by

Microsoft to Store Data in Germany. Make it Harder for Foreign Authorities. Safe Harbour Lesson #1.

Here’s a way to increase your data protection from US government access: Store it in Germany!

As you probably know, in October 2015 the European Court of Justice declared invalid a "Safe Harbor" agreement between the European Union and the U.S. that allowed Facebook and other firms to transfer data in huge quantities to their servers in the U.S.

The court threw this deal in the bin because it was worried about "mass indiscriminate surveillance and interception" of personal data by the U.S. authorities.

And that’s what’s Microsoft is proposing: to make it harder for Government authorities to put their hands in people’s data.

image

 

Why Germany?

After the whole saga between Microsoft vs. USA Justice Department, European consumers, rights groups and lawmakers have expressed concern about what U.S.-based companies share with American authorities.

image

The European Union has very rigorous rules to protect data, and Germany's regulations are considered especially strict. Besides that EU authorities have been clamping down on data protection in recent months over concerns about mass spying by U.S. intelligence services. Especially after the revelations made by former NSA contractor Edward Snowden that the U.S. spied on German officials, including Chancellor Angela Merkel, angered Berlin.

 

Where Will the Datacenters be Located in Germany?

They will be in Magdeburg and Frankfurt. These new datacenters will maintain the same level of expectations , security, service and quality standards as all Microsoft datacenters globally. The services offered will abide by the Microsoft trusted cloud principles of security, privacy, control, compliance and transparency, as well as consistency with Microsoft’s global cloud services.

image

The reason for 2 datacenters is to ensure business continuity. Also their data will be exchanged through a private network to ensure data resides in Germany even in transit.

 

What is Planned to be Stored in Germany?

As part of this big initiative, Office 365 customers will soon be able to choose to store all data from the following products in Germany:

  • Azure,
  • Office 365 and
  • Dynamics CRM Online

 

Who Will Oversee this Data?

Deutsche Telekom will be the assigned data trustee and will control and oversee access to all customer data.

 

What is a Data Trustee?

Data trustee is an entity that will handle data on your behalf. In this case, it will be a company called T-Systems, which is a subsidiary of Deutsche Telekom. It means that Microsoft will not be able to access this data without the permission of either:

  • customers or
  • the data trustee itself

and if permission is granted by the data trustee, will only do so under its supervision.

This is ground-breaking stuff. Never done it before in Europe and after the repercussion of the Safe Harbour case, this service is expected to grow rapidly.

 

What are the Impacts on Compliance for Customers?

These new cloud services in Germany will specifically address organizations and enterprises operating in data-sensitive areas such as the public, financial or health sector. The immediate effect on this is positive: Now you can even choose the datacenter within the EU jurisdiction which will translate in a better granularity of controls.

We are talking about the German Government which traditionally have a very high level of data handling regulations and security by default. As a matter of fact, Germany is one of the leaders in this quadrant. Together with Customer Lockbox, customers will be able to view how and where data is processed.

 

Will this Avoid the US Authorities to Access my Data?

Honestly, No. Any government that requires access to data stored in the cloud, regardless of the provider (Microsoft, AWS, Google etc) will get this access. In a fight between governments and private companies, governments always win.

However this move will make it increasingly harder for governments to have this access. And that’s the main goal here. It is not to block the access, but to put stronger controls around data access by other people except the data owner.

This move will be likely followed by Amazon and Google very soon.

 

Sounds Great! When Can I Move my Data to Germany?

There is a LOT of ground work to cover. Involving auditing, certifications, and buildings construction. Microsoft is releasing this information now to calm-down the nerves of some big customers. The expected timeline for availability will be around the 2nd semester of 2016

Read the official announcement here from Microsoft Europe.

by

CheckList to Buy an Used iPhone

I am in the market for a new phone. Got tired of my Windows Phone, which I gave so much love for years but unfortunately the market didn’t care for it. Windows Phone is like a beautiful princess locked in a castle that noone knows where it is.

I am going for an iPhone. You can’t beat its app store. Nowadays people don’t buy phones, they buy the app store.

I am thinking about buying a 2nd-hand device so I listed a few things to check when I found one and I am sharing these tips here with you. Hope it helps you as well if you’re in similar situation.

Here are my 9 checks to perform a good smoke-test on the device you want to buy:

  1. Check for Warranty and Support Status
  2. Check the iPhone Activation Lock Status
  3. Examine the Device
  4. Test the Display
  5. Access the Internet over Wi-Fi and Cell Network
  6. Make a Call and Send a Text to a Friend
  7. Take a Picture and Make a Movie
  8. Check the Battery
  9. Disassociate the Device from iCloud

And now let’s go into more details on how to check them.

1) Check for Warranty and Support Status

If the phone you’re buying is sold as “under warranty”, make sure it is.  Enter the iPhone serial number into the Apple’s site to see the report. You can check this here. 

image

2) Check the iPhone Activation Lock Status

Before transferring ownership of an iPhone make sure the Activation Lock has been disabled and the device is ready for the next user. This also applies for iPad, iPods and Apple Watches. You can check this here.

image

Note: Once an IMEI is blocked, let’s say due to theft or lost device,  it cannot be undone. It means the device has officially become a brick. With no use for noone except the recycling company. So if the IMEI is locked here, don’t bother testing anything else…actually, you CAN report it to the police.

