RSSAmplifier

Blog

Privacy, Power, & Protection In The Cyber Century

Recent content on Privacy, Power, & Protection In The Cyber Century

blog.eutopian.ioRSS feed ↗39 posts

Latest posts

Rating Cyber Security Practitioners

1330 words, 5 minutes. Jean-Léon Gérôme, The Gladiators (Bronze, c.1878). Do you like hyper-masculine, gladiatorial confrontations where losers suffer not just the ignominy of defeat but significant even permanent loss of status in a rigid hierarchical system? You do, do you? Well then you’ll like this. Or do you think that sounds detestable? If so you’ll want to defeat this barbarous…

Huawei 5G, The UK Gets A Lesson In Go

4300 words, 14 minutes. This post was circulated privately in April 2020. Three months later the government announced that Huawei 5G equipment will be removed from the UK by 2027, a reversal of their previous position. I’ve updated the timeline with that development. Otherwise, the text is almost unchanged from the original. Keep that in mind. It follows my July 2019post on the consideration…

Huawei 5G

4095 words, 16 minutes. A Diplomatic (Chinese) Design Presented to the U.S. – 12th February 1881 by Thomas Nast, for Harper’s Weekly. I rarely mention vendors here, so this post is an exception. It’s the second in my “Projectionist”series. The series is ultimately about power and the great forces and constraints shaping our world. I’m going to talk about 5G, Huawei, China…

Comment on FT/NSO/Cloud Article July 19th 2019

650 words, 2 1/2 minutes. Article Financial Times article “Israeli group’s spyware ‘offers keys to Big Tech’s cloud’”, Mehul Srivastava in Tel Aviv and Tim Bradshaw in London, July 19th 2019. https://www.ft.com/content/95b91412-a946-11e9-b6ee-3cdf3174eb89 Comment This comment is provided on the basis that the article is factually correct and the details within are technically accurate.…

APT34 Tools Leak

4300 words, 17 minutes (full). 1500 words, 6 minutes (short). The seven great monarchies of the ancient eastern world. Rawlinson, George. Pub. Lovell 1862. Sketched from North Palace, Koyunjik (Nineveh).` Leak Summary APT34 is an Advanced Persistent Threat group associated with the Islamic Republic of Iran. Its source code and tools were recently leaked via a Telegram channel. In addition to those…

The Projectionist

750 words, 3 minutes. The reason I don’t post on Cyber Security current affairs? It’s a scramble to be first. If I’m to write something, what should it be? What’s my angle? Which lens do I use on the microscope, or since this is a mass medium, the projector? What film can I show you that you haven’t already seen a dozen times? I’ll attempt to answer these questions…

Documenting Breaches With H Diagrams

1500 words, 6 minutes. “For the sake of brevity, we will always represent this number by the letter e” - Leonhard Euler, Mechanica. 1736. Illustration Pub. 1881. What if you could understand and explain any breach 10x faster? Security breaches are a staple of mainstream news. In the past, details only emerged through technical analysis, research papers, and the forensic review of press releases.…

Attack Surface Reduction By Dynamic Compilation

1850 words, 7 minutes. …or, how the cave fish lost his eyes. Iranocypris typhlops - 1944, By B.Coad for Bruun & Kaiser. This post follows directly from the last. In that post, we learned that everyone could do something to reduce their attack surface and decrease the likelihood of a breach. I’m going to show you what that winning system looks like when taken to its ultimate logical…

Winning Systems & Security Practitioners 7. Attack Surface Reduction

2000 words, 7 1/2 minutes. Attack Surface Reduction Illustrerad verldshistoria utgifven av E. Wallis. volume I. 1875-9. “Out of every hundred men, ten shouldn’t be there, eighty are just targets” Heraclitus 535 - 475 BC. My posts on Winning Systems for Cyber Security Practitioners are my most popular. In them, I attempt to change your perspective on the relative importance of products and…

Work In Progress

650 words, 2 1/2 minutes. A Metapost This is a post about posting. Expect changes, deletions, corrections and improvements. From my first post in July 2017: I expect much of the content here to be around the subject of what we now call Cyber Security, since this is a field I began researching around 1990 and have worked professionally within for years in both an offensive and defensive capacity.…

Geopolitics For Fun & Profit

1750 words, 7 minutes. Sketch by Sir William Rothenstein, 1933. “Who rules East Europe commands the Heartland. Who rules the Heartland commands the World-Island. Who rules the World-Island commands the world." - Sir Halford Mackinder, Democratic Ideals and Reality. 1919. Do you work in technology, are you building a company? You should think about how your product or service fits with the…

A Universal Lemma For Compliance

2500 words, 9 1/2 minutes. Matthew Hopkins, Witchfinder General. 1647 Engraving. Here I describe a lemma1 or helping theorem for technical compliance of IT with a focus on Information Security. It’s an approach for all compliance regimes whether regulatory or corporate. It doesn’t date, nor is it predicated on a technology or platform. It isn’t a trick. It doesn’t provide…

The Largest Open Goal In Cyber Security

1000 words, 4 minutes. “But how was one to explain repeated instances of derisive laughter at melodramas and films that hardly set out to be funny?" - Prof. Eric Rentschler1 Out of place laughter is an anarchist in the dark. Someone who refuses to let the film cast its spell. Imagery is important. Moving or still. Whether it be religious iconography, depictions of national myth, a coat of…

NSA PRISM's Commercial Cousin

2200 words, 11 minutes. Engineering, Vol. 62, December 18 1896. “In 1882 I was in Vienna, where I met an American whom I had known in the States. He said: ‘Hang your chemistry and electricity! If you want to make a pile of money, invent something that will enable these Europeans to cut each others’ throats with greater facility.’” - Hiram Maxim. Selling arms during an arms race…

Avoiding The Infosec Extinction Part 2.

