Posts

A third party view on the security of the Canaries (Guest post by Ollie Whitehouse) tl;dr Thinkst engaged NCC Group to perform a third party assessment of the security of their Canary appliance. The Canaries came out of the assessment well. When compared in a subjective manner to the vast majority of embedded devices and/or security products we have assessed and researched over the last 18 years they were very good. Who is NCC Group and who am I? Firstly, it is prudent to introduce myself and the company I represent. My name is Ollie Whitehouse and I am the Global CTO for NCC Group. My career in cyber spans over 20 years in areas such as applied research, internal product security teams at companies like BlackBerry and, of course, consultancy. NCC Group is a global professional and managed security firm with its headquarters in the UK and offices in the USA, Canada, Netherlands, Denmark, Spain, Singapore and Australia to mention but a few. What were we engaged to do? Quite simply we we...

Sandboxing: a dig into building your security pit

Image
Introduction Sandboxes are a good idea. Whether it's  improving kids’ immune systems , or isolating your apps from the rest of the system, sandboxes just make sense. Despite their obvious benefits, they are still relatively uncommon. We think this is because they are still relatively obscure for most developers and hope this post will fix that. Sandboxes? What’s that? Software sandboxes isolate a process from the rest of the system, constraining the process’ access to the parts of the system that it needs and denying access to everything else. A simple example of this would be opening a PDF in (a modern version of) Adobe Reader. Since Adobe Reader now makes use of a sandbox, the document is opened in a process running in its own constrained world so that it is isolated from the rest of the system. This limits the harm that a malicious document can cause and is one of the reasons why malicious PDFs have  dropped from being the number-1 attack vector seen in the wild as more a...

On anti-patterns for ICT security and international law

(Guest Post by  @marasawr ) Author’s note : international law is hard, and these remarks are extremely simplified. Thinkst recently published a thought piece on the theme of ' A Geneva Convention, for software. '[1] Haroon correctly anticipated that I'd be a wee bit crunchy about this particular 'X for Y' anti-pattern, but probably did not anticipate a serialised account of diplomatic derpitude around information and communications technologies (ICT) in international law over the past twenty years. Apparently there is a need for this, however, because this anti-pattern is getting out of hand. Microsoft President and Chief Legal Officer Brad Smith published early in 2017 on ' The need for a digital Geneva Convention ,' and again in late October on ' What the founding of the Red Cross can teach us about cyber warfare. '[2] In both cases, equivalences are drawn between perturbations in the integrity or availability of digital services, and the circumsta...

A Geneva convention, for Software

The anti-pattern “ X for Y ” is a sketchy way to start any tech think piece, and with “ cyber ” stories guaranteeing eyeballs, you’re already tired of the many horrible articles predicting a “ Digital Pearl Harbour ” or “ cyber Armageddon ”. In this case however, we believe this article’s title fits and are going to run with it. (Ed’s note: So did all the other authors!) The past 10 years have made it clear that the internet, (both the software that both powers it and the software that runs on top of it) are fair game for attackers. The past 5 years have made it clear that nobody has internalized this message as well as the global Intelligence Community. The Snowden leaks pulled back the curtains on massive Five Eyes efforts in this regard, from muted deals with Internet behemoths, to amusing grab-all efforts like grabbing still images from Yahoo webcam chats ( 1 ) . In response to these revelations, a bunch of us predicted a creeping Balkanization of the Internet, as more people becam...