Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Thursday, 21 January 2016

Hacking the Nazis: The secret story of the women who broke Hitler's codes


Of the 10,000-plus staff at the Government Code and Cypher School during World War II, two-thirds were female. Three veteran servicewomen explain what life was like as part of the code-breaking operation during World War II.

"I was given one sentence, 'We are breaking German codes, end of story'."

It was Ruth Bourne's first job out of college, when, like thousands of other young British women during World War II, she was recruited to aid the Allied cipher-breaking efforts at Bletchley Park.

Today, the mansion in the heart of the southeast English countryside is famous for being where the brilliant mathematician Alan Turing cracked the Nazi's Enigma code.

Because Turing's individual achievements were so momentous, it's sometimes forgotten that more than 10,000 other people worked at the Government Code and Cypher School, of whom more than two-thirds were female. These servicewomen played a pivotal role in an operation that decrypted millions of German messages and which is credited with significantly shortening the war.

The vital importance of preempting German plans led to a huge push to create machines that could crack ciphers at superhuman speeds. These efforts produced Colossus, the world's first programmable electronic digital computer.

However, the reality of running these electromechanical machines, setting rotors and plugging boards day in day out, was often less than thrilling, with the 18-year-old Bourne envying the girls who test-piloted aircraft fresh off the production line.

"That was exciting but standing in front of a machine for eight hours was not," she said.

As mundane as her daily routine was, it was vital in deciphering coded messages sent by the German army, navy and air force and helping the Allied forces turn the tide of war.

The problem facing Britain and its allies early in the war was that the Enigma machine used to encrypt Nazi military traffic could scramble a message in 158 million million million ways, and each day the settings used would be changed. On top of that, on an average day at Bletchley Park code-breakers were tasked with breaking between 2,000 and 6,000 messages of German, Italian, Japanese and Chinese origin. There were far too many to check by hand.

The code-breaking needed to be automated, and it fell to British mathematician and father of the computer Alan Turing, with the help of the British Tabulating Machine Company, to devise the machine for the job.

His solution was the bombe, an electromechanical machine designed to emulate the workings of 36 Enigmas.

Bourne was a member of the Women's Royal Naval Service, known as the Wrens, who were charged with preparing the machines each day, turning the drums on the front and plugging up the boards at the back according to settings laid out in a menu. These settings were derived from cribs, which were best guesses at fragments of plain text—for example, standard openings such as weather reports—from the enciphered messages.

If correct, these cribs would reveal some of the Enigma settings used to encode the message and provide a starting point for devising the remaining settings. The bombe could check the possible ways the Enigma could have been set up incredibly rapidly, dismissing incorrect settings one at a time.

If the crib and initial settings were good, then the bombe could return the information needed to crack the code within minutes.

"I joined just around D-Day and at that time the traffic was tremendous. We were breaking thousands of messages," Bourne said.

Tuesday, 4 February 2014

11 Sure Signs You've been Hacked

In today's threatscape, antivirus software provides little piece of mind. In fact, antimalware scanners on the whole are horrifically inaccurate, especially with exploits less than 24 hours old. After all, malicious hackers and malware can change their tactics at will. Swap a few bytes around, and a previously recognized malware program becomes unrecognizable.

To combat this, many antimalware programs monitor program behaviors, often called heuristics, to catch previously unrecognized malware. Other programs use virtualized environments, system monitoring, network traffic detection, and all of the above at once in order to be more accurate. And still they fail us on a regular basis.

Here are 11 sure signs you've been hacked and what to do in the event of compromise. Note that in all cases, the No. 1 recommendation is to completely restore your system to a known good state before proceeding. In the early days, this meant formatting the computer and restoring all programs and data. Today, depending on your operating system, it might simply mean clicking on a Restore button. Either way, a compromised computer can never be fully trusted again. The recovery steps listed in each category below are the recommendations to follow if you don't want to do a full restore -- but again, a full restore is always a better option, risk-wise.

