Showing posts with label smart phone. Show all posts
Showing posts with label smart phone. Show all posts
Monday, 14 September 2015
Too busy to think Data
This week we failed to help a friend in need. He'd left a single copy of those everso valuable baby photos on his Laptop and failed to back it up. I really feel for him. Despite a platter change and a huge amount of effort it was too late. Technically it's possible to recover data from mechanically damaged platters but sadly baby photos don't justify the cost.
These days we have free Cloud services thrown at us from multiple providers however most corporations quite rightly prevent or block them as they can lead to uncontrolled business data leaking in to private cloud space. It's easy to do if not controlled.
In the past we have found extremely sensitive data on discarded "home computers". I remember the launch sequence of a missile system being one! One can imagine an under pressure worker bringing home some important work to finish off over night, probably on an uncontrolled USB stick and copying it on to his home PC. That's two uncontrolled copies before we consider factors such as the cloud.
In my friend's example however it's the opposite. He works for a company who manage their data very carefully. Whilst he's obviously been able to copy his personal data to the device it's excluded from his normal business data and so it's not backed up. All hard disks will fail at some point so this is a time bomb.
My point is that due to human nature we fail to consider the implications of our data actions. We just assume it will be there when we need it and not there when we need it gone. But this is very often not the case and is always a rash assumption.
Just like a warehousing error is very often in fact two errors; 1) where something should be and 2) where it actually is... we have the same consideration with data. We must consider BOTH where we want data to be and where we do not want data to be.
What The Cloud does is enables the data to be in a dozen places at once without us thinking about it. Yet that's exactly what we need to do. Think about it.
Labels:
back up,
cloud,
data recovery,
data security,
personal computer,
personal data,
residual data,
smart phone,
tablet
Tuesday, 1 July 2014
Data Data Every Where
You’d have to be comatose not to notice the massive increase
and proliferation of data devices. Those
of you who know me know I am a huge fan of the Glastonbury Festival. Even at Glastonbury this year you could see
crowds of people drudging through the mud glued to the screen of their smart-phone. EE cleverly deployed 4G WiFi cows painted in
their branding to connect up 250,000 festival goes and workers. It didn’t work. I could see telecom masts on each hillside, we
had 4G WiFi cows and yet I still couldn’t effectively get online.
This was of course due to the insatiable demand of the
consumer for more data, more devices – “we need more power Scotty”. Well, the
shift has moved from processing power to pure volume of data. From the device to the data-centre of course. The other power needed was of the 5 volt DC
type and EE had another cleaver idea – a swap out charging cell for your
phone. Neat idea but AGAIN – hugely oversubscribed
and they couldn’t recharge them fast enough.
So, what I observed was a huge number of avid music fans in
a very muddy field all struggling with their addiction… no, not that, their
addiction to data. This is a huge change
in just a few years. We are addicted to
our data-fix and yet there is something really strange. We don’t have a clue and don’t really seem to
care where our data actually is. We just
push it out in to the cloud and expect it to be there and safe for when we
require it.
It’s a small wonder the heavens opened twice over the
weekend with an electrical storm which stopped the festival for 40 minutes. I think it was all the data and the cloud just
couldn’t cope and this caused the storm.
It simply has to let go of some of that energy.
But seriously; who is keeping track? Why don’t we care? How
can it be managed if we don’t really know or care where our data is held? We seem to go through a huge change sometimes
called growth, then realise we didn’t consider the consequences and then catch
up trying to put things right after the event.
It’s a massive technology change and social change and yet we take the
security and even location of data for granted.
Labels:
data security,
Glastonbury,
ipad,
iphone,
personal computer,
personal data,
policy,
residual data,
smart phone,
tablet
Wednesday, 29 January 2014
BYOD – Bring you own Databreach
I have worked closely with companies who have quite relaxed
policies on BYOD (Bring your own Device).
They liked the idea that if an employee wants an iPhone, this was OK,
as long as they paid for it. Personally;
I blame Ryanair. People are always telling me what a clever business Ryanair
is. They even charge their employees for
training and uniforms.
I’ll resist the Ryanair tangent for fear of this turning in
to a customer service rant and I have strong views on business culture. My point, however, is a simple one. A BYOD device is another device on your
network. It’s a MAC address with a set
of permissions. Allowing a BYOD access
to a network or allowing access to your corporate email system can be little different
from allowing an uncontrolled device to connect up remotely to your business critical
data.
