A Substack article by author Rosy Gee reminded me of my introduction to the security industry, many decades ago. (You may remember my interviewing Rosy regarding her novel The Mysterious Disappearance of Marsha Boden.) I too began with an Amstrad home computer (the PCW8512) that was primarily marketed as a word processor, though it also ran the operating system CPM+, which enabled me to experiment with a range of other software, from programming languages to some of the office applications of the day (Wordstar, DataStar, SuperCalc). That was comparatively late in my career, but early in my IT career. That is, as long as you don’t count the programming job I didn’t get in my early 20s. Unsurprisingly, as I hadn’t touched even a calculator at that point: still, the interviewer did offer me the chance to play guitar behind his daughter, a singer, but I didn’t follow up on that, for whatever reason.
I was in my 30s when I bought my Amstrad, having just been made redundant from a job in the building trade. The last time I clocked off from that job, I promised myself I’d never punch another clock card – I haven’t! – so I started looking for retraining in areas that would suit me better. There were no retraining opportunities in programming, in which I’d been interested for some time, for someone so ancient. However, I did accidentally fall into a secretarial course that included some hands-on IT and even a data-processing side-qualification, and that was my first step into the IT industry (and eventually the security and antimalware sectors of IT). I think it was actually the data-processing course I applied for, but it was suggested that I was well qualified for the secretarial course as well, and it seemed sensible to take the opportunity to diversify.
That certification led me to an administrative job, where I sometimes used a PC and coded my first programmes for money, but also spent much work time sitting behind a terminal connected to a mini-computer, running a very slow database app on a primitive CPM-like multi-user system called TurboDOS, as well as doing some work that was purely secretarial.
At the same time I resumed my academic aspirations with some courses at the Open University. And all that took me to another administrative job that gave me access to a wider range of systems, using and supporting dumb terminals, dedicated word processors, and some (by modern standards) pretty primitive PC and Apple desktops – often using terminal emulation software so as to access ‘real’ computing power: Unix or VMS, mostly). Kermit may be a frog to you, but it’s still a communications protocol to me! Not that I’ve used it in a very long time. Over the next decade or so, my job expanded into systems administration, user support, and eventually security (specializing in malware, which is how I passed from a managerial role in the NHS to providing consultancy to the antivirus/antimalware industry).
At that time, internet connections were usually via some form of ‘big iron’ using dumb terminals or terminal emulation software like the afore-mentioned Kermit or NCSA telnet. Connections from home were usually via a painfully slow modem, using a service like Compuserve, Prodigy, or CIX. I was fortunate enough to be able to access work systems from home, which made it easier for me to work from home when necessary. As my daughter was then very young and my wife often worked away from home, that was already very helpful, and even more so when I became a single parent, since I was able to make up for work hours lost during the day by connecting from home during the evening and at weekends.
However, in the office, the rigid distinction between the desktop and the server was eroding in the 90s as desktop machines started to evolve into multi-user systems sharing resources and accounts across networks. (I remember a Novell Netware admin complaining when PCs on his network began to try to connect to my experimental NT system (which also ran Windows and Linux) ahead of his production Netware servers.) Portables become truly portable rather than luggable, so it was practicable to use the same machine at home and at work. Before you could say “telnet”, road warriors and people working from home became able to VPN into the workplace intranet and/or use their work account as a doorway to the internet, or continue to work on the same documents they were working on in the office, or access an enterprise email server. Still, iIn the enterprise environment, the “private” cloud with low bandwidth connections to Novell networks or AppleTalk, or an Intranet run off VAX or UNIX clusters, was slowly giving way to architectures where the default “cloud” was the Internet and/or the web (not always the same thing).
In a sense, we have had an online existence for a long time, even when our link to the world was filtered through AOL or CompuServe. However, the size of the cloud has increased exponentially (for once that overused term is actually appropriate), and so has the number of devices we use as a channel into it. And we live our lives distributed over multiple devices. We don’t just access The Cloud, we live in it. That is, we don’t readily distinguish between our private and work lives, as witnessed by all the devices we use to access our on-line personae (work-related and recreational).
