Home  |  About  |  Contact

Wednesday, 11 Mar , 2015

Weekly Wee One #3 – Passwords and Biometrics are like….

Share this article

This week’s tweet-size InfoSec analogy with not so tweet-size extra stuff 🙂 [tweet https://twitter.com/S_Clarke22/status/575685304574738432 hide_thread=true width=’900′] [tweet https://twitter.com/S_Clarke22/status/575558596278288384 hide_thread=true width=’900′] In one resulting twitter conversation you’ll find very pertinent questions from Van Amenya (a non-security person who bravely weighed in) about whether consumers really care about security, my very personal opinion on how things are security-wise in the retail/IT vendor […]

This week’s tweet-size InfoSec analogy with not so tweet-size extra stuff 🙂

[tweet https://twitter.com/S_Clarke22/status/575685304574738432 hide_thread=true width=’900′]
[tweet https://twitter.com/S_Clarke22/status/575558596278288384 hide_thread=true width=’900′]
In one resulting twitter conversation you’ll find very pertinent questions from Van Amenya (a non-security person who bravely weighed in) about whether consumers really care about security, my very personal opinion on how things are security-wise in the retail/IT vendor space and good stuff from Dr Danniel Dresner (with his usual sense of humour attached).
In the second one, we’ve got Philippe Verstichel, Claus Cramon Houmann and Per Thorsheim indulging my inexpert questions about the inner workings of biometric authentication and sharing opinions on it’s future usage and security.
When this one came to me, I did a fairly long search for recent articles calling out how vital it is to secure around identification and authentication data stores. Almost nothing, nix, nada on that subject (feel free to flag any I missed). I therefore feel justified pointing to my post on passwords and their future.
Another symptom of the lack of joined-up-ness in the way we approach security, or (more realistically) another victim of the ‘wow’ driven media experience? Not so sexy to say:

‘Biometrics are amazing, BUT one lax privileged access policy, holey database or iffy connection and your ‘you data’ goes bye bye’.

Having said all that I can’t wait for biometrics to become mainstream. Even with a password safe, my InfoSec pro tendency to set evilly long passwords sometimes makes my life a misery (look for a tweet in that second thread proving that point). And that, right there, is the problem. Super convenience makes everyone less cautious…well…except paranoid security pros like myself. We’re paid to be that way, so you (as long as you pay heed to us), don’t have to be 🙂 .
To underline that point: Think about the explosion of mobile apps. How long was it before most folk considered whether they were secure, or why they wanted permission to access (among many other things) all your contacts?
Perhaps biting off my nose to spite my face, I’ll be a late adopter of biometrics. Watching carefully (and probably tweeting/posting about) who’s good at security and mistakes made by others.
Soooo, this turned out to be not so wee, but mainly due to the great input provided by the Twitter community. Thanks for that! And hopefully I’ll have more tweet-size inspiration by this time next week.


If you liked this, you can find more here, or try The Analogies Project for loads of bigger ones from just about every big name in the security game (plus plenty of folk from other trades). It’s a fab resource.

Data Protection, Security, and the GDPR: Myths and misconceptions #2

Welcome back! This is a shamefully delayed sequel to my first instalment of security themed GDPR thoughts: Data Protection, Security, and the GDPR: A fraught and fuzzy relationship. Here I look back again over my pre-privacy IT and InfoSec career to spot things likely...

Where and to whom does the GDPR apply?

Yeah, I doubted my sanity going at this one too, but here I am, because working out whether or not the GDPR would apply in different practical and geographical circumstances is proving harder than it really should...for everyone. This regulation has been my almost...

GDPR – You’ve analysed the gaps, but can you close them?

  There is a critical gap for most firms: An inability to interpret and leverage gap analysis, data discovery, and mapping output to actually implement technical data processing change. This article is about the challenges most large firms are facing when trying...

GDPR – The Compliance Conundrum

There is one question related to the General Data Protection Regulation that will arguably cause more ulcers than any other: How much is enough? In some portions of the GDPR 'good' is straightforward. In many others we are asked to respect principles of fairness and...

Opinion: The role of automated data discovery in a GDPR programme

Do you have any online profiles or posts featuring those 4 magic characters: G D P R? If so, whether you are a business decision maker, IT body, security body, charity boss, employed data protection pro, or job seeking data protection pro (less and less likely), you...

When Business Culture Eats Cybersecurity For Breakfast – Part One

A four-part story of budget cuts, blamestorming, breaches and massive bumps in the road to mature security. Wild Speculation & IT Transformation Do you remember Nick Leeson? On February 23rd 1995 he sent a fax telling bosses at Barings Bank he was ill and wanted...

Cyber Insurers Dictating Cybersecurity Standards?

A run down of the key challenges with choosing and using cyber insurance called out in the last few months. It looks entirely possible you will have 'adequate' security dictated by your insurers, so it is your job to understand the risk based yardstick they're using...

There Is No Such Thing As Information Security Risk

Having worked in IT and Information Security for 13 years, I've come to the conclusion that there is no such thing as information security risk. There are just business risks that have one or more security or IT related causes. There is a fundamental and persistent...

We welcome the Children’s Commissioner report “Who knows what about me?” which shows how children’s data is routinely collected online. The report points out that children are among the first to be ‘datafied’ from birth, including policy and practice in schools, and comments on the datafication of children in the education sector; school databases, classroom…read the full article on the Defend Digital Me blog

Read more

Children’s Comissioner on concerning use of school children’s data

We welcome the Children’s Commissioner report "Who knows what about me?" which shows how children’s data is routinely collected online. The report points out that children are among the first to be ‘datafied’ from birth, including policy and practice in schools, and...

The IT Asset Disposal Vicious Cycle

Most retired equipment is ground up for minimal financial and recycling return... ...that model is financially, environmentally, and socially unsustainable. The way we all do business is changing. Increasing numbers of staff work flexibly and use their own kit....