Thursday, February 26, 2009

PCI DSS - Random Musing #1

For anyone wondering why I posted random stuff about PCI when I've been harping on about Internet Filtering for months, well, I've been doing some work in this space for awhile.

For the uninitiated, PCI DSS is a standard for handling credit card security. It's been around for awhile now but its only really started gaining momentum in Australia in the past 12-24 months.

When you go to the Tier 1 merchant training sessions, talk to the QSAs, the acquirers, etc, the message is loud and clear - don't store cardholder data unless you really, really, REALLY have to. Just hand them over to the payment processor. At least that's the crux of it.

So why did I post those articles?

Well, my point is we rely on the payment processors and best practise tells you that is where the data should be going - and I agree 100%. Online businesses send their credit card data directly to the payment processors and minimise any storage of anything on their side of the fence. Pretty cut and dry right? Minimise your liability and protect your clients, reduce PCI-DSS audit scope where you can and everyone is happy - right?

Except for the consumer if their data gets stolen from your payment processor because they used your site.

You get the blame because they (the unfortunate consumer) used your site. Even though it was your payment processor's responsibility to protect that data and you did everything by the book. You get smeared by association and lose business. If you're really unfortunate and you follow this train of thought to its ultimate logical conclusion, couldn't your business go under? This scenario could easily kill a small business. If so, could the payment processor be open to a lawsuit?

PCI DSS states that any third parties you rely on for the processing of cardholder data must be validated they are PCI DSS compliant. But these articles prove that this isn't enough.

So this raises a bunch of questions that came to mind:
  • Are the payment processors implementing "real" security or just trying to get ticks in the boxes of their audit?
  • How many of these companies restrict outbound Internet access? Limit/filter HTTP access?
  • Failing that, how many segregate their core IT systems from their internal LAN? And who has access to these systems and how is access facilitated?
  • What controls are in place for their administrators and staff with privileged access? What sort of background checks are performed?
  • What boundaries and checks exist to measure/reduce/prevent authorisation creep?
  • Just how restrictive is the SOE? Do they have appropriate network access controls to prevent random devices (i.e. contractor laptops, executive's children, etc) being plugged into the office LAN?
I think most enterprises in general are pretty weak on the above controls. But can these business afford to not implement the most paranoid levels of security when they are owning so much risk and clearly high priority targets?

You be the judge.

The takeaway lesson I guess for security professionals is that we need to be asking some seriously tough questions (above and beyond PCI-DSS) when conducting vendor selection for payment processor facilities. We need to ensure they implement security to a level we think is commensurate to the level of risk. If you're in the middle of PCI DSS remediation and looking to consolidate payment processors, you're in the prime position to do so.

And somehow we are expected to be pragmatists about it. Can we make sure we aren't holding them to an impossible standard? Can the bar be set too high with cardholder data when the costs for breaches and liabilities involved are so high?

Like I said, you be the judge.

BTW, I'm not suggesting the above list of questions are perfect - or even a place to start. Those are just some random questions that just occured to me personally. I just couldn't help but wonder how serious these guys take their security and if so, to what extent do they take it and is it really enough?

- J.

Web censorship plan heads towards a dead end

This sounds too good to be true:

"Senator Nick Xenophon previously indicated he may support a filter that blocks online gambling websites but in a phone interview today he withdrew all support, saying "the more evidence that's come out, the more questions there are on this"."

I think the writing is on the wall.

The article highlights that clearly Senator Conroy is pushing this despite overwhelming lack of public support and ignoring all facts and professional opinion and discourse. His blatant disregard for conducting fair and representative tests by failing to include any of the Tier 1 ISPS, is the icing on the cake IMHO. While it seems that sanity shall prevail, we should not let our guard down and should keep pushing an end to this ridiculuous move and see it through to the very end.

Oh, before I forget - I found this quote to be even more poignant:

""Unfortunately, such a short memory regarding the debate in 1999 about internet content has led the coalition to already offer support for greater censorship by actively considering proposals for unworkable, quick fixes that involve filtering the internet at the ISP level," Labor Senator Kate Lundy said in 2003."

