From the Blogosphere
What ‘Mr. Robot’ Can Teach Us About Incident Response | @CloudExpo #IoT #Cloud #Security
It is not often that movies and television shows give viewers the opportunity to explore the world of hacking & digital security
Dec. 8, 2016 10:00 AM
It is not often that movies and television shows give viewers the opportunity to explore the world of hacking and digital security in a realistic manner. After two seasons, "Mr. Robot" has attracted its share of IT professionals as well as average citizens. The show has offered numerous depictions that are of particular interest to those who make their living by protecting their organizations.
The critically acclaimed television series offers fictional situations rather than documentary evidence. However, the plots and actions of both the security engineers and hackers are realistic enough that they can send a shiver down the spine of any professional responsible for safeguarding their organization's system and responding to incidents. This two-part post explores some of the most chilling incidents depicted on the show - incidents that are especially disturbing because they can and do happen in the real world.
People Are the Weak Link
Employees are walking, talking cyber-risks. Sometimes they commit breaches out of anger or because they have been offered payment for sensitive data. At other times, they are innocent pawns or fall victim to a phishing attack. For example, in one episode of "Mr. Robot," Elliot is able to gain physical access to Steel Mountain by manipulating an eager-to-please employee. Elliot himself is an example of an employee who is working to sabotage his employer. One of the worst things about insider hacking is that it can be months or years before it is detected. Controlling access and permissions by employee can help as well as keeping a log of everything that comes in and goes out over the network.
Passwords Present Problems
Users prefer to select passwords that they can easily remember and, in many cases, they use the same password or a slightly modified form of it for all of their sites. If the password is difficult to remember, the user will probably write it down. In one episode, an attorney kept the password to her email account on a sticky note on her desk. In case you're wondering whether users are still playing fast and loose with passwords, you need only check SplashData's list of the worst passwords found in 2 million leaked passwords. Despite compiling and publishing the list annually, the password "123456" still tops the list, followed by "password," "12345678," and "qwerty." Security professionals must be more proactive about training users in the selection of easy-to-remember but hard-to-guess passwords, keeping passwords private and choosing different passwords for every platform.
There Are Times When Being Social Is a Mistake
It is amazing what you can learn from many people's Facebook pages. Information such as their mother's maiden name, the users' date of birth, names of children, favorite pet and much more is often posted for all to see. In many instances, this is all the information that a hacker needs to respond correctly to a secret question in order to have the password reset. Hackers can also use the information to guess passwords. In one episode, Elliot is able to access his therapist's accounts by guessing that her password was a combination of her birth year and the name of her favorite musical artist. However, Elliot has also been able to glean information over the phone and in person by misrepresenting himself.
Never Expect Privacy from a Public Network
In the very first episode, Elliot exposes the manager of a coffee shop as the owner of a website featuring child pornography. He discovered the truth by observing the manager's activities through the coffee shop's public Wi-Fi network. With just a bit of free software and a little technical knowledge, intercepting people's activities is relatively easy on an unprotected network. Employees should be warned to avoid using public networks to access email accounts or conduct other activities that could leave their personal data exposed.
Skimping on Security Investments Is a Mistake
In one episode, Elliot winds up in a hospital, and it's revealed that he chose the hospital because of its one-person IT department that operates on an inadequate budget. He has no problem hacking the hospital's database to alter records. Organizations that do not make the necessary investments in personnel and hardware could suffer a similar fate, especially if they do not bother to keep software updated.