Saturday, September 27, 2014

Assurance is not for Arminians

I have been reading through Thomas BrooksHeaven on Earth and the book has been focusing a lot on the doctrine of assurance and thought I would share some tid bits.
“This precious ruth thus proved, looks sourly and wishly upon all those that affirm that believers cannot in this life attain unto a certain well-grounded assurance of their everlasting happiness and blessedness, as papists and Arminians; all know that know their writings and teachings, that they are in arms against this Christ-exalting, and soul-cheering doctrine of assurance. ‘I know no such thing as assurance of heaven in this life’, saith Grevinchovius the Arminian. Assurance is a pearl that they trample under feet; it is a beam of heaven that hath so much light, brightness, and shining glory in it, that their blear-eyes cannot behold it.” “Arminians are not ashamed to say, that God may crown a man one hour, and uncrown him in the next.”

So we see in this excerpt from Mr. Brooks work that what the Arminian professes is actually antithetical to the gospel and brings if not bad news, then most certainly questionable news. From this we can see why the Roman Catholic church places such emphasis on purgatory; they have no hope of assurance without a meritorious work of penance that cannot ever be met since only Christ was sinless to pay the offenses against an infinite God would take an infinite amount of time to satisfy and that would never bet met and hence no hope at all. What saith the scripture? In John 10:29, Christ says, “My Father, which gave them me, is greater than all; and no man is able to pluck them out of my Father’s hand.” Notice that Christ assures the believer that salvation is not dependent upon the believer in that God’s electing purposes take precedence over man’s efforts to earn salvation. This does not make man an autonomous robot requiring no action on his part; it just means that God’s grace is sufficient to secure the believers position in Christ.

Let the reader consider.

Am I Evil?

td1

“And GOD saw that the wickedness of man was great in the earth, and that every imagination of the thoughts of his heart was only evil continually.”Genesis 6:5 (KJV)


Before I became a Christian I was a big heavy metal fan of Metallica and one of their songs off of their first albums, was a song titled, “Am I Evil?”
Years later, I am now a Reformed Christian and Calvinist and I thought that this song as bad as the lyrics are morally, does teach a fundamental Christian doctrine; Total Depravity.
So what is the definition of Total Depravity?

 
I think John Frame has a nice terse definition that we will use: “Although fallen persons are capable of externally good acts (acts that are good for society), they cannot do anything really good, i.e., pleasing to God (Rom. 8:8). God, however, looks on the heart. And from his ultimate standpoint, fallen man has no goodness, in thought, word, or deed. He is therefore incapable of contributing anything to his salvation.” –John Frame
I often hear people say that they believe in the basic goodness of human beings. As nice as that would be to believe, the bible negates this premise from Genesis to Revelation. From the original verse that was quoted(Genesis 6:5) the people teaches in the basic sinfulness of human beings, which is why the flood occurred and why the Bible teaches Total Depravity as the true nature of mankind.
This doctrine is defined holistically in the five points of Calvinism of which, Total Depravity is the first point and it’s a negative one. The good news is that God has remedied this problem through His plan of redemption in sending His only begotten Son, the Lord Jesus Christ. It is only by this one act of grace that God transforms a total depraved heart into a sanctified one.
“I thank God through Jesus Christ our Lord. So then with the mind I myself serve the law of God; but with the flesh the law of sin.” –Romans 7:25
To conclude the song that I referenced, “Am I Evil?” closes with the same question as its title, Am I Evil? Apart from God’s saving grace in Christ, the answer will always be, “I am man, yes I am.”

