Because I'm all about the "good enough."

Thursday, February 21, 2013

Pack all the things!!

It's almost RSA time. I haven't figured out yet how many pallets of business cards to bring along, but I have got my two dozen Band-Aids and blister cream, three pairs of shoes, and two backup power supplies. So I'm pretty well set.

I'm looking forward to spending at least some of Sunday at B-Sides San Francisco, where there are some cool talks such as "Sorry Your Princess is in Another Castle: Intrusion Deception to Protect the Web" by Kyle Adams, and "My First Incident Response Team: DFIR for Beginners" by Chort (I feel as though the latter one should come with a picture book and a juice box).

I missed TongaCon last year, and I simply can't do that any more; if @Gillis57 is going to rickroll the Tonga Room again, I need to be there to lend a hand.

On Monday I'll be moderating two panels at the AGC Partners' 9th Annual West Coast Emerging Growth Conference (and that's the only time I'll try to type that again or say it out loud for the week). "New Frontiers in Endpoint Security" and "Taking the Fight to the Adversary: Threat Intelligence in 2013" are both going to be fun -- not just because there are going to be great panelists from many companies, but also because there have been some recent headlines that fit very well with both topics.

Tuesday is our company's breakfast event, and it's another chance to catch up with a lot of people I missed seeing last year. Wednesday morning is my panel with esteemed colleague Daniel Kennedy, "Psychographics of the CISO," also starring two actual live rockstar CISO types. And it'll be great to see the crowd at the Security Bloggers' Meetup in the evening. Rumor also has it that the Girls of Misogyny Networks will be in evidence somewhere on the RSA exhibit floor.

Friday is my talk with Andy Ellis (@csoandy) on "Living Below the Security Poverty Line: Coping Mechanisms," and I'm happy to be able to present this topic in front of an important audience.

And the rest of the time? Well, my Outlook calendar view for the week currently says "66 items."


See you there.

Tuesday, February 19, 2013

Exercises left to the reader.

The Mandiant report on the threat group it calls APT1 has made a big splash, and deservedly so: the combination of juicy details and actual data such as IOCs (indicators of compromise) is another example of groundbreaking data-sharing around security breaches. Of course, the other side to the publication is its assertion that APT1 is Chinese in origin, and most likely a part of the Chinese government; this is going to provoke a lot of heated discussion.

I've seen some responses already from skeptics, casting doubt on the report's conclusions based on the fact that it didn't include any alternative conclusions other than two that pointed at China (operating either officially or unofficially). Before I get into my own opinion on it, I'd just like to throw out some considerations.

First of all, read the report in its entirety. The authors spent a lot of time connecting every dot they listed, with the proper amount of hedging words in place. Like other high-data reports such as the Verizon DBIR, this one included alternative explanations and caveats in many places. Follow the chain of logic and look at all the data presented before you start to poke holes in it.

Now let's think about some of the assumptions, either implicit or explicit, in the report's assertions. We can call out some alternatives, whether they're realistically possible or not. In no particular order:

Because of the scale of its operations, APT1 must be centrally organized and funded. 
Alternatives: it could be organized, but not from within China; it could be loosely affiliated without being centrally so; it could be using individually contributed resources.

Only the Chinese government has the resources for such an operation.
Alternatives: a very large company or extremely wealthy individual could provide the necessary resources; a different government could be providing them.

An operation that large in scale could not go unnoticed by the Chinese government; therefore it would be operating at least with approval, if not support.
Alternatives: it could be an operation outside of China, faking very large amounts of China-based IP blocks, domain registrations, and other indicators of origin (such as phone numbers); the Chinese government might not know about it, might be unable to stop it, or might simply not care to.

Bad English speakers that use simplified Chinese keyboard layout settings must be native Chinese speakers.
Alternatives: the APT1 group is very good at planting false flags using Chinese speakers (native or not) and using bad English.

Because the three revealed personas appear to be working together and sharing resources in the same geographic location, they must be working for 61398.
Alternatives: they could simply be three people in a social group or other organization that is also located in the region, or is using the same false flags.

Because this linked activity has been going on for so many years (with domain registrations starting as early as 2004), it must be using the same people, the same resources and be supported by the same central organization.
Alternatives: it could be the same people over time, but not affiliated with the same organization; it could be different individuals who "take the reins" and continue the same general activity.

Because APT1 is attacking industries listed in China's strategic five-year-plan, it must be furthering China's goals.
Alternatives: those industries could be on the strategic lists of a lot of countries, and the match with China could be a coincidence.

