Wednesday, October 19, 2011

Blame the humble “CC” for data leaks

Many of us have either been a victim off or perpetuator of the “CC” gaffe. Instead of using the “BCC” function we inadvertently send mails using a “CC” which results in recipients being aware of the other members of the group. Whether it is a party invite or a large bank disclosing the name of its high rollers, the simple “CC” is one of the big sources of inadvertent data leaks.
Many times we deliberately “CC” a wider audience to make sure we cover anyone remotely concerned with the mail contents irrespective of information confidentiality and adherence to the simple principle of need to know. These fringe recipients may not value the information, forwarding or disclosing it to others. In extreme cases copies of these mails find their way to media or social networks. If you are surprised at how quickly your organization’s grapevine got hold of the news, the humble “CC” may be to blame!

Tuesday, October 18, 2011

Woman CEO cyber harasses female coworker

Woman CEO maligns female colleague on Net, detained  ran the unusual title of news report by the Times of India. Apparently a women CEO had been cyber harassing her junior by posting remarks about her character or lack thereof which “described the victim as a sex pest who eyed newly recruited young men and was also "having a good time with a former employee". Apparently the women CEO was jealous of the rapid rise of the victim and wanted to bias her management against her.
This case was unusual as it demonstrates how the career pressures and workplace politics spill online with jealous peers using the net to spread a disinformation or disaccreditation campaign using the anonymity of cyberspace.
The important aspect of this news item was the victim registering a complaint to the cyberpolice. I am sure that simply catching the perpetrator must have brought great joy. It also underscores the importance of having a social networking policy and strong corporate governance.

Monday, October 17, 2011

The relationship between the threat of political violence and Cybersecurity attacks

The Indian political story is markedly different from what happens in the rest of the world. Firebrand politicians make loaded statement to create divides or spur street violence to win votes by appeasing majority sentiment. The police fail to arrest these leaders fearing a mass breakdown in the law and order situation and instead arrest a few minor miscreants. This constant threat of violence ensures that leaders usually get away with actions and statements that are simply unacceptable to Indians at large.
In the security world I see a similar pattern of retribution or vigilante attacks if a business targets hackers. There are two classic examples. The first was Sony; it went after a hacker who disclosed vulnerabilities in the Playstation, and issued threats of penal actions against other who may try to compromise its products, which was swiftly followed by what we all know to be a cyber cyclone which left Sony poorer by $200 million.  Later, an arrest of an alleged perpetrator of the first attack led to a follow on attack.  Wikileaks was the second example; the retribution was in response to actions taken to shutdown Wikileaks and arrest Assange for the disclosure of US cables.
Businesses now face a tough decision; do they prosecute and eventually make the world a safer place or do they ignore and settle such attacks? 

Monday, October 10, 2011

The Impact of the Rise of Tablets on Corporate Security

India launched a 35$ tablet based on Android 2.2. It may lack sophistication but has the functionality needed to browse the web, use apps and so forth. This launch is a future indication of how cheap and therefore ubiquitous a tablet is set to become. Corporate employees will soon carry a tablet as a personal item.
The cultural change brought on by online banking, shopping and social networks pressured IT departments to allow access to social sites through their corporate networks. Most refused citing five main reasons; loss of productivity, need for larger bandwidth, security reasons such as malware, violation of corporate policy (viewing adult content, legal issues) and fear of employees posting uncensored content (against other employees or corporate info). But these restrictions simply suppressed a desire. Smartphone’s allowed limited access to social networking sites and email but lacked in rich browsing experience.
Tablets overcome this limitation with larger screen size. As the device and the mobile data access charges are paid by the employee the IT department has no control over its use. Of the five main reasons for disallowing access to social networks the company is freed from; risk of malware, legal issues and higher bandwidth charges. The risks of malware does not go away but simply shifts from the company to the user, but baring this the company will not be able to control the loss of productivity, violation of company policy and uncensored content.
Companies will have to learn to accept the risks, just as companies long stopped trying to prevent employees chatting in corridors and set-up quiet corners and coffee places for employees to mingle.  The net result was an increase in conversations around business and better productivity.
The next step for security professionals will be to modify company policy to accommodate the use of employee owned tablet in the workplace which may be difficult to monitor and enforce.