Monday, August 11, 2008

Protecting Your Online Trading Account

Among the many entertaining stories in the book "Stealing Your Life" (mentioned below), Frank Abagnale relates the story of an online brokerage customer who has their account taken over by a hacker and used to trade options in Cisco Systems, to the tune of a $40,000 profit.

Now, if the story stopped there, you can imagine it becoming a modern-day version of "The Elves and the Shoemaker".

"I swear Honey, we had 2,000 Cisco options when I went to bed, but when I woke up, they'd all been sold - for a net gain of 170%!"

Unfortunately, like most stories involving identity theft, the story doesn't stop there. The thief isn't a charitable elf. He performs a risk-free set of trades, cashes out, and leaves you with those GM and Lucent shares you bought eight years ago.

Yes, you can go to your broker and explain your loss, and most of the time they'll believe you. But don't think this is the first time your broker has heard the "it wasn't me - I was hacked" story. Be prepared to have all your documents prepared, and get ready to prove your case.

Or better still, stop it from happening before it starts.

This is both harder (and, ultimately, easier) than it sounds.

Harder, because a lot of people try and apply enterprise security solutions to situations that are much different.

Easier, because it is possible to harden the user authentication mechanism against attack, so that user credentials are not easily stolen. You just need the right approach.

A lot of on-lines banks and brokerages have recently started experimenting with expensive physical tokens and "virtual keyboards" - on-screen keyboards that feature randomized, repainted numbers that users can click on with a mouse to gain access.

Both these approachs are seriously flawed.

Let's look first at Virtual Keyboards. Let me say this loud and clear: virtual keyboards are 100% useless. If you're infested with malware created by a hacker with an IQ even slightly above room temperature (and more than half of you that are reading this are infested with malware that matches this description), your randomized virtual PIN entries are going to get captured - in the form of JPG screen shots.

Print. Print. Print. Send as email (to hacker).

Hardware-based tokens can be equally problematic. It's not that these sleek-looking devices don't do their job and create credentials that are unfathomably hard to guess - they do. That isn't the problem.

The problem is that these credentials are susceptible to being stolen by hackers en route to the login page, via very simple forms of the Man In The Browser attack. See my earlier post on this subject a couple of months back.

So what's an online brokerage to do, if it wants to protect its customers, aside from keep paying its SIPC dues?

The technology issues seem overwhelming. If someone were to dream up a technology solution for adoption by online trading professionals, it would, on the surface, appear complex.

It would, out of necessity, include a combination of system-level command handling and file hardening approaches, desktop virtualization, a locked-down non-standard browser with update and plug-in controls, secure DNS infrastructure, secure application update channel, and the best in current third party anti-phishing systems. And all of this would have to work seamlessly and simply.

I'll spare you any further build-up: we've built this. The solution we've created to protect consumers against online trading fraud is called SafeCentral.

Authentium SafeCentral is currently being evaluated by online brokerages on four continents, and our first release went live just over three weeks ago at Firstrade, the top-ranked US online broker (Consumer Reports).

"Stealing Your Life" by Frank Abagnale

Frank Abagnale is best known for writing a rip-roaring memoir that was adapted into the Steven Spielberg/Tom Hanks/Leonardo DiCaprio movie "Catch Me If You Can".


The scenes where Frank impersonates a PanAm pilot are my favorite - I think of them everytime I travel through MIA/Miami.

I contacted Frank (played by Leonardo DiCaprio in the movie) right after seeing the movie, to see if there was a way we could team up to fight Identity Theft.

At the time, Frank was helping to put together PrivacyGuard, now one of the most widely-deployed solutions on the market. We decided to keep in touch, once our respective identity protection products - PrivacyGuard, and SafeCentral (then called VirtualATM), launched.

As it turns out, Frank's product beat me to market by three years. And, as I recently found out, he followed up the launch of PrivacyGuard with an outstanding book on the identity theft problem.

Called "Stealing Your Life", the book is one of the best-researched and practical books on identity theft yet written - and easily the most readable.

As in "Catch Me If You Can", Frank is able to detail what criminals are thinking as they're plotting to steal your money. The stories he has to tell in "Stealing Your Life" are disturbing - in some cases, appalling.

I'm going to pick up on a couple that I have some additional color on and share them over the next week or so. In the meantime, I strongly suggest you go out and find this book, or order a copy through Amazon.

You won't find a more informative book on the wide-ranging forms of identity theft out there, and you certainly won't find another written by a former confidence guy.

If you'd like to review our own solution to identity theft, Authentium SafeCentral, just head over to our site and download the free trial version.

Saturday, August 9, 2008

ID Theft: What is a 419 Scam?

The term "419 scam" is synonymous with phishing and identity theft. I personally receive about a hundred million dollars' worth of these emails a day.


The variations are endless. The scams range from the baiting of the greedy and needy ("I AM THE FORMER CFO OF A LARGE BANK AND I HAVE 9.5 MILLION DOLLARS THAT I WISH TO SHARE WITH YOU") to out-and-out scare tactics ("SOMEONE HAS PAID ME $5,000 TO KILL YOU").

But what does "419" mean?

"419" refers to the name of the section of the Nigerian Criminal Code used to prosecute these crimes, when they are prosecuted. The section, one of several sections within Chapter 38 (Obtaining Property by false pretences; Cheating), reads as follows:

419. Any person who by any false pretence, and with intent to defraud, obtains from any other person anything capable of being stolen, or induces any other person to deliver to any person anything capable of being stolen, is guilty of a felony, and is liable to imprisonment for three years.

If the thing is of the value of one thousand naira or upwards [about seven $US], he is liable to imprisonment for seven years.


It is immaterial that the thing is obtained or its delivery is induced through the medium of a contract induced by the false pretence.
The offender cannot be arrested without warrant unless found committing the offence.

A quick read of a half dozen Nigerian newspapers today turned up very few stories involving the successful prosecution of 419 email scammers. Attempts to pass and prosecute a law in Nigeria targeting computer crime in general, such as the above, have mostly failed.

This inaction at the government level has reduced many intelligent and proud Nigerians to despair. One London-based Nigerian expat, tired of the association with Nigeria and email scams, blames lack of government investment in Nigeria's younger generation:

"What has the local, state or federal government done in the last 20 years for example to prepare for the future of this generation of internet rats? What have they done or what are they still doing other than stealing, looting and gallivanting like nonentities?"

Many other in-country commentators agree. About the only positive seems to be the fact that voices are at last being raised. Maybe change (and a decent law) is in the air.