These are just the ones coming off the top of my head. Now, let's take a step back:

Would any one of these alternatives, if it proved to be correct, torpedo all the other assumptions? Or would a large number of all the alternatives have to be correct, and fit all the available evidence?

In other words, how probable do these alternatives need to be in order to supplant all these assumptions?

(This is my amateur version of an ACH, because I am not in that line of work.)

Now, bear in mind that the evidence laid out in the report may not be all the evidence; it might just be the parts that Mandiant feels are safe to disclose. So the evidence may be even more compelling than we know. Working with what we're given, it appears to me that unless you assume a large-scale conspiracy or an equally well-resourced organization that can fake being sourced in China extremely well (without the knowledge or cooperation of the Chinese government), the preponderance of the evidence points most simply to Mandiant's conclusion. To put it another way, an alternative conclusion would have to be supported by a larger number of less probable, more complicated scenarios that would all have to fit themselves to the facts even better than the China theory does.

It could be that the evidence in the report is either partially or wholly incorrect, or there's a bunch of evidence that contradicts it (and supports the alternative conclusions) that we just don't see. What other evidence would need to show up to do the trick? And how probable is that?

So it's kind of like insisting that the Moon landing was faked -- it would require a perfect conspiracy of silence from hundreds of people over decades, and more sophisticated special effects technology than we know to be available at the time. Sure, you could come up with an alternative conclusion that fits the same evidence, but you'd have to work a lot harder at it.

Would you rather believe that there's an extremely clever and powerful organization out there that is managing to look over years as though it's sourced in China -- without making any mistakes to give it away -- and that the Chinese government can't do anything about? Or would you rather believe that there's a long-term, Chinese government-approved hacking group that isn't perfect and has left quite a few clues behind?

There will never be an airtight case one way or the other, but these things aren't binary. From what Mandiant has presented, the simplest explanation is the one it's offering. It's politically explosive, of course, and that's why belief comes into play. But if you have to do more work to deny something than to accept it, you might want to reconsider your chain of logic.









Saturday, February 9, 2013

All up in your bitness.

We knew it would happen: another security vendor gets hit: this time Bit9, which was admirably quick to disclose after it got in touch with its affected customers (and that's the order it should have happened in, folks). We also knew this would follow: the piling-on (I think Bromium wins the ambulance-chasing award this time around). Which is only fair, in that everyone is tempted to pile on every time there's a failure that is linked to a competitor.

But there's a big gap between those who are all pointing and laughing and those who sympathize. It falls along very clear lines: those who have spent time in defense and those who only know offense; those who enjoy pointing out flaws and claiming to have the answers, and those who have had to clean up after the proof that there are no complete answers.

Guess what? If your "solution" needs to be 100% implemented to be successful, then it's never going to solve the problem. Because in the real world, there's no such thing as 100%.

Security is an unrelenting business, one that you can never prove is done adequately. You'll never be finished, and you can never know if you can even take a break. And it's never fully appreciated by the people who make a living based on that reality: the vulnerability finders and the "solution" providers.

You may walk into an enterprise as a consultant, and you may be focused on addressing one particular problem (let's say, implementing monitoring). You may just assess the current situation, prescribe some controls, wish the customer luck, and be on your way to the next gig. Or you might even stick around to see that one project to its "completion" -- in which case, you'll be there for months or years. But unless you spend a year in the captain's chair, trying to cover every possible contingency with fallible humans, limited budget and "helpful" researchers coming up with new ways that your systems are attackable, you don't understand a thing about real defense.

If you are playing just one position, you don't understand the whole game.

Defense is frustrating; it's boring; it's tedious. It's not sexy when you are sitting in a boardroom with an auditor, or when you are looking at a list of scanner findings and trying to manage the year-long projects to fix them. You need an accountant's attention to detail, the skills of a master social engineer, the diagnostic skills of a doctor, and the patience of a saint. In short, you need to know everything that every possible attacker does, and you need to block all of it, all the time, immediately, using resources that you will never completely control.

So if you're one of the ones scolding a breach victim, you're just displaying your own ignorance of the reality of security in front of those who know better. Think about that for a while, before you're tempted to pile on.




Thursday, January 31, 2013

Training for RSAC.

Yes, I'm getting ready for the RSA Conference next month in San Francisco. RSA is a particularly brutal week for those in my line of work; thus far I'm meeting with 23 vendors, most of them in 30-minute sessions, and that's not counting the time I'll be walking the exhibit hall, trying to meet with more. I have three panels and one talk to give during the week. We won't mention all the vendor events in the evenings, both public and private, the side conferences taking place, or the fun gatherings like the Security Bloggers' Meetup.

