Wednesday, December 17, 2008

Microsoft issues emergency patch

Microsoft (NSDQ: MSFT) is planning to release an out-of-band patch for Internet Explorer on Wednesday to address a critical security vulnerability that's being actively exploited. Microsoft Security Response Center researchers Ziv Mador and Tareq Saade said in a blog post, "Based on our stats, since the vulnerability has gone public, roughly 0.2% of users worldwide may have been exposed to websites containing exploits of this latest vulnerability." While that percentage may seem very small, it means that 1 out of every 500 IE users has the potential for being infected. According to reports, the exploit seems to have been sourced on sites hosted in Taiwan and Hong Kong.

This is the second time in 2008 that Microsoft has released an "out of band" patch, with the last coming just 3 months ago (it was the subject of my Oct 23, 2008 blog: Urgent Security Patch from Microsoft).

This issue first came to light on Dec 9, 2008, when Microsoft issued a very limited Security Advisory. At the time, the company indicated that they were "ware only of limited attacks that attempt to use this vulnerability." Since then, however, the alert has been updated at least four times, expanding the list of affected software to include several versions of IE... including IE7, IE6, IE6 SP1, IE5.01 SP4 and IE 8 beta 2. Virtually all of the versions of Windows installed by most users are affected... XP SP1 and SP2, Sevrver 2K3 SP1 and SP2, Vista with and without SP1, and Server 2K8.

At some point over the next couple of days, PCs that are set for automatic updates will get the patch and likely be rebooted. If your firm has not recently reviewed your strategy for managing Operating System updates, please contact me. It is well worth a small investment to have a good handle on these kinds of events.

Monday, December 15, 2008

Can the internet really handle mobility?

The base architecture of the internet contains two fundamental and significant flaws. One has been addressed, but one has not.

The internet relies on the basic assumption that every device must have a unique address. That includes every PC, every PDA, every GPS unit... everything. The current protocol for assigning addresses is called IPv4, and it allows for a finite number of addresses. Look at the accompanying graph and you see that we are rapidly approaching the upper limit of available addresses.

A new protocol, called IPv6, is meant to resolve this problem. However, a recent study indicates that less than 1% of IT executives say they are deploying IPv6. Furthermore, those respondents cite government mandates as the only reason they have gone through with the deployment. It is unlikely that IPv6 will be widely deployed until government or market conditions compel organizations to do so, making it very probable that this particular IPv4 limitation will have a significant impact on all of us.

However, even if IPv6 is deployed flawlessly across the world tomorrow, we still have a significant problem, especially as it relates to mobility. Once a device is assigned an address, the internet establishes a path to that device. And the details of that path have a significant reliance upon geography. As a device moves from one region to another -- in an airplane or a ship -- that path will need to be updated. The computing power required to keep track of all of those individual paths, and their changes is virtually incomprehensible.

Unfortunately for all of us, the fundamental design and development of the base internet was "good enough" for the purposes of the last 15 years. However, to paraphrase Jim Collins, we've allowed "good enough" to become the enemy of progress. I'm sure there is no simple solution. But ignoring this problem will invite significant disruption in our global connectivity.

Read the findings from Nemertes Research: Internet Interrupted

Sunday, December 14, 2008

Gartner identifies alternatives for off-shoring

Economic conditions being what they are, off-shoring is going to become an even more attractive option for organizations searching for ways to keep their projects going. Gartner (NYSE: IT) released a study last week that identified the thirty "best" countries for off-shore capabilities. India still tops the list. However, the rest of the top countries contained names that may surprise you.
  • Americas: Argentina, Brazil, Canada, Chile, Costa Rica, Mexico and Panama.
  • Asia/Pacific: Australia, China, India, Malaysia, New Zealand, Pakistan, the Philippines, Singapore, Thailand and Vietnam.
  • Europe, the Middle East and Africa (EMEA): The Czech Republic, Egypt, Hungary, Ireland, Israel, Morocco, Poland, Romania, Russia, Slovakia, South Africa, Spain and Ukraine.
Because of the criteria used in the study (see below), English-speaking countries like Canada, Ireland, Australia and South Africa will fare well. Using a Canadian firm may prove to be a very attractive alternative given the cultural similarities... and don't forget about the time differences.

This study did not seem to address outsourcing as it relates to operational tasks, like network maintenance and desktop support. For firms that have already gone as far as they can on project expenses, those areas will be logical targets for review.

Gartner's study also claimed that out-sourcing expenditures world-wide will have grown by 40% during 2008. I am suspicious of that number, and the report does not back it up with any details.

Gartner study criteria:
Language, government support, labour pool, infrastructure, educational system, cost, political and economic environment, cultural compatibility, global and legal maturity, and data and intellectual property security and privacy


Link to Gartner study: Gartner Identifies Top 30 Countries for Offshore Services

Wednesday, December 10, 2008

Keeping data secure from internal users

When conducting your annual security assessment, be sure to pay close attention to internal users with access to privileged information. A study conducted over the summer by a California-based security company identified several key findings regarding security breaches from the inside:
  • Security breaches not only manifest as mishandled data. In some cases, perpetrators targeted specific employees' personal information.
  • Data stolen by insiders is highly likely to be used in a geographically concentrated area, near (within 20 miles) the scene of the crime.
  • A majority - 69% - of stolen ID's were used to fraudulently obtain cell phone services.
  • Almost all of the resulting illicit activity occurred very quickly ... within 2 weeks of the theft.
  • The vast majority -- 80% -- of fraudulent activity was perpetrated online

What does this mean for you?
It means that, while perimeter defenses are important, enforcing sound security policies with staff and associates is absolutely critical. Secure passwords for internal applications (not just for network access) should be a requirement for all users, including executives. Creating local copies of sensitive information should be restricted. And all applications should be reviewed for hidden developer access.

Link to ID Analytics Press Release: Study Reveals Employees' Criminal Misuse of Stolen Identities