1: Fake antivirus messages
2: Unwanted browser toolbars
3: Redirected Internet searches
4: Frequent random popups
5: Your friends receive fake emails from your email account
6: Your online passwords suddenly change
7: Unexpected software installs
8: Your mouse moves between programs and makes correct selections
9: Your antimalware software, Task Manager, or Registry Editor is disabled and can't be restarted
10: Your bank account is missing money
11: You get calls from stores about nonpayment of shipped goods

Read the full post

Friday, 24 May 2013

10 worst-case BYOD scenarios (and how to prevent them)

Bring Your Own Device has stirred plenty of controversy. Companies are either embracing it to its fullest extent or avoiding it like the plague. BYOD can potentially save you money and help make your employees happier and more productive. But it also brings along with it a number of possible pitfalls, from security to compatibility and everything in between. For the most part, those pitfalls can be avoided with just a little planning and education. “No way,” you say? Let’s look at some likely worst-case scenarios and see how you can prevent them from occurring.

1: Exposed data
2: Passwords in the wild
3: Declining productivity
4: Compatibility issues
5: Bandwidth overuse
6: Device management
7: Wireless bottlenecks
8: Autonomy overuse
9: Virus infections
10: Compatibility complaints

Bring Your Own Drama

It’s coming to an IT department near you. When it does, be prepared for anything and everything. You’re dealing with the teen years of mobile devices and you’re going to have to have tricks up your sleeve you never thought you’d need. But if you’re prepared, and if you’ve prepared your users, that drama will hardly get the chance to rear its ugly head.

Read the full post

Related Articles

10-essential-elements-of-byod-training

10 BYOD mobile device management suites you need to know

Wednesday, 30 January 2013

Top 10 Reasons to Strengthen Information Security with Desktop Virtualization

The tension between security and business productivity has never been so acute. To operate at peak performance and competitiveness, organizations need workers to access enterprise resources in more places and in more ways than ever before—but the resulting proliferation of work locations, types of workers and access methods has pushed traditional security strategies to the breaking point. The consumerization of IT adds further complexity as a diverse mix of laptops, smartphones and tablets enter the environment, including both enterprise-owned devices and those purchased by workers.

While technologies such as firewalls, anti-virus, access control and perimeter monitoring remain an important base, they’re increasingly bypassed, as today’s skilled attackers directly target applications and data. What’s needed is a new security layer—one that makes it possible to manage risk more effectively.

According to Forrester Research Inc. “Proper management and control of user accounts, access permissions, and privileges is one of the most effective avenues to ensuring that data doesn’t walk out the door.” (“Twelve Recommendations For Your 2011 Security Strategy”, Forrester Research Inc. December 2010). Desktop virtualization provides that additional security layer, allowing full freedom for organizations to embrace workshifting and deploy personnel and resources wherever and whenever they’re needed, while fortifying information security and compliance in support of business and IT priorities.

Download

Friday, 19 October 2012

10 Secure Linux Distributions You Need To Know About

With security constantly in the news lately, you can't help but feel ill at ease and vulnerable -- vulnerable to teams of hackers whose only motivations are to expose and attack their victims. Perhaps you think you've done due diligence by keeping your patches updated, installing security fixes, and maintaining a corporate firewall. Those methods are effective about 50 percent of the time. For the other 50 percent, you need to do more. You need penetration testing, security audits, intrusion prevention and intrusion detection, and you need to plug security holes that only hackers know about by using the tools they use to compromise your systems.

Security is expensive no matter how you slice it but it doesn't have to be a death knell for your business. This list of 10, in no particular order, security-enhanced Linux distributions can give you peace of mind by beating hackers on their turf.

Read the full post

Saturday, 29 September 2012

9 Dirty Tricks: Social Engineers' Favorite Pick-Up Lines

What the average guy might call a con is known in the security world as social engineering. Social engineering is the criminal art of scamming a person into doing something or divulging sensitive information. These days, there are thousands of ways for con artists to pull off their tricks (See: Social Engineering: Eight Common Tactics). Here the author Joan Goodchild looks at some of the most common lines these people are using to fool their victims.

Full article

Tuesday, 21 August 2012

10 crazy IT security tricks that actually work

IT security threats are constantly evolving. It's time for IT security pros to get ingenious.