1600 words, 8 minutes. Turning Up The Magnification Three lens microscope for simultaneous observations. 1882 This is the second of a short series of posts about the Cyber Security market. This market is interesting now because I believe it’s at a juncture where we can choose one of two possible futures. We being the product builders, investors, and customers. In the previous postI presented…

The Next Big Thing? Go Back To The Future.

1500 words, 7 minutes. Man, embracing his origin, … civilization, … mental and moral faculties. … Illustrated. Lind, G. Dallas, 1884. I’m interested in the history of technology, especially those moments which gave rise to great advances or failures. I’m interested to know the conditions, the growth medium, the organisational structures, the management strategy…

Don't help the CSO out. Build him up!

950 words, 4 1/2 minutes. One of the reasons why organisations ultimately fail at Cyber Security, is because the office of the CSO lacks power. In this post I’ll explain why that is and what we can do about it. Why The CSO Lacks Power The Cyber Security industry constantly strives to produce better products and services. Engineers work tirelessly to improve deployment practices. There are dozens…

Avoiding The Infosec Extinction Part 1.

800 words, 3 1/2 minutes. Making Your 1st Decision This is the first of a short series of posts about the Cyber Security market. This market is interesting now because I believe it’s at a juncture where we can choose one of two possible futures. We being the product builders, investors, and customers. The choice being whether to align ourselves with reality or fantasy. Plenty of markets…

Breach Handling & The High Ground

1600 words, 8 minutes. You’ve suffered a breach. Your security was circumvented. Data was lost and the public, shareholders, media, and perhaps regulator must soon be informed. A chain of events has begun. What you do next will determine in large part where that chain leads. In this post I’m going to talk about a tactic I’ve seen used to successfully re-frame a bad situation and…

AI & The Great Reorientation

600 words, 3 minutes. Photograph of UK’s first cash machine installation 1967. Martins Bank Archive. In this bite-sized post I’m going to talk about the lag between initial adoption of transformative technology and the increase in productivity it’s supposed to bring. I’m going to talk about the disappointment felt when such technology meets established, dogmatic structures…

An Idea Whose Time Has Come

950 words, 4 1/2 minutes. Hugo by Étienne Carjat, 1876 “Nothing is as powerful as an idea whose time has come." - Victor Hugo. This is the second of two posts on strategic software. The first explained what it is, what it does, and where to find it. Now I’ll tell you why it’s an idea whose time has come. I’ll tell you why it will be more powerful in some respects than…

The Age Of Strategic Software

1300 words, 5 minutes. Belloc by E. O. Hoppé, 1915. “Whatever happens, we have got the Maxim gun, they have not." - Hilaire Belloc. Once upon a time software was just for counting beans. It counted more beans faster and cheaper than anything else. Then computers became personal, then portable, then pocketable. All sorts of different kinds of software were created to serve the people and help…

Better Odds For VCs & Founders

1500 words, 7 minutes. Fishing Through Ice, Bain News Service. c.1910. This post is written from the perspective of a VC screening for success factors. In it, I drill deeper into successful operational characteristics. If you’re an entrepreneur or founder, you should give consideration to adopting some of the systems I talk about here. I’ll even suggest prioritising them over features…

Beating The Samson Option

1300-1600 words, 6 1/2 to 8 1/2 minutes. An Etching of Samson by Julius Schnorr von Carolsfeld, from an 1882 German Bible. “He grasped two pillars of the temple and bowed himself with all his might” - Judges 16:30. Introduction This post is about online services which rely partly, or wholly, on user-contributed content. It’s about what happens to that content if those services…

Building A Better LinkedIn

1300 words, 4 and a half minutes. This will probably be the first and last time I write about social networking. I’m an antisocial social networker. I had an expectation that part of the job of a networking platform (professional or social) would be to filter content or updates, both in terms of who was posting them and the individual significance or quality of the posts. Boy was I wrong.…

Winning Systems & Security Practitioners 6. Final Remarks

550 words, 2 minutes. Final Remarks “All men can see the tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved” - Sun Tzu. This is the 6th and final post in a short series on winning systems for security practitioners. The first postfeels like a while ago already, about 6000 words or 25 minutes. Those minutes haven’t been wasted. The…