Note to recipients of 419 scam emails: 419 scams are unbelievably easy to avoid. If you receive an email from anyone, claiming:

a) you won a lottery you didn't enter
b) you have the same last name as the heir to a fortune
c) you are targeted for murder (unless you pay up)
d) you will have "bad luck" if you don't pass on the email
e) you are otherwise in line for a windfall

...you have just received a scam email of the variety commonly known as a 419 scam. Don't respond to strangers offering money by email. Don't get tricky and try and "scam the scammer" like some have attempted. Delete the email.

There is a much better chance you'll get five dollars in a card from your grandmother on your birthday that you'll see any money from one of these emails.

Note: I found a curious story tonight while researching this post. Rumor has it that Mary Winkler, the Tennessee woman convicted of shooting her 31 year old preacher husband in the back, owed $17,500 to the Nigerian "Yahoo Boys" (the local Nigerian lingo for 419 perps) at the time of the murder.

You can read more about this story, and others, here.

Friday, August 8, 2008

Counting Sheep

Brian Krebs of the Washington Post wrote a nice article today about how sometimes security industry folks don't follow their own rules.


In fact, it turns out that security professionals can be pretty bad at remembering not to send their usernames and passwords over non-encrypted wireless networks - of the temporary type typically slapped up at conferences.

Thank goodness none of them were in a room full of hackers when their credentials were sniffed*.

You can get to Brian's post on the Black Hat "Wall of Sheep" here. The part where some of the people change their credentials after finding out they've been outed (even thought they are still connected to the same non-secure wifi network) is, well, illuminating.

*That's a joke, folks. The Wall of Sheep experiment takes place at every Black Hat conference, and always, unfortunately, they post similar results.

Bring Back "I Am Rich"

Dan Frommer of the Silicon Valley Insider thinks the Apple iPhone "I Am Rich" application that Apple pulled from their store today is "for jerks" because it costs $1,000 and "doesn't do anything" except twinkle.


I disagree entirely.

I think Armin Heinrich, the developer of "I Am Rich", is possibly smarter than just about any other developer on the iPhone platform. Not only has he created the first $1,000 program, he's come up with an app that acts exactly like a Rolex watch or a Gold Card, except in software.

Yes, you got it. "I Am Rich" meets a need that is as old as time: creating attraction by proxy.

Let's compare: Real gems are typically purchased from trusted brands/stores. Real gems feature hefty price tags. Real gems do nothing - except twinkle and assist in attracting mates, which in turn helps us, their owners, propagate the species.

Yes, I know, anthropologists and economists would have us believe that people also buy gems and precious metals in order to make their wealth more portable - but I think people also buy gems for the same reason people buy silver BMW convertibles and Apple iPhones: to show off/try to be more attractive.

Think about it. What need does the iPhone really serve, aside from creating a sense of status? Do we really need all those sleek, cool design components, just to make a call? If it's all about "personal communications" and "productivity-based applications", why isn't there a brown-paper-bag version? Why is the iPhone always on display?

The answer, as everyone knows, is that "cool is attractive" - and being cool is as important to us humans as shiny chrome objects are to bottle cap-collecting magpies.

"I Am Rich" may indeed be crass, and it may be a little too "in your face" for some (or possibly many) iPhone users - but that doesn't mean it deserves to get yanked from Apple's store.

One of the benefits of living in a free society is that you get to choose what kind of jerk you want to be. In revoking this application, Apple has acted more like an old-style communist dictatorship than an innovative, capitalist-led technology company.

Apple should recognize what's going on here and bring back "I Am Rich". It doesn't matter what people think of the app - revoking it wasn't cool, and will just create unfair competition for a space that Mr. Heinrich had targeted well - almost as well as Apple itself.

Thursday, August 7, 2008

DNS - The Basics Explained

I realized today why consumers sometimes get so fed up with news involving Internet security alerts: it's because sometimes the basics and the acronyms are not explained, which makes the rest of the news story hard to follow.

Take, for example "DNS", as in the recently-announced "DNS flaw" - currently the subject of much current news and speculation.

What, exactly, does a Domain Name Server do?

Let's start by explaining the concept of a "domain" on the Internet. The modern word "domain" originates from the Latin word "dominion". It's most commonly used by people to refer to their house, corner office, or area of expertise.

If you live in a block of condos, your domain is the condo in which you live. If you live in a house in the suburbs, your domain is your house. Your "domain" is simply your part of a much larger area - i.e. your condo, vs. the entire development.

Likewise, in Internet terms, a "domain" in simply a sub-section of the Internet.

The largest "top level" domains (i.e. the suburbs) use ".com", ".net", ".org", ".gov", ".edu" and similar suffixes to identify the type of top-level domain (.gov = government).

The next level down (i.e. your condo development) is usually the name of a company, organization, or government agency that is part of the top-level domain.

For example, the domain name "authentium.com" refers to the ".com" top level domain, then to the part of the Internet that is under Authentium's control. "Google.com" refers to the ".com" top level domain, then to the piece under Google's control.

Put another way, when you type the domain name "google.com" into your address bar, you are saying, I want to 1) Go to the commercial section of the Internet, then 2) Go explore the domain of the company Google.

"Finance.google.com" refers to a sub-domain of Google relating to finance. The smallest domain is on the left: The finance sub-domain is smaller than the Google domain. The Google domain is smaller than the ".com" top-level domain.

Now you're probably reading this, thinking "I thought I heard today that there was a problem with Domain Name Servers. How could there be a problem? I just type in a web site address, and so long as I spell the domain name correctly, I connect, right?"

Unfortunately, the answer is no.

The definition I just gave you is how us humans look at domain names. Computers - more specifically, the web servers that host the web pages of Authentium and Google - use a different form of domain name: a set of numbers called an Internet Protocol address, or IP address.

Human-version domain name: "google.com"
Computer-version domain name: "72.14.207.99"

Which is where the Domain Name Server (DNS) comes in.

DNS servers, or Domain Name Servers, are simply translation devices. What they do is take your request for "google.com" and turn it from "google.com" into the IP address 72.14.207.99, so that your request can be understood by the computers that form the Internet and sent to Google's domain for processing.

As you can imagine, translating the names of all the web sites we type in every day into numbers is a massive task - and that is what the ten million or so DNS servers do every day.

Sometimes, to make things faster, the servers store these translations. It is not uncommon for even small-sized Domain Name Servers, like the kind you might have sitting in a rack at your office, to contain thousands or even millions of similar "translations" in storage.

The problem with this approach is that hackers can make a ton of money by successfully changing the "translations". Typically, in a DNS hack, the hacker just takes your request for mybank.com, changes the IP address, and re-routes you to a look-alike site, so he can steal your username and password.