Socially it is expected. It might be small and hugely featured but it’s easily lost
and exposes the weak underbelly of your whole business system. In short; it’s a disaster waiting to
happen. Your BYOD is possibly linked to
a cloud service such as Dropbox or iCloud.
It’s a high resolution camera which might be used to photograph that
White Board so you can write up the notes later.
Remember James Bond with his mini cameras in the classic Bond
movies? Well now we all carry one. Ours are better actually as they don’t need
developing and they transmit and sync our images almost instantaneously to the
cloud whilst our phone is in our pocket.
Now let’s look at email.
I know of situations where member’s of staff have had both personal and
work email accounts on the same BYOD. This
enabled them to forward work email to their home account (with attachments) with
no record on the business exchange server other than the email had been read! This is a security haemorrhage point and
nobody really seem that bothered.
Of course you will be thinking that the Cloud services,
email policy and even the camera could be controlled in a switched-on company. You are probably right and of course they
should be. My point is really one of
attitude.
We all carry these devices with Gigabytes of data on them in
and then out of our business worlds.
They soak up data and information about our habits and movements and
they record highly sensitive data.
BYOD need to be controlled – just like any other business critical
device. Ownership actually complicates
the situation. They need to be controlled,
audited and the risk assessed. Staff
need to be trained. Ownership of the
data needs to be considered with great care and attention. Policies need to be written, implemented and
measured. People need to be
trained. BYOD is not a panacea to cheap
technology infrastructure. BYOD could
become your worst nightmare.
Lastly; what happens when the employee leaves? Is the demarcation
of personal data and business data a clear one? – probably not. If their personal iPhone has been linked to
their home PC (and it probably will have been) then you don’t just have the challenge
of you data being on one device but probably many. Not only that but you probably have no idea
where your business data is.
By its very nature BYOD puts your data in an uncontrolled environment. Phones and tablets are lost and stolen in
huge numbers every day. On average a
London taxi has a phone left it in once every day! The disposal of data and devices upon leaving
the business is an HR minefield and a risk most businesses haven’t even
considered.
Bring you own device? - Bring your own Databreach!
Labels:
bring your own device,
BYOD,
CIO,
CTO,
data breach,
data security,
ipad,
iphone,
personal computer,
personal data,
phone recycling,
policy,
refurbishment,
residual data,
smart phone,
tablet
Monday, 20 January 2014
A Fictional Data Breach Scenario
In 20 years in the technology industry, I have yet to find a
business who has their data under control.
It’s a really tough challenge! It
slips through your fingers like water due to human nature. It’s human nature to take a path of least
resistance to achieve an objective especially when you add pressure to a
circumstance.
I’m going to give a fictional circumstance to a data breach
which is in the public domain but a data breach which I commented on at the time. In May 2009; a disk bought on eBay contained
details of test launch routines for the THAAD (Terminal High Altitude Area
Defence) ground to air missile defence system. The same disk also held
information belonging to the system’s manufacturer, Lockheed Martin, including
blueprints of facilities and personal data on workers, including social
security numbers.
Based on other information found on the disk it was probable
that an employee or supplier or perhaps a consultant took valuable highly confidential
data home and worked on his or her home computer. He (for brevity) might have even deleted local
copies although he probably forgot. He
certainly failed to securely erase data which in the wrong hands could be invaluable.
We’re going to call him John in my fictional scenario. John is under a huge amount of pressure. He’s consulting for his aerospace client having been bought in to cover the sudden sickness of a key member of a program team. This is a bit of a stroke of luck for John as he’s been without a contract for a few months.
At home John is a family man but he has pressure from this
side of his life too. Financial pressure
has been building up. His wife has been
working longer hours to try to cover the shortfall. This has meant John has been helping with the
kids and the school run.
John’s in that horrible stage of a new contract where he
doesn’t know all the team and he needs to build relationships. He’s completed his induction but the pressure
is now on full to catch up for the lost time.
The project didn’t plan for the key man sickness and its John’s job to
catch up.
Today John has to get home on time as his wife’s at work but he must also complete an urgent report. Frustratingly John’s not got his new work laptop yet. He’s getting in to the office as early as he can but today he must leave on time for child care. His new boss and the person who decides his future needs the report “on his desk at 8am, without fail”.
John can’t win. He
can’t leave his children and he can fail in his new job. The pressure is unbearable. His only option is to pull out of his briefcase
a USB flash drive. He plugs it in and tries
to copy the files. Frustratingly his aerospace client has disabled the USB
ports. Then he has a brainwave. He logs on the webmail of his personal
consulting business. Hotmail and Gmail
are blocked but his consulting domain works.
