Wednesday, November 21, 2007

New Risks you Cannot Control


In the world of risks we are confronted with a range of dangers from sloppy personal behavior (losing your wallet at the State Fair) to flaws in the most basic computation and processing systems. Our identity theft protection project (funded in part by the national Science Foundation and by the Center for Information protection) deals mostly with human behavior flaws that lead to data loss risks.

At the other end of the spectrum it was revealed this week there are other and much larger risks as John Markoff writes in the New York Times, (Nov. 17, 2007).

“One of the world’s most prominent cryptographers issued a warning on Friday about a hypothetical incident in which a math error in a widely used computing chip places the security of the global electronic commerce system at risk.”

Adi Shamir, a professor at the Weizmann Institute of Science in Israel, circulated a research note about the problem to a small group of colleagues. He wrote that the increasing complexity of modern microprocessor chips is almost certain to lead to undetected errors.

Historically, the risk has been demonstrated in incidents like the discovery of an obscure division bug in Intel’s Pentium microprocessor in 1994 and, more recently, in a multiplication bug in Microsoft’s Excel spreadsheet program, he wrote.

“A subtle math error would make it possible for an attacker to break the protection afforded to some electronic messages by a popular technique known as public key cryptography.”

Although it’s inappropriately complex for a discussion such as ours here, we do wish to point out that this is one of those “systemic breakdown” as opposed to the “personal behavioral breakdown” which we are studying and for which we are seeking solutions through highly targeted and systematic education and training.


The lesson for those of us working in the area of critical information protection is clearly that there needs to be a range of security assessment starting with hardware and software makers (including cell phone companies whose microwave transmissions are woefully insecure) to the personal behavior of employees handling sensate material and ultimately to ourselves in our daily behavior. (This is outlined in our first book “Who is You: The Coming epidemic of Identity theft”)


Labels: , , , , , , , ,

Monday, November 19, 2007

Information Protection and Behavior Modification


In 2006-2007 the National Science Foundation (NSF) and the Iowa State University Center for Information protection (CIP) funded a study on information and identity theft protection of which I am the PI (Principal Investigator). The NSF-CIP project is directed at identifying factors that lead to data and critical information loss and then designing targeted and appropriate educational/training programs that change people’s behavior and lead to more “Security Consciousness” – (SEC-CON).

As a result of this research we are now developing best practices for information and ID protection. Our colleagues in computer science, computer engineering, mathematics, and management information systems (MIS) are working on parallel discoveries that will make information more secure and personal identities less vulnerable. Their work and ours will be incorporated into corporate, government, non-profit organizations and into individual practices.

I am delighted to report some preliminary findings which can help secure information.

Individuals need to have personal security of personal data high on their “awareness” list. In fact research shows that ID security needs to become a “second sense”. It should never be something we do once a month or quarterly.

There is now significant evidence that there is an “Unwarranted Trust” - UT -factor which basically “disarms” people’s behavior when it comes to securing and protecting sensitive data. Understanding UT as a sociological and psychological behavioral phenomenon, we feel, is THE single most critically important factor in successful “Security Behavior Modification” – SBM.

The second phase of the NSF-CIP project is designed to modify and improve and develop a continuous improvement paradigm for training systems for employees who have access to critical information. As one of our sponsors who is with a large multinational company pointed out at a recent briefing SBM is invaluable not only for the protection of traditional data of concern such as Social Security and Credit Card numbers and birth dates but also as a means of sensitizing employees to the risk of revealing or losing proprietary information, business plans, patents, and other information that should be secured and protected.

For more information on the National Science Foundation/Center for Information Protection project please contact us at ---
Michael McCoy - 559 Ross Hall Ames, IA. 50011-1204 or email: mrmccoy@iastate.edu


Steffen Schmidt

Labels: , , , , , , , , , , ,

  • All Material is Copyright © 2009 Michael McCoy and SEAS, L.L.C
  • Deter. Detect. Defend. Avoid ID Theft - www.ftc.gov/idtheft