Showing posts with label secrecy. Show all posts
Showing posts with label secrecy. Show all posts

Monday, August 24, 2015

Bleeding Data: SXSW Interactive Proposal

With new data breaches appearing in the news every day, how can anyone protect their information? With a few simple tools - which we will demonstrate - you can dramatically improve the privacy of your personal information. 

Among the tools that we will provide and explain are Secunia PSI; KeePass Password Manager; and OpenDNS.

We chose those and other tools because they have high reputational value in the computer security community. They are easy to use. They specifically protect the most vulnerable aspects of your information flow. 

We will guide the workshop attendees through the installation and use of the tools. Tutors from the Austin computer security community will be on hand to provide individual instruction.

Selection of SXSW Interactive workshops and panels is, in part, by open voting. To vote and view the proposal video click here: http://panelpicker.sxsw.com/vote/50060

You can view the video directly on YouTube here:


You can read more about how to protect your personal information on Laurel's blog, IntentionalPrivacy.

Also on NecessaryFacts:

Friday, October 24, 2014

LASCON 2014

OWASP (the Open Web Application Security Project) sponsors LASCON, the Lonestar Application Security Conference.  This year's two-day assembly brought together cutting edge vendors, theoreticians, and developers.  It was my privilege to be the introductory speaker serving KUNAL ANAND of Prevoty and KSENIA DMITRIEVA of Cigital.  The general session guest speakers included Martin Hellman, co-inventor of Public Key Cryptography, and Kelley Misata, formerly of Tor, now with Suricata.
Martin Hellman (right)
"The Open Web Application Security Project (OWASP) is a 501(c)(3) worldwide not-for-profit charitable organization focused on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks." - www.OWASP.org



Ksenia Dmitrieva of Cigital answers questions
after her presentation
"Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. You'll find everything about OWASP here on or linked from our wiki and current information on our OWASP Blog. OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide. We ask that the community look out for inappropriate uses of the OWASP brand including use of our name, logos, project names and other trademark issues." -- OWASP.


Keynote Speaker Kelley Misata spoke on behalf of Tor.
Misata is now working with the CERIAS project of Purdue
and Suricata, an Open Source Foundation partner
.
Martin Hellman worked directly with Whitfield Diffie to realize public key cryptography. They then discovered that Ralph Merkle had independently submitted papers some months earlier.  Merkle's work was rejected for openly running contrary to the mainstream of cryptographic theory. ("Secure Communications over Insecure Channels" on his website here.) They published congruent ideas but under a less contrarian article title, "New Directions in Cryptography." (On his own pages here and archived widely, including here.).  Also,  Hellman was a professor. (Diffie was his doctoral student). On the other hand, Merkle was working on his doctorate; and he had no support for his theories from his own mentors.  So Hellman brought more social status to the supposedly impartial peer-review process.  He also brought Merkle to Stanford from Berkeley.

Kelley Misata had been cyber-stalked for eight years. She watched while her computer was taken over and worked remotely. Trashy emails were posted in her name from cuts and pastes from her own Facebook pages. She could not apply for a job without her stalker knowing it and intruding.  She figured out who he was.  However, the FBI said that they were powerless, and a judge refused to issue a restraining order, both because the stalker hid behind Tor and could not be identified.  So, she took her MBA and her experience in marketing to Tor where she advocated for privacy and security. She now helps the Center for Education and Research in Information Assurance and Security (CERIAS) while working on her doctorate at Purdue.

Appropriately, the front of the vendor's hall was held by White Hat Security of Santa Clara.  All of the sellers were satisfied to have made good contacts. While setting up his talk, Kunal Anand underscored for me the importance of qualified leads to a start-up looking to scale its services. 


OWASP co-founder and Contrast Security CTO Jeff Williams 
Among the fifteen sponsors set up in the vendor hall were HP (both local and national sales offices), Contrast Security of Palo Alto, Trustwave, F5 Networks (headquartered in Seattle), Checkmarx from Chicago, Qualys (Redwood City), and K2Share from College Station. Texas.
Wade Williamson from Shape Security of Mountainview. 
OWASP conventions always include several security challenges, such as "capture the flag" and locksporting.  The convention name tags were puzzles with imbedded clues.  (Decipher the Roman numerals into an IP address and go from there.)  Winners received a challenge coin. "Capture the flag" lets would-be hackers attack knowledgeable defenders of a target computer.  Of course, all the firewalls do you no good if someone can pop the lock on your server cage. 


Jgor taught me how to pick a four-wheel combination lock.
After I felt successfully for the solution, he showed a slide
with a cutaway view of the internals . 
Over 40 different breakout sessions provided expert presentations on application security, rugged development, agile development, cryptography, IoT and mobile platforms, and an array of special case studies.  The two-day conference ended with giveaways and drawings. The top prize was a Pwn Phone from Pwnie Express.


