Archive

Archive for the ‘Technology’ Category

Thoughtlet – Are we moving to a single device?

June 15th, 2013 No comments

This isn’t a fully fleshed out thought. It is the beginning of some musings after looking at the Apple WWDC announcements and how they are building tighter integration between OSX and iOS. It was also spurred on by this article. As users are being driven by portability and the lag between feature parity of devices is shrinking, and looking at the history and trends of personal computing purchases, are we finally moving to the “single device”? What will this new “single device” look like and what affect will it have on the current trends in the market?

Screen Shot 2013-06-17 at 9.42.33 AM

If you don’t like my picture there are others to choose from

Personal computing kicked off in the 1980s with the personal computer. This was the first time that general and flexible computing was available to the average person.

In the 1990s mobile phones took off as did the personal digital assistant (PDA) in the mid to late ’90s. This took communications and personal computing mobile. Given the limited capabilities of the PDAs at the time, most people still had a desktop PC. Those lucky enough, also had access to laptops in the ’90s, these too had limitations and for the more powerful users, increased their device count further.

In the late 1990s PDAs merged with phones to create the first smart phone, reducing the number of devices a person carried.

The 2000s brought the advancement of laptops as the norm and in the latter part of the decade saw the introduction of net books and ultrabooks as a way of increasing the portability of computing, it also saw the paradigm (can’t believe I used paradigm) shift in mobile telephony with the introduction of the iPhone. This new interface saw people’s view of mobile computing change forever.

By 2010 tablet computing, on the back of smart phones, came to market and introduced another compromise to computing. This now sees people with 3 devices, notebook, smart phone and tablet computer, each needed for a specific purpose, notebook as the data entry and manipulation device, smartphone for the all purpose device and a tablet as the compromise of the two, meeting somewhere in the middle.

In 2013 we now see the decline in PC sales and increase in smartphone sales with tablets of varying specification and size, trying to balance capability and portability, as well as smartphones that are so large that the challenge the smaller of the tablets on the market. Why? This jostling and positioning is trying to meet the consumers needs what are these needs?

 

I argue that people are trying to get that balance right. Ideally they don’t want a phone and a tablet, but the phone screen is too big, or the tablet too big to always have with them. If this is truly the case then the real future is going to look a lot different from where we are now, reaching an almost sci-fi climax.

 

I think what will eventually happen is that the processing power that a mobile phone can have will be comparable with that of the ultrabooks of today. Once this happens is there really a need for everyone to  have 16 devices? The new devices will be like the smart phone today with a docking capability to turn it into a powerful data entry and manipulation tool or a sleeve that allows it to have a bigger, interactive display like that of a tablet or laptop .

iphone_5_aluminum_oc_dock

vision of future of personal computing

If this is the case, what are the implications to current enterprise trends?

 

Cloud Services - Today file sharing tools like box and dropbox allow us to share files with others, but most people tend to use them as a way of synching and backing up their own personal data. In the single device world this won’t need to change. whilst the synch capability will be less of a concern, the sharing capability will increase as it does today, moving from file sharing to collaborative content creation and manipulation.

BYOD – the Bring your own device phenomenon,like cloud, is moving past the disruptive trend and becoming the norm. With a single device, the only barrier is compartmentalisation of work and personal. As mobile computing power increases so will the ability to have capabilities like personas or profiles. Allowing the seamless switching between contexts work and personal contexts

Security implications – This will cement the concept of the micro perimeter (see really crappy Figure 2 below). Mobile computing and secure code execution is becoming more and more mature, so too has the shift in desktop computing. We’ve moved from the personal firewall and the Hypervisor to the Micro-visor (see Figure 1 below) providing the ability to secure the execution of the operating system itself, as well as temporary sandboxed instantiation of the applications as they are used. Incorporating the Mobile device management (MDM) platform concept into a policy based micro visor, allows the seamless movement from personal device to multifunction device, with employers being able to specify policies for the components under their control.

Hyper-Micro

Figure 1: Hypervisor to Micr-visor

Figure 2: Evolution of the micro-perimeter

Figure 2: Evolution of the micro-perimeter

I think that the trends of today are not going to change much or slow down, each seems to fuel the other in regards to personal computing. There are still niches in the market to be had to help consumers and businesses ease into this new paradigm (there you have it I use paradigm)!

UPDATE – 18/6/13: After a brief twitter exchange with Brian Katz (@bmkatz) and Ian Bray (@appsensetechie) I realised that I conflate the concept of Mobile Device Management, Mobile Application Management and Device Data management into the MDM terminology.

