Posted by:
admin
14 years, 10 months ago
There were a number of tweets yesterday about "best practices". This took me back to Adam Shostack's post at New School on his best practice: Think. Now I am throwing my hat in the ring with:
Improve.
This best practice was in part in reaction to the conversations about APT or Advanced Persistent Threat, or as CSOAndy says: Adaptive Persistent Threat and to some conversations around the pain being felt right now around Zeus and other malware by banks and (mostly) their corporate banking customers. Adaptive is the correct word here. Whatever security mechanism you put in place to protect yourself will eventually be circumvented (most likely) or defeated.
What this means that security is always going to be additive. You can't turn off your firewall just because today's threats go around them. Those old threats are still out there.
It also means you should think about how you structure contracts with vendors. I've long believed that the "permanent license" was not. An annual license makes more sense when your goal is to keep your vendor improving their product.
An interesting sub-practice implied is to start simple. As some of you may know, we have a partner in the corporate banking space, Online Banking Solutions. They have embedded our software tokens for two-factor session and mutual https authentication into their products, including M-Secure Browser, a hardened browser they have in production at a couple of banks. At a recent joint presentation, we were asked if their USB version has "FIPS-whatever encryption". The answer is no, but it certainly could be. It certainly would be more secure if it did, but the current solution solves the current problem of Zeus and other MiTB attacks and traditional phishing and MITM attacks.
The problem with running on a hardware-encrypted USB drive now is that it is expensive to do and might not protect the user from the next attack. It might be better to do transaction authentication on a separate wireless device. Or to require two digital signatures/authentications just like checks that require two signatures. Or maybe it will be to use a hardened USB drive with it's own hardened version of Linux and a hardened, single-site browser. The point is not to over-spend now and plan on improving.
Share on Twitter Share on Facebook
Recent Posts
- Blast-RADIUS attack
- The latest WiKID version includes an SBOM
- WiKID 6 is released!
- Log4j CVE-2021-44228
- Questions about 2FA for AD admins
Archive
2024
2022
- December (1)
2021
2019
2018
2017
2016
2015
2014
- December (2)
- November (3)
- October (3)
- September (5)
- August (4)
- July (5)
- June (5)
- May (2)
- April (2)
- March (2)
- February (3)
- January (1)
2013
2012
- December (1)
- November (1)
- October (5)
- September (1)
- August (1)
- June (2)
- May (2)
- April (1)
- March (2)
- February (3)
- January (1)
2011
2010
- December (2)
- November (3)
- October (3)
- September (4)
- August (1)
- July (1)
- June (3)
- May (3)
- April (1)
- March (1)
- February (6)
- January (3)
2009
- December (4)
- November (1)
- October (3)
- September (3)
- August (2)
- July (5)
- June (6)
- May (8)
- April (7)
- March (6)
- February (4)
- January (427)
2008
- December (1)
Categories
- PCI-DSS (2)
- Two-factor authentication (3)
Tags
- wireless-cellular-mobile-devices (7)
- Two-factor authentication (10)
- Wireless, cellular, mobile devices (6)
- NPS (1)
- Phishing and Fraud (111)
- Active Directory (1)
- pam-radius (3)
- privileged access (2)
- Cloud Security (10)
- Mutual Authentication (60)
- Web Application Authentication (1)
- Authentication Attacks (99)
- pci (50)
- Security and Economics (97)
- WiKID (133)
- pam (2)
- VPN (1)
- Installation (2)
- RADIUS Server (1)
- Open Source (64)
- Tutorial (2)
- Strong Authentication (35)
- Information Security (137)
- Transaction Authentication (13)
- Miscellaneous (100)
- Linux (2)
- transaction-authentication (6)
- Two Factor Authentication (254)