We who forget the past are doomed to repeat it... indeed.

- J.

Tuesday, February 24, 2009

PCI-DSS compliant payment card processors targeted

Two articles worth reading.

Here:

"What concerns me is that Visa and MasterCard, they clearly know who it is," Shettler said. "That just won't say anything because the processor hasn't come clean. The sort of feel it gives people is that Visa and MasterCard are covering for some unnamed organisation."

and here:

"This is clear evidence to me that the criminals know how to bypass the traditional security controls in place today," Litan said. "It's clear that they're targeting the processors now because there's much more data there. [Processors] are more centralized and the thinking is that more attention is paid to their security, but they are at the nerve center of processing systems."

I hope these guys are implementing real (paranoid level) security given they're operating in high risk environments and not paying lip service to the PCI DSS standard.

- J.

Tuesday, December 23, 2008

Australia To Block BitTorrent

Just when I thought our government couldn't get any dumber.

Did Senator Conroy take my comments on P2P a bit *too* far... ?

So it seems.

Time to setup up your own private VPN boys and girls. At least, let us hope he doesn't try to outlaw VPNs too.

Doomed to Fail...

I hate to say "I told you so" but....

I told you so.

Key quotes:

"Professor Landfeldt, one of Australia's leading telecommunications experts, says some of the fundamental flaws include:

■ All filtering systems will be easily circumvented.

■ Censors maintaining the blacklist will never be able to keep up with the amount of new content published on the web every second.

■ Filters using real-time analysis of sites to determine whether content is inappropriate are not effective, capture wanted content, are easy to bypass and slow network speeds exponentially as accuracy increases.

■ Entire user-generated content sites such as YouTube and Wikipedia could be blocked over a single video or article.

■ Filters would be costly and difficult to implement for ISPs and put many smaller ISPs out of business.

■ While the communications authority's blacklist will be withheld from internet users, all 700 ISPs will have access to it so it could easily be leaked.

■ The filters will not censor content on peer-to-peer file sharing networks such as Limewire, online chat rooms, email and instant messaging."

Thursday, November 13, 2008

Censorship Update

Hi all

Today I emailed my local MP to ask them to apply the hard questions to Senator Conroy. I strongly urge you all to do the same.

For more timely advice, I urge you all to visit http://nocleanfeed.com/.

Cheers.

Thursday, November 6, 2008

Email to Senator Stephen Conroy

Email him yourselves at senator.conroy@aph.gov.au.

--
Dear Senator Conroy

My name is Jarrod Loidl and I am curently employed as an Information Security Specialist. I have been actively employed as an information security professional for the past five years, active in the Information Technology industry for the past ten years. In that time I've spent approximately six years working for various Internet Service Providers (both in Australia and outside of Australia).

Some of the responsibilities I have had in that time have been:
- managing spam filters for a major U.S. ISP serving approximately four million users,
- reporting child pornography cases to federal law enforcement,
- managing intrusion detection and prevention systems,
- conducting/coordinating penetration tests and vulnerability assessments of various networks,
- develop and provide recommendations on security architecture for various projects,
- provide strategy guidance on policy creation and development, etc.

I am also a member of the Australian Information Security Association and Open Web Application Security Project.

As such I am aware of the way criminals operate over the Internet to escape detection and have a unique perspective on these issues having worked them from both technical and security angles. I am also familiar with the social and political issues surrounding the proposed Internet filtering.

I am writing to state my opposition to this plan and it is my hope that by explaining why, you will reach the same conclusion.

Firstly, these filters being proposed are based on HTTP proxy level filtering. That means these filters will only inspect unencrypted web traffic. That means that anything that is encrypted or not web based, will bypass the filtering.

