Monday, September 19, 2022

Rise of the Help Desk - 70s through 90s

 I would always tell my students that the best kind of training they can get is by working at an IT help desk.  Most of us have bad memories from interacting with a Help Desk.  I understand that because Customer Resource Managers (CRM)   otherwise known as "press 1 for ... "  are universally disdained.

I first encountered a small Help Desk at Penn State, where visionaries such as Bill Verity were hired as systems analysts to help faculty and graduate students use the computing resources on the IBM mainframes. Those old guard, Bill, Dan Bernitt, Chet Smith and others, came from various disciplines. It was a time full of potential.

When I worked at Pitts Comp Center from 76 to 83, the latter part of that as a manager. They were also mainframe based and everyone had to put in 1 or 2 days a week at the User Consultant desk at Old Engineering Hall on the Oaklland campus.  Those were fun times as I would get a sausage dog at the Original.  I spent a lot of my youth on Oakland.

The Help Desk was an amazing training ground. One had to be aware of a broad range of things, not only programming.

Saturday, September 17, 2022

What do you do if there is widespread cyber-warfare?

 In 2015, Dr Pete Forster and I developed a class for the MS Program in Homeland Security tentatively named SRA-404.  It was focused on cyber-espionage and cyber-warfare.  It was one of the first classes of its kind.  Peter is an expert on the political and espionage scene. My expertise was in the technology of cyber crime, espionage and warfare.

One of the bigger things, IMHO, to come out of the class was an exercise on what to do if this happens or how to prepare. In this posting I present the suggestions. I cannot say they are complete. A lot depends on specifics.

Direct attacks.

By these I mean worms, viruses, and such. They could conceivably be deployed for activation later.  Mainly we are talking about home and small-business systems. Of course you have good anti-virus and firewall protection. Make sure you have backups stored on a non-electronic media - such as CD or DVD. A low nuke could put off an EMP and potentially fry solid-state or magtape backups.  If you have access to a safe or faraday cage use it for your backups.  I bought a home safe and a home UPS for under $200. I also have multiple backups on CD and DVD (also SSD ) all of which goes in the safe with my pistols.

Attacks on servers and networks

I would create a doc with all of your PWs and IDs on it and print that a few times.  Also maybe encrypt it and put it somewhere on the cloud.  Having encrypted docs on the cloud is great if you know what you ae doing.  I will post more about that later.

Do not expect that any of your online services will be working under a cyberattack.  Therefore have a backup plan for paying bills, etc.  In the old days we used to write checks. I would also keep about 2K in cash (20s) just in case. Should hold you over for a week or more.

Now the bad stuff. I learned a lot living in a Hurricane zone.  Prepare as if a disaster were coming. Esp your meds, water, canned food, peanut butter, etc. In PA we had the occasional blackout during a blizzard. We used a wood stove to stay warm.

I am not suggesting becoming a survivalist, but the potential for damage from a cyberattack is too great to ignore. And BTW, a cyberattack can come from the Sun as well. More on that later.

Friday, September 16, 2022

Relauching the Blog

 Hi Yinz'all,

I am gonna try re-launching my blog, but as a slight twist from the traditional science/ security blog.

Yeah, it will have some of that. It will also have some of the memories of a city kid who followed his dreams and became a scientist.

but I refer you to the following:

Apple Steve Jobs Heres To The Crazy Ones - YouTube

The stories I tell will be mostly true, as true as I can remember them. But I will NOT say anything bad about anyone. Not my place. Watch for a few posts each week.

gerry


Sunday, October 20, 2019

Perils of Social Networking

Many of us use social networking sites. Facebook, Linkedin, Instagram and more. Often fun sites, also great way to stay in touch with friends and family.

But of course there is a downside. These sites are a treasure trove of information about legitimate users. Their backgrounds, politics, interests, and even passwords.  As a result it is no surprise that big money is being put into ways this information can be stolen.