This blog post offers 10 security ideas that have been -- and in many cases still are -- shunned as too offbeat to work but that function quite effectively in helping secure the company's IT assets. The companies employing these methods don't care about arguing or placating the naysayers. They see the results and know these methods work, and they work well.

1: Renaming admins
2: Getting rid of admins
3: Honeypots
4: Using nondefault ports
5: Installing to custom directories
6: Tarpits
7: Network traffic flow analysis
8: Screensavers
9: Disabling Internet browsing on servers
10: Security-minded development

Read the full post

9 popular IT security practices that just don't work

The security products and techniques you rely on most aren't keeping you as secure as you think.

When it comes to IT security, FUD (fear, uncertainty, and doubt) is more than just the tool of overhyping vendors hoping to sell their next big thing. It is the reality that seasoned IT security pros live in, thanks in large part to the -- at times gaping -- shortcomings of traditional approaches to securing IT systems and data.

The truth is most common IT security products and techniques don't work as advertised, leaving us far more exposed to malicious code than we know. That's because traditional IT security takes a whack-a-mole approach to threats, leaving us to catch up with the next wave of innovative malware, most of which rolls out in plain view on the Internet.

1: Your antivirus scanner won't uncover real network killers
2: Your firewalls provide little protection
3: Patching is no panacea
4: End-user education earns an F
5: Password strength won't save you
6: Intrusion detection systems can't determine intent
7: PKI is broken
8: Your appliances are an attacker's dream
9: Sandboxes provide straight line to underlying system

Read this interesting post

Monday, 14 May 2012

CIO challenges: Bringing your iPad to work

The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not yet adapted for corporate use, and CIOs are asking what security policies must be put in place to safeguard network services and company data are these devices proliferate. This white paper describes how these devices can be identified on the network, securely enrolled, and authenticated and authorised on the network Download the whitepaper

Monday, 16 April 2012

10 Immutable Laws of Security

Here at the Microsoft Security Response Center, we investigate thousands of security reports every year. In some cases, we find that a report describes a bona fide security vulnerability resulting from a flaw in one of our products; when this happens, we develop a patch as quickly as possible to correct the error. (See "A Tour of the Microsoft Security Response Center"). In other cases, the reported problems simply result from a mistake someone made in using the product. But many fall in between. They discuss real security problems, but the problems don't result from product flaws. Over the years, we've developed a list of issues like these, that we call the 10 Immutable Laws of Security.

Don't hold your breath waiting for a patch that will protect you from the issues we'll discuss below. It isn't possible for Microsoft—or any software vendor—to "fix" them, because they result from the way computers work. But don't abandon all hope yet—sound judgment is the key to protecting yourself against these issues, and if you keep them in mind, you can significantly improve the security of your systems.

Law #1: If a bad guy can persuade you to run his program on your computer, it's not your computer anymore

Law #2: If a bad guy can alter the operating system on your computer, it's not your computer anymore

Law #3: If a bad guy has unrestricted physical access to your computer, it's not your computer anymore

Law #4: If you allow a bad guy to upload programs to your website, it's not your website any more

Law #5: Weak passwords trump strong security

Law #6: A computer is only as secure as the administrator is trustworthy

Law #7: Encrypted data is only as secure as the decryption key

Law #8: An out of date virus scanner is only marginally better than no virus scanner at all

Law #9: Absolute anonymity isn't practical, in real life or on the Web

Law #10: Technology is not a panacea

Read the full post

Thursday, 14 April 2011

Are you following cloud security standards?

Some best practices from the Cloud Security Alliance on how you can protect your company in the cloud

To help promote information security and good practices related to cloud computing, ISACA joined the CSA (Cloud Security Alliance) (www.cloudsecurityalliance.org)

The CSA document has divided the security guidance into three sections and 13 domains:

Read it

Info leakages — Control and cures

A reasonable approach is to build defence indepth by having multiple, independent layers to protect the information

No, this is not another article on Wikileaks. This is about how to avoid any kind of information leak. The type of information leaks exemplified by Wikileaks is a nightmare for any information security professional.

Read it