Now, the effort required to hack a DNS server is not trivial, and not likely to be successful with respect to large, well-organized organizations. But the recent announcement of a major flaw in the underlying DNS software has even seasoned pros working late into the night to get their fixes in place.

The good news is - since the announcement yesterday of the full extent of the "Kaminsky DNS flaw", a majority of the world's servers have been patched, including 70% of Fortune 500 companies.

The other good news is, our product SafeCentral provides a really nice set of protections that secure DNS requests and bypass the standard DNS infrastructure. If you're worried, give it a try. It also stops key-loggers and screen-scraping spyware.

Note: If I didn't do a good job explaining these basics, email me, and help me improve this post. The shorthand in here (yes, I know the Google domain includes multiple IP addresses, etc, etc) is by design - I just want to help folks understand the basics of DNS so they can get a handle on what this flaw means.

If you want to dig deep on DNS, head over to Kaminsky's blog at DoxPara Research.

VIP Laptop "Rematerializes" in Office

Verified Identity Pass issued a press release today stating the they have "found" the laptop we reported was missing with over 33,000 personal profiles on it.

According to the firm's head of business development, the laptop was discovered in the office in which it was lost over a week ago. An "initial investigation" has revealed no tampering with the data.

Comments out on the blogosphere this afternoon range from the sarcastic ("that must be one a heck of a large office") to the suspicious ("Probably was put back after stealing the information" and "I would not use that computer - there is probably a hacker chip installed in there now") to the incredulous ("How do we know it's even the same laptop?").

I'm going with the "Gordian Knot" approach on this. I'm assuming VIP simply misplaced the laptop and found it sitting under a paper file somewhere. I am going to assume there was no attempt at cover-up, or no attempt to deceive -because that is the simplest explanation.

But I have a feeling that we're going to hear a lot more of these "discoveries" in future.

"Rediscovering" a laptop that has been reported missing with your entire company's customer base on it - after it has been missing a week - is a lot less painful than watching the story grow and your business shrink.

I am happy to assume this didn't happen in this case, but I'm quite certain folks looking for a quick solution in future will remember this approach, and apply it - safe in the knowledge that like me, most people will accept the news at face value.

Note: I originally read this occurred in NY. It didn't - it happened in SFO.

DNS Flaw: Two Practical Things You Can Do

Dan Kaminsky got two standing ovations at Black Hat yesterday - one for his detailed and thorough explanation of the DNS flaw he discovered earlier this year, and a second ovation for his handling of the matter.



He should get another ovation for media-savvy. Thanks to Kaminsky's diligence, 50% of DNS servers tested on July 25th were shown to be patched to the required levels - up from barely 15% on July 7th. 70% of Fortune 500 companies were also passing the test, as of last night (push "play" on the video above for Kaminsky's animated "DNS patch status map").

Also, by building up the focus to the August 6th announcement, and leaking out just enough information to push people to the right textbooks, he ensured that not only were the IT teams up to speed, but the journalists were as well.

But now that the applause is died down, we need to provide consumers with some practical answers.

Some of the other announcements - of flaws in various forms of VPN software and the Secure Sockets Layer (SSL - the technology that powers the padlock in your https:// secure browser sessions) were very well explained in the mainstream press reports I read last night.

But I wouldn't be surprised if there are a lot of consumers out there reading all this and saying "What the... ?" and wondering the best way to get to their bank or brokerage this morning. Let me suggest two sites: Kaminsky's own "Check My DNS" test page, and Authentium's very own SafeCentral.

If you're worried about the DNS you're using right now, head over to Dan's personal blog and click on "Check My DNS". It will run a quick test on the DNS server upstream from you to see if the patches are in place.

That check isn't going to fix anything, but it is a useful start. If you're interested in protecting your local HOSTS file and making sure that *all* of your requests are securely handled, I would strongly suggest you head over our site at www.safecentral.com and download the latest version of Authentium SafeCentral.

SafeCentral was designed to provide strong protection against many of the hacker exploits mentioned yesterday. PC Magazine and IRM have both tested our DNS security, and they say it worked 100% as advertised.

SafeCentral protects your local HOSTS file, blocks key-loggers and screen-stealers, and sends all web site requests to a secure DNS service.

Note re the patch map from www.doxpara.com: Red = Unpatched; Yellow = Patched (but NAT is screwing things up); Green = OK.

Note: Doxpara is getting *lots* of traffic this morning. Patience may be required to get in.

Wednesday, August 6, 2008

33,000 Customer Profiles Lost by TSA Vendor

This morning, it was announced that VIP, one of the vendors behind Clear, the smartcard that allows frequent travelers to breeze through TSA-controlled security lines at airports, lost 33,000 personal profiles of its VIP customers when one of its laptops went missing.


The 33,000 customer profiles were *not* encrypted.

Despite the company having adopted an internal policy of always encrypting important data (i.e. like customer profiles), the missing profiles may apparently be freely viewed by identity thieves, terrorists, or pawn shop owners with equal ease.

Which means that whoever now has this laptop has exactly the personal profiles most useful in engaging in acts of terrorism. A more perfect treasure trove of targeted identities could not be imagined.

I don't know about you, but I'm really tired of hearing about vendors that put data on laptops and then lose that data - data that consumers have entrusted to them.

I'm also tired of hearing vendors say "we don't think anything bad is going to happen because of our mistake". Yeah, right.

There is no reason on this Earth that anyone should ever download their entire unencrypted database of customers onto a laptop. None. Zip. Zero.

Congress - want to pass a new law? You should make this kind of action - carrying around unencrypted customer profiles on a laptop - subject to a massive fine, and I mean massive. That might start to clean things up.

Though somehow, I doubt it.

Tuesday, August 5, 2008

"TJ Maxx 11" Charged With 40 Million Card Theft

A group of hackers that spent several months downloading 40 million consumer credit card profiles from horribly insecure wireless networks operated by TJ Maxx have allegedly been found, arrested and charged.

Yes, I know: "TJ Maxx Eleven" isn't about to be turned into a movie. But it certainly has the makings of one.

The hackers, which took turns monitoring wifi traffic from cars parked outside the stores, found security was so lax on TJ Maxx's wifi networks that they allegedly left notes for each other in plain sight in the databases they hacked into - informing their cronies which records still needed to be uploaded/stolen.

"Dave, I'm fresh out of Doritos and trail mix... suggest you start downloading the credit card records from the August purchases table while I reload..."

