Huthuthut
Blessed are the Geeks, for they shall internet the earth
Network Security... Hut hut hut!
William M. Nett
Hut
hut hut hut...That's what I think of when I contemplate modern day
Infrastructure Security and corporate policies. A whole lotta hoopla with
black suits running around, clueless, aimless, and oblivious. My jaw hit the
floor when I saw the want ad for a computer security professional in a
civilian organization with a government Top Secret (with polygraph)
clearance! What's more is that most companies with open computer security
related positions require nothing less than a BS degree and government
secret (or civilian equivalent) clearance! "Security and credibility is
paramount," they say... and yet they all still get hacked and
exploited. Don't believe me? Go to any major bookstore and pick up a current
copy of 2600 magazine, "The hacker Quarterly." In it you will find
the IP addresses and machine names of an entire class B network... which
belongs to NCSC.MIL (National Computer Security Center) ahem, that's the NSA
for those of you who don't know. Let me shed some light on this.
Someone who has recently acquired a BS degree in computer science is already
two years behind in the computer security field when he or she graduates.
Computer security moves far faster than educational curriculum developers
can publish. Likewise, someone with a security clearance is often
intimidated by organizations about consorting with real hackers and their
groups and therefore gain no insight about modern methods of attacks. They
become reactive security consultants with little or obsolete knowledge. When
management asks why, the newbie focuses more intently on the problem (insert
blinders) and less on the overall
picture. This is exactly what the 'hacker' wants your Joe or Jane security
person to do.
Also, consider the following: 1. The dot com bubble busted, and left many budding computer professionals out of a job. 2. The biggest hacking threat to companies and organizations are former disgruntled employees. 3. The second biggest hacking threat to companies and organizations are 'script kiddies'. 4. Most companies have little or no clearance requirements for non or low computer related positions. 5. Many ex-computer professionals were forced to accept non or low computer related jobs to feed their families and make their mortgages. 6. Three to six percent of low wage employees are either convicted felons or illegal immigrants. 7. 65% of all companies that check for felony records, only check within their state. 8. 47% of convicted felons move to another state as soon as legally possible, to avoid employment discrimination. 9. The ratio of hackers to employed computer security professionals is +1,000:1. 10. Most companies spend more money and thought on coffee supplies and condiments, than on computer security and computer security education. 11. 95% of all Windows based computers can be compromised in less than ten minutes with hands on access leaving no trace of breach. 12. 81% of employees that use computers would be reluctant to report that their computer has been hacked for fear of reprimand. 13. A recent 'war-drive' through downtown San Diego's Broadway unveiled 147 wireless access points... less that 34% had their security turned on. 14. Recently, a news station attache' crossed a Mexican border with a fake ID baring the picture of one the FBI's ten most wanted for terrorist connections... and was not stopped. 15. The FBI has granted 'secret' clearances to civilian employees whom refuse to pay income taxes! 16. The longer and more complex the password requirement is, the simpler the employee will try to make it so they can remember. 17. 79% of corporate employees either have no idea who their security officer is, or are afraid to approach them. 18. Physical Security Guards are often paid less than $11/hr and are legally required to do nothing more than to observe and report. 19. Physical Security Guards often do not even need a high school diploma to be employed. 20. 98% of social engineering hacks are sucessfull within the first three attempts.
So, I have to ask... who's taking out your office trash? How much does your receptionist know about information security? How do you classify your documents and to whom do you make them available to? Does your office post-it-notes have passwords written on them? How many people have you 'let-go' and how many of them have enough inside company operational knowledge to cause trouble? If you outsource... how much do you know about your outsourcing company and more importantly it's hiring requirements? How many rogue wireless access points does your company have on it's network? Do they have an information 'chain of custody?' Do they require password changes with complex attributes on a regular basis?
If you cannot definitively answer all of these questions... then you are in trouble. But, I can't help you... Your strict policies exclude me from being hired unless I apply for a janitorial position with the same physical access as your most senior network administrator. In fact, I really don't want to help you. You turned your noses up at me, and those like me... so accept the nostril as I turn mine towards you... and hackers explore your vulnerabilities. Personally, I'd like the government to apply the same policies to congressmen and congress women that you have applied to me...but where would we be then?
Of course there can be a resolve for you... Get educated, and instead of being top heavy with narrow-minded personnel security requirements, develop policies which disseminate responsibilities and encourage reporting on appropriate teired levels. You can't expect everyone in your office to pass a security clearance, but you can expect everyone in your office to be security conscious.