Wednesday, August 10, 2011

USENIX: Three Cyber War Falacies, Dave Aitel, Invited Talk

Dave Aitel, CEO of Immunity, Inc, started out with a picture of "The truth shall make you free" - a quote from a wall in the offices of the CIA, which helped Aitel launch his talk on cyber security and cyber war and how irony pervades this industry.

According to Aitel, there are three fallacies of cyber war:
  1. Cyberwar is asymmetric
  2. Cyberwar is non-kinetic - as in it's in the virtual world, no "real" victims.
  3. Cyberwar is not attributable
Aitel notes that there won't always be explosions or "instant death" when it comes to cyber war, but there can still be great consequences - including loss of utilities, the more things come on line.

He warns Californians about the security implications of PG&E's SmartGrid, where a not-so-smart chip will control when you can have AC, etc., that will be very easy to compromise. That type of attack, along with recently discussed expoits on automobiles, put people's lives in jeopardy every day.

For example, STUXNET, which many took as a temporary trojan horse that is now totally under control - what the community at large doesn't seem to see, is that it was a demonstration that this (or something like it) can be used to target any factory or any utility at any time.

The problem with a lot of these trojans and worms, is that once your corporate network is infected, it is virtually impossible to to completely rid your network of these hackers. Think about it, if it took you six months to a year to discover the intruder, then you have to assume they are everywhere and you will unlikely be able to totally get them out.

Aitel then started on his point about how cyber war is NOT asymmetric by giving many counter examples, though, unfortunately he spoke very fast and the slide ware moved quickly (and was overcrowded and filled with tiny words) so I had a hard time following that point...

Automated computer security commonly involves things like vulnerability scanners, static analysis, web application scanners - they just don't work, too slow and tedious and really still require manual analysis. Aitel believes his team can find more bugs by just looking at the code, rather than relying on this analysis. Personally, I think that's great if we were all perfect, but I've definitely seen static analyzers find stuff that humans missed, both in writing and while reviewing.

Aitel has a very strong opinion on "script kiddies" - he believes that the term "script kiddie" belittles what is really a challenging career, which he compares to nuclear scientist. I'm sure he's trying to be a bit tongue in cheek, but, as someone with a science degree, I can say for certain that a nuclear scientist would most definitely be a lot more skilled than someone that runs someone else's attack scripts. Sure, there may be some learning curve to running these, but... it's not nuclear science.

Aitel then went on to quote CERN about how SSL based VPNs are all broken, due to fundamental flaws in the architectures, but did not go into details. I'm happy that I'm reading my mail over an IPsec connection ;-)

One thing that has changed over the years is that the attacking community is now mature, organized and highly motivated. After realizing that DefCon this year had reachead 19 years of age... and that I started attending back in DefCon 2, I can only imagine how accurate that statement is. [and at DefCon this year, there was a children's track.... ]

Regulation can't help here - it's too slow. Aitel argues until the "traditional bearded men that work on security get into Government" it isn't going to get better. I guess Professor Spafford meets that mold, but not sure how Susan Landau fits that mold.... guess she'd better work on her beard.

Overall, this talk was fun and entertaining, but seemed to be an agenda for why you couldn't possibly secure your own network or code on your own, and you need to hire his security team.

I think the important take-a-ways are that you cannot rely on static analyzers alone to make sure your code and network are secure, policies and tools need to be regularly re-reviewed, and keep ahead of the attackers.

The audio and video of the talk are now online.

This post is syndicated from Thoughts on security, beer, theater and bikes!

USENIX: Charles Stross Opening Keynote

Charles Stross, two time Hugo Award winning science fiction writer, greeted us with a talk on Network Security in the Medium Term (2061-2561). He quipped that by setting his predictions so far out, we'll be unlikely able to prove him wrong - and if we can, then he'll be happy to just be alive.

His talk started out with stating the obvious, that we won't have to worry about network security if, for example, we have a global system panic - so, he's going to assume that doesn't happen. The other issues around seeing his predictions come to fruition depends on medicine meaningfully extending our lives, having stable political systems and managing society's increasing complexity.