Database hacks are horrible because consumers are entirely at the mercy of corporate policy - there is almost nothing they can do aside from buying insurance.

And getting hacked doesn't just mean your credit is up for grabs - it creates inconvenience, and potentially large costs for banks and credit unions who must reissue new cards.

The hack was allegedly the biggest ever. The DoJ is calling it an international conspiracy and says that nationals of The Ukraine, Belarus, China and Estonia are responsible. These guys will be going away for a long, long, long time.

The TJ Maxx IT security guys? Still at large.

Note: TJX Corp is a large holding company and operates the TJ Maxx chain, plus Barnes and Noble, BJ's Boston Market, Dave and Busters, DSW shoe stores, Forever 21, Office Max, Sports Authority and the Wholesale Club.

I'm sure they have a different group running IT security these days. Or at the very least, a much larger security budget.

Sunday, August 3, 2008

Websense: 60 of Top 100 Sites Pushing Malware

Last week, Authentium partner Websense published some rather interesting statistics about what users can expect to find on the top-ranked web sites. In summary, what users can expect to find, at 60% of these sites, is malware.

"60 percent of the top 100 most popular Web sites either hosted malicious content or contained a masked redirect to lure unsuspecting victims from legitimate sites to malicious sites - Websense Security Labs."

Note that Websense in not just saying "60 leading websites" - it is saying specifically that 60 of the top 100 ranked web sites either directly or indirectly (i.e. via a link) delivered some form of malware or link to malware - to their visitors.

Part of the reason for this may be that 45 of the 100 web sites that Websense Security Labs studied support user-generated content, such as the posting of images, videos, audio files, messages, comments, email attachments, etc.

Unsurprisingly, given the rise we've seen in sophisticated key-loggers and screen-stealers in the wild, the Websense Threatseeker Network found that 29% of the malware discovered involved a key-logger, screen-stealer, or some other form of data capture malware.

More statistics can be found at the Websense site.

Beyond FDIC: Ideas for Protecting Your Cash

Most consumers and small business owners in the US are aware that the FDIC insures individual accounts up to $100,000. That is the figure that each account holder is insured for in the event of a bank failure, such as the one that just occurred at IndyMac Bank in California.


FDIC insurance provides adequate protection to consumers with total cash assets below $100,000. However, retirees and small business owners need to look at things a little differently - that $100,000 limit may not be nearly enough if your retirement savings are $1,000,000, or the monthly payroll for your landscaping business is $200,000.

I saw a number of worried-looking retirees (and possibly a few landscapers) standing behind the television reporters in the IndyMac parking lot as they announced the failure.

Hopefully, some of these retirees had split their funds into multiple sub-$100k accounts at different banks, or, if a couple, split their deposits into separate joint accounts registered to the couple, single accounts registered to the husband, and another single account registered to the wife.

However, the looks on the faces of the folks I saw on television tells me otherwise. I think it's fair to say that a lot of people who saw the same images are looking to take action. If you're one of them, here's some ideas:

One option is the one I just mentioned - if you have $200,000 in a single account at a single institution, you may want to consider splitting it between yourself and your partner, or moving half to a different institution.

Another option that concerned retirees and small business owners might also wish to consider re insuring larger short-term cash deposits is CDARS. CDARS is a program that enables small businesses to split larger (e.g. >$100k) deposits into individual, FDIC-insured CDs.

CDARS was founded in 2003 by Alan Binder, former Vice-Chairman of the Federal Reserve. Around 2,200 banks in the US now offer this option. The program offers insurance for amounts up to $50mm - but even small business owners/sole proprietors with much smaller balances of working capital should take a look at CDARS.

The typical term of the CDs is four to six weeks. The CDARS web site is here.

Another investment category that concerned consumers need to keep an eye on is their stock portfolio. Because it is so convenient, a majority of consumers now trade their portfolios online. But accounts with online brokerages are not insured by the FDIC.

If you have $100,000 on deposit at one of the leading brokerages, you are SIPC-insured by a private non-government group. How much insurance is offered depends on the individual brokerage.

Many online brokerages offer 100% coverage, but the system has not yet suffered a test involving the closure of a large brokerage. Read the small print carefully - and look at their balance sheets - before you sign up.

Finally, one additional piece of "insurance" that retirees and small business owners should definitely consider is using Authentium SafeCentral - especially while banking or trading online.

The criminals behind last year's multimillion dollar thefts from online brokerages used stolen user credentials to steal $26 million in cash from online accounts in 2007. SafeCentral was designed to prevent that kind of fraud.

SafeCentral protects consumers and small business owners from key-loggers and screen-stealing malware better than anything else we've tested. If you're worried you and your funds may become a target, just go the web site: you can download SafeCentral for free.

Note: PC Magazine just gave SafeCentral an excellent review. Check out my blog post for the link.

Note: I'm not a financial advisor, or a banker - I'm a consumer and small business owner, just like you. I suggest you check out the above suggestions with your bank - they will undoubtedly have some excellent additional suggestions.

Thursday, July 31, 2008

"Same Last Name" Email Scam

The Sharp family woke up to some some good news this morning: a private investigator who works with a private bank in the UK has offered to share a fortune with us - because we are lucky enough to have the same last name as a deceased client.


In his email to "undisclosed recipients", the aforementioned P.I. says that he is "not a criminal", which is good to know. He is, apparently, doing this because "the dynamics of my industry dictates that I make this move."

Whatever.

Folks, if you receive an email from someone - anyone - saying they have found a pile of money previously owned by a deceased person with the same name as you, don't reply. It is a scam.

If someone says in an email that they have been hired to kill you - but will forget about it if you empty your bank account in their direction - don't reply. It is a scam.

If a bank or credit union asks you to change or verify or transmit your login credentials via email, don't do it. It is a scam.

An unfortunately large number of people are still are replying to these emails - and many are still being taken for a ride, to the tune of hundreds or even thousands of dollars.

I followed one of these threads to its natural conclusion a couple of years ago, and the guy on the other side - "a UK barrister" was pretty slick. I can see how to some folks a deal might just seem real enough to invest a few hundred bucks.

Bottom line: if an email from a stranger - or an institution - surprises you in some unexpected way, delete it, or if you bank with the institution in question, call customer service before clicking on anything in the email.

Monday, July 28, 2008

Vista Not "New Coke"

Okay, I've been on Vista on and off since the start of the year, and as a regular user of more than three applications, I feel qualified to comment about the comparison Forrester is making between Vista and New Coke.


My two cents: New Coke sucked. Vista is just fine.