3) Examine the Device

Scratches, chipped glass, dock connector. Then plug the phone in a charger to make sure it will take a charge. Listen to music through the headphones. Use the headphone’s controls to navigate music and volume.

4) Test the Display

This is tricky as well. Make sure you are in a place with good natural light when inspecting the phone screen. Visit this website iPhone Dead Pixel Tester to test for dead pixels. Make sure the screen displays a solid colour and it does not have any stuck pixels that won’t go away.

image

5) Access the Internet over Wi-Fi and Cell Network

Go and browse places like news or weather sites because they have tend to have small local caches.

6) Make a Call and Send a Text to a Friend

This is to make sure the phone perform trivial tasks as expected. During the call, put the volume up and down. Pay attention how you communicate with your friend and check if the call behaves as expected.

7) Take a Picture and Make a Movie

Make sure the photo does not look weird, too dark or too bright or have fuzzy spots.

8) Check the Battery

Go to  Settings/General/Usage and check the time when the device had the last full charge. This is a bit tricky, but once you have the phone use it as much as you can and see if you are getting the battery duration expected.

9) Disassociate the Device from iCloud

Hopefully you won’t be buying a stolen iPhone so make sure the current owner disassociates the device from the iCloud account otherwise you won’t be able to login using your credentials and activate your new phone. See how to do this here.

image

If you find out later that the previous owner did not disassociated it properly or he/she doesn’t know how to do it, ask him/her to go to iCloud, login and remove the device from their account. They can do this by going here.

image

by

Ethereum Blockchain as a Service Now Available on Microsoft Azure

Microsoft and ConsenSys are partnering to offer Ethereum Blockchain as a Service (EBaaS) on Microsoft Azure so Enterprise clients and developers can have a single click cloud based blockchain developer environment. The initial offering contains two tools that allow for rapid development of SmartContract based applications:

  • Ether.Camp - An integrated developer environment, and
  • BlockApps - a private, semi-private Ethereum blockchain environment, can deploy into the public Ethereum environment.

image

 

What is Ethereum?

If you’re not following closely the whole movement started with BitCoin, have a look at this video.

 

Why Ethereum?

The Enterprise Partner Group at Microsoft is on the front lines with some of our largest customers.  Everyone, particularly Financial Services, is interested in Blockchain technology. While a platform like Bitcoin has many great uses specifically as a Cryptocurrency, Ethereum provides the flexibility and extensibility many of our customers were looking for. 

In Financial Services particularly, Blockchain is a major disruptor to some of their core businesses, and FinTech companies are driving innovation in this space.  Ethereum is open, flexible can be customized to meet our customer’s needs allowing them to innovate and provide new services and distributed applications or Đapps.

Ethereum enables SmartContracts and Distributed Applications (ĐApps) to be built, potentially cutting out the middleman in many industry scenarios streamlining processes like settlement. But that is just scratching the surface of what can be done when you mix the cryptographic security and reliability of the Blockchain with a Turing complete programming language included in Ethereum, we can’t really image what our customers and partners will build.

‘'Ethereum Blockchain as a Service” provided by Microsoft Azure financial services customers and partners to play, learn, and fail fast at a low cost in a ready-made dev/test/production environment. “

It will allow them to create private, public and consortium based Blockchain environments using industry leading frameworks very quickly, distributing their Blockchain products with Azure’s World Wide distributed (private) platform.

That makes Azure a great Dev/Test/Production Environment for Blockchain applications. Surrounding capabilities like Cortana Analytics (machine learning), Power BI, Azure Active Directory, Office 365 and CRMOL can be integrated into apps launching a new generation of decentralized cross platform applications.

 

How to Try Ethereum?

It is available as an Azure VM Template. It means you need to spin up an Azure VM with the Ethereum template loaded. The virtual machine main system is Ubuntu, and it will contain a Go Ethereum client and a Genesys block. Also this template is available on GitHub, you can get it here.

 

Deploying with PowerShell

You will need Azure PowerShell to perform the deployment. You can install Azure PowerShell from here.

Switch-AzureMode AzureResourceManager
New-AzureResourceGroupDeployment -Name <deployment-name> -ResourceGroupName <resource-group-name> -TemplateUri https://raw.githubusercontent.com/azure/azure-quickstart-templates/master/go-ethereum-on-ubuntu/azuredeploy.json

 

All this is a pretty straight forward process, you will need to specify:


 



Read more about this exciting announcement here.

by

Western Australia Government Agencies Security Flaws

That’s appalling news. The Western Australian Office of the Auditor General engaged and was able to break into 2 Australian government networks. Worse, in the very first attempt! Both networks were using the login “admin” and password “password”. No joking here!

image

 

The Auditing team managed to download thousands of highly confidential documents into an USB drive.

And then they came back a week later…Smile

And then they used the same login and password, and downloaded more stuff…Nobody noticed anything. No alerts, no monitoring, no defensive measures. IT team, hello?

