Monday, August 13, 2012

Cloud complications sinking security?

Any solution that claims security, but moves identities and credentials off premise is a security risk.

A wise statement from SecureAuth co-founder Garret Grajek in his blog commentary on the Mat Honan affair. It rang a bell with me based on some research I’ve been doing since last year on this topic:

Why aren’t customers deploying federation for access to cloud services that support federation?

Answers:

  1. Federation is complicated and we don’t have the expertise (or want to get the expertise) to manage it.
  2. We want “one throat to choke” if there’s a problem. “I don’t want to call the cloud provider to have him tell me it is Microsoft’s ADFS and call Microsoft to have them tell me it is the cloud provider or some other piece of my infrastructure.”
  3. Password synchronization is something we already do and are comfortable with. (A variation of #1)

I think Garret’s blog post gives a good overview of why #3 above is an issue. I’ll say it can be especially concerning if it is your Active Directory password that is being synced to multiple cloud properties.

Another bid of good advice:

An enterprise needs to retain the “keys to the kingdom” by (1) Retaining the identities (2) Conducting the authentication (3) Federating the identity and (4) Logging the Access for secure cloud usage.

Couldn’t agree more about giving away the keys to the kingdom! And I know many companies are behind here – especially when it comes to logging & auditing.

Wednesday, August 01, 2012

Will third time be the charm for DropBox?

So it’s the second time that DropBox has been hacked. Lots of coverage about the hack which came to my attention here. I hope everyone remembers the previous hack from last year.

Now DropBox is adding two-factor authentication after the horse has bolted from the barn – twice. Will there be a third hack?

After last year's embarrassing data breaches, Dropbox promised to implement additional safeguards "to prevent this from happening again." Whoops, it just happened again.

DropBox is an excellent product. I use it. I really like it for probably the same reasons you guys do but I continue to be amazed that cloud-based apps don’t come out of the box with two-factor as an included – preferably for free – feature. I mean even supporting something like Symantec’s VIP token would be a plus and not hard to add. (I know, we’ve added it to our Webthority product)

This simply re-enforces two things:

  1. Despite all of the surveys that say people are concerned about cloud security the vendors (aka YOU the product managers at these companies) aren’t listening.
  2. Simplicity, coolness and ease-of-use will continue to trump security. (i.e., People like me who know better are using the product without enhanced security)

Oh, I wonder if the users who were hacked have mentioned to their employers that perhaps some of their data was compromised? Yah, right.

The company also said that one of those stolen passwords was used to access a Dropbox employee’s account, which contained a project document with user email addresses.

Where’s my cloud compliance solution…? Is it possible to prevent this from happening again? What’ll happen if (when?) this happens a third time to DropBox? Does your company have a written policy about the use of cloud-based file sharing solutions? What is the air speed velocity of an unladen swallow? (This last question is to see if: a) you have read this all the way thru; b) you know Monty Python; and, c) you get the fact that cloud security is verging on being a great Monty Python skit)

Tuesday, July 31, 2012

Compliance In The Cloud Era–New Pressures

Interesting article in Information Week going over the results where they surveyed 422 business technology professionals about compliance. Not surprising one of the top technologies identified to aid in compliance was identity management.

ScreenHunter_03 Jul. 31 11.41

The image above – from the article – is interesting. A whole 6% of businesses will use the cloud regardless of compliance concerns. The other 94% of the businesses – according to the graphic – either won’t put data in the cloud that is subject to compliance or need to assure themselves that they’d remain compliant. I hate to be glass “half-empty” but one could read that as 94% of respondents won’t risk the cloud for data subject to compliance.

With all of the hype around privileged account management it is interesting to see that there are nearly no vendors that support PAM for cloud service providers. Also, the same goes for both discovery of data in the cloud that might be subject to compliance regulations (e.g. an Excel spreadsheet with social security numbers in an Office 365 document) and data loss protection (DLP) solutions.

So either a lot of companies (i.e., more than 6% noted in the graphic) are just doing it or they are leveraging private clouds. But, if they are leveraging private clouds they still have issues managing privileged accounts and discovery/DLP.

Yes, the cloud is generating new pressures.

Monday, July 16, 2012

Yahoo’s Unbelievable Lapse

Well, the title in this article says it all and if you’re like me you probably still can’t believe it.

The error that led to the breach of nearly half a million user passwords from Yahoo was so basic, that the security expert who first spotted it didn’t  believe it. “When I first looked at it, I thought it was fake because there’s no way Yahoo would store 450,000 passwords in the clear”

That being said, I’ll remind everyone that Google has a similar faux-pas in 2008. For a quick refresher on that incident check out my blog entry from then: http://jacksonshaw.blogspot.com/2008/09/google-age-and-single-sign-on.html. And, as quoted then:

As an industry we shouldn’t be making the kinds of mistakes we made 15 or 20 years ago.

Well, it seems we’re still making those kind of mistakes. What Yahoo allowed to happen is not only unbelievable but unconscionable. There’s a good article on creating strong passwords but does having a strong password really matter if the password is stored in clear-text on a back-end server somewhere? If some of this doesn’t push us to better use and better integrate two-factor authentication into our lives I am not sure what will.

In the meantime, I’ll go and change my Yahoo password…

Technorati Tags: ,,