2013 Security Reading List

During the second week of December I realized that our group had not used their 2012 training budget. Realizing that there was not enough time to get a formal security class under way before the end of the year, I suggested to my manager that our group use the funds to order security-related books. He gave us the green light and behold the list below. Goal is to finish them by December 31, 2013. We’ll see what happens.
Security Analysis: Principles and Technique
White-Hat Security Arsenal: Tackling the Threats
Violent Python: A Cookbook for Hackers, Forensic Analysts, Penetration Testers and Security Engineers
Malware Analyst’s Cookbook and DVD: Tools and Techniques for Fighting Malicious Code
Defense Against The Black Arts: How Hackers Do What They Do And How To Protect Against It
The Web Application Hacker’s Handbook: Finding and Exploiting Security Flaws
The Implementation (TCP/IP Illustrated, Volume 2)
TCP/IP Illustrated, Volume 1: The Protocols
Security and Access Control Using Biometric Technologies
Cisco IOS Access Lists
Social Engineering: The Art of Human Hacking
IT Security Metrics: A Practical Framework for Measuring Security & Protecting Data
Securing The Cloud: Cloud Computer Security Techniques And Tactics
Cyber Warfare: Techniques, Tactics and Tools for Security Practitioners
CEH Certified Ethical Hacker All-In-One Exam Guide [With CDROM]
Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems
Gray Hat Hacking the Ethical Hackers Handbook
Hacking: The Art of Exploitation
Metasploit: The Penetration Tester’s Guide

Whole Disk Encryption Principles

All of the components associated with managing the Whole Disk Encryption(WDE) infrastructure should be classified as a High Value Asset (HVA). The backend assets contain the components involved for protecting the encryption and decryption keys that are used to encrypt hard drives. Treating the backend components of the Disk encryption environment as HVA, will ensure that the cryptographic keys are protected through a layered approach to securing the environment. This of course assumes you are architecting your security environment around various layers and are classifying certain assets as HVA’s and others at lower classifications.

Here some basic principles to ensure you are following when designing your WDE:
  • Recovery tools to recover a dead machine by putting the hard drive in a different machines.
  • Enforce Progressive password policy or use enterprise credential store.
  • Whole disk encryption by volume or sector. File based encryption is not acceptable.
  • Central management of keys.
  • Central management of machine and user policy.
  • Unlock as a known user before logging into the desktop.
  • Prove that the machine was logged into/unlocked by a specific user.
  • Machine is secure & encrypted until unlocked by an approved user.
  • Disabled users cannot unlock the machine.

A Security Perspective on the Conneticut Shootings

Given the horrible tragedy that took place yesterday in our nation, I have been given a lot of thought to how to mitigate these shooting incidents. Given the fact that my career has been centered around protecting company resources and putting plans, processes, and procedures in place to respond to security incidents, I thought I would provide a similiar approach for dealing with school shootings.
It’s important to note when I’m referencing “assets” I”m referring to the victims involved in the given incident. Please do not take this as an insensitive term to those victims, it’s just easier as a point of reference. I would also point out that I have two boys (12 & 8) that have just as easily been victimized as those from yesterday’s incident. When I use the term “threat vector” I’m speaking mainly of the perpetrators involved in the shootings.
To keep things simple for those not acquainted with Information Security concepts, I’m going to break my recommendations into two main headings; Access Control and Incident Response.

Access Control

1. Authentication – This is the means by which we identify who a given asset is in order to determine who to control what that asset has permissions to do and what resources that asset has permissions to access. The fundamental question that needs to be answered with this is, “Who are you?”.
Recommendation: Our school systems need to put security controls in place that enforce authentication checks for all staff and students within our school systems. This would take the form of a badge swipe system implemented on every entry point within the physical boundaries of the school system. Minimally this should be placed on all entry points into the building and on each classroom door.
2. Authorization – This is the means by where once the authentication question has been answered (Who are you?) we can determine what access the given asset has access to. The fundamental question that is asked with authorization is, “What are you permitted to access?”.
Recommendation: Our school systems to implement authorization controls to control who has access to what areas of the school buildings to minimize the threat vectors that can be exploited. For example, I think it would be entirely plausible for teachers to have authorized access to all of the classrooms, but not every student should have access to every classroom.