 

But Wait, It Gets Worse…

Check these findings:

  • Dozens of database administrator accounts using default passwords and usernames that had never been changed.
  • Several database accounts with passwords as: “test”, “password1” and “sqladmin”.
  • A database administrator account using password ‘DBA’.
  • Other administrator passwords had not been changed for over a decade. Leaving access to people who might have left the organization still intact.
  • A database server was being administered using 17 highly privileged accounts for which the passwords had never been changed!
  • All 13 Production databases were hacked. None of them had back-ups encrypted. All there for the taking.
  • At least one database server had never been patched.
  • Unexplained misconfigurations in at least two of the agency databases with opened backdoors.

 

The Full Story

The Office of the Auditor General compiled a damning report about the atrocious state of the security in WA into a report, you can see it here. This is stuff of movies Smile

by

Office 365 E5, Cloud PBX, PSTN Calling : Is Microsoft Becoming a Telephone Company?

Disclaimer: All this information is as of November 5th 2015. Make sure to remember that when reading in the future.

The new Office 365 E5 plan will include:

With this Microsoft’s goal is to expand the Office 365 market opportunity by more than $50 billion.

 

So the natural question is….

Is Microsoft Turning (also) into a Telephone Company?

Yes, absolutely they are. To make all these cloud PBX things to work they will be able to issue and manage individual telephone numbers for your business, which came to me as a surprise, and it is part of the new voice services that are coming in to Office 365. Not only this but if you have your own telephone number with a traditional telephone service, you can port your number to Microsoft. The new kids on the block are called: Cloud PBX and PSTN Calling.

image

 

How the Office 365 Plans Look Now?

Here you can see the new look of the Office 365 E plans and prices.

image

 

What About Customers Already on Office 365 E4 Plan?

Office 365 E4 will be phased-out and customers who are still interested in on-premise voice services can buy additional CAL subscriptions.

 

What is Cloud PBX?

Cloud PBX is your call control from the cloud. See this as a service that enables to control where the calls are going, but that's just one component. In order to allow a connection between an actual telephone network, a calling plan is needed. Customers can then either chose to:

  1. Have their call control in the cloud and route down to on premise and then call with one of the existing providers or
  2. They can choose to contract Microsoft Cloud Telephony services and connect their calls from the cloud.

 

What is PSTN Conferencing?

PSTN Conferencing Is the ability to be able to dial-in to conference meetings. Microsoft will be able to provide customers with actual real telephone numbers to call. As a trivia bonus, this is the same service used during the last Olympics for conferencing. It has initially a “limit” of 10.000 people connected to the same conference but according to Microsoft really this number is “in theory”. There is no limit except whatever is provided by the infrastructure. This service is provided by PSTN Calling

 

Will PSTN conferencing Be Available as Add-on for Skype For Business Subscription Plans and E3?

All services existing on the new E5 are already available as individual add-ons to E3 customers, assuming the pre-requisites are there. For example, you won't be able  to add PSTN calling if you don’t have cloud PBX service first, obviously. Any of the services available in E5 can be purchased individually. Dollar for dollar, for bigger deployments the best value will be go all the way to E5 instead of keeping E3 and adding individual add-ons.

 

For Hybrid Cloud PBX Scenarios, If a Customer Wants to Buy E5 and Wants to Integrate with Their Own PBX, How Easy Would That Be?

Hum…easy? Yes and no. At the moment, there is no easy answer for that. At this stage what we can confirm is that at least currently there is technology to deploy that sort of integration with existing PBX systems and take advantage of Cloud PBX services.

Having said that, if the question is not about integrating with current PBX systems but instead you just want to take advantage of your own existing telephone connectivity to your current provider, that's a much simpler proposition. This will require a small number of small virtual machines acting as gateways and depending on what you want to achieve there is likely a gateway appliance involved in that architecture. And according to Microsoft this is how most of the customers are thinking about doing it.

According Microsoft research, people want to do this on a hybrid setting because they are simply not ready to go to the cloud and move all the users up there and trust a telephone company to help them. Nobody has ever done this what Microsoft is doing it with E5, specially at this scale.

Another tip: If you are familiar with ExpressRoute, customers can use it to connect their on premise to the cloud with a private connection keeping their current telephony carrier. As a matter of fact, this is the recommendation from Microsoft: Use ExpressRoute because you won’t rely on the public internet and, according to them,  one will have more certainty and consistency in their telephony experience.

 

How Will the Billing System Work? How to Control Abuse/overuse of the Telephone Infrastructure with Office 365 E5?

Well, as of today, there are no over-usage charges as per-se in the new E5 plan. What is going to be put in place is monitoring of fraudulent behaviour and subsequent remediation. Let's say for example, someone left the telephone unattended for hours and hours and there is no audio. E5 will detect there is no voice coming through the endpoints so the call will be automatically disconnected. In that sense, it is expected there will be parameters that will monitor and manage and remediate issues/misuse when they occur, but MS at this stage did not signal any additional charges in the billion for over usage.

Also a cool thing if you live in the US is that the domestic service will be launched in the US with unlimited dial-in and out calls.

 

I love These Ideas. What Can I/We/My Company Do Now?