In the future, we won't be able to ignore emerging countries like China and India, and, well, the whole of Africa, all of which will change how we manage security and interact together.

Stross told a story of a theoretical time traveler from the 1960s and how huge of a technology hurdle he'd have to overcome - no imagine how much technology change we can expect in the next 50 years! Children nowadays will never know the experience of being lost, always connected, always with GPS at hand. [of course, such an assumption presumes the child growing up in a home of means, don't forget the aforementioned Africa!]

Stross took us through a myriad of potential futures - like will we, as humans, have a lifelog like we have in modern cars? Will we have to fight super viruses, bacteria and cancer? Will genome sequencing computers be able to help protect us? But, will we want to share our own DNA in order to aid these computers? Give up our privacy in order to always have an alibi? Give our insurance companies access to vehicle harddrives so they can detect how people really drive?? It seems unlikely.

I've personally submitted my DNA into two systems: Kaiser Foundation's Genome Study and 23andMe. I did this both to advance science and to give myself valuable information about my gene profile, though my neighbor, a DNA forensic scientist, believes I was insane to share my DNA with anyone. Perhaps I should've consulted her before I spit in that cup.

Lots of interesting scenarios to think about, we'll definitely have to be more careful with our privacy as more information is put online and in storage.

The audio and video of the talk are now online.

This article is syndicated from Thoughts on Security, beer, theater and biking!

Sunday, August 7, 2011

Peaches en Regalia

My husband and I had the pleasure to see Peaches en Regalia from Wily West Productions at the Stage Werx Theater in San Francisco last weekend.

This is a new work, being presented for the first time as two acts. It's a sweet play revolving around the ever changing life of the title character, Peaches, who has recently taken a job at a restaurant where they serve... wait for it... Peaches en Regalia.

Sarah Moser, as Peaches, takes the stage by storm with her opening monologue which describes college, her internship at a financial institution and why she decided to take a job at a diner. Moser is energetic and her monologue comes to life as the other actor's help her reenact scenes from her recent past.

The hilarity continues when Philip Goleman comes into the diner as Norman and then gives us a hilarious monologue on bathroom etiquette and working on his flirting skills.

Of course, the two come together. The fast paced and delightful show moves along as Nicole Hammersla (Joanne) and Cooper Carlson (Syd) fill in the picture. Joanne has a nervous tic (picking at her sweaters) and Syd is a soft-hearted republican.

This was a wonderful production that will keep you entertained throughout! Even with a short 10 minute intermission, the show was still about 90 minutes running.
Definitely worth a trip up to San Francisco!

This post is syndicated from Thoughts on security, beer, theater and biking.

Thursday, August 4, 2011

Oracle Solaris Security BoF at USENIX Security

I'm excited to announce that Oracle Solaris Security developers will be presenting on our recent work, talking about cloud security and doing a Q&A panel at a BoF at USENIX Security next Thursday night.

Date: Thursday, August 11, 2011
Time: 7:30-8:30 PM
Location: The Westin St. Francis, 335 Powell Street, San Francisco, CA
Room: Elizabethan A

If you're attending USENIX Security, please come by. There will be give-a-ways for excellent questions and beer. Does it get any better than that?

Tuesday, July 26, 2011

Scratch: Lagunitas Beer Dinner

I've got a huge backlog of beer related blog posts, so many that it's a bit overwhelming. So, instead of starting many months back, I'm going to restart with some recent brew dinners and hopefully get the others picked up in a retrospective of sorts.

A new restaurant in Mountain View recently opened up called Scratch. They feature upscale American "comfort food" and have recently begun doing beer dinners. This is very appealing to me, because I can walk there, which beats the myriad of trains and late nights it takes to get to the Monk's Kettle (but, wow, are the Monk's dinners good).

The featured brewery on July 7, 2011, was Lagunitas Brewing Company, based in Petaluma, California. I've been to a Lagunitas beer dinner before up at the Monk's, so I was very excited they were coming down to Mountain View. You've probably all seen their IPA in the grocery store, but don't let that fool you - Lagunitas does a lot more than just IPAs.

