Tuesday, 2 October 2007

Encryption and Key Management

I'm pretty busy this week, last week I was traveling around, meeting and greeting new customers, busy, but not having to think too much. This week I've had to re-learn some stuff I haven't done for a little while, and unlearn some stuff that I've worked with up until now.

I don't want to go into detail on things you can look up on Wikipedia. Encryption is done using algorithms, symmetrically in streams or blocks, or asymmetrically. In fact, talking of Wikipedia, there is a very good diagram of the different types of ciphers available here which saves me going into any more detail on this point too. Another area I don't really want to get into are the modes of block cipher operation, although they are a very interesting introduction to the next level of encryption for those who are interested.

So what do I want to talk about then? Well, I've represented a number of companies in this area in my time. I've worked with RSA, nCipher, Vormetric and currently Ingrian Networks. They all do it differently, apart from when they do it the same. I've also partnered with Utimaco and recently spoken with some of the team at Voltage, so you could say I've tried to cover encryption as broadly as possible, if not in depth, as this post probably proves.

If any of you know anything about any of these companies you will know that each of them concentrates in one particular area. It's not my position to criticise, nor to compare. Other than to say that I've ended up in a position where my skills are best placed in a market with great momentum, I will not comment on the strength of various solutions by name.

What none of these solutions has managed to do is create an all encompassing encryption solution. What most companies would like to do is buy one system of encryption for laptops, desktops, servers and email. They would also love this to achieve full data protection. If you've read any of Rich's posts recently, you'll know this doesn't work, you need the full works. Rich is doing a far better job of explaining this at present than I can hope to, so I'm going to stick to my little corner of data centric security and bow to his superior experience in these matters. I'm also planning to speak to him about it sometime this week, perhaps I should record the call and post it here.

What works well for laptops does not work well for desktops. Laptop encryption cannot rely on a central repository of keys for encryption, because they are mobile. A key must be kept on the local machine, and the only way to protect it is with a password. Therefore, laptop encryption can only ever be as strong as a password. In a fixed desktop and server environment, encryption can be administered centrally, and we can use asymmetric encryption to protect files.

In a database environment, file encryption does not protect from internal RDBMS users, i.e. the 'rogue DBA' we hear so much about. Row and column encryption is a far more effective way of protecting databases and applying proper controls. None of these solutions can protect email, and a special email encryption gateway is required for this, which brings up all the issues of end point protection, data leakage, and everything Rich has been talking about recently.

The method of encryption rarely matters, if the maximum strength algorithm and a large enough key are used, any method should be as good as another. The keys and algorithms are not the whole story for these methods however. Laptop encryption relies on a password, but the business drivers tend to be around speed of encryption, so algorithms are closely guarded. Desktop/server file encryption relies heavily on access controls and policies, as does database encryption. These are usually client-server encryption solutions, an agent residing on the machine to be encrypted on, keys kept on a key management hardware device - usually FIPS compliant, or available in a FIPS compliant option.

Email encryption has all of the issues of access control and key management, policies, plus the added complexity and overhead of having to encrypt, store and decrypt a large number of small files. I wrote about elliptic curve cryptography recently, and this looks like a great solution in this area, but not something that scales back to databases or file encryption, or laptops.

The real key to encryption is... just that, the key. With a symmetric key, if it is discovered, data can be breached, so asymmetric keys are preferable, where the private key can be protected. The private keys then become extremely important to an organisation, and very tough to manage, however any algorithm can be used, any method of encryption or access control/policy can be used. Key management is the killer app in the encryption space.

Saturday, 29 September 2007

Digging deeper

I wrote yesterday about the reactions I am getting to encryption. 5 or 6 years ago when I talked to people about the same products which I am representing now, people who were interested were enthusiastic, but few and far between. Now they are less enthused, but there are far more of them. It's as though there's a finite amount of enthusiasm about encryption in the world, and it's slowly spreading around. Encryption enthusiasm entropy if you will.

The reality of the matter is that exactly the same number of people need encryption (i.e. everyone with any confidential information), but now compliance is forcing some of them who weren't interested in taking it any further into doing so. So I remain ambivalent towards compliance. On the one hand it is necessary to drive security forwards, on the other, it pushes people in the wrong directions. On the one hand it drives sales, on the other it makes people resent good intentions.

