<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: centric]]></title>
    <link>http://securityratty.com/tag/centric</link>
    <description></description>
    <pubDate>Sat, 20 Sep 2008 18:36:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Talking Engagement]]></title>
      <link>http://securityratty.com/article/b1376fcaf83b962af2522fd39ae76937</link>
      <guid>http://securityratty.com/article/b1376fcaf83b962af2522fd39ae76937</guid>
      <description><![CDATA[So, it finally happened. I was invited to talk at an Information Security Conference and I went and talked

My talk was about the risks of information leaving the organisation but I decided to add in...]]></description>
      <content:encoded><![CDATA[So, it finally happened. I was invited to talk at an Information Security Conference and I went and talked.<br /><br />My talk was about the risks of information leaving the organisation but I decided to add in the risks of information <span style="font-style: italic;">not</span> leaving the organisation.<br /><br />This may sound counter productive but in these though times your IT department should really be looking at using services such as GMail, your Marketing department should be looking at using Facebook, Twitter, Blogs etc. Your HR department should be looking through LinkedIn for new staff.<br /><br />If your Security Department is too tough on information leaving the organisation then you are missing out on opportunities. Of course, if you are too lax then information will make its way out and that can't be good for the company either.<br /><br />Information Classification is key. As is awareness.<br /><br />My speech was very well received, achieving over 8/10 for the different areas and I have been invited back to speak again.<br /><br />I must admit that my speech was aimed at business decision makers and not technical people and yet the people who showed up were more technical people. There are very few companies in South Africa (with my employer being a noted exception) that treat Information Security as a business issue and not (only) a technical issue.<br /><br />I'm not really one to tooth my own horn but I wrote this blog entry to thank a number of people who made my speech possible.<br /><br />Firstly thank you to the two blogs that I feel are on the forefront of Information-centric Security - <a href="http://securosis.com/">Securosis</a> and <a href="http://rationalsecurity.typepad.com/blog/">Rational Survivability</a>. I used some material from both sites and some that was sent to me by Richard Mogull from Securosis.<br /><br />I used some speaking tips that I got from <a href="http://www.presentationzen.com/presentationzen/">Presentation Zen</a> so I didn't put everyone to sleep (even though my speech was at the danger time of 3:30pm when everyone is tired and wants to go home) and I used some (free!) graphics from <a href="http://www.sxc.hu/">Stock Exchange</a>.<br /><br />When I was preparing for the speech, I revisited some of my old Blog posts which I think I need to repost as I have some more ideas about them.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/452816173" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 06:46:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/treat information security">treat information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information classification">information classification</category>
      <category domain="http://securityratty.com/tag/security department">security department</category>
      <category domain="http://securityratty.com/tag/information security conference">information security conference</category>
      <category domain="http://securityratty.com/tag/technical people">technical people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/452816173/talking-engagement.html">Talking Engagement</source>
    </item>
    <item>
      <title><![CDATA[Innovation In Security--Lessons from TelePresence and Cloud]]></title>
      <link>http://securityratty.com/article/301883cbb5e30fc8992da3c13f88e3b7</link>
      <guid>http://securityratty.com/article/301883cbb5e30fc8992da3c13f88e3b7</guid>
      <description><![CDATA[Innovation in Security is a theme that we at EMC and RSA strongly believe in it was central to my keynote speech at the NCA Security and Technology Conference in Seattle on the 29th of October. Yet,...]]></description>
      <content:encoded><![CDATA[<p>Innovation in Security is a theme that we at EMC and RSA  strongly believe in&mdash; it was central to my <a href="http://www.ncanet.com/SatchitDokras.php">keynote</a> speech at the NCA  Security and Technology Conference in Seattle on the 29th of  October. Yet, as the day progressed, I could not help but think of how  extensively we need to innovate in our security deployments, to enable vibrant  new information exchange capabilities, and to sustain the rapid changes in our  information-centric lifestyles.<br />
  <br />
    <strong>And are we being hit with Change!</strong><br />
  Carlos Dominguez, the SVP at Cisco, spoke to <B>the profound  impact of Web 2.0 and TelePresence [TP] technologies on our business and social  lifestyles...</b>]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security deployments">security deployments</category>
      <category domain="http://securityratty.com/tag/social lifestyles">social lifestyles</category>
      <category domain="http://securityratty.com/tag/nca security">nca security</category>
      <category domain="http://securityratty.com/tag/information exchange capabilities">information exchange capabilities</category>
      <category domain="http://securityratty.com/tag/lifestyles">lifestyles</category>
      <category domain="http://securityratty.com/tag/rsa strongly">rsa strongly</category>
      <category domain="http://securityratty.com/tag/telepresence">telepresence</category>
      <category domain="http://securityratty.com/tag/innovation">innovation</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1386">Innovation In Security--Lessons from TelePresence and Cloud</source>
    </item>
    <item>
      <title><![CDATA[When Markets Collide]]></title>
      <link>http://securityratty.com/article/b33dd419bf17d2010a5e8c1da7814637</link>
      <guid>http://securityratty.com/article/b33dd419bf17d2010a5e8c1da7814637</guid>
      <description><![CDATA[One of my favorite Motley Fool analysts is Bill Mann, yesterday he wrote an article on China that re-set a number of the investing thesis themes in the current global situation


