Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, February 20, 2014

I don't think this is what's meant by Silence is Compliance.

I'm sorry you don't like the new security program.  But look at it glass half-full.  It's only a proof of concept.

I saw this on a white board today.  Usually it's a debate-related or argument-related term.  If you don't speak up, the default assumption is you must concur.  Ah, there's even a Wikipedia article related to my understanding of the term from high school speech.  But the context in which I saw it today clearly made it a security-related statement.  E.g. if you don't talk, someone can't go phishing on you, listening for names and details.  So despite the rather 1984 Orwellian nature of the statement, I understand where they're coming from given the number of contractors and sales folks who try to get me to talk in order to find additional names and details they can use to show they know something and know someone, so it must be safe to tell them more.

Snarky: I'm sorry you don't like the new security program.  But look at it glass half-full.  It's only a proof of concept.
Title: I don't think this is what's meant by Silence is Compliance.

Thursday, February 6, 2014

I can't spell?

When our security review asked if we were multi-tenant, why did you answer, "That would be a paradox"?
The important lesson to learn here is not all the faces of the Doctor.  Not that multitenancy can be a concern for your FEDRAMP analysis.  But that the ? goes outside the quotes and no period goes inside the quotes because the most important piece of punctuation wins.  You can show that off in your next work email.


Snarky: When our security review asked if we were multi-tenant, why did you answer, "That would be a paradox"?
Title: I can't spell?

Tuesday, December 10, 2013

I meant, I t'aint checking that.

I know what taint checking is. I just think you're referring to semantic change, not linguistic drift.

I think the only commentary I can possibly give you for this incredibly nerdy bit of humor that spans the domains of programming, security, linguistics, and popular culture is a series of Wikipedia links that breaks out all the relevant bits.  Admittedly, I think Snarky and Poor Paired Cube Guy switch roles a little in this frame, but hey, artistic license.

"When McGee tells a bad joke, Molly often answers with the line "T'aint funny, McGee!" which became a familiar catch phrase during the 1940s." [Wikipedia].

"Taint checking is a feature in some computer programming languages, such as Perl[1] and Ruby,[2] designed to increase security by preventing malicious users from executing commands on a host computer. Taint checks highlight specific security risks primarily associated with web sites which are attacked using techniques such as SQL injection or buffer overflow attack approaches.

The concept behind taint checking is that any variable that can be modified by an outside user (for example a variable set by a field in a web form) poses a potential security risk. If that variable is used in an expression that sets a second variable, that second variable is now also suspicious. The taint checking tool proceeds variable by variable until it has a complete list of all variables which are potentially influenced by outside input. If any of these variables is used to execute dangerous commands (such as direct commands to a SQL database or the host computer operating system), the taint checker warns the program it is using a potentially dangerous tainted variable. The computer programmer can then redesign the program to erect a safe wall around the dangerous input."  [Wikipedia].

"According to Sapir, drift is the unconscious change in natural language." [Wikipedia].

"Semantic change (also semantic shift, semantic progression or semantic drift) is the evolution of word usage — usually to the point that the modern meaning is radically different from the original usage. In diachronic (or historical) linguistics, semantic change is a change in one of the meanings of a word. Every word has a variety of senses and connotations, which can be added, removed, or altered over time, often to the extent that cognates across space and time have very different meanings. The study of semantic change can be seen as part of etymology, onomasiology, semasiology, and semantics." [Wikipedia].




Snarky: I know what taint checking is. I just think you're referring to semantic change, not linguistic drift.
Title: I meant, I t'aint checking that.

Tuesday, July 16, 2013

I'll get my Easter bonnet. I love a good chocolate hunt.

Now that we're taking a  look at that gap, we've found a number of others to address.

I was recently introduced to two more phrases at work I hadn't heard before.

Chocolate Hunt: as in, if we allow them the opportunity to voice an opinion about how they'd like that feature changed, they're going to consider it an invitation to go on a chocolate hunt and change everything.  When I figured out what the individual was talking about, it reminded me of the paranoia about a constitutional convention when I was a kid and there was concern if states allowed a constitutional convention to pass the equal rights amendment, we would end up with a thousand additional amendments related to nonsense.  A constitutional chocolate hunt.  I appreciated the coworker who wanted to avoid a chocolate hunt as it would have fallen disproportionately on development in my opinion.

