Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, July 30, 2015

Banks: Protecting Yourself From the Invisible - Ignorance is Bliss But Only For the Moment

Knowledge is power – Francis Bacon

Knowledge is power only if man knows what facts not to bother with. - Robert Staughton Lynd

Knowledge is power. Information is power. The secreting or hoarding of knowledge or information may be an act of tyranny camouflaged as humility. - Robin Morgan

[Important updates are at the bottom of this blog post]

Some years ago, I attempted to use my US-bank issued credit card in NYC and was surprised to discover that it had been disabled.  Calling the bank, I discovered that copies of the card had been used in Germany, the US and Brazil within a two-hour span the previous day.  In the argument that ensued on the phone, where the call center person insisted that I must have been in Germany the previous day and just didn’t remember it, I reminded them that it was physically impossible to have gotten to three countries that far apart in two hours and she finally agreed and told me a new card would arrive in two days.  I didn’t understand the argument anyway since it was their suspicion of fraudulent use that had caused the card to be killed in the first place.

The next day I received a call from the bank telling me that when the new card arrived I was to destroy it because it had already been compromised and that a third card would be sent.

I naturally assumed it must have gotten lost in the mail (thereby creating an opportunity for compromise) and so you can imagine my surprise when the now-dead replacement card arrived the next day with the envelope security seal still in place.  The card had not been intercepted and so it was obvious that it had been compromised at point of origin.  When I called the bank to understand what was going on (part of my profession is in the area of technology security architecture on Wall St), I was told it was an internal matter and that the details were none of my business.

A few years later, I had a considerable sum of money drained out of an account of a US bank, had it replaced and then had the same cycle of events repeated a short time later.  When I asked the bank what was happening, I was told it was none of my business.  However, when I informed them that I was calling the police, they relented and explained what was happening.  It was sweet, simple and frightening.

Here’s how it works.  A person presents the teller with a group of bogus payroll checks written out to a bunch of people.  The checks are knowingly drawn against a valid account in the bank that is known to be empty.  The teller, who is in on the scam, processes all the checks and pays out cash to the person.  When the bank reconciles the checks at night, they realize that all the checks are NSF and they reach into each person’s account to take the money back (since they assume they have already paid THAT person cash earlier in the day and are therefore taking the bank’s money back and leaving it to that person to deal with the NSF check that they allegedly cashed but in reality have no knowledge of).

The bank wouldn’t explain this until I brought the police in and secured bank surveillance video.  Until that moment, what was happening was none of my business according to the bank, even though it took a couple of weeks of hassle, paperwork and affidavits every time to prove that I hadn’t taken the cash and wasn’t  trying to defraud the bank.  During the first incident, one of the bank support people even suggested “Maybe your wife is taking the money and not telling you.  How strong is your marriage?”

I and a number of other people in that bank were guilty until proven innocent every time one of these incidents occurred.

In the investigation, the bank manager admitted that this happens a lot but “It’s ok, the customer always gets their money back”.  This may be so from their perspective but in addition to the inconvenience, someone is paying for the reimbursement of my money since the bank doesn’t eat the loss.  Eventually, despite CDIC, FDIC and other insurance vehicles, the responsibility for paying for it eventually trickles back to the customer.

Meanwhile in Alberta …..

A few days ago, I received two calls from my bank in Alberta.  I ignored the calls initially because the caller ID said “Alaska”, so I assumed it was a scam call or a wrong number.  When I finally played the voicemail, it said “I needed to get to a branch immediately”.  It sounded like a scam so I called the bank and they confirmed that “yes, it is imperative that you get to your branch immediately”.  When I asked “why?”, I was told politely that it was none of my business.

I went to the branch which was filled with people getting their cards replaced so I knew this wasn’t a one-off incident affecting just me.  When I asked the teller what was going on, she told me that she wasn’t allowed to tell me and that all cards (debit or credit) I had with the bank should be replaced immediately.

I asked if the cards were being skimmed (since such information would help me  avoid certain vendors or locations), if my online account had been compromised (requiring me to change my login credentials), if the bank had been compromised by an outside entity or if an internal miscreant had gotten up to no good.

I was politely told it was none of my business but as a precaution, I should change my PIN daily.  “Daily?”, I asked, “What is going on that you are recommending this?”

“I can’t tell you”, she replied.

Since I had been out of province the previous week, I asked the teller “How could I have gotten to a branch last week when this bank has none where I was?  What would happen then?  Can you kill my cards and get new ones to me where I was?”

Her answer was “No – we can’t do that.  We would try to figure something out.”

How comforting.

I asked on Twitter what the issue was and was told very politely that “We take security seriously and for this reason, we can’t tell you”.  My email to customer support politely asking for details went unanswered.

The bottom line from the bank:

“Be vigilant against a threat that we won’t tell you about.  It doesn’t matter – you always get your money back so why do you care?”

It reminds me of all the times Homeland Security would tell us to be very careful in a certain part of Manhattan.  When we would ask “What are we looking for?” we’d be told that we can’t tell you but let us know when you see something unusual or abnormal.  It’s NYC – what do you define as “normal”?

It also reminds me of the time when a bank that I was consulting to was allowing its consultants to host a porn site on the same servers as our customer-facing websites.  I reminded senior officials that not only was this not legal, ethical or moral, a compromise of the porn site (since porn sites are favorite targets for attacks) would reveal a smorgasbord of client information from the bank.  The bank indicated that “what customers don’t know won’t hurt them”.  They finally took the porn site down when the threat of a public leak became apparent.

So security wasn’t the issue – public relations was.

The Bottom Line

Security in our society, whether it be our physical safety, the safety of our bank accounts or anything else, begins when we are informed and when the institutions we work with are transparent, forthcoming and honest.  We can’t make intelligent choices if we don’t know what threatens us.

The suggestion that revealing some “secret” to the public would enable the criminal or tell the criminal that “you are onto him / her” doesn’t hold water.

Here’s a newsflash – the criminals already know how to do whatever they want.  In fact, they are likely thinking about compromises that we haven’t even thought of yet so they are actually ahead of the people and organizations that they are targeting.  They also know that the likelihood of getting caught these days is slim, making what they are doing very lucrative and risk-free from their perspective.  For every large-profile case proudly trumpeted by law enforcement as “solved”, many more are not solved in time (or solved at all) until the damage done is significant.

Groups like Anonymous and groups backed by other governments hack into government agencies like CSIS, the NSA and other groups at-will.  It’s time to be honest with people that total security doesn’t exist.  Even things like air gaps within technology architecture have been compromised.

The reality is that revealing cracks in security is very bad for business and for consumer / public confidence.  The first institution that can openly demonstrate that they are secure will be able to garner quite a bit of business from their competitors.

Well …. maybe – the reality is that security of anything is impossible.  We accept freedom and flexibility and in exchange, we trade away privacy and security.  Since this is our reality, society would be more secure if we worked together instead of the organizations who are charged with protecting us and our “stuff” forgetting about who works for whom.

As for my bank, all of my cards are chipped and yet banks insist that chipped cards have not and cannot be compromised.

Uh huh.

Here’s another newsflash – the chip technology was compromised before the banks finished rolling it out. Not only does the chip not protect you from anything, but technology exists to allow people to lift your card info from your pocket, wallet or purse without them ever seeing your cards (read Flaw in New “Secure” Credit Cards Would Allow Hackers Steal $1M Per Card).

When we can have an honest, transparent conversation, maybe then we can start working together towards a better society, each of us protecting ourselves and the other as a result of this dialog.

Until then, we will dance around security and privacy until something really bad happens.

And then we will all act surprised, angry, indignant, outraged or anything else.

But we will only have ourselves to blame, having accepted “none of your business” as a perfectly valid response to “What is happening?”, “Why did it happen” or “What are you doing to prevent it or mitigate my risk or exposure?”

What do you think of that?

With all of the enhanced technology, processes, methodologies and frameworks in the IT industry, you would think that we would be safer now than ever before but the reality is that we are less secure today than we were 20 years ago.

I’d tell you more but it’s none of your business. Smile

In service and servanthood,

Harry

Addendum – A Response – July 30, 2015

In all transparency, the financial institution in question sent me a note after this blog post was published:

Thank you so much for reaching out to us, I truly value the time you put to send us this note.

We’ve identified that there may be a compromise in an area that you’ve used your debit card. For this instance we’ve reached out to many clients to be proactive and have their cards replaced with a new pin number.

I apologize for the lack of information around this because we’ve also recognized that the areas and stores affected are victims as well. This is a precautionary measure as we want to protect our direct clients as much as we can.

Hope this sheds some more light.

I appreciate the note but have a few observations regarding it which I sent back to the bank:

  1. It would be useful if the tellers, people on the phone and on social media could have explained this – it would have avoided some confusion.
  2. It still doesn’t explain why I need to continue to change my PIN daily even though I have a new card.  It is as if they are anticipating that I will have new transactions in compromised areas.
  3. I was told that all debit AND credit cards need to be replaced.  This references debit cards only.
  4. Pursuant to the previous point, they don’t tell me where the issue is.  I understand protecting “other victims” including businesses and areas but if we are destined to conduct other transactions in known compromised areas, I and other customers will merely recreate our problems since we don’t have enough info to avoid problem areas.
  5. The teller did admit that a specific range of card numbers was affected.  A specific range of card numbers is not the same as a random selection of customers and so the information is not consistent and potentially suspect until clarified.
  6. The person on the phone said that if I didn’t receive notification of compromise for other cards, then I shouldn’t change them.  The person at the bank said I must change them regardless.  Erring on the side of safety is important but clarity and consistency in message promotion is equally important and less confusing, especially when no other details are being offered.

Knowledge is only power when sufficient knowledge is provided AND it is applied.

One of the key ways to acquiring knowledge is through asking questions that matter.  We tend to focus on asking questions about the unimportant while not asking them about the things that matter (or we accept an answer that we know is insufficient but we don’t want to press the point).

Accountability, transparency and knowledge are created and shared when the right questions are asked and appropriate answers are demanded.

Do you ask questions or do you not care?

Does it matter?

Are you sure?

How do you know?

Addendum 2 – Insider Update – July 31, 2015

In speaking to my sources in banking and law enforcement, they have indicated that a sweeping federal investigation encompassing at least 5 Canadian banks is in progress.  I was given the names of the banks but cannot reveal them here due to the nature of the investigation.

It is because the federal investigation is in progress that the institution noted here cannot reveal the areas / vendors involved, etc.  Sadly, because of this constraint, the problem has a slight risk of spreading to new victims while the investigation is going on (or ensnaring original victims).  There is some concern also about whether the losses will be covered under CDIC or not but that is a subject for someone else to debate.

That being said, secrecy around such investigations while they are in progress makes perfect sense and is often essential for the successful conclusion of the investigation.

What makes better sense for this institution in this case is to just tell the truth.  By doing so, they don’t reveal any secrets, they don’t endanger or compromise the investigation and they can assure customers using facts that the right people are looking at the issue effectively and appropriately.

Transparency works a lot better than avoidance and when done effectively, intelligently and strategically, provides the information necessary to maintain the strength of a business / customer relationship.

It just requires a little effort and resonates better than “none of your business”, especially when it’s your money, security, privacy, etc. Smile

Tuesday, March 24, 2015

Public Relations–The Only Investment in Aviation Security That Works

The history of PR is… a history of a battle for what is reality and how people will see and understand reality. - Stuart Ewen

Since we cannot change reality, let us change the eyes which see reality. - Nikos Kazantzakis

The #1206 “fiction” series continues …


In a meeting room at FAA Headquarters on Independence Avenue in Washington, DC, representatives of the commercial aviation industry sat around a large boardroom table.  They had been summoned to address concerns over aviation security and the rumors that such security was still a non-existent fantasy.

One by one, they answered questions from bureaucrats seated around the table.  The questions were direct and to-the-point and the bureaucrats asking the questions did not challenge any of the responses from the aviation representatives.

The Secretary of Transportation said nothing as he watched his team interrogate the aviation officials.  When the last of the questions had been asked and answered, silence pervaded the boardroom as he clasped his fingers together, frowned and pursed his lips.

After a brief pause, he leaned forward in his chair.

Clearing his throat, he addressed the boardroom.  “So after hearing all of the evidence presented by the industry today, the fears of myself and my team have been confirmed.  Despite spending billions on aviation security over the decades, we are no closer to preventing an explosive device from being planted on an aircraft nor are we any closer to preventing cockpit compromises similar to those that occurred on 9/11.  Am I correct in my understanding or have I missed something in your presentations?”

The aviation officials said nothing, some of them squirming nervously in their chairs while others stared at the boardroom table to avoid the gaze of the Secretary.

”So what you are saying”, he continued, “Is that while it is unlikely that a specific individual could be killed in a terrorist act in an aircraft, the likelihood that someone will be killed by a terrorist act is very high.  Is that what you are telling me?”

“That would be correct, Mr. Secretary”, said a voice at the other end of the table.

The Secretary nodded for a moment before responding.  “Do you realize that knowledge of such an inconvenient truth could derail your industry and cripple the economy of the entire nation?”

His question was again met by silence.

“Hmmmmmph”, grunted the Secretary, “That’s what I thought.  Well, if we can’t secure the aviation industry or any place where the public congregates for that matter, then we will have to promote things such that the people believe they are secure anyway.  In anticipation of this, I have invited some guests to make a presentation to those of us assembled here today.”

He nodded to the aide sitting at his side and the aide promptly stood up and left the room.

The aide returned a few minutes later with three individuals.

“Ladies and gentlemen”, began the Secretary, “The Secretary of Homeland Security needs no introduction.  I would, however, like you to meet two of the most brilliant public relations people in the nation.”


In a small street-side cafe in a city in the Middle East, two men argued passionately over their coffees.  One argued for quicker action against the infidel in the west while the other argued for a more patient, methodical approach.

Finally, the younger of the two men couldn’t contain his anger any longer.  “I don’t understand you”, he exploded, “What in the name of Allah is the value in training some of our best people in public relations?  We need fighters and not talkers.”

“Patience, my friend”, his companion replied.

“Patience”, he said again, his voice trailing off as his mind travelled westward and he wondered how his companions were doing.

To be continued.


© 2015 – Harry Tucker – All Rights Reserved


Addendum – Humans – The Weakest Link – March 26, 2015

News about the Germanwings crash this week indicating that the co-pilot may have deliberately crashed the aircraft puts this aircraft on a shortlist of planes known to have been deliberately crashed by crew members.

In a strange twist of irony, the processes implemented after 9/11 that were designed to keep hijackers out of an aircraft cockpit may have kept the pilot out of the cockpit in this instance, thus preventing him from saving the aircraft from doom.