The first course, prepared by Executive Chef Sean Eastwood, was an ahi tuna "gazpacho". With a name like that, I was expecting a sort of soup, but what we got was a lovely, thick piece of raw tuna topped with a sweet gelee, served with an heirloom tomato confit, almond and avocado puree. This was paired with Lagunitas classic IPA, coming in at the evening low of 6.5% ABV. The IPA is their standard hop forward American style IPA, which was softened nicely with the food. An excellent pairing.

Ahi Tuna

While waiting for the next course, we got to try the Wilco Tango Foxtrot (available in the 22oz section of many local groceries - yay!), a wonderful brown ale with 7.8% ABV. Jack Alger, in charge of Ales and Marketing at Lagunitas, told us a bit about this beers origins: While most browns are low in alcohol and typically a session beer, that's just not what Lagunitas makes - yes, this beer was mild in flavor, with the slight nuttiness you'd expect from a brown, but an extra sweetness made this even easier to drink and reminiscent of a bourbon barrel ale. Approach with caution, as a 7.8% ABV beer will bite you on the butt if you're not careful!

Wilco Tango Foxtrot

The next course was sweetbreads. Not something often eaten anymore stateside, but something my husband, a Brit, had had more than enough of growing up. Scratch and the chef were awesome and prepared my darling husband some sweet pea ravioli as an alternate course.

Mark's Alternate

He absolutely loved the course and in particular the thinly sliced fried zucchini.

The rest of us at the table got the sweetbreads. I'll let you read the wikipedia entry to see what exactly sweetbreads may be (hint: all kinds of things qualified as offal), so as diners, we were left to our imagination to guess what exactly we were eating. The black lentils were delicious, but the citrus (grapefruit?) was a bit too tart for the beer and the rest of the dish. The sweetbread itself (which was later identified as the thymus gland) was very fatty, and tasted a bit like chicken livers with the texture of frog legs. I think it could've been much better prepared if it were in a bread sausage like form, where the bread could've helped to soak up some of the fat. The fried giant capers, though, were a nice touch.

Sweetbreads

Next came out the Lagunitas Hop Stoopid. With a name like that, I was worried - I like a hop flavor in my beers, but not "attack hops" - you know the kind, so bitter they make your tongue curl? Well, it was a bit like that... but, my husband and the other Brit at the table love their beers like that, and so the ABV 8.0% brew did not go to waste.

This was paired with the "Bone Marrow, Two Ways" course. As should be obvious from the picture, the first way was right in the bone. The second way was fried - a bit like a tater tot. This came with a wonderful salad, again with grapefruit, that was very delicious. I spread my bone marrow right onto the crunchy crostini, but even then it was still a bit too rich. I'm not sure how the fried quail egg fit into the picture, other than making for quite a beautifully plated dish.

Bone Marrow 2 Ways

Finally, the Lagunitas folks brought out one of my favorite styles: a red! The Lucky 13, coming in at a hefty 8.3% ABV, was a much more mellow beer than the Hop Stoopid, with toasted malts being the prevailing flavor. This paired wonderfully with the lamb ravioli served with sweet peas, pickled artichokes, mint syrup, pea and mint puree all on top of... cassoulet lamb shank! This was a meat lover's delight. The ravioli was fork tender, and the lamb simply melted in your mouth. The beer positively opened up with this course, the best course and the best pairing of the night... well, until dessert.

Lamb Ravioli

Lagunitas delighted us with the next beer, Little Sumpin' Sumpin' at 7.5% ABV. This was their version of a Belgian Wit beer, made with Belgian yeast, yet filtered (which seems, at least for me, to lower the hangover factor). While it was hop forward, the beer was still delicate and sweet, with a slight hint of peach to it, which means it paired absolutely perfectly with the Peach Buttercake. The cake, similar to an upside down pineapple cake - just with peaches, was moist and bold enough to stand up to the beer. The lavender caramel made it all just like a spa experience. I was in heaven.

Dessert

That was supposed to be our last course, but Jack had something else up his sleeve, a Cappuccino Stout (8.8% ABV). This beer, which smelled just like chocolate covered espresso beans, was actually made with a special blend from Hardcore Espresso in Sebastopol.

