Skip to main content

Posts

Showing posts with the label Security

The Pandemic and the Security Paradox

  Ten years ago, I wrote a post titled: Cloud Computing and the Security Paradox . In this ancient post I argued that the claim of insufficient Security of the Public Clouds systems is based on a perception that what is not controlled by the Enterprise within its Data Center is less secured. However, Public Clouds Security was better than assumed  based on our perception.  Sometimes it was better than the Security of Data and Systems located within the Enterprise's Data center.  The COVID-10 magnified the Security Risks and the Public Clouds are more Secured than many Private systems. The enhanced Threats landscape   The COVID-19 Pandemic restrictions changed dramatically the way people collaborate and interact. The Security measures, Procedures, Policies and tools should be adapted to the new  interaction  style. Adaptation is a continuos Process therefore the vulnerability is higher than before COVID-19.  Main reasons for the higher vulnerabilit...

IBM z15 Mainframe First take: Mission Critical Hybrid Cloud

     I was a Junior IBM Mainframe COBOL Programmer in the beginning of the 1970's.  IBM 360 computers was the leading platform with SVS Operating System and afterward MVS Operating System. IBM Mainframe platform was a leading platform in the decade before I started my computers career. My roles were changed to a System Programmer, a Manager, a Consultant etc.  I worked on many other platforms and on multiple platforms environments. The IT industry was also changed and the IBM Mainframe was no longer the leading platform. However, unlike other proprietary platforms it survived.  Nine years ago I wrote a post about a new Mainframe released. The post was titled:  IBM z-Enterprise First Take: Data Center in a Box or Cloud Computing . IBM Mainframe was still a viable platform for large Enterprises. It should be noted that Public Cloud implementation replacing Core Mainframe systems by Linux and/or Windows based systems is not yet a vi...

Security threats: The real Authorization level of the CEO's Secretary

Few years ago I watched a bank's branch working process. Senior Bankers received a digital card which should be passed prior to executing operations requiring higher level of Authorization.  Other bankers has lower Authorization level. They did not receive these cards. They are prohibited from executing high level authorized operations. The Computerized Branch systems were built according to the defined Authorization levels. However, Senior Bankers were busy. When another banker asked a senior banker to perform an operation very often he gave him his digital card instead of executing the operation and asked him to execute the operation behalf of the Senior and Busy Banker. The real Authorization system was different from the formal analyzed, designed and developed systems. The real system authorized every banker to execute most operations. The formal system limited Authorization of non-Senior Bankers. This kind of dissonance between implemented systems and ...

Personal Devices Security lessons learned from my mistakes

A broad metal chain made of torus-shaped links Source: Wikipedia 9 years ago I wrote a post titled: The Chain is as Strong as the Weakest Link in the Chain . Based on my experience in a Penetration Test, I argued that human beings are the weakest link.  Many employees Security awareness is insufficient. Few employees are even motivated to breach Security.   As far as the home computing or the consumers computing is concerned, there is even less Security Awareness than in organizations. I am a Security and Risk Management expert, therefore I should be aware of Cyber and Security threats and I should refrain from being damage by these threats.  I am certainly aware of them, however I failed twice by ignoring a potential threat. This post is about lessons learned from my Security protection failures.  I love you - I hate you Many years ago I received an e-mail message from a friend. My friend is an IT expert,...

Is Mobile Banking a unique Channel?

iPhone 4s, showing Google Search Source: Hebrew Wikipedia Apple 's  iPad  (left) and ,   Amazon 's  Kindle Fire  (right) . source: Wikipedia The advantages of Self Service channels are well known in Banking, as well as in other verticals.  The advantages are depicted in a post I wrote two years ago. The post is titled:    The Marriage of Customer Centric and Multi-Channel .  Recently I read an article  titled: Consumers Addicted to Mobile Banking , written by Jim   Marous. According to the article "Mobile devices are transforming the way consumers conduct their everyday banking. Digital is disrupting existing banking paradigms and creating tremendous opportunities for new financial industry players". As far as the question: Is Mobile Banking a unique Channel? is concerned, no doubt that  Jim   Marous believes that it is unique because is is a paradigm change.   The article cites a survey ...