There have been other stories over the years of crew members suddenly needing to be restrained by fellow crew members and passengers after exhibiting behavior that endangered an aircraft.

It goes to show that when one needs to rely on the weakest link, humanity, that there are never any guarantees of safety.


Background

Two themes are present here.

The first is that the aviation industry (or any public place for that matter) can never be secured as long as there is a human element present in managing that security.  We are always our own weakest link, whether it is in preventing explosives from being planted on aircraft, weapons being carried onto an aircraft or in preventing the wrong people from gaining access to the cockpit.  All are still realistic possibilities today.

The second theme is that if someone could be convinced by an insider to diminish action in favor of merely promoting positive spin as the government is doing now, then the risks to the aviation industry could be increased even further.

Meetings as described in this post have been taking place in the commercial aviation industry for years.

No results of merit in relation to true security have ever been produced and the aviation industry has resigned itself to acceptable losses of passengers and assets.  The use of statistics in promoting the likelihood that you will not die at the hands of a terrorist are accurate.  However, the darker side of statistics, that someone will die, are also accurate but are not promoted.

This is not something to be upset about since the reality is that the aviation industry cannot be totally secured.

But it would be interesting if the government and aviation industry admitted this instead of spending billions for security procedures and equipment that complicate the average passenger’s Life while leaving the trained, patient terrorist with plenty of time and opportunity to plot what they intend to accomplish anyway. 

The difficulty is that the truth is often so inconvenient for government intentions and agendas that many people are better off without it.  Most people couldn’t deal with the truth anyway so what difference does it make for them whether we know the truth or not?  Ignorance is truly bliss in today’s world.

Meanwhile, we continue to be lucky in the aviation industry.

I wonder how long our luck will last.

I had close friends who were killed by terrorists on 9/11, both on the ground and in the air.

They weren’t so lucky.

Series Origin

This series, a departure from my usual musings, is inspired as a result of conversations with former senior advisors to multiple Presidents of the United States, senior officers in the US Military and other interesting folks as well as my own professional background as a Wall St. / Fortune 25 strategy and large-scale technology architect.

While this musing is just “fiction” and a departure from my musings on technology, strategy, politics and society, as a strategy guy, I do everything for a reason and with a measurable outcome in mind. :-)

This “fictional” musing is a continuation of the #1206 series noted here.


Thursday, January 8, 2015

Social Media: When TMI Stands For "Steal My Identity"

If we don't act now to safeguard our privacy, we could all become victims of identity theft. - Bill Nelson

When it comes to privacy and accountability, people always demand the former for themselves and the latter for everyone else. - David Brin

While in Calgary airport the other night, I happened to overhear someone from the drilling industry in Calgary speaking to an airline representative on the phone.  While in the process of making a reservation change to postpone his flight until the next day, he gave his email address to the person on the other end of the conversation.

I started twiddling on my phone and my travel companion asked me what I was doing.

“Professional curiosity”, I replied as I continued to poke on my phone.

Within 60 seconds, I had obtained this person’s name, birthday, home and work addresses, his home, work and mobile numbers, his boss’s name and contact information and how long he would be out of town.  At the same time, I obtained the same personal information for his girlfriend, thus confirming that they lived apart.  I also had his flight reservation code. One call on my part could have obtained his credit card information as well since I had sufficient information to pose as either of them.

I looked at my travel companion, sighed and then made the following observation.

“So after 60 seconds, I can do the following.  I can alter his flight information, changing or cancelling his flight.  I know he is out of town so I can arrange to break into his home.  If his girlfriend is staying at his house while he is away, I can break into her home instead since I know where she lives also.  I could stop by to see his girlfriend or stalk her if I was depraved enough to do so.  Their social media profiles are open to posting by non-friends so I could post things on either of their social media profiles just for the point of making trouble (something like “It was great seeing you last night, __name__.  I was relieved when you said that __name__ wouldn’t be back into town until __date__ and can’t wait to see you again.” or “the company that I work for, __name__, really sucks and doesn’t know how to do anything right”).

I also had enough information to begin the process of stealing both of their identifies.

All because of a couple of pieces of information that we carelessly toss around at will, not caring who hears it, and being a little too liberal with what is shared on the Internet.

People are always screaming about the importance of governments and social media platforms like Facebook working harder to protect our privacy.

However, I think that we need to do a better job of protecting our own privacy.

What do you think?

In service and servanthood,

Harry

Addendum

In this situation, neither of the people had children.  If they had, it is likely that I would have been able to obtain more information about the children than the parents would have appreciated.  However, I was able to obtain information about their relatives’ children.  I’m not sure their relatives would have been amused.

What if it were your kids?

Wednesday, January 15, 2014

Do We Write History Or Does History Dictate To Us?

The past speaks to us in a thousand voices, warning and comforting, animating and stirring to action. - Felix Adler

History is a vast early warning system. - Norman Cousins

The #1206 “fiction” series continues …….

---------------------------------------

He started in disbelief at the PDF document on his screen as a babble of voices on the Skype call continued in the background.

One insistent voice in particular brought his attention back to the conference call.

“As explained in the document that accompanied this PDF”, explained the meeting moderator, “the PDF represents the efforts of some of the best linguists in the world for over 60 years.  We have ascertained that the content of the original material dates back several thousand years but it has taken up until now to translate it.”

He frowned as he paged through the PDF.  He opened his mouth to speak but someone else on the call beat him to it.  “How can you claim that this document is several thousand years old when it describes events in our recent past?  This has to be some kind of hoax.”, the voice expostulated.

The resulting cacophony of protests from the conference call attendees forced the moderator to mute them all.

“When we have quiet, I will continue”, he said tersely.

Pausing as the participants acquiesced to his demand, he continued.  “Good, that is much better.  It is important that you understand and accept some basic conditions before we continue.”

The moderator paused for a moment, cleared his throat and then proceeded.

“The origins of this document and our best understanding of who wrote it will be explained shortly.  However, there is something else interesting about this document.  Has anyone noticed it?”

A voice, choppy because of poor connection quality, asked in an intermittent voice, “Why does it end in 2001?”

“Ahhhh ….. excellent question”, replied the moderator.  “The original document was written beyond the point that you see here but at one point was divided into two documents, with the latter requiring a much higher security clearance that exceeds even the level of the President of the United States.  Now that we have some semblance of order, I will share my screen so that you may see what part two of the document looks like.  I will warn you in advance that what you are about to see may disturb you.”

Moments later, the screen displayed another PDF.

As soon as he realized his screen capture had been disabled remotely to prevent capturing images of this PDF, he grabbed his phone and started photographing his screen as the pages were turned by the moderator.

The moderator’s voice came over his laptop speakers.  “I have stopped on this page for a reason”, he said.  “Please note the significance of the events described on this page”.

He dropped his phone and stared stupefied at the screen.

“How is this possible?”, he thought.

“It appears”, continued the moderator, “at least according to what we have read, that we are about to live through what you see described before you.  The obvious questions, above and beyond so many, are ‘How would somebody know this in advance?’, ‘How can we verify this is real?’ and ‘Can we prevent it if someone seems to have already documented it as if it has happened already in their history?’”  The moderator’s emphasis of “their history” was unmistakeable.

His eyes flicked over Wall Street references, some references to specific hacker events, pandemonium and the results of a dreadful miscalculation by a few world leaders.  The estimated death toll, being more than 95% of the current population of the United States and Canada, particularly jumped out at him.

