miércoles, 22 de noviembre de 2017

Make Your Online Identity Safe Again (4) - Let's see how you get pass this!

Recently Blizzard gave us an animation that inspired the name of this blog entry. The character Mei is an interesting data analyst who hyper-slept for 0 years. I'll leave the link to the video at the end of the post. It is worthy of watching.

So we're gonna talk about authentication. Right now there are only 3 ways for a computer to know that you are IN FACT you. Apple has given us a lovely example of this with their new iPhone X.

The most common way to authenticate is by testing the knowledge of the user. This can be used by asking for a password, just as Facebook, or a NIP, like an ATM. By asking the user for a specific piece of knowledge, the application can trust some rights to the person trying to access it. That's why it is so important for you to NOT share passwords, and to be very unrelated to you.

The next method is a little bit more secure but actually can be more problematic as well. In Walt Disney World, there exist something called a Magic Band. It is a bracelet that every member of a family must have on themselves through all their stay. The parks react to the band, so they can give you a more personalized experience, you can also access to your the parks and hotel room with it. You can even connect your credit card to it and you can pay for food and souvenirs inside the Walt Disney World with it. The system knows who you are, and gives you access to everything you paid within easy reach of your wrist. The big problem about this is that you COULD lose your Magic Band and someone COULD access to your room, park tickets, and credit card without your authorization. The credit cards in Mexico function like this as well, if you have an account, you just have to have your card with you to make a transaction. If you ever lose your Magic Band or your Credit card, report it immediately.

The third method you can use for authentication is something you CAN´T lose: Your own self! Apple started using Touch ID a while ago, and now with your new iPhone X, they are using Face ID. That's right! If you want to unlock your phone, you just have to watch it and it will recognize is you. Awesome, right? Well, Apple claimed that the chance that someone who isn't you unlocks your cellphone by Touch ID is 1 in 50,000. And by Face ID is 1,000,000. There exist room for error. If someone wanted to go through your iPhone X, they could even print a 3D scale of your face and use it to unlock it.

My point is that there's not one final or best way to authenticate, we just have to protect our data as much as we may be able to, and we also have to be ready for the worst case scenario.



lunes, 2 de octubre de 2017

Make Your Online Identity Safe Again (3) - One Code To Rule Them All.

We live on a society, and one of the responsabilities we have is to follow a set of rules for the greater good. The Code of Ethics is no different from this rules. In my opinion, this are the most essential baselines we all have to follow just because we are human beings. The code of ethics at Disney World is extremely long a specific, I had a set of rules to follow on almost every single scenario I worked at.

Mission and vision are present in almost every code of ethics I've read. Most of them are looking forward to create a better society. It makes sense for them to be placed there, because those are the goals of the company. If a company knows what and how it wants to reach its goals, it will do great. 

As a worker, you have to be completely trustworthy to you client. They have to feel confortable giving you the information you need to develop a project. I think this may be one of the most important values at Disney World, you have to be approachable to children that may be lost or that just want to ask you something about the park.

Most codes of ethics include respect on their pages. There's a popular phrase on my native language that says "A donde fueres, haz lo que vieres". It means that if you are traveling to another country or working with someone that has different values than you, you have to follow that set of rules and conducts. Respect is the key to a better society. 

PS:  I just re-applied to work at Disney World, I'll keep you posted about it.

Image result for disney world gif

miércoles, 13 de septiembre de 2017

Make Your Online Identity Safe Again (2) - Don't Let Your Risks Be Risks!

I had the opportunity to work for Walt Disney World on 2016, and I realize that I keep relating things I learn there with every single topic we've covered on this course, so I might just share them with you as well for you to easily understand  them.

Every single thing we do in this world has its risks. Waking up has its risks. You may get off of bed and slip on the floor and get hurt, or you could wake up late because you didn't hear your alarm. When we take this concept to computer science, the moment you turn on your computer for the first time, and connect it to the Internet, you are a target and you are taking the risks of going online.

