Posts

Introducing Consli, easy scheduling and feedback for conference organisers and attendees

The number of security conferences shows no signs of slowing down, feeding an ever-growing appetite for talks, presentations and content . If you're anything like us, both attending and speaking at conferences is part and parcel of your job, even if it's one event per year. In the absence of publication channels available in other disciplines such as good quality journals, security researchers have the option of blog posts, ezines such as Phrack, mailing lists or conferences. Many choose to go to conferences. It's a source of regular wonder that computing/IT conferences are still so heavily paper-based. Your conference pack is typically a sheaf of papers that includes, at a minimum, a schedule and a set of feedback forms. They lead to a few headaches for both attendees and organisers. Larger events have schedules where multiple talks happen in parallel. Planning my conference day involves circling talks I want to see, changing my mind, scratching out talks, circling others....

ThinkstScapes 2013-AH1: On the China report

The Mandiant APT1 report that was released a week ago has been causing some consternation, which makes it a ripe topic for our ThinkstScapes service . This morning, we issued an ad-hoc update to our customers containing our views of the APT1 report. In short, the data is interesting, but does not conclusively point to Unit 61938. There are too many open questions to justify the finger pointing. Take, for example, the markers released for the APT1 group. The report does not contain sufficient data to replicate the grouping of attackers bearing those markers into a single cohesive unit. By Mandiant's own admission the presence of a single marker is insufficient to tag an attacker as APT1, but thresholds are not provided for the number of markers required. In the end, it appears as if the classification boils down to an analyst's opinion, metrics are absent the public report. The entire report is founded on the notion that APT1 exists and is definable; should this not be the case...

Your company's security posture is probably horrible (but it might be OK).

The past few years have provided us with a number of high profile hacks and data breaches. In 2010 Google famously announced that they were hacked and put out details on the compromise (later dubbed the Aurora incident ). In the months that followed, it became clear that google were not the only Aurora victims. Companies in almost every sector from DuPont to Disney were also breached (but were less forthcoming on the details). If these companies, widely lauded as having the brightest minds in their respective spaces were so publicly spanked, an obvious question raises its head? Why wasn't yours? Sadly two of the likeliest answers to this question are equally uncomfortable. a) you haven't been compromised (yet) because people haven't bothered b) your company has been compromised and you just don't know it Brian Snow, former director of Information Assurance for the NSA said it best at a conference in Greece recently: "I’m here to tell you that your cyber systems con...

Introducing.. Signalnoi.se

Image
This post is about 6 months overdue, but we have been busy with a whole bunch of interesting projects (which always manages to dent blogging time.) One of these projects, is http://signalnoi.se We formed Thinkst to work on difficult, interesting problems, and while working on security problems for a well known media organisation, we bumped into (a surprisingly common) problem organisations have: failing to benefit from the available insights afforded by the real-time social media networks. Signalnoi.se managed to win the Knight Fundation's News Challenge in 2012 (which we take as pretty good validation for the idea). If you have 3 minutes, checkout the video on the signalnoi.se page . It still shows version-1 of the interface (we have gotten all fancy since!) but should give you a good overview of the product.

Etsy shows established companies the way..

Image
Fred Wilson over at AVC.com wrote a piece on the Etsy offices (in 2010) titled: " The office matters " In it he explained how " They are getting the best talent in NYC to come to their company " and commented on the importance of paying " attention to the office and the culture " of a company. Around the same time I had written a piece titled " Cargo Cult Startups " in which i posited that too many companies were faking startup culture, keeping draconian productivity-killing rules in place while plastering their offices with beanbags and nerf guns. I still maintain that copying Etsy's office style is not sufficient to inject Etsy-style-startup-magic into a company. But.. I recently came across a job-ad from Etsy which strikes me as completely awesome, start-uppy and yet completely stealable by established companies. ie. I think if a company was going to copy something that could actually help their business, it should be related to the Etsy j...

The lamest hacks

Image
A little while back, a colleague of a colleague approached me with a favour request that was hard to refuse (no, not that kind...) They had one of these external harddrives that supports on-drive encryption and, as you will have guessed, had forgotten the password. No more saved business docs, but also no more saved baby pics. "Could we have a look?", they asked. A brief search online revealed companies who claim to be able to recover passwords for these very drives, but required shipping the drive from South Africa to Europe, and the cost was not instantly dismissible. Surely there was another way? Automating password entry was easy enough; when powered on, the drive's password entry dialog popped up and it was simple to drive the GUI and enter passwords. However, the slight hiccup was that, after five password guesses, the drive needed to be powercycled to reset the guess counter. One of my many failings is a distinct lack of basic electronic experience, and even being...

marco@thinkst.com

Image
In 2009 I wrote a post on recruiting and mentioned " the T-shirt Test ". It read: The T-Shirt test is simply to ask yourself: "how will i feel standing at a conference, with this guy next to me wearing my company T-Shirt". If you don't like the thought, you shouldn't make the hire. I still feel strongly about the T-Shirt test, and feel really strongly about the importance of company culture which makes it crazily cool to officially welcome Marco Slaviero as the newest member of Thinkst. I worked with Marco for several years at SensePost, and we have had some über fruitful collaboration during (and after) that period. I could wax lyrical for a while, but we believe the results will be self evident. Watch this space!