There was silence as people around the world on the Skype call stared at their screens in silence.

“According to one former senior advisor to the President of the United States, the events described cannot and will not be prevented”, said the moderator. “How he claims to know this is beyond my knowledge.”

“We must prepare for the transition as noted here”, he concluded.  “The difficult question becomes how.  I’m told that our hope lies not in preventing what you see described but rather, by successfully living through it.  We will be supported by legislation, particularly Executive Directive 51, which provides for the continuity of basic government services during the transition period.  What remains to be determined is who decides what 5% of the people will survive and how the process of government will be returned to those people once the transition has completed.”

He paused for a moment.

“Are there any questions?”, he asked.

To be continued.

-----------------------

© 2014 – Harry Tucker – All Rights Reserved

Background:

I wrote a much longer version of this post and submitted it to members of my network for vetting as I do with all of the #1206 blogs.  It was rejected twice and I was asked to remove some specific references. 

The closing lines from “one former senior advisor” and “the moderator” are direct quotes from a former advisor to multiple Presidents in his response to my original material.  Curiously and by coincidence, he is also a master in the study of history. The death toll reference comes from him based on scenarios that he has reviewed with peers of authority.

Executive Directive 51 is an executive Presidential order that provides the President of the United States with the authority to bypass Congress, the Senate and the process of elections during times of specific emergency and until such time as that emergency has passed.  He also assumes full control of the military during the emergency period.  The definition of what constitutes an emergency is described in loose, fuzzy terms and the rights of the people during the emergency period are classified.  The President has sole discretion as to if and when the Directive is invoked and when it is revoked. 

Once the emergency has passed, the process of returning government back to a working Congress and Senate and the restoration of elections has also not been publicly defined and is in fact, also classified.

This process exists for a well-meaning President who can save a country in trouble, a mentally-disturbed President who is not quite sure what he or she is doing (or is being influenced by someone else) or a President who seeks to seize more control for any reason.

It could even be invoked by a President who, after losing an election, rationalizes that an incoming President might disrupt the country and so the Directive is invoked “in the best interests of the country”.

This is complicated stuff that exists but no one likes to talk about under the guise of “no one would ever abuse the authority”.

That’s the problem with history.  Every time we repeat it, the price goes up.

So has a process for returning power to the people been defined?  It is not known although one would suspect that if the information was simple or positive, it would not be classified.

Take from all of that what you will. 

On a side note, I much preferred the version I really wanted to write but couldn’t get permission to.  As a writer, I am unhappy with this.  As a strategy guy, I’ve said all I am allowed to say.  Ahhhh the structural tension of it all.  I will explore permission to add more data to this as time permits.

Series Origin:

This series, a departure from my usual musings,  is inspired as a result of conversations with former senior advisors to multiple Presidents of the United States, senior officers in the US Military and other interesting folks.

While this musing is just “fiction” and a departure from my musings on technology, strategy, politics and society, as a strategy guy, I do everything for a reason and with a measurable outcome in mind. :-)

This “fictional” musing is a continuation of a series noted here.

Thursday, December 19, 2013

Target and Credit Card Theft–If Ignorance Is Bliss ….

Leadership is about taking responsibility, not making excuses. - Mitt Romney

News of the compromise of 40 million debit and credit cards at Target in the US seems to have shocked a lot of consumers this morning and I have no idea why.

Once consumers get it into their mind that pins and chips don’t protect their plastic assets, maybe then they will stop being surprised to hear they have been compromised yet again and instead will demand better of the institutions that issue the cards and the organizations that accept them for transactions.

Even those of us inside the system have had our share of compromises.  I have had my personal and banking information given away three times by bank employees on the take – twice in the US and once in Canada.

You have to trust the system but when the system’s weakest link is human greed, there is not much standing between you and financial complexity.

My favorite incident, if you can call it that, occurred about 10 years ago when one of my credit cards was compromised.  When I called customer support to ask why a transaction had just been blocked, I was told that there was suspicious activity on the card.

Upon subsequent exploration, the card had allegedly been used in person (not online) in Germany, Brazil and the US over the course of about 4 hours on the previous day.

The customer support person asked me if the card was still in my possession to which I answered yes.  When I indicated that I had never been to Germany and Brazil in my Life, she suggested that maybe I had traveled there but just didn’t remember.  I assured her that my short term memory was working just fine.

In the discussion that ensued where she was trying to prove to her own satisfaction that I wasn’t in all three nations within a 4-hour window, I finally asked her this question.

“Do you know how I can prove that I wasn’t physically in Germany, Brazil and the US within a 4 hour window yesterday?”

“How?”, she asked.

“Because the laws of physics don’t allow it”, I replied.

She didn’t understand my sense of humor.

Here’s the best part.

She indicated that my current card was now cancelled (which was cool), a new card would be issued immediately(arriving in two days), would need to be activated, blah blah blah blah.

The next day, I was contacted by the bank and told that when the new card arrived, I was to destroy it and wait for another card.  Why? Because the new card had already been compromised, activated and used from somewhere within the credit card facility before I even had a chance to touch it and activate it.  Customer support had no official explanation of how this could happen.

Someone knows though.

Once again the weakest link being human greed had reigned supreme over “checks and balances”.

Better systems exist to protect our security

Biometrics and other security techniques exist and despite industry claims that they are in their infancy, some of my clients have been using them for decades.

Do you know what the real problem is with implementing such technology?

1. A lot of consumers would need to be trained to use new security technology.

2. We will need to pay a little extra for devices that ensure security, either at home or in the form of fees to cover technology implemented by others.

3. Many institutions will have to pay a lot of money to implement such systems.

It all comes down to how badly we want something, doesn’t it?

And there’s the rub.  Every time you get ripped off, the institutions pay you back and get reimbursed themselves.  They even get to write off any costs absorbed in processing compromises so there’s no downside to them.

It’s all offloaded onto the consumer who may live with the ramifications for a long time, depending on the nature of the compromise.

However, to create a new system requires a major outlay of capital on the part of the institutions, some of which would be passed on to the consumer in fees to cover the implementation.

And as long as we (the royal we) refuse to suck it up and pay for the technology that will provide the financial and personal identity security that we demand, then we need to stop acting surprised every time something like this happens.

Of course, having been compromised three times by employees of national banks, I can assure you that there will always be a weakest link.

But at least there will be a lot fewer of them.

In service and servanthood,

Harry

Tuesday, August 20, 2013

The Coffee Shop–The New Source of Privacy Leaks

I was in a coffee shop this morning where I couldn’t help but overhear a very loud conversation taking place. 

It was a strategy planning session for Alberta Health Services and ironically, the strategy session was about protecting privacy.  Names were named, email addresses and phone numbers were tossed around, different people’s positions were discussed, ways to bypass “difficult people” were evaluated, strategies to secure capital in a time of austerity were discussed, etc.

It was probably a conversation that I shouldn’t have heard and I won’t share details of it nor did I take notes.

However, it is not the first Alberta Health Services conversation I have heard in a public place.  I remember overhearing a nurse last year who proudly pointed out to a coffee colleague that she only looks up private patient information on behalf of people that she can trust and in a specific way so that no one else finds out she is doing it.

The only problem is that if you really want to keep a secret you don’t tell anyone – especially in a public place. :-)

I’m not picking on Alberta Health Services. 