Things are so bad in...]]></description>
      <content:encoded><![CDATA[<p><span style="font-size: 13px; ">One of my favorite Motley Fool analysts is Bill Mann, yesterday he wrote an </span><a href="http://www.fool.com/investing/international/2008/11/07/why-i-believe-in-the-chinese-miracle.aspx"><span style="font-size: 13px; ">article</span></a><span style="font-size: 13px; "> on China that re-set a number of the investing thesis themes in the current global situation:</span></p><div><span style="font-size: 13px; "><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #222222; font-size: 14px; line-height: 20px; "><span style="color: #222222; line-height: 20px; font-size: 13px; ">Things are so bad in China that its gross domestic product growth rate may fall from double digits to the dowdy level of 8%. Eight percent, by the way, is a level at which the United States is unlikely&#0160;</span><em style="background-repeat: no-repeat; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 100%; font-weight: inherit; font-style: italic; "><span style="background-repeat: no-repeat; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-weight: inherit; font-style: italic; font-size: 13px; ">to ever grow again</span></em><span style="color: #222222; line-height: 20px; font-size: 13px; ">. It can&#39;t. Our economy is simply fully developed. Thus the sobriquet &quot;developed economy.&quot; I know, not exactly catchy.</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #222222; line-height: 20px; font-size: 13px; ">..</span></p></blockquote><p><span style="font-size: 13px; "><br /></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #222222; font-size: 14px; line-height: 20px; "><span style="font-size: 11px; line-height: 10px; "><p style="background-repeat: no-repeat; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-left: 0px; font-style: inherit; font-weight: inherit; font-size: 1.3em; margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; line-height: 20px; padding-bottom: 5px; "><span style="background-repeat: no-repeat; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-left: 0px; font-style: inherit; font-weight: inherit; margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; line-height: 20px; padding-bottom: 5px; font-size: 13px; ">All of the headlines show China sitting at a crossroads. But the reason I have faith in China is that it has historical proxies. Since 1970, with the exception of a few OPEC members, only four economies have made the transition from emerging to developed markets (meaning their per-capita incomes exceed $15,000 per year): Taiwan, Singapore, Hong Kong, and South Korea.</span></p><p style="background-repeat: no-repeat; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-left: 0px; font-style: inherit; font-weight: inherit; font-size: 1.3em; margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; line-height: 20px; padding-bottom: 5px; "><span style="background-repeat: no-repeat; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-left: 0px; font-style: inherit; font-weight: inherit; margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; line-height: 20px; padding-bottom: 5px; font-size: 13px; ">These four economies have two things in common. First, they have few natural resources; and second, they are dominated by Chinese values and the traditional Chinese work ethic. Mainland China is different only because it got a later start.</span></p></span></span></p></blockquote><p><span style="color: #222222; line-height: 20px; font-size: 13px; "><br /></span></p><div><span style="color: #222222; line-height: 20px; font-size: 13px; ">Also, China reportedly has currency reserves $1.6 trillion. That means that China has a better balance sheet than the US, plus 1.6 trillion beats minus 12 trillion if you are scoring at home.</span></div><div><span style="color: #222222; line-height: 20px; font-size: 13px; "><br /></span></div><div><span style="color: #222222; line-height: 20px; font-size: 13px; ">Given that the Chinese stock market is down 70% in the last year, its an interesting time to look at Chinese stocks. A few weeks back Mohamed El-Erian made the bull case for buying the MCSI Emerging Markets index which gives you exposure to the BRICs plus a lot of other countries.