Bruteforce become DOS

May 27th, 2013 No comments

I noticed that I started too get a few emails from Wordfence about invalid login attempts. Now as I have both wordfence and Google two factor authentication happening I wasn’t worried, though I thought I’d do a large IP range block just to cut down on the noise.

 blocked login
What I found was that my provider was being really awesome in their pro-activeness and started automatically detecting brute force attacks on WordPress sites and removing the login.php
As I stated above I have both Wordfence installed, this will automatically block users and IP addresses that have attempted too many times to log in to a site. But what I also have is Google 2 Factor authentication set up as well, stopping these clowns.
 2FA
So whilst my provider was doing an awesome job preventing those-bad-guys™ from getting to my site, they in essence have locked me out too. Hats off to the support team for pulling this together. But the next stage really needs to include, not only scanning for the fact I run wordpress to block attacks, but scan for plugins too. Or even better, allow me to opt out..

Being an Architect

February 24th, 2013 No comments

crossroads

It has been some time since I felt inspired enough to put fingers to keyboard and create a new post. That changed when a friend of mine, recently released his Architects Manifesto in which he summarises his 10 points for delivering good Architecture.

Architect Manifesto:

  1. Provide true value-add to clients. Just adding value is no longer enough
  2. Commit yourself to being an architect and technologist, rather than acting like a ‘techie’
  3. Solve client business challenges instead of simply fixing technical problems
  4. Architect compelling and cost effective solutions that close business
  5. .Ensure client satisfaction instead of focusing on increasing customer satisfaction scores
  6. Don’t just build solutions with cool technologies; focus on building profitable solutions
  7. Maintain leverage and objectivity when working with vendors and partners.
  8. Create intellectual property and sustainable competitive differentiation. Do it!
  9. Know the competition; understand their value proposition, and solution to win.
  10. Deliver real innovation to clients. Simply being innovative doesn’t cut it anymore.

Whilst I pretty much agree with this call to action as it stands, I thought I’d delve into the points myself and add my own perspective, as there is a little repetition in there. Each one of these I could probably write enough material to fill a book, a wildly disjointed book that is. Instead I’ve put together my high level view on each point.

1 Provide true value-add to clients. Just adding value is no longer enough

We live in a day and age where marketing hype is designed to make us believe that because a product or service exists, we need it.

Value, as we all know, is a relative statement. In order to provide something of actual value you need to know your audience. As cliched as it sounds, what keeps them up at night, goes a long way to understanding what they care about. If you can address those cares you can show true value.

2 Commit yourself to being an architect and technologist, rather than acting like a ‘techie’

An Architect is someone that “works with stakeholders, both leadership and subject matter experts, to build a holistic view of the organization’s strategy, processes, information, and information technology assets.”  and a Technologist is someone that uses technology to solve practical problems. Being an Architect and a Technologist is taking that holistic view and applying technology, and services, to solve business challenges.

Contrast these to a “techie” who is looking at the shiny and the cool features and functions that exist, doing stuff with them because you can, not because you need to.

3 Solve client business challenges instead of simply fixing technical problems

As covered in the last point, in our role as Architects our job is to look at how to fix business challenges (or problems) with technology. But to fix the problem we need to know what the problem is. this too goes back to the first point, know your audience.

This is vastly different than looking at technical issues and working out how to make it better. It doesn’t require you to know much about your audience at all. This is also why this is the easy way out for most.

Most of the time what comes to us is a technical problem, or an abstracted view of what the real issue is. The trick is to ferret out the underlying business challenge that needs to be addressed.

4 Architect compelling and cost effective solutions that close business

Before you cry out “what has closing business got to do with it?” think about what happens when there are no more projects. Very soon there will be a whole lot of people without a job, including you!

If you are pulling together solutions that solve actual business challenges with technology or services that are of actual value, chances are you are 90% of the way there. When you look at delivering the solution in the most cost effective manner you are home and hosed.

Cost effective can me a lot of things, but put simply, how can you resolve the challenge in front of you in the cheapest way. Can the solution be only 85% of what people want? Can you deliver it a different way? Is there a smarter way to cut the financials to make it more viable? You won’t know until you look.

5 Ensure client satisfaction instead of focusing on increasing customer satisfaction scores

When you take in the full picture of what it is you are trying to address, looking at all the stakeholders for the specific business concern, the more you work an understanding your audience, or customer, the more focused and tailored your solutions will be. This in turn will ensure satisfaction.

6 Don’t just build solutions with cool technologies; focus on building profitable solutions

This goes back to point number 2. Often as ex-techies we Architects love us some cool tech. If you have been keeping the previous rules 1 through 5 you should be in good standing. For me where this comes into play is if, when building your solution, you don’t reach back into the standard kit-bag you possess as a business to deliver what is needed.

If you reach for that latest and greatest bit of tech BEFORE you have a look at what you already have access to that is good enough you are potentially going to have something that is more expensive to build and run. That said, sometimes the new thing is cheaper and does a better job.