I've talked about compliance and the state of the market for too long now however, I don't think there is much more that can be said. If you want to know anything about compliance, read PCI Compliance Demystified where I haven't posted for too long, risk, read Riskanalys.is, and for the state of the market you can't get much better than Mark Curphey. If I start talking about data security, Rich will only do it better, and in more detail, then Hoff will jump in and make things complicated, but with great pictures.

So whilst I'm still after finding my niche, and whereas I deal with all of these issues still, I'm going to try a few more technical posts for a week or so, primarily to prove to myself that I still can, but also to get back to familiarity with the subjects I'm dealing with now. I hope you enjoy the 'back to basics' approach I am taking, and appreciate that it is purely for my own benefit. In the meantime, keep reading the guys I mentioned above, and I'm sure I'll go back to normal again soon.

Friday, 28 September 2007

Shifting sands

I have traditionally worked for companies where I end up talking in quite a lot of technical detail to people who often have better technical knowledge, and sometimes better security knowledge than I do. I'd be surprised if anyone else hadn't.

In my last job as a Product Manager, everyone I spoke to was more technical than me on the development side, and the customers I spoke to were the market leaders, the visionaries and early adopters. These are often better informed and better read than those who follow.
Before that, as pre-sales manager at a distributor, I dealt with network and security architects, product specialists and SEs on a daily basis. I often had to ask people to repeat themselves or slow down and explain - and this was before I went to Spain.

Previous to this I was at another vendor, in a similar position to that which I find myself now. Those of you who are regular readers will know they were a competitor of my current company, but I am not the kiss and tell type (not that I kissed any of them). I was the product specialist, but people usually knew more about the networks, or why they needed the security, than I did.
Encryption has never been mainstream, it is part of our everyday usage of the internet, but it's built in, so we barely notice SSL sessions being set up, or passwords being stored in an encrypted file on a server unless we are in the business.

Recently, i.e. this week, I have been traveling the country, visiting new customers, installing new kit and talking about security - as I planned to do from the start, and I'm really enjoying it. However, "The Customer" has changed. Whereas before I usually dealt with a technical guy who had demanded to use encryption in his project because it would help achieve something for the business, now the business is demanding that the technical guy use encryption to satisfy a regulation. They don't like it. They aren't as interested in it. It makes my job a lot harder.
The technology is easier to use, it breaks less often, it fills a specific business need, and is quicker to set up. The technical meetings are kept light hearted, because if they ever get in depth, I am the bad guy, no longer "the interesting guy".

I guess I should be glad, encryption is finally becoming more popular to the business, if not amongst the workers. I should be glad because I will get paid on what the business gets paid. I can't help feeling a little bit sad at the fact that the people I am working with just want to get it done though, rather than sharing in my interest as they have done before.

I guess it's my job to change that.

Tuesday, 25 September 2007

The Word on the Street

I'm glad to see that everyone has an opinion on the Jericho Forum. Even if some of you are completely wrong! Obviously I won't be proven right until the last firewall and IDS box is disconnected and Richard Stiennon is carted off to the asylum, but it's closer than you think.

Mostly though, your opinions have little effect on what the market actually decides, which is, of course, why I'm right. I'm selling what I'm selling (Ingrian Networks), because of what I believe in, not the other way around. It just so happens that business in the UK is absolutely flying at the moment. I'm only on day 3 of official activities and I've got a list of "to dos" as long as your arm. Most of them learning more about the stuff I love and can't stop talking about.

I like to keep myself informed however, and having been away for a few months, I wasn't sure of how the market in the UK was looking. When I left for Spain, the economy was strong, load balancers were selling like hot cakes, SIEM/SIM was the exciting new thing on the block and at least 3 vendors (Bluecoat, F5 and Juniper) were converging on devices which did pretty much the same thing, but from different angles. I was waiting to see which would sell best.

Despite knowing lovely ladies in each (Lucy at Bluecoat, Louise at F5 and Sarah at Juniper), I haven't stayed in touch with the market movements, and would probably get biased reports anyway. So, what's the solution? My old friends in distribution, they NEVER lie.

I spoke to Bruce, the Business Development Manager at Equip/Horizon just this evening, and he seemed downcast. Apparently, since the economy's taken a hit, the business has started to dry up. Then he perked up a bit, seeming to enjoy the challenge, saying that he needed to find a way to differentiate better and drive business forwards. Knowing Bruce, he will do it.

But why has our economy taken a hit? Well, when the subprime mortgage crisis hit the US, the banks in the UK stopped borrowing off each other, imagining each other to own some of the US debt, and clamming up, like a clam. When the borrowing stopped, the cash stopped flowing, banks which relied on interbank dealing to make their profits threatened to disappear overnight (Northern Rock), until the government stepped in to rescue them.

The economy is looking shaky as a result, manufacturing has obviously taken a hit as no-one has faith in the high street, which in turn means no-one has faith in anything else you can buy. Thus, no-one is buying what I like to call "stuff".

I blame the Americans.

Monday, 24 September 2007

We shall fight them at the perimeter...

I was interested to read all the Jericho stuff going around recently. One thing I wanted to put right immediately was Stiennon's reference to Jericho being like the Flat Earth Society. That's completely the wrong way around. Everyone used to believe the world was flat, up until, ooh, I don't know maybe Aristotle, Strabo or Ptolemy, who all wrote about it. Yes, the Ancient Greeks knew way in advance of Columbus. That's not the point though, only in the last 2000 years have the educated believed, then proved, then observed that the Earth is in fact round.

Networks are nowhere near as old as the Earth. However, people laughed, mocked, criticised and ostracised those who believed in the round earth theory before it was commonly accepted - even though it was right. Jericho is much more like the round earth theory. It is old school network security
which hasn't moved with the times. The Flat Earth Society are a bunch of misinformed people who hang on to old thinking, ignore proof and science and construct paranoid theories because it suits their ends. I'm saying nothing more.

I have met with Andrew Yeomans a couple of times, once when I was a spotty young thing, once more recently, and I am fairly familiar with the Forum's work as a result of these meetings. After I posted a sarcastic message on Hoff's recent post about how Andrew failed to recognise me at InfoSec (hardly surprising now I have blossomed into a rugged hunk of a man) I had a mail from him, apologising. After I'd cleared up the coffee that I'd spat all over my desk, I dropped him a mail back to see how things were going.

First of all he pointed me here: https://www.opengroup.org/jericho/brochureJF070828.pdf as many of my questions were for personal reasons, and I wanted to know how I could get involved. Then he must have got sidetracked, because he went on to clarify things in a much more verbose way. Rather than spoil this with too much of my own moribund rhetoric, here's the salient points, straight from the horse's outbox:

"One key message is that "de-perimeterisation" is the business problem, not the proposed security solution. If we believed we could still maintain a neat defensive perimeter around our networks, I'm sure we would do so as it makes our work easier. But the business requirements drive us to do business - on equal terms - with partners; they ask us to outsource the management of IT assets; and they ask us to support connections for business partners within our networks. And those requirements mean that the traditional firewall defences are just becoming less useful as a true security measure, as we've already let outsiders into the networks."

This sums up my feelings about the current state of security very neatly. Anyone still crapping on about network security these days has missed the boat and needs a new haircut. Sorry, I knew if I started saying stuff it would end up sounding bitchy... back to AY:

"We still see some point of firewalls and other types of network defence, but they are in transition, moving from the old days of attempting to provide confidentiality and integrity, into the new view of providing availability or quality-of-service. So the firewalls filter out network junk; but the networks and systems should be designed to continue to function even if that junk got through."

So, Andrew even doffs his cap to the firewall/IDS crowd, but then makes the real point which is at the heart of all of this - the systems should be designed to continue to function, whatever gets through. Then, in time, the perimeter stuff is totally UNnecessary. This isn't his view, it's mine, I don't see the point of these lumbering great boxes all round the perimeter. As he says, they just become availability management boxes, and that can be built into software. OK, I admit they have their place now because the data security hasn't yet been built in, but they will disappear in favour of something more... virtual? distributed? a framework? A virtual distributed framework? Software at any rate. Take off the blinkers, look at the patterns, look into the future.

Is that the problem we have here, the Jericho Forum is looking too far forward for anyone to take it seriously? For all the talking I would have expected bloggers at least to understand these points a bit better, that they are not going to arrive on your doorstep in the morning. If I wanted to sell something that was popular now I'd make yet another NAC device.

"We realise that this has not always been understood in the media, so have been thinking of ways to present this more clearly. I came up with the term "Collaboration Oriented Architecture" http://en.wikipedia.org/wiki/Collaboration_Oriented_Architecture though there's still debate whether that is the best terminology.

We have had debates whether this is de-perimeterisation or re-perimeterisation or micro-perimeterisation or whatever. The terminology might help the product marketing buzzword people, but it's not proven very useful when it comes to designing a security architecture. Of course we have Policy Decision Points and Policy Enforcement Points; and you could join these and say that's where the perimeter is. But when those PEPs and PDPs go round mobile items of data, it's a moot point to say it's a perimeter at all. As for "fractal perimeters", that might sound buzzword compliant, but I won't believe it has any real meaning until someone measures the fractal dimension."

Yes, "fractal perimeters" does indeed sound like some marketing turd with a linear constant greater than or equal to 1. Please ignore them as if your reputation depends on it. It will do. It doesn't even sound buzzword compliant to my ears, just bollocks, but Andrew is far too constructive and polite to say that.

I hope that's cleared a few things up for you nay-sayers and non-believers. Andrew parenthesises at the end of his mail, in case you were wondering: Great Britain coastline has a fractal dimension of around 1.24.

Sunday, 23 September 2007

Newby

As Rich noted a couple of weeks back, I'm a Newby again. Today is my first (official) day with Ingrian Networks. I'm up at the break of day, which is how I prefer it after the fog has cleared, and have a few moments to reflect before a quick drive up the M3 in my shiny new car.

It feels like yesterday still that I was sitting in a top floor office in central Barcelona, sweating and swearing, trying to sell software. Already I'm back in the UK, back in my flat, and back to work in what seems like such a short time. I could use another 6 months holiday to be honest, but then I'd run out of money, my wife would leave me and the house would be repossessed, so on balance, I think I'm better off working. And what better way to fill my days than talking about something I love: encryption. Actually, Ingrian's portfolio is broader than just encryption, it is db and application security, data security (yipee!), key management and encryption. All of these words get me more excited than the average human is supposed to about such terms. All except one, which is a new departure for me. And about bloody time.

I am quite recent to application security, and whilst I follow Jeremiah Grossman, RSnake et al. as much as possible, it has always seemed like a different art to what I know. From today that's going to change, and I'm going to be cutting my teeth in public (if that doesn't sound too weird). I will be writing my learnings here and hopefully be put straight on a few things where needed. I'll keep on throwing the data stuff around too, but maybe I'll become a bit more rounded, and more technical, in the coming months as I settle in to my new role.

After that, the role will be evolving with me, the aim is for Ingrian in EMEA is to grow significantly in the coming year to 18 months, I will be heading up the technical/services side, with Jon (Shaw) heading up the Sales team across the region. I love the smell of business, especially a successful one, and this has all the hallmarks of being a great move for me. Watch this space, and hopefully there will be some meaningful security in here soon!

Friday, 21 September 2007

The Horns of Jericho

Hoff and Mogull, 2 people I admire very much, have been blethering on at each other about Jericho for what seems like weeks now. I gave up reading after the first "yeah, but..." to be honest, but tried to set a few things straight in an argument which was essentially about two sides of the same coin, and not really anything to do with the Forum itself, but the media coverage it gets. Like blaming Prince Charles (sad looking chap, big ears, married a horse) for being the Queen's son.

I received an email from Andrew Yeomans for my troubles, a more gentle and kind man you could not hope to meet. He sounds incredibly busy, and was bemused as to what all the fuss was about. So on behalf of Andrew et al. who don't have as much free time as me:

The Jericho Forum has been around for donkey's years (I don't have exact figures, but consider the average age of a donkey, and they're about that old). When it was first set up, everyone said "ha ha, that's crap, it'll never catch on" and compared them to Chicken Little. Some years later (i.e. now) everyone is saying "ha ha, everything they're saying is obvious", or "ha ha, they're saying it wrong".

I'm not going to pull out the old cliche about laughing at Christopher Columbus or Edison (or is that a song...?), but really, look at what you're saying, and consider why you're saying it guys! Personally, I've backed the JF stance since I first heard it from Andrew's own lips 7 years ago, before he was on the management board. As a movement it has it's own momentum, and the people who are part of it's management team are merely sticking to their guns. They are all hugely respected security officers in their own rights. That the message hasn't changed should be admirable, not risible. It means they got it right first time. That it is only a set of guiding principles is GOOD in my opinion. That the media reacts with FUD is no concern of the JF.

Bloody foreigners.

MadKasting