I have overheard accountants discussing a company’s financial position in public (without the owners being present), lawyers planning their defense for murder, DUI cases and other litigation matters, politicians discussing strategy, senior politicians who left confidential or classified briefing notes on their table while they went to the restroom, confidential employee reviews, married lovers planning adulterous rendezvous, businessmen preparing for hostile takeovers, etc.

And then there is the less impactful but potentially problematic “Are you ready for me to read my credit card # to you?  It is ….. and the expiry date is …… and the name on the card is …..”.

I have been approached by lawyers and businessmen who, upon realizing that they were overheard, approached me and demanded I sign an NDA, which I have refused (although I have told a few of those folks that if they worked for me, they would have been fired immediately for indiscriminately sharing confidential information).

And I interrupted a potential terrorist who was writing a pro-Jihad presentation.  I wrote about this event in The Power of Trusting Your Instinct.

Protecting privacy used to be a source of humor

Back in the late 60s, we used to laugh at the character of Maxwell Smart in the TV Series “Get Smart” when he would insist upon using the Cone of Silence to protect the privacy of sensitive conversations.

But in the modern era, privacy is not a laughing matter.  We get up in arms about the NSA, Facebook and other groups snooping in our emails, social media interactions and phone calls while we freely share information that we shouldn’t (especially regarding our children) and we speak loudly in public places when we probably should wait for a more private moment. 

We log onto public Wi-Fi and conduct sensitive transactions despite the number of products out there that have been demonstrated to be able to read our online interactions no matter how secure those interactions are according to software vendors.

And yet we cry foul when someone else contravenes our privacy.

Protection of our privacy, whether personal or professional, is not only a matter for other organizations, private, public, judicial or legislative to take care of.

It is something we need to play a bigger role in ourselves.

Otherwise, it doesn’t matter what groups like the NSA or Facebook do – we’ve given it all away anyway.

Most of us who overhear or see that which we shouldn’t are trustworthy and will do nothing with the incessant flow of sensitive information that comes in our direction.

Unfortunately, the same cannot be said for all members of the human species.

Do you really want to take the risk of not knowing who is in the room taking notes?

I didn’t think so.

In service and servanthood,

Harry

PS Bad news, ██████████. You are about to be fired from ██████████ in Calgary.  HR and corporate legal just wrapped up their meeting at the table beside me and will tell you on Friday.  I Googled your name and found you in LinkedIn, Twitter and Facebook but it’s not my place to tell you.

Or is it – you appear to be a nice family guy from what you have shared publicly.  The GPS coords on the photos of your family are a nice touch also … if someone wanted to violate the personal space of your family.  Hmmmm … maybe you’re not so smart after all.


Addendum – August 20, 2013

I wrote about the same subject back in February of 2012 in the blog post Privacy and the Real Weakest Link, highlighting some of my concerns then. While not trying to be redundant, I think it is a subject that is worthy of revisiting once in a while until organizations and the people who represent them get their act together when it comes to privacy. 

What is curious to me as I revisit that blog entry is that it mentioned two social workers who were openly discussing (with some level of disgust) their current cases (with names).  I wonder if they were associated with Alberta Health Services also.  I hope note.

I also noticed that I was in a coffee shop when I wrote that blog also.  Before anyone asks, the answer is “No – I don’t live in or own a coffee shop”. :-)


Addendum – No One Cares - April 15, 2014

As news broke today of over $1 Billion in spending within AHS via sole-sourced contracts (in some cases in violation of its own rules) I reviewed some email exchanges I had with AHS staff where I described the things I noted in this blog post and other posts

For the different interactions, people thanked me for the emails (proving they received them) but they never seemed to care nor did they ever bother asking for details.

I wonder what it will take to make them care.


Tuesday, April 30, 2013

Predictability–Reliability Versus Vulnerability

As someone who has a background in providing solutions regarding the prediction of human behavior, I was thinking the other day of the conundrum of being predictable as an individual, a society and as a species.

Being predictable is often considered a desirable trait to have since it gives others a sense of how reliable we are.  When we are predictable, others know if we will rise to the occasion and deliver when called upon or if we will collapse and not deliver as needed.  Based on this predictable outcome, others can decide if they should engage with us or not for a given need and situation.

Being predictable also helps us to create a reasonably organized, structured, non-chaotic society (at least to the best of our ability).

However, when we are predictable, the same knowledge can be used to exploit vulnerabilities within individuals and society.  This is common knowledge used by law enforcement, terrorists and other organizations and individuals.

Discovering vulnerabilities provides an opportunity to do one of three things:

1. Remove the vulnerability with an eye towards strengthening the individual, society or species.

2. Exploit the vulnerability for the benefit of others.

3. Exploit the vulnerability at the expense of the person(s) being exploited, possibly putting them in peril.

Remaining unpredictable does not provide protection against such exploitation since it introduces chaos at the individual or society level, thus potentially creating a net negative result for either or both levels.

Perhaps the best answer as to how one’s predictability affects the results in their Life and the result of those who interact with them (for positive or negative reasons) is simply to be more cognizant of the message one sends out when it comes to one’s predictability.

Do you prefer to be chaotic, keeping everyone off balance, including yourself ….

….. or ….

…. do you consider yourself reasonably predictable, in which case have you ever asked yourself the question of whether your level of predictability demonstrates reliability or vulnerability?

Because in the grand scheme of Life, if you are not cognizant of the question (and the answer), you can be sure that someone else may be asking it on your behalf, for your benefit or to your detriment.

Does it matter to you?

Are you sure?

In service and servanthood,

Harry

Tuesday, April 16, 2013

Boston: Freedom, Security and Difficult Choices

The cowardly, senseless attack at the Boston Marathon this week once again brings a powerful question to the fore – a question that people seem unable to come to grips with.

It is the question of which do we value more – freedom or security?

We all demand security for ourselves, our families and our nation.  We all like to live as we please, doing what we enjoy.  Many of the latter also demand the ultimate right to do as they please outside the all-seeing eye of government, various security agencies, law enforcement groups or Big Brother organizations.

Sadly, when we demand both and champion such freedoms that we enjoy in Canada and the US, freedoms that many brave people have paid the ultimate sacrifice to protect, such freedoms also provide reasons for some to resent us. 

More importantly, such freedoms also provide opportunities for nutbars to leverage vulnerabilities created by such freedoms to inflict pain upon us.

The only way that the cowards, miscreants and deviants of our world can be totally prevented from inflicting pain upon us is for us to totally give up all the freedoms that we cherish, including but not limited to the areas of:

- the right to assemble (especially to celebrate)

- privacy of communication

- privacy of financial transactions

- the right to go anywhere in the world and be assured of our safety

- the right to do whatever we want without fear of oversight (including regulatory) and

- the right to go wherever / whenever we please without the inconvenience of metal detectors, being wanded or being corralled inside specific areas.

Few people are willing to give up such freedoms in totality.  We believe that such freedoms are a foundational component of our society, a foundational need for our species and one of the many things that makes our society great.

Unfortunately, while we have become a society of “I want it all and I want it now” there are still a few areas where we can’t have it all, including in the areas of freedom and security - at least as we define them today.

Our society, as it strives (and struggles) to find the best solution possible, will always find itself navigating the difficult balance between these two things that we believe we need and deserve.

As Dwight Eisenhower once said:

“If you want total security, go to prison. There you're fed, clothed, given medical care and so on. The only thing lacking... is freedom. ”

A truly enlightened species wouldn’t have a problem with figuring out how to have both.

But an enlightened species we are not and so we must do our best to recognize that such violent acts will always be with us – at least for the foreseeable future.

However, when such heinous acts occur, human attributes in the areas of bravery, love, unselfishness, teamwork, collaboration and yes, justice, will always stand out and clearly send a message that such acts are not acceptable.

It is a message that we are not defeated by the intimidation attempts of the few, the weak and the cowardly.

And maybe, just maybe, if we give ourselves enough time and don’t tear our society apart before we figure this out, we will have an opportunity to discover that we can find a way to bring freedom and security together.

Until then, we move forward, together, in support, in mourning, in strength, in love and with a vision and intention to move towards the promise of something better and with a strong message to those who oppose such ideals that their actions are not acceptable nor will they ever be.

But until then, human beings will continue to demonstrate the perfection of our imperfection, reflecting the best and worst of our potential.

And until then, the question of “why?” when it comes to understanding the evil motives of certain individuals will rarely produce a satisfactory or even a rational answer.

But those questions can be answered tomorrow.

Today we mourn the lost, comfort the living and show the world the best of humanity.

What human potential do you promote, allow, enable and create?

How do you know?

Are you sure?

In service and servanthood,

Harry

Saturday, January 26, 2013

The Security of Our Society: The Emperor IS Naked–Now What?

Reading the news that the hacker group Anonymous hacked the website belonging to the US Sentencing Commission should be a wake-up call to people in the West but I suspect for most people the news will fall on deaf ears.

I participated in an invitation-only national emergency preparedness meeting a couple of weeks ago where the presenters discussed the likelihood of our society being destroyed or disabled by different events over the coming decades and how prepared we are as a nation and as individuals to prevent or survive these events.

I didn’t sleep for a week - we live a more precarious Life than we care to think about.

Unfortunately, as in the Hans Christian Anderson story “The Emperor’s New Clothes”, pretending we are prepared for the real world and actually being prepared for the real world are not the same thing.  As the Emperor relied on the “wisdom” of shysters who proclaimed how great he looked, we often rely too much on the “wisdom” of self-described experts who tell us how safe we are when they don’t really know (or they know otherwise but won’t admit it).

The great challenge in today’s world is that the “child” who cries out that the Emperor is naked is hushed up or discredited for uttering the “ignorant words of a child”.  Meanwhile, others who think that the child may be right are silent for fear that they will be branded the same way.

Remember when the Stuxnet worm attacked the nuclear facilities in Iran?  Few in the west cared because “someone else” was taking out “the enemy”, even though there was evidence to suggest that the US government participated in its creation. 

Many of us who declared that this worm, whose source code was now publicly available for anyone to use  (including terrorists) and could be used against our own society, were dismissed as fear mongers. 

After all, one thing we have perfected in society when it comes to dodging accountability and responsibility is the art of discrediting or intimidating the people whose message we don’t like.

Meanwhile, few Americans paid attention when it was announced that two unnamed US power plants were disabled by similar attacks.  Whether Stuxnet-related or not as alleged experts argued over the nature of the attack, what matters is that a vulnerability had been successfully exploited as many of us had predicted would happen.

The warning shot had been fired but we couldn’t hear it over our need for personal overindulgence or in fairness, because many people are fighting just to stay afloat from one day to the next and don’t have the time or energy to see the bigger picture.

Do you really want to know how vulnerable we are?

The ability for Anonymous or other groups to be able to freely take down any website of their choice, whether a government website, a bank, a credit card company or anything else should be a wake-up call to people.

What happens if someone using the same techniques disables our communications infrastructure, our energy distribution, our water supply systems or similar systems?

What happens if our military or civil defence systems are compromised as a precursor to a larger event, including an event planned by another country?

The experts tell us that it can’t and won’t happen.  Unfortunately, their track record speaks volumes otherwise as our compromises to-date prove.  Their efforts are more directed to managing public relations then they are to really solving the problem.

Those of us who have worked on many of these systems will tell you that it can and it will happen - that such compromises are a matter of “when” and not “if”.  Even President Obama knows this but we are doing little of measurable value to protect ourselves.

These larger, more painful, more dangerous attacks will happen unless we get a lot more proactive and a lot more intelligent about admitting the compromised, vulnerable state that we are in.

After the admission, we will have to endure the quick wave of panic, followed by the more powerful wave of indignation that we allowed things to get this far.

Hopefully that indignation will then be followed by a resolution to make the world a better place.

Because it doesn’t become a better place merely through secrecy, indifference, apathy or crossing our fingers in the hopes that everyone is good and that everything is secure.

And while I don’t condone what Anonymous does, their actions and results in the name of social justice demonstrate our vulnerability and our weakness – socially, legally and from an national security standpoint.

What happens if someone uses the same techniques to take advantage of our vulnerability for a more nefarious reason?

It wont’ be their fault.

It will be ours – for being afraid to admit that the problem exists and for not having the courage, wisdom and strength to demand accountability and responsibility to create solutions to make our society stronger on all levels.

And so the “Emperor” that is our society is stark naked.

Let’s not be afraid to call it as it is and do something about it ….

…. while the opportunity is still within our reach, an opportunity that may be a narrower window than you might be comfortable with.

In service and servanthood,

Harry

PS The feel-good stuff that many people like to distribute, some with an effort to hide or ignore the difficulties we face, does have an important place in society.

However, it will take effort on our part to rid the world of as much evil, ignorance, apathy, indifference and stupidity as we can so that future generations will still have feel-good stuff to be inspired by.

A strong, positive future is not a right.

It is something we choose to earn and create ….. or not.

Friday, July 13, 2012

The Shaw Fire And Why It Matters

At 7:12am MDT on July 13, 2012, Alberta Treasury Branch tweeted that their online systems were officially back up, approximately 40 hours after the fire in Shaw Court took out the primary servers of the data center they exist in and water from a sprinkler system took out their backup servers sitting in the same location

I’ve been on a bit of a rant lately about the thoroughness of IT architecture and this unfortunate incident makes me angry.

I know there’s a lot of debate going on around why sprinklers were in the data center and why a non-water-based fire suppression system wouldn’t have been used.  As my buddy Mike D. explains, in a world where inert gas and other forms of fire suppression are very expensive, there are many data centers that actually opt for sprinklers (with an important caveat, which I will explain in a moment).

When hardware was expensive, we tried to save the hardware with non-water solutions.  As hardware became cheaper, the services provided by the hardware (and not the hardware itself) became the priority, which means bouncing control to the secondary site while aggressive fire suppression (including water) deals with the primary location. 

The following statement, released yesterday, explains why this incident makes me angry as an architect:

The system-wide outage was caused when a transformer exploded in an electrical room at Shaw Communications’ downtown headquarters Wednesday afternoon. Although the backup system was activated, when the sprinklers came on, they were also taken out.

This statement violates a basic truth in IT infrastructure.

It doesn’t matter if your building is fire proof, earthquake proof, tornado proof, nuclear bomb proof or whether it has its own nuclear reactor for unlimited power.  It doesn’t matter if error-prone humans are not allowed in the building, replaced by “perfect robots” (created by error-prone humans).

You never put your primary and backup servers in the same place.

There’s one thing that we know about IT and communications.

Murphy’s Law rules everywhere.

When you put your primary and secondary systems together, you are doing so while crossing your fingers, picking a 4-leaf clover, sacrificing a goat to the gods and saying a silent prayer that bad things won’t happen to you.

