Thursday, June 18, 2009

Upgrade yourself @ 30 years old



I am 30 years old and honestly I feel more fit then I was like 5 to 6 years ago. I think I am in the best shape of my life, both physically and mentally.

I grapple, I wrestle, I box, I jog, I ride skateboards, I read a lot of networking, programming, and quantum physics books, all in a span of 7 days. Could it be possible that my physical and mental being has improved despite aging? I can never do all this 5 to to 6 years ago, I get tired easily, and my patience for reading and digesting complex concepts is absolutely horrible. Now, I can read a book for the first time, and absorb its content without going back to it and reading it again. I never even imagined I can learn to write codes! Now, I am creating my own Cisco IOS simulator using Python and thinking of porting it as a Java Applet.

Whatever it is I'm doing, I am sticking to it. I think its my positive outlook in all things in life that is helping me a lot.

Dreaming while awake, of things I want to accomplish and acquire is also helping me push harder to achieve them. A man without a dream will never reach his potential.

Good thing its Friday, I can now work on my Fakie 180 Ollies, hell, there's even a 4-set stairs in a park nearby that I am trying to ollie on. The young kids, around 15 to 18 years old that skates on that park can easily ollie and kickflip those 4-set of stairs without breaking a sweat. If they can do it, I can do it. I will even do it better, in style, style comes with age :-)



Sunday, June 14, 2009

Multi-Factor Authentication FTW!

Two-factor authentication is old-school now, it has served its purpose in the past. Bank institutions that offers on-line banking to its customers should think beyond two-factor, why not make a multi-factor authentication?

The current safeguard, standards, policies and other techniques to mitigate on-line banking fraud cannot keep up to the meteoric rise of tools to commit fraud. A simple kid struck by the hacking curiosity phenomenon (thanks to Hollywood of course) can easily just search Google for keywords "hacking tools download" and voila, links and links where to download and how to use them. In the past, one needs to understand how to write codes and navigate the command line interface, today, its the age of point and click cracking. Thank goodness for that rich, easy to use graphical user interface.

As Security Expert Bruce Schneier recommended, Bank institutions should focus on authenticating the transaction itself and not the identity of the individual. Identity information theft is so easy to accomplish nowadays. Crackers owe MySpace, Friendster, FaceBook, LinkedIn a lot. No need to do some serious underground data mining work, almost all personal and private information are tucked inside social networking website user profiles. You will be amazed on the high number of people setting their profile to public, exposing all their family pictures and personal information to the world wide weird.

Focusing on authenticating the actual on-line bank transaction is indeed a better way of controlling fraud.

Below is a sample Multi-Factor Authentication Process that Bank institutions can utilize:

1. Bank provides a secure login page for customer username, account number and password input.
2. Bank Server checks on the source public IP address and computer OS and/or MAC address of the transaction, which I am calling as "on-line transaction signature" logs the transaction attempt, and checked against that account owners database of logins if this IP address and other transaction signature has been used already in the past.
3. If public IP address is not listed, computer OS signature and/or MAC address does not match or not on the database for that account owner, this will trigger an alert to the Bank Customer Support Anti-Fraud Agents and they will call the customer on his listed telephone numbers for transaction verification.
4. If customer cannot be reached, the transaction is denied by default.
5. If Bank Agent was able to contact the customer, the Bank Customer Support Anti-Fraud Agent then asks a series of challenge questions to the customer to verify the identity of the customer.
5. As the customer answers the challenge questions, a voice recognition software runs on the background of the Bank Agent's telephone and analyzes the voice signature of the customer. The voice recognition signature software is the safeguard for impersonation attempts.
6. If customer was able to provide correct answers to the challenge questions and passes the voice signature match, customer is authenticated and authorized and transaction is allowed.
7. All transaction logs, denied or authenticated are stored on a secure server, and mirrored on a hot-site server.

Although possible, It will be very difficult even for the smartest social engineer to go through this multi-step authentication. It will make them think twice because of the tedious process. I know many of you will react that this will make on-line banking tedious which basically defeats the purpose of on-line banking, but id rather spend a couple of extra minutes doing secure on-line banking than opting for the fast method but opens the process to a lot of back doors for evil doers to come in.

Bank institutions should go above and beyond in protecting the investments of their depositors. They should invest serious money on research and development of the latest technology in transport layer security, cryptography and other safeguard mechanisms as well as improving standard policies and procedures. They should be liable for every on-line transaction fraud that involves one of their accounts, not the depositors because they should have complete control of a transaction that involves their network. All money matters should be taken seriously, no matter how small the amount is. This multi-factor authentication is one serious approach to curb the rise of on-line bank transactions.









