Skip to main content

Posts

Showing posts with the label Security

Secure on the Cloud: a Keynote

Some time ago, I gave a keynote at a CloudSec 2016 Conference in Mumbai. I was pleased to learn recently that the organizers put it on Youtube. I've presented this point of view before - with slides; this was my first attempt to break away from the oppression of Powerpoint and be slidefree.

Dodging Battle

Security is obviously on everyone’s mind these days with the media gleefully broadcasting with unfailing regularity yet another marquee name falling victim to a breach. Much energy goes into discussing the latest attacks and protections and responses, peppered with generous doses of doomsday scenarios. The talk is all of battle, of fighting off the evil hacker enemy. It may not be the losing battle that it looks like at the moment -remember the war against viruses once looked similarly bleak - but its certainly not looking easy. As the great Sun Tsu probably said, the greatest victory is avoiding battle. And even in this cyber-battle, there are a few ways to do that. Tokenize internally Dealing with sensitive information is a necessity, but there are ways to make it less sensitive. The most effective - mask sensitive data at source and keep it masked all the time. We’ve been doing this to passwords for years but have never gone beyond it. If you store sensitive information in the cl...

Changing a Password

It's that time of the month. My corporate email account has started warning me of dire consequences if I don't change my password. I'm going to have to start thinking again of a hard-to-guess easy-to-remember never-used-before nonsense string that will be my companion till thirty days do us part. Now security experts are always telling me "industry best practice" dictates that I change my password ever so often. I never quite believed it, because it just did not add up. There just didn't seem to be a feasible attack that could take advantage of this kind of hole. After all, password changes matter only if someone is already accessing your account. If your password did get compromised, what kind of hacker would wait thirty days to take advantage of it? There are indeed some stalker scenarios where this kind of thing can be useful, where I might want to see all the emails being exchanged without doing anything for as long as that window is open but in other sc...