Most people who put both systems together often do it because:

1. They are saving money

2. They don’t know any better

3. They are overly confident of their solution

4. They don’t care, exposing themselves to Hanlon’s Razor – “Never attribute to malice that which is adequately explained by stupidity.”

Money Rules the Day

I suspect it was reason #1 … well, I hope it was anyway because the other 3 reasons are REALLY problematic.

The reason this event makes me angry is that physical separation of primary and failover servers is basic, teach-the-kids-in-college stuff.

And so when I see some significant names taken out because economics seem to have ruled the day, I wonder what other architectural best practices have been compromised by economics – best practices in the areas of privacy, security or other areas.

I worry because I have seen over the years that the factors listed above tend to not settle in just one area of an organization’s architectural best practices.  Once factors that limit effective solutions are present, they tend to be pervasive through all aspects of an organization’s IT solutions.

If it was for reasons 2-4 (non-financial reasons), the players involved need to be considered for re-education, reprimand or “retirement”, including but not limited to:

1. The architect(s) who designed the solution.

2. The data center facility manager(s) who approved it.

3. The customer service exec(s) who sold it to other orgs (unless they don’t understand it, in which case they shouldn’t be selling it anyway).

Regardless of the reason, the following need to be considered for the same “special treatment”:

1. The leadership team of the creator of the solution.

2. The buyers representing ATB, Alberta Health Services or other groups who evaluated and recommended use of the solution.

3. The leadership team of the buyers who signed off on the solution.

If it was for reason #1 (which, in a twisted sort of way, offers the most comfort), the bean counters now need to reflect on the result of their cost saving venture as they sort out consumer impact and a multi-tier service level agreement involving IBM, Shaw Communications and the many users of the facilities, including ATB, Service Alberta, Alberta Health Services (which cancelled surgeries as a result of the fire) and other groups.

Failures like this matter to all of us since that which we tolerate today becomes the norm tomorrow. And we know what history teaches us:

Those who don’t study history are doomed to repeat it while those who study history are doomed to watch those who don’t to repeat it.

Or maybe, given that similar failures have occurred in the past such as with Aliant 6 years ago, maybe the truth is that:

History teaches us that history teaches us nothing.

The Bottom Line

For me, no matter what the reason for the failure, doubt has been planted in my mind.  Doubt that makes me wonder where else compromises have been made.

And will such compromises produce a 2-day inconvenience the next time or will it be more dramatic or problematic?

Only the architects of the affected organizations really know.

I wonder how many 4-leaf clovers they have in their back pocket.

In service and servanthood,

Harry

 

PS   In reflecting on my experience over the years with data centers, I remembered an interesting incident early in my career.  During a tour of a data center containing classified government information, I was asking questions about the halon fire suppression system.  The system was designed to seal the data center, with no means of reopening the doors or exiting from the inside until the fire was under control. 

As a young, naive IT guy at the time, I remarked that while I saw 20 or 30 people working in the data center, I only saw a small handful of breathing apparatus to be used by these people should escape be required.

With that, he escorted me to his office and pulled out their operations guide.  In it, in clear language that could not be misinterpreted, one policy jumped out at me.

In case of fire, the first priority was to save the facility.

To be able to save the people inside was secondary in importance.

In essence, they were expendable.

Of course, everyone assumed that a fire would never occur in that data center and so such a policy wasn’t questioned. 

But as in the case of the Shaw Court fire, you know what happens when one assumes things.

I would like to think that in today’s world, such a policy within a data center like that couldn’t exist.

But then again, who knows?

 

Addendum: July 14, 2012

Three days after the fire, the impact on Alberta Health Services and other organizations continues to be felt. Public accountability and transparency are essential to understanding what happened and how such situations can be prevented moving forward.

Thursday, July 12, 2012

So How Secure Are We Anyway?

I was in the process of completing my annual report on security vulnerabilities yesterday when the news reported that an explosion in a communication hub in downtown Calgary had compromised landline and 911 service for 30,000 Shaw customers, including some municipal and provincial services.

As I write this this morning, service is almost completely restored.

No biggy …. they only lost service for 12 hours or so, right?

Well, maybe …. but where was the redundancy that should have prevented the failure from impacting those affected?

Here was the cause for the failure:

The system-wide outage was caused when a transformer exploded in an electrical room at Shaw Communications’ downtown headquarters Wednesday afternoon. Although the backup system was activated, when the sprinklers came on, they were also taken out.

I guess they didn’t think of or couldn’t afford a non-water-based fire suppression system, typical for rooms containing mission-critical computer or communication equipment nor did anyone consider the impact of a total site loss, given that they kept the backup system in the same building as the primary system.

Then I think about the time I was in Newfoundland when a fire in a communication hub took out land lines, cell phones, Internet and all forms of communication (thus knocking out any use of debit / credit cards).  The outage was only hours in duration but while the event was in progress, spokespersons for Aliant (the communication company that owned the building) were saying they had no idea when the outage would be corrected, creating extra concern at the time.

Was there redundancy of technology in this situation to protect consumers against a catastrophic failure?

Yes, according to Aliant.  They had full redundancy of all systems.  Unfortunately, the primary and backup systems were in the same building and shared a common power supply.

Where did the failure occur?

You guessed it – the power supply.

So much for redundancy in either of these events.

Ironically, the Aliant redundancy mistake, which occurred six years ago, was studied by information and communication providers across Canada to make sure no one repeated the same mistakes in the future.

Ooops.

When the World Trade Center came down, some of the major communication providers had been using it as a communication hub.  After all, they figured, what are the odds that we could lose the entire site?

Sadly, we know the answer and communication in the NYC area was compromised as a result of the WTC collapse and an excessive number of people using the system in the hours of terror that followed.

When we build communications systems such as these, we strive to strike a balance between need and cost, factoring in the probability of various external factors and events.  We don’t build systems that can handle everyone and everything because, as we like to think, what is the likelihood of a worst case scenario occurring.

As we proved in NYC on 9/11, the likelihood is low but when we need it, the importance of having systems that can handle emergencies is critical.

But alas, I digress ….. on to my originally intended subject.

My Security Report

As part of what I do as a strategy advisor and global technology architect, I provide services to some clients in the areas of assessing security vulnerabilities.

Specifically, how secure are various client’s IT infrastructures, what can be done to enhance their security and should a compromise occur, how quickly can the compromise be neutralized while minimizing the impact of the compromise?

The contents of my report, which will be distributed to specific organizations, shows a number of interesting slices of society that are vulnerable to attack.

The list includes, but is not limited to:

- Specific large-scale banks and credit card providers

- Specific health-care providers

- Specific municipal, state and provincial governments

- Specific airlines

- Specific energy generation / distribution groups

- Specific infrastructure organizations, including some that govern water distribution and public transit

- A specific Roman Catholic Archdiocese that has been rocked by pedophile priest prosecution in the past and is alleged to be hiding a list of known pedophile priests (unknown to the public) who are still active priests

- Other large corporations in manufacturing and retail

- Other entities whose “commercial” nature I am not allowed to mention here.

The vulnerabilities range in nature and scale but the bottom line is this.

There is still way too much vulnerability in our infrastructure, whether it be in our communication infrastructure, in the security and privacy of our data and in national security overall.

Why Is This Happening?

Some folks do the best they can with the limited funding they are given by their leadership - leadership that downplays the risks of not having a thorough solution or who don’t understand the impact to their organization, public or private, and the people they serve should a compromise occur.

