Press "Enter" to skip to content

Security Awareness For You | Jason Callahan | TEDxUCSD


you
about 15 years ago I remember sitting
doing something many of us will do in
our professional life I was sitting with
my colleagues trying to figure out how I
was going to raise money and in this
case I was working for a very large life
sciences company and we were trying to
figure out how we were going to build a
cybersecurity program to protect the
company and back then it was incredibly
difficult there was no money nobody
understood the need for cybersecurity
and I remember vividly sitting with them
and saying one of our challenges is that
you’ve never heard the President of the
United States say anything about
cybersecurity it didn’t exist it wasn’t
in the news now today I almost regret
ever thinking that because today we are
inundated with this information about
cyber threats and it doesn’t matter if
it’s the FBI trying to hack your phone
nation-states destroying Sony ransomware
phishing the news is overwhelming now as
a professional I have to try to separate
that news between what is interesting
policy decisions we need to make or
where can I make a difference from my
company to change the threats and I
suspect for you as individuals listening
to all this news is quite maddening
because it’s so much of it and when you
deal with so much of this information
and you don’t know what to do with it
you tend to ignore it and that’s what we
all do so I want to go through an
exercise today to talk about how we can
consider where we can make a difference
as citizens so what we’re going to talk
about is what you want to keep safe and
what’s important to you from those
people you can practically keep it safe
from when I started my career I was in
the Air Force I was a police officer my
first role was basically as a guard for
the f-117 stealth fighter it was really
cool at the time and the way the
military would work is you’d have a
series of protocols to get near that
aircraft and my job was to be there and
use those protocols to know right from
wrong good from bad friend from foe and
what I learned very quickly was I loved
working Saturday and Sunday night at
midnight because it was really easy at
midnight if anybody showed up they were
probably in the wrong place it made my
job incredibly easy to know right from
wrong
but that’s not the world well we know
that’s not the world our police officers
live in today right and it’s not the
world that we live in as digital
citizens in this world the Internet is
not really about good or bad or right or
wrong I try to think of it more about
like leverage people are extracting and
exchanging values some of that is good
some of it is bad some is legal some is
not so it try to start this exercise by
thinking about who is exchanging value
who is leveraging us as citizens now if
you’ve been working a long time you
remember when they gave you your first
computer it came with a cable lock right
and that’s because the computer was more
valuable than any information that came
on it we were worried about the thief
stealing your computer nobody cared
about anything that was sitting on your
hard drive and I remember giving
security awareness presentations and I
said the Internet is the wild wild west
we all need to worry it’s a lawless
place and we can’t tell what’s going on
that didn’t get me any money nobody
understood that and then we maimed our
bad guy the hacker and I thought we
finally got it we have a bad guy we put
a name on him the problem was we all
know that hackers are kids in their
basement sitting in their computer
eating Cheetos or something so that
didn’t get me any money nobody was
afraid of them and those hackers grew up
right they either became me or they
started working for professional
cybercrime organizations and those
groups have extracted a lot of value
from us today we read about that with
ransomware phishing attacks they steal
our credentials our identity information
they’ve done a pretty good job of
leveraging us online but they’re not the
only ones marketers have done an even
bigger job and what I mean by this are
the social media platforms that we share
our digital lives with and the online
advertisers they are all in the business
of buying and selling information about
us mostly for the purpose to sell us
more goods or create more value for
themselves we also don’t have to look
much further than the most recent
political election to see how political
parties have leveraged data and the
internet world today while I was
watching TV it looked like every other
election we talked about demographics
and regions and states
and polling but what these parties were
actually doing was looking at lists of
individual Americans and the issues that
were important to them and the sway
ability factor which was determined by
data that we gave up as part of our
digital footprint and our sharing of
social media online they looked at us as
individuals let’s face it it’s a
relatively small data problem there’s
only a few hundred million of us in this
country and somewhere in all of that we
also have nation states we have to
assume that there’s a weaponization
model to the internet we haven’t seen
that as citizens yet I hope we don’t
soon we could debate the curve or
capabilities there so if these are some
of the groups that are trying to
leverage us and these are the ones we
hear about in the news on a regular
basis next we have to think about what
we’re going to protect so the concept of
availability is a core tenet of
information security and it’s very
simple is the resource available to you
at the time you actually want to use it
so the best way to start this exercise
is to say your friends and family are
safe your pets are safe your house is
burning down at that moment as you stand
and watch everything you own go up in
flames what are you wishing that you
could run in there and save what is
important to you now I know when I
thought about this I used to tell my
wife I have to save my photos right my
photo those are my memories put to film
and paper I can’t get those back they’re
priceless to me I can buy another couch
that’s not really important and over
time those photos moved from boxes to
