Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, October 6, 2013

On a Slippery Road in the Name of National Security

Two very important things happened at the recently concluded Cocon 2013. Not surprisingly, the media missed these, in favor of more "mainstream" news focusing on the celebrities and visible initiatives.
  1. The Deputy National Security Advisor, Sh. Nehchal Sandhu gave a largely statistics & routine talk with the notable exception of a superb pronouncement:
    "We will not go down that road
    He was referring to the recent events surrounding NSA's surveillance and its fallout in the US (civil rights outrage) and in the rest of the world (Brazil, anyone?), including India (such as new guidelines on email usage, etc.). This statement was made to convey that the Indian Government would not indulge in the kind of tactics that NSA and FBI are being accused of.

    Why is this important? It portrays a commitment from the Government to act with a level of wisdom and maturity that has been hard to find recently not just here, but in most parts of the world.

  2. A few speakers talked about the Government's collaboration with the hacker community. One of the talks included an unapologetic response to the criticism of this year's takedown of a malware's C&C Server at this year's nullcon -- announcing a new era of Government - Community partnership.

    On the sidelines of this talk was a much more sinister discussion. That some parts of the Government might be willing to take hackers for hire -- for ostensibly National Security engagements.

    On the face of it, it should not cause any concern, right? Not until you understand the implications, subtle and otherwise. How will this relationship begin, what pitstops will it make and how far will it go?
    An example: LulzSec (ex-)leader cooperating with the FBI.
    Another: Desi hackers join Indian Cyber Army. In this, there is even a mention of a lawyer wanting to change the IT Act to provide protection for "patriotic stealth operations". Of course, they might be talking about "usual" hiring of infosec professionals in cyber-defense positions... but there is enough to indicate otherwise too.

    There are enough rumours and murmurs on whole truckloads of East European hackers being allowed to flourish in the fond hope that they will provide the necessary "air" cover (and perhaps, tactical support) to their governments when push comes to shove in cyberwars. Are we talking about going down that route?

    National Security as a justification to do things that you wouldn't otherwise do is a very slippery slope. Once you start the journey, you have no control on the speed, direction or the destination. This is a route that argues that the means justify the ends. No doubt there will be people who argue that when our adversaries do it, we must do it too.

    However, I hope that saner voices such as Sh. Sandhu's will prevail.
On a different note, I do hope that our above-board educational hacker groups (such as garage4hackers) make every effort not to tip and fall into the wrong category. A few beers, some boasting and a vulnerable target are all the ingredients that enthusiastic young blood needs to cross the line. There are always rationalizations that can be made after the fact. Including misplaced patriotism.

Saturday, November 10, 2012

More on building secure IT systems

Last week, I wrote how the current system (of designing and developing IT systems) is broken. How business will simply not be able to support high-levels of post-facto InfoSec expenditure that is necessitated by increasing sophistication (and automation) of attacks. That we need to build security into our systems at design & development time.

It appears that I am not alone in this thinking. I came across a paper (in the SANS library) by Dan Lyon - apparently as a part of his GIAS GSEC Gold Certification effort - titled "Systems Engineering: Required for Cost Effective Development of Secure Products (PDF document)". In this he builds a case to take a Systems Engineering approach to build-in security into products; and that building security right from design makes more sense than otherwise.

He also refers to others writings and talks on the subject (though as a means to introducing the need for systems engineering approach), such as:

