An intermittent record, if that is what it could be called, of my journey of learning, as I come to grips with the implications of e-Trust.
Tuesday, June 24, 2014
Respect Network is Launched
Monday, June 16, 2014
Challenged to write 750 words on the future of Cyber Security 20 years from now!
The Worm Turns
The prior generation of internet service providers, had used the business model of profiting by personal data acquisition based on the provision of free internet services. The e-trust ecosystem swept away this Service Provider centric approach, that had only really enabled innovation of technologies that made the ISP's more wealthy, though not their users. The new ecosystem enabled an entity centric approach that accelerated and distributed wealth creation, which in turn caused the world economy to burgeon. The expanded wealth creation caused by a surge in innovation was supported by the e-trust eco-system, which had enabled collaboration and co-creation at previously unseen levels. The new economy is referred to as the intention economy, as it is driven by the desires and intentions of individuals and corporations alike.
Digital Agents Reduce Malfeasance
An entities Digital Agent will report it to the COW, if the entity chose to initiate illegal actions that would be sufficiently detrimental to humanity. If however the action would only be of detriment to another entity, their Digital Agent would negotiate the “right fee" with the other entity and pay it. Such transaction fees are very low due to the fact that the e-trust ecosystem enables very high numbers of transactions, and that malfeasance has an extremely low success rate. The offence of SDA Subborning Digital Agents is seen as abhorrent in all societies, equivalent to rape. There is zero-tolerance for such behaviour, and all Digital Agents operate with COW to detect and cleanse Subborned Digital Agents.
Road Safety Improved, Energy Consumption curbed
Smart Cars are happy to drive at their maximum speed, however their drivers are fully aware that while this is totally safe due to the quality and presence of sensors and agents, on the roads and in the cars. it is very expensive as the smart car will report their speed and energy consumption to the road tax sub component of the e-trust ecosystem, and also arrange for real time transfer of funds. A journey taken at 40 Km/h costing £1 would cost £600 if made at 100 Km/h, and £10 if made at the inefficient speed of 25 Km/h. What in the past would have been a traffic jam automatically travels at 40 Km/h.
100th Luddite Tribe found in Norway
Friday, June 13, 2014
OODA not PDCA in an Outside-In World
OODA comprises of 4 decision states;
Observation - Gather Facts
Orientation - Analyse Facts
Decision - Decide on a course of Action
Action - Act!
The most important feature of this decision cycle is the fact that it is designed to operate quickly, the faster one can go around the decision cycle, the more effective the likely outcome. Boyd designed his decision cycle to facilitate defeating an enemy and surviving! His goal was not to achieve a perfect decision.
The traditional business decision cycle PDCA, promoted by the International Standards Organisation and specifically referred to in the ISO 27000 series, and which encourages quality of the outcome. Completion of a PDCA cycles is normally achieved in weeks if not months.
Effective completion of OODA loops decision cycles are achieved in hours, if not minutes.
In the Outside-In world speed is king, and getting inside the decision cycles of your competition is an added real bonus, for in their cycle you can create confusion and doubt.
Is your organisational agility up to this challenge?
What will it take to get an organisation to shift to decision cycles that are completed many times a day?
What processes and communication systems will need to change.
Which types of organisational structures are up to this challenge?
Command & Control or Command & Empower, which will operate best in the Outside-In world, in which contexts?
Does the phase of the battle make a difference? Boyd thought it did, how will this effect your use of the decision cycle in an Outside-In world?
Thursday, June 12, 2014
The important measure!
Imagine that a Formula 1 team that published data on how many crashes they had during the season, with very detailed root cause analysis of each and every one of the crashes; totally ignoring the teams race results, e.g. how many times they won a race, or the position they achieved in a race.
Omitting any data on the impact of the crashes on the car in question.
Their analysis might also detail the effectiveness of the different controls that could have mitigated the different types of crashes.
Such a Formula One team might valuably ask the questions:
How might we link the value of crash avoidance to our final podium position?
How might we link the impact of controls on our final podium position?
For every member of a Formula One team knows the important measure is Podium Position, achieved by consistently attaining the fastest lap times.
In the Infosec world, our maturity in this space is still quite limited. Incident reports are by their very nature very Anti-Clockwise. How can we connect the analysis of this data to the positive outcomes desired by our business or better our customers? For after all the important measurements should always start with the customer's needs and desires.
Imagine that in a bank a positive correlation is made between the implementation of a control and the reduction in customer longevity.
A security control that is helping to retain customers.... Hoozah!
Developing a Clockwise Security mind-set starts with fully understanding the key business measures of success.
What is that measure in your industry?
