The identity crisis: Password managers and your business


Steve Cassidy

3 Apr, 2018

It used to be the case that when someone said they were having an «identity crisis», they would go on to tell you about their imaginary friend. However, this is 2018 and issues of identity are all over the news – and of the utmost importance to businesses.

If you’re the go-to person for an organisation of any size or scale, you’ll know that problems with passwords have gone from a quiet, almost academic bit of admin to a headline-grabbing, company-destroying risk. So every business should be asking: what are the potential hazards, and what can we do to protect ourselves?

The ID problem

Nobody can get away from the need for passwords these days. They used to be the preserve of the office network, but now you can’t even avoid them if you’re unemployed: benefit systems want you to log in and prove who you are to access your personalised view, save your data and so on. And as online security has become a growing burden, not just at work but in our personal lives, it’s been no surprise to see password managers gaining popularity all over the app and web service marketplace.

Great, problem solved – no? Well, that was the theory. But cynics such as myself weren’t at all surprised when it emerged that these services had security vulnerabilities of their own. In the summer of 2017 we saw a spate of accusations that one web password manager or another had been hacked or cracked.

Regardless of whether your precious identity data had actually been compromised or not, this was a painful wake-up call for customers. Many had entrusted their passwords to such systems believing this would allow them to stop worrying about security scares; now they found themselves forced to think about questions such as what happens when your password manager gets taken offline and you don’t have paper copies of all the passwords you’ve loaded into it.

And what if you get caught without a Plan B on the day when a hacker (or disgruntled staff member) changes all those passwords and locks you out of your own system?

Five years ago, one aspect of this discussion would have been what makes a good or a bad password. Today, that’s rather a moot point. First, due to the fact that folklore is the dominant source of advice on the topic for most people, your typical CIO – or, as it often is, an overstretched support junior – has to cope with all the possible levels of password quality across their whole organisation.

Secondly, it’s a fact of life that most companies are no longer in a position to fully dictate their own password policies, thanks to an increasing reliance on external service providers. Your company procedures may state that all passwords must be deposited in escrow, written in blood on vellum, or changed every leap year: the reality comes down to the cloud operator’s policy.

Security in the cloud

Ah yes, the cloud – the single greatest confounding factor when it comes to password security. At the start of this decade, it was still possible to talk about «single sign-on» and mean nothing more than granting access to the LAN plus Active Directory resources, and perhaps a few HTTP services.

Meanwhile, in 2018, we have to deal with much bigger challenges of scope. Your access security systems have to work inside the company office; in employees’ homes; with the third-party services that your business signs up to; with your smartphone apps, on at least two platforms; with physical tokens for building access; on networks where you are a passing guest; in IPv6 environments… well, that’s enough semicolons for now. You get the picture.

Needless to say, where there’s a technical challenge this confusing, there’s a proliferation of outsourced «solutions» that can help you get on. However, these are almost entirely aimed at larger businesses, where a dedicated individual is available to negotiate between what the business wants to do with identities – the usual staff join/move/leave lifecycle – and the demands made by regulations or relationships with third parties.

And even then, recent trends in larger business IT make things very complicated. Remember, both identity solutions and line-of-business services tend to live in the cloud, and a lot of their appeal to customers is down to their ability to interoperate with other services by way of inter-supplier APIs.

So if, for example, you’re logged into Salesforce and hit a button to switch to another app, it’s not your PC that forwards your credentials to the next host: Salesforce initiates a direct conversation, server to server. We’re very much living in the age of the business-to-business API economy – and good luck managing that.

Then there’s software-defined networking (SDN) – an idea that can deliver a great security boost for your network. SDN takes advantage of the fact that there’s enough computing power floating around now for even a humble network switch to actively isolate, monitor and manage the network traffic generated and received by each individual PC.

This is seriously useful when it comes to infection control: after all, in most company networks, PCs have next to no need to talk directly to each other – only viruses do that. SDN ensures that PCs only talk to the appropriate servers and routers, using rules that relate to the individual, rather than to the floor or department their computer happens to be in.

The thing about SDN is that it requires users to authenticate before they can have any sort of access to the network. No biggie, you might think – users these days have been schooled by Wi-Fi to expect a login prompt. However, if your identity broker is in the cloud, you need a way for users to access that before logging into the SDN-secured network.