  • Software Security: Building Security In (2006), by Gary McGraw
  • The Security Development Lifecycle (2006), by Michael Howard and Steve Lipner
  • At the SANS Rocky Mountain 2012 Conference John Strand: "... the current state of information security is broken; new approaches are needed for information security. Many current practices for achieving information security are applied after a product has been developed. Examples such as firewalls, intrusion detection, intrusion prevention and antivirus are all external systems to what organizations use to conduct business..."
While it is gratifying to see that I am not alone in this line of thinking, I wonder why so little progress has been  made in building more secure IT systems from ground-up. Perhaps it is because of one or more of these reasons:
  1. Addiction by tradition: We are so deeply habituated to current development processes that we are unable to break free from them.
  2. Demand-side ignorance: Businesses don't see (and consultants are unable to make them see) the perils of current approach; and hence they are not ready to pay. In the absence of demand (from businesses), supply chain isn't ready to invest and gear-up.
  3. Supply-side ignorance: The word hasn't quite spread into the developer world! Yes, even in today's hyper-connected over-communicated world, this can happen. Too many people have yet to adopt new digital media consumption methods; and those who have, are subjected to information overloads that much gets filtered out.
  4. Industry Ostrich posturing: This could be deliberate (vested interest by current approach's beneficiaries) and/or simple denial. 

What do you think are the reasons?

I am exploring the possibility of me doing something about it (instead of merely whining / writing about it). Stay tuned.

Tuesday, November 6, 2012

Built-in robustness in IT Systems

Yes, it is true. We are woefully short of InfoSec professionals. Recent events (including the spate of #5Nov attacks) bear it out. We need more (and better trained) professionals to protect our systems; better technologies and products. One-way gateways, passive DNS traffic monitoring systems, more sensors, more analytics, you name them.

Yet, we are missing something fundamental in the picture.
Would you knowingly build your home with termite-infested wood and water-soluble walls? Would you  forego doors and locks and ignore building safety codes - just because you can add a swanky swimming pool with the money you save?
Would you then insist that we hire more security guards, buy more fire sensors, build protective shields on the outside and install props to shore up the insides of this hopelessly vulnerable home?
Absolutely not. Yet, we do it every day, when building our critical IT systems. Aren't we?
Well, the problem isn't so obvious with IT systems as with our homes. Neither the systems nor the weaknesses are visible to the naked eye. We can therefore make convenient assumptions on what is good enough security and still not lose sleep at night.

For decades, innovation and IT systems have romanced each other - and focused nearly exclusively on functionality, ease of use, etc. Yes, there have been developments in security - but almost all of them are post-facto solutions. Not built-in security. Not robust-by-design. Not in every component of the system.

Thanks to this approach, we are soon reaching a point where the IT sprawl will collapse on itself in a catastrophic sequence of events. Unless we shift our focus to the process of building the systems in the first place.

Networking technologies are beginning to show this trend in a small way. Computing, not so much. Operating Systems are only scratching the surface with the notable exception of OpenBSD and Kaspersky OS (is it named yet?). Databases, Application Platforms and Application software themselves haven't even begun. How many software professionals have even heard of secure coding? 0.001%? Or less?

We must change now and change quickly. Businesses will not be able to bear the burden of spiraling costs of post-facto and ineffective security solutions for long. We may not perish yet, but that is nothing to celebrate.

Saturday, March 31, 2012

Why I won't register with NPR

I asked a few people "Why should I register with NPR?". The responses are mostly along these lines.

"It is the law. So you must!"
Nope. That argument is for sheep and mindless drones. It is pretty much the same as:
  • "Everyone has to, at some point or other"
  • "Everyone else is doing it. So you should too"
  • "What do you lose? Why not just go with the flow? Why do you want to stand out?"

"It is against the law. If you don't, the government can jail you!"
Yea, well. I am thrilled. My government says I must come and "register" (for what?). If not, they will jail me! Can't get any more tyrannical that, can it?

Here is something getting close to real logic.
"Someone thought this is going to help identify all illegal immigrants. So they said let us register all our citizens; anyone who isn't, is an immigrant! To make sure they can force you to, they wrote this down in the Citizenship Act."

Sounds okay. Even if you overlook the assumption that "all illegal immigrants are terrorists". Until you think about it. 