Perhaps more importantly how do you customers measure success?
Friday, June 06, 2014
Why are we all doing Anti-Clockwise security?
Sunday, June 01, 2014
On Learning and Cyber Agency
1) Unconscious Unconsciousness
Key learning step: Awareness
2) Conscious Unconsciousness
Key learning step: Education
3) Conscious Consciousness
Key learning step: Practise or Automation
4) Unconsciousness Consciousness
or in plain English
1) Not knowing you don't know
2) Knowing you don't know
3) Knowing you Know
4) Not Knowing you Know
These four states can be applied to our ability to attain Cyber Agency, in this context I define Cyber Agency to be the degree of control that an entity has over all the elements of Cyber Space that they interact with, be they; Data, Things or Services.
Current State: We do not know that we are not in control of our Cyber Space
(ie We do not know that we do not have Cyber Agency)
In the world of Cyber Agency the vast majority of the planet's inhabitants are in the first state, and apparently either have little interest in accepting that there is anything in this area that they need to know, or, sadly for some, have no access to cyber space, thus have nothing to be concerned about; for one cannot have control over something one cannot access!
The first step to the next state is likely to be the hardest, for the incumbent service providers are doing all in their power to keep as satisfied with the status quo. They want to suppress Awareness of the importance and value of our being in control.
Here perhaps, the Privacy Advocates are doing us all a dis-service by distracting us from the real issue.
Author shivers and SCREAMS to himself: "IT'S NOT ALL ABOUT PRIVACY!" But sadly the politicians, (at least in Europe) are enamoured with the idea of giving us all the "Right to be Forgotten!"
(I wonder who this right is really aimed at!) Apologies to Ms Neelie Kroes, but I did try and tell you!
(ie We are working hard to achieve Cyber Agency)
This state is probably the most transient and sadly once the average individual understands how much effort it is going to take to achieve and maintain control with current tools and services, they well revert rapidly back to state 2... "Cyber Agency is hard! Who needs it!"
"How to get individuals to the next state?" without them freaking out, will be the most important question to answer. There is likely to be tool and service requirements here...
- Better information; How in control am I?
- Better and easier to use controls; How easy is it to "be in control"?
Target State: Being "in control" of our Cyber Space, with little or no conscious effort.
With the appropriate training and capabilities we can all gain Cyber Agency.
Automation is likely to be key.
e-Trust will be foundational
Cyber Agents that act on our behalf to help us maintain control of our personal Cyber Agency will be common place.
Who will provide them, and how will we be able to trust them?
- You will not know what data you have
- You will not know the import or value of your data
- You will not know the value or capability of your things
- You will not now the limitations of your things
- You will not know when others are controlling your things
- You will not know when others are using your data
- Others will be making money out of your data
- You are likely to lose access to data that is important to you
- You are likely to keep too much rubbish data
- You will know what data you have
- You will know the import and value of your data
- You will know the value and capability of your things
- You will now the limitations of your things
- You will be able to control who controls or uses your things
- You will be able to control who uses your data
- You will be making money out of your data
- You will have access to data that is important to you
- You will have curated your data, keeping only that with value.
There is no spoon!
Thursday, April 10, 2014
Sometimes I just hate my how we treat users!
The latest example is HeartBleed, even the normally sane BBC News Channel is joining in the the hysteria.
Don't get me wrong the HeartBleed vulnerability is really really bad!
However the hysterical cries to "Change ALL your passwords!" is worse.
As a reminder here is the current flow:-
Flaw Detected in OpenSSL (Versions 1.01-1.01f)
(NB Most sites are still using older OpenSSL code that is the sites are Not Vulnerable)
Some of the "in the know" sites update their sites, and keep their heads down.
Security Experts start crying "Update ALL your passwords!"
News Media picks up and echoes the cry.
The sites with the vulnerability patched keep their heads down.
The sites with the vulnerability unpatched keep their heads down.
Some sites update their Security Certs but not all...
Some Users Update ALL their Passwords wasting time and not getting any real increase in their security.
Most users just raise their eyebrows, and think "Not again!"
(NB Simply patching the OpenSSL code is not enough. The affected sites also need to update their security certificates. As an example O2 have patched and updated, it seems that EE have just patched and not yet updated their Security Certs. Though some Certificate Providers do not update their Certificate dates when re-issuing Certificates so, who knows!!)
Of my 257 internet accounts 249 of them were apparently not affected, either they were not on the affected versions, or they did not use SSL!
Of the 8 sites that Lastpass detected were affected, 5 of them had not yet updated their security certificates, and only 3 had updated their certificates. So in fact I apparently just had 3 passwords to update.