being on the computer we scan them
digitized and of course today we take
them all through our phones and I had
other things on that computer my
financial information documents wills
contracts mementos things that were
important to me and so it became I have
to protect the computer forget the
monitor and a keyboard just the box has
to come with me when that house is on
fire there’s other things that we all
want to protect we think about our
identity and the pain that can cause us
from people extracting value from that
and we think about our digital footprint
we talk about it at least and this is
everything that we leave behind us we’re
doing it right now are the sensors and
our pockets know that we are here and
it’s being shared around the world our
habits our purchases our friends and
family
who they are every app that you download
that once access to your contacts is
sharing who your friends and family are
with someone in the world
some of us want to keep that private
alright so we can put those two together
and we can try to figure out where to
focus our energy now I said this was
awareness for you
so I started by adding the employer
category because some people worry about
you know is my employer Big Brother and
are they trying to spy on me all right
so I’m the head of security for a
publicly traded company I don’t have the
time or interest in what you’re doing in
your personal life to be quite honest
with you but I think you have a chance
of keeping your private life separate
and prevent me from knowing about it but
it’s really really hard here’s how you
have to never check your personal mail
on any of the company’s assets or
internet connections you have to not
view all of your wonderful photos from
over the weekend on your computer or
share them with people at work you have
to not be playing games on your phone
connected to the company’s network if
you can separate your personal life from
the company’s assets then I will know
nothing about you I know that sounds
really hard I know I’m not very good at
it myself
another big takeaway you might see here
is the digital footprint I personally
don’t believe we can keep that safe from
anybody today I’m sorry to share that if
your belief was different it’s
incredibly difficult
dr. Kaczynski from Stanford University
has done some amazing research in this
face and he take he took data from all
of the stuff that we’ve all given to
social media platforms and these free
applications that ask us questions about
our lives or asked for permissions and
you’ve mined it for data that’s so
powerful it can tell us more about
ourselves than our friends and family so
when I think of that research I think we
can’t really protect our digital
footprint in the world today and one of
the groups that’s leveraging that are
the marketers and those marketers in the
United States in particular can buy and
sell other information about us our
financial information we store our
photos on their servers the cloud right
what is another word for the cloud
somebody else’s computer we give it to
them so they have access to all this
information which they use primarily to
sell us more stuff the other one is
nation-states we worry about that
because we
here it in the news all the time now I’m
a citizen in the United States an
impractical reality I can’t save my data
from them they can get warrants they can
get subpoenas to collect my information
so I have to assume that ultimately they
can gain access to my information all
right so there’s a really bright
takeaway from this data this exercise
it’s that there’s one I’m sorry there’s
two groups of people on here that we
actually can keep our data safe from and
they are the people that are actually
trying to hurt us directly right that’s
thieves and cyber criminals they
actually want to cause you harm and you
have a chance of stopping them it’s
really not hard now if you’re worried
about marketers nation-states and your
digital footprint that’s a different
story when you read those things in the
news those are items you have to talk to
your political leaders and policymakers
about that’s where you can help make a
difference on that front if you want to
protect yourselves from thieves and
cyber criminals which are who I believe
you have a chance of protecting yourself
from today I have a few steps so now let
me know it’s important to us now that we
know who we can possibly protect it from
let’s talk about what we can do
number one passwords
I would love to stand up here and tell
you passwords are dead but they’re not
and you all know they’re not because you
type them all day long so it’s very
simple make them long to make them
strong never reuse them use multi-factor
authentication and always change the
default passwords you’ve probably all
heard this before if you’re thinking
this Hardy sounds really hard I’ve been
using this one password across 27 sites
my whole life use a password manager I
use the password manager it’s wonderful
I know one really long password use
multi-factor authentication to protect
it and it makes it really hard for me to
reuse passwords and it makes it really
easy for me to make complex passwords
that’s a pretty good deal it also logs
me into all the websites I visit faster
than I could ever type them it’s kind of
a no-brainer updates your car needs
maintenance your house needs paint your
computer needs updates as well now when
you’re at home if your computer’s
reasonably new it’s probably set to
automatically get updates but I’m asking
you to take two minutes to go to the
settings and check to make sure that’s
happening when you go to buy your next
mobile phone ask the carrier ask the
manufacturer what their commitment is to
providing updates and what their track
record is this is an area where we as
consumers can help push that along I’m
going to put my IT hat on for just a
moment when I talk about work computers
for those of you who work for a company
who provides you a computer the IT team
pushes out patches and we of course
never force that reboot that’s usually
required for them to take effect because
we know if we did it would happen during
your most important presentation so we
rely on you to do that so you always get