From an architectural perspective, the answer is simple: just have a default access policy that lists the identity servers as always available, without credentials. But that’s not quite the same as saying that every cloud- based identity broker recognises the problem. Many businesses undertake big reorganisations in order to escape the «Microsoft Trap» of server-centric networking, only to fall into a maze of incompatible authenticators, each of which is sufficiently new to consider a three-year product lifecycle in this field as perfectly normal.

All of which brings me to another issue: portability.

Moving your users around from service to service

If you’re thinking of engaging a cloud-based password-management service, this is a key question: how easy is it for the administrator to do drastic things with the database of users and passwords? Is it possible to upload bulk lists of users (say, on the day your company takes over another one) and indeed, download and examine such lists, looking for issues such as duplicate passwords?

These aren’t unreasonable things for an IT department to want to do. Yet, online password managers, anxious about the potential for abuse, tend to rule it out completely. This is an unfortunate side effect of the influence of consumer security policies – everyone gets treated as a separate individual with no security crossovers.

But, if you think about it, that’s the diametric opposite of what most companies actually want. Your firm’s user database is built on groups and policies, not on hundreds of unique individuals.

There is another way. It might sound unfashionable in 2018, but what people are crying out for, in a forest of password-as-service cloud apps, is a return to the glory days of Active Directory. The simplest answer to bridging the divide between cloud identity and LAN identity is to focus on the lowest common denominator, namely an old-school Windows Domain environment. Don’t rely on the cloud for everything: use it to grant access to a Windows server, which can take on the traditional role of local service manager and gateway.

It’s an approach with numerous benefits. For a start, nobody in the old-school LAN world is going to hold your company user list to ransom, or make changes to pricing once you’re on board, or restrict your choices of IoT deployment to a limited roster of approved partner manufacturers. Indeed, the idea helps justify the high price of Windows Server licences – they’re steep if you just want file and print services, but if you look at the complexity and cost of managing passwords and user identities, it starts to make a lot of sense.

Crystal balls

Passwords have their benefits, but (as my colleague Davey Winder has frequently noted) a physical token can be a powerful alternative or supplement to a conventional password. Indeed, it remains a great puzzle that business hasn’t really embraced the idea. You can find products that use USB or Bluetooth to provide preset usernames and passwords, but these tend to exist only in specialised niches.

Notably, in the consumer sector, the idea of using a physical key has been superseded by two-factor authentication (2FA), where a login attempt generates a second single-use password that’s sent to the customer’s registered mobile number. This too has its strengths, but there’s an assumption of continuous internet access – or, in some cases SMS service – that isn’t always realistic. It’s fine if you’re sitting at your desk trying to log into your email, but less so if you’re standing in a snowy car park late at night, trying to get into the office because you’ve been called out to deal with a network outage.

In fact, if you’re going to rely on any sort of single sign-on system, there’s an almost inevitable requirement for defence in depth – that is, you need the same identity data to be accessible in several different ways, so it can remain available under most plausible scenarios. Again, this is certainly not a new insight when it comes to system design, but it’s one the always-connected generation finds easy to forget.

This doesn’t have to mean investing in layer upon layer of redundant infrastructure. What it might mean, however, is a «fog computing» approach – a model where cloud-based services connect directly to the perimeter of your home network and devices. In this case, you want systems that are reachable from that snowy car park, able to remember the last state of the security database – and just smart enough to let you in.

Image: Shutterstock

Eight steps for a pain-free cloud migration: Assessment, migration and support

Cloud adoption by UK companies has now neared 90%, according to Cloud Industry Forum, and it won’t be long before all organisations are benefiting to some degree from the flexibility, efficiency and cost-savings of the cloud. Moving past the first wave of adoption we’re seeing businesses ramp up the complexity of the workloads and applications that they’re migrating to the cloud. Perhaps this is the reason that 90% is also the proportion of companies that have reported difficulties with their cloud migration projects. This is frustrating for IT teams when they’re deploying cloud solutions that are supposed to be reducing their burden and making life simpler.

With over a decade of helping customers adopt cloud services, our iland deployment teams know that performing a pain-free migration to the cloud is achievable but that preparation is crucial to project success. Progressing through the following key stages offers a better chance of running a smooth migration with minimum disruption.

