The time is ripe for open dialogue around teaching trust, says RSA Conference's Hugh Thompson.
Buy Cheap Viagra now!Ah, the good old days of phishing. There was once a time when princes shared inheritances, when wholesalers made promises of discounted herbal enhancements, and when everybody was an occasional winner of a foreign lottery they never remembered entering. Life was pretty good.Today phishing emails are a bit different. Less sensational, unmemorable and, in a word, boring. They ask us to review a spreadsheet, install a browser plugin for a new document type the company is rolling out, or just ask us to email our credentials off so that IT can check to see if someone has broken into our account (if you hit reply on this one, the answer is “yes”). These dull phishing emails are starting to look just like the dull but legitimate work emails that we receive every day. And therein lies the problem.Phishing emails are getting personalized, adaptive and virtually indistinguishable from legitimate email. This is why the security industry is now in serious trouble – we've bet the farm on the ability of our employees and users to make fine-grained trust choices.Let's take a look at one of the most infamous hacks of 2011 – where the group Anonymous broke into the security firm HBGary. According to accounts, they were able to access the company's email server using a technical attack, but hit a wall (a firewall to be specific) when they tried to get remote root access to a server that hosts rootkit.com, a popular site devoted to the subject of rootkits that was founded by Greg Hoglund, HBGary's CEO.After a few back and forths, the administrator dropped defenses and created a remote access doorway for attackers to walk through. There's good reason that the rootkit administrator fell for it. It was sent from Hoglund's real email account. It used the same phrasing Hoglund typically uses. It also included “convincers” – old and current passwords gleaned from the technical attack to add an extra layer of believability. The truth is, the communication was incredibly convincing and it gets to the heart of our current security dilemma: How can we help people make good trust decisions?| “It is time for us to come together and get creative...”
|