</span></div><div><span style="color: #222222; line-height: 20px; font-size: 13px; "><br /></span></div><div><span style="color: #222222; line-height: 20px; font-size: 13px; ">Speaking of El-Erian, his book &quot;When Markets Collide&quot; was just </span><a href="http://business.timesonline.co.uk/tol/business/economics/article4968973.ece"><span style="font-size: 13px; ">voted Best Business Book of the Year</span></a><span style="color: #222222; line-height: 20px; font-size: 13px; ">. If we could have voted for a book that we wished everyone had read in 2007 he would have won that too, he said&#0160;</span></div><div><span style="color: #222222; line-height: 20px; font-size: 13px; "><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: 16px; font-size: 13px; ">“When I wrote the book, I thought I was writing about the future. When it was going to press, I thought it was about current affairs. Now I wish it was about history.”</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: 16px; font-size: 13px; "><br /></span></p></blockquote><p><span style="line-height: 16px; font-size: 13px; ">This part below reminds me a lot of 1995 security architectures used to defend 2008 integrated applications</span></p><div><span style="line-height: 16px; font-size: 13px; "><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; ">The present crisis had been triggered because the international financial system had undertaken activities that had “far outpaced the ability of the infrastructure to sustain them”, said El-Erian.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; "><br />And it was not just the markets that could not cope with their own changes, but governments as well. Significant weaknesses had been exposed “from the firms, to the regulatory agencies, to governments, to multilateral oversight”.<br /><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; ">“Turbocharge that with financial innovations, which history tells us we tend to overproduce and overconsume, and it’s inevitable that you will get a series of market accidents,” he said.<br /></span></p></blockquote><p><span style="font-size: 13px; "><br /></span></p><div><span style="font-size: 13px; ">In a Robert Garigue sense, in computer security our infostructure (users, apps and data) &#0160;are outpacing our infrastructure-centric security models</span></div><div><span style="font-size: 12px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="font-family: Arial;"><br /></span></div>]]></content:encoded>
      <pubDate>Sat, 08 Nov 2008 08:29:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/markets">markets</category>
      <category domain="http://securityratty.com/tag/china">china</category>
      <category domain="http://securityratty.com/tag/china reportedly">china reportedly</category>
      <category domain="http://securityratty.com/tag/markets collide">markets collide</category>
      <category domain="http://securityratty.com/tag/mainland china">mainland china</category>
      <category domain="http://securityratty.com/tag/markets index">markets index</category>
      <category domain="http://securityratty.com/tag/business book">business book</category>
      <category domain="http://securityratty.com/tag/trillion beats minus">trillion beats minus</category>
      <category domain="http://securityratty.com/tag/trillion">trillion</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/when-markets-collide.html">When Markets Collide</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #83: SIP and Asterisk vulnerabilities, voice biometrics, P2PSIP, Aircell blocking Skype, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/3a845f6538a2b485677d7771f5d125ce</link>
      <guid>http://securityratty.com/article/3a845f6538a2b485677d7771f5d125ce</guid>
      <description><![CDATA[Synopsis: Blue Box #83: SIP and Asterisk vulnerabilities, voice biometrics, P2PSIP , Aircell blocking Skype, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #83, a 39-minute...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #83: <span class="caps">SIP</span> and Asterisk vulnerabilities, voice biometrics, <span class="caps">P2PSIP</span>, Aircell blocking Skype, VoIP security news and more…</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #83, a 39-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-083-2008-09-04.mp3">Download the show here</a> (MP3, 18MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was recorded on September 4, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-083-2008-09-04.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-083-2008-09-04.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 


