Wednesday, April 20, 2016

If Only It Were Sci-fi: CEOs, CFOs, COOs and Cell Phone Vulnerabilities

Like many of you, I ease back into the workweek on Sunday evenings getting a jumpstart on things with 60 Minutes in the background giving me a heads-up on developing matters here and abroad.  This Sunday, Sharyn Alfonsi’s segment, Hacking Your Phone, jolted me back to business.  If you missed the program, here’s the takeaway:  your smart phone is defenseless against hacking and executives are particularly targeted.  Watching a U.S. Congressman’s mobile phone hacked in seconds, I reacted childishly – hoping it just wasn’t so.  But when I reached out to my speaker, Robert Bigman, former CISO of the U.S. Central Intelligence Agency – under whose watch the CIA was never hacked – I learned that, in fact, that our mobile phones and their networks are, indeed, entirely vulnerable and for simple reasons.  I asked him what my clients and readers need to know and what they can do to protect the privacy of their calls and their clients' information discussed in those conversations.  He shared:

It has been recognized for some time now that while cell (smart) phone is a new technology, the protocols that it uses to maintain wireless sessions, collect and communicate caller/device meta data and interface with the "wired" world, is decades old software and replete with vulnerabilities.  These "wired" world protocols (collectively known as Signals System 7), lack session authentication/integrity mechanisms and thus, are subject to call spoofing and redirection attacks. 

Cell phone users should also understand that while the "smart" devices contain incredible processing and communication capabilities, they are no more secure than your desktop/laptop computer running Windows or Linux operating systems.  Smart phones, like other computers, lack trusted "boot" protection, are written in coding languages that facilitate vulnerabilities, and allow applications to run that also expose the computer's operating system to memory exploitation. 

Your best bet for securing cell phone conversations (although far from guaranteed) is to use a separate/dedicated phone device with only an encrypted Voice Over IP (VOIP) application that, hopefully, satisfies the Federal standard for system cryptography (NIST FIPS Pub. 140-2).

Here's the link to the story:  http://www.cbsnews.com/news/60-minutes-hacking-your-phone and a link to Bob's full bio at www.SecuritySpeak.net.

 

Saturday, April 2, 2016

As Washington Hosts World Leaders at the Nuclear Security Summit ...



I asked Dr. Paul Bracken, author of the tour de force book, The Second Nuclear Age: Strategy, Danger and New Power Politics, for a comment. He replied:
 
 
The pace of military technology has reached a level not seen since the cold war in the 1950s.  Drones, cyber-war, targeted killings, anti-satellites weapons, hypersonic missiles are coming into the forces not just of the United States but of many countries.  Add to this atomic weapons, and soon, hydrogen bombs for India, Pakistan, Israel, and North Korea.  We are entering a new world of technology, yet the old political order of nation states remains essentially unchanged.  The 2016 Nuclear Security Summit shows the growing tension of a political order that is out of phase with technology advances.  Something has to give, and I don't think it's going to come from a slowdown in technology.
 
 
Scroll down for video of Dr. Bracken speaking to the North Korean missile program, STEM, emerging technologies and other key topics in security.

Security Synonyms: Planning, Preparedness & Perspective - Take One



 
The passing of Andrew Grove hit me personally.  Not that I ever met him, but I quoted his words of wisdom each time I gave a motivational address to professionals in legal, financial planning and accounting services:  “You need to plan the way a fire department plans.  It cannot anticipate fires, so it has to shape a flexible organization that is capable of responding to unpredictable events.”  Years back, in the aftermath of my family’s tragedy, via platform speaking, I prepared professionals to steward their clients through “the unthinkable” - and to do so with clarity, compassion and responsibility.  In other words, keeping their eye on the ball as others panic, grieve and recover.  In this spirit, on Friday 1 April,  2016, I was especially moved to interview Security Professional and ASIS International, Southern CT Chapter’s Co-Chair, Lex Giannini, on practical planning for the real issues at stake during a terrorist attack, natural disaster, or other crisis with human casualties.  Do stay tuned as I share Mr. Giannini’s insights in this space via excerpts over the next weeks.  This interview has resonance for us in our professional, community and family roles.

Wednesday, February 17, 2016

Why the Worry about Wi-Fi?


As a communications coach, when I attend presentations I watch the audience as much as I watch and listen to the speaker.  When I attended Ami Soifer’s, Getting Your Head in the Clouds, Comfortably and Carefully, presented to a packed room of attorneys, I gleaned that he was one to watch.  Educated at Boston University as an Electrical Engineer and co-founder and CEO of a pioneering IT firm, Ami has a knack for translating cyber-matters into terms that non-techie professionals can appreciate and comprehend.  I welcomed him to my interview chair last Friday and we discussed what is worrying my followers about public Wi-Fi.  What follows are his responses to the most “frequently asked questions” I hear from sole-proprietors, business-owners, and practitioners, especially those in 2-25 person firms whose staff and employees communicate largely on mobile phones and devices. 

Lisa Bernard:  I travel a lot for business and don’t know if airport Wi-Fi and hotel Wi-Fi are secure.   Should I be concerned?

Lisa Bernard:  Is there a difference between using my mobile phone and using my tablet in terms of secure communications?   Is one more secure than the other? 

Lisa Bernard:  What is a VPN? 
 
 
Lisa Bernard:  If I email from my office with secure Wi-Fi to someone using public Wi-Fi – say at an internet cafĂ© - does that compromise my communication and data?

Lisa Bernard:  Ami, thank you.  Your office is buzzing here - even late on a Friday afternoon - and your generosity with your time, commitment to education on cyber-matters, and insight are appreciated by my followers and me. 

To host Ami Soifer for a briefing, dinner presentation or address on CyberSense at your firm, school or association see Ami's bio at  www.SecuritySpeak.net and email me LisaBernard@SecuritySpeak.net.  I am happy to talk with you about the particulars and make it meaningful for your audience.   

 
 
 

Sunday, February 14, 2016

Talking with Paul Bracken: Today's and Tomorrow's Technologies, Developments and Dangers in the Nuclear Arena

It was grey and cold outside when I arrived at Yale University to sit in on Dr. Paul Bracken’s class, Strategy, Technology & War, but illuminating and warm in his classroom.  There, eighty-five coeds and grad students from around the world (selected from hundreds who seek registration) engaged in a back and forth about strategy and the function of nuclear weapons from the Cold War into this “the second nuclear age.”  That is also the title of Dr. Bracken’s tour de force book, The Second Nuclear Age:  Strategy, Danger and the New Power Politics, a clarion-call for policymakers, technologists, investors and industrialists about this precarious era of nuclear proliferation.  It was just a few days after the North Korean missile launch when I arrived at the School of Management and I was percolating with questions for Dr. Bracken which he graciously addressed in our interview after class.  I am happy to bring the highlights to you in this space. 

Lisa Bernard:  Just this weekend, North Korea successfully launched a long range missile – a provocation deemed so serious that the United Nations Security Council convened an emergency session.   In what context can we understand this?
 
Lisa Bernard:  A recent article in the Wall Street Journal, The Other Dangers from That North Korean Nuke Test, by Messrs. Gilinsky and Sokolski, describes a frightening development, namely, the increasingly available advanced technologies and materials for hastened and state-of-the-art nuclear weapons development.  What does this mean, practically speaking, for the proliferation of WMD - weapons of mass destruction? 
 
Lisa Bernard:  We are coming upon the twentieth anniversary of STEM and the tenth anniversary of President George W. Bush’s American Competitiveness Initiative to bolster STEM.  With a B.S. in Engineering, a Ph.D. in Operations Research, as a Professor of Political Science and Business and a consultant to various branches of the U.S. government, you are uniquely positioned to view the impact of these efforts.  Professor Bracken, what do you see?


Lisa Bernard:  Paul, you speak and write so insightfully about the symbiotic relationship between Silicon Valley and the Pentagon.  Given the dynamics of national security today, what do you think might we see come out of Silicon Valley in the next chapter of their connection?
 
 
Lisa Bernard:  The gravity of these matters is sobering - even overwhelming. Thank you for helping me help my audience gain some perspective on the news we hear and the realities we face.  Your time and sharing of your expertise is very much appreciated. 


Would you like to host Paul Bracken and continue this conversation at your organization?  Call me at (203) 293-4741 or email LisaBernard@SecuritySpeak.net.  I’d be happy to help you through the particulars and arrangements.

 
 

Saturday, January 23, 2016

ISIS: Crisis or Crucible?

Last week’s shift in White House policy regarding ISIS in Afghanistan occasioned me to interview Dr. Austin G. Long, a specialist in counterinsurgency and irregular warfare.  We met up at the Saltzman Institute of War and Peace Studies.  Dr. Long was an analyst and adviser to the U.S. military in Iraq from 2007 to 2008 and to the Combined Forces Special Operations Component Command in Kabul, Afghanistan in 2011 and to NATO Special Operations Component Command/Special Operations Joint Task Force in 2013.   I had four questions for him.

BERNARD:  Austin, American and British news agencies report that thanks to international air strikes ISIS has lost as much as forty per cent of the territory it held in Iraq and twenty per cent of the ground it commandeered in Syria.  How meaningful are these numbers and how do they translate into actual degradation of ISIS?
 
BERNARD:  As I mentioned in my set-up, just this week The White House gave the Pentagon a green light to target ISIS in Afghanistan, suggesting – based on the President’s State of the Union message—that there is a threat coming from ISIS in Afghanistan – a threat to us here in the homeland.  What kind of threat does “ISIL–K” pose to the United States? 
 
BERNARD:  Syria, Libya, Afghanistan … failed states where ISIS has exploited the situation.  Where next do you see a “failed state” ISIS might seize? 
 
BERNARD:  There’s a spectrum of thinking here in the U.S. – all sincere, it seems to me – on how to rid the world of ISIS:  destroy it militarily, counter it ideologically, starve it financially.  Given what you know about how ISIS’s motivation and nature, what’s your sense of what would get the job done?
 
BERNARD:  Austin, I thank you for your time and sharing of your insights in such a concise manner.  I’ve been in the audience when you’ve made full-length presentations and moderated panels and this format, I see, is yet another forum in which we can learn so much from you.  It is a pleasure to represent you at Lisa Bernard’s SecuritySpeak and I note that those who wish to host you for talks and briefings can contact me directly by calling (203) 293-4741 or emailing  LisaBernard@SecuritySpeak.net and view your full profile at www.SecuritySpeak.net.

 



Wednesday, January 20, 2016

The Games People Play


We are a cyberspatial culture.  We work on mobile devices.   We shop online.  We navigate by GPS and kids today view Cyberchase on PBS before Sesame Street.  Along with this way of life comes challenges to it.  Threats to our cyberspatial existence are real and varied.  Some are a nuisance like a hacked email account and others are detrimental like the downing of a power grid.  Fortunately, an entire industry is developing to protect our devices, systems and data and one entrepreneur in particular has a particularly clever and culture-friendly approach.  Marc Groz is CEO of CyberXplore and I was delighted to interview him to learn more about the sources of some breaches and his firm’s remedy.
 
 To host Marc Groz, call Lisa Bernard at (203) 293-4741 or email LisaBernard@SecuritySpeak.net.