Tuesday, March 06, 2007

Does Social Engineering = Fraud?

With all the conference blogging I've been doing lately, I haven't blogged about something I read in February that I've been thinking a fair amount about. Mordaxus over at Emergent Chaos made a compelling argument to get rid of cutesy names for attacks like pharming, phishing, pretexting as they are exclusionary jargon that prevent people from understanding the issues at hand. Overall I totally agree with him on the exclusionary jargon ban, though I will miss saying w00t.

However, something in the post has been occupying my thoughts for some time now (obviously), and my consternation gets worse every time I hear another person toss out 'social engineering = fraud' with disdain and disgust, like only an uneducated plebe would use the term social engineering anymore.

Social engineering != fraud all of the time. Sometimes fraud is just fraud, like counterfeiting currency. And sometimes social engineering is just social engineering, like dressing nicely, smiling sincerely, and treating the ticketing agent like a human being so you stand out from the masses of annoying and frustrated travelers as a Nice Person That Should Be Upgraded To A Premium Seat Without Having To Ask. That isn't fraud, that is understanding something about psychology and sociology that you apply in human interactions to help yourself come out ahead. Social engineering is a concept, a practice if you will, that can be used for malicious purposes, but in and of itself does not require lying, misleading, deception or fraud!

So I would suggest that saying 'social engineering is a con job' is an oversimplification that contributes to shallow thought by the masses. Like calling all of these populations:
- people who find security vulnerabilities and report them
- people who write POC code
- people who reverse engineer security patches
- people who write/release worms
- people who steal your credit card number and passwords via keystroke loggers and a botnet

'hackers'.

Too much jargon and exclusionary language is bad, but so is oversimplification. Should people be afraid of botherders? yes. Do they need to fear and revile security researchers? no. Well, not all of them anyway. (ha ha, it's a joke people)

~Elphie


(Adam, it would be super if you were able to hook up trackbacks on EC so I don't feel the compulsion to crosspost a comment on your blog to my own so it appears in both places. you know, with all your free time.)

Labels: ,

Saturday, July 08, 2006

quitcherbitchen

The life of an international chinchilla smuggler is not always easy or predictable. Sometimes I am just too busy flitting through the seedy underworld of exotic pet trade to expatriate my furry leetle amigos and dodging customs agents to blog much. Its not like I can just FedEx them to their new homes around the world - though we all know I'd never use FedEx, they have no sense of humor.

While offline and transporting cargo, I am reading The Presentation of Self in Everyday Life. If I'm going to mither on about identity here on the Hideaway, I should probably do a bit of organized reading on the topic. Surely there will be more soul-searching posts once I'm done feeding my brain.

In the meantime, a lot of interesting stuff has happened in the world. Dan Kaminsky has an interesting article about Net Neutrality on ComputerWorld that I highly recommend reading. Once you've read that, check out Adam Shostack's thoughts on how net neutrality impacts innovation. Adam, if you get someone to make chocolate toothpaste, I will soooooo buy some. HD Moore has announced July as the Month of Browser Bugs, I guess it is like the Year of the Dog for software. HD is a smart guy, and while I'm quite sure he is looking at all browsers, it does appear that Microsoft might have pissed him off a bit recently... whoops. surely unintentional, seeing as they've invited him to speak at not one but two of their hoity-toity BlueHat events...

There was something else interesting but I've temporarily forgotten what it was, and I've got to get back to the chinchillas. Another time...

~Elphie

Labels: , , , , , ,

Friday, April 07, 2006

I'd like to buy an 0, HOPE6, BSOD, Captain Obvious and media whoring...

Let's start with CanSecWest, and the vulnerability commercialization panel they had on Wednesday. There was much spirited debate but no end agreement between the parties... takes me back to ShmooCon and the BOF panel on training... but I digress.

In the press, Michael Sutton is quoted as saying that vendors need to pay for vulns, and later in the article a customer states he expects vendors to pay for vulns as well.
"The only economic model that does not make sense to me is the vendor's," Sutton said. "They get to know about a vulnerabilities ahead of time, but they are unwilling to pay for them."
Let's blithely assume for a moment that vendors and researchers could agree on the dollar value of a vulnerability (ROTFLMAO). There is still a big problem with the 'buying vulnerabilities protects customers' argument: if Oracle buys a vuln from David Litchfield, Oracle now owns the vuln. That means that they don't EVER have to fix it if they don't want to. I'm not just picking on Oracle - this is true of ANY vendor. They wouldn't be buying vulns, they'd be buying silence. And that would just piss everyone off - hell, that's why full disclosure practices started to begin with - the only way to get a vendor to fix a security bug was to publicly shame them with it. So I wholeheartedly disagree that vendors buying bugs would make me as a computer user any safer.

I have no problem with reputable third parties buying vulnerabilities and working with vendors to protect customers. I'll admit I think Tipping Point's ZDI program does a better job of that than iDefense's VCP program simply because iDefense's customers leak their confidential advisories all the time before patches are available. But these programs do play an important role in the security ecosystem that benefit customers, researchers, and vendors.

Other stuff:

Dates for HOPE number 6 have been announced - July 21-23, just a week or so before Black Hat Vegas. Of course I've added HOPE to the upcoming cons list...

Check this out - I've heard most people aren't having much trouble with Apple's Boot Camp beta, but this guy managed to get the legendary Blue Screen of Death. I haven't seen that on one of my boxes in over five years. Wow. Comments on the blog suggest that this was a known bug in the beta relating to iSight... doh!

Adam Shostack makes some interesting observations on recent media regarding rootkits on the Emergent Chaos blog. Yeah, he is right, this is a Captain Obvious type of situation where everyone in the security space already knew that rootkits were a big dangerous problem. But I think (or at least hope) the point of the Microsoft presentation at InfoSecWorld in FL that spurred the eweek article was to educate less security savvy customers about threats we are facing today and give guidance on how to deal with them. Adam also mentions the extremely cool work being done by John Heasman of NGS on ACPI BIOS rootkits that was presented not only at Black Hat Federal, but Black Hat Amsterdam and will again be presented in May at the Computer and Enterprise Investigations Conference. Right now it is super cutting edge stuff - so maybe if John gives the talk often enough, more people will pay attention (and by someone I don't mean the bad guys). After giving the talk at Black Hat Federal in January, Rob Lemos ran a story which quoted Greg Hoglund as saying:
"It is going to be about one month before malware comes out to take advantage of this," said Greg Hoglund, CEO of reverse engineering firm HBGary and editor of Rootkit.com. "This is so easy to do. You have widely available tools, free compilers for the ACPI language, and high-level languages to write the code in."

It would be a shame if the security industry didn't pay attention in January to John's early warning and is surprised when malicious bios rootkits emerge.

And since I've mentioned CEIC, I may as well throw a shameless plug out for Vinnie Liu's talk on Defeating Forensic Analysis (with his business partner Patrick Stach) on Thursday May 4 at the con. Vinnie is a very smart guy - if you are attending CEIC, I'd definitely attend their session. I'm such a groupie I'd go to NV just to see this talk, but I think that would violate the restraining order...

~Elphie

Labels: , , , , , , , , , ,