They don't have a clue of how to determine citizenship, do they? Their processes are dependent on someone local not "objecting" (which one overrules?) to your being included. So some whacko decides he will "object" to people either out of vendetta or simple thrill of being able to - and off goes your citizenship. They have a "process" for grievance redressal, I am sure. I will have to run around government offices proving that I am a bonafide citizen. But hey, why put my citizenship in question in the first place? 

Here is what it all comes to - a classic case of a process design gone wrong. To catch the small set of exceptions, we treat everybody like they are criminals.

I say NO. Those of you who agree, please join me in saying NO.

Friday, February 3, 2012

Why it is not NPR vs UID

First. During the past week, we have had a lot of questions and a lot more messages of support at the thinkuid.org web site. My big Thank You to all those interested enough to participate, support or argue with us. It shows that you care.

[edit 4-Feb: Making some corrections, thanks to suraiya95's point that NPR is not a statistical exercise. So I will cross out the deletions & put additions in purple. I will distinguish between Census (the statistical exercise) and NPR (the new project by the Census dept). 
Net effect of these corrections: Either because I am pig-headed or perhaps my reasoning stands yet, the essence of my post remains. I leave it for you, the reader, to decide.]

Now for the tough part. Tough because NPR the Census is an otherwise good example of a huge project, well-executed. It is also tough because of my own first-hand experiences that color my views despite well-meaning admonition by a Director-Census once: "Don't let your personal experiences be the sole basis to pre-judge our work, Sastry".

I'll try to keep those in mind. This is going to be long, so grab that coffee, switch off that phone and make yourself comfortable. :)

NPR The Census is a great project, no doubt.
Those who criticize the NPR project Census Dept casually, can only do so when they don't understand the goals, the vast scope and the extraordinary amount of effort that goes into such a gigantic exercise. No doubt, it is a great project - created to count the population of India and various demographic profiles of the population, to better understand our nation as a whole. There in lies the problem.

It has been, and still is well-suited to be only a statistical exercise. The processes and the error-tolerances are perhaps within acceptable bounds, statistically speaking. But they are not good enough when it comes to matters that need every individual to be more than a statistic. Not acceptable when one or two, but a staggeringly large number of people are casually tossed aside as a mere statistical anomalies. Oh please don't quote percentages. Please be one-of-those anomalies and tell me.

Pardon me for being a skeptic. Perhaps I don't exist.
Since 1986 I've been trying to get on to the census and the electoral rolls. Without using bribes and calling favors of people I know, I have tried every possible avenue that I came across including online campaigns such as Jago Re. Stood in queues, wrote letters, stood against walls for photographs - all in vain. The only thing I did not do is to become a fanatic, chasing them day and night. Incidentally, the same government lets me be an income-tax payer (pan card), a vehicle-regn-fee-payer, a home-registration-fee-payer - but nothing where it doesn't want money from me. No ration card. No voter id card. Not on census. If this is my fate, what do you think is the plight of the poor ID-less?
I have no better result from the UID project either (waiting since June 2011; many attempts at follow-up and escalation silently rebuffed). So I won't defend UID on this count.
Now for the other points I've been hearing frequently.

#1. UID & NPR are double the effort, double the cost. Hard to argue, except when you consider that enumeration is very different from enrollment. In order to achieve coverage, even in enumeration you need multiple visits. Even more so, with enrollment.

I don't know about elsewhere, but in Haryana, we pay the operators only upon successful de-duplication -- effectively curtailing artificial enrollment inflation; and keeping costs within reason. Good enough, to curtail a majority of the costs, I think.

Overall, there is some credence to this argument; though it is not 100% duplication as it is criticized to be. Theoretically, this could've been avoided; but in practice I am not so sure. I see the current compromise as a vast improvement over the pre-compromise situation.

#2. UID & NPR cause double the pain to the citizens. Yes it is avoidable. Given that UID has set a scorching pace and high standards of quality of execution, would the NPR set aside its pride and UID do a job it is designed to do? If only prejudices are set aside one might see as a neutral party would. Instead of re-defining a statistical exercise as a deterministic one, NPR might embrace logic and piggy-ride on UID (permanent enrollment centers among other ideas).