We enjoyed great guitar work from Chris Devore
at both lunches and the Thursday evening social.
ALSO ON NECESSARY FACTS
B-Sides 2013
Open Secrets
Fortune Cookie in Hex Code
The Eurion Project
Securing Your Viper Against Cylons

Saturday, December 21, 2013

The Code Book

In the University of Texas library stacks, looking for the early history of word processors, I was in the Zs and discovered that my book on codes and ciphers was actually checked out.  It took three editions to get it right.  The first 3000 years were easy enough to understand. I wrote programs in Basic that transposed and substituted right up through the Playfair and Vigenere ciphers.  RSA was a tough nut to crack; and I finally just cut-and-pasted one of their own graphics and quoted their own abstract. 
 As the IBM-PC finally overtook the TRS-80, other amateur cryptographers published more complete books of programs for personal computers.  By 1993 or so, with Phil Zimmermann's PGP becoming common in sig lines and footers, applied personal cryptography sped light years past high school algebra in Basic. PGP is now part of the Symantec suite. 

This week, news about more of Edward Snowden's leaks revealed that RSA (now an EMC label) took $10 million from the NSA and installed weaknesses to allow backdoors to its encryption.

Codes and ciphers are about more than sending secret messages, though there is that.  When the first public key cryptosystems were being publicized in the 1970s, authentication was a suggested application.  How do you validate a digital signature?  If you have the answer to the public key question, then you must hold the authenticating string. Although the first Diffie-Hellman knapsack system was later exposed for weaknesses, the problem itself and the algorithms for instantiating it remain as possible platforms. Others have been invented since.

Whether or not you rely on cryptography, and independent of which (if any) system(s) you choose, codes and ciphers are in and of your daily world. They make credit card transactions and cellphone handshaking possible.  They allow the efficient compression of messages. In fact, the common zip command on your computer is one way to encipher any message. It is easy to break, but the message is no longer in plaintext. Many other simple systems are available.  No better or worse than the Yale or Schlage lock on your front door, they do stop all honest people and many who are not.

Of all the secret messages from World War II, many remain unbroken because the need is gone. Those ciphers have kept their secrets. 

Of all the "unbreakable" codes, the one-time pad and the dictionary code remain easy and effective.

ALSO ON NECESSARY FACTS
Basic: Turing's Truth
Patterns in Pi
Open Secrets
BSides Austin 2013
Visualizing Complex Data

Friday, December 7, 2012

Open Secrets

A popular TED Talks from Johanna Blakley (view here), showed that revenues in the fashion industry where intellectual property rights are weak are three orders of magnitude greater than in sectors with strong intellectual property rights.  In "Bourgeois Virtue (link here)" Deirdre McCloskey cited Shakespeare's Merchant of Venice as one of many examples of the importance of discourse to commerce: "I will buy with you, sell with you, talk with you, walk with you, and so following...  What news on the Rialto?"  Modern insurance and modern banking both have origins in the coffeehouses of London. The great value in urban culture is that communication is profitable.  



Openness brings risk.  We all take the keys from the car and lock the doors when we leave it parked. But for 100 years collectivists right and left declared that our open society would be easy to infiltrate and destroy. We're here. The Nazis and Communists are gone. Today, the open society, the agora, is attacked by new enemies who fear knowledge.  While the need to secure our infrastructure is clear, it is more important to maintain, reward and enhance the creation and  transmission of information, money, goods, services, and people.



In Systems of Survival: A Dialogue on the Moral Foundations of Commerce and Politics Jane Jacobs identified the dichotomy between the commercial ethos and the guardian way. Secrecy is important to police forces, armies, charities, and socialist economies.  On the other hand, scientists, farmers, and merchants depend on open communication.



Your computer is the result of a completely open and unregulated market in cybernetics.  No government agency defines what a computer is, who can build one, who can own a computer or who is qualified to program one.   The USSR excelled in theoretical mathematics and chess because the people of the mind, the initiators, the doers, the contrarians had no other outlet.  Politics was forbidden and economics did not exist. Meanwhile, in America, personal enterprise continued to blossom and bear fruit.


In 1991, I was a delegate from the Michigan patron community to the White House Conference on Libraries and Information Services (WHCLIS-2).  Among the guest speakers was Newt Gingrich.  As a result of that, I sent a check to GOPAC and benefited from being on their mailing list for audio tapes.  At some $100-a-plate dinner Dr. Gingrich said that at a previous dinner, someone asked him if he did not think that it was horrible that welfare recipients sell their food stamps for 75 cents on the dollar to buy booze and cigarettes.  The professor said, "Of course not."  These people are Americans, he said.  "You cannot give an American a negotiable instrument and then complain when they negotiate it for something they want."

In April 2009, I attended a presentation by former KGB agent Boris Yuzhin. (See New York Times story "Graying Double Agent" here.  Visit his Wikipedia biography here. Read the ZoomInfo sketch here.)



As he told it, trained in computer architecture, he was recruited by the KGB to come to American and find others to work for the USSR. The KGB heard that there were a lot of "communists" at Berkeley, so they sent him there. Not only did none of the comrades want to talk to him, when they did, it was a debate -- and he lost. He could not win a debate on Marxism because in the USSR they could not read all of the theoretical works which we in the USA can. So, he got a carrel at the library and began studying Marxism in the USA.  That convinced him of the strength of an open society. He defected to our side.

ALSO ON NECESSARY FACTS
Engines of Creation
The Genius of Design
Venture Capital
Entrepreneurship