Wednesday, November 13, 2013

Top 10 IT/InfoSec terms that need to go!

Many people are sick of buzzwords and want to see them go. I am one of them. I never had a problem with it in the past. Until, that is, non-techies began using them without understanding the implications. 

Here is a list of some of my favorites words or phrases that need to go...

1. Cyber - After many years in the DoD I never got tired of this word. Why is it on my list? Because it is overused by non-DoD peeps when they complain about its use. If you stop complaining about the word, its use will be cut by 3/4.

Image credits - L Macvittie

2. Cloud - When I first used this (10 years ago) it was a picture of an actual cloud to show users that the ISP took over. Now it is so pervasive my kids think of computers before they think of rain.

3. Big data - Uh, what! Why did we ever start using this phrase? Oh, I know. The phrase "lots and lots of data" never caught on. 

4. Black swan - Used to be something until it was EVERYTHING. Just because you suck at business continuity and disaster recovery doesn't mean your problem (experienced by others, by the way) is a black swan.

5. ... for fun and profit - Try to at least be original. Nothing says "I'm a copycat" like this phrase.

6. iWhatever - See number 5.

7. APT - If I can sell you on an idea, I can sell you anything else I want.

8. De-duping - Stop trying to sound cool and use words like efficient.

9. Bloatware - Really, we have to create a new word for unwanted software just because it is on a phone (a.k.a. handheld computer)?

10. Brick - You say you bricked your device. Then you rebooted/restored it. If it is bricked then it will never work again for its intended purpose.

Lets throw one more in for good measure.

11. 4G - Stop using this for anything phone related. It is the 4th generation of mobile phone technology, that is all.

There are others that annoy me but these are the top of my list. Do you have any terms that you want gone? Add them to the Comments sections so they will be used again. 

Monday, November 11, 2013

My misfortune and my new (old) phone

     A few months ago, I had the distinct displeasure of updating my company's Mobile Device policy. It was not the fact that I was writing policy (I actually am one of those weird types who enjoy the nuances of policy writing). The displeasure stemmed from the fact that I purchased the Samsung Infuse and this particular phone did not allow encrypting the handset, a clear violation of said policy. Woe is me. I was discussing this fact with our company's AT&T rep when those fateful words came out; "What kind of phone do you want?" I immediately went tops and asked for a Samsung Note II. His answer, "Give me a few weeks and you'll have it!"

     This sounded like a great deal. In hindsight, it was a mistake. After getting attached to my new Note II, I got a fateful call. I had to return the phone. Now I am back to my Infuse. What was a great phone (when first purchased) is now woefully inadequate. Not only that, but now my development device is no longer usable. I can't play with the Infuse while using it as my only phone. Also, I cannot login to corporate email anymore. (Actually, I can. I just choose to not bypass our technical controls). All of this has led me to technology withdrawals. I feel out of touch when I can't respond to an email while waiting in line at the DMV. I always laughed at those who were not sufficiently connected to the world. I know know their pain.

***On a later note. After a week of using my original phone, I am rather enjoying the freedom of responding in my own time! #silverlining***

Thursday, October 31, 2013

ACLU - A Wolf in Sheep's Clothing: But they got this one right!

     In my recent presentations at Hack3rCon^4 and SkyDogCon 2013, I spoke about the fact that NSA wiretaps are legal (according to current interpretation of many laws). In addition, I highlighted some programs that push the envelope on constitutionality. One such program is the Nationwide Suspicious Activity Reporting (SAR) Initiative (NSI). I talked about how this program violates our First Amendment and (possibly) Fourth Amendment rights.

     Yesterday, program details came to light after many years when the ACLU published the findings of its Freedom Of Information Act request. Years ago, the ACLU submitted a FOIA request that  was summarily denied by the government. They quickly followed this denial with a lawsuit against the FBI. Well, they won.

     Just as I suspected, the ACLU determined that the program did not have adequate checks to ensure citizen's rights were being honored. This is not their interpretation of the data. You see, they received volumes of internal  emails and reports that stated this as fact. Several State level "fusion centers" complained about the handling of private citizen's data, the lack of a privacy policy, and storage of data in the eGuardian system.

     I still stand by the premises I stated in my presentation. NSA warrantless wiretaps are legal (albeit, unconstitutional), blame rests equally on the 3 branches of the government, and the ACLU is a den of hypocrisy! I base the latter on the fact that they claim that they have

"been the nation's guardian of liberty, working daily in courts, legislatures and communities to defend and preserve the individual rights and civil liberties that the Constitution, Bill of Rights and laws of the United States guarantee everyone in this country."  