Thursday, June 4, 2009

IP Artificial Intelligence Module: The Center of Your IP Network

In about 20 years or maybe less, we should have already created an Artificial Intelligence (A.I.) module that plugs in to our IP network. The sole purpose of this A.I. IP module is for automated governance of multiple Wide Area Networks (WAN) of the future.

This AI-IP module will be so advance that it will not rely solely on hardware power to completely manage your interconnected-network devices. I believe this A.I. module will contain sophisticated coding techniques that someday someone will discover. A.I. technology has been around so long, this should not take long to be discovered.

A sophisticated A.I.module for a computer network will act as the central control, no matter how many nodes you have on it. It can utilize a simple code tagging technique to a specific packet or traffic, keep track of the signature, payload, and behavior on its almost infinite database. The packet infrastructure of IP networks will evolve beyond IPv6.

No, this is not SkyNet. It will not be sentient, it will only follow what it has on its code.


Sunday, May 17, 2009

A quantum-powered laptop for my son's 22nd birthday

On his 22nd birthday, I decided to bring my son to the nearest Electronic Boutique and let him choose the gift he wants. I am proud of what my son has become, he inherited my passion and curiosity with computers, and her Mom's fortitude. He is a very-technical guy with a knack for street fashion and martial arts. In short, he reminds me of me when I was his age. He goes to work wearing old-school Chuck Taylor's, Tap-Out Shirts ( A famous Mix Martial Arts company back in the year 2006, now owned by UFC Inc.) faded Levis Jeans, a Long Sleeve Shirt by GAP, and baseball cap with a Google logo on it. Google was the leading and famous Search Engine back in the days of the Internet and silicon-powered microprocessors.

What even makes me even more proud on that day is he chose the gift me myself would choose. He chose a top-of-the-line Quantum-Powered Quad Core Laptop by Intel, developed by Apple. It is one of the slimmest and lightest laptop released this year. 80% of the body, including the keyboard is made of combined graphite, aluminum and composite materials used by NASA. making it super light yet virtually indestructible because of the Nanotechnology used to developed it. The material used in the body has the native characteristic of repelling materials that comes close to it, its like a mini-magnet but with a South Pole. It Is even rumored that the technology was derived from the nearby civilization discovered in the outskirts of Venus. But Intel and Apple refuses to give comment about this, since only the US Military has access to such technology, a thing frowned upon by the Neo United Nations.

My son gave me a full smile after I flashed my credit card in front of the automated cashier. The price was hefty, but it hella' worth it in my opinion. When I was at my son's age, I was using a laptop powered by silicon and transistors on their microprocessors. Silicon-based Microprocessors during those times only has two states, either a 1 or a 0, called the Binary System. It will take years to crack a 1024K-bit encrypted message using the laptops I used to use during those days. Now, even the cheapest Quantum-Powered Processor Netbooks can crack a 1024K-bit encrypted message in minutes.

I think not only my son will enjoy this new toy we are taking home, I am thinking of installing SETI@Home on it, then connect it to my 100-Gigabit Wireless Network at home to help my main computer's processor and resources in reaching signals far beyond Venus. Who knows, my son might be the next Galaxy Civilization discoverer, and not some UC Berkeley and MIT alumni. I am getting old, the year 2030 has been good to me and my finally. I am looking forward to visiting our retirement home back in our homeland, Neo Manila. But that will be another blog entry.

Cheers and reach for the stars!
Ron

(P.S. Although a fictional story, the future technology depicted here is a possibility. This story focuses on the future of Nanotechnology and Quantum Physics. It is getting more exciting every day as scientists and experts around the globe continue to push the limits of our current technology and discover new ones in the process.)

Wednesday, April 29, 2009

Learning Objective-C and Xcode

Hmmm, looks like its going to be a while before I update this blog with a security-related post. I am currently studying the Objective-C language and Xcode on my Mac. Although I have a new book here entitled "The Mac Hacker's Handbook" lying around, I have not yet touched a single page of it, maybe next month.

My ultimate goal in learning Objective-C is to create my own App for the iPhone and iPod environment. Apps are selling like pancakes on Apple's website, even the US Military is using their own custom App. They have iPod Touch's attached to their M4's. I'm not kidding. This makes their M4 assault rifles the most advance rifle in the planet. Imagine an App that automatically calculates the distance or tracks a moving target, an App that acts as a night vision, and even an App that will automatically fire the rifle, like an electronic triggering device, even remotely. Wow.