Set your goals at the outset

Every organisation has different priorities when it comes to the cloud, and there’s no “one cloud fits all” solution. Selecting the best options for your organisation means first understanding what you want to move, how you’ll get it to the cloud and how you’ll manage it once it’s there. You also need to identify how migrating core data systems to the cloud will impact on your security and compliance programmes. Having a clear handle on these goals at the outset will enable you to properly scope your project.

Before you begin – assess your on-premises

Preparing for cloud migration is a valuable opportunity to take stock of your on-premises data and applications and rank them in terms of business-criticality. This helps inform both the structure you’ll want in your cloud environment and also the order in which to migrate applications.

Ask the hard questions: does this application really need to move to the cloud or can it be decommissioned? In a cloud environment where you pay for the resources you use it doesn’t make economic sense to migrate legacy applications that no longer serve their purpose.   

Once you have a full inventory of your environment and its workloads, you need to flag up those specific networking requirements and physical appliances that may need special care in the cloud. This ranked inventory can then be used to calculate the required cloud resources and associated costs. Importantly, this process can also be used to classify and prioritize workloads which is invaluable in driving costs down in, for example, cloud-based disaster recovery scenarios where different workloads can be allocated different levels of protection.

Establish tech support during and post-migration

Many organisations take their first steps into the cloud when looking for disaster recovery solutions, enticed by the facility to replicate data continuously to a secondary location with virtually no downtime or lost data. This is fundamentally the same as a cloud migration, except that it is planned at a convenient time, rather than prompted by an extreme event. This means that once the switch is flipped, the migration should be as smooth as a DR event. However, most organisations will want to know that there is an expert on hand should anything go wrong, so 24/7 support should be factored into the equation.

Boost what you already have

Look at your on-premises environment and work out how to create synergies with the cloud. For example, VMware-users will find there’s much to be said for choosing a VMware-based cloud environment which is equipped with tools and templates specifically designed for smoothly transitioning initial workloads and templates. It’s an opportunity to refresh the VM environment and build out a new, clean system in the cloud. This doesn’t mean you can’t transition to a cloud that differs from your on-premises environment, but it’s a factor worth taking into consideration.

Migration of physical workloads

Of the 90% of businesses that reported difficulty migrating to the cloud, complexity was the most commonly cited issue, and you can bet that shifting physical systems is at the root of much of that. They are often the last vestiges of legacy IT strategies and remain because they underpin business operations. You need to determine if there is a benefit to moving them to the cloud and if so take up one of two options: virtualise the ones that can be virtualised – possibly using software options – or find a cloud provider that can support physical systems within the cloud, either on standard servers or co-located custom systems.

Determine the information transfer approach

The approach to transferring information to the cloud will depend on the size of the dataset. In the age of virtualisation and of relatively large network pipes, seeding can often be viewed as a costly, inefficient and error prone process. However, if datasets are sufficiently large, seeding may be the best option, with your service provider providing encrypted drives from which they’ll help you manually import data into the cloud. A more innovative approach sees seeding used to jumpstart the migration process. By seeding the cloud data centre with a point in time of your environment, you then use your standard network connection with the cloud to sync any changes before cut-over. This minimises downtime and represents the best of both worlds.

Check network connectivity

Your network pipe will be seeing a lot more traffic and while most organisations will find they have adequate bandwidth, it’s best to check ahead that your bandwidth will be sufficient. If your mission-critical applications demand live-streaming with zero latency you may wish to investigate direct connectivity to the cloud via VPN.

Consider post-migration management and support as part of the buying decision

Your migration project is complete, now you have to manage your cloud environment and get accustomed to the variation from managing on-premises applications. The power and usability of management tools should be part of the selection criteria so that you are confident you will have ongoing visibility and the facility to monitor security, costs and performance. Furthermore, support is a crucial part of your ongoing relationship with your cloud service provider and you need to select an option that gives you the support you need, when you need it, at the right price.

As more and more businesses take the plunge and move mission-critical systems to the cloud, we’ll see the skills and experience of in-house teams increase and the ability to handle complex migrations will rise in tandem. Until then, IT teams charged with migration projects shouldn’t be afraid to wring as much support and advice out of cloud service providers as possible so that they can achieve a pain-free migration and start reaping the benefits of the cloud.