This would strengthen the hands of "UID is not really optional" logic of some opponents, but it is still a workable method. It would actually recognize that the NPR's work would never really be 100% done -- it would correctly be designed as an ongoing exercise. So is UID work, of course.

Bottomline: Citizens are definitely inconvenienced by the government's pig-headedness; but to blame the UIDAI alone on this, is nothing but hypocrisy.

#3. NPR is more secure! Of all the tall claims, this is the most laughable. Here again, a personal example might help illustrate. I am sure a vast majority of passport holders will also agree with this.
Ironically for all the famed MHA's well-suitedness on security, it was a good samaritan Sri Lankan national in Bangalore who held me by hand, took me directly into the police commissioner's office, introduced me and got my police verification done in a few minutes. Every other transaction related to my passport (required police verification twice) since then was done by touts without my presence anywhere on the scene. The police officer once came home 3 months after the passport did - to ask for money for verification. 
Yes, I know, passport is MEA's area; but what about the police? How do the NPR proponents expect much better security from other apathetic government employees? These are the same employees who routinely ask that 30+ year-olds be enrolled as eligible for old-age pensions; and intimidate any private sector employee who dared ask questions during biometric enrolments of the said pensions. The same employees who, in panic, declared "dead" even those pensioners with bank accounts (that were opened with biometric enrollment, incidentally) - when they were asked to remove duplicates. Mild protests by NIC officers and yours truly were set aside under the "due process and empowerment" garb.

No, it doesn't inspire any confidence -- unless you are a statistician; in which case, you can find some solace in that most out-of-process (paid-for or otherwise) verifications are also genuine anyway. For all others, the question remains, "how many illegal immigrants got through this allegedly watertight security"? How many genuine citizens are left out not because of security, but because of apathy?

Someone told me about audit trails being a strong point of NPR. And UID isn't? Audit trails mean something when a) the original job hasn't been routinely botched up; b) when people have mechanisms to complain and they use it; and finally c) someone actually looks at those trails and does something about them. All the govt officers I have seen are content to write file notes and DO letters - instead of doing something, anything about security. Including in the UID project. So here is one more area where I can't be accused of bias.
[edit @4-Feb: There is some credence to the idea of community verification apparently being used in NPR. Admittedly, it is a strong method, esp., in rural India - when collecting biographic data. But it leaves the door open for exploitation of the ID-less by the very same power-centers who excommunicate people or order honor killings. This could still be made to work: e.g., biometrics enrollment "anywhere" guarantees identity; other processes for dispute resolution on biographic data.]
Bottomline: Security arguments are lame, IMHO. If you are still worried about fake UID enrollments, please read my blog post Consequences of a fake UID

#4. Two outstanding issues with NPR - that I cannot comment on with the same feeling and authority as the above.
  • How is citizenship determined (inclusions and exclusions) in the light of all this? I am yet to finish reading all the relevant documents; as yet I am unconvinced. (yes, as suraiya95 pointed out, the citizenship issue is no longer central to UID vs NPR debates - though not everyone has left it behind just yet)
  • What exactly is the meaning of "NPR is mandatory"? It is mandatory for all citizens to enroll? Or mandatory for Census Dept to enroll all citizens? What happens if either party defaults? No clear answers yet; searching for them.
A note of balance before closing:
  • In all the above, please note that I did not rate UID as higher than NPR in anything other than the scorching pace and high standards of execution. The idea is not to vilify one in favor of the other; rather to put things in perspective.
  • In all my years in working with the government, I have had a chance to work with some very diligent govt officers - including some exemplary police officers and a few passionate regular employees. Most of them suffer silently.
Done correctly, pro-NPR and pro-UID proponents (me included) should bury their hatchets (and egos) and get down to doing a good job. There are people out there with outlandish arguments to derail both sides. Squabbling on this topic will get us nowhere.