	<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Three-year anniversary of Blue Box coming up on October 24th - any thoughts you'd like to share with us? (Please send them to us by October 23rd.)</li>
		
	</ul>
</li>

<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-July/002702.html">Remote DoS in reSIProcate</a></li>

<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-July/002699.html">Remote root shell in Trixbox</a></li>

<li><a href="http://voipsa.org/blog/2008/06/25/avaya-cisco-and-nortel-voip-security-vulnerabilities-to-be-announced-today/">Second route of VoIPShield Cisco/Avaya/Nortel vulnerabilities</a></li>

<li><a href="http://voipsa.org/blog/2008/07/22/two-new-asterisk-security-advisories/">AST-2008-010 – <span class="caps">IAX2 </span>‘POKE’ Resource Exhaustion</a></li>

<li><a href="http://voipsa.org/blog/2008/07/22/two-new-asterisk-security-advisories/">AST-2008-011 – <span class="caps">IAX2 </span>Firmware Provisioning System</a></li>

<li>Saunderslog: <a href="http://saunderslog.com/2008/07/14/squawkbox-july-10-2008-voice-biometrics-and-voiceverifiedcom/">Squawk Box – July 10, 2008: Voice biometrics and VoiceVerified.com</a></li>

<li>Saunderslog: <a href="http://saunderslog.com/2008/07/09/squawkbox-july-9-2008-p2psip-guest-david-bryan/">Squawk Box – July 9, 2008: <span class="caps">P2PSIP</span></a></li>

<li><span class="caps">IETF</span>: <a href="http://www.ietf.org/internet-drafts/draft-matuszewski-p2psip-security-requirements-03.txt">P2PSIP Security Requirements</a></li>

<li>Voice of <span class="caps">VOIPSA</span>: “Aircell blocking VoIP on a plane” – <a href="http://voipsa.org/blog/2008/08/26/how-aircell-is-probably-blocking-voip-phone-calls-on-planes-hint-voip-whack-a-mole/">part 1</a> , <a href="http://voipsa.org/blog/2008/08/26/the-reason-why-probably-you-can-use-phweet-on-a-plane-when-skype-is-blocked/">part 2</a> and an <a href="http://voipsa.org/blog/2008/08/28/update-on-the-aircell-voip-on-a-plane-prohibition-and-an-aircell-response/">update</a></li>

<li>Voice of <span class="caps">VOIPSA</span>: Shawn Merdinger’s series on “Asking The Cisco <span class="caps">IPICS </span>Expert” – Questions <a href="http://voipsa.org/blog/2008/07/17/asking-the-cisco-systems-ipics-expert-questions-1-5/">1-5</a> – <a href="http://voipsa.org/blog/2008/07/23/asking-the-cisco-systems-ipics-expert-questions-6-10/">6-10</a> – <a href="http://voipsa.org/blog/2008/08/02/asking-the-cisco-systems-ipics-expert-questions-11-15/">11-15</a> – <a href="http://voipsa.org/blog/2008/08/18/asking-the-cisco-systems-ipics-expert-questions-16-20/">16-20</a> – <a href="http://voipsa.org/blog/2008/09/02/asking-the-cisco-systems-ipics-expert-questions-21-25/">21-25</a></li>