I am a not interesting target, and surely, our knowlegde as computer science engineers make us more difficult targets because we are aware of lots of the problems we have on a daily basis. But an enterprise is a great target to attack. You could control their finances, the information of their employees and clients and God knows what else they could do with all that data. Luckily, someone tought and registered a way to manage this risks: They created frameworks for risk management.

The U.S. (I'm assuming) Government adopted the NIST Framework: It includes 6 basic steps that can be cycled as many times as needed.

  1. Categorize Information System
  2. Select Security Controls
  3. Implement Security Controls
  4. Access Security Controls
  5. Authorize Information System
  6. Monitor Security Controls
In Disney World, I also had to follow some "frameworks". For example, if we saw a bag forgotten on a place, we first have to wait to see if anyone claims it. If not, you have to call security because it could be a bomb or something dangerous. After they decide if it's dangerous or not, they decide if we should keep the bag or if they have to take it. Then they follow some protocols to ensure the safety of all the guests and cast members. 


lunes, 21 de agosto de 2017

Make Your Online Identity Safe Again (1) - The Other CIA.

It is common to think on the U.S.A.'s Central Intelligence Agency when we hear the "CIA" name. It even makes more sense when we are talking security, but SURPRISE! There is another CIA!

I still don't know what format will I use for this series, so for this special ocassion I will talk about something that we all students from the Tec de Monterrey have suffered of: "Las Inscripciones" (a.k.a. that period of time where all the students have to make their schedules at the same time)

So, you may be wondering, "What does CIA mean to you?". When we are talking about computer and information security, one of the most important concepts is the CIA Triad, three components to measure how protected your information is. "C" stands for Condifentiality, "I" for Integrity, and "A" for Availability.

So let's talk class registrations. Why are they always a mess? Imagine that the Tec de Monterrey HAS to fulfill the Triad before you create your schedule. The first thing you have to do, is to enter to your account. By doing these, the ITESM can manage that ONLY YOU can see your information. You can manage your payment, insurances and courses to take there, this is an example of what confidentiality is.

By the way, here's a Top 10 list of words that shouldn't be your password:

  1. 123456
  2. password
  3. 12345
  4. 12345678
  5. football
  6. qwerty
  7. 1234567890
  8. 1234567
  9. princess
  10. 1234
So, please, if you have one of these on your bank account, make youself a favour and change it!

Going back to our subject, let's say you already chose your courses, and you are happy with your schedule (this has never happened to me, by the way), but suddenly, when you want to show it off to your friends, it looks nothing like the one you made, heck, you even had a course on Saturday. This would be a problem of Integrity, the information has to be protected so no one can alter it without supervision.

But the Tec is actually pretty good on the first two letters! Our information is confidential, and it has integrity. The problem is that it is so hard to access to the portal at the same time as the other 7000 students from Campus Guadalajara want to enter as well. When your turn to create your schedule is at 10 a.m. you're doomed because the site will not be available. Just when you need it the most, you'll find it very troubling to enter. Backing-up your information is normally a way to ensure daya availability, so, have your hard drives backed-up somewhere folks!

I heard that they are thinking on changing the name of the CIA Triad to the CAI Triad, but I think that would be a loss. How will everyone start talking about the Triad without an obvious reference to the Intelligence Agency?

miércoles, 16 de agosto de 2017

Make Your Online Identity Safe Again - Introduction to the Course.

Welcome to my blog for Computer and Information Security! You may remember me from such blog series as "Surviving at the Software Industry" and "On The Topic".

This semester I'm on a pilot program for the ISC semestre I at the Tec de Monterrey Campus Guadalajara. One of the courses I'm taking is Security with Ken Bauer. This is not the first time I have a course with him, neither the first time I write for one of his classes. I hope you all enjoy what I write and that it can be helpful for someone in the future.

I am not sure on what will my format be for this series, but stay tuned for more.