Saturday, May 23, 2020

To do or not to do….the Covid app.



Corona or Covid-19 as some like to call it – is in the news everywhere. It has practically become the central theme of the world now. With due respects to people and families who lost their loved ones – it would be safe to say that Covid-19 has also spun off many unexpected positives. Low levels of pollution,  Himalayas visible from far off places, free movement of wild animals etc. It also has spun off a technology challenge / opportunity.

‘How can we?’ or ‘can we at all?’ use technology to map the infected patients and alert the healthy ones?

There are several countries like Australia, Singapore, China and many more that have launched COVID apps for contact tracing. Aarogya Setu is one such app launched by Govt of India.

Not surprisingly there are naysayers and sceptics who are thrashing this initiative.  In this article – let us take a view into some of these and objectively look at it.

How do the contact tracing apps work?
Not very different than Google Maps. The first step is to get as many people as possible to use this app. Now, when a person (of course with the app) is moving around say in city – his movements are kept track of in the app. If the person happens to be Asymptomatic patient and figures it - 2 days later, then all the people he was in touch with for the past 2 days can be alerted. The app also helps to identify clusters or hot spots of infection, helping local authorities to initiate containment in that area.
Great logic and will work for sure. The Govt needs to make sure a large volume of people use the app for this to be successful.

Privacy concerns?
One of the biggest concerns is that there is no specific Data Protection Law in India under which this App could have been safeguarded or evaluated. Though there is a proposed bill - Personal Data Protection Bill 2019 – but that is yet to become a law. Work in progress.
The other big concern is what happens to the data being collected. I installed the app on my phone to figure that app takes information like name, gender, travel history, telephone number, basic health info and location. I will be concerned if this data is misused by tele-callers who inundate me with unsolicited sales calls. There is no financial data or major identity data– so I do not have to be bothered about losing my identity or bank balance.
On one hand most of the users would happily and voluntarily part with data on social media platforms and other apps. How else do you think Amazon and Facebook know what is (was) on my mind? Which product or service interests me. I can say with confidence that possibly Facebook, Amazon and Google know more about us than any company HR where we work or even our near and dear ones.

Track the tracker!
Various benchmarks are used to track the tracker– of course there is no standard way of doing it. Looking at the way MIT Technology review does it. It looks at 5 areas:
a)       Is the App voluntary?
To begin with the app was said to be Mandatory. Driver’s license is mandatory, and one can be punished for driving without one. This app was compulsory, but cops were not stopping you to check if you obeyed the Govt. The government, to their credit, is trying to allay the fears around data misuse and have made the use of Arogya Setu completely non-compulsory. The app now holds the record for world's fastest-growing mobile app with over 100 million downloads.

b)      Limitation on data use?
The govt has not clearly mentioned nor the data protection provisions elaborate on this. We just need to trust the govt here. People who are worried this could be used for surveillance should remember that if you use anything that is “SMART” – it is watching you – Smart phone, Smart TV or Smart home.

c)       Data Destruction?
Here the Govt has come clean. It has a data destruction policy and most of the data is stored in the phone itself for unaffected people.

d)      Data Collection?
This is a relative comparison. Compared to China and Turkey – India is collecting data that is absolutely required. Compared to some EU countries – India may be overstepping – like it asks questions like – do you have Diabetes or BP? Anyway, for most of the Indians Health info is not a very big secret.

e)      Transparent coding?
The app is developed by NIC. Not sure if they have adhered to any specific standards but if the app must be successful in the long run – it will become standardized and interoperate. I am hoping it will work well with Apple and Google’s initiatives.

Conclusion:
Comparing the potential upsides and the potential downsides – I would choose to have the app installed on my phone with a hope that all those around me too do it as well. Until the vaccine comes – until corona is overcome – let us do all that we can to stay safe.

Tuesday, October 1, 2019

Almost Hacked...

I always kept wondering why the bad guys (in Cyber security) succeed most of the times and I got my answer this morning.
It is that time of year when we have all file our IT returns and await our refunds or confirmations from the IT department. It is almost a month since I filed my returns and have been waiting for that SMS. This morning at 4:47am my phone beeped and the much awaited SMS popped. 


I was excited when I saw my name and ITFUND as source of the message.  I was wee bit disappointed on the amount as I was expecting a higher refund. Nevertheless I clicked on that link from my mobile. I noticed it got re-directed a couple of times and landed on this Income Tax Department page (look alike page).