Oracle automates the cloud data warehouse with AWS in its sights


Clare Hopping

29 Mar, 2018

Oracle is taking AWS head-on, with its newly launched Oracle Autonomous Data Warehouse Cloud, which uses machine learning to provide self-managed security for the cloud.

The smart service can secure itself against threats and implement patches autonomously to ensure data stays as secure as it possibly can be.

Not only does the technology mean databases can be ultra-secure, but it also significantly cuts down the time it takes to set up the data warehouse. Admins don’t have to manually manage workloads, even when they change, nor do they need to lift a finger when storage volumes are adjusted.

Migration to the cloud is made simple too, with full compatibility between on-premise and cloud databases.

«This technology changes everything,» said Larry Ellison, Oracle’s co-founder. «The Oracle Autonomous Database is based on technology as revolutionary as the Internet. It patches, tunes, and updates itself. Amazon’s databases cost more and do less.»

Oracle’s Autonomous Data Warehouse Cloud spins up a secure data warehouse in seconds, automatically setting up backup, encryption and high availability without humans intervening.

The tech is built upon Oracle Database 18c, the company’s latest database infrastructure it introduced back in October, alongside its automated cybersecurity platform.

The company said in the announcement that it’s so confident in its Autonomous Data Warehouse Cloud, it reckons its product offers the same workload as AWS, but at half the cost – a bold claim indeed.

This is the first Autonomous Database Cloud service Oracle plans to launch in its series. Coming up in the next few months will be Autonomous Database for Transaction Processing, Oracle Autonomous NoSQL Database and Autonomous Graph Database for analysing network traffic.

Last year, just after Oracle first announced it was working on self-healing databases, Ellison said if Equifax had been using his company’s self-patching database, it would not have been hacked. 143 million customer details were exposed when hackers broke into the credit firm’s database, because the company hadn’t rolled out a patch issued by the Apache Foundation.

Salesforce harnesses Mulesoft to connect data silos


Clare Hopping

29 Mar, 2018

Salesforce has announced Salesforce Integration Cloud, taking advantage of its recent acquisition of MuleSoft to surface relevant customer data and turn it into valuable insights to better target them through relevant content.

The company explained it would use MuleSoft’s technology to power its integration cloud, although Salesforce made it clear Mulesoft’s standalone Anypoint Platform would continue to develop in its own right.

Salesforce’s Integration Cloud allows marketers to build a comprehensive profile of the customer from all sources of data, all accessible from one place, making it much easier to manage interactions and touchpoints without having to bounce from app to app, platform to platform.

This means administrators can find the best ways to target customers with relevant information across sales, service, marketing and commerce. 

An integral part of Salesforce Integration Cloud is Lightning Flow, which allows developers other parts of the business to build workflows based around customer data. It’s a visual way of building processes, which makes it easier for everyone in the organisation to understand, resulting in increased productivity and less waiting time for customers.

The company will also give developers the chance to integrate Einstein into their apps, embedding Einstein Analytics and live updates, alongside third-party Quip live apps.

«Companies of every size and industry need to transform how they operate in the digital era—and that transformation starts and ends with the customer,» said Bret Taylor, president and chief product officer of Salesforce said.

«The Salesforce Platform empowers our entire Trailblazer community, regardless of skill levels, to harness the latest advancements in technology and deliver the connected customer experiences that will take their companies and careers to new heights.»

DevOps Panel with @Aruna13 | @DevOpsSummit @CAinc #Agile #Serverless #CloudNative #DataCenter

As DevOps methodologies expand their reach across the enterprise, organizations face the daunting challenge of adapting related cloud strategies to ensure optimal alignment, from managing complexity to ensuring proper governance. How can culture, automation, legacy apps and even budget be reexamined to enable this ongoing shift within the modern software factory?
In her Day 2 Keynote at @DevOpsSummit at 21st Cloud Expo, Aruna Ravichandran, VP, DevOps Solutions Marketing, CA Technologies, was joined by a panel of industry experts and real-world practitioners who shared their insight into an emerging set of best practices that lie at the heart of today’s digital transformation.

read more

Oracle announces first autonomous database service, promises to ‘redefine cloud database’

Larry Ellison praised Amazon for ‘inventing’ the infrastructure as a service (IaaS) market – but with the announcement of the first service based on Oracle’s much-touted autonomous database, the company aims to go bigger and better than the IaaS behemoth.