  • If you or your company have access, deploy Skype for Business internally as soon as you can, then deploy the preview cloud PBX, PSTN conferencing and calling before the December 1st launch. Visit www.skypepreview.com for more info.
  • Learns about Skype for Business Cloud Services. What Microsoft is doing here is an unprecedented move, from any cloud provider as a matter of fact, and with it a lot of new concepts, considerations and technologies comes into play. Now is the best time to learn about it and to position yourself as an early adopter on this growing market.
  • If you’re a partner, start working on communications strategies to discuss opportunities on hybrid systems integration. A lot of people will be interested in learning more about it.
by

Customer Lockbox in the Office 365 E5 Plan

Every cloud service provider recognizes  that your data in the cloud is yours and you want to have full control over its access . Customer Lockbox is a feature for Office 365 that provides customers with unprecedented control over their content in the service by giving them explicit control in the very rare instances when a Microsoft engineer may need access to resolve an issue.

image

The whole Customer Lockbox service has been engineered to require nearly zero interaction with customer content by Microsoft employees.  Nearly all service operations performed by Microsoft are fully automated and the human involvement is highly controlled and abstracted away from customer content. As a result, only in rare cases a Microsoft engineer might have any reason to access customer data in Office 365, and when it does you, the customer, will be part of the process.

image

That technology, process and approval workflow is called Lockbox, and its approval process go through multiple levels of authorization. In addition, all access control activities in the service are logged and audited to make sure all compliance and regulatory needs are matched.

No other cloud service at this day offer this level of access and control where the customer can scrutinize the request and either approve or reject it.

A Matter of Trust

All this transparency and control are to make sure a satisfactory level of trust is maintained between Microsoft cloud services and the customers. All Customer Lockbox activity will be available to customers via the Office 365 Management Activity logs for easy integration into customer security monitoring and reporting systems.

The Office 365 E5 Plan

Microsoft announced a new E5 Office 365 plan and the E5 will contain that service by default. Customer Lockbox will be available for Exchange Online by the end of 2015, and for SharePoint Online by the first quarter of 2016.

by

Cyber Threats: Nation-States

This article is part of a series of called “Cyber Threats: Who Wants Your Money?”. If you missed the first post, you can read it here.

After the Operation Desert Storm, in 1998, USA for the first time has shown to the world their military prowess and how technologically advanced they were. Countries everywhere looked at how technology was being utilized by the US Marines and realized that simply no country was a match for them. The warfare landscape has been taken to a new level. The Chinese army were quick enough and studied how tech was applied by the USA and wrote a military study called “Unrestricted Warfare”. A classic now.

The summary of the book: A small nation can achieve a powerful hit against a bigger one by exploiting technological weaknesses. The technological warfare between nations started.

China then created a Cyber Militia, a group of hackers based on the findings of that study. Chinese schools invested heavily in programming and network computing. And I’ll use this Chinese event to explain a bit what goes behind the minds of a Nation-State Cyber Threat.

image 

Why They Did it?

The answer to this question is similar to the answer “Why is Windows Phone trying to compete with iPhone?”. Because if they don’t, the competition will take over without resistance. And from a nation perspective, everyone was going to invest in cyber tech. China could not afford to be out.

Since then, reports of cyber attacks attributed as originating from China emerged in the news frequently.

 

What Is a Nation-State Attack?

Every western organization likely experienced an increase in port scans and access attempts to their systems around the year 2000. Port scans are considered attacks because they are done with:

  1. Explicit Intent to actively look for weaknesses in your security stance. These are not done for fun or curiosity, they carry a malicious purpose.
  2. Malicious Purpose. They are like “checking doorknobs on people’s houses”. Once they identify, the next step is to compromise information and integrity in exchange of political of financial gains

To mention a few examples:

Regardless where they came from, executives all over the world recognized the threats and the Three Warfares was written. A mark on defensive systems against Nation-State attacks.

People started to understand their devices could be attacked, casual conversations recorded and personal storage devices compromised.

Small and medium companies started to be attacked. They were used as a new attack vector against their partners, big corporations.

 

Why Nations Do This?

Because it is profitable and offer an upper hand in tactical politics. Big damage can be done by small groups against large organizations by a fraction of the invested cost. According to Interpol data, cyber espionage theft amounts to US $1 trillion.

The Center for Strategic and International Studies, estimated that cyber espionage incurs in losses of about US $100 billion per year to the US economy.

 

Most of Countries are Capable of Cyber Attacks

A few countries are the undisputed leaders such as USA, Russia, UK and France. That’s where the power of alliances come into play, but many small nations proved to be highly effective. Take for example Stuxnet, which has the power to take over power grids and nuclear plants.

Have a look at this video explaining how powerful Stuxnet can be for a Nation-State attack:

 

 

It is impossible to talk about Nation-State attacks and not to mention Edward Snowden famous for the Wikileaks whistleblowing and now writing for the Guardian which “confirmed” the USA actually created Stuxnet.

by

Cyber Threats: Who Wants Your Money?

Nowadays, no organization which is planning to go or it is already (partially or completely) in the cloud can minimize the importance of cyber-security. Like a fighter during the last round of a combat, an organization cannot let the guard down after hours.

image

photo courtesy: @MSAU

Virtually everyone, from employees to executives and partners, are always connected to the Internet. Internet access is ubiquitous and everyone is carrying super-computers in their pockets.

And that increased surface of utilization created by the possibility of “access everywhere” challenges cyber-security status, because the interaction between smart devices and users and locations (safe or not) exposes individuals and companies to several security threats. That’s why in many organizations employees with access to important documents should treat their personal devices with the same rigor as their computing systems at work.

At the end of the day, cybersecurity is risk management, and the best approach to handle this is by establishing a secure corporate culture with positive management practices.

 

“Know Yourself and Your Enemy” – Sun Tzu

The internet is a fantastic place. Any information at the reach of your fingertips, however evil lurks. Cyber-Criminals are on the look out, looking for the right person to prey on. Day in, day out, thousands of hackers navigate through the web, attacking systems, devising plans, looking to exploit weaknesses in someone’s environment. 24x7. 7 days a week. The importance of the right security partner is paramount because it doesn’t matter how secure you try to be, hackers will always outnumber the defence team.

And now, hackers are not only after fame and glory. They are after intellectual damage and financial loss. Countries are fighting each other using the cyberspace, which created a whole new of threat classification in itself. It is like the wild west out there, and they are after everyone weak enough.

Despite that, successful enterprises didn't get there by avoiding risk. Instead they managed them to obtain a competitive edge on the competition.

 

The Enemy

The main cyber threats to organizations nowadays can be categorized as:

  • Poor or Malicious Products
  • Internal Threats (Insiders)
  • Hacktivists
  • Terror and Crime organizations
  • Nation-States

Today we will start a series of posts targeted to “know your enemy”. We will identify the players in the current cyberwars, their threats and how to manage them.

Let’s start talking about the threats posed by Nation-States.

by

The World in the Year 2020, According to Gartner #GartnerSYM

Every year, Gartner releases a list of predictions in a huge simultaneous event across the globe (respecting the individual location timezones) which are followed closely by strategists, IT thought leaders, futurists et all from all over the world. The 2015 event key takeaways were:

  • Autonomous Software,
  • RoboBoss and
  • Smart Devices.

I’ll spare you the suspense. Let’s go straight to them. Here are are Gartner’s top 10 predictions for 2020.

image

#10 - Writers Belong to the Past

Machines will be responsible for 20% of all business content created. In fact, these “robowriters”, as they are called, already produce reports, sports tickers, graphics etc. Once you stop to think about it, yeah, they are here already.

#9 - Connected “Things” will Need You

6 billion connected things will be requesting support. This “things” are smart-devices living in the Internet of Things (IoT)  needing services, data etc. It is expected that campaigns of new business models will be developed targeting these “things” which will then influence their owners.

#8 - Software that Works on its Own

Autonomous software”, that’s the key.  These are agents working independent of human interaction. They will participate in 5% of all financial transactions across the globe. Machine learning systems and predictive algorithms are actually beginning to perform transactions in many banks without our help as of now.

#7 - Meet Your New Boss: A Robot-Drone

3+ million workers will have a roboboss. It is unclear at this stage how this interaction will develop, as in a employee-boss setting or if it will be on a employee-watchdog basis. Either way, artificial intelligence will play a big part in this story.

#6 - RoboCop Buildings

20% of smart buildings will experience digital vandalism. From hacking to physical damage, these are smart, automated constructions which will affect the lives of communities around them. Hacking IoT is a new attack vector.

#5 - Top Companies will Have Machines as Employees

50% of the top IT companies will have more smart machines than smart employees. That’s because several smart machines will be easy to leverage new ones by the same group of smart employees.

#4 - Digital Assistants Will Interact with People

Digital assistants will finally recognize and interact with individuals by face and voice, a bit like what Microsoft Kinect does today. They will open the doors for a new age of biometric security, incorporated with a much powerful and consistent delivery.

#3 - All Your Health and Fitness Data Are Belong to Us

2 million people will be required to wear fitness tracking devices as a condition of employment. This will affect deeply the insurance industry and the design of smart cities. People will be encouraged to be healthier and with the “open doors privacy” (allowing iWatch, Facebook etc read and share individual data) currently being the status-quo, that trend will definitely get stronger.. Overall this is clearly a fantastic benefit for the community living in the year 2020. Likely people won’t be using independent trackers, but instead this tech will be incorporated into their current devices.

#2 - Apps will Use Apps for You Better Than You

40% of mobile interactions will be done paired with smart agents. Yet again another prediction following the mantra of autonomous apps and software.

#1 - When a Cloud Security Breach Happens, It is Because of You

Cloud security will be so powerful and so pervasive that 95% of all failures happening in the cloud will be due to  customer's fault (not the vendor’s), varying from poor usage and risky user behaviours up to incompetence. Did your data leaked to 4Chan? Don’t blame AWS or Microsoft. It was you!

by

Personality and Imperative Test: Ambassador

I’m not a big fan of personality tests. I think that sometimes they show a different side of us that might not represent our individual as a whole. However I took the suggestion of a friend over twitter and gave the www.imperative.com a try. And I was pleasantly surprised. The description is very very accurate about my drivers in life.

I am not sure if you believe these things or not, either way give it a try. Worst case scenario it will be fun.

Meanwhile have a look at my profile. Below are my results:

The Ambassador

You make your mark on society by facilitating authentic human connection.

Edge Pereira: My imperative is to shape societies and communities to help them overcome societal barriers engaging them and bringing them together.

You change the world by connecting and bringing people together. Driven to promote fairness and equality to ensure equal access to opportunities - you work to empower communities and enable them to tackle significant challenges that bring about large-scale change. By connecting people through a shared vision and fostering commitment and ownership, you ignite the collective energy and drive needed to move towards concrete societal progress. Your work feels especially worthwhile when you see your contributions leading to widespread changes that expand opportunities for all.

image

Who Do I Want to Impact: Society

You seek to impact communities and society. You find purpose when you:

  • See others promote your solutions and ideas
  • Implement a new policy
  • See a change you made have long term impact

image

Why Do I Work: Harmony

You are driven to ensure everyone has access to opportunity. You find purpose when you:

  • Level the playing field
  • Help others overcome barriers
  • Ensure everyone is heard

image

How Do I Solve Problems: Community

You bring groups together to build engagement and ownership. You find purpose when you:

  • See a team come together to accomplish a goal
  • Connect two people who would get along
  • Empower a group solve its own problems

 

Defining Motto

“Equality is not a concept. It's not something we should be striving for. It's a necessity. Equality is like gravity.”-
Joss Whedon

by

ASN Website Security Flaw

This is really a bit disappointing. YET ANOTHER website that stores and sends login information as plain-text.

www.asn.com.au guys, please fix this. If you can’t see how is this an issue, please have a look at this article explaining: Ticketek Website Security Flaw.

asn-plaintext-offender

You tell me that ASN does not involve a lot of credit card processing. OK, I grant you that. But the issue is a lot of people use the same password for several websites. You get hold of someone’s password then this password might work in other websites.

Come on ASN, you can do it! Smile

by

What’s the Problem with Plain-Text Passwords? A Disaster Waiting to Happen.

TickeTek is a great site. Actually, I love all the online booking capability industry. These guys apply a lot of cool stuff over the internet to make our lives easier when booking tickets for events. No more queuing to get to that place and worrying about where one will be seated. (unless you’re an iFan)

image

And because they deal with personal details and personal information, they should be extra careful to make sure data don’t get leaked for criminal purposes. Which brings us to the reason I am writing this post.

The other day I went on to book tickets for my family so we all could go see the Australian football competition. We picked the Brisbane Roar vs. Central Coast Mariners game. It has been a while since I bought my last tickets and I forgot the site password.

No worries, just click the option to remind the password, right? so, I did that and this is what I’ve got in my email.

image

Yep. They sent me my username and my password, in plain text to my email. To the unaware or naive mind, this doesn’t look too bad, actually some people think this is very cool, so you don’t think about a new password. Just use this one, right?

Here’s the problem: If they are sending me my password then…

  1. They are storing my password as it is or;
  2. They are storing my password in a way that it can be scrambled/descrambled

Either way, they are storing my password somewhere. And that’s not great! Room for improvement here….

Why is this a Problem?

There are a lot of problems with this, but I’ll nail it down to 2 points:

  • Email is not a safe environment. There are hundreds of types of attacks that can be done on emails. The email protocol itself is not encrypted.
  • Easy as copy/paste. If someone get hold of my email account, they can go and search for the text “password” and voila…there it is for the taking. And there is no need for hacking to be involved. Just need to leave your browser accessible for a few minutes while you go do something else and you’re done. The options go from someone lurking behind your back and writing down the password, until virus that take screenshots of your computer.
  • Multiplication of the weakness. Now your password is stored: at your place, at TickeTek and now in your email server. Like it or not, every time that email gets forwarded it increases the chances of someone getting hold of it.

So, here TickeTek is telling me that “hey, if you forget your password don’t worry, we are storing it for you in plain-text, or using a reversible encryption process to get it for you”. This is a big no-no! This is a sign of poor thought out security here.

Another problem is that if a hacker gets a very limited, very restricted access to the system…let’s say, “read-only” kind of access, he/she still can read the password and from there empower themselves to a higher ground of disaster. This is not unheard of. If you don’t believe me ask the folks at:

All these people said they used secure procedures to safeguard user’s details, yet when they were hacked it was all exposed they did not go through the steps to make sure it was secure enough. The sad conclusion here: This is still a very common vulnerability even among big companies. Sad smile

image

General rule: Nobody, nobody except you, should know your password.

Who Owns My Data?

Ok, further in the process. Now I have the right username and password, then I proceed to buy the tickets. Because I once bought tickets with the site, they stored my credit card details. Now you see the danger brewing…

Imagine if someone grabs my password. Because the site stores my credit details, now the hacker have my credit card. The party is getting better.

image

The Privacy Policy

The publication BusinessWeek did a report on internet privacy where the results show that the majority of internet users are worried about how their personal information can be used. From a customer respect perspective is it always good to have a privacy policy. A privacy policy’s objective is to disclose, to inform people (visitors/customers). TickeTek is doing the right thing here. They also have a privacy policy. That shows they care for how the information is handled and they have guidelines. Great job here TickeTek.

image

However, by looking at the policy (something I am sure a large parcel of the visitors don’t do) we see statements like this

image

I would say that text is missing some points because as you could see they store my password. But maybe here’s the reason why. Apparently the personal information collected is stored outside TickeTek on a 3rd party vendor database.

image

Which can get even more complicated. This increases the surface for attack. Here are some possible attack vectors:

  • What if such database is backed up by yet another external company
  • What if the operating system from these companies are not fully patched against security risks
  • What if there are weak points in any other hardware or software firewall involved
  • What if a given user that have access to this database get a virus that could exploit the data
  • What if this database, for whatever reason, ends up in a computer, laptop, removable media and it gets stolen
  • What if a frustrated employee, not related to Ticketek at all, decides to "hit back"

All these are plausible scenarios and require appropriate mitigation strategies in place. In-depth security: every layer in the system needs to be hardened individually.

In short, here’s the diagram explaining this. Look at the attack vectors in red:

edge-pereira-security-attack-vectors

So now, there you go, your password is stored in yet another place, a 3rd party company. And again, to bring up the point of the security vulnerability: This 3rd party company might have a team of IT professionals that can handle the data stored. So now your password is stored:

  • In your email server
  • In anyone’s email server if you forward the message in anyway
  • In your ISP
  • In your laptop or mobile
  • In someone’s else company …

So the threat model now has additional attack points, because now you are involving more parties. And again: the password it is still stored either in plain-text or in a way that it can be deciphered. Regardless the way you want to look at it, this is a bad practice….but salvation is at arms length and it is not complicated at all to fix !!

Fixing This: How Should Passwords Be Stored?

Well, ideally you wouldn’t want to store a password. Let’s take a step back and see the purpose this: Authentication. If we stop to think about it, we don’t need to check if the password matches, we need to check if the password is right! And there are several ways to do this, one way is to generate something called “hash”. A hash is a code generated using your password as initial value and an additional value called “salt” which is random and individual per password. That code is always unique and that’s the value you should store. I like the analogy that the hash is like putting meat through a grinder. Anyone can manipulate the meat afterwards but there is no way you can restore the meat to the original state. Likewise, you can always verify the hash generated based on the password the user provides in the website, but there is no way to process it and to revert the password back.

And because nobody knows the user password, no email can be sent to them with a plain-text password. Instead, an email will be sent with instructions to set a new password, which is not only a good security practice but also forces the user to recycle an old password.

It is All About Reducing the Surface for Attack

Techniques like this will not avoid a website from being attacked. If you were patient enough to read up to here (thanks for that, I really appreciate it! Smile) you see that all we want to do is reduce the surface for attack and minimize the damage. Adding enough security measures in place to make sure that even if an attacker can get hold of this data, the potential for damage is minimized.

One More Thing Before You Go

I wanted to point out also 2 cool things the website is actually doing very well. See this image below, this is me sniffing all the internet traffic between my computer and TickeTek website during the credit card processing. Everything is using SSL/HTTPS, which means all the communications are encrypted. Good job!

image

Also TickeTek has a Privacy Officer, which is pretty cool if you ask me. If you’re a customer and have any concerns about your data and how it is being handled by them, just contact these folks and they will address your concerns. Good job again !!

image

On a final note, all this thing about sending passwords in plain-text via email is a big security issue because it comes from a weak security stance, which then projects an image of “hey, other places might not be using the best security practices”; however this fix is extremely common and, I dare to say, is a bread-and-butter of any decent programmer.

I really hope they fix this soon! By the way, I did send this post to their Privacy Officer.

by

Office 365 and the Australian Data Retention Laws

Since October 12th, 2015 all the online communications done in Australia now is being tracked, monitored and stored for 2 years via a new law enforced. The so called Data Retention Bill. All this info is valid as of October 2015, you know…in the cloud, things change rapidly Smile

image

The Data Retention Bill, also known as "Telecommunications (Interception and Access) Amendment" is a hot topic right now. And as in any new technology, a lot of misconception is around. Let’s talk a bit about it and how does it impact if you have data hosted with Microsoft Office 365.

I am not going into the merit of right or wrong, because I know you came here from a business perspective and with the question in mind “What can I do to make sure I am compliant?”. Also a good place to start is to have a look at my post about Cloud Data Governance.

Explaining the Australian Data Retention Law

To be quite frank, apparently the law has so many loop-holes that it is hard to explain, but the Australian Parliament website has a good summary its intentions which is to force Internet Service Providers to keep "Telecommunications Data" for 2 years, limiting the reach of agencies that are able to access this data and to provide record-keeping and reporting on the use and access of this data.

Important to note here that they are talking about generic, abstract data. Not necessarily content, which takes us to the next point

The Metadata

Quoting the back then Minister for Communications, and now Prime-Minister Malcolm Turnbull:
"The type of data referred to in the bill as telecommunications data, more often described as metadata, is information about a communication but not its content. So, in the telephone world, it reveals that one number belonging to a particular account was connected to another number at a time and for a duration, but does not reveal what they discussed. In the IP world it reveals that a particular IP address, which may have been observed to have been engaged in some unlawful activity, had been at the relevant time allocated to a particular account. In the context of messaging—email, for example—it reveals the sender, recipient, time and date, but again not the content. Access to content, I stress, requires a warrant."

In his explanation, on this telecommunications data monitoring, only source and destination endpoints that are tracked, not the content that is exchanged and any access to the exchange data would require a warrant.  So, the government will know that for example Mr John Bloggs send a message to Mrs Jane Citizen on 13 October 2015 at 11:30 AM but the content of the conversation is not covered by the law.

