Friday, February 12, 2010

Svar fra Henriette! :-)

Nedenstående er mottatt pr mail og postet av meg som nytt innlegg (det fortjener det). Litt krøll med Google Accounts i dag + litt tidspress gjorde at det ble gjort slik som dette.  mvh. Per
----
 Hei Per

Takk for konstruktive innspill. 

Aller først: Jeg ville ikke ha kalt deg det ”security guy” med mindre du selv hadde omtalt deg som det i bioen din på Twitter http://twitter.com/thorsheim – og det var ikke vondt ment, ei heller ment for å provosere.  
Du har mange gode poeng. 

Til Henriette, fra Per

Hei Henriette!

Her er blogginnlegg fra meg, ref vår dialog på Twitter. Jeg antar at dialogen fra din side er på vegne av din arbeidsgiver. Mitt svar er mine meninger, punktum.

Uansett, jeg skulle skrive litt i forhold til mine erfaringer, ref din tidligere artikkel "Hvordan selge inn sosiale medier internt". Jeg svarte deg på Twitter med "Nå om dagen er det ikke mye behov for å selge det inn, men å holde det tilbake i kontrollerte former". Jeg følte meg vel litt stemplet da du svarte "the security guy", riktignok med smiley vedlagt. Derfor dette innlegget fra meg. :-)

Thursday, February 11, 2010

What's a wordlist?

"You should not...". An opening phrase commonly used by security people while talking to others, while "Thou shalt not..." is used somewhere else. I've said it myself countless times, still trying to change that.

Maybe we should do a competition; the first security person who can stay away from answering "no" or saying "you should not..." for a month gets an award? I guess it would be a tough challenge to many security administrators out there!

Tuesday, February 09, 2010

"Karsten experiences reality"

I just had to make this cartoon as well. Again to illustrate an important point to all the paranoid people out there. Please note that i made this with an enormous respect for the work conducted by Karsten Nohl , Chris Paget
(and probably many others as well). The work they've done on A5/1 is incredible (to me at least), and I'm still reading the even newer stuff on KASUMI (A5/3). I'll get back on both in later blog posts.
(Click the picture to see it full size).

Monday, February 08, 2010

Handmade graphics!

Enjoying a rather quiet evening, and - boom - a few ideas for a simple comic (?) strip enters my head. Well, not really a comic.. I don't know. Heavily inspired by xkcd I guess. I haven't made a drawing of any kind for ages, as far as i can remember. Can't draw anything really :-) For some reason this one came to mind, I just had to make it. Maybe another will appear as well very soon. Be nice, I'm trying to illustrate a point here (click for full size).

Saturday, February 06, 2010

Question: What about RFID security?

A good colleague of mine asked me if i could write something about RFID security. Sure! :-)

First of all; I'm not an expert on RFID, so if any readers of this blogpost should disagree, please tell me asap at per - at - thorsheim DOT net. Thanks! :-)

Wednesday, February 03, 2010

Criticism of PCI password requirements

In my daily job I work with standards such as PCI and ISO27001, as well as numerous other standards and regulatory requirements. Before proceeding, I'll repeat that the opinions expressed here are my own, period.

I saw Ben Rothke being quoted today (Feb 2nd) in this article at GovInfoSecurity.com along with Marcus Ranum of Tenable Security. In the same article there's also Bob Russo, general manager of the  PCI Security Standard Council. Bob Russo is quoted as saying "The standard is solid; there is nothing in the standard which needs change or requires to be addressed immediately". I'm not going to challenge any of them on their opinions in the article, since i fully agree with what they are saying, except the quote from Bob Russo here.

The Password Meta Policy

Light CaressPatterns. They're everywhere. The way you get dressed in the morning. The way you brush your teeth. The way you fold your underwear (or in men's case, the way you just toss them in a drawer, unfolded). The way you tie your shoes or neck tie. The way you start your car. The way you drive to work. The way prepare and eat food. The way you make love...

Whenever we do anything more than once, we tend to create patterns that dictate how we perform even the most minuscule task. Patterns are good. In fact, patterns are great! They help us predict how much time and effort each task will take, and they reduce the amount of processing our brains need to do to get a task done. They also makes it easier for others to predict how we will behave in a given situation, which in turn makes cooperation easier.
But sometimes, patterns just suck. Bear with me while I explain...

Tuesday, February 02, 2010

The Password Policy Fallacy

Greetings!
As I am shutting down my mostly inactive blog, I'll start my guest blogging career by reposting the few blog posts I made there. Here goes...


Dilbert.com

Well, that was funny! At least I thought so back in 1998, when I first saw that Dilbert strip. Like many others, I thought that there was no way we would ever subject ourselves to such a complex and draconian password policy. Little did we know then, that 11 years later, the brutal reality is that we wish our password policies were that simple.

New contributor to this blog

Quick announcement: my friend and colleague Jan Fredrik Leversund (KluZz) is joining my blog as a contributor. He is already helping me out with some really nice coding for password analysis, and we have some other projects as well for future blog posts.