Cappuccino Stout

I was actually thinking at the time that I would've liked some more of that ice cream from the previous course so I could make my self a beer float. Fortunately, the chefs wanted to surprise us as well and they brought out a bonus dessert of chocolates! Splendid!

Second Dessert

Overall, a magnificent dinner right here in Mountain View. The staff was friendly and accommodating. I loved having someone from the brewery present to tell us all about the beers, and the pace of the food was perfect. For future dinners, though, I would recommend the chef try to balance the super rich and a bit strange courses more with the rest of the menu. The only bad surprise came at the end when there was a 22% gratuity added on top of the total bill (that is, food plus tax). I didn't expect that for our group of four, and only mention it so that if you join a future dinner, you can be prepared.

Now the question, do you like the picture of the course before I talk about the course, or after (as is done in this post).

This post syndicated from Thoughts on security, beer, theater and biking!

Wednesday, July 20, 2011

Woe is Me -or- Going through TSA with a broken finger...

Sorry it's been so long since I've written - I had a broken finger!  It's mostly better now, but for awhile there, I kept my typing to mostly work specific activities. Typing when down an index finger is not the easiest thing to do, especially since I've been touch typing since I was 12 years old, not to mention the finger just plain hurt.

What does this have to do with the TSA you might ask?  Well, I did this on my way to the airport when I was coming back from a trip to Fort Wayne, IN.  Being rushed, talking to my sister on the phone, and my dad and a friend in the car, while getting out to get a coffee... something fell through the cracks. Well, or got stuck in it... slammed that finger right in the door! The folks at Starbuck's were kind enough to give me a bag of ice, but that was not something I really needed at that moment. While I didn't know it was broken, I did know it hurt like nobodies business.

Fast forward 20 minutes and we're going through TSA. The Fort Wayne airport, while very small, seems to have the most well provisioned TSA division in all of America.  If there's a new process or tool, they have it.  Plus, they don't really have any lines, so what's the rush?

I'm not a big fan of the new scanning machines. I think they were rushed into the airports, aren't well studied, and are a great example of industry lobbyist pushing "safety" standards, so I wanted to opt out.  One of my traveling companions has recently had a lot of radiation (treatment for cancer) and also opted out.

This airport isn't really set up for this - as the line just puts every single passenger through the scanner, so anybody that opts out has to go through an unusual procedure.  As my friend was also a female, she had the one female agent on pat-down duty totally occupied, so I had to send all my luggage through the x-ray and wait on the outside of the metal detector.

Even though my finger was in excruciating pain, I waited until my friend cleared.  My pat down was uneventful and no worse than I've gotten before when setting off the metal detector. I was neither embarrassed nor threatened, the TSA agent was respectful and friendly, and she screened her gloves for explosives after the pat down.

But then I set off an alarm.  Hrm. Even though my finger was in excruciating pain, I had to go to another room and get another pat down, this one slightly more invasive. After awhile, the agent and her supervisor took pity on me and brought me the ice my husband had gotten for me, which helped a lot.

But then I set off the alarm again.  This time nobody knew what to do next. They decided they needed to double search my bags (by rescreaning, hand check and check for explosive residue), but that's where there was another pickle. In all that time where I was not able to get to my luggage, my husband had repacked it for me. And since he was standing with our traveling companions and TSA didn't know, 100%, if something may have been handed over - my companions all got rescreaned. They (and all of our luggage) were negative for any residue or suspicious items.

I finally thought of what might have been causing the alarm: I'd gone to an antique store with my Dad that day, and he'd looked at antique guns. Was it possible I actually *did* have residue on me?

Two TSA agents and two supervisors later, we were all on the airplane!

Coming home, my husband thought of a more likely cause: I'm always fertilizing things in our garden and may have done so in those same jeans right before I left.  Word to the wise, don't wear clothes to the airport that you may have worn in your garden! Or go antiquing ;-)

As I was walking away, one of the TSA supervisors asked the other, "Did you write down her name?", and I heard, "Yes, it's right here."  Which, of course, means I'll be sure to be extra early for all of my future flights.