By now, I knew this was a fraud but went ahead and choose a bank – obviously – these fellas have setup a trap to steal banking credentials – I did choose a random bank and gave some random credentials – the hackers now take me to a RBI website (look alike) and ask for all personal data. With this they will create a fake ID and swap my SIM to steal my OTP as well.

Tell me one thing – would you have clicked on that link and would have keyed in your password? - Put your answers in the comment section

I also clicked that link from my laptop and as expected our web security solution blocked that link.


Friday, June 22, 2018

Disgruntled employees can pose serious threat


Tesla, the American multinational corporation that specializes in electric vehicles, energy storage and solar panels. A disgruntled Tesla employee broke into the company’s manufacturing operating system and sent highly sensitive data to unknown third parties. This is a steadily growing trend that is being witnessed in various parts of the world. Unhappy employees / sacked employees and some cases even high performing ex-employees try to actively damage their ex-employer. Such employees should be ashamed of themselves.

What can Employers do?

well, there is help available now. Technology can help address this issue. We now have Behavior analysis solutions that can figure out the current mood of your employees - are they happy? sad? Angry? Frustrated? Pose a danger to organization? The solution is called User and Entity Behavior Analytics.




Saturday, May 26, 2018

Fancy Bear returns


The hackers responsible for Democratic National Convention (DNC) hack in 2016 are back in the news again. On May 23rd - Cisco announced a major breach of over 500,000 routers and network storage devices. FBI acted swiftly and seized the internet domain that was used in the attack, cutting off the communication between the hackers and the infected devices. For now, the hackers will not be able to exploit these half a million devices for their malicious intentions but the malware still resides in all these devices. The infected devices are spread over 50 countries and the most likely author of this Malware is Fancy Bear - the hackers behind the 2016 DNC hack.

Researchers found VPNFilter source code on these infected devices - the malware that was used by Russia to attack Ukraine including the massive power outage. VPNFilter is hard to detect, works in Stealth mode and is known to steal critical data from Infrastructure systems.

As an immediate next step - it is advised to reboot the devices, change the passwords, do not use default passwords and disable remote admin on all internet facing devices. Legacy security systems depend on static policies and rules for their providing security, In an ever changing threat landscape of current times - there is a need for RAP - Risk Adaptive Protection, which will understand the behavior of people and adversaries to dynamically change policies and rules to provide better security.



Thursday, May 3, 2018

Forcepoint helping its customers build a secured data environment

My interview with VAR India
By VARINDIA    2018-04-23


Calling for a shift in the way cyber security is approached, Ajay Dubey, National Manager - Partners & Alliances – Forcepoint tells VAINDIA of how as a security focused company, Forcepoint is trying to address the challenges that crop up while securing its customers and their critical data - 
 
How is your organization geared up with security strategies for the industry at large?
Cyber security as a domain is going through a constant churn to help organisations stay focused on protecting against breaches, protecting critical business data at all times and complying with regulations. This is the reason, over the years, cyber security budgets have increased multi-fold, making it a huge industry. But, despite all these investments, the cyber security attacks have only increased. 

This calls for a complete shift in the way cyber security is approached. If you look at threats and technologies, they continue to evolve, but one thing that has remained constant throughout is people. This is what Forcepoint is doing, it is rethinking security from a human-centric approach. The approach emphasizes understanding human behaviour and user interaction with critical data over networks of different trust levels to combat cyber-attacks. 

Can you highlight the solutions you are offering for addressing the growing challenge of cyber security?
At Forcepoint, we have unique cyber security solutions for protecting the data - 

•    Our CASB (Cloud Access Security Broker) is designed to secure data on the cloud. CASB solutions address cloud service risks, enforce security policies, and comply with regulations, even when cloud services are beyond their perimeter and out of their direct control. We acquired Cloud Access Security Broker (CASB) firm Skyfence that has helped increase visibility, control and security as users interact with data wherever it resides, including within cloud applications.

•    Forcepoint’s UEBA (User and Entity Behaviour Analytics) helps organizations to baseline behaviour of users and also entities like endpoint servers or applications and then see if there are any deviations from normal baseline. We acquired Red Owl, a leader UEBA (User and Entity Behaviour Analytics) technology to better understand and manage human risk.

•    Forcepoint’s Web and Email Security Solutions protect users against multistage advanced threats that often exploit user’s data, which penetrate the organisation’s IT defences. 

