Infosec Europe 2008 funded by Ministry of Silly Walks

Opinion
Apr 28, 20088 mins

For those of you illiterate in British comedy, the Ministry of Silly Walks is a fictitious British organization, which only existed in the world of Monty Python in the 1970’s.   The classical comedy sketch presents a man in need of funding to further develop his “silly walk”, yet due to the government’s economic constraints of financing Defense, Social Security, Health, Housing, Education and Silly Walks, he is told the Ministry of Silly Walks cannot help, due to their budgetary limitations…..and also because his walk was simply not silly enough.  (At the end he is offered a research fellowship)

What is the relevance of this skit to Infosecurity Europe 2008?  It appears that Britain’s “Ministry of InfoSec Training”, just as the Ministry of Silly Walks, is underfunded.  Actually, I have no idea how Britain allocates its financial resources for information technology, or to any other sector for that matter.  Furthermore, in no way am I criticizing their abilities in mathematics, computing or information security. (Some of you may have heard of Alan Turing). OK…maybe a little in bureaucracy.

Unfortunately advertised as Europe’s number one Information Security event, Infosecurity Europe 2008 took place during April 22nd through 24th.  I’m not sure if anyone else noted some the ridiculous press releases from the event, but I did.  I would like to take the opportunity to share some highlights, which when listed together, is nothing short of an InfoSec blooper reel.

Information Security Awareness Week starts Monday 21st April 2008.  Monday April 21st 2008 is the first day of Information Security Awareness Week.  The industry has created this week as a way to improve the UK’s understanding of information security by creating a number of initiatives.  “A big problem for companies and individual alike is the lack of awareness of information security.” Said Dr David King, ISSA-UK and Chair of the Information Security Awareness Forum, “It has to be a good thing for organisations to take opportunities to raise awareness amongst their constituents.  By combining efforts, the effectiveness of the delivery of messages can only increase.   Information Security Awareness Week 21st – 25th April 2008 gives organisations and individuals this chance, and the Information Security Awareness Forum is pleased to behind this initiative.”

So that’s how to improve information security….create an awareness week.  People would miss out on so many unknowns of our world if it weren’t for awareness weeksNational Handwashing Awareness Week, National Sky Awareness Week, and Squirrel Awareness Week, have helped me refocus on some very relevant issues in society.  If you’re an information security professional, and need to dedicate a week each year to be reminded of the importance of information security, then please consider a new career path.  In the field of InfoSec, every week is information security awareness week.  If you are not aware of this, spend some time appreciating the fact that you’re aware of anything, by observing National Brain Awareness Week. Fortunately, Exploit Awareness Week is coming to a close, thus ceasing all malware propagation and computer hacking for the next 51 weeks.

Infosecurity Europe launch online community for information security industry.    London 22nd April 2008 https://www.infosecurityadviser.com/ has been launched today by the organisers of Infosecurity Europe, this portal brings together the information security industry, to chat, share views and discuss the latest issues online.  Find out what people really think about the products they have used.  Ask the burning questions you have always wanted to ask to our panel of experts.  Search for jobs currently available in the market.

…another security website, well done!  Where else could one possibly find answers to the issues this site addresses? (I have a question about burning that I would like to ask their panel of experts) If you’re reading this blog, you’ve probably already been to several hundred security sites (I’m still working on my Google ranking).   Is this really necessary?  Is another “InfoSec community forum” or “place to foster one’s security knowledge” a measure that’s going to change anything?  Great use of time and resources.  As I have predicted before, with the amount of senseless registration occurring, we will run out of domain names before IPv4 address space.

Women 4 times more likely than men to give passwords for chocolate.  A survey by Infosecurity Europe of 576 office workers have found that women far more likely to give away their passwords to total strangers than their male counterparts, with 45% of women versus 10% of men prepared to give away their password, to strangers masquerading as market researches with the lure of a chocolate bar as an incentive for filling in the survey.

Crikey!  Somebody please tell me that this is some sort of joke.  While the headline speaks for itself, I have yet to see anyone else stupefied by this piece.  Were they studying information security or gender behavior?  With the answer being both, does this suggest some sort of sex-specific security training should be considered?  What’s next?  Security training based on race, religion and age?  I would also like to comment about their methods of “social engineering”, as described by Claire Sellick, Event Director for Infosec Europe. 

Offering a chocolate bar in exchange for what someone claims is their email password, is a comical example of social engineering, if one at all, to present at a security conference.  Considering that the validity of the passwords weren’t verified (if they did, then I hope they ran it by legal), than perhaps they were the ones socially engineered, having been handed random words and numbers to obtain free chocolate (an incentive only effective in England).  Regardless, this survey’s significance to the IT community is equivalent to the findings of a sixth-grade field trip.  Next year, forget the demonstration and invite Johnny Long, or just have the Ministry of Social Engineering shell out some shillings to hire Mitnick to speak.

Technology helps the police to crack down on computer theft and data loss.  Once Absolute Software is notified that a ComputraceOne equipped laptop is stolen, the ComputraceOne agent calls into the Absolute Monitoring Centre every 15 minutes to report its Internet Protocol (IP) address. With this address, the Theft Recovery Officer produces an evidence pack to give to the police, they in turn contact the Internet Service Provider (ISP), who is able to identify the address of the person using the stolen laptop allowing the police to recover the laptop and return it to its rightful owner.

Another Lojack for laptop technology…absolutely brilliant.  You could also just place a sticker on the bottom of your laptop that reads, “If found, please call… (your phone#)”.  When your laptop is stolen, you don’t call the police…you check what it’s going for on eBay.  Seriously though, the person who steals your laptop is usually not its new end user.  A hot laptop often finds its way into the hands of a hacker, who uses it as a “hacktop” for 20 minutes, before tossing it into the nearest large body of water.  Furthermore, this product is useless against incidents of sensitive data loss due to laptop theft. Even in the UK this can be costly. You don’t need to be online to clone a hard drive or harvest its data.  I was thoroughly amused by ComputraceOne’s “skeptics” page, where they’ve pretty much written a disclaimer stating that, although rare, there are some “master criminals” who might be able to bypass their system.  Regardless of what OSI layer Absolute Software uses to “trace” the machine, circumvention is a trivial task for anyone who’s read a few issues of 2600 and watched a couple episodes of Hak.5.  For those of you not versed in the dark art of BIOS hacking, print out one of these good articles on defeating Computrace (here and here), download the appropriate software, backup your BIOS, follow the instructions, and Bob’s your uncle.  What I use for theft prevention is essentially the equivalent to The Club for laptops– having a Windows 98 ME sticker prominently displayed.

For those of you who think my commentary on this year’s InfoSec Europe is a little harsh, remember that this was not an adult enrichment learning seminar called “Driving Safely on the Information Super Highway” (I took that last year).  This was a premier information security conference….well it was supposed to be.  I can offer you a different angle from which to view my remarks.  Imagine any of these being newsworthy at BlackHat, DEFCON, ShmooCon, or ToorCon.   On second thought….don’t.

And now for something completely different. 

Tell me to bugger off at: greyhat@computer.org