<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IT Security Attaché &#187; Backdoors</title>
	<atom:link href="http://theitsecurityattache.com/blogs/tag/backdoors/feed/" rel="self" type="application/rss+xml" />
	<link>http://theitsecurityattache.com/blogs</link>
	<description>His life, profiles, work, aspirations, agenda and schedule.</description>
	<lastBuildDate>Mon, 26 Jul 2010 22:05:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>IT Security Education and Awareness 04-09 #1 &#8211; IT Security is a people problem, not an industry one</title>
		<link>http://theitsecurityattache.com/blogs/2009/04/06/it-security-education-and-awareness-04-09-1-it-security-is-a-people-problem-not-an-industry-one/</link>
		<comments>http://theitsecurityattache.com/blogs/2009/04/06/it-security-education-and-awareness-04-09-1-it-security-is-a-people-problem-not-an-industry-one/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 02:44:27 +0000</pubDate>
		<dc:creator>Brett A. Scudder</dc:creator>
				<category><![CDATA[My Writings]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[The Attaché]]></category>
		<category><![CDATA[401K]]></category>
		<category><![CDATA[Anti-Malware]]></category>
		<category><![CDATA[Anti-Virus]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[Backdoors]]></category>
		<category><![CDATA[Blended Threats]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Crack Files]]></category>
		<category><![CDATA[Crackers]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[End Users]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Health Insurance]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Keygens]]></category>
		<category><![CDATA[Life Insurance]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Patching]]></category>
		<category><![CDATA[People problem]]></category>
		<category><![CDATA[The IT Security Threats Landscape]]></category>
		<category><![CDATA[TITSTL]]></category>
		<category><![CDATA[TV]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Worms]]></category>

		<guid isPermaLink="false">http://theitsecurityattache.com/blogs/?p=352</guid>
		<description><![CDATA[Good day to you,
 
Every day I talk with people across all vertical markets, business sizes, organizations and cultures about the IT Security issues being faced in our world today and how it impacts our everyday lives, and it is becoming one of those awakening kind of issues for many. Whether they like it or not, [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Good day to you,</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Every day I talk with people across all vertical markets, business sizes, organizations and cultures about the IT Security issues being faced in our world today and how it impacts our everyday lives, and it is becoming one of those awakening kind of issues for many. Whether they like it or not, they know they are affected in one way or another. While most people tend to try and figure out if and where they fit into this Matrix, the recent mass media explosion of the Conficker worm created somewhat of a sense of understanding as many now saw it from a non technical aspect and as what it really is, a people problem.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">As a security attaché, I have relayed this message of IT Security being a people problem and not an industry one for years but it doesn’t resonate well for many because they didn’t understand the matrix and how it worked. Now that they saw and heard of it on the TV (which is an even bigger influencer on people today), the same things we IT people have been trying to tell them now makes some kind of sense. Let us take away the fact that whether the media coverage on the TV was doing much justice or help for the issue(s), it did add a well needed visibility to the scope of the problem and that was very well needed today. It would be nice if we say a segment on the news specific to The IT Security Threats Landscape ~TITSTL~ and issues in and around it. They could bring in some professionals in the field to talk about the issues and what is going on and how people can protect themselves in it. That would be a well needed thing to see at that level today as we are going into this vast technology future of ours which we’re taking head on without looking at the real implications and effects of it.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The logic behind the issue is simple, because your system(s) are up and running and have not been wiped out nor shut down by a threat doesn’t mean it is safe, secure or threat free. In many of my health assessments I have shown the owner my findings of worms, trojans and other blended threats that are sitting on their systems because of lack of proper security solutions to protect them or the improper configuration of the solution being used. The fact that they are there is one thing, what they are doing is something else and both are critical issues to ponder.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">While many will refute this fact, I have seen, worked and handled enough of these cases to state as a fact that many fall into this area of The IT Security Threats Landscape. A resident rootkit, keylogger, worm or whatever the variant may be, is actively working its way through your system and causing some form of data loss/theft or compromising the state of applications, connectivity or system stability that we security professionals deem critical. Here is another way to look at this. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If you went to the doctor for a cough that has been bugging you for a while and he says to you, you have a chest or respiratory infection would you tell him no?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">If he says to you that you need antibiotics and some cold medicine do you tell him no?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Why not?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Because, this is his field of expertise and study and as such he can make this assessment based on his knowledge of the issue and the facts he has from testing you.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Are you a medical person to dispute his statement and will you seek a second opinion from someone else?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The fact that you’re still alive and well (somewhat, depending on how you define well) does not negate the reality of the issue that you are infected with something that is causing some kind of issue/effect on the body resulting in that cough which in our field of IT we would call an early warning. So, this is the same way in which we look at the IT Security issues of today and how people tend not to look at it. They haven’t gotten that early warning of a cough because the system hasn’t picked up on it yet and when it does happen, because they have not fallen and can’t get up this is not a critical issue. The system becoming slow and unresponsive is that early warning and at that stage most people tend to seek professional help depending on the need/use of the system and how critical it may be for business or even personal use.