This is an article from ThreatPost about the threat. They claim that almost half of all social media logins are fraudulent. Automated attacks (bots) are the most popular form of attack.

https://threatpost.com/half-social-media-logins-fraud/147688/


Monday, October 14, 2019

Quantum entanglement and what it could mean to Cybersecurity

Chinese scientists have succeeded in sending a photon to a device in Earth orbit. The big deal is that they used quantum entanglement, what Einstein called 'spooky motion at a distance' to do it.

Entanglement is a cool property of the universe in which two 'objects' (a photon is an object) can be linked in such a way that a change in one results in a change in the other, regardless of how far they are separated. What is spooky about this is that there is no media. The change simply happens!

What is actually teleported is 'quantum information' - and this is where cybersecurity comes in.  One of the more common attacks is the 'man-in-the-middle' attack, where an attacker is able to eavesdrop on a communication. If full control of quantum entanglement can be achieved, there will be no 'middle' to attack.

However, much still needs to be understood. It is still not clear whether the change happens immediately, or somehow propagates with the speed of light.  An experiment called Bell's Inequality tries to solve this but the matter is still being debated. So far there is no evidence that the speed of light is violated. But the possibility exists. If there is no 'between' the issue of speed could become mute.

https://time.com/4854718/quantum-entanglement-teleport-space/?fbclid=IwAR3RCF7AGy-wo9qP4Lo_u2CQStO25XJEnPCVdfwI9DX2WFkqCiYwLTXpgwI

Thursday, October 10, 2019

The Cyber-Threat to Universities

This is an article from the National Cyber-Security Center in the UK.  It specifically addresses the threat of cyber-espionage to universities and colleges in the UK. However, everything in this article also applies to the US.

I started work at Pitts Computer Center in 1977, and later went to the Penn State Information Technology Services in 1983. The emphasis was always on capability and accessibility. Security, if ever considered, was really an after thought.

This all changed as networks were introduced. Security measures had to be applied, especially at the network level. However, faculty balked at this. How dare the IT staff take away their complete and total control? I became the poster-boy for least-privilege access among the faculty to show that it would not negatively affect our work.

Two-factor authentication has been slowly adopted by many academic institutions, and is one way that  they are starting to address this issue. Read on to learn more.


https://www.ncsc.gov.uk/report/the-cyber-threat-to-universities


Tuesday, May 9, 2017

Are security questions secure?

Many online sites have a mechanism where a user who has forgotten a password can get a new password by answering one or more 'secret' questions.  In some cases these questions may be used as a second authentication factor.

The questions tend to be of the form "what was the name of your first pet," or "what is the name of your first grade teacher."  They are intended to be personal but also easy to remember.

The problem with this is that it may be possible to learn enough about a person using open source intelligence tools to answer these questions correctly.  In 2008, VP Candidate Sarah Palin had her Yahoo e-mail account hacked by a young man who correctly answered security questions about her birth date and where she first met her husband.

Even worse, a researcher at the University of Washington has pointed out that popular surveys encountered on social media could provide enough information to compromise these questions.  For example, consider the currently popular survey in which a person lists 10 concerts, 9 of which they have actually attended.  The game is to figure out which of the 10 they have not attended.

Although this seems harmless, and in most cases is harmless, it is possible to develop a profile of the users age, culture and interests from these surveys.  The general advice is that "secrets make bad passwords when those secrets can be discovered or guessed."

So what can you do?  In many cases the secret questions are required.  My advice is simple, answer the questions but lie, and remember the lie.  It helps if you have a basic scenario, such as Star Trek, to use in constructing your lies.  For example - "What was the name of your first pet?"  Answer: "Tribble."   "What was the name of your High School?"  Answer: "Starfleet Academy."

If you have a scenario in mind (Star Trek, Harry Potter, Lord of the Rings, etc.) it will be easier to construct lies that can be remembered.  Just make sure the scenario cannot be easily determined from your online presence.