Why am I so critical? The ACLU pushes hard for the Bill of Rights on a national level with the exception of the Second Amendment. When I questioned an ACLU lawyer about this at DEFCON XXI, I was summarily dismissed just as the government dismissed their FOIA request. When I asked again for a reason, this time at their vendor table, I was told that it was a state-by-state issue, not a national issue. 

***Apparently, rather than being a guardian of you rights, they see fit to pick and choose what rights you should have!***

I once again submit to you that you should NOT support the ACLU but you should support organizations that believe the entire Constitution and Bill of Rights is worthy of being defended.

Also, before you try and interpret the Bill of Rights, you must read what the authors and original supporters of this great document said on the issue.

If you would like to know more see the following sites:
NSA wiretaps are legal (and other annoying facts) presentation http://www.irongeek.com
Quotes by founding Fathers (public domain) http://cap-n-ball.com/fathers.htm
ACLU article and reports on SAR/NSI www.aclu.com

Wednesday, October 30, 2013

SkyDogCon 2013: Southern charm meets hackers/makers, then gets owned!

   
     I wrapped up my year of cons with the 2013 SkyDogCon. After attending last year for the first time, the decision to attend this year was a no brainer. This is perhaps the most unique collection of mini-events wrapped up into a con there is. Highlights include the typical: quality speakers, lock pick area, hardware hacking village, etc. In addition, there is a healthy smattering of the unique: a rocking electronic badge (includes a hardware hacking challenge), paid breakfast on Sunday morning, a Pirates vs. Ninjas Ball, a ham radio license exam, lego challenge, and others.

     I will begin the blog with a review of the Hotel Preston. This hotel is the model of "southern hospitality" with a twist of the unique, bordering eclectic . From the decor to the staff, this hotel sets itself apart. Think of a scaled down version of The Artisan Boutique Hotel in Las Vegas (former home of BSides Las Vegas) but not as dark. The artwork and decor is an experience in itself, the food is appropriately priced, and the rooms are clean and modern. My one complaint from last year was the speed of food delivery from the kitchen. This was remedied this year. No complaints from me.

 ****Note: If you are feeling lonely, ring the front desk and ask for a fish. Yes, you read that correctly. If you ask for one, the hotel will loan you a fish tank, complete with scenery and a fish. Then you won't feel weird since you can talk to something instead of yourself.****


   The second thing I will talk about is the relentless promotion of the con by its Core Team and Staff. I first learned of SkyDogCon from SkyDog himself, at DerbyCon. Yep you read that correctly. SkyDog was staff at DerbyCon in Louisville and was printing up gimmick badges from popular movies. The one from last year was a mock credit card with the "Triple Crown" challenge on the back. This was a call for all card carriers to attend not just SkyDogCon but DerbyCon and Hack3rCon (a.k.a. the trifecta of regional cons). I later discovered that SkyDog (who is also a Goon at DEFCON) was going to give out special promotional badges at DEFCON to anyone willing to promote the con. Sign me up! This level of detail for promoting his con, and the sister cons of the area, highlights his commitment to the industry as a whole! This year he and Mad Mex spent over 6 hours, during the party, printing up badges for anyone who wanted one.

     Third, we have the awesome lineup of speakers. There were 2 speaker tracks (Friday-Sunday) with 20 minute Lightening Talks (Thursday night). I was fortunate enough to be selected for both a Lightening Talk and a main track. The Lightening Talks format was a set of 20 slides that autoforward every 30 seconds. This was a challenge that forced me to work on my presentation skills. My Lightening Talk was entitled Defense-in-Depth: Fists, knife, gun and will be posted on my blog when they are uploaded. Unfortunately, with 2 main talks going on simultaneously, and the other speaker in my time slot being Deviant Ollam, I had a sparse audience. (Thanks to the 7 people who listened to my presentation NSA Wiretaps are Legal and Other Annoying Facts.) My favorite presentation of the weekend was Evan Booth's. He presented a very serious topic with wit, charm, and grace. Then he showed videos of himself totally destroying fruit. You have to see it. It will make your day as well as scare the heck out of you.