Incident Response

In the six steps that are to follow I will at times be making reference to the Access Control section. This is because in a number of areas the success of your response to a school shooting incident depends on your Access Control system.
1. Preparation – The fundamental success of any incident response plan is preparing for known risks that could turn into incidents. Given the number of incidents that this nation has been affected by, I think this is the only area that is lacking the most. Without access controls how are you going to prepare for the next shooting incident?
Recommendation: Our school systems need to create preparation plans for responding to a shooting incident. This will be radically enhanced if adequate access controls are in place.
2. Identification – The next step in the incident handling process is identifying the source of the incident. Without being able to identify the threat as it happens you will not be able to respond.
Recommendation: Our school systems need to be able to identify the threat vectors as they are occuring to minimize the number of causulties.
3. Containment – Containment has to due with isolating the threat vector that is responsible for the incident. The goal is to minimize the damage this is occuring as much as possible.
Recommendation: Our school systems need to be able to contain the threats vectors as they are occuring. Yes, getting the kids and staff out as soon as possible is probably the best method for the current system, but with fully implemented access controls containment processes will most likely need to be modified.
4. Eradication – No surprise here, the threat needs to be removed from the environment one way or the other.
Recommendation: I think our law enforcement agencies get a good grade on this one. The only change I would like to see is to have at least one dedicated security officer to each school to start the eradication process prior to law enforcements arrival.
5. Recovery – This has to do with getting this back to normal within the environment.
Recommendation: Our school systems should have a vareity of services available to console the victims that were affected by the incident and to get the school back in working order.
6. Lessons Learned – The entire sequence of events relating to the incident need to be reviewed and graded based on how things were handled.
Recommendation – Our school systems need to review every shooting incident that occured to determine the effectiveness of the response and how to improve it.
I do recognize with what I have proposed that a significant amount of cost will need to be invested by the state into our school systems to provide these controls. Given the current budget crisis of nearly every state in our union the only alternative I can see is for each state to get federal funding to charter a national campaign to protect our school systems from the next incident.

Keys to Data Loss Prevention (DLP) Success

Being a Information Security geek for sometime I have had a significant exposure to DLP over the years and being exposed to two major vendor distributions along with processes and procedures I have found some high-level principles that should be followed.
1. Know Thy Risk – This often seems to be taken for granted, but depending upon your business model not everyones risk for data leakage will be the same. Healthcare will be more at risk for HIPAA than the Banking industry and Food Chains will be more at risk for PCI than body shops. In addition to known regulatory laws such as HIPAA and PCI you also need to assess the risk to your organization if one classification of data was leaked versus another. Once this risk assessment has been completed it will make it easier to drive priorities around your DLP initiative.
2. Data Classification – It is also important to define a Data Classification policy so that you can use this to define and drive your DLP policies. For example, you may have a Data Classification such as Highly Sensitive, Sensitive, Internal, and Public. Policy might dictate that all data identied as ‘Highly Sensitive’ must be encrypted, while data that falls under ‘Sensitive’ just needs to have strong access controls.
3. Document & Define Workflows – This is probably the most difficult aspects of DLP due primarily to dependecy upon other groups (Legal & HR) and the potential resource hours needed to manage the process. It basically comes down answering questions such as:
    Who needs to be notified when an incident is created by the DLP solution? Do we need to define thresholds for the notifcations?
    Who will determine if the incident is a false-positive or a real incident?
    Should the data be acted upon automatically? Should we quarantine or block the data that was identified in the incident?


I’m planning on making a series of additional blog entries around various other aspects of DLP in the near future.

Backtrack 5 & Scapy Python Dependecies

Have not blogged on any security-related topics in a while so I thought it was time. Scapy is a Python-driven program for generating TCP/IP packets on the fly and programtically. If you fire up Scapy on a fresh Backtrack 5 system you will be welcomed with two dependency errors; one complaining about the GNUPlot Python library and the other for PyX. I think there was another one for a GUI library, but can’t seem to find it in my Bash history.
Like most things Ubuntu/Debian the fix is pretty trivial:
apt-get install python-scitools python-pyx
There you go, happy packet hacking!

Buying Ammo Online

Since firearms sales have been skyrocketing since March 2020 due to the Rona and riots in some of the US larger Democrat controlled cities, ...