Some organizations, governed by greed, pour their efforts into maximizing return, assuming that creating secure, redundant  architecture is just a money-wasting venture that impacts their bottom line unnecessarily.

Some organizations create solutions so complex that obvious vulnerabilities slip by them and they watch in dismay as the seemingly ultimate in technology falls to simple attempts to compromise them.

Some organizations have a lack of knowledge about the threats they face and what is needed to neutralize the threat.  I saw with amusement (and concern) last year when a national retailer placed a classified ad looking for someone to take charge of the design and implementation of a security solution for their entire corporation.

Why was I concerned?  The minimum requirement for the position was a high school diploma.  No other experience, education or security solution background was required.  I guess they will learn on the job.

All of this being said, I still believe that ego and an excessive amount of hubris is responsible for most of the problems we face today.

Beliefs such as “nobody can defeat my security solution” or “the likelihood that compromise or disaster will hit us is minimal” are responsible for many of our compromises, both the ones that make the press and the ones that people on “the outside” never hear about.

How much of a problem is this?

A significant one.

While billions of dollars go into airline security and border control annually, I believe we face a much larger threat when it comes to the security and redundancy of our infrastructure then we do from someone taking a plane out of the sky or sneaking something across the border.

Much of the knowledge of how to compromise, penetrate, steal from or cause the failure of communications and IT infrastructure is available in the public domain.  We face multiple threats ranging from the seemingly benign example of kids trying to hack into the local high school to get the answers to an upcoming exam up to agencies (including foreign governments) attempting,  sometimes successfully, to penetrate our critical corporate, government and military computer systems.

The head of the National Security Agency recently said we need to pour more resources into beefing up our cyber security, causing many people to cry foul that Big Brother was using this as a guise to exert even more control over us.

While I am wary of how much insight government has into our private matters, this is one area where we must not underestimate the need to invest more into protecting our technology assets.

I once asked a well known US / UK military advisor-turned-journalist how he dealt with his knowledge of our vulnerabilities and this was his reply:

“I try not to stay sober”

Now that’s a sobering thought.

The people in my industry (information and communication technology) need to do a much better job at enhancing the security of the citizens of the world at the personal, corporate, national and global levels.

The people who provide funding and make the go / no-go decisions that enable / restrict the people in my industry need to be better informed about the importance and impact of their decisions in supporting such ventures.

And each of us, while varying in levels of technical savvy, must do our best to hold all of these organizations responsible and accountable to do the best they can.

And we’re a long way from doing the best we can.

Many organizations, private and public, have knowingly or unknowingly created ticking time bombs that will impact all of us.

Acknowledging this is not “sky is falling” pessimism.

Acknowledging it is the only way it gets fixed before we get punished for not taking appropriate action.

This is not pessimism.

It is reality.

Most of us say we would do anything to protect the security of our families, our businesses, our nations and the world.

It is time to prove it … with a sense of urgency and appropriate action commensurate with the threats that exist.

In service and servanthood,

Harry

Addendum – July 12, 2012

This news story (about compromised Yahoo accounts) that broke an hour after I wrote the blog is a reminder of our personal responsibility to ensure the integrity of our personal information on the web.

And then a bank went down …..

I noticed that a Canadian bank, more than 24 hours after the previously noted fire in Calgary, still does not have an online presence as a result of this outage in one building.

Here is what Alberta Treasury Branch customers (both personal and corporate accounts) receive if they go to access their online accounts for bill paying and such (emphasis shown is theirs):

We're Sorry...

The fire at the Shaw Court building in Calgary yesterday caused our banking system to go down.

Overnight we moved our system to a back up location. We are working to resume normal services, and anticipate that it will take us a bit of time.

Meanwhile, ABM, debit cards and MasterCards are available, and our branch staff will also be able to assist customers.

We are currently working to restore ATB Online banking and ATB.com as soon as possible, please check back here or on our ATB Financial Twitter account (@atbfinancial) for updates.

We can not access emails right now, so please call your local branch directly if you have questions or require assistance. Our Customer Care Centre associates (1-800-332-8383) are also available to provide more information. And remember, we never contact you via text or email to ask for your personal or banking information.

© 2011 ATB Financial | All Rights Reserved. TM Trademark of Alberta Treasury Branches. Unauthorized access is prohibited. Usage may be monitored. Please visit our website at www.atb.com

So an electrical fire in one building has derailed the online processing for an entire bank for an entire province.

Not comforting nor an unacceptable architecture, in my opinion.

Addendum – 5:40 PM MDT

I received the following note which I couldn’t help but share :-)

Dear Mr. Tucker,

My name is Dxxxxx and I live in xxxxxxx, Alberta.  I am a customer of ATB and because I am on the road, I need to pay some bills today using their online system and of course I cannot. When RIM went down last October, I had to deal with a lot of angry customers and almost lost one because of my inability to respond quickly to them.  With all the firefighting I had to do with my customers because of RIM, I got some free games from RIM for my trouble.

Since I need to explain to some people why I can’t pay my bills today, do you think that ATB will offer me some free games also?

I guess on days like this you need a sense of humour.

Cheers,

Dxxxxx

Dear Dxxxxx,

I hear that the new Angry Birds is pretty cool and might be appropriate. :-)

Thanks for the note!

Harry

Addendum: July 17, 2012

This little ditty was announced on July 17, 2012.  Info about up to 2.4 million voters may be compromised: Elections Ontario.  Preventable and sadly …. predictable.  We can do better and must do better.

Addendum: August 7, 2012

Here’s how easy one can be compromised.  If we are in the IT industry, we need to demand better of ourselves.  If we are not in IT, we need to demand better from those who are.

Tuesday, June 21, 2011

As You Sow …..

… so shall you reap.

So goes the expression.

Financial institutions, government organizations and other corporations have found themselves to be hacked at-will in recent weeks by a couple of different hacker groups.  The organizations who have been hacked claim to be victims of “Internet bullies”, citing they are doing all that they can to prevent loss of data, customer privacy and consumer confidence.

And so I wasn’t  really surprised when a household name in the US banking industry posted a position last week in some of the major job search engines, looking for a senior security expert, someone who would help them architect a stronger, more hack-proof system for their infrastructure.

However, I was really surprised to see the minimum qualifications:

  • Must have graduated high school
  • Should (not “must”) have two years experience in IT

Meanwhile, a retail giant and household name brand (in sports apparel and clothing verticals amongst others) in Canada seeks a corporate strategy advisor to lay the roadmap for the entire organization’s strategy as they make their way through the challenges the world currently faces.

While they require more education than high school, they also preferred a minimum of two years experience.

Billions of dollars and thousands of jobs on the line, in a world that is complex to navigate …. all hanging in the balance with someone who should have at least two years experience.

As someone who spends his day helping people navigate the complex world of strategy and tactics, when I see these organizations making such choices, I realize that it is time to short their stock.

Why?  Because the outcome is extremely predictable and unfortunately for many innocent people, it won’t be pretty.  As the leaders of these organizations sow, so shall their customers and staff reap.

And that is the most unfortunate part of all.

We must do better – we owe it to the generations that follow ours if we are to remain a society of strength and opportunity moving forward.

Don’t we all want the best for our children and the next generation?

I thought so – then it’s time to demand the best from ourselves and others.

For as we sow, surely we will reap.

And I’m not entirely convinced the current harvest is the best we are capable of.

In service and servanthood,

Harry

My Musings-in-a-Minute entry for “As You Sow ….” is the same as this one and can be found here.