Many of us have come a long way from the issue of a corporate laptop with a standard image and the lowest possible level of privilege for the intended user’s account. The Bring Your Own Device (BYOD) culture means that where we once might have been allowed to access work resources from home, we’re now often encouraged or forced to save our bosses the expense of providing us with company-owned hardware. In fact, we live our lives distributed over multiple devices. My iGadgets and phone don’t have quite all the functionality of my first work laptop – I’m sorry, but I need a full-size keyboard, being a trained typist – but they have more storage, computing power, and general usability, and didn’t cost the company I last worked with a penny in outlay for hardware, training, or software. Even I, a dyed-in-the-wool reactionary dinosaur who refuses to do anything on a mobile phone that he can do better on a laptop, have been known to give presentations from my own laptops or even my tablet, which has never benefited from the tender security-enhancing ministrations of an IT department.
Many of us (especially those of a certain age) see our offspring (and even their offspring) flit from device to device like butterflies. Much of the time they’re accessing the same apps, services and data even while they’re jumping from platform to platform like Lemmings, from smartphone to tablet, from iOS to Android, from family PC to boyfriend’s or girlfriend’s MacBook. But even my generation of IT professional expects a certain amount of interoperability between our smartphones and our laptops, and we are disappointed when our tablets and desktops don’t play together nicely. Naturally, even this far from consistent degree of interoperability has security implications.
There’s some divergence between the older generation of desktop-oriented operating systems, as opposed to operating systems designed for mobile devices. The hardware vendor can exercise more control over what applications – not only malware, but security software – can be installed on mobile devices. In fact, the major vendors of smartphones and tablets are reluctant to admit that their OS is anything but impregnable, and have sometimes actively suppressed the legitimate use of some security apps. While the big players currently selling into this space are able to exercise more control (or veto) over the installation of unhealthy apps by incautious customers than we are used to in desktop operating systems, that security can be subverted by jailbreaking or obtaining apps from an unofficial source. Bypassing security and escalating privilege on a corporate laptop is unlikely to be in the skill-set or comfort zone of the average corporate end-user, but those inhibitions are less likely to apply to something that’s perceived primarily as a personal (and recreational) device.
However, malware is not the only security issue with a device that commutes with you, and not necessarily the most critical: let us not forget phishing, smishing, targeted social engineering scams of all sorts, loss and theft of an easily portable device that may or may not be protected with PINs and passwords. In the case of such a device, the exposure is not only of the data it contains, but the data it can access from a central or external resource.
In a BYOD world, it might be just too much trouble to ensure that each and every device that might be connected to the corporate network is required to authenticate properly, or runs appropriate security software, or updates and patches OS versions, firmware and applications in a timely manner. After all, diversity of hardware militates against the use of standardized profiles. Yet is it really a good idea to abandon the use of corporate standards and management tools when just about any device may provide a window into a private cloud that might entail access to highly sensitive and critical data? The recent spate of high-impact ransomware attacks on large organizations (the British Library, Heathrow, Marks & Spencer, Jaguar Land Rover et al.) suggests not.
Can the enterprise afford not to evaluate and protect each device? Yet consistent regulation and updating and patching of OS versions, firmware, and applications are daunting and expensive challenges.
Businesses are attracted by BYOD strategies because the outlay on hardware and the cost and effort of learning the skills to use and secure it (or at least the responsibility for securing it), are partly or entirely on the shoulders of the end user. But there are indirect costs entailed by leaving security in the hands of the end user, and they go further than being unable to assume that they will install effective security software. Where the use of corporate standards, policies, and security and management tools can’t be enforced through standardized profiles, diversity of access tools becomes a problem in itself. Can the enterprise afford not to evaluate and protect each device? Yet consistent regulation and updating and patching of OS versions, firmware, and applications can be daunting challenges.
But the home-user device is also a smart terminal into the enterprise’s private cloud. Exposure of a device that may or may not be properly protected can lead to the destruction or theft of critical data and intellectual property through ransomware, doxware etc., as well as entailing legal consequences such as breach of data protection legislation.
Nowadays, the base operating system is the Internet, and the borders between the individual’s data and those of his or her employer are already irreversibly blurred by the irresistible rise of the social network in all aspects of daily life, and now it seems that the ‘yours versus mine’ distinction in hardware has gone the same way. But when every worker is a potential entry point for malware or social engineering, and every gadget they use is a potential vector, the concept of the corporate perimeter protected by firewalls and patrolled by centralized filtering software seems a little threadbare, and endpoint security seems more important than ever.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.