<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/07/23/asterisk-hack-to-show-blocked-caller-id-points-to-larger-trust-issues-with-sip/">Asterisk ‘hack’ to show blocked Caller-ID points to larger trust issues with <span class="caps">SIP</span></a> (and SpeechTEK speech)</li>

<li>NetworkWorld: <a href="http://www.networkworld.com/news/2008/072908-georgia-student-arrested-for-hacking.html">Georgia student arrested for hacking grades, VoIP</a></li>

<li><span class="caps">CRN</span>: <a href="http://www.crn.com/security/209900949">Analysis: Hacking VoIP as easy as 1-2-3</a></li>

<li><a href="http://voipsa.org/blog/2008/07/16/ari-takanen-starts-blogging-at-itworld/">Ari Takanen starts blogging at InfoWorld</a></li>

<li>InfoWorld: <a href="http://www.itworld.com/security/54688/there-motivation-voip-fuzzing" class="Is There"> Motivation for VoIP Fuzzing</a></li>

<li>TMCnet: How to keep your tech career afloat</li>

<li>New analyst report: <a href="http://www.sunherald.com/prnewswire/story/687245.html">Security Threats Loom Over Unified Communications</a> pointing to <a href="http://www.lightreading.com/entvoip/details.asp?sku_id=2230&amp;skuitem_itemid=1113&amp;promo_code=&amp;aff_code=&amp;next_url=%2Fentvoip%2Flist.asp%3Fpage_type%3Drecent_reports">Light Reading report</a> and <a href="http://www.lightreading.com/entvoip/document.asp?doc_id=159146">article</a></li>

<li><a href="http://www.callcentre.co.uk/c/portal/layout?p_l_id=259723&amp;CMPI_SHARED_articleId=551057&amp;CMPI_SHARED_CommentArticleId=551057&amp;CMPI_SHARED_ImageArticleId=551057&amp;CMPI_SHARED_ToolsArticleId=551057&amp;CMPI_SHARED_articleIdRelated=551057&amp;articleTitle=VoIP%20companies%20to%20fight%20for%20market%20share">VoIP Companies to Fight For Market Share</a></li>

<li><a href="http://www.thetechherald.com/article.php/200836/1907/IEEE-approves-802-11r-roaming-Wi-Fi-standard">IEEE approves 802.11r standard</a></li>

<li>Google Chrome – upgrading the web to be application-centric</li>

<li>Items on my <a href="http://www.disruptivetelephony.com/">DisruptiveTelephony</a> blog… Skype 5th birthday, Asterisk future, Digium/Nortel</li>