I look at this with my outsourcing Enterprise Architect hat on and how I know that for the most part customers are looking for cost effective solutions. When you bring in the new and unknown, you introduce risk. Risk equates to money and whilst you can  estimate what this might be, there will be a lot you don’t know. At best you bake in a risk contingency to your cost, worst case you end up getting caught out doing a large amount or remediation work at your own expense. This kills profitability and the financial viability of the solution as a whole.

7 Maintain leverage and objectivity when working with vendors and partners.

The one thing to remember when working with vendors and partners is that they want to maximise their

components of the solution you are pulling together. If you are looking after rules 1 through 6, when you get here you won’t have much in the way of issue as you will have a clear view on what the business concern you are addressing is, what specific bits of technology you need to address it and the value of your solution to the business.

Remember, you are only bringing in a partner or a vendor because there is something specific you need.

8 Create intellectual property and sustainable competitive differentiation. Do it!

This is a hard one. Many times we as Architects reach into the kit and and find that there isn’t the tool or appropriate building block available, so we create something new to fill the gap.

My thoughts on this is that if you work on the other 9 points, and do it well, this will fall out the bottom quite nicely, however, the trick here is to understand what it is you have done. Rarely will you be immediately aware of this yourself and this is where I find having a team to support you comes into play.

Whilst your head is down developing solutions that meet points 1 – 7 and 9 – 10, you won’t necessarily know what gold you have produced. In the peer (critical) review of your work, this will come to light. It will be honed and the nugget you have at the end needs to be understood and passed on. So many times I see Architects re-inventing the wheel where there was work that could have, should have, been  built on top of.

9 Know the competition; understand their value proposition, and solution to win.

You spend months pulling together that perfect solution and writing up the value proposition, only to find you’ve been pipped at the post by someone else.

Now there is nothing wrong with having a component of a solution that is a “me too”  offering, but you need to understand why yours a) has value and b) has unique value to that of the competition.

If you don’t take time out to understand what else is out there, what is in their bag of tricks (solution building blocks) and how they position their unique value, you will be doomed to failure, because I can guarantee you that they are making sure that they know yours.

10 Deliver real innovation to clients. Simply being innovative doesn’t cut it anymore.

To me this is calling something “innovation” when it is not. Building something that is looking for a problem is not really innovation, neither is an incremental improvement on what went before.
Innovation is the development of new values through solutions that meet new needs, inarticulate needs, or old customer and market needs in value adding new ways. Nuff said!

Summary

So my summarised, or condensed version of this would be:
  1. Focus on the underlying business concern that is driving your engagement.
  2. Understand your stakeholders concerns in order to deliver value
  3. Build a cost effective solution that addresses their concern
You do these things, you are going to see some success.

Categories: Technology Tags: , ,

Are passwords the new security theatre?

September 10th, 2012 2 comments
Offline Password

Offline password by binaryCoco available at “http://www.flickr.com/photos/binarycoco/2704267877/”

As you may have noticed there have been a lot of website and business breaches in the last 3-4 months where usernames, passwords and occasionally some personal information has been taken. You can see a consolidated, and up to date list here at liquidmatrix.org. Given that passwords are so easily “lost” these days, are they doing much more than security theatre?

This has been an ongoing topic of discussion for several years inside the info-sec community and I thought I’d get my current thoughts out on the subject as it seems to be coming to a head again.

It is becoming generally accepted that users cannot be trusted/expected to look after their credentials and more and more businesses are looking at offering additional ways in which to secure user accounts beyond the humble password.

Background

A bit of Background, the issue is really comprised of 2 parts, the businesses supplying their services and the people that use these services.

Part of the problems is that the businesses breached don’t always take the appropriate care when managing credentials, these are stored in plain text (readable by anyone) or in a poorly encrypted form (that allows the passwords to be cracked or reversed).

This is not always something that is malicious and there can be any number of reasons why this happens. For example, the people building these websites are web developers and not security people, they don’t necessarily know that the standard library or function that they call when building a web application is 10 years old, calls a deprecated function/hashing algorithm and doesn’t do what is required in this day and age.

A more pessimistic take is that you can see, historically, businesses that have been caught out by these breaches in the past don’t always take a hit financially (unless it leads to privacy violations and they are fined or sued) and weigh up the cost of doing things right vs. the likelihood of something going wrong and having to pay compensation. This attitude is definitely changing, as be described. More and more businesses are beginning to offer alternatives.

The other factor in this is that users tend to reuse their passwords across multiple sites. Users tend to do this for any number of reasons, mostly because it is convenient to only have to remember a small set of credentials to get around work and social media sites.

This too is understandable as most people don’t realise that once there is a breach, and your credentials are leaked, people (hackers or script kiddies) will automatically try them against other popular sites or even your place of work (as apparently one Dropbox employee found out).

What’s the hoopla anyway?

Those that say, yeah great for clear text passwords, but mine is/was encrypted, how does that cause an issue? For a great overview of the problem with password breaches and cracking, head over to Ars Technia. The summary of the article, however, is that with the cracking tools available today, each breach feeds the beast and makes it easier to crack each time there is another breach.

The other issue today is that Microsoft (live), Facebook, Google, and Yahoo!, to name a few, offer the ability to provide federated authentication services through OpenID, SAML, OAuth or similar services.

This means that you can use your credentials, username and password, for one of these systems to authenticate (verify you are who you say you are) to another completely separate system that then authorises (provides permissions to do things based on who you authenticated as) you. So if your Facebook account is compromised and you use it to login to any other account with your credentials that you have linked to Facebook.

People also tend to cascade the linking of their accounts so that when you’ve forgotten your password you have Facebook , Twitter or Apple  email your Gmail account with the password reset token, allowing the compromise of one account open up the possibility of access to a lot more.

Whilst you can point the finger and blame the companies that were breached, your username and password, and the management of them, are ultimately your responsibility.

What can you do?

Given that this looks like the sky is falling and that every password leaked means that it becomes easier and easier to get into systems, what can you do? You can invest in a password generation and management tool or look at 2 factor authentication methods offered by vendors.

Password Management

The first thing you can do is start using a password generation tool like LastPass or 1Password. Most of the tools out there have the ability to generate passwords given a number of different parameters like whether it is pronounceable, includes numbers, capitalisations, hyphens, etc (see the example below of 1Password browser plugin for password generation).

Couple this with a tool that remembers your passwords and you now have the ability to generate new and unique passwords for each and every application and website you can think of.

Most of these applications have browser plugins too that automate the entire process so there isn’t even the need to do more than follow the prompts.

Passwords – becoming too hard

Given that all of this is very complicated and relies heavily on you to do the work, more and more businesses are realising that trusting their user base to create unique passwords is not necessarily the best thing and offer a number of additional mechanisms to assist in the protection of themselves and the authentication of their users.

This second factor authentication mechanism is something that you should always take advantage of.

 

2-Factor authentication

What is 2-Factor authentication? Two factor authentication takes the something you know (your password) and then adds in either something you have (like a security token) or something you are (biometrics).

The “something you have” can be any number of things:

  • Digital certificate;
  • Smart card (generally stores a digital certificate);
  • Physical Token (generates a one time password or pin on a screen of a device);
  • Soft token (generates a one time password or pin via an application); or
  • SMS (short message service) one time password or pin.

The something you are is exactly that, something that is uniquely you:

  • Fingerprint;
  • Retina scan;
  • Palm print;
  •  etc.

This second factor when coupled with your password makes it a lot harder for your account and personal information to be compromised should one or the other components be lost.

Most financial organisations offer a number of options for 2 factor authentication. The most common of these are SMS based one time passwords for transactions. Others opt to provide their customers with physical tokens that generate one time passwords.

Other organisations have started offering 2-factor authentication methods for their users -

Google offers both SMS and soft tokens for unauthenticated devices or services across their services like Reader, Gmail, etc.- http://googleblog.blogspot.com.au/2011/02/advanced-sign-in-security-for-your.htm

Dropbox have just added soft tokens for previously unauthenticated devices - https://blog.dropbox.com/index.php/another-layer-of-security-for-your-dropbox-account/

WordPress are now offering Vasco tokens - http://www.scmagazine.com.au/News/313736,wordpress-adds-vasco-one-time-password-technology.aspx and support for the Google Authenticator application –  http://wordpress.org/extend/plugins/google-authenticator

Facebook  now supporting SMS based tokens for unauthenticated devices- http://www.facebook.com/note.php?note_id=10150172618258920

The above list is certainly not exhaustive, but shows that there is now a move away from the old Username and Password as the way in which to authenticate a person.

 

What should I do?

The short answer to this is as follows:

  • Never reuse passwords. Ever;
  • Be aware of the risks in linking accounts to each other;
  • Use a password manager; and
  • Take advantage of 2-factor authentication.

Following these 4 simple things won’t guarantee that you and your accounts will not be compromised, but it will guarantee that the damage will be mitigated.

Been a bit quiet

August 24th, 2012 No comments

I realise that things have been a bit quiet here. As I do from time to time, I have my head down working on things; addressing the bits in life that are important. I read a post by Rich Mogul of Securosis on his priorities in life at the moment and have an almost identical one. Between flying around the country and doing my day job I’ve been silly enough to pick up some additional vocational education and this is taking up my spare time. My version of the priority list looks a little like:

  1. Family
  2. Fitness
  3. Work
  4. Study
  5. Everything else in my life

During the rare moments of down time I have I’ve managed to get several bit posts put together and hope to start to flesh these out in the coming months.

Sometimes I wonder if I bite off more than I can chew to see if I’ll break.

Categories: Technology Tags: