Looking further into MA regulation 201 CMR 17.00

Wednesday, October 22nd, 2008

Thanks to MSCPA, I finally tracked down the Governor’s press release which, at first glance, has a reasonably clear description of the regulation’s intent. Also came across an analysis by Beth Israel’s CIO, a positive blurb from a Maine consultancy, and a brief mention by a MA payroll company.

As for me, I still need to do my official audit of our procedures vs. those specified by the regulation.

new Massachusetts personal info requirements

Thursday, September 25th, 2008

Networks Unlimited just sent out a note (thanks!) about the Mass Office of Consumer Affairs’ new
Standards for The Protection of Personal Information of Residents of the Commonwealth, aka 201 CMR 17.00: M.G.L. c. 93H. It outlines the responsibilities of anyone who gathers personal information on Mass residents. At a glance, they look pretty reasonable. From the intro:

Every person that owns, licenses, stores or maintains personal information about a resident of the Commonwealth shall develop, implement, maintain and monitor a comprehensive, written information security program applicable to any records containing such personal information.

It’ll be interesting to sit down with this & see how our policies & procedures match up.

Whoops — my rails app was open to a common vulnerability

Tuesday, September 23rd, 2008

Thanks to Hacker News for bringing this common problem with Rails apps to my attention. Nobody seems to have taken advantage of it on my app, but still, it’s a drag having insecure applications, and a little disappointing that there aren’t more heads-up about this, or a more secure default as Merb apparently has.

Planning soekris project

Wednesday, June 25th, 2008

In the market for a reliable, cheap, low power firewall, and already familiar with OpenBSD & PF, I’ve been eying the Soekris line of products. This project looks like it’ll be just a little more involved than buying something off the shelf, but way more flexible, and have more parts in common with other stuff I’m already using.

From my research, it looks like the necessary pieces are:

So, for about $250 + some shipping, and a bit of fiddling around time, this could be a pretty robust solution. I’m not sure I’d care to work out all the installation and configuration details myself, but there are a couple guides to getting everything up & running. I’ll certainly add my own notes if I go through with this.

Data Connectors Tech-Security Conference

Tuesday, June 24th, 2008

I spent part of last Wednesday at the Boston Tech-Security Conference, held at lovely UMass Boston. Getting me there was a triumph of email marketing by hosts Data Connectors, as I hadn’t heard of this series and couldn’t really find any 3rd party accounts on the web. That, and it was free. Since I’m newly back in a higher-level IT administrative capacity after years of just focusing on web application security, I decided to give the conference a try.

First impressions (after noting how unfriendly the UMass campus is to bicycles) were of an absence of buzz. Many vendors hanging around in one room, and then a vendor representative giving a traditional one-way presentation in the next room. After attending a few barcamps, it really seems to me that a more interactive format would benefit everyone involved. This conference was clearly driven by the vendors, but it seems to me that it’d be in their best interests to learn more about their potential customers’  interests and concerns, rather than broadcasting a sales message.

Despite the one-to-manyness, the presentations I made it to varied quite a bit. A few did a good survey of some aspect of security, and then tied that discussion into the vendor’s offerings right at the end. Others were basically just sales pitches. Guess which kind lost more of the audience?

new concepts to me

NAC - Network Admission Control. Folks will sell you systems that go beyond requiring just a username / password combo to get on a given network, by combining checks on device MAC / IP, allowed hours of operation, and presence and activity of specified software. Packetfence looks like a promising open source NAC.

IPS - Intrusion Prevention System. If I’m understanding correctly, these go beyond IDSes by taking some action such as updating firewall rules when naughtiness is detected. It looks like Snort has been able to do this sort of thing for a while, also PF has some related capabilities.

notable speakers

Ming Fu of Lumension introduced me to the concept of thumbsucking — apparently the new hotness in social engineering attacks is to leave USB drives with said software lying about in parking lots, expecting that some percentage will be picked up & plugged in… nasty! Lumension’s tie-in is that they have a product that allows strictly defined device access controls for windows boxes, so you could set up rules that would prevent employee accounts from mounting any USB devices, and only allow admins to mount USB devices already encrypted with your organization’s key.

Ken Pappas of Top Layer Networks gave a high-level rundown on the overall tech security situation, and managed to do it with not an ounce of sales pitch. Authentic confidence is an excellent marketing tool, and Ken’s got that. His early remarks included a shout-out to the Boston chapter of the possibly shooting-to-kill InfraGard. He then went on to summarize the state of security in ‘08, which is basically: not that great. Incidence rates are going up, the range of attackers is increasing in professionalism and skill at the top end and becoming even less sophisticated (i.e. lower barrier to entry) on the low-end with easily available point-and-click tools for launching mail bombs, etc. Those of us responsible for computers attached to networks definitely need to be budgeting some of our time to keep up with the evolving threats, regardless of whether we’re aware of any particular adversary that’s out to get us or our data.

takeaway

It’s important to get away from the daily stream of projects periodically, to think about things from a higher level. Vendory as this conference was, it did give me that opportunity, and I did re-prioritize my TODO list at the end of the day.

The downside: I hadn’t thought through how many calls & emails I was setting myself up for receiving from the conference vendors. FYI, I am 100% of the time never going to spend money with someone who calls me out of the blue and interrupts whatever I’m working on. Send me an email, and I’ll file it for processing at an appropriate time.

cross another shared host off the list

Friday, February 8th, 2008

Just opened my first support ticket with the shared host Site5, and was shocked to see that every email generated by the process includes my username and password. Granted, these credentials only apply to their helpdesk site, but this is still so fundamentally stupid that I feel completely justified in avoiding them in the future. WTF.