<li>No comments this week.<br />
</li>

<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list<br />
</li>

<li>Wrap-up of the show<br />
</li>

<li>39:08 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=0LabzA"><img src="http://feeds.feedburner.com/~a/BlueBox?i=0LabzA" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=uRYdM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uRYdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=urdIM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=urdIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=OnnxM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=OnnxM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=g0lNM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=g0lNM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=sWBIm"><img src="http://feeds.feedburner.com/~f/BlueBox?i=sWBIm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=77UtM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=77UtM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/422759142" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 06:48:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip companies">voip companies</category>
      <category domain="http://securityratty.com/tag/voice biometrics">voice biometrics</category>
      <category domain="http://securityratty.com/tag/voice">voice</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/p2psip">p2psip</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/422759142/blue-box-83-sip.html">Blue Box #83: SIP and Asterisk vulnerabilities, voice biometrics, P2PSIP, Aircell blocking Skype, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Integrating Event/Incident and Problem Management]]></title>
      <link>http://securityratty.com/article/fbba6395d7eaad30dc65321fe9f0fd16</link>
      <guid>http://securityratty.com/article/fbba6395d7eaad30dc65321fe9f0fd16</guid>
      <description><![CDATA[Change, Change, Change. What needs to change as IT organizations move towards sophisticated virtualized infrastructure ? Event/Incident and Problem Management integration of course
We have been...]]></description>
      <content:encoded><![CDATA[<p>Change, Change, Change. What needs to change as IT organizations move towards sophisticated <a href="http://blog.taragana.com/index.php/archive/virtualization-technologies-full-virtualization-versus-para-virtualization/" target="_blank">virtualized infrastructure</a>? Event/Incident and Problem Management integration of course!</p>
<p>We have been conducting polls of our customers and of IT professionals at technology trade shows for the past two years and the results are in: Pulling together all of the management pieces and processes is even more crucial in a virtualized environment.</p>
<p>So what does this mean for you? You will need to refine your <a href="http://blog.evergreensys.com/2008/01/10/meeting-tough-customers-over-incident-management/" target="_blank">incident and problem management</a> processes with new technologies in order to reduce downtime and maintain end user performance. But of course even the most basic technologies are not well integrated even in today’s world.</p>
<p>I recently participated in a <a href="Gartner%20Conference" target="_blank">Gartner Conference</a> and watched to my amazement a real-time electronic survey of the audience. To my disbelief, the audience, filled with 300+ people from Fortune 2000 companies provided real-time responses to the question:</p>
<p><em>What level of integration does your IT org have between event management and service desk applications?</em></p>
<ul>
<li>None: 10%</li>
<li><strong>Manual Phone call from IT ops to IT service desk staff member: 46%</strong></li>
<li>Manual click button on event manager to open trouble ticket: 20%</li>
<li>Automated event management system automatically opens trouble ticket without requiring human oversight or approval: 24%</li>
</ul>
<p>Unbelievable… still very few of the survey respondents have yet to formalize problem management systems with event management systems. For 56% of the audience the process is still manual!</p>
<p>Another interesting real-time survey question at the Gartner Conference was:</p>
<p><em>Who in your organization is responsible for critical problem processes and resolution?</em></p>
<ul>
<li>IT Service Desk 13%</li>
<li>IT Operations 49%</li>
<li>Process Team 12%</li>
<li>Other 9%</li>
<li>Responsibility not formalized 17%</li>
</ul>
<p><a href="http://blogs.technet.com/virtualization/archive/2008/10/10/Guest-post_3A00_-virtualization-requires-the-proper-perspective-.aspx" target="_blank">Virtualization adoption</a> and the speed with which things change in a virtualized environment require automation and will transform <a href="http://servicexen.wordpress.com/2008/07/02/implementing-service-management-processes-in-small-and-medium-companies/" target="_blank">Incident and Problem Management</a>. Clearly with <a href="http://tarrysingh.blogspot.com/2008/10/microsoft-to-train-thousands-in.html" target="_blank">this new technology we are required to re-think</a> Organizational, Behavioral and Cultural Challenges required to take advantage of the opportunities that virtualization provides.</p>
<p>Incident and problem management processes and metrics must bridge organizational silos that have been the norm within IT. With virtualization, people have to work more closely together in the different silos than ever before. IT leaders need to break down the walls between the technology-centric silo mentalities.</p>
<p>Business Imperative Action Plan:</p>
<ol>
<li>What can you do<strong> today</strong>? &#8211;Understand the impact of virtualization on incident and problem mgt. workload, provide technology training for helpdesk/service desk staff.</li>
<li>What can you do in the <strong>next 12 months</strong>?</li>
</ol>
<p>Formalize problem management processes, metrics and personnel.<br />
Invest in tools and processes for systems on virtualized servers.<br />
Long term: On the Radar Screen!<br />