What follows is a list of technologies that are free (or easily affordable at most) that will defeat this form of filtering:
- Anonymous Proxies and anoymisation services (e.g. TOR),
- Virtual Private Networks,
- SSH Tunnels,
- Peer-To-Peer (P2P) Networks,
- SFTP/FTP.
I'm sure there are more but those are the most prevalent in use today.

Studies have statistically shown that most of the traffic ISPs service today is P2P based. This traffic is not just generated by kids downloading music but also criminals sharing child pornography. These tools are either easy to install, easily bypass the proposed filters and what's more are completely legitimate in day to day business - so blocking or prohibiting these tools isn't a feasible option either. Criminals have been using many of these tools for years to minimise their chances of detection or avoid it entirely. I urge you to ask anyone dealing with child pornography or computer crime from the Australian Federal Police or Australian High Tech Crime Commission.


Infact, this proposal may have the unintended side effect of creating a smarter criminal by forcing them in larger numbers to adopt the above technologies and hamper law enforcement dramatically.

Secondly, my understanding of the proposal hinges on the use of two blacklists (and please correct me if I'm mistaken) - one is an "opt-out" list for general adult content. The second list cannot be "opted out" and is for content deemed illegal. Looking at the black list issue from a purely technical perspective, it is well regarded as a poor security model. The reason being is that anything not defined as prohibited is expressly permitted. This means any site that hasn't been classified as either adult or illegal will be allowed. Managing these lists becomes a full time basis as they will only grow over time as more sites are classified. Infact for a blacklist to work, you would need to classify every site on the Internet - a rather impossible feat given my estimate to be in excess of 30 billion pages to date and growing at an exponential rate.


If the solution relies on automated tools to populate these lists, this opens up the potential for sites to be incorrectly classified - potentially creating an even larger problem.


But let us assume for a moment that somehow, every page is classified appropriately. The proxy filters will then have to match all web requests against these two very, very, very large lists to see if a search is prohibited. This will cripple Internet speeds - already I'm sure you've heard of the reports surrounding performance concerns. I can assure you that by using this approach that such reports will only increase over time as the lists grow in size and performance impacts will be inevitable.

The preferable security model is to do the reverse - whitelist "permissible" websites and block anything not on that list. However, this would also require the classification of every website as well and also create another large list - thus creating the same issues.

Thirdly, there is the issue of classifying content. How is that assessment made and who determines it? What if a site is classified incorrectly? What one individual finds offensive another may not. Is it open to public scrutiny? What checks and balances are put in place to prevent abuse by Government or private enterprise by adding content they deem to be "undesirable"? There are equal arguments for and against open inspection of the black lists by the public and I completely recognise this. If you open the lists to inspection, people will invariably try to access the content however, if you don't how can the public at large be assured they aren't being censored by content that the Government doesn't want them to access? There is no clear cut answer to this - only a careful deliberation of risks can help to shed some light here. However when you weigh it all up with the other points I've raised I'm sure you will agree that this proposal creates more problems than it solves.

To summarise my key concerns -
- It is technically trivial to bypass such filtering,
- Managing the blacklists or whitelists for that matter to determine the content of all web traffic is largely impossible,
- This will create performance issues,
- By allowing a specific group to classify content on behalf of all Australians poses the risk of widespread abuse to all Australians.

In my following of this issue it seems that there hasn't been much clarification around the impetus of this plan. Is the plan to protect children from exposure to inappropriate content? Is it to stop the proliferation of child pornography? Before we can rush ahead with a technical solution that does not work, we need to be very clear about what it is we are trying to prevent. With collaboration with the ISP industry, information security professionals, law enforcement as well privacy and civil liberty groups such as the Electronic Frontiers Association - I have no doubt a better path can be found.


As a soon to be parent, I fully support the governments cyber-safety initiative. However as an information security professional I must advise you that the current proposal is rife with flaws and further examination of the issues is required. What I've covered here is just the tip of the iceberg.


I apologise for the long email but sincerely hope you read this and take the above into due consideration. I welcome any further feedback or response.

Best regards,

- Jarrod Loidl
Ph: XXX-XXX-XXXX