Chinese Walls: I heard this one today uttered by someone from overseas.  I'm not going to use it as a Snarky because it seems inappropriate.  "In business, a Chinese wall is an information barrier implemented within a firm to separate and isolate persons who make investment decisions from persons who are privy to undisclosed material information which may influence those decisions. This is a way of avoiding conflict of interest problems. In general, all firms are required to develop, implement, and enforce reasonable policies and procedures to safeguard insider information and to ensure that no improper trading occurs. Although specific procedures are not mandated, adopted practices must be formalized in writing and be appropriate and sufficient. Procedures should address the following areas: education of employees, containment of inside information, restriction of transactions, and trading surveillance." [Wikipedia].  I was excited to read that it has software implications, particularly in conflict interest modeling, which is something I'm involved in.  It's also called an ethical wall or ethical screen in some places, which you can read about in Lawtalk, The Unknown Stories Behind Familiar Legal Expressions (I'll have to put that on my library list), partially do to Justice Low in  Peat, Marwick, Mitchell & Co. v. Superior Court 200 Cal.App.3d 272, 293–294, 245 Cal.Rptr. 873, 887–888 (1988).

"The term has an ethnic focus which many would consider a subtle form of linguistic discrimination. Certainly, the continued use of the term would be insensitive to the ethnic identity of the many persons of Chinese descent. Modern courts should not perpetuate the biases which creep into language from outmoded, and more primitive, ways of thought."

I don't often get a history lesson with the colloquialisms uttered in meetings.  It's exciting to learn something new.

Snarky: Now that we're taking a  look at that gap, we've found a number of others to address.
Title: I'll get my Easter bonnet.  I love a good chocolate hunt.

Tuesday, May 7, 2013

As long as I don't have to write a unit test to assert it's true.

They asked me to provide attestation for our security investigation. I think I'll need you to vouch for my character.

I spend a lot of time lately working on SOC 2NIST 800-53, and FedRAMP security digs.  One of the differentiation factors that is often discussed is whether a security dig is prescriptive and bound to extremely specific pieces of evidence that must all be fulfilled, or whether a dig is an attestation, and the rules are not strictly speaking externally determined, but attested to by a company and only those the company attests to fulfilling and providing evidence for matter.  It's amazing that one little idea can make such a huge difference in a dig, although when you pull both versions through the microscope and look at the security control proof through the lens, it looks suspiciously similar when it lands on your desk with a four hour deadline.

Snarky: They asked me to provide attestation for our security investigation. I think I'll need you to vouch for my character.
Title:  As long as I don't have to write a unit test to assert it's true.

Tuesday, January 22, 2013

But we capitalize it! That makes it a corporate standard.

They didn't approve of our concept of Secur

Security through obscurity (or by obscurity) was a new phrase for me the other day and it came up as part of a security audit.  I think the folks using it were joking.  I hope they were joking.
"a principle in security engineering, which attempts to use secrecy of design or implementation to provide security. A system relying on security through obscurity may have theoretical or actual security vulnerabilities, but its owners or designers believe that if the flaws are not known, then attackers will be unlikely to find them." (Wikipedia, link above).
What made it even more tangled than the definition above is that it was implied that they didn't know their own security flaws, or where to find passwords and servers, so if they couldn't, then an outside intruder couldn't.  Which is probably valid for phishing, but not for someone hacking remotely.

It's good to know NIST specifically argues against the practice.

Snarky: They didn't approve of our concept of Security by Obscurity.  Even though we have a layoff process designed to facilitate it.
Title: But we capitalize it!  That makes it a corporate standard.

Wednesday, November 28, 2012

So there's no trust boundary violation when I steal your candy.

Snarky: Why did you write root on my door?


You might have to see security related stick figure comics from me for a while.  Sort of my new gig whenever I get a few minutes of free time between my other work duties.
According to Wikipedia: "Trust boundary is a term in computer science and security used to describe a boundary where program data or execution changes its level of "trust". The term refers to any distinct boundary within which a system trusts all sub-systems (including data). An example of an execution trust boundary would be where an application attains an increased privilege level (such as root). A data trust boundary is a point where data comes from an untrusted source. For example, user input or a network socket.  A "trust boundary violation" refers to a vulnerability where computer software trusts data that has not been validated before crossing a boundary."


Snarky: Why did you write root on my door?
Title: So there's no trust boundary violation when I steal your candy.

Tuesday, November 13, 2012

Just being in your office is damaging my brand.

Staying a few extra hours will not 'damage your brand.'

I've been dealing a lot with application security lately, and one of the reasons touted most often as why to protect your code and your app has to do with preventing damage to your brand.  Good advice.  Most of what I've been reading has to do with the OWASP Top 10.  If you're a .NET developer, and you want to read about Cross Site Scripting, SQL Injection, Insecure Direct Object References, and more, I strongly recommend Troy Hunt's free e-book and, if you feel like a Pluralsight subscription, their class on ASP.NET security, which includes great examples of what a hacker would actually do when implementing the OWASP Top 10 against your site.

Snarky: Staying a few extra hours will not “damage your brand.”
Title: Just being in your office is damaging my brand.