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So here we stand dealing with people who are harvesters of thousands of people’s information and things about them (whether you know or like it) and they rest idle to this decadent behavior and mindset. Yet, unchecked, their systems sit comfortably hosting these blended threats which are sending/stealing critical private, personal, financial data/information to these hackers unbeknownst to them. The careless whisper of ignorance to these issues is the driving force behind the growing success of such threats today. A hacker have so much more to gain from you giving it to them than for them having to go through getting it from you and is why the botnet issue is such a growing one today. The use of keygens, crack files, peer to peer (P2P), unpatched applications and systems makes it so much easier to exploit what is available that one tends to wonder when and where does it end. It ends with user education and awareness on and about the threats landscape and what these issues are. It end when people start taking this seriously and realizes that you’re just as much a victim as anyone anywhere if you’re not protected properly.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you stop saying I have anti-virus protection and so i’m ok when you know you haven’ renewed that subscription over six months ago and so you’re missing all the latest and greatest signature based protection that it should provide. Anti-virus alone CANNOT protect you from the threats out there today, it has to be a layered approach where various solutions are in play to cover the needed layers.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you wake up from this illusion that my OS is more secure than the other and so I don’t have to worry about these security issues.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when we stop underestimating the knowledge of your youths and start educating them much early on the proper use of the internet and the functions and features of it. IT Security must be a part of the school curriculum today as technology is our future for tomorrow and they are our next generation of professionals and leaders.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you start accepting the fact that you are as much a risk to me as I am to you if we’re not practicing basic IT Security best practices.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you stop taking the cheap way out of operating a business when hosting people’s private and confidential information which is priceless to them and they trust you to keep it secure. Have some respect for your customers and let them rest comfortable knowing that you have their best interests at heart in properly protecting your infrastructure.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It ends when you realize that these threats are released in the wild with no specific targets but the system(s) you’re using which unfortunately is in the homes, schools, workplaces and places of general interest. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The treats are not specific to government and their systems. It is not specific to the private or public sectors. It is not specific to the educational institutions and it certainly isn’t targeting the healthcare sector only. All are affected and are in the path of these threats because, they are all sharing the same interconnectivity transport medium, the internet and the internet respects no one and has no boundaries.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">It is time that people take this as a basic part of their lives where one does not get consumed on questioning the validity or severity of the threat but questioning the readiness of themselves and their systems to face them. While our government may understand the real scope of these issues, their efforts to create effective management and policies to protect the country’s infrastructure are missing critical elements, the people and the roles they play in strengthening the protective layers or being a weak link and point of entry/compromise for what is being implemented. Unless we strengthen the people through education and awareness they will always be a weak link in the chain of protection.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When a company is hacked or they lose their data by whatever means there is, who suffers the most, the employees, the end users. The company suffers a data loss or has a breach but the actual data may be your private and confidential information. Even if the company loses its financial data, it has a much better recovery rate through insurance and such than an individual who now suffers from the loss of privacy and here in the US, credit ratings. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Think about the many places that have information about you that you consider to be private and confidential. Your employer has your social security info (and possibly family members who are covered by you), some financial info for direct depositing of your paychecks. Your 401K info. Health and life insurance info.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Your doctor has your private health records and, results. They have your family’s private info as well as some kind of visit may have been had over the years and that info is in the system.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Your bank has all your financial info and records. They may have your mortgage info as well (if you own a home). The car loan and all the info in it. Student loans and the works.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">So think on these things and when you look at all of them, who is most affected in the event of a data loss or breach at any one of those kinds of organizations or businesses, you, the end user, consumer, employee.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">IT Security is a people problem and must be dealt with accordingly. It is not about selling security, it’s about creating greater education and awareness about it so we can all contribute towards upholding the strengths of the protective security layers that are there for our protection.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">Stop asking if this is real, ask yourself, how do I protect myself, my family, my business, my country from these elements and there effects. This is REAL.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">When in doubt, reach out.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">~Brett A. Scudder~</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: &quot;Garamond&quot;,&quot;serif&quot;; color: #000099; font-size: 12pt; mso-bidi-font-size: 11.0pt;">The IT Security Attaché</span></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://theitsecurityattache.com/blogs/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://theitsecurityattache.com/blogs/2009/04/06/it-security-education-and-awareness-04-09-1-it-security-is-a-people-problem-not-an-industry-one/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