At an event yesterday, Ellison announced the launch of the Oracle Autonomous Data Warehouse Cloud. As the company put it, the new product ‘delivers all of the analytical capabilities, security features, and high availability of the Oracle Database without any of the complexities of configuration, tuning, and administration’.

This news had been coming. Last month saw updates to the autonomous database cloud by making all Oracle Cloud Platform services ‘self-driving, self-securing and self-repairing’, in the words of Thomas Kurian, president of product development. When Oracle reported its latest financials earlier this month, Ellison promised more of the same, expecting to deliver autonomous analytics, mobility, application development and integration services over the coming months. Attendees yesterday were told this was the ‘first of several’ autonomous PaaS services Oracle will deliver this year.

Ellison espoused his views on AWS during an impromptu break to fix slides at the beginning of his presentation. “Everyone knows, and everyone gives rightful credit to Amazon for kind of inventing the market for infrastructure as a service. They noticed that in a lot of ways it’s more efficient to rent computers than buy computers.

“Amazon pioneered the notion… but the way Oracle plans on – and is in the process of – differentiating itself from Amazon is to offer a complete suite of platform services that are at a higher level than low level infrastructure stuff,” added Ellison. “Rather than developing database applications like you used to develop, you’ll use these new PaaS services.”

Back in October, Ellison ran a series of benchmark demonstrations around running an Oracle database on an Amazon cloud, and on its own cloud, joking to the audience that he would have to skip some of the Amazon demos because they took too long to complete. The company still promises to cut Amazon bills in half running the same data on an Autonomous Data Warehouse Cloud service, with the offer valid until the end of May 2019, which you can find out more about here.

Change Your Thinking About OSes

Virtual machines (VMs) have a number of features and properties that require a new way of thinking about operating systems (OSes) so that you can take full advantage of a VM. Doing a major OS update on your Mac®—or even installing a macOS® from scratch—scares many users. “What if the update fails, will my Mac […]

The post Change Your Thinking About OSes appeared first on Parallels Blog.

AWS says its entire cloud is GDPR-ready


Clare Hopping

28 Mar, 2018

Amazon Web Services (AWS) has officially announced that all of its products and services are fully GDPR-compliant, meaning any businesses looking to beef up their policies for the incoming law change are covered if they use the platform.

The company said it drafted in «security and compliance experts» to audit its inner workings as a data processor, who approved it as fully compliant. 

AWS explained the aspects that ensure it’s compliant with GDPR include the encryption of personal data, assurance that any data processed on its platform offers ongoing confidentiality, integrity, availability, and resilience and that data can be restored quickly should a physical or technical incident occur. It also said it regularly tests, assesses and evaluates its operation to ensure it complies with security.

«This announcement confirms we have completed the entirety of our GDPR service readiness audit, validating that all generally available services and features adhere to the high privacy bar and data protection standards required of data processors by the GDPR,» said VP of AWS security assurance, Chad Woolf in a blog post.

«We completed this work two months ahead of the May 25, 2018 enforcement deadline in order to give customers and APN partners an environment in which they can confidently build their own GDPR-compliant products, services, and solutions.»

Wolf said AWS is also prepped to train staff around compliance issues via a range of workshops and summits, led by its Professional Services team. The workshops are tailored to each business’s particular needs and these will be supported by presentations during the company’s European, San Francisco and Tokyo summits.

AWS will also make its compliance, data protection and security teams available to businesses via their AWS Account Manager, so if they need any further clarification AWS’s staff will be on hand to help.

Wolf also pointed to four existing services, Amazon Guard Duty, Amazon Macie, Amazon Inspector and Amazon Config Rules, that could help customers ensure their own GDPR compliance as well.

«AWS’s GDPR service readiness is only part of the story; we are continuing to work alongside our customers and the AWS Partner Network (APN) to help on their journey toward GDPR compliance,» he concluded.

Main image credit: Shutterstock