Now, why is this all so frustrating? I'm sure you've all heard of the guy last month that was flying around with expired boarding passes.  He wasn't arrested the first time he was caught, but the second time.  Are we really spending our efforts in the right place?

This post is syndicated from Thoughts on security, beer, theater and biking

Thursday, June 30, 2011

Sun Metaslot and my missing keystore

By Karen Tung on Jun 14, 2005

[VAF: This entry was transfered from Karen Tung's old Sun blog, due to its relevance to the Solaris Cryptographic Framework]

Since The Solaris Cryptographic Framework is integrated into Solaris 10, we have added some new features to the framework. One of these features is the Sun Metaslot, which will be generally available in the next Solaris Update release. In case you can't wait till the next Solaris Update to try out this exciting feature, this is also available since Solaris Express 2/05, and in Solaris Patch 118918.

The Sun Metaslot will greatly simplify the life of developers who write applications that uses PKCS #11. Now that Open Solaris is a reality, I can talk about the implementation of this new feature and clarify one question I often get from users who are used to using the framework the way it was in Solaris 10.

What is Sun Metaslot?

The Sun Metaslot is a new additional slot to the The Solaris Cryptographic Framework. It provides the virtual union of capabilities of all other slots in the framework. Instead of having to deal with many slots, an application can simply choose the Sun Metaslot, which have access to features of all slots currently plugged into the The Solaris Cryptographic Framework. It also does the tedious work of managing sessions and objects on different slots so an application can use the best slot for a particular mechanism without having to move objects and sessions back and forth. The Sun Metaslot behavior conforms to the PKCS#11 Standard. Applications should treat it as if it were any PKCS#11 slot with normal PKCS#11 semantics.

When you install the next Solaris Update release (or Solaris Express 2/05 or the patch), you will get the Sun Metaslot feature by default. There is no special configuration necessary. The Sun Metaslot is always presented as the first available slot in the The Solaris Cryptographic Framework. As such, if your application is written in such a way that it just uses the first capable slot to perform cryptographic operations for your application, your application will use the Sun Metaslot with no modification at all. If your application is very particular about the exact slot in which an operation is done, all slots in the originalThe Solaris Cryptographic Framework is available as usual except a minor catch, which I am going to explain below.

Why is one of my slots missing?

Ever since I gave the beta version of my Sun Metaslot implementation to other Sun internal engineers to try, I often get this question in my email. I am sure many of you might have exactly the same question. So, it's probably useful to explain it here for the last time, hopefully.:-)

Here's the typical email:
I installed the Sun Metaslot feature into my test system, and everything seemed to work fine. However, when my application does a C_GetSlotList(), I found that the "Software RSA PKCS#11 softtoken" slot is missing. Is this a bug?

This is working as designed. When the Sun Metaslot feature is enabled, one visible difference you see on your system is the slot that is configured to provide persistent storage for "token" objects (aka keystore) is "hidden". The Sun Metaslot does not have its keystore. It uses the keystore from one of the actual slots. By default, Sun Metaslot is configured to use the "Software RSA PKCS#11 softtoken" slot, so, users will see that it is "missing".
The slot to be used as Sun Metaslot's keystore is configurable. See the cryptoadm(1M) command on how to configure a different keystore for Sun Metaslot.

During the Metaslot implementation, we found that making the keystore slot as one of the available slots will cause a problem with "object aliasing" between the Sun Metaslot and the keystore slot. If an application accesses the Sun Metaslot and the keystore slot at the same time, we won't be able to control the authentication state. For example, if the application first calls C_Login on the Sun Metaslot, Sun Metaslot will call keystore slot's C_Login(). Now, if the application makes the a sequence of a C_FindObject calls to retrieve the list of private objects from on the keystore slot, it will be able to successfully get the list. However, this is not the right behavior since the application hasn't done a C_Login to the keystore slot yet.

To prevent the above problem, we decided that it is best to hide the keystore slot. Even though an application won't be able to access the functionality of the keystore slot directly. All its functionality are still available via the Sun Metaslot.