A far more Open and sane approach to the process would have gone like this-
Flaw Detected in Open SSL (1.01-1.01f)
Some of the "in the know" sites update their sites: Goto **
Security Experts get the message out "Site Admins Update OpenSSL (Versions 1.01-1.01f) and Certs
News Media keeps its head down. IT and Security Media repeats the message above
The sites without the vulnerability keep their heads down.
The sites with the vulnerability unpatched declare on their website that it is insecure but they are working on it.
The sites with the vulnerability patched and certs updated: Goto **
** Force re-authenticattion and password reset on ALL site users, admitting that the site had been vulnerable.
Funny how LastPass did not declare themselves as one of the affected sites, despite the fact they were, an example of the "in the know" keep our heads down approach to security and brand protection. Thank fully I use my Yubikey(s) to protect their site! I wonder how they have been compromised by Heartbleed?
Oh! how my HeartBleeds!
Tuesday, April 08, 2014
It's the data, stupid!
Tuesday, March 18, 2014
I'm up to here with Privacy!
Don't get me wrong, I like my Privacy! But everyone trying to legislate for it or protect it, are missing the slow creep of change. Security folks are even largely missing this change, though they might argue that they catch the real issue obliquely under the guise of the I or A in C.I.A. that is Integrity or Availability
But sadly Integrity or Availabilty do not cut it...
It's about Control, or more correctly the downside, ie "Loss of Control". Take a look at the real threat behind Advance Persistent Threats (APTs). Many of the famous one's had no interest in exfiltrating information, that is threatening Confidentiality or Loss of Privacy. They were about taking control of the assets they were attacking whether alternating rotational speed of centrifuges, in order to cause them to self destruct. or just prior to the attack on Iraq taking control of the Iraqi military Communications, Command & Control system.
In short Agency is the thing we should be maintaining and protecting not Confidentiality or Privacy. Basically because if the right entities are "In Control" of the right assets then most security problems are solved.
In order to keep control in the right hands, our focus should be on Identity, and Entitlement.
Watch the Jericho Forum Identity, Entitlement, and Access Management videos on YouTube.
Some call Entitlement; Rights Management, sadly this term has been discredited due mainly to the fact that initial "rights management" implementations were used by the music industry to reduce or control the rights of listeners asymmetrically, i.e. in a manner that is similar to the "Heads I Win, Tails You Lose" model of control.
Effective controls have to be symetrical, with the right entity being in control of the right assets, in order for this to occur, legislators should stop focussing on Privacy, and start focussing on Agency.
We are living in a world where Agency is being, at best reduced, at worst destroyed. Devices are being built and sold that Never give full control to their users. The early PC was Agency neutral, it arrived with no one in control, the owner could gain "Root" access to the device and take full control. more recently devices arrive that can never be controlled by the purchaser of the device. Sony took the control of their Play Stations away from their owners, Apple never gave iPhone Users control, they tried to keep it, "JailBreaking" being the only means of gaining true "Root" access.
Samsung Smart TVs are another example of a class of devices that denies control to their owners.
I blogged on this earlier.
Imagine, if you will a world where devices like for example an aeroplane could be configured to act in a manner not directed by the pilot or co-pilot. The current conundrum of the missing Malaysian Airline could well be explained by catastrophic loss of Agency. The communications, command and control systems on the plane are all controlled by software normally controlled by those in the cockpit. A malicious third party, or nation state may have inserted an APT that took control of the plane. Was this a trial run of a new form of terrorism?
It may turn out to be a pilots malicious actions, either way it is an Agency problem!
"He says typing on an iPad that he doesn't have full control of!"
(As I have stated before the word Agency is not being used here in it's more recent organisational construct.)
I'm up to here with Privacy!
Tuesday, February 25, 2014
Aargh! Yet another Raised Bed/Silo in my Walled Gardens
Dear Satya
To give an Entity (Government, Organisation, Person or Device) Agency, there are three things that must be sorted:-
1) The ability and capacity to trust the identity of remote entities,
whether Anonymous (but same) or Named (and verified)
2) The means to transact in a trusted manner, ie negotiate, contract, commit, deliver, and pay in whatever persona we chose.
3) The opportunity to collaborate in a trusted environment
For me the current manner of attempting to achieve this with secrecy is doomed to failure.
We need an open trustworthy ecosystem, to accomplish the above.
I believe Microsoft can be one of the reasons that this ecosystem can come into being.
Please help us move from the "Agency Free" Enterprise/Network space through the "Agency Impaired"(App/Service)^2 domain to the "Agency Enabling" Entity/Device/Data Nirvannah
Is it just me?
Human Agency defined previously here; is something that we innately desire, but are too often giving up in exchange for mere fripperies. A free game gets access to our location, our friends, and all their details and even the right to change our address books, without any further input from us, and often with not even a tiny shiver of fear.
Many moons ago I was advised to cook a crab by placing it in cold salt water and slowly bringing the temperature up, as it would not notice before it was too late, that it was in "hot water".
The water is getting warmer, and yet we still do nothing but click on anything that gives us "something for nothing". Except, it is our "Agency", it is not nothing! If we give it away it will be very hard to get back. Atfer all the web never forgets...
If Religion is the opiate of the People, then Apps are the Designer Drugs, and Devices are the Syringes!
Inject them into your life at your peril!
At least think before you click...
Remember: We are the Crabs!
Enterprises should ask:
How to invest in a Collaborative Future?
How to avoid cooking your customers?
How to compete in ways that develop Human Agency?
Governments should ask:
How to legislate to protect Human Agency?
How to achieve compliance?
How to punish the theft of Human Agency?
How to empower the populace? (Education?)
Individuals should ask:
How can we (Co-)create our future?
How do we get out of the pot?
How to support organisations that protect our agency?
Monday, February 03, 2014
The Missing Commandment
Some apparently establish the prime law in their initial attempt, in 2009, Robin Murphy (Texas A&M) and David D. Woods (Ohio State) proposed "The Three Laws of Responsible Robotics"
The laws are as follows:
- A human may not deploy a robot without the human-robot work system meeting the highest legal and professional standards of safety and ethics.
- A robot must respond to humans as appropriate for their roles.
- A robot must be endowed with sufficient situated autonomy to protect its own existence as long as such protection provides smooth transfer of control which does not conflict with the First and Second Laws.
- Fundamentals
- Surviving in a Hostile World
- The Need to Trust
- Identity, Management, and Federation
- Access to Data
Tuesday, January 14, 2014
So what drives e-trust in an Outside-In world
We probably first need to define Outside-In and e-Trust:
The first definition will be the most difficult to capture in a single sentence, especially as LEF's own understanding of the concept is fast evolving, from being just an IT based paradigm focussed on platform location, to taking a more holistic business perspective resulting in the importance considering and engaging in the development of new business ecosystems, often powered by the fast evolving internet.
Outside-In
The approach or mindset of an enterprise or entity that makes use of an external network of partners and/or co-creators to expand the size of the network for the benefit of it's participants. This will more often involve the effective use of information or innovation sourced from the external network, than it will internally created information or innovation.
e-Trust
Involves the capacity to develop confidence during specific interactions, that involve specific assets, through various devices and systems across networks to other knowable and unknowable entities. One might call it Virtual Trust.
After my coughing bout, and a period of what felt like insane clarity, I fell asleep after having created the following seven top Level "A"s, as perceived by the end user.
(NB I did not concern myself with the deeper, more technical components that will be required to deliver on these high level drivers.)
Affordance, Accessibility, Availability, Accuracy, and Agency....
I swear I came up with a sixth and seventh A, but as I fell asleep soon after with a deep sense of satisfaction, I failed to properly store it in my sleepy neurons. Wait, they have appeared, I can't believe I momentarily forgot them, they are of course;
Authenticity and Authority
As I went to sleep, I gave myself the challenge of comparing these seven terms with the Parkerian Hexad, but first lets quickly define these seven drivers, not in any specific order. I will tweak the Wikipedia definitions to match the needs of this blog post. Remember we are considering the drivers of e-trust in an Outside-In world. I will not argue for or against these terms, I will just try and define them in the context of Outside-In.
Affordance
The capacity of an object, service, ecosystem, or environment, to allow an entity to perform an action.
This term relates also to such concepts as usability, simplicity
Accessibility is the degree to which information, products, devices, services, or environments are available to as many entities as possible.
Availability is the probability that an item will operate satisfactorily, or information would usable at a given point in time when used under stated conditions in an ideal support environment. Simply put, availability is the proportion of time a system is in a functioning condition.
Accuracy The nearness or closeness of information to the actual value of information being accessed.
Agency is the capacity of an agent (a person or other entity) to act in a world, including controlling access to their own information.
Authenticity The genuineness of content or identity, actually possessing the alleged or apparent attribute or character,
Authority Represents the legitimacy of an entity to define formal rules or rights, established in law or by decree of the owning entity.
So onto my Parkerian Hexad comparison...
My seven terms Affordance, Accessibility, Availability, Accuracy, Agency, Authenticity and Authority
The terms from the Parkerian Hexad
- Confidentiality
- Possession or Control
- Integrity
- Authenticity
- Availability
- Utility