Winning Systems & Security Practitioners 5. Resilience

1450 words, 5 1/2 minutes. Resilience “In defeat: Defiance” - Winston S. Churchill. This is part 5 of 6 in a short series of posts on winning systems for Information Security practitioners. It aims to plug the gap between policy and products and put you, the practitioner, back in the driving seat. After all if you don’t know what system you’re implementing, how can you…

Winning Systems & Security Practitioners 4. Robustness

1200 words, 5 minutes. Robustness “The first virtue in a soldier is endurance of fatigue." - Napoleon Bonaparte. This is part 4 of 6 in a short series of posts on winning systems for Information Security practitioners. It aims to plug the gap between policy and products and put you, the practitioner, back in the driving seat. After all if you don’t know what system you’re…

Winning Systems & Security Practitioners 3. Responsiveness

1100 words, 4 1/2 minutes. Responsiveness “No battle plan ever survives contact with the enemy” - Helmuth von Moltke. This is part 3 of 6 in a short series of posts on winning systems for Information Security practitioners. It aims to plug the gap between policy and products and put you, the practitioner, back in the driving seat. After all if you don’t know what system…

Winning Systems & Security Practitioners 2. Preparation

1100 words, 4 1/2 minutes. Preparation “One of the best ways to keep peace is to be prepared for war” - Plato & others. Today attacks come thick and fast. The chances are that all public IPv4 address space is regularly scanned. Time-to-compromise of an unpatched, non-firewalled, Microsoft Windows host is about 5 minutes. Systems are attacked not because they are valuable, but because…

Winning Systems & Security Practitioners 1. Introduction

1100 words, 4 1/2 minutes. Introduction “Never tell people how to do things. Tell them what to do and they will surprise you with their ingenuity." - George S. Patton If you’ve read my previous postyou’ll know that to get beneficial, long lasting, low-maintenance results in Information Security, you need winning systems. Not skills. If you like grinding monotony punctuated by…

Forget Solving The Cyber Security Skills Shortage

1100 words, 4 minutes. This post is one of a short series on structural and systemic things the Information Security industry does wrong, and what we might do about them. Disclaimer: I advocate lifelong learning, that includes professional training, product training, workshops, online or in-person courses, and academic study. The professional trainers I know who author and deliver their own…

The Age Of Invisible Disasters

1400 words, 5 minutes. The Tay Bridge disaster occurred during a violent storm on 28th December 1879 when the first Tay Rail Bridge collapsed while a train was passing over it from Wormit to Dundee, killing all 70 people aboard. It is widely accepted by engineers that disasters teach us more than successes. Said another way, we don’t learn from the bridge that stays standing. After the Tay…

Elephant Proofing Your Web Servers

750 words, 3 minutes. The Case For Default Deny What’s free, permanently reduces your exposure to a range of potential vulnerabilities, requires no maintenance, and takes only a few minutes to implement? Most web servers are installed to serve content to unauthenticated users on the Internet. Most only have a finite list of URLs or a specific number of web apps. I’ve always thought it…

About me

900 words, 3 minutes. Arno Breker’s Dionysos. 1936. 20+ years as CTO, Founder, Investor, Product Manager, Consultant, Engineer & advisor to corporations, law enforcement, government, & NGOs. Cyber Security Éminence Grise. Still a work in progress. This is how I got here: From Internet Start-Up To Global Telecommunications Giant In 5 Years I started researching computer and network security…

Arrival

1200 words, 4 1/2 minutes. Welcome to the first post of my blog. Here I explain the why, what, and how of everything else you will see on this site. If you want to know more about the who, then read this. Most of my professional life involves winning systems or processes I’ve already established, monitoring progress or performance against targets, solving recognised problems. Here is where I…

Copyright

220 words, 1 minute. Attribution-ShareAlike 4.0 International (CC BY-SA 4.0) Unless described otherwise, the contents of this site are provided under the terms of the Creative Commons CC BY-SA license. I am the sole author of the text of the articles appearing on this site. Where direct quotations are used they are attributed to their originator. Where images are used they are: Original Work.…

The Stack

360 words, about 1 minute. The site is built and maintained by me using Hugo, a static site generator written in Go. It’s running on a FreeBSD nginx web server. By the time you read this nginx will probably be inside a jail. The theme is a port of Ghost/Casper. My criteria was low maintenance, good security, performance, and simplicity. The content is all written in Markdown in a text…

PGP Pub Key

-----BEGIN PGP PUBLIC KEY BLOCK----- Version: SKS 1.1.5 Comment: Hostname: pgp.mit.edu mQINBFkCCS4BEAC8cC7geoSLb6xG+BM2XCCMl81KxIibgs+5UuD2slIvGBVntWg2BYQF5oHD Dbcqx3FmiRkU5L9clwYTMpR9293b4+fk64cPm1bGx0YTU6vpRmA+Cc5Q36Mny/okhWNr0Fxb UMh+EfTIjp/U0zXF/sFLcZgM0pUO0KRkaWkcLuuD0QuCx93Eo4IY169RqPwjRhw33EhDpgmC Xrfwnug31CTt+z6VNFmYv9Pm14u8ct/8wBh47J374mlRm+fTovw0qzokUYDAd4l9PHF0+K9l…