In order to get ready for this challenge, I've been doing the following exercises, which you may want to try as well:

  • Walk three miles in heels; drink two cocktails and then walk another mile without spraining an ankle.
  • Stand for two hours in one spot, holding a tiny napkin full of mini-quiches and seared tuna canapés in one hand, a glass of Pinot Noir in the other, and handing out business cards with the other other hand.
  • Go to a public restroom and practice removing stains from the aforementioned wine and canapés from a white shirt.
  • Do wind sprints through a hallway full of high school students to practice the art of the two-minute break between one-on-one meetings.
  • Speed-read through books on calculus, knitting, quantum mechanics, teleology, bread baking, and constitutional law to get ready for reams of vendor brochures and white papers.
  • Practice lip-reading in a dark room by the light of strobes and lasers. 
  • Memorize 80 names per day out of the phone book.
  • Practice listening earnestly to comedian monologues without cracking a smile or giggling.

    and finally ...
  • Go geocaching in Costco to practice finding the one vendor at RSA that is not claiming to do 'big data' or 'analytics.'
 See you there.






Saturday, December 29, 2012

Levelling up in the real world.

Here's a great post from Victor Wong on What They Don't Tell You About Promotions.

All of his points are so, so true -- and I thought I'd add some more from my own experiences and perspective. There are a lot of misconceptions out there about what entitles you to a promotion, so let me get those out of the way first:

What does not get you promoted:
  • Being the oldest person on your team. (Really, some people seem to believe this.) It's not about how old you are; management or senior positions are not about babysitting other people.
  • Being in your position the longest. Your position does not expire after a certain date, and you don't level up just by doing your job.
  • Doing your job the best of everyone else on the team. It's not about how well you do what's expected of you; it's about what you do above and beyond your job description.
  • Needing the money. Sorry, but that is not a sufficient reason for your boss to actually give you more money, much less move you to another position. You have to prove that you're worth it.
  • Working the hardest on your team. Again, it's not about fulfilling your current responsibilities. If you are working much harder than others, your boss might be looking at you and thinking, "This person doesn't know when to stop." Or your boss might decide, "We really need this person to keep the group afloat, so we're not going to change her job." It might even be, "This person has to work harder to do the same job as everyone else -- he's not as competent."
  • Taking a course or two to prepare for your next level. Courses are nice, but there's no guarantee that you can actually execute on what you've learned. You need to prove that you can do the next higher job by actually doing it. Think of a promotion as an acknowledgment of what you've already been doing rather than a change into a brand-new set of responsibilities that you haven't done yet.

Here are some other things that will keep you from getting promoted:
  • Not playing well with others. If you upset people inside or outside the team, it creates extra work for your boss, who has to smooth things over. When you create extra work for your boss, you are totally not getting rewarded for it. 
  • Taking a negative view of things. If you complain about other people, your workload, or talk about customers as if they're idiots, you're not going to level up. Nobody likes a pill.
  • Having no helpful ideas of your own. Your boss wants a problem-solver who can be trusted to do it the right way without creating other problems (see above). Just reporting on problems isn't enough.
  • Not seeing the big picture. If you are thinking only about your current job or your current team, you're not thinking big enough. You need to prove that you can approach things from your boss's perspective (or that of your boss's boss). Even better, you should be coming up with ideas that they haven't (but that they like).
  • Not doing the job your boss wants you to do. You may be the most brilliant person in the world who is going to change the whole industry; you may think you have the right answers (and in some cases that might even be true). But people who haven't managed teams have no idea how annoying it is to have an employee who won't just do his fricking job because he thinks he knows better. If you don't agree with your boss on how to do things, go find another boss. You'll be doing everyone a favor.

And finally, here's one that not a lot of people think about:

Being irreplaceable. Yes, being irreplaceable will keep you from being promoted. If you are so key to operations that you can't take a vacation or sick day without things falling apart, you are not going to get moved to a different position so that things can fall apart full-time. If you are already a manager, your job is to make sure your team has the skills and empowerment to take care of anything that comes up in your absence. A succession plan is vitally important in every organization. Your own boss will feel much better knowing that you have a stable and successful team, and knowing that you're not endangering operations by indulging your ego's need to feel special.

When you are looking out for the welfare of your organization instead of focusing on what you can get for yourself, that's when you'll be given the chance to do more and own more. 


Tuesday, November 20, 2012

Sure, I'll be your unicorn.

I was fascinated to read about the cancellation of the British Ruby conference due to the arguments that the speaker lineup lacked diversity.  Other people have their own opinions on why we have this problem and what we should do about it.  I've spent a lot of my career as a hiring manager, trying to walk the fine line between encouraging diversity and slipping into tokenism; I've also had to be as impartial as possible in selecting conference talks (full disclosure: I'm on the RSA 2013 committee).

As someone who has a chromosome allocation that has traditionally been in short supply in IT, I'm used to being the only one of my kind in the room. If that makes me a unicorn from time to time, there's not much I can do about it, short of leaving the room, and that kind of defeats the purpose of my being there in the first place, which is simply to learn from and contribute to whatever is going on. If I've been exceptionalised, it wasn't such that I could detect it, but I don't know what discussions are ever held behind the scenes.

But here's the thing, the most important thing: What we see every day is what we expect.

Our brains are hardwired that way, so that we spend less processing time trying to re-analyze and make predictions about stuff that we've experienced before. It goes on without our realizing it, and you can sometimes tell it's happening when you find yourself paying more attention to something than you usually do; it means that something is different from what your brain was used to. We expect humans to be walking on two legs, and so we notice anyone we see on crutches or in wheelchairs. We are used to women with hair on their heads, so a woman with visible hair loss receives a lot of attention (as I did in the middle of chemo when I visited my kids' school playground). This is natural.

So if we want to hack our brains, we have to be conscious about it, and put some effort into changing our subconscious expectations of the way things ought to be. This is why I applaud conference organizers such as Chuck Hardy who work on soliciting paper submissions (and more than one B-Sides conference does this too; I've volunteered to be a speaker mentor for London 2013). Reaching out to anyone who is different from yourself -- and helping them along if necessary so that nobody can complain about quality -- is what we need to do to change our experience, and therefore our expectations, of who is seen onstage.

I don't know whether I've ever been invited to speak simply on account of being female, but if it happens, I'm okay with it. Haters gonna hate, and they probably won't change their minds on why I was selected just because I gave a pretty good talk. But at least I have a chance with the rest of the audience: to change their experience regardless of whether I'm a quality presenter (we're all used to seeing bad male speakers, aren't we? Why shouldn't I be allowed the same opportunity to fail?).

So if you want me as your unicorn, I'll take one for the team. If it means opening up the door a little wider in the future for other people who look different, then I still think it's worth doing.



Saturday, August 18, 2012

Pre-rejected CFP submissions.

Here are some of my planned conference submissions that I thankfully abandoned early in the process:

"Increasing Security Awareness Using Wall-to-Wall Counseling"
Most security awareness training is less effective than it could be.  Introducing a physical reminder component boosted our compliance levels up to 450% (but did necessitate a new carpet from time to time). 

"Zero-Day Exploits For CP/M"
There are critical risks to data integrity for every enterprise using WordStar.  Help us get the word out about these frightening vulnerabilities that have been around for DECADES.

"A Meta-Discussion on Meta-Talks at Security Conferences"
A disturbing trend in security conferences is meta-talks that have nothing to do with, like, pwning stuff.  Burnout, sexism, career advice, economics, recruiting, food, exercise and other presentations, usually on what's wrong with the security industry, are replacing actual knowledge transfer involving shell scripts, cookie abuse and lockpicking. Our whole community is in danger of extreme navel-gazing.  This presentation aims to point out the meta-risks of meta-talks.

"On a New Certification For Security Professionals"
We can't possibly take ourselves, or each other, seriously in the security industry without certifications.  The current ones are not fine-grained enough to depict the exquisite subtleties of arcane knowledge that make us so proud to be in this business.  In this presentation, we will propose a new certification model with 25 levels and over 18,000 separate certifications to remedy this granularity problem.  (And all of them start with the letter C!)

"Musical Ports"
After many years of research, we have discovered a new weapon in the battle against intruders:  musical ports, in which services migrate every few seconds to new port numbers so that they can't be found and exploited.  This is done to the system administrator's choice of music (or you can leave it on the default setting, which uses streaming dancehall reggae).  Every so often, when the music stops, one service that can't find an open port is arbitrarily terminated.  The end effect is a much more secure infrastructure.

"The Original Internet Privacy Threat: Your Mom"
You think you can still fight for your privacy?  Privacy is deader than you know.  Your mom built the Internet, punk, and not only has she been monitoring all your activity, she's got Google alerts on you and has a network of other moms planted where you least expect them. She thinks it's really cute how you change pseudonyms every so often, by the way. And since you're reading this, she'd like to remind you to take out the garbage and brush your teeth.

"It's Probably Okay, Don't Worry About It"
Security isn't the problem that people think it is.  Chill, folks.  It's just ones and zeroes.  You're just getting everyone upset with all this bogeyman talk about APTs and insider threats and whatnot.  Relax, open up the firewall to let it breathe, and embrace the Internet.