He emails his work to himself, presses send and then logs off. John rushes to collect his kids.
At home John cooks his kids their diner, puts them in front
of an x-box and settles down to his evening’s work. It’s half 12 at night by the time john
finishes. He emails the work back to the office and goes to bed.
Two years later his home PC is upgraded and he recycles the
old one at a local civil amenities site.
The hard drive along with the memory are scavenged by a temporary
employee at the site and are sold on eBay for a few extra dollars.
This scenario is made up but I hope it makes you think just
a little. How waterproof (dataproof?)
are your processes and procedures? Have
you tested for leaks? Do you record and
track when data is accessed and copied?
Is your “bring you own device” (BYOD) policy and control in place?
Confidential data is like water. It finds a way if it’s not contained.
Labels:
BTOD,
data breach,
data security,
personal computer,
personal data,
residual data,
smart phone,
tablet
Saturday, 7 December 2013
A Gateway in to our Private and Professional Lives
A change to our perception of data is long overdue. We all know the volume of data is rising exponentially. We see the value of large scale data
processing happening in the data centre. As users we take for granted the huge amount
of information available to us however we chose to ignore our side of this
bargain.
Users keep their head in the sand with regard to
their personal data. We don’t think
about what we put on our smart phones, tablets or personal computers. Smart phones, tablets and personal computers
hold a snap-shot of our lives and they hold ever increasing level of
detail. Smart phones, tablets and PC’s
become a gateway in to our work and personal lives.
Take my iPhone as an example. I take some care of it and I work in the
industry so you would imagine my data is pretty safe. I have both my personal and work data on this
device and of course my contacts and their details. A quick scan suggests about 1400 contact
details.
Now let’s imagine the impact of me losing it. I’d buy another one and I’d recover my data
from The Cloud. Great! I am back up and running. What might happen should I fail to change any
of my email passwords, iCloud account and potentially a whole lot more? That phone in the wrong hands is a gateway in
to my most precious world. Most people haven't considered the risk.
Mr Smith who now has my phone is a pretty smart man. He plugs the phone in to a PC and analyses
the data shared between the two devices.
If he’s smart getting round my access code is quite simple. In about 5 minutes he’s reading my live email
stream. I’ve done the PC equivalent of
forgetting to change my locks after a break in/security breach.
A “fixer” who was buying smart phones from a market in Lagos,
Nigeria once told an investigative journalist friend of mine that there were
two prices – one for phones with data and one for phones without. The model and condition where less
important. I’ve now been told the same
is true of hard disk drives. The reasons
for this are obvious.
So thousands of us could be sitting in blissful ignorance as
our private emails are mined for data which could be used to blackmail us, to steal
our identity or for information which can then be sold on to others to do with
what they will at any point in time.
Much data doesn’t lose its value.
A Social Security number, date of birth and mother’s maiden name doesn’t
change. Dates such as birthdays, anniversaries
etc. don’t change.
Users seem to assume that the data on a device is equally
obsolete as the device they are changing.
We change devices sometimes every few years and we more often than not,
throw away our data on the chance that Mr Smith won’t get hold of it.
Personal information can also be used for social
engineering. It can be used to make a
fraud or crime seem completely credible.
For example; say I have a hobby, perhaps basket weaving. Mr Smith can
easily gain the trust of family and friends just by knowing this tiny piece of
information. Add to that some dates and
times of events and it would be easy to socially engineer somebody’s trust.
We love what so called smart devices do for us and our lives
but we fundamentally fail to understand the risks of discarding the data. I sometimes wonder if we are smart enough for
the smart devices we crave for.
Jon Godfrey is a Director of Intelligent Lifecycle Solutions who provide services including the refurbishment and recycling of Hard Disk Drives, Mobile Devices and technology equipment.
http://www.lifecyclesolutions.net
Jon Godfrey is a Director of Intelligent Lifecycle Solutions who provide services including the refurbishment and recycling of Hard Disk Drives, Mobile Devices and technology equipment.
http://www.lifecyclesolutions.net
Labels:
data breach,
data mining,
data security,
ipad,
iphone,
personal computer,
personal data,
residual data,
smart phone,
tablet
Sunday, 24 November 2013
Vodafone Recycles Customer Data in Databreach
Vodafone is more than a little embarrassed this morning when
a customer was contacted by a complete stranger saying she had her email and personal data. The stranger had bought a
“new” iPhone and yet it was a refurbished model and Vodafone had failed to securely
remove the old customer’s data.