I actually have bigger problems with the Office redesign than I do with Vista - and suspect that Vista issues may not be the only reason behind the fact that 87% of corporate PCs (and I presume laptops) are still running XP (Forrester).

Whoever redesigned Office did so with little thought to the fact that the majority of new computer users would be buying laptops with wide-screen formats. And with less thought to the fact that the canvas is the most important part of the interface.

It isn't so much a CPU hog as it is a real estate hog. The design shows the designers were a lot more enamored with the application than they were with any ideas about what magic might be done with it, in the form of documents, presentations or spreadsheets.

But Vista is a different story. After several months of using it, I would not go willingly back to XP. I like it.

Stylistically, I like the way the windows open and close. I like the Aero interface. And yes, I've even gotten used to the redesigned treeviews - to the point where the internal window "jog" has actually started to feel intuitive.

In terms of performance, on my machine - a Sony Vaio with crapware removed - Vista runs really fast, and starts up faster than any of my previous machines running XP. All my plug and play game and music stuff seems to work fine. No networking issues.

What's not to like?

As it turns out, plenty. But some of that hatred is misplaced. According to the results of the Microsoft "Mohave" experiment announced last week (in which XP users were shown a new test "post Vista" operating system and proclaimed it to be great), users may tend to react more to "fuzz and buzz" than to actual experience.

Maybe the Vista team should take the Mohave experiment on the road...

Note: Full results of the Mohave experiment are due to be posted tomorrow here. Kudos to Microsoft PR folks - great job in thinking up this idea in the first place, and getting the word out there.

Saturday, July 26, 2008

U Michigan: 75% of Bank Sites Flawed

Yesterday, data presented by Carnegie-Mellon University demonstrated some of the issues that stand in the way of creating the safe Internet experience that online banking consumers are seeking.


The data, based on a University of Michigan study conducted by Atul Prakash, a professor in the Department of Electrical Engineering and Computer Science (and the author of over fifty papers in the field), and two of his doctoral students, Laura Falk and Kevin Borders, examined 241 sites in 2006, including the sites of major financial institutions.

Prakash apparently initiated the study after noticing that his own interactions with financial insitutions on the web were less than secure.

The results are worthy of study. As re-reported on Friday, Prakash and his team found that three quarters of consumer banking sites suffered from some form of fundamental design flaw impacting security.

"To our surprise, design flaws that could compromise security were widespread and included some of the largest banks in the country," Prakash said.

Some of the flaws uncovered by Prakash and his team included:

Placing "secure" login boxes on insecure pages

47% of banks were found to be guilty of this particularly transgression. Doing this is rather problematic in that it exposes user names and passwords to hackers using man-in-the-middle attacks, or siphoning data off wireless networks.

Hosting of support/help/security advice on insecure pages

55% of banks presented their support pages within a non-secure environment, allowing hackers to easily intercept support request or even set up their own spoofed web pages and call centers using DNS redirects.

Non-Domain Redirects

Prakash found that 30% of banks surveyed sent their customers to other sites in order to facilitate transactions. Unless these other sites utilize some form of identity federation or shared trust, this practice is *not good*.

SSNs and Non-Secure User IDs

Prakash and his team faulted sites utilizing social security numbers and email addresses as login credentials s user ids for exposing this information to hackers via man-in-the-middle attacks. I agree with this "outing" of this practice.

Weak Passwords

Given the ease of validation methods, allowing weak passwords to exist isn't a great idea, and doesn't safe anyone any money in the long run. According to Pradah, 28% of the sites surveyed allowed weak passwords.

Insecure Messaging

31% of the web sites of financial insitutions surveyed by Prakash were found to be emailing statements and/or passwords to customers.

None of these design problems are issues if consumers do their banking using Authentium SafeCentral, but all should be examined/fixed anyway. The cost of fixing each of these issues is minor; the benefits are potentially significant.

The fact that we are able to protect against the exploitation of these weakenesses should not be used as a reason not to fix them. Consumers will on occassion need to use a non-secure browser. Banks should perhaps examine this list for indications their own sites could be improved.

Friday, July 25, 2008

China: 253 Million Internet Users and Counting...

Ten years ago, before co-founding Authentium, I traveled to Beijing to meet with China Radio International and discuss a possible joint venture with them and the satellite company I was working for.


I've always loved going to China. But this time there were several notable highlights to the trip.

One of the highlights was a tour of CRI's multistory, mid-city facility, during which we were shown several interesting items, including their concert hall, a map of the Chinese shortwave radio grid and the China National Radio Museum.

The museum was fascinating. At the time, CRI was broadcasting over its shortwave grid (and via AM repeater stations) in 49 languages, including Esperanto. Arranged in a large darkened room in glass and wood cabinets were gifts from all over the world, including operettas in Hungarian, bottles of whiskey (unopened), and hand-written song requests.

In one cabinet, sat the polished gray and chrome microphone used by Chairman Mao to proclaim the new order, from the Peace Hotel in Shanghai.

I checked into the room Mao stayed in during a previous visit when I was there in 1995. The room cost me $140 for the night. The guys in the jazz band in the bar downstairs were all eighty years old.

After the museum, we ended up in the basement of the building looking at a map showing the shortwave repeater stations... but what really took my attention was a powerpoint slide showing the fiber being laid between the major cities.

One of the guys in our small group said something like "this is a very ambitious plan". Our translator translated this and the Chinese just shook their heads and smiled at the poor naive Westerners sitting across from them.

"This is not our plan", our guide explained. "This is our current capacity".

He went on to explain that in major cities they already had fiber passing about 70% of buildings, and broadband uptake was in double digits and growing fast. We all looked at each other, and then looked back at the maps, and wondered - could this really be the case?

Could China have really built the largest broadband network in the world?

The news out of China today - that they now have 253 million Internet users sitting in a market that is growing above 50% a year - shows that indeed they have.

I wouldn't be surprised if it is announced next week by the ITU that China already has more broadband users than the US: after all, they were ranked second by the international body at the end of 2005.

Commentators will come out in the next few days and claim these numbers are inflated. I don't think so. Based on what we saw a decade ago, I think the numbers are real, and I think the growth figures are real too.

Note: Check out the image above - yes, that really is a program guide from China Radio International in Esperanto, complete with banner ads, also is Esperanto. Don't believe me? Click on it and check out CNI's site.

Unpatched: 10 Million DNS Servers, 500 Million Browsers

A few weeks ago, I blogged about the 500,000,000 unpatched Internet browsers that the Swiss Insitute of Technology estimates are out there.

Yesterday, I blogged about the 10 million DNS servers now at risk because of the DNS vulnerability recently identified by Dan Kaminsky.