     Finally comes the piéce de résistance (i know, the accent mark on the first e is going the wrong way, but I can't make it work on my Mac).  SkyDogCon is known for its electronic badges. This year's badge does not disappoint. This badge, which has some hardware issues, is utilizing only about 5% of the functionality it was designed for. That 5% however will blow you away! It's simple design, coupled with the Parallax Propeller chipset, and brilliantly written code is a n00b hardware hacker's dream.

****Note: SkyDog announced that he will repair the badge himself if you bring it to one of the future cons he will be at. Anyone up for a quick trip to Atlanta for Outerz0ne? I'll drive if you pick up the room!****

Schematics and badge hacking tips will be posted on the website shortly.


     So, if you feel that you want to know more, visit the website. Don't forget to sign up for the mailing list and follow them on Twitter.

Website: www.skydogcon.com
Twitter: @skydogcon

I hope you enjoyed this blog entry and I hope to see you next year.

P.S. If you sign up for a ticket early, you get "Early Bird" status and this results in upgrades to your badge!

Wednesday, October 23, 2013

"Stop Watching Us Rally" - How I wish I could be there!

     I recently gave a presentation entitled "NSA Wiretaps are Legal and other Annoying Facts." I am not a lawyer and maybe I got some things wrong. I am ok with this since my point was to get the community talking. The basis of my talk was that the NSA is performing many surveillance actions at the direction of the President, under the guise of crappy law written by incompetent lawmakers in Congress, and with the aid of a Supreme Court and a legal framework that couldn't care less about the Constitution. I made mention of the rally put on by Stop Watching Us. My only regret is that I cannot be there in person. That is why I am writing this. I want to get the word out!
     Please use the link to check out Stop Watching Us and sign their petition (571,000 have signed so far). Also, sign up for their rally. If you cannot go to DC on such short notice, fine, you can attend online. After you do this, please use these 2 links to find you Representative and Senator. When you find them, send them an email AND fax. Then call them! This has to STOP!
     Don't stop there. Think long and hard about supporting the EFF and their Constitutional campaign.

I will leave you with a quote from one of our founding fathers. Keep in mind that these guys were in the midst of throwing off the yoke of tyranny and the blood was still in their mouths from the fight.


"Those who would give up essential liberty to purchase a little temporary safety deserve neither liberty nor safety."
Benjamin Franklin, Historical Review of Pennsylvania, 1759
US author, diplomat, inventor, physicist, politician, & printer (1706 - 1790)

Sunday, October 20, 2013

Hack3rCon^4: Eye of the Storm

     What do you get when you mix Information Security, prepping, and technology with mountains, makers, and moonshine? Hack3rCon! I was fortunate enough to both attend and speak/teach at Hak3rCon^4 this year. This is my second time to attend Hack3rCon and I was not disappointed. For the meager price of $75 the attendee will be privy to cutting edge tools, "A" list presenters, and fellowship.



     This year's con began on Friday with a community driven class on the installation and use of the new Kali Linux BackTrack load. This class introduced the novice to the tool. The relaxed setting and knowledge of the instructor set the tone for the weekend. Students learned that installing and setting up Kali is easier than earlier versions and is not as frustrating for noobies. Friday ended with an @HackerFamilyDinner at a local steakhouse.
     Saturday began with Dave Kennedy as the keynote. As always, Dave captivated the audience with his simple way of communicating the holes in security "best practice." After all, just because the masses are doing it, doesn't mean that it is best. He wrapped his presentation by performing a quick demo of his new tool [working title: Pentesting Framework]. This was promptly followed by a series of outstanding presentations that ran until 5PM. After a short break for dinner, 304 Geeks treated everyone to a gun safety class (something you never see at a conference).
   The conference wrapped up on Sunday with another lineup of great talks, the wrap-up of the CTF, and several raffle drawings. People said their goodbyes and, as usual, teams were formed to tackle some hard infosec problems.
    My thoughts of this conference are all positive. The small size, usually around 100 people, coupled with the low price for a ticket and the caliber of the presentations makes this one of my favorite cons. I look forward to attending next year.

As always, videos for this con can be found at irongeek.com. Thanks Adrian!

I would also like to thank the rocking sponsors for making this con possible. This is the first time I have thanked sponsors on my blog. This should tell you something about the level of support.






Saturday, October 19, 2013

Hack3rCon^4: Handgun Safety Course

     For those of you that attended my handgun safety course, and are wanting to file for your license in West Virginia or Virginia, you will be required to present a copy of my NRA Instructor credentials in addition to the affidavit. Please go here to download my credentials. NRA Card