just saw a demo of how windows can be snapped into place and easily arranged on the screen. That looks cool. And useful.

I will keep playing and testing, and look forward to the upcoming versions. And in the end it will probably all be fine and I will install the final version on my PC, install the usual applications and keep going, get back to business as usual. Because that is something left out in much of the OS hype and hate: Every OS is useless, it is the apps and how you use them that matters.


PS: Installation of Virtual Box Guest Extensions failed – not surprisingly, considering that Oracle’s developers are also just having their first look at Win 10. So are the charms of pre-release software : )