Now, let's assume that 20% of the DNS servers have been made compliant over the past few weeks, a number that I personally believe is a stretch. That still leaves 8 million DNS servers as targets for hackers looking to redirect Internet traffic, and 500,000,000 unpatched browsers.

That's a lot of potential for evil.

A friend from one of the larger online financial service providers in the US sent me a link to a quote Kaminsky made that was published yesterday. In this quote, Kaminsky is starting to sound the alarm:

"We are in a lot of trouble," said IOActive security specialist Dan Kaminsky. "This attack is very good. This attack is being weaponized out in the field. Everyone needs to patch, please. This is a big deal."

As I mentioned yesterday, we shouldn't hold our breath when it comes to hoping all the DNS servers out there are going to get patched anytime soon.

Another issue that I can see looming regarding this issue is the difficulty that the mainstream press is going to have in "sound-biting" a technically complex (for non-IT folks) problem so it can be made interested for consumers.

That initial explanation of how large and small remote Domain Name Servers and local HOSTS files all work together to resolve URL requests is going to have folks reaching for their remotes pretty quickly...

The good news is that there is a solution available. Almost five years ago, we started work on a system that would protect there requests from the origin point through to the destination server.

As I mentioned yesterday, our service, Authentium SafeCentral, bypasses the non-secure DNS infrastructure and provides a secure means of correctly connecting to transaction sites.

This patent-pending service operates securely, anywhere in the world, regardless of whether or not your ISP's DNS servers have been patched. And if you're one of the 500,000,000 who haven't updated your browser, SafeCentral will provide you with a much safer Internet.

Note: Some of you asked where the estimate of 10 million DNS servers came from. Although I thought this was was clear in the original blog, the sources of the number was the Infoblox DNS Report Card, which estimated there were nine million DNS servers in place at the end of 2007.

I simply took the previous year's growth and used that as a guide - which produces a total base of just slightly less than 10m servers.

Wednesday, July 23, 2008

PC Magazine Reviews Authentium SafeCentral

PC Magazine just published an excellent review of Authentium SafeCentral.


Our security features all worked exactly as advertised and the reviewer had many positive things to say about the enhanced security SafeCentral offers online consumers - especially when it comes to online banking transactions.

The only negatives were lack of a password manager, lack of support for Firefox antiphishing, and slight slowness in rendering pages. All of these feature requests/issues have already been addressed for our new release.

The review focused on three main areas: phishing/spoofing, keylogging and screen-stealing, and DNS (URL lookup) security.

With respect to our antiphishing capabilities, one of the things I liked about the review was that the reviewer understood the need for a systematic, real-time approach to preventing phishing. Here's what he said about our abilities in that area:

"If you always visit your sensitive sites by launching them within SafeCentral, there's almost no chance you'll be taken in by a phishing scam."

He also tested our secure DNS lookup capabilities by hacking his test system HOSTS file, and found that we prevent that kind of DNS poisoning.

"I added a line to make requests for www.pcmag.com go to a different site. IE and Firefox were totally fooled, but the SafeCentral browser brushed aside my amateur hacking and went directly to PC Magazine's site."

Excellent! That is exactly what is supposed to happen - poisoning of the local HOSTS file is one of the easiest hacks to pull off, and our patent-pending TSX library (now part of SafeCentral) does a great job of preventing this.

On the subject of sneaky key-loggers and screen-stealers, the reviewer used a keylogger that's "sneakier than most" (his words) and again compared us to IE and Firefox (check out the slide show on PC Mag's site for screen shots of this attempt):

"The keylogger totally captured everything I typed in IE and Firefox. It saved screenshots, it recorded data from the clipboard, and it even tracked what URLs I visited in IE. But it didn't get a single byte of information from the SafeCentral session. I tried several other keyloggers with the same result. Good job!"

The reviewer noted at the end of the review that we could do with some improvements in speed (already addressed), password manager support (also already addressed), and support for the Firefox antiphishing technology (included in the latest build).

The complete text of the review, including screenshots of SafeCentral, can be found by going to PC Mag's site, buying the magazine, or clicking here.

If you'd like to download SafeCentral for free, please go here.

Tuesday, July 22, 2008

The DNS Mystery Ends Badly

Okay, like a lot of security guys, I speculated on what Dan Kaminsky was going to announce at Black Hat regarding the current DNS vulnerability.

Here's a quick recap of the problem, courtesy of Wired:

"The DNS flaw that Kaminsky discovered allows a hacker to conduct a "cache poisoning attack" that could be accomplished in about ten seconds, allowing an attacker to fool a DNS server into redirecting web surfers to malicious web sites..."

"A cache poisoning attack allows a hacker to... translate a website's name to a different address instead of the real address, so that when a user types in "www.amazon.com," his browser is directed to a malicious site instead, where an attacker can download malware to the user's computer or steal user names and passwords that the user enters at the fake site..."


My own speculation involved an assumption of stupid levels of randomness. But if Thomas Dullien (aka Halvar Flake) turns out to be right (and as of this writing, most people seem to think that he is), I was off by a force of magnitude - in terms of both stupidity levels and the ease with which this vulnerability can be exploited.

The vulnerability allows hackers to basically take over a DNS cache "in about ten seconds" (see above quote). Wired predicts the first root kits will be in circulation by *tomorrow*. Here's a link to the post from Dullien.

So if the problem is known, why do I say this ended badly? Because we're looking at a massive, Internet-wide problem. Even though vendor patches are available, Internet security - and DNS lookups - are going to be compromised for as long as it takes for everyone to get compliant.

There are an estimated 10 million DNS servers out there. According to the Infoblox DNS Report Card survey in 2006, by the end of 2006, less than two thirds of DNS servers (61%) had been upgraded to BIND 9 - an improvement of barely 3% over 2005 levels.

With no policing forces at work (other than customer complaints and market forces), I predict that it will take years for all servers to be brought compliant. Which means this problem - DNS insecurity - is going to be around for a while.

I wouldn't be doing my job if I didn't point out that our secure transaction service, Authentium SafeCentral, uses an independent system of secure DNS servers linked to a secure client to make sure that every request for a bank or brokerage web site goes to the right place.

Saturday, July 12, 2008

Building a Successful SDK

Software Development Kits are a big part of what we do at Authentium.


For more than a decade, we have packaged and released system-level tool kits, including Linux and Windows-based antivirus SDKs, personal firewall SDKs, and system-level file-hardening tools.

These tool kits have been used by many industry leaders in the security, SAAS-based managed services, and telecommunications industries to create new products and services.