2 Years Data Retention

All these communications will be retained for a period of 2 years. Data retention is expensive, very expensive. It is still a bit unclear how all this will be paid for and covered, what agreements will be in place, recovery and disaster strategy etc.

How Prepared are Australian Business?

apparently, not much. According to research ~90% of business are not. So much so that Telstra just revealed it needed another 18 months in order to become compliant. That’s a complicated matter, as you can see.

image

You Have No Reason to Worry

For us, law abiding citizens, I expect we have nothing to worry about. All this things are being tracked, monitored, collected and so on. The amount of data is ridiculous, gigantic, and it is very unlikely that the government will pinpoint someone and start monitoring the internet movements without a good reason. At the moment, there is not enough manpower, bandwidth and time for this. Clearly, these laws are targeting people with criminal intents, people in blacklists and persons of interest. For example, when a crime is committed and a person is identified, then the stored metadata about his/her communications can be used to clarify the root cause of their intentions.

I like compliance, structures and mostly, I like the identified needs to treat about data better. Some might say this is a bit overrated but at least they are this from a security mindset, which is a good thing. If you have nothing to hide, then there is no reason to be worried about it.

On Office 365

We know that now Office 365 has datacenters in Australia, this means that this data falls into the category of the Australian cyber laws initiatives. Luckily for you, Microsoft has a strong tradition of working closely with law makers and make sure that all data in the cloud is compliant and secure. Your data is still YOUR data..

Here are some of the controls in Office 365 that addresses the legislation and regulatory needs. In some cases, you can go through them and make sure they are aligned with the current legislation:

In short, if you are an Office 365 customer you can see that most of the controls needed to make sure your business is engaged with the Australian Data Retention laws are there already. However, this is only the technological part…the biggest challenges are on the business’ processes and procedures.

by

Azure vs. Amazon AWS EC2 vs Google Cloud

Lately I’ve seen a few articles comparing the size of the clouds. Who is bigger? Who is more secure? Who has more customers? and unfortunately a lot of the links people send me are from 1, 2 years ago a time when Amazon AWS reigned supreme.

In this area things are literally changing every week! So while the number of costumers in Amazon AWS is still larger than anyone, both Microsoft Azure and Google Cloud are make huge leaps catching up with AWS.

Next time you see an article or when you are researching for a real comparison, I suggest to do 1 thing first: Check the date of the article and apply a gain of salt for anything written older than 6 months.

So here’s a summary of the Azure state of play as of October 2015. You can learn more about these numbers here.

Azure Datacenters

Azure has more datacenters than Amazon EC2 and Google Cloud combined.

image

Azure is also the first cloud service to open datacenters in India, which escalates the numbers of users to billions. Compare this with the size of the Amazon AWS EC2 and Google Cloud datacenters.

imageimage

 

Trustworthy Computing

image

Microsoft invests heavily on compliance, data security, controls and transparency initiatives. As of today, Azure is the cloud service that has the broadest numbers of regulatory and data compliance certifications. This means that virtually any business environment can be delivered using Azure. That’s a challenge for Google and AWS for example, if they are not compliant with the Israel Government Data Compliance regulations, cloud solutions cannot be used for their projects.

One interesting fact on this about Google Cloud: With Google Cloud you cannot guarantee where your data will be located. Even if you select your datacenter to be in your own country. If you are an Australian customer, for example, Australian laws requires the data not to leave the country for some industries.

From Millions to Billions to Trillions

image

An interesting statistic not mentioned here is that more than 40% of the Azure revenue comes from start-ups and small ISVs building the next generation of businesses.

Fortune 500 Weapon-of-Choice

image

The proof is in the pudding. 80% of the largest companies in the world are using Azure. These guys don’t go picking up a cloud provider easily. They have specialized IT departments that take these decisions very seriously. Leverage their time and knowledge when considering your cloud decision.

Internet Of Things (IoT) Services

image

A lot of customers are already joining the IoT strategy to help them run their businesses more effectively and in a more innovative fashion. People like Rockwell Automation are using the Azure IoT API to manage gas dispensers across critical infrastructure around the world. From 2015/2016, all Ford vehicles will come out with dozens of IoT sensors and these guys will be streaming this data to the cloud. ThyssenKrupp is using IoT sensors in elevators all across the world tracking the equipment health of millions of elevators across the world and using Azure Machine Learning they will use these IoT signals to predict when these elevators will break down and be able to act of it before they do.

 

The Largest Cloud VM Infrastructure

image

With Azure, you can have virtual machines running on 32 CPU cores, 450 GB RAM, using SSD up to 6.5 terabytes of space, which combined can go up to 64 terabytes of storage per VM, all this with less than 1 millisecond latency. That’s huge and unparalleled at the moment.

Bring Your Own Enterprise Security Partner

image

Azure is already a very secure environment with platinum quality, and on top of that if your company already has a trusted security partner relationship you can bring this partner to your public cloud with Azure. The biggest and most common enterprise security firms are certified and can run on Azure as an appliance for your cloud. Implement their security protocols end-to-end with little impact on your security experience.