As this is a clear data breach of personal data and I am sure
the Information Commissioner's Office (ICO) would be interested. Vodafone don’t do this work
in-house but are still responsible. They use one of many “professional”
refurbishment businesses which have grown up very quickly to support our insatiable appetite
for smart phones and the need to recycle them when we chose to change.
The speed of change is a challenge for the market. People, just like those in this story
wish to change frequently and without hassle, in this case from Apple to
Samsung. However the manufactures,
networks and the whole supply chain who support them have been slow. Slow to understand the importance of personal
data.
A director of one refurbishment company once said to me; “I
don’t get all this fuss about data. It’s the same data when it’s in their hand
or pocket”. He’s right to a limited extent however he’s missed the real
issue. When the data is in our hand it’s
in our control and we are responsible for it - a sort of micro-controlled environment. If we lose it or it’s stolen we can take remedial
action. We can contact our bank, the
network to block the phone or even remotely wipe the device with some providers.
When we trust responsible others including networks and “take
back” service businesses we expect them to adopt a “duty of care”. We TRUST them with our data. In my view this is a wholly misguided trust. If the directors of these businesses “don’t
get it” they can’t be trusted. If
networks the size of Vodafone don’t have sufficient fail-safes in their procedures
we clearly can’t trust them either.
It’s our data and we should either ensure it is safe
ourselves or seek guarantees and evidence that it has been destroyed. As the CEO of Blancco (a Finnish company who
provide secure erasure software for PC’s and Phones) once said; “It’s not about
the data erasure. It’s about the data
about the data erasure”. What he was
saying is that we must prove the data has been destroyed and have evidence.
We simply can’t trust people sitting in factories doing repetitive
tasks to get it right 100% of the time.
At best it’s perhaps 98%. With
over 60m phones in the UK alone changing every, say three years that could mean
400,000 phones with data on all out there somewhere!! I think,
however this is a huge underestimation. In
my view most phones never make it to the desk of the poor person whose job it
is to wipe them. Most are shipped abroad,
mainly to China, India and Africa. In
these areas your data has a VERY sinister value. "EH from London" was VERY lucky. Her data didn’t find its way in to the wrong
hands.
For close to 20 years now I have been trying to make people aware
of the data they throw away. We have
found Sir Paul McCartney’s bank details and missile launch codes on thrown away
hard drives. Phone and hard drives
contain a snapshot of our lives and we carelessly throw that data away on the trust and hope it will be managed correctly.
We live in a blind faith that big companies and recycling centres will
look after our data.
Jon Godfrey is a Director of Intelligent Lifecycle Solutions who provide services including the refurbishment and recycling of Hard Disk Drives, Mobile Devices and technology equipment.
http://www.lifecyclesolutions.net
http://www.lifecyclesolutions.net
Vodafone rings up complaints selling my old iPhone and data as new
A stranger phoned to say that she had bought my iPhone from Vodafone – and it still had all my data on it
I signed a two-year contract with Vodafone and got a new iPhone, before deciding to switch to a Samsung. I was assured by the store that all my personal data would be removed from the iPhone before it was sold on as used.
A few weeks later I got an email from a stranger saying she had my iPhone with all my data, including my email account. Vodafone had repackaged my old phone and sold it as new!
Vodafone customer service insisted this data breach was "impossible" and refused to apologise. Three months on I have still received no explanation. To make matters worse, the new Samsung phone does not work. Vodafone will not provide a replacement, nor "courtesy phone" while it's sent off for three to four weeks for repair. EH, London
Almost as worrying as the data breach is the fact that a used phone was sold as new. Vodafone explains that its returns policy allows customers to change their mind within seven days and, if the seal of the handset is unbroken or there is less than five minutes' activity on it, it is wiped and resold as new.
Interestingly, once your complaint is forwarded under The Observer banner, Vodafone realises it has a case to answer after all. "For the process to fail in this way is extremely rare and our corporate security team is investigating," says a spokeswoman, who has also started an inquiry as to why customer services was so hopeless. The company has offered you a new phone and a reduced rental deal but, unsurprisingly, you prefer to seek another provider and so, in a magnificent gesture of contrition, it has released you from your contract without a termination fee.
Labels:
blancco,
data breach,
iphone,
phone recycling,
refurbishment,
smart phone,
vodafone
Subscribe to:
Posts (Atom)