Showing posts with label bullshit. Show all posts
Showing posts with label bullshit. Show all posts

Thursday, January 8, 2009

Fear and Terror! All your data are being stolen!

Wow, this is just asinine, with emphasis on the ass part. http://news.bbc.co.uk/2/hi/technology/7816446.stm

This article is telling everyone that if you really want your data to be safe when you throw away your computer, you need to beat the thing to a pulp with a hammer.
The most straightforward solution, according to Which?, is complete destruction - and it recommends using a hammer.

If you're that worried, get rid of it properly: burn it or put it in acid.
Frankly, I think that this article is irresponsible. In a nutshell, the article is saying that yes, you can find software out there that will erase your data securely, but the only way to be completely positive is if you beat your hard drive with a hammer. This, I believe, does a disservice to the non-computer experts of the world. Consider a case of two identical hard drives, one beaten to pieces and the other overwritten a single time with random data. Which one would be easier to retrieve data from?

The answer is the broken one. Now I wouldn't want to be the guy to have to do it, but you can piece together all those broken platters and recover data from them. I was watching Forensic Files a few months ago and they had a case where someone had cut up a 5 1/4 inch floppy drive with scissors and the Department of Defense was able to piece it back together and get the data. On the other hand, recovering data that has been overwritten with other data is as close to impossible as I would say you can get...and it becomes less possible as hard drive densities increase.

Once upon a time there was a man named Peter Gutmann who suggested that with the use of an electron microscope you might be able to figure out what was once written to a part of a hard drive that had been overwritten. That lead people to come up with policies like "you have to overwrite 7 times before it is safe to dispose of." However, despite all the assurances I've heard that it can be done, nobody knows anyone that has actually done it. A couple years back I took a forensic class with Mike Murr from the SANS institute and he was talking about this very thing. Everyone knows someone that has done it, but nobody has done it themself.

I should be clear that I'm talking about data that has been deleted and overwritten by the operating system or some other software. Here is a great quote from the Wikipedia entry on the subject:
Daniel Feenberg, an economist at the private National Bureau of Economic Research, claims that the chances of overwritten data being recovered from a modern hard drive amount to "urban legend".[3] Daniel Feensberg also points to the interesting fact, that the "18 minute gap" Rosemary Woods created on the tape of Nixon discussing the Watergate break-in, has not been recovered. An easy task compared to recovery of a modern high density digital signal.
I'm worried about people like my dad. He's going to read something like this and instead of looking for some free software to clear his old hard drive, he's going to take it out to the garage and hit it with a hammer. He's going to go through all that work and possibly give himself a heart attack when he could have sat in his living room chair, watching TV and actually had better protection. Poor dad. Please don't let this happen to your dad. Spread the word that overwriting or encrypting your data is more effective than pulverizing it.

Tuesday, December 23, 2008

PI licenses for forensics: Texas screws the pooch even harder.

I just read this blog posting from Benjamin Wright talking about some decisions made by the Texas Private Security Bureau. Benjamin has been keeping a close watch on this issue in Texas and his input on the subject has been very valuable.

In previous articles, Benjamin has talked about the law in Texas requiring Private Investigator licenses for persons performing digital forensic work and how that law was being used to challenge tickets issued by red-light cameras.

Now the Texas Private Security Bureau has issued a decision that makes it OK for the red-light cameras to operate, but I'm afraid that it muddies the water about who can and cannot perform digital forensics without a PI license. And I have to disagree with Benjamin's conclusion that this is probably a step in the right direction. I have been very clear about my opinion that the whole notion is completely bunk, and this new decision doesn't help the digital forensic field because it allows the government in the state of Texas to sidestep the B.S. that comes with this law, but everyone else still has to shovel it.

I also think that my reading of the decision left me with a different conclusion about the rational that the Bureau used to justify their decision than what Benjamin reported on. The main reason that the Bureau does not see a problem with the red-light cameras is that they are operated by municipalities, and the government is exempt under the Texas law. The Bureau felt that the contractors are only providing ministerial work for the municipalities.

I feel that this decision skirts the intent of the law as it was passed. In theory, the reason this law was passed was to ensure that people's rights were not violated when an untrained, unlicensed person undertook an investigation. If we accept for a brief moment that having a PI license does make you more qualified to perform the investigation then this decision is in essence allowing the government to use unqualified persons to perform digital investigations. I mean, I understand that a police officer is trained in how to gather evidence while protecting people's rights, but these cameras are probably operated by some dude in the IT department. That dude, by the way, has no more forensic qualification than I do. So when a private organization wants to investigate something they need to hire someone with a PI license to protect everyone's rights. But when the government wants to investigate something they don't need to hire someone that has special training on the matter. The libertarian in me is screaming that the people need just as much protection from their government as they do from corporations. The government in Texas can use unlicensed investigators to gather evidence against you, but you need to hire a licensed investigator to counter that evidence.

This decision by the Bureau also leaves us scratching our heads as to how much work an unlicensed investigator can do for the government and still fit the definition of ministerial acts. For example, the red light cameras are simply gathering evidence. Does that mean that acquiring a hard drive image is also simply a ministerial act? What if the investigator takes special steps to gather data from a Host Protected Area or Device Configuration Overlay? Where does it stop?