This is going to be fun, the learning curve is easier than I expected. Who knows, along the way I might stumble into an exploit. I am just hoping it will not be my App that I am working on, lol.
Sometimes I have to tell myself numerous times that I am not born a coder, I find it hard to digest even the most simple Regular Expressions, while I find it easy as pie configuring and troubleshooting multi-layered Cisco ACLs, lol.


Later guys.
Ron2

Wednesday, April 1, 2009

SIP is taking over

Aside from computers?

SIP has already infiltrated the following mainstream gadgets opening a lot of promises:

1.  Apple iPhone and iPod Touch
2. Nintendo DS
3. Sony PSP
4. ARM-processor handheld computers
5.  And many more soon.

Time to pick-up a SIP book and start developing your apps guys, its the signaling protocol of the future.


Friday, March 13, 2009

The Road to VoIP-GuruNess starts with the CompTIA Convergence+ Certification

I strongly recommend taking (and passing) CompTIA's Convergence+ Certification offering. Fellow VoIP enthusiasts, researchers, technical support people, technical account managers and VoIP Guru-wannabes (like me) should aim for this certification.

I just passed this exam last month (February), and to all seasoned Traditional Telephony and IP Telephony guys and gals out there, the exam is no joke. You need to review and prepare for it still regardless how l337 you are in Cisco. I was under the impression that I will easily crack this exam since I have 4 years of advantage working for a VoIP/SaaS vendor, but It was the other way around. The exam cracked me up. There were tons of questions on the exam on techniques and protocols that I have never heard of (or studied!), lol!

In order to pass this exam, here are my Top 3 recommendations:

1. Master the fundamentals of Traditional Telephony
2. Master the fundamental of Data Networking
3. Do not rely on the official CompTIA Convergence+ Materials alone!

Below are the books and on-line resources that helped me pass the exam. If you can read all this books before you take the exam, I strongly believe you have at least more than 70% chance of nailing it. Please nail it once, $200 plus for the examination fee doesn't come easy nowadays.

Books:

1. CompTIA Convergence+ Certification, 2nd Edition + CertBlaster, Student Manual (Official Student Manual from CompTIA)
2. CompTIA Convergence+ Certification Study Guide (Certification Study Guides) by Tom Carpenter (Hardcover - Jan 7, 2009)
3.
VoIP Deployment For Dummies (For Dummies (Computer/Tech)) by Stephen P. Olejniczak (Paperback - Nov 17, 2008)
4.
Internet Multimedia Communications Using SIP: A Modern Approach Including Java® Practice (The Morgan Kaufmann Series in Networking) by Rogelio Martinez Perea (Hardcover - Jan 15, 2008)

On-line resources:

1. http://www.ietf.org/
2. http://www.voip-info.org/wiki-SIP
3. http://voiptroubleshooter.com/
4. http://www.nanpa.com/

There are tons of on-line/web resources out there!

Also, please be reminded that this certification is not VoIP-centric, hence the name Convergence. It will challenge your knowledge in deploying, managing, and troubleshooting converged networks, computer networks with both data and voice traffic running on it.

Remember, to be able to pass this exam, you need to master the fundamentals for all subject areas AND be updated on the current technology and practice. In my case, I allocated at least 2 months of studying and reviewing, reading all those books I identified on top from cover to cover, and making it a habit to visit those on-line/web resources I identified to keep myself updated on the industry of converged networks.

Feel free to ask for questions, I am already working on getting my second certification from CompTIA, Security+. I want to focus on the field of securing IP Communication.

For more information regarding CompTIA's Convergence+ Certication exam, please point your browser to their website:
http://certification.comptia.org/convergence/

Good luck and enjoy the challenge, I did!
Ron

A playground for network security enthusiasts, innovators and early adoptors


Welcome to my blog, this is me thinking out loud about Voice over IP security (VoIP), managing and optimizing converged networks, Metasploit Framework, Cloud Computing, general security and privacy concerns, grappling adventures, and tuning my MKIV VW Jetta.

All inputs, feedbacks and violent reactions are welcome.

Packet Boy Perseus
Helping spread a positive image why we hack things.

About Me

I am an InfoSec Innovator, a Blue Ocean Seafarer and a Paul Graham Pupil.