Based on this experience, we have learned a lot about what tool kits need to offer engineering teams. But first, let's start with a proper definition.

Software Development Kits (SDKs) should enable developers outside of the distributing organization to access and utilize the code/intellectual property in a way that clearly defines both the scope of the intellectual property (IP), and the scope of what is allowed to be done with it.

The commercial model needs to closely match the scope of the toolkit. If your toolkit effectively allows other companies to compete with you, or includes some significant ongoing service commitments (both these are true with respect to anti-virus tool kits, for example), then your model needs to take into account the need to price using a "co-opetition" model and fund the ongoing service costs.

SDKs by definition also need to be well-documented, starting with the licensing schema.

It is extremely important to let developers know up-front what can and can't be done with the code. In my opinion, Firefox does an excellent job of explaining what is covered under general public license (GPL) and what is owned by the third party developer. Knowing what the tool kit owner owns, and what you could potentially own, based on your use of the kit, is important when licensing in code.

Documents designed to inform engineers are the next step. There is nothing worse than "snobby" or badly-written documentation. Engineers face deadlines and have limited time to learn your code. They need to know that your engineers are dedicated to bringing them up to speed and helping them make this deadline - the quality of your documentation reflects this better than anything else.

For me, the first step in testing your documentation should be to ask someone that has never tried your toolkit to build something with it. Does the documentation clearly enable the engineer to create something using your toolkit, without resorting to calling the manufacturer? If the answer is yes, and your legal agreement is clear, proceed.

Features found in the product that a toolkit is based on are often not included in the SDK. In my view, this is wrong - rather than force your partners to "reinvent the wheel" you should present them with features as part of your commercial model. Include them in the code and value them correctly - that way, everyone wins.

The final thing any decent open platform code-base or SDK needs is good support, provided by people who are proud of the code and willing to help. SDK need to be supported either by an interactive, wiki-based community, such as is the case with Linux, PayPal or Firefox, or by a dedicated team of engineers prepared to answer questions from other developers.

In summary, SDKs need precise legal and commercial definitions, an appropriate and understandable commercial model, great documentation, cool features, and solid support. If you have all these, your SDK should be successful.

Note: My thanks to Vladimir Dubovik at US Bank for asking the question that led to this post.

Thursday, July 10, 2008

DNS Insecurity

Imagine an attack in which the hacker controls all your Internet traffic, and is able to redirect your web site requests away from your requested destination to a spoofed web site that they control.

This scenario is called a Man-In-The-Middle (MITM) attack, and is achieved when a hacker is successful in "poisoning" or modifying the Domain Name Server cache.

Once a DNS cache is poisoned, it enables intelligent interception and redirection of web site requests to be managed from a point remote from the client (and the destination.) DNS poisoning is, in many ways, a case study in online criminal efficiency.

Next month, as everyone in the security industry now knows, Dan Kaminsky is going to step up to the mic at Black Hat and talk about something everyone already knows is a big problem - DNS insecurity.

So what is Kaminsky going to tell us? The fact that an out-of-sequence patch was issued by Microsoft two nights ago (a patch that apparently kicked users of Zone Alarm firewalls off the Internet) explains where the problem probably lies.

The Register (which refers, accurately, to DNS insecurity as "the mad woman in the attic" and a "peripheral, forgotten issue") added some color today, unearthing a 2005 paper from Ian Green which makes for some interesting reading. Here's a peek at his paper:

"...as the infamous Mitnick vs Shimomura attack and other subsequent attacks have shown, many weaknesses in network protocols are a result of poor implementation rather than weaknesses in the underlying protocol. In the Mitnick attack, 'IP source address spoofing and TCP sequence number prediction were used to gain initial access'."

Hmmm. Can you can tell what is coming next? Three pages later, post a few hours of research, Green writes, of his target research (the XP DNS Resolver):

"The DNS transaction ID always begins at 1 and is incremented by 1 for each subsequent DNS query; and... the UDP source port of the query (which becomes the UDP destination port of the response) remains static for the entirety of a session (from startup to shutdown)."

In other words, Green has followed Mitnick's advice and found exactly what was predicted: stupid levels of predictability. The DNS transaction ID, which is allowed to be a random number 16 bits long, has been implemented in such a way it can be easily guessed ("n" + 1).

In his paper, Green faults Microsoft's flawed implementation of DNS in XP ("ten years after the Mitnick attack"). The Register article uses this as the basis of a theory about what Kaminsky is going to talk about - a theory that was bolstered by MSFT's out-of-sequence patch this week.

Anyway, let's assume that's right. That leaves us Internet users with a problem. Mitnick first paved the way 13 years ago. Green's paper, which was published by the SANS Institute, came out three years ago, in 2005.

If it turns out this is what Kaminsky is going to talk about, why is everyone assuming the problem will be taken care of quickly?

The truth is, it won't. Only a minority of vulnerable users will hear about this and download and install the patch - leaving lots of room for those folks looking to pull off the perfect Internet crime - the MITM, or Man In The Middle attack.

Note: It would not be proper for me to sign off without pointing out that a solution exists for XP users: Every single DNS request made inside Authentium SafeCentral is handed off to our secure DNS service.

This ensures that even users with totally compromised machines get to where they want to go, without experiencing a MITM attack.

Hartford Courant Does Good

This morning, the editors of the Hartford Courant took a walk down the Yellow Brick Road and found courage, smarts - and a heart.

In an editorial this morning entitled "Drop The Charges" the Courant challenged Connecticut prosecutors to drop the bogus charges they have lined up against Julie Amero and take the retrial off the books.

In writing the piece, they proved that it is never too late to right a wrong, or claim back some respect.

For anyone unaware of this case, Julie Amero was the schoolteacher who was kicked out of her job after pornographic pop-ups appeared on an un-patched, unprotected school computer in front of several students.

Lots of people have since looked at the exact code she was looking at at the time (thank you archive.com) and found unmistakable evidence that this is probably among the worst cases of injustice ever perpetrated in the short history of Internet-related crimes.

Amero was without any shred of doubt very unjustly punished - there were links in the code that I saw that led to places other than those advertised, popups that aggressively spawned new popups, and let's face it, even if Amero went everywhere the prosecutors claim, why isn't the IT guy at the school attracting attention for not keeping the schools filters up to date?

The whole idea of having filters is so that kids don't get exposed to stuff like this - no matter what actions adults take.

The Courant compares Amero's current dismal state with that of some of the borderline inmates waiting for trial in Guantanamo. This isn't nearly as crazy as it sounds. Amero is also sitting in limbo waiting for prosecutors to get off their butts and admit they don't have anything.

