Note: this was an old post that I never got around to posting. Better late than never, I guess.
This is a more technical post than I usually do so bear with me. I spent the day yesterday at a security symposium being inundated by PowerPoint presentations and the requisite bullet points galore.
The Boise chapter of the ISSA (Information Systems Security Association) puts this event on every year and last year's made me not want to attend this one, but a day off from work being a day off from work, I'm not one to look a gift horse in the mouth. The speakers weren't terribly good and it was mostly boring. A lot of people must have felt the same way because the attendance was depressed compared to last year.
First, the president of the international ISSA, Howard Schmidt, gave a keynote address which, while it had its interesting points, was mostly a namedropping exercise (I know Bill Gates, yada yada ... worked in the White House, yada yada, FBI, CIA, Air Force, blah blah). Then Michael Reifer, a National Security Agency employee, discussed the Network Geolocation Technology process which he co-invented. It's an interesting enough technology that attempts to determine the physical geographic location (city-level resolution only) of a network connection using Internet latency. Supposedly, this will help online commerce outfits better pinpoint fraud.
Reifer was a pretty good speaker and made fun of being an NSA employee in general and about the NSA and geolocation (look, they're coming after us with Geolocation!) in particular. The spooky thing is, the video cameras ordinarily taping all the lectures were turned off and facing backwards while he was speaking and there's no photograph of him on the list of speakers page. He also holds several classified patents, Ooooo.
John Wylder
John Wylder is a halfway decent speaker who works for Microsoft (or, as their table sign read Micro Soft, heh). Problem is, the bullet-ridden PowerPoint presentation made it very difficult to follow his otherwise interesting speech about the future of Internet security. He constructed an intriguing metaphor-laden tale about Internet security, the banking "industry" and the Wild West in Arizona, circa 1890.
The point is, he said, that vendors today are essentially selling guns, just like in the Wild West in which everyone had to have a gun to defend themselves. In the Internet age, these guns are the various anti-virus, anti-spam, anti-etc. He calls it an arms race and that it needs to stop. He then made a connection to banking. In Ye Olden Times, every state could print its own money and several things happened as a result. For starters, no one trusted checks and cash issued by any out-of-state banks. People bought vaults to keep their cash oh hand and hired personal security for protection.
It wasn't until the advent of the FDIC and the Federal Reserve that things became standardized and the insurance provided by the FDIC engendered trust in transactions among others. His point being that there evolved this centralized mega-overseer of sorts that ensured fair play and created trust. His idea then is to either create something like this for security on the Internet or create an Internet equivalent to the FDIC that will ensure that losses incurred while using the Internet as provided by this body will be refunded. Apparently, the Fed and the FDIC
Until then, he says, Vista is the best stop-gap measure. Yawn, I knew it would turn out to be selling stratagem for Microsoft (of course, can you blame him?) but he fails to mention—maybe think of is a better term—several downfalls to his proffered solution. As an aside, wouldn't you know it that a Microsoft employee thinks a centralized source of security is a good thing? H'm.
The strength of the Internet partly lies in the decentralized nature of the beast. It's one of its weak spots, sure, but it's more of a strong point than anything. It ensures diversification, something, as any amateur Biologist will tell you, ensures systemic disease resistance and the continuance of "life," albeit technological life in this case.
Secondly, the reason things are this fucked up is due to, in no small measure, to Microsoft's software building practices itself. Sure, Vista was built with strict security guidelines, but what good does that really do? I mean, practically, from the news reports, Vista doesn't seem that particularly safe as it is now. I'm pretty sure there's going to be that unending stream of vulnerability patches we Windows admins all know and love, even for this, the supposed "safest, most secure OS we have today."
These are just two of the quick thoughts I have concerning this idea, but kudos to Microsoft for even thinking about security and attempting to do something about it. One gets the feeling, looking at its present and prior software offerings that security wasn't high on Microsoft's priorities. I base this mostly on the number of freakin' patches and updates and hotfixes and all that fucking nonsense I have to apply every so often.
Dunham on Rootkits
Ken Dunham is the outgoing president of the Boise chapter. He's an interesting little fellow, to be sure, with his long list of certifications (CISSO, GSEC, GREM, GCIH--Gold GCIH, even!) and a fascinating lisp. Ken led a "hands-on" review of some of the more interesting Rootkits available today and showed us, using a VMWare virtual machine running Windows XP and a suite of anti-rootkit tools, how to combat these nefarious bits of code. Mainly, what I got was: block anything coming from the 81/8 network. Also, the Rustock.C rootkit is a bad mofo. Undetectable and irremovable, this bad boy is a monster. Fascinating, really, and the best part of the conference.
On returning home, I immediate ran some of the tools he'd told us about, starting with IceSword. My computer immediately blue screened.
Uh oh! This is exactly what Rootkits do, attempt to escape detection by forcefully rebooting the machine.
It turned out, thankfully, that this happened due to another application attempting an update at the same time as I was running IceSword. All the other anti-rootkit software I ran showed a clean system, including IceSword. These things are nasty and will make your online life a living hell should you get infected.
Be careful out there.
No comments:
Post a Comment