Monday, 19 October 2009

Dear Charlotte (Part 2 of 2)

What He Said:

http://entertainment.timesonline.co.uk/tol/arts_and_entertainment/music/cd_reviews/article6874885.ece

Great to see Charlotte Hatherley's new album being chosen as CD Of The Week in the Sunday Times Culture magazine. From the article by Dan Cairns, three excerpts:

There are seven primary and five secondary notes in western music...

What [Charlotte] should really be cherished for is her trio of solo albums, of which New Worlds is the third and best...

...these are sensational songs, from an artist who remains bafflingly overlooked, but continues to dive into that tiny pool and come up bearing pearls.


That puts it so much better than I ever could, so I won't. Save to express the hope that the epithet, "bafflingly overlooked", which has already been applied to Charlotte many times, will begin to work its magic this year.

Just over a year ago one of my favourite bands, the Criminally Neglected Elbow, won a Mercury prize, and immediately began enjoying great success as simply Elbow.

Sadly the same effect doesn't seem to be working this season for my SPL team, Hamilton Academicals Nil.

To your great relief, my planned discourse on the theory and nature of progressive music has been dropped, however temporarily, in favour of simply asking you to click through and glance over Dan's article, above. It's almost enough to forgive him this howler, from his extensive Fleetwood Mac article in the same issue:

Not that things don’t remain unsaid: this is Fleetwood Mac, after all.

Seriously, who needs three negatives?

Tuesday, 13 October 2009

A Cross-Domain Conversation

RIA Security Flash!

Adobe Senior Security Researcher Peleus Uhley recently wrote a Microsoft BlueHat blog guest post, on the subject of web sites' permissions for cross-domain access, and some security issues with these arrangements:

http://blogs.technet.com/bluehat/archive/2009/10/06/collaborating-on-ria-security.aspx

It's interesting to see how security considerations encourage companies such as Adobe and Microsoft to work together. The MS BlueHat Conference Series in particular now has a history of "building bridges" between their developers and executives, key security program partners, and members of the security research community.

Peleus gives multiple examples of threats, based on a vulnerability introduced by cross-domain XMLHttpRequest. More generally, the gotcha to look out for is the transitivity of cross-domain permissions. Commenting on this research in the MS-SDL blog, Bryan Sullivan puts it like this:

If site A grants privileges to site B, and site B grants privileges to site C, then site A is implicitly and perhaps unknowingly granting privileges to site C.

So, let's assume I've provided cross-domain XMLHttpRequest Level 2 (XHR2) permissions, for MySite, to YourSite. Let's also say YourSite serves interactive third-party SWF advertisements, provided with JavaScript access via the allowScriptAccess parameter. Then we have this situation:

[AdSite] -> [YourSite] -> [MySite]

Obviously I never intended to give AdSite's advertisements access to MySite, but that's exactly what I've done! As Peleus notes, this is the vulnerability recently exploited by the Renren worm.

Bryan goes into some detail about the history of these issues and their mitigation, also linking to one of his earlier (April 2008) articles, provocatively titled Cross-domain XHR will destroy the internet. Try not clicking on that!

Peleus concludes his BlueHat article, "Combining research makes it easier to communicate common risks with deploying RIA technologies." The next BlueHat conference, "Microsoft BlueHat Security Briefings: Fall 2009 Sessions", is being held next week:

BlueHat v9 will again bring leading external security researchers to campus to present timely and lively presentations that showcase ongoing research, state-of-the-art hacking tools and techniques, and emergency security threats. Our main themes for BlueHat v9 will be around e-crime attacks, the exploit economy, the global threat landscape, online services, security in the Cloud, mobile (in)security, and cool tools and mitigations.

BlueHat v9: Through the Looking Glass, October 22-23 at the Microsoft corporate headquarters

Thursday, 8 October 2009

Coraline 3D Telepathy

More Geek Points

This week, Henry Selick decided to leave Laika, the animation studio he joined in 2004.

After the worldwide success of Coraline, and particularly Coraline 3D, which he directed, Henry did not share in the storm of promotions that then hit Laika. His title never changed, and he was left without a new project to work on.

Henry should be used to disappointment. This is the guy whose previous masterpiece originally came out under the title Tim Burton's The Nightmare Before Christmas. But Henry is also an all-round nice guy, who is never likely to say anything remotely uncharitable about those he works with. At most, he might be pressed to admit that the whole Tim Burton misappropriation of credit thing "...still stings a little."

This is my Coraline 3D story. It's also another in a series documenting how your geek credentials can earn you a big hug: in this case, a psychic one! And needless to say, I will of course get straight to the point immediately, as always, without any unnecessary diversions whatsoever.

Days Of Science

We begin at the Edinburgh International Science Festival in 1995, where we were treated to a memorable selection of top quality presentations.

There was Richard Dawkins, in the days when he was renowned primarily as an ambassador for the theory of evolution by natural selection, and as a champion for the public understanding of science, rather than today's media caricature of a grumpy old atheist. He was busily promoting his new book, yet still managed to diverge more than enough from his prepared text, to give us numerous new (to us) and fascinating insights into aspects of evolution. Afterwards Linda took my book to ask him to sign it - I was starstruck and incapable of approaching the good professor - and she even bought a wee chapbook, "God's Utility Function", so as to have something of her own to get signed.

There was Lewis Wolpert, similarly holding court and proclaiming "The Triumph Of The Embryo" to an equally spellbound and appreciative audience, another evangelist for the cause of rationality and enlightenment, and no less a model of earnest clarity and sincerity.

There was also a larger meeting involving many scientists and other speakers from various disciplines, all preaching urgently about the state of the planet, and the coming devastations in the whirlwind that we'd soon reap. The general feeling in the room was that the 1992 Earth Summit in Rio had been a missed opportunity, failing to grasp the real risk that human activities – especially the consumption of coal, oil and gas – could affect the earth’s environment to a hitherto unseen and potentially very serious extent, as foreseen in the 1990 synthesis report of the UN climate panel (the IPCC). “The earth’s future is in danger” was the message, and the imminent Kyoto Conference was widely being touted as Our Last Chance.

Ayers Rocks

For all that enlightenment, celebrity and drama, the one thing that sticks out most prominently in my memory of that year's festival, was a picture of Ayers Rock in Australia.

We saw it during our trip to the Royal Observatory. It was the first time either of us had seen a demonstration of full colour 3D images. Well, I mean apart from the stereoscopes we'd played with as children, those truly marvellous binoculars that accepted a disk with diametric set pairs of left/right full-colour slides, projecting a different image directly into each eye. My favourites were collections of stills from Star Trek (the original series, of course).

This particular demonstration in the Royal Observatory used simple passive spectacles, but instead of the traditional red/blue filters they used polarised glass, with the left and right "lenses" mutually cross-polarised at 90°. The room was darkened, and a succession of still images was shown via the special projector. Ayers Rock jumped out of the projection screen and landed, in dazzling full colour, in the middle of the floor.

Introducing: Little Niece & Nephew

It was the memory of this experience that made me want to see Neil Gaiman's story Coraline in cinematic 3D when it was released this year. Word was, this would be a narrow opportunity window, since the supply of modern 3D cinematic projectors around these parts is still a bit low, and the Jonas Brothers were in hot 3D pursuit.

With no children of our own, we obviously needed cover to get into the cinema, and so we grabbed Little Niece and her bro, Little Nephew. Having employed these two true professionals before, when we went to see The Golden Compass, I was confident they wouldn't blow our cover and croak that they weren't actually ours. They even sat through a pre-show pizza with us, smiling and chatting, utterly convincingly.

Linda, who quite understandably loves nothing better than to be out with the kids, naturally beamed with happiness throughout the meal; particularly when a pizza was dropped on the floor (by one of us), and immediately replaced by a free one, courtesy of the manager. You are The Hut, Renfield Street Pizza Hut, you are The Hut!

When we got to the cinema, we grabbed the middle 4 seats of the front row, and proceeded to enjoy Neil's story and Henry's replacement animation masterpiece. Needles were thrust out of the screen and into our gaping faces, strange creatures danced in the middle of the air, French & Saunders squabbled behind a curtain somewhere out of view. Our looks of wonder became set in skin and bone for the full one hundred minutes.

Looking along the row of smiles, I began to know that this would be an evening we'd remember. And although Linda was three seats away to my right, bespectacled eyes transfixed on a point halfway between the screen and her nose, I could physically feel her delight at bringing these two youngsters to this new experience for the first time. That, and all the other aspects of this day when everything went right, and nothing disappointed.

Later in the week she would say to me, "When that movie started, I just wanted to give you a big hug!" and I would reply, "Yes I know, I felt it! And I hugged you back!"

Security Digest #2

Another collection of minor articles, references, and other resources, relating to computer security generally, and to the Microsoft SDL particularly.

Installing & Using the SDL Process Template

Here's an MSDN video (WMV, 9 minutes and 4 seconds) on how to install the SDL Process Template, followed by a walkthrough on how to start using it in a new project.

The Microsoft SDL Process Template for Visual Studio Team System was created to ease adoption of the SDL by automatically integrating the policy, process and tools of the Security Development Lifecycle v4.1 into Visual Studio Team System 2008.

Ref: http://msdn.microsoft.com/en-us/security/dd819921.aspx.

Most Popular Vulnerabilities!

From Virtual Tech Days, February 18th 2009, comes this combination PowerPoint / live demo presentation by Varun Sharma (Security Engineer, ACE Team, MS Information Security) enumerating and illustrating the top 5 Web App security bugs: Authorization Issues, Clear Text Secrets, Cross-Site Scripting (alone responsible for more than half of all incidents found by the ACE Team in 2008), SQL Injection, and Verbose Error Messages.

The 56.5MB, 68 minute WMV can be downloaded here.

How Do I: Use the SDL Process Template Documentation and Reporting?

This video shows how to use the SDL Process Template document templates and security metrics reporting. The built-in SDL document templates help to jump start the use of the Microsoft SDL. The reporting allows improved visibility into key security risks for the application, and the progress the team is making toward their security goals.

WMV, 5 minutes 17 seconds.

!exploitable Crash Analyzer - MSEC Debugger Extensions

Apparently that's pronounced “bang exploitable” (don't kill the messenger), and it's a Windows debugging extension (Windbg) providing automated crash analysis and security risk assessment.

The tool first creates hashes to determine the uniqueness of a crash and then assigns an exploitability rating to the crash: Exploitable, Probably Exploitable, Probably Not Exploitable, or Unknown.


In other words it parses crash logs and gives you two important pieces of information:
  • First, it will collate all of your crashes and determine exactly how many there actually are. So for example, out of 60 crash reports, there may only be 2 or 3 actual problems.
  • The second thing it does is look at the type of crash and try to determine if the error is something that could be exploited by a malicious hacker. This means that more junior employees can work these bug issues without taking the time of more senior examiners.
There is more detailed information about the tool at http://www.microsoft.com/security/msec. Additionally, see the blog post at http://blogs.technet.com/srd/archive/2009/04/08/the-history-of-the-exploitable-crash-analyzer.aspx, or watch the video at http://channel9.msdn.com/posts/PDCNews/Bang-Exploitable-Security-Analyzer/.

Microsoft SDL - Developer Starter Kit

This month's final quick link is to the July 2009 download of the SDL Starter Kit, which "provides a compilation of baseline developer security training materials on core Microsoft Security Development Lifecycle (SDL) topics."

The topics included, most of which I have covered in a little detail in previous articles, are:
  1. secure design principles;
  2. secure implementation principles;
  3. secure verification principles;
  4. SQL injection;
  5. cross-site scripting;
  6. code analysis;
  7. banned application programming interfaces (APIs);
  8. buffer overflows;
  9. source code annotation language;
  10. security code review;
  11. compiler defenses;
  12. fuzz testing;
  13. Microsoft SDL threat modeling principles; and
  14. the Microsoft SDL threat modeling tool.
Each set of guidance contains Microsoft Office PowerPoint slides, speaker notes, train-the-trainer audio files, and sample comprehension questions.

That is all.

Tuesday, 29 September 2009

Microsoft Security Essentials

Morro Launch Day!

Without a hint of a sense of irony, Redmond today acknowledged the leaking (on a New Zealand website) of the Microsoft Security Essentials launch, by bringing forward an announcement originally planned for 5pm BST.

That's a free download incorporating anti-virus, among other things such as protection from spyware and malware, but in a basic form that's unlikely to threaten the big players - including their own Forefront Client Security paid-for business offering.

Microsoft has said that it wants to provide a free security offering for all consumers. The Forefront team blog describes the relationship between Forefront and Security Essentials here. Initially, the new software will be available in eight languages and 19 countries: Australia, Austria, Belgium, Brazil, Canada, France, Germany, Ireland, Israel, Italy, Japan, Mexico, the Netherlands, New Zealand, Singapore, Spain, Switzerland, the United Kingdom and the United States (the originally planned list included ten languages and 20 countries; the missing one is China). Windows XP, Vista and Windows 7 are supported in both 32-bit and 64-bit versions. There is no support for "legacy" operating systems, like Windows 98 or Windows 2000.

The limited beta had been running in the U.S., Israel and Portugal, since June 23, when it dovetailed into the June 30 discontinuation of retail sales for the Windows Live OneCare subscription service.

Monday, 28 September 2009

Geek Points

Heavenly Bodies

It was just getting dark when we arrived home after an evening out, earlier this summer. As I turned to retrieve my jacket from the car seat, Linda looked up at the night sky, then said "Wow, look at that!"

Years ago, I showed her how to spot satellites in the clear night sky. We still do that sometimes, whenever we get away somewhere with good clean air. The sky over Skye, for example. But this satellite was quite unusual. It was far brighter than any we'd seen before, and moving fast.

"Ah, well that's the International Space Station," I remembered from reading an article earlier that week. "It's a lot brighter than usual, because space shuttle Endeavour is docked onto it right now. Wish we had the binoculars, you would actually see it hanging down from the station."

"Gosh."

We watched it speed across the night, until it disappeared behind Earth's shadow, setting in the east. "Let's get the kettle on," I said, wide grinning as my geek credentials earned me yet another big hug.

Note: the photograph below shows Endeavour docked to the ISS, with the sun in the background. But I don't remember the sun being there that night.

Friday, 25 September 2009

Security Digest

Being a collection of minor articles, references, and other resources, relating to the fascinating world of computer security, often with particular relevance to the Microsoft SDL; and wherein, Channel 9 videos are frequently indicated by the judicious proximal placement of a clickable, widescreen dude shot...


SDL Threat Modeling Tool 3.1


This is Thing One for the Security Software Development Lifecycle: the release of the Threat Modeling Tool, which helps engineers analyze the security of systems "... to find and address design issues early in the software lifecycle".

Have fun! Note that Visio 2007 is required.


Jeremy Dallman on the SDL

The Microsoft SDL Process Template for Visual Studio Team System is intended to ease adoption of the Microsoft Security Development Lifecycle. The template integrates the SDL directly into the software development environment, provides auditable security requirements and status, and demonstrates security return on investment.

Larry Larsen stopped by the Microsoft Security group and spoke with Jeremy Dallman about the SDL, and what it means for developers.

The Process Template is free, and can be downloaded from www.microsoft.com/SDL/.


SDL-LOB Phase 3: Implementation

Gentle reader, I have been remiss in not yet introducing you to the SDL-LOB. This is: the Microsoft Security Development Lifecycle for Line-Of-Business applications.

LOB applications are a set of critical computer applications that are vital to running an enterprise, such as accounting, human resources (HR), payroll, supply chain management, and resource planning applications. The corresponding SDL guidance is positioned exclusively for LOB applications or Web applications, and not for ISV/rich-client and/or server application development.

Eugene Siu, from Microsoft Information Security, describes some of the security pillars that are key in this phase, including code review, authentication, authorization and configuration settings. Also, he explains how penetration testing can complement your code review when bulletproofing your code against vulnerabilities.


SQL Detect

In this video, first posted in July 2009, Maqbool Malik of Microsoft Information Security describes aspects of the new Security Runtime Engine (SRE), with particular reference to one of the very clever tools to be included in it: SQL Detect.

This is a real-time mode SQL injection filter. When a request occurs in the application, the tool applies a variety of heuristics to the data, trying to identify possible attacks. Once the request is validated, it is allowed to proceed as normal.

See the Information Security Tools blog for more on such cool tools. Here is one professional website developer's description and assessment of "... a good combination of the Security Runtime Engine and the methods on AntiXss ...", and the Microsoft Anti-Cross Site Scripting Library V3.1 is available here.

Privacy Guidelines

"This document is a set of privacy guidelines for developing software products and services that are based on our internal guidelines and our experience incorporating privacy into the development process."

The SDL is one part security, one part privacy. The user-requested, experience-won "Privacy Guidelines for Developing Software Products and Services" (September 2008, 1.1MB download) addresses privacy as a core topic in its own right, based on the core principle that Customers will be empowered to control the collection, use, and distribution of their personal information.

After an extensive and, necessarily, somewhat legalistic Basic Concepts and Definitions section, the actual guidelines are partitioned into nine example scenarios, covering the range of considerations that we need to be aware of. These include server and software deployment and installation; storage and transfer of personally identifiable and anonymous data, both within and outside the company; and a separate section detailing the special privacy considerations and exceptions necessary when your website is accessed by children.


Live long, and have a Security Strategy.