Hartford folks, when your local politicians come to you for re-election, please do all of us a favor and ask them where they stand on the Amero issue. Make it a local issue.

Take a brave action - like the Courant has done today - and vote some prosecutors into place that will make your community worthy again of respect.

Update: Re the last paragraph, an alert reader has pointed out to me that things are not done quite so democratically in Connecticut. Click "Comments" (and watch for future entries in the Authentium InSecurity blog) for more...

Wednesday, July 2, 2008

500,000,000 Unpatched Browsers

IBM, Google and the Swiss Federal Institute of Technology have just come out with a really interesting study. The subject was the relative security of the 1.4 billion users of the four main browsers currently in distribution.


Browser security is the hot area of study right now. Last week I wrote a piece in the blog on man-in-the-browser attacks, describing why it is so important that you use a secure browser. If you haven't read it, you should. But back to the study.

The study looked mainly at two things: the security "holes" or exploits that currently exist, and the effectiveness of the update strategies used by the 1.4 billion users of the four main browser developers - Mozilla (Firefox), Microsoft (IE), Opera (Opera) and Apple (Safari).

Firefox, which uses a completely automated update strategy, won the day with 83.3% of users patched up to the latest version, compared to less than 50% of IE users. IE users chose to ignore patches far more often because of IE's "permanently put-off this update" approach - leaving them more open to browser-based attacks.

As the ArsTechnica overview of the report states:

"Firefox and Opera are both credited for including an auto-update feature, but the team notes that "Firefox’s auto-update was found to be way more effective than Opera's manual update download reminder strategy." How effective? way more effective."

We like Firefox at Authentium. Authentium's SafeCentral end-to-end transaction security solution utilizes a specially-hardened version of Firefox 3 in conjunction with our system-level hardening technologies and a secure DNS system.

If you're thinking of downloading FF3, or upgrading, I'd recommend you go over to the site and get yourself a really secure browser.

Note: the ARS article was entitled "40% of Surfers Don't Bother With Browser Security Updates" - for us and all the other people working in risk mitigation, the fact that there are half a billion unpatched browsers out there is one scary fact.

Tuesday, July 1, 2008

Security 101: Locking Down Your Premises

Bank Infosecurity's Linda McGlasson has an excellent post over at her site today on what happened during a real-world, real-person penetration testing exercise at an (unnamed) financial institution.


I had had two discussions this week CSO at banks who said they are becoming overwhelmed with similar real-world security problems, like social engineering of their call-center staff and proper checking of vendors and hosting companies at the front desk.

The bottom line is that a lot of nice people just want to be nice - and that makes them easy targets for people looking to do "walk-in" style attacks. These nice people need to be better trained to understand that sometimes being nice involves being firm and inflexible.

In any case, locking down these vectors is the correct place to start. The correct prioritizing of security efforts involves first locking down the physical premises. Putting in place advanced network security is only effective in conjunction with a robust and wide-ranging set of security policies that includes every potential attack vector.

Linda's blog can be found here.

Insecurity and the Need for Heroes

I was in Lower Manhattan on 9/11 when the planes hit. And as the horrible events of that day unfolded, I, like many other New Yorkers, tried to help.


I went first to St Vincents in Greenwich Village to donate blood, watching as thousands of dust-covered refugees from the City streamed north, past white-coated doctors and nurses waited in vain beside a line of empty gurneys.

Then, once it became clear that blood wasn't what was needed, I headed with a group of other guys over to the docks to volunteer to help dig people out - only to be turned away because they wanted people "with tools and experience" - as in, experience in digging and cutting through steel and concrete.

So I went back to the neighborhood - just as the National Guard arrived and started locking everything down, from 14th St south to Battery Park.

As it turned out, the only heroic act that I managed to perform during 9/11 was the procuring of emergency supplies and the refilling of Kristen Johnson's water cooler (it's a long story). Hardly the stuff of legend. I went to bed - late - deeply unsatisfied with my contributions.

Meanwhile, the real heroes became more heroic to us New Yorkers by the day.

That afternoon, and for all the next day, and days after that, we would cheer them on from the east side of West St, as the firefighters and cops and construction workers kept digging, looking for "the people in the pictures" as we came to call the missing in the weeks after the tragedy.

The experience was unprecedented for me. I'd never felt such insecurity - or been in the middle of a disaster scene before. I had never ever before seen real life heroes up close, working to save lives - except for doctors and nurses and mothers. This form of heroics - the disaster response - I had no ability to comprehend it beyond the obvious sacrifice happening right in front of me.

Which brings me to the subject of this blog.

In his book "The Black Swan", Nassim Taleb postulates that a forward-thinking, highly-placed politician could have prevented the tragedy of 9/11 - by forcing the adoption of laws mandating additional security in the form of terror-proof, secure cockpit doors on aircraft.

He then explains that had this additional security been put in place, 9/11 would probably not have occurred, and New York, and the WTC, would have continued much as before.

But as Taleb explains, every action has a cost. Imagine the life of our politician as he faces re-election one year after his successful legislation. His success in forward-thinking has, unexpectedly, created a large personal problem: His overwhelming success has resulted in the complete destruction of a whole class of threats.

What remains, once the threat of an attack has been removed? The cost. And only the cost. Ask George W. Bush and Dick Cheney.

And so it ends with our hero. Taleb's story concludes with our lawmaker - the politician who "prevented" the attack - being turfed out of office for imposing such a ridiculously costly and unnecessary "security burden" on the airline industry, perhaps after the running of an ad campaign explaining how "all that money" could have been "better spent".

Taleb's story (originally told to explain the theory of Black Swans, like 9/11) goes a long way to explain why CSO's and their hard-working IT security staff often feel unappreciated.

It explains why boards and governments almost never sign up for large-scale security spending. It explains why "adequate amounts of security" and "heroics" will forever be incompatible. It explains why firefighters get depressed and sometimes light fires.

It also explains a lot about the security software industry. Analysts and engineers working in antivirus facilities like Authentium's Virus Lab sometimes get frustrated when criminals and hackers get lionized by the press - especially after an all-nighter spent securing the world from the threats they've created.

Taleb's story illustrates why when insecurity is rife, as it was on 9/11, heroes are needed. But it also explains why, with few exceptions, the names of the most successful folks in the threat prevention business are seldom heard outside of the industry.

Because, by improving security, they have killed off the likelihood of threats, and the need for heroes. They have made the terrible event go away, before it could occur, and become invisible as a result.