Posts tonen met het label Bruce Schneider. Alle posts tonen
Posts tonen met het label Bruce Schneider. Alle posts tonen

woensdag 21 april 2010

Typoos? It shuold be verboten!


Want to hide information in a sea of data? Try typoos.

From the RSS feed of Bruce Schneier I was pointed to an article about the nominated head the of US Cyber Command, Lt. Gen. Keith Alexander, the current Director of NSA. In a snipped of his 'job interview' there has slipped a typo that has been copied & pasted in to 9 sites indexed by google.

Google "both government and insustry to consider" [with quotes ofc] and get 9 hits [21st of april 2010 at 09:18 GMT].

Gotta love unique typoos for tracking information spread.

But what if the bad guys would do the same? Use some 'easy to remember but unlikely to make' spelling errors so their cells can easily find instructions?

Just like Steganography, this should be investigated and a lot of money poured into to keep the spy catchers happy & busy.

donderdag 20 maart 2008

Inside the Twisted Mind of the Security Professional

Uncle Milton Industries has been selling ant farms to children since 1956. Some years ago, I remember opening one up with a friend. There were no actual ants included in the box. Instead, there was a card that you filled in with your address, and the company would mail you some ants. My friend expressed surprise that you could get ants sent to you in the mail.

I replied: "What's really interesting is that these people will send a tube of live ants to anyone you tell them to."

Security requires a particular mindset. Security professionals -- at least the good ones -- see the world differently. They can't walk into a store without noticing how they might shoplift. They can't use a computer without wondering about the security vulnerabilities. They can't vote without trying to figure out how to vote twice. They just can't help it.

SmartWater is a liquid with a unique identifier linked to a particular owner. "The idea is for me to paint this stuff on my valuables as proof of ownership," I wrote when I first learned about the idea. "I think a better idea would be for me to paint it on your valuables, and then call the police."

Really, we can't help it.

This kind of thinking is not natural for most people. It's not natural for engineers. Good engineering involves thinking about how things can be made to work; the security mindset involves thinking about how things can be made to fail. It involves thinking like an attacker, an adversary or a criminal. You don't have to exploit the vulnerabilities you find, but if you don't see the world that way, you'll never notice most security problems.

[...]

The security mindset is a valuable skill that everyone can benefit from, regardless of career path.