a little message that pops up right
please reboot your computer when you get
a chance just a couple of weeks ago a
worm spread the internet called the one
a cry it mostly impacted organizations
and it did this because organizations
have a lot of applications they’re
usually a little slower to patch than
home users because they’re all set to
auto update now as a professional in
this space I always see the graph we’ve
pushed the patch to this many machines
and this many are waiting to be rebooted
so there’s always this gap so on behalf
of your IT team please reboot as soon as
you can when you see that request they
would appreciate it
number three is encryption
incredibly complex topic we could talk
about quantum encryption and what it
will do to the current standards SSL TLS
key lengths government backdoors there’s
all sorts of things we could talk about
here but it’s very simple if encryption
is available to you and it is on most
modern operating systems please turn it
on have you ever seen that security
video where a pickup truck in the night
backs up to a bank guy jumps out runs a
chain around the ATM machine rips it off
the wall of the building and drives off
into the into the darkness he drives off
to somewhere to his shop he takes his
sweet time carving a hole into the ATM
machine and extracts the money your
computer is a little like this if you
have the really great password and I
break the window of your car and pull
your backpack out of it with your
computer in it I have full
access to all of your data it’s very
simple however if you encrypt it the
only thing I have is your computer and
your computer is not even valuable
enough that anyone gives you a cable
lock for it anymore
it’s probably worth a couple hundred
bucks so encryption is there to keep
your data from being shared to others
I really hope no one in this room has
ever been victim of ransomware I
sincerely hope no one has experienced a
house fire and had to go through that
experience I really hope none of you
have had a window broken out of your car
and your belongings stolen and I really
hope none of you ever been walking down
the hallway to give that really
important presentation and watched your
laptop slip out of your hands and brake
onto the floor in front of you
I really hope none of these things have
ever happened to you but what I know is
if anyone in the room has this happened
they will tell you that they now back up
their data failures happen we should all
make a backup now if you’re saying
listen I sync everything I own to the
cloud I back it up in someone else’s
computer that’s great
every once in a while take it out of the
cloud and make a copy that’s not
connected to the Internet you’ll thank
yourself one day lastly and this one’s a
little tricky we have to be aware we
need to slow down the internet is coming
at us really really fast when I go home
and I check the mail I go from the
mailbox to the recycle bin before I get
to the house and at the recycle bin I
stand there and I’m able to easily
evaluate trash not really going to save
me hundreds of dollars from my actual
bill I can tell and we all do this
practice the Internet is the same when
you’re looking at your internet you’re
looking at your email you have to decide
is this really something useful to me
are they really going to save me
am i clicking to places that that maybe
are not the ones I intended to go to so
my ask is that you slow down a little
bit while we’re clicking around the
Internet
why does all this matter a few months
ago there was a major denial of service
attack that hit ports parts of the
Internet one of the functions that it
hit were companies that ran a service
called DNS it’s kind of core to how the
internet works
and this attack mostly came from
consumer grade security cameras that all
had default passwords and they all
pointed their pointed their traffic at
these DNS servers which then fell over
and many businesses use these and their
services fell over which means a lot of
economic value was lost and that was
lost on all of our companies you may
remember it you probably weren’t able to
go shopping online that day because you
couldn’t do your work anyway and then
you couldn’t do your shopping so it was
kind of a frustrating day for a lot of
people but much more important than that
in 2005
Thomas Friedman taught us that the world
was flat he talked about these forces
that were converging around the world to
change things and one of those was fiber
optic cables and how this expanse of
fiber optic cables was going to change
our world from round to flat and create
much much better economic prosperity for
people around the world we don’t live in
that world anymore we have been moving
so quickly that we’re far beyond that
pace this this digital place that we
live in today defies physical reference
to quote Morpheus to neo this digital
world is the world that’s been pulled
over our eyes to blind us from the truth
and that truth is we sit here today and
you can reach out and touch the people
around you and shake hands and say hi to
the people around you but the reality is
you’re sharing this experience with the
whole world we’re all here together it’s
not just flat it’s not just a flat world
it’s actually happening in one instance
that we all share it’s not about my good
neighborhood or your good neighborhood
or this nation or that nation we are all
living a digital life that is highly
connected together you are one arm’s
length away from everyone in the world
and they are one arm’s length away from
you you are one click to any location in
the world and likewise they are one
click to you and the world isn’t the one
that I talked about earlier of black and
white and good and bad and Friend or Foe
it’s much more complicated than that
it’s about the exchange of value some of
that’s economic value some of its value
about who we are and what we believe and
that’s
being traded around the world today and
there’s no political party or system
that can currently keep up with it
where does that leave us it leaves us as
digital citizens in this world with an
obligation to try to try to keep it
moving along well for the greater good
thank you
[Applause]
Please follow and like us: