<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: brett]]></title>
    <link>http://securityratty.com/tag/brett</link>
    <description></description>
    <pubDate>Sun, 24 Feb 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Lords debate Personal Internet Security]]></title>
      <link>http://securityratty.com/article/e68b4f70acd9eac9c340126b268863eb</link>
      <guid>http://securityratty.com/article/e68b4f70acd9eac9c340126b268863eb</guid>
      <description><![CDATA[Last Friday the House of Lords debated their Science and Technology Committees report on Personal Internet Security (from Summer 2007) and because the Governments response was so weak the additional...]]></description>
      <content:encoded><![CDATA[<p>Last Friday the House of Lords <a href="http://www.publications.parliament.uk/pa/ld200708/ldhansrd/text/81010-0006.htm#08101048000005">debated</a> their Science and Technology Committee&#8217;s report on <a href="http://www.publications.parliament.uk/pa/ld200607/ldselect/ldsctech/165/165i.pdf">Personal Internet Security</a> (from Summer 2007) and &#8212; because the Government&#8217;s response was so weak &#8212; the <a href="http://www.publications.parliament.uk/pa/ld200708/ldselect/ldsctech/131/131.pdf">additional follow-up report</a> that was published in Spring 2008. Since I had acted as the specialist adviser to the Committee, I went down to Westminster to sit &#8220;<a href="http://www.parliament.uk/about/glossary.cfm?ref=belowth_5748">below the bar</a>&#8220;, in one of the best seats in the House, and observe.</p>
<p><a href="http://www.theyworkforyou.com/peer/lord_broers">Lord Broers</a>, the Committee Chairman during the first inquiry, kicked things off, followed by various Lords who had sat on the Committee (and two others who hadn&#8217;t) then the opposition lead, Viscount Bridgeman, who put his party&#8217;s point of view (of which more in another article). Lord Brett (recently elevated to a <a href="http://en.wikipedia.org/wiki/Lord-in-Waiting">Lord in Waiting</a> &#8212; ie a whip), then replied to the debate and finally Lord Broers summarised and formally moved the &#8220;take note&#8221; motion which, as is custom and practice, the Lords then consented to <em>nem con</em>.</p>
<p>The Government speech in such a debate is partially pre-written, and should then consist of a series of responses to the various issues raised and answers to the questions put in the previous speeches. The Minister himself doesn&#8217;t write any of this, that&#8217;s done by civil servants from his department, sitting in a special &#8220;box&#8221; at the end of the chamber behind him.</p>
<p>However, since the previous speeches were so strongly critical of the Government&#8217;s position, and so many questions were put as to what was to be done next, I was able to see from my excellent vantage point (as TV viewers would never be able to) the almost constant flow of hastily scribbled notes from the box to the Minister &#8212; including one note that went to Lord Broers, due to an addressing error by the scribblers!</p>
<p>The result of this barrage of material was that Lord Brett ended up with so many bits of paper that he completely gave up trying to juggle them, read out just one, and promised to write to everyone concerned with the rest of the ripostes.</p>
<p>Of course it didn&#8217;t help that he&#8217;d only been in the job for five days and this was his first day at the dispatch box. But the number of issues he had to address would almost certainly have flummoxed a five-year veteran as well.</p>
<p>Amusing though this might be to watch, this does not bode well for the Government getting to grips with the issues raised in the reports. In technical areas such as &#8220;Personal Internet Security&#8221;, policy is almost entirely driven by the civil servants and not by the politicians.</p>
<p>So it is particularly disappointing that the pre-written parts of the Minister&#8217;s speech &#8212; the issues that the civil servants expected to come up and which they felt positive about addressing &#8212; were only a small proportion of the issues that were actually addressed in the debate.</p>
<p>It still seems as if the <a href="http://i.abcnews.com/2020/story?id=3131332&#038;page=1">penny hasn&#8217;t dropped</a> in Whitehall <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 18:57:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/personal internet security">personal internet security</category>
      <category domain="http://securityratty.com/tag/lord">lord</category>
      <category domain="http://securityratty.com/tag/lord broers">lord broers</category>
      <category domain="http://securityratty.com/tag/lords">lords</category>
      <category domain="http://securityratty.com/tag/civil servants">civil servants</category>
      <category domain="http://securityratty.com/tag/box">box</category>
      <category domain="http://securityratty.com/tag/lord brett">lord brett</category>
      <category domain="http://securityratty.com/tag/dispatch box">dispatch box</category>
      <category domain="http://securityratty.com/tag/issues">issues</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/13/lords-debate-personal-internet-security/">Lords debate Personal Internet Security</source>
    </item>
    <item>
      <title><![CDATA[McAfee's Hacker Safe nominated for a Pwnie]]></title>
      <link>http://securityratty.com/article/19cd58f1b0361803b4a478f04fdc8485</link>
      <guid>http://securityratty.com/article/19cd58f1b0361803b4a478f04fdc8485</guid>
      <description><![CDATA[Mondays don't usually include such glorious highlights but I'll gladly pass on this exception. The Pwnie Awards 2008 nominations are out, and under Lamest Vendor Response we find McAfee's Hacker Safe,...]]></description>
      <content:encoded><![CDATA[Mondays don't usually include such glorious highlights but I'll gladly pass on this exception. The <a href="http://pwnie-awards.org/2008/index.html" target="_blank">Pwnie Awards 2008</a> nominations are out, and under <a href="http://pwnie-awards.org/2008/awards.html#lamestvendor" target="_blank">Lamest Vendor Response</a> we find McAfee's Hacker Safe, specifically Joesph Pierini's response to the findings <a href="http://www.xssed.com/news/55/ScanAlerts_Hacker_Safe_badge_not_so_safe_and_PCI_compliant/" target="_blank">XSSed.com</a> and I gave to Thomas Claburn for publication in <a href="http://www.informationweek.com/news/security/cybercrime/showArticle.jhtml;jsessionid=JN2ZP21JSGB4WQSNDLOSKH0CJUNN2JVN?articleID=205900444&_requestid=339479" target="_blank">Information Week</a> this past January. <br />Joseph Pierini, director of enterprise services for the "Hacker Safe" program, stepped in it when he said that XSS vulnerabilities can't be used to hack a server:<br /><span style="font-style:italic;">Cross-site scripting can't be used to hack a server. You may be able to do other things with it. You may be able to do things that affect the end-user or the client. But the customer data protected with the server, in the database, isn't going to be compromised by a cross-site scripting attack, not directly.</span><br />As you can imagine, this one gets my vote.<br />Winners will be announced at the BlackHat USA reception at Caesar's Palace, Las Vegas on Wednesday, August 6th, 2008.<br />Should you wish further reading on the McAfee Secure / Hacker Safe fiasco, you need only utilize this <a href="http://www.google.com/search?hl=en&q=site%3Aholisticinfosec.blogspot.com+%22mcafee%22+%22hacker+safe%22&btnG=Google+Search" target="_blank">query</a> or refer to all of Nate's <a href="http://www.google.com/search?hl=en&q=site%3Ablogs.zdnet.com%2Fsecurity+%22mcafee%22+%22hacker+safe%22&btnG=Google+Search" target="_blank">coverage</a> on <a href="http://blogs.zdnet.com/security/" target="_blank">Zero Day</a>. <br />I must admit, I'm curious who McAfee will have at Black Hat to receive this prestigious award should they win. I'm torn between suggesting <a href="http://www.0x000000.com/?i=574" target="_blank">Brett Oliphant</a> or Pierini himself. ;-)<br />Cheers.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/07/mcafees-hacker-safe-nominated-for-pwnie.html&title=McAfee's%20Hacker%20Safe%20nominated%20for%20a%20Pwnie " title="McAfee's Hacker Safe nominated for a Pwnie ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/07/mcafees-hacker-safe-nominated-for-pwnie.html" title="McAfee's Hacker Safe nominated for a Pwnie ">digg</a>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 07:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hacker safe">hacker safe</category>
      <category domain="http://securityratty.com/tag/mcafee">mcafee</category>
      <category domain="http://securityratty.com/tag/hacker safe fiasco">hacker safe fiasco</category>
      <category domain="http://securityratty.com/tag/pierini">pierini</category>
      <category domain="http://securityratty.com/tag/joseph pierini">joseph pierini</category>
      <category domain="http://securityratty.com/tag/mcafee secure">mcafee secure</category>
      <category domain="http://securityratty.com/tag/vendor response">vendor response</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/joesph pierini">joesph pierini</category>
      <source url="http://holisticinfosec.blogspot.com/2008/07/mcafees-hacker-safe-nominated-for-pwnie.html">McAfee's Hacker Safe nominated for a Pwnie</source>
    </item>
    <item>
      <title><![CDATA[Digital Piracy]]></title>
      <link>http://securityratty.com/article/3a5ccc04272f7ea2619360967ad1c727</link>
      <guid>http://securityratty.com/article/3a5ccc04272f7ea2619360967ad1c727</guid>
      <description><![CDATA[This paper, written by Brett Pladna will discuss piracy and copyright infringement. Since the boom of the Internet it is possible to download all types of...]]></description>
      <content:encoded><![CDATA[This paper, written by Brett Pladna will discuss piracy and copyright infringement. Since the boom of the Internet it is possible to download all types of files.]]></content:encoded>
      <pubDate>Thu, 22 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/copyright infringement">copyright infringement</category>
      <category domain="http://securityratty.com/tag/brett pladna">brett pladna</category>
      <category domain="http://securityratty.com/tag/discuss piracy">discuss piracy</category>
      <category domain="http://securityratty.com/tag/types">types</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/boom">boom</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/download">download</category>
      <source url="http://www.infosecwriters.com/texts.php?op=display&amp;id=625">Digital Piracy</source>
    </item>
    <item>
      <title><![CDATA[McAfee Partner isn't McAfee Secure either]]></title>
      <link>http://securityratty.com/article/51b396ff6d9541ffa1a5939d9e429101</link>
      <guid>http://securityratty.com/article/51b396ff6d9541ffa1a5939d9e429101</guid>
      <description><![CDATA[Winferno.com is an authorized distributor of McAfee Software. OK
They use Verisign 128-bit SSL to secure your transaction. Can't take issue with that
All good so far...but wait
Shouldn't a McAfee...]]></description>
      <content:encoded><![CDATA[<a href="http://www.winferno.com/">Winferno.com</a> is an authorized distributor of McAfee Software. OK.<br />They use Verisign 128-bit SSL to secure your transaction. Can't take issue with that.<br />All good so far...but wait!<br />Shouldn't a McAfee Partner be McAfee Secure?<br />Apparently not, and being one wouldn't have cured the XSS blues anyway.<br />Next in our video series, a supposedly secure shopping cart that is far from.<br /><br />Here's an <a href="https://secure.winferno.com/s/vstore_precheckout/102/precheckout_rpcsz2008.asp?source=102_RPCSZPRECHECKOUT_0606_bottom_sie_05?CID=%22%3E%3Ciframe%20src%3Dhttp%3A%2F%2Fxssed%2Ecom%3E">IFRAME</a>.<br />Here's the <a href="https://secure.winferno.com/s/vstore_precheckout/102/precheckout_rpcsz2008.asp?source=102_RPCSZPRECHECKOUT_0606_bottom_sie_05?CID=%22%3E%3CSCRIPT%3Ealert%28document%2Ecookie%29%3C%2FSCRIPT%3E">cookie</a>.<br />As well we know, coughing up the cookie counts as a really bad thing for any shopping cart, let alone an SSL protected shopping cart that happens to be a McAfee Partner and authorized distributor of McAfee Software. But lest we forget, McAfee doesn't count XSS as concerning.<br />Here's the <a href="http://holisticinfosec.org/video/mcafee/winferno_mcafee.html">video</a>.<br />Huge props to <a href="http://www.0x000000.com/">Ronald van den Heetkamp</a> for starting this whole debate years ago, and for exposing <a href="http://www.0x000000.com/?i=574">Brett Oliphant</a> for the fraud that he is.<br />Fraud is the key word here. Hacker Safe <span style="font-style:italic;">was</span> fraudulent, McAfee Secure <span style="font-style:italic;">is</span> fraudulent, and buying from Winferno puts consumers at risk for being defrauded, not only due to horrendous site code, but perhaps bad business <a href="http://winferno.pissedconsumer.com/">practices</a> as well.<br />I won't even ask if McAfee has any standards, we already know the answer.<br />Their standards have left the building.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/05/mcafee-partner-isnt-mcafee-secure.html&title=McAfee%20Partner%20isn't%20McAfee%20Secure%20either " title="McAfee Partner isn't McAfee Secure either del.icio.us">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/05/mcafee-partner-isnt-mcafee-secure.html" title="McAfee Partner isn't McAfee Secure either ">digg</a>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 17:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mcafee">mcafee</category>
      <category domain="http://securityratty.com/tag/mcafee secure">mcafee secure</category>
      <category domain="http://securityratty.com/tag/mcafee partner">mcafee partner</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/mcafee software">mcafee software</category>
      <category domain="http://securityratty.com/tag/verisign 128-bit ssl">verisign 128-bit ssl</category>
      <category domain="http://securityratty.com/tag/bad">bad</category>
      <category domain="http://securityratty.com/tag/bad business practices">bad business practices</category>
      <category domain="http://securityratty.com/tag/ssl">ssl</category>
      <source url="http://holisticinfosec.blogspot.com/2008/05/mcafee-partner-isnt-mcafee-secure.html">McAfee Partner isn't McAfee Secure either</source>
    </item>
    <item>
      <title><![CDATA[The Lack of Attention in the Prevention of Cyber Crime and How to Improve It]]></title>
      <link>http://securityratty.com/article/13b8ac364e7f00e5a2859c92e0f081e4</link>
      <guid>http://securityratty.com/article/13b8ac364e7f00e5a2859c92e0f081e4</guid>
      <description><![CDATA[This paper, written by Brett Pladna, discusses the issues of cyber crime and what is being done to prevent...]]></description>
      <content:encoded><![CDATA[This paper, written by Brett Pladna, discusses the issues of cyber crime and what is being done to prevent it]]></content:encoded>
      <pubDate>Tue, 13 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cyber crime">cyber crime</category>
      <category domain="http://securityratty.com/tag/brett pladna">brett pladna</category>
      <category domain="http://securityratty.com/tag/issues">issues</category>
      <category domain="http://securityratty.com/tag/discusses">discusses</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <source url="http://www.infosecwriters.com/texts.php?op=display&amp;id=623">The Lack of Attention in the Prevention of Cyber Crime and How to Improve It</source>
    </item>
    <item>
      <title><![CDATA[Computer Forensics Procedures, Tools, and Digital Evidence Bags: What They Are and Who Should Use Them]]></title>
      <link>http://securityratty.com/article/39660298249d23a12f693b2118e793fa</link>
      <guid>http://securityratty.com/article/39660298249d23a12f693b2118e793fa</guid>
      <description><![CDATA[This paper, written by Brett Pladna, will try to demonstrate the importance of computer forensics by describing procedures, tools and differences in the use for individuals/small organizations vs....]]></description>
      <content:encoded><![CDATA[This paper, written by Brett Pladna, will try to demonstrate the importance of computer forensics by describing procedures, tools and differences in the use for individuals/small organizations vs. large organizations.]]></content:encoded>
      <pubDate>Wed, 07 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer forensics">computer forensics</category>
      <category domain="http://securityratty.com/tag/procedures">procedures</category>
      <category domain="http://securityratty.com/tag/brett pladna">brett pladna</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/importance">importance</category>
      <category domain="http://securityratty.com/tag/differences">differences</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <source url="http://www.infosecwriters.com/texts.php?op=display&amp;id=620">Computer Forensics Procedures, Tools, and Digital Evidence Bags: What They Are and Who Should Use Them</source>
    </item>
    <item>
      <title><![CDATA[NAC is a battlefield - Only the strong survive]]></title>
      <link>http://securityratty.com/article/c960dc03b52138212a94130ce5290bca</link>
      <guid>http://securityratty.com/article/c960dc03b52138212a94130ce5290bca</guid>
      <description><![CDATA[First it was Caymas Systems, then it was Vernier Networks, now Lockdown Networks appears to be exiting the NAC market . Of course the obvious reaction as a competitor is to say good riddance, one less...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>First it was Caymas Systems, then it was Vernier Networks, now Lockdown Networks <a href="http://lockdownnetworks.com/lockdown_networks.php" target="_blank">appears to be exiting the NAC market</a>.&nbsp; Of course the obvious reaction as a competitor is to say good riddance, one less competitor to deal with.&nbsp; But to turn a quote on its ear, I write today not to bury Lockdown Networks, but to praise them. More than the other two NAC companies that have exited the market, I was personally in the loop on Lockdown Networks. I first heard about them when a VC friend of ours asked us about them years ago.&nbsp; This was when we were still planning Safe Access and Lockdown's business plan was vulnerability management. They had not raised money yet and were still in stealth mode. We thought of them as competition for our VAM product, but wanted to see what they would come up with. I stayed abreast watching their progress from afar. Some time later, when I was looking to put together a group of companies to form a coalition to develop an independent NASL script library, knowing that they used Nessus, I reached out to them.</p>

<p>This is when I first met Rob Gilde.&nbsp; Subsequently I also met Brett and most of the rest of the team there. I like Rob, he ran their product team, was knowledgeable and a nice guy in a west coast laid back kind of way.&nbsp; In short time it became apparent&nbsp; to me that Lockdown was looking to move out of the VM business.&nbsp; Rob realized that just scanning and reporting was not going to make it.&nbsp; He had the notion of adding enforcement to his vulnerability scanning. If you failed a vulnerability scan, you should be denied access to the network.&nbsp; My initial reaction was vulnerability scans are done mostly on servers, but Rob wanted to do vulnerability scans on endpoints.&nbsp; That is when I told him about our own product which we were about to release. Rob and the team re-tooled and released their Enforcer product some time later.&nbsp; </p>

<p>I personally always thought that doing SANS TOP 20 scans on endpoints was not where it was at in NAC, but Lockdown raised money from Intel and a bunch of other folks and was making a big splash in the heady, gold rush days of NAC.&nbsp; We ran into them on deals from time to time, especially in many of our major partner/OEM deals.&nbsp; The good news for us, is that just about all of the time, our product was picked over theirs.</p>

<p>Soon rumors were everywhere that Lockdown was on the block.&nbsp; Brett and team were looking to grab 20 or so major customers and quickly flip the company for a big win.&nbsp; Than we began hearing that they were looking for less and less money.&nbsp; Also, their PR began becoming more and more desperate.&nbsp; That is when I began calling them on it in my blogging.&nbsp; Evidently that got their attention.&nbsp; A few Interop shows ago, Rob called me over and said he and especially Brett were really upset I called them out.&nbsp; I apologized and said hey I call them as I see them.&nbsp; At RSA or another show after that Brett walked right by me and tried his best to diss me.&nbsp; People from NY don't get dissed that easy though.&nbsp; I just laughed it off, but it was the last time I spoke to anyone at Lockdown.&nbsp; </p>

<p>Recently we have begun to see a few customers that were choosing our Safe Access product to replace Lockdown's.&nbsp; I thought this was ominous for them, but hey good for us! I truly expected to hear any day of someone picking them up at a decent price. I didn't think it would just implode.&nbsp; In many ways a company shutting down is a death of a thousand dreams.&nbsp; The soaring aspirations of the founders, the individual sugar plum fantasies of the early hires, the VC's thinking this could be the big hit.&nbsp; Perhaps most sad of all, the customers who looked at the market and for whatever reasons decided that Lockdown offered them the best product for providing NAC and solving their problems.&nbsp; Those people made a bet that Lockdown would be there to solve the issues and provide a great solution.&nbsp; They as much as anyone lost that bet.&nbsp; </p>

<p>As they do on Ebay, here is a second chance for Lockdown customers.&nbsp; We will have on our web site a special offer to upgrade you to Safe Access and leverage your investment in Lockdown.&nbsp; Lockdown's misfortune does not have to be yours.&nbsp; We are here to help and are here to stay.&nbsp; So to all of Lockdown's customers, I am sorry you are left in a hard place here, but there is help.</p>

<p>To Brett, Dan Clark and the rest of the Lockdown crew, most especially to Rob Gilde, I offer my sympathies that this did not turn out better for you.&nbsp; You all made a great effort and you made us try harder which resulted in our product being developed faster than it would have otherwise.&nbsp; For that I thank you and wish you all the best of luck in your future endeavors. This song is for you:</p>

<div class="wlWriterSmartContent" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:ac1ba53c-4651-4700-8523-c45cc557ec53" style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"><div id="d5269806-6ca5-47f2-afdd-a496ae1b682a" style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"><div><embed src="http://www.youtube.com/v/j9J9rTZJBmw&amp;hl=en" width="425" height="350" type="application/x-shockwave-flash" wmode="transparent"></embed></div></div></div></div>
]]></content:encoded>
      <pubDate>Tue, 18 Mar 2008 22:48:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lockdown networks appears">lockdown networks appears</category>
      <category domain="http://securityratty.com/tag/lockdown networks">lockdown networks</category>
      <category domain="http://securityratty.com/tag/bury lockdown networks">bury lockdown networks</category>
      <category domain="http://securityratty.com/tag/lockdown">lockdown</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/product team">product team</category>
      <category domain="http://securityratty.com/tag/product">product</category>
      <category domain="http://securityratty.com/tag/vam product">vam product</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/03/nac-is-a-battle.html">NAC is a battlefield - Only the strong survive</source>
    </item>
    <item>
      <title><![CDATA[NAC is a battlefield - Only the strong survive]]></title>
      <link>http://securityratty.com/article/893663b3663f65421ed045d52b851cc5</link>
      <guid>http://securityratty.com/article/893663b3663f65421ed045d52b851cc5</guid>
      <description><![CDATA[First it was Caymas Systems, then it was Vernier Networks, now Lockdown Networks appears to be exiting the NAC market . Of course the obvious reaction as a competitor is to say good riddance, one less...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>First it was Caymas Systems, then it was Vernier Networks, now Lockdown Networks <a href="http://lockdownnetworks.com/lockdown_networks.php" target="_blank">appears to be exiting the NAC market</a>.&nbsp; Of course the obvious reaction as a competitor is to say good riddance, one less competitor to deal with.&nbsp; But to turn a quote on its ear, I write today not to bury Lockdown Networks, but to praise them. More than the other two NAC companies that have exited the market, I was personally in the loop on Lockdown Networks. I first heard about them when a VC friend of ours asked us about them years ago.&nbsp; This was when we were still planning Safe Access and Lockdown's business plan was vulnerability management. They had not raised money yet and were still in stealth mode. We thought of them as competition for our VAM product, but wanted to see what they would come up with. I stayed abreast watching their progress from afar. Some time later, when I was looking to put together a group of companies to form a coalition to develop an independent NASL script library, knowing that they used Nessus, I reached out to them.</p>

<p>This is when I first met Rob Gilde.&nbsp; Subsequently I also met Brett and most of the rest of the team there. I like Rob, he ran their product team, was knowledgeable and a nice guy in a west coast laid back kind of way.&nbsp; In short time it became apparent&nbsp; to me that Lockdown was looking to move out of the VM business.&nbsp; Rob realized that just scanning and reporting was not going to make it.&nbsp; He had the notion of adding enforcement to his vulnerability scanning. If you failed a vulnerability scan, you should be denied access to the network.&nbsp; My initial reaction was vulnerability scans are done mostly on servers, but Rob wanted to do vulnerability scans on endpoints.&nbsp; That is when I told him about our own product which we were about to release. Rob and the team re-tooled and released their Enforcer product some time later.&nbsp; </p>

<p>I personally always thought that doing SANS TOP 20 scans on endpoints was not where it was at in NAC, but Lockdown raised money from Intel and a bunch of other folks and was making a big splash in the heady, gold rush days of NAC.&nbsp; We ran into them on deals from time to time, especially in many of our major partner/OEM deals.&nbsp; The good news for us, is that just about all of the time, our product was picked over theirs.</p>

<p>Soon rumors were everywhere that Lockdown was on the block.&nbsp; Brett and team were looking to grab 20 or so major customers and quickly flip the company for a big win.&nbsp; Than we began hearing that they were looking for less and less money.&nbsp; Also, their PR began becoming more and more desperate.&nbsp; That is when I began calling them on it in my blogging.&nbsp; Evidently that got their attention.&nbsp; A few Interop shows ago, Rob called me over and said he and especially Brett were really upset I called them out.&nbsp; I apologized and said hey I call them as I see them.&nbsp; At RSA or another show after that Brett walked right by me and tried his best to diss me.&nbsp; People from NY don't get dissed that easy though.&nbsp; I just laughed it off, but it was the last time I spoke to anyone at Lockdown.&nbsp; </p>

<p>Recently we have begun to see a few customers that were choosing our Safe Access product to replace Lockdown's.&nbsp; I thought this was ominous for them, but hey good for us! I truly expected to hear any day of someone picking them up at a decent price. I didn't think it would just implode.&nbsp; In many ways a company shutting down is a death of a thousand dreams.&nbsp; The soaring aspirations of the founders, the individual sugar plum fantasies of the early hires, the VC's thinking this could be the big hit.&nbsp; Perhaps most sad of all, the customers who looked at the market and for whatever reasons decided that Lockdown offered them the best product for providing NAC and solving their problems.&nbsp; Those people made a bet that Lockdown would be there to solve the issues and provide a great solution.&nbsp; They as much as anyone lost that bet.&nbsp; </p>

<p>As they do on Ebay, here is a second chance for Lockdown customers.&nbsp; We will have on our web site a special offer to upgrade you to Safe Access and leverage your investment in Lockdown.&nbsp; Lockdown's misfortune does not have to be yours.&nbsp; We are here to help and are here to stay.&nbsp; So to all of Lockdown's customers, I am sorry you are left in a hard place here, but there is help.</p>

<p>To Brett, Dan Clark and the rest of the Lockdown crew, most especially to Rob Gilde, I offer my sympathies that this did not turn out better for you.&nbsp; You all made a great effort and you made us try harder which resulted in our product being developing faster than it would have otherwise.&nbsp; For that I thank you and wish you all the best of luck in your future endeavors. This song is for you:</p>

<div class="wlWriterSmartContent" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:ac1ba53c-4651-4700-8523-c45cc557ec53" style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"><div id="d5269806-6ca5-47f2-afdd-a496ae1b682a" style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"><div><embed src="http://www.youtube.com/v/j9J9rTZJBmw&amp;hl=en" width="425" height="350" type="application/x-shockwave-flash" wmode="transparent"></embed></div></div></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=TILm20"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=TILm20" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=HKAJDSF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=HKAJDSF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TTKjSCF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TTKjSCF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=VGlkLDF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=VGlkLDF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=R7tpBuF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=R7tpBuF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=NNemlbf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=NNemlbf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BAmoWbf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BAmoWbf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/254086539" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Mar 2008 21:48:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lockdown networks appears">lockdown networks appears</category>
      <category domain="http://securityratty.com/tag/lockdown networks">lockdown networks</category>
      <category domain="http://securityratty.com/tag/bury lockdown networks">bury lockdown networks</category>
      <category domain="http://securityratty.com/tag/lockdown">lockdown</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/product team">product team</category>
      <category domain="http://securityratty.com/tag/product">product</category>
      <category domain="http://securityratty.com/tag/vam product">vam product</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/254086539/nac-is-a-battle.html">NAC is a battlefield - Only the strong survive</source>
    </item>
    <item>
      <title><![CDATA[Have the wheels fallen off at Lockdown]]></title>
      <link>http://securityratty.com/article/800a010ab706c62015cebdfd30ebf27b</link>
      <guid>http://securityratty.com/article/800a010ab706c62015cebdfd30ebf27b</guid>
      <description><![CDATA[Lots of buzz that Brett and the rest of the exec team have left Lockdown and they are closing up shop. I have already gotten one resume
I guess all those press release about record quarters where not...]]></description>
      <content:encoded><![CDATA[<p>Lots of buzz that Brett and the rest of the exec team have left Lockdown and they are closing up shop.  I have already gotten one resume.  </p>

<p>I guess all those press release about record quarters where not enough.  I will blog more about this when I land later tonight.</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=DCZTWv"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=DCZTWv" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=pLn3k1F"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=pLn3k1F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=caly3DF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=caly3DF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=C4EuMBF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=C4EuMBF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qA7FNlF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qA7FNlF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=yZxbybf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=yZxbybf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=aTOEnrf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=aTOEnrf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/253852602" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Mar 2008 12:30:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/press release">press release</category>
      <category domain="http://securityratty.com/tag/exec team">exec team</category>
      <category domain="http://securityratty.com/tag/lockdown">lockdown</category>
      <category domain="http://securityratty.com/tag/record quarters">record quarters</category>
      <category domain="http://securityratty.com/tag/resume">resume</category>
      <category domain="http://securityratty.com/tag/rest">rest</category>
      <category domain="http://securityratty.com/tag/brett">brett</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/tonight">tonight</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/253852602/have-the-wheels.html">Have the wheels fallen off at Lockdown</source>
    </item>
    <item>
      <title><![CDATA[Cyber Terrorism and Information Security]]></title>
      <link>http://securityratty.com/article/40356fe8265e63c1e47fdfa4aa9251bb</link>
      <guid>http://securityratty.com/article/40356fe8265e63c1e47fdfa4aa9251bb</guid>
      <description><![CDATA[Brett Pladna writes this research paper analyzing and outlining CyberTerrorism and the role Information Security has with...]]></description>
      <content:encoded><![CDATA[Brett Pladna writes this research paper analyzing and outlining CyberTerrorism and the role Information Security has with it.]]></content:encoded>
      <pubDate>Sun, 24 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/brett pladna writes">brett pladna writes</category>
      <category domain="http://securityratty.com/tag/role information security">role information security</category>
      <category domain="http://securityratty.com/tag/research paper">research paper</category>
      <category domain="http://securityratty.com/tag/cyberterrorism">cyberterrorism</category>
      <source url="http://www.infosecwriters.com/texts.php?op=display&amp;id=611">Cyber Terrorism and Information Security</source>
    </item>
  </channel>
</rss>
