Posts

Skill Levels in Digital Security

Image
Two posts in one day? These are certainly unusual times. I was thinking about words to describe different skill levels in digital security. Rather than invent something, I decided to review terms that have established meaning. Thanks to Google Books I found this article in a 1922 edition of the Archives of Psychology that mentioned four key terms: The novice is a (person) who has no trade ability whatever, or at least none that could not be paralleled by practically any intelligent (person). An apprentice has acquired some of the elements of the trade but is not sufficiently skilled to be trusted with any important task. The journey(person) is qualified to perform almost any work done by members of the trade. An expert can perform quickly and with superior skill any work done by (people) in the trade. I believe these four categories can apply to some degree to the needs of the digital security profession. At GE-CIRT we had three levels -- event analyst, incident...

When You Should Blog and When You Should Tweet

Image
I saw my like-minded, friend-that-I've-never-met Andrew Thompson Tweet a poll , posted above. I was about to reply with the following Tweet: "If I'm struggling to figure out how to capture a thought in just 1 Tweet, that's a sign that a blog post might be appropriate. I only use a thread, and no more than 2, and hardly ever 3 (good Lord), when I know I've got nothing more to say. "1/10," "1/n," etc. are not for me." Then I realized I had something more to say, namely, other reasons blog posts are better than Tweets. For the briefest moment I considered adding a second Tweet, making, horror of horrors, a THREAD, and then I realized I would be breaking my own guidance. Here are three reasons to consider blogging over Tweeting. 1. If you find yourself trying to pack your thoughts into a 280 character limit, then you should write a blog post. You might have a good idea, and instead of expressing it properly, you're falling into...

COVID-19 Phishing Tests: WRONG

Malware Jake Tweeted a poll last night which asked the following: "I have an interesting ethical quandary. Is it ethically okay to use COVID-19 themed phishing emails for assessments and user awareness training right now? Please read the thread before responding and RT for visibility. 1/" Ultimately he decided : "My gut feeling is to not use COVID-19 themed emails in assessments/training, but to TELL users to expect them, though I understand even that might discourage consumption of legitimate information, endangering public health. 6/" I responded by saying this was the right answer. Thankfully there were many people who agreed, despite the fact that voting itself was skewed towards the "yes" answer. There were an uncomfortable number of responses to the Tweet that said there's nothing wrong with red teams phishing users with COVID-19 emails. For example: "Do criminals abide by ethics? Nope. Neither should testing." "Ye...

Seven Security Strategies, Summarized

This is the sort of story that starts as a comment on Twitter, then becomes a blog post when I realize I can't fit all the ideas into one or two Tweets. (You know how much I hate Tweet threads, and how I encourage everyone to capture deep thoughts in blog posts!) In the interest of capturing the thought, and not in the interest of thinking too deeply or comprehensively (at least right now), I offer seven security strategies, summarized. When I mention the risk equation, I'm talking about the idea that one can conceptually image the risk of some negative event using this "formula": Risk (of something) is the product of some measurements of Vulnerability X Threat X Asset Value, or R = V x T x A. Denial and/or ignorance. This strategy assumes the risk due to loss is low, because those managing the risk assume that one or more of the elements of the risk equation are zero or almost zero, or they are apathetic to the cost. Loss acceptance. This strategy may assume...

Five Thoughts on the Internet Freedom League

Image
In the September/October issue of Foreign Affairs magazine, Richard Clarke and Rob Knake published an article titled " The Internet Freedom League: How to Push Back Against the Authoritarian Assault on the Web ," based on their recent book The Fifth Domain . The article proposes the following: The United States and its allies and partners should stop worrying about the risk of authoritarians splitting the Internet.  I nstead, they should split it themselves, by creating a digital bloc within which data, services, and products can flow freely, excluding countries that do not respect freedom of expression or privacy rights, engage in disruptive activity, or provide safe havens to cybercriminals... The league would not raise a digital Iron Curtain; at least initially, most Internet traffic would still flow between members and nonmembers, and the league would primarily block companies and organizations that aid and abet cybercrime, rather than entire countries.  Governm...

Happy Birthday TaoSecurity.com

Image
Nineteen years ago this week I registered the domain taosecurity.com: Creation Date: 2000-07-04T02:20:16Z This was 2 1/2 years before I started blogging, so I don't have much information from that era. I did create the first taosecurity.com Web site shortly thereafter. I first started hosting it on space provided by my then-ISP, Road Runner of San Antonio, TX. According to archive.org, it looked like this in February 2002 . That is some fine-looking vintage hand-crafted HTML. Because I lived in Texas I apparently reached for the desert theme with the light tan background. Unfortunately I didn't have the "under construction" gif working for me. As I got deeper into the security scene, I decided to simplify and adopt a dark look. By this time I had left Texas and was in the DC area, working for Foundstone. According to archive.org, the site look like this in April 2003 . Notice I've replaced the oh-so-cool picture of me doing Ame...

Reference: TaoSecurity Press

I started appearing in media reports in 2000. I used to provide this information on my Web site, but since I don't keep that page up-to-date anymore, I decided to publish it here. As of 2017 , Mr. Bejtlich generally declines press inquiries on cybersecurity matters, including those on background. 2016 Mr. Bejtlich was cited in the Forture story Meet the US's First Ever Cyber Chief , published 8 September 2016. Mr. Bejtlich was interviewed for the NPR story Cybersecurity: Who's Vulnerable To Attack? , aired 30 July 2016. Mr. Bejtlich was interviewed for the Washington Post story It’s not just the DNC; we all send emails we probably shouldn’t , published 25 July 2016. Mr. Bejtlich was interviewed for the New Scientist story NATO says the internet is now a war zone – what does that mean? , published 22 June 2016. Mr. Bejtlich was interviewed for the Military Times story The Pentagon's controversial plan to hire military leaders off the street , published 19 June...