•    Forcepoint NGFW (Next Generation Fire Wall) caters not only to network needs but also security needs of all the networks of our customers. With NGFW 6.4, network security admins can more clearly see and understand the rhythm of their people as they use network resources. 

•    Our data protection is integrated with DLP (Data Loss Protection) solution and now we have augmented our DLP with insider threat and UEBA (User Entity Behaviour Analytics) solution that understands the context and intent of user behaviour and dynamically applies enforcement policies to activity representing the highest risk.

How are you seeing the security trend to continue in 2018? 
The biggest security trend in 2018 will be EU’s GDPR regulation which will have a considerable impact on nations that control or process data of EU citizens. With the regulation of GDPR coming into action in May 2018, the focus should now shift towards three areas like the adoption of the prescribed nature of controls in the regulation in specific areas, improvement of the existing privacy structure to work according to the requirements of the regulation and reassessing the opportunity of processing in the context of GDPR. 

The second massive trend that’s being observed is the adoption of cloud. Even highly regulated industries like banks have started to adopt cloud on a big scale but the problem with cloud is that it opens up everything and it does not restrict the access anymore.  

Additionally, the IT security solutions are unable to understand behaviour of malicious, accidental or compromised users in spite of the technology investments. Therefore, cyber security must move from a technology-centric view to one that understands human behaviour and intent and employ a security system that can effectively do the same.

With new wave of security intelligence and its intensification, what are your prospect marketing plans?
Forcepoint’s unique brand strategy of focusing on cyber behaviours instead of emphasizing just on technology to protect a perimeter that no longer exists has helped customers in building a data secured environment. This approach requires both intelligent systems and transparent collaboration between an organization’s stakeholders. 

Our brand’s theme of protecting organisations against accidental, compromised or malicious users to protect against data thefts reflect the shift in the current security paradigm, which is largely technology-oriented, to focus on people as they interact with critical business data and intellectual property. 

How are you going to leverage your market strategy to further boost your presence in the country?

Our approach is to help our customers increase their security effectiveness while lowering risks as they accelerate digital transformation of their business. We continue to engage with companies across the entire ecosystem including Banking and Finance, IT and ITeS, Manufacturing, Government, Pharmaceutical, Insurance and many more to help them understand the need to protect critical data and importance of providing their employees access to the right data whenever and wherever it’s needed. 

Friday, April 6, 2018

The World This Week - April 1, 2018


The World This Week.

Truth is sometimes stranger than fiction. But for the whistle blower - It would have been impossible to believe that a company like Facebook would have allowed itself to be used by such spurious app developers.

In a nutshell – A company called Cambridge Analytica paid nearly $1M to Cambridge psychologist Aleksandr Kogan to create an app called ‘thisisyourdigitallife’. The intent of the app was to collect Facebook user profile data and pages liked in the guise of an online personality quiz. The app was able to directly access 270,000 user’s data. Here is the real catch – using this data the app developers were able to access data of 50M users – which they then misused to allegedly influence Donald Trump Victory in 2016. They apparently also influenced several other democracies including India, Argentina, Kenya, Nigeria, The Czech Republic and others.

There have been several data breaches in the recent past – Equifax, Yahoo, Deloitte, NSA, Indian telco giant – Reliance Jio and few more but there is none as damaging as this Facebook fiasco. Facebook itself seems to be under fire with the “#DeleteFacebook” hashtag trending, Mark Zuckerberg has formally apologized but his troubles are far from over. Many governments will be under pressure – political parties will have to answer a lot of questions. You and me – public at large are the helpless victims – what more this borrowed phrase summarizes this point – “If you’re Not Paying for It; you’re the Product”.

Among other major whistle blower new grabbers were the leak of CBSE board exam papers in India and possible fraud / conflict of interest at board room level of India’s ICICI bank.

Yet another data leak - US based Orbitz – a subsidiary of Expedia – has suffered a leak 880,000 credit card numbers putting that many people in risk.

So here’s what we can start doing differently from tomorrow. Be alert and vigilant on what you share on social media, when creating online account – avoid using Facebook to login or authenticate yourself. Don’t believe everything that you see in the social Media – especially WhatsApp. Think before you forward.

Business are equally vulnerable if not more to data thefts. Among the few options that companies have – the prominent one is to safeguard and have controls over PPT – People, Process and Technology. Like they say – never try to make a Matchbox at home – it will not only cost more – it will be a far from a perfect product – Cyber security is similar – In-house is fine for certain areas but for most of the other areas outside help is always better. It will not only cost lesser dollars – it is sure shot to work.