Digital Human Beings: Vision or Risk?

Artificial cardiac pacemaker Source: Wikipedia Wearable Computing is a new Buz and/or new Technology . The vision of human beings with permanent Computing device is beyond wearing it. The vision is of a an electronic chip implanted in our body i.e. Computing device inside every one or a Digital Human Being. Each Digital Human Being will have an IP address. An Internet of Human Beings beyond The Internet of Things . The device can record and transmit body measurements and control and regulate them. Unlike Wearables, e.g. Apple Watch, which you can get rid of, you are not able to get rid of a chip easily: you will probably need a medical operation in order to take it out from your body. Actually a limited version of that vision is already a reality. For example, the Artificial cardiac pacemaker , which maintains an adequate heart rate. Wearable cardiac pacemakers are available since 1958. Modern cardiac pacemakers are implantable and are externally programmable.  S...

Cloud Computing and the Security Paradox

Cloud Computing and the Security Paradox On September, 14th  I participated in a local IBM conference titled: Smarter Solutions for a Smarter Business. One of the most interesting and practical presentations was Moises Navarro's presentation on Cloud Computing . He quoted an IBM survey about suitable and unsuitable workload types for implementation in the Cloud. The ten leading suitable workloads included many Infrastructure services and Desktop Services. The unsuitable workloads list included ERP as well as other Core Applications as I would expect (for example, read my previous post SaaS is Going Mainstream ). However, it also included Security Services, as one of the most unsuitable workloads. On one hand, it is not a surprising finding because Security concerns are Cloud Computing inhibitors, but on the other hand Security Services are part of infrastructure Services, and therefore could be a good fit for implementation in the Cloud. A recent Aberdeen Group 's Research No...

Your private Data is Unforgettable

Borges in 1951, by Grete Stern Picture Source: Wikimedia Commons   On June 14th I attended the Israeli Wikipedia Academy 2010 conference in Tel-Aviv University. The interesting conference focused on Wikipedia and Wiki technology usage in Academic context and schools. Most of the presentations focused on Wiki or Wikipedia research, usage and projects. The main theme repeating in most presentations was that Wiki based Collaboration and Participation changes the Game's Rules. However, in some contexts changing the rules is very useful, while in other contexts the usefulness is questionable. Changing the rules implies new challenges to all process participants such as Users, Content Creators, Managers, Auditors etc. I already described these challenges in previous posts: Wikipedia the Good the Bad and the Ugly and Web 2.0 for Dummies – Part 7: Wikipedia. A Keynote Presentation on Remembering and Forgetting In my opinion, the Keynote by Prof. Viktor Mayer-S...

The Chain is as strong as the weakest link in the chain

The title describes a Security approach. According to this approach the easiest and most plausible Security breach is by usage of the weakest link. Lessons learned from few Penetration Tests I conducted, support the cited above approach. It is true that there is no way to assure absolute Security (For deeper explanation why you can look at a well known security Guru, Bruce Schnirer's web site ). A ny Security mechanism is breakable by someone who has expertise and spends a lot of resources (including time). But it is also possible to breach Security without expertise and by spending only few resources for a very short time: just exploit the weakest link . As part of a Penetration Test, I always looked for simple unsophisticated methods to penetrate instead of penetrating by usage of very sophisticated methods. These methods could be used by anyone, unlike the sophisticated ones, which could be used only by a limited group of very talented experts. ...

Cloud Computing Challenges and Risks

This post complements the post Cloud Computing: Hype, Vision or Reality? The previous post describes the presentation by Pini Cohen STKI Vice President in a in the 23 rd meeting of the SOA Forum of the Israeli Association of Information Processing . This post describes the interesting discussion during the meeting, which was focused on Cloud Computing challenges and risks. Security Often cites as the major risk of Cloud Computing and verified as the leading cause for avoiding Cloud Computing in surveys. One of the participants (a Security expert) argued that Security is partially real issue and partially psychological issue. The image of less controlled environment (Cloud is less controlled by a customer) is an image of less secured environment; therefore we should expect resistance to Cloud Computing. My take The issue is not only Security. It could be also an issue of Privacy. For example, usage of Infrastructure as a Service (IaaS) for backups by a home c...