So I am very disappointed with this decision. By allowing the State government of Texas to avoid the pain of this law, there is a reduced probability that sensibility will prevail and the law will be changed. People in Texas are going to be hiring Sam Spade to do their forensic work and talented IT people who have a passion for technology will be kept out of the business.

Sunday, December 7, 2008

More on PI Licenses for Digital Forensic Work.

There has been a little more chatter on the subject of private investigator licenses for people performing digital forensic work, or in other cases perform digital investigations.

Here is a short piece by Ben Wright (who commented on my blog the other day) about unintended consequences in Texas from their law requiring PI licenses for computer investigations. Hint: People are challenging tickets issues by red light cameras.

I also found a posting where the State of Michigan has defined what it would take for you to be a private investigator working on computer forensic cases. I have to actually say that I'm not up in arms about what Michigan has done as much as what I've seen in Texas. The Michigan law requires you to be a private investigator, but you can become a private investigator by getting certified as a computer forensic specialist and they had defined what exactly they expect from a certification program. So rather than tell me that I have to spend 10,000 hours working for someone peeking in peoples windows to catch cheating spouses before I can do computer forensic work, I have been given the option to complete a reasonable amount of study in areas that make sense for what I would want to do. Kudos to you Michigan.

There is still the problem of defining what an investigation is. Many times system administrators have to figure out what is causing a problem on their systems...and sometimes that problem turns out to be people. At what point would you say that their work has become an investigation? Is it an investigation if you set out from the start to catch a criminal as is the case for the red light cameras in Texas? What if a student comes to the help desk with a computer that is acting funny and I start to investigate? During the investigation I might go through log files, and I might run tools like Seccheck and rootkit revelaer. Maybe I'll even take a snapshot of the ram and look for running processes or open ports that are hidden. What if during this process I figure out that someone intentionally installed bad software on the computer and I figure out who did it? Has all the evidence been spoiled because I am not a private investigator and I didn't know that in helping this student out I was going to find evidence of misuse?

I'm also still not a big fan of the whole private investigator license anyway. Even though Michigan has done something to make it easier to swallow, I still don't want to be a private investigator. I am a computer security professional, and I don't want to be lumped in with a group of people 95% of whom do not do what I do. I can't show up to a industry meeting of private investigators and start talking about extracting strings from a hard drive image to find useful files that are hidden in slack space on a hard drive. If it is so important that we forensic types prove our worth then come up with some other licensing for us. Most state legislators recognize that even though coroners do investigative work, they are completely different from private investigators and have different licensing requirements. If there are any states where you can be a county coroner just by getting your PI license then let me know so I don't visit. I don't want Sam Spade performing an autopsy on me.

Saturday, December 6, 2008

Does it seem like people with more education are harder to educate?

I'm kind of annoyed today. I was in meetings for pretty much all of Friday and then after I got home I made the mistake of reading my email. The lesson I've taken away is that people with more education might be more difficult to educate.

For those who don't know me, you can see from my profile that I work for a four year university. So I am surrounded by some of the best and brightest minds in the Western world. Or at least one would think that, but todays events have lead me to doubt that.

Starting in January we are going to have a new standard in place governing the length and complexity of passwords. On Friday I met with some people to talk about the best way to get the message out to the campus community. At this point our standard has been drafted and signed, and we've already presented it to various groups of stakeholders that had no objections. But one faculty member was acting like I was throwing puppies out of the third floor window. He was shocked and incensed that we weren't going to let them use the same password over and over again. He didn't seem to have a problem with us changing passwords every 180 days as long as he could keep setting the password to what it was. He kept asking me "How are they going to remember these passwords?" I can't believe it that an army of PhDs can't remember passwords.

After we got done with that unpleasantness, we moved on to a configuration standard for computers that are available to the Internet. This time I was getting grief because my standard is too difficult to understand. This same faculty member was suggesting that we can't expect people that set up these server to know what things like TCP, SMTP, or DNS are. Sorry, but I feel like if you're going to set up an SMTP server you better know how to make sure it isn't an open relay. I did get some satisfaction from telling him that if I don't enforce these rules then the rest of the Internet will by blacklisting that open relay. And while it may be true that some people wont be able to understand the technical talk in my standard, it still needs to be documented somewhere so that people don't think we make these requirements up on a server by server basis. This guy just wasn't getting it.

So then after that great day, I went home and ready my email. We have been having a problem with phishing emails being sent to the campus and several people have been tricked into giving their password to spammers. To combat the problem, we have send emails out to the entire campus, and I have gone to several meetings with leadership groups around campus. For the last three months I haven't gone a day without telling someone that ITS will never ask for your password over email. So guess what I found in my inbox? One of the most senior leaders in our organization asking for the fourth time if a phishing email was legitimate or not? I have to say that it is really demoralizing when the leaders that are supposed to be supporting your efforts don't even know what you're doing...even after you have told them four times!

I've heard other security managers mention that it can be difficult to get the message through to senior leadership that information security is important to them. I also have heard that it can be difficult to teach users to change the way they do things. I guess I am disappointed because I thought that a University would be full of thought leaders, lifelong learners, and people that could grasp a simple concept after four lessons. Also, most of the staff and students are grasping these concepts quite quickly. So is it just that people who have more education are too thick-headed to learn this?