{"id":892,"date":"2024-08-21T09:47:32","date_gmt":"2024-08-21T17:47:32","guid":{"rendered":"https:\/\/unmitigatedrisk.com\/?p=892"},"modified":"2024-08-21T13:40:58","modified_gmt":"2024-08-21T21:40:58","slug":"when-words-mislead-cybersecuritys-terminology-problem","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=892","title":{"rendered":"When Words Mislead: Cybersecurity\u2019s Terminology Problem"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">At Black Hat this year, I did my usual walk around the vendor floor. I talked to lots of companies about their products. One thing that stood out to me is vendors either by accident or on purpose are redefining terms in a way that does harm. One vendor in particular was calling \u201cbearer tokens\u201d \u201cattestations\u201d in both their marketing and product documentation. Let\u2019s use this as an example and break down why this matters.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What\u2019s an attestation?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">An attestation is when someone says something is true and puts their reputation behind that statement. It\u2019s like when your friend vouches for you at a new job. A good technology example is a TPM attestation. The TPM in your computer can prove certain things about how your machine started up. When we trust the chip\u2019s design and the company that made it, we can believe what it tells us.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What\u2019s a claim?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A claim is just something someone says. It might be true, but there\u2019s no proof. If I tell you my name is Ryan Hurst, that\u2019s a claim. I haven\u2019t shown you my ID or anything. Claims can also be about other people or things. If I say Cloudflare is safe to use, that\u2019s just my opinion unless I back it up with something.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What\u2019s a bearer token?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A bearer token is like a temporary password. It\u2019s a secret that proves who you are to a service. Anyone who has the token can pretend to be you. We use them because they\u2019re necessary, but we try to limit their use in modern systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You usually get a bearer token by trading in something more permanent, like an API key, which is essentially a long-lived password. It\u2019s like swapping a house key for a hotel room key. The hotel key only works for a short time, but anyone who finds it can get into your room.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why does any of this matter?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When companies use the wrong terms to explain what they do it can lead people to make bad security choices. For example, If you hear a vendor say their system relies on bearer tokens and then you do a search on the term, you\u2019ll find experts talking about their risks and how to manage them. But if you search for attestations, you\u2019ll find different info about how they help prove things are reliable, trustworthy or factual.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a company selling security products tells you it does one thing, but it does another, it\u2019s a bad sign. They either have some technical debt buried in the design that may have a negative impact, don\u2019t know what they\u2019re talking about, or they\u2019re trying to confuse you. Either way, you might want to look at other options.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, when you\u2019re buying security products for your company, pay attention to how vendors use words. If they\u2019re changing the meaning of important terms, be careful. It could mean you\u2019re not getting what you think you are.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>At Black Hat this year, I did my usual walk around the vendor floor. I talked to lots of companies about their products. One thing that stood out to me is vendors either by accident or on purpose are redefining terms in a way that does harm. One vendor in particular was calling \u201cbearer tokens\u201d [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,201,4],"tags":[168],"class_list":["post-892","post","type-post","status-publish","format-standard","hentry","category-security","category-technology","category-thoughts","tag-security"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/892","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=892"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/892\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=892"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}