Instill teamwork into all groups responsible for the <a href="http://servicexen.wordpress.com/2008/07/02/implementing-service-management-processes-in-small-and-medium-companies/" target="_blank">virtualized environment</a> service and support. Map components and configuration items directly to end user services.</p>
<p>Final Thoughts: Know the management pieces and ensure that they fit together. It’s great to buy new technology, but be demanding to ensure that your vendors show you have they will help to link all these pieces together - Change, Inventory, Incident, Problem, Server, Capacity, Performance, Configuration, Event, and Integrated Workflow.</p>
]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 14:00:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/event management systems">event management systems</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/management processes">management processes</category>
      <category domain="http://securityratty.com/tag/management pieces">management pieces</category>
      <category domain="http://securityratty.com/tag/management systems">management systems</category>
      <category domain="http://securityratty.com/tag/management integration">management integration</category>
      <category domain="http://securityratty.com/tag/event management system">event management system</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <source url="http://blog.sciencelogic.com/integrating-eventincident-and-problem-management/10/2008">Integrating Event/Incident and Problem Management</source>
    </item>
    <item>
      <title><![CDATA[A horse's ass approach to virtualization security]]></title>
      <link>http://securityratty.com/article/6d6310950dd47b0806138e4729f21f01</link>
      <guid>http://securityratty.com/article/6d6310950dd47b0806138e4729f21f01</guid>
      <description><![CDATA[The interest and excitement around virtualization is palpable. However, it seems like the security approaches in this area are similar to the constrains that a horse's ass put on the space shuttle...]]></description>
      <content:encoded><![CDATA[The interest and excitement around virtualization is palpable. However, it seems like the security approaches in this area are similar to the constrains that a <a href="http://www.astrodigital.org/space/stshorse.html">horse's ass put on the space shuttle design</a>.<br /><br />Virtualization security solutions today primarily focus on protecting the virtual OS, the virtual networks, or the hypervisor software itself. More specifically, most current virtualization security technologies are focused on preventing hypervisor root kits, providing intrusion detection, anti-malware, anti-virus, network security, etc. In the physical world, this is similar to individually protecting hardware, operating systems, and the networks that connect them. That is, the focus is mainly on protecting infrastructure and perimeter, not data. Protecting that data, however, should be the single most important aspect of virtualization security.<br /><br />Here is why: Any execution environment requires four elements: devices/hardware/OS, networks, applications, and data. With the advent of virtualization, physical devices/OS are being replaced by flexible, on-demand virtual “devices,” networks are being virtualized and applications are being streamed down from virtual environments. Therefore, the only remaining “constant” element is the data itself - which also has a longer lifetime than the ephemeral virtual environment. While protecting the virtual infrastructure is important, I believe the primary focus for protection should be the data – the true IT asset.<br /><br />Virtualization is a game-changer for computing and has forced the IT world to rethink its infrastructure; now virtualization security has to be rethought as well. An information-centric approach to persistently protecting the data itself is the only way to really benefit from virtualization and keep the data truly secure.<br /><br />Or thinking about it another way - why was Google's approach to navigate the web using search better than the initial Yahoo approach of hierarchical mapping? Coz Yahoo was mapping an old yellow-book approach to managing data, while Google took advantage of the new medium.<br /><br />I shall try and elaborate on my thoughts in upcoming posts...<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=I3ERM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=I3ERM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=Y0Zmm"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=Y0Zmm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=uQozM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=uQozM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/420080548" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 21:52:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization security">virtualization security</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization security solutions">virtualization security solutions</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <category domain="http://securityratty.com/tag/virtual infrastructure">virtual infrastructure</category>
      <category domain="http://securityratty.com/tag/approach">approach</category>
      <category domain="http://securityratty.com/tag/on-demand virtual devices">on-demand virtual devices</category>
      <category domain="http://securityratty.com/tag/ephemeral virtual environment">ephemeral virtual environment</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/420080548/horses-ass-approach-to-virtualization.html">A horse's ass approach to virtualization security</source>
    </item>
    <item>
      <title><![CDATA[User-centric security begs for process overhaul]]></title>
      <link>http://securityratty.com/article/b9ad0209f220932489e5adf8ff48ef72</link>
      <guid>http://securityratty.com/article/b9ad0209f220932489e5adf8ff48ef72</guid>
      <description><![CDATA[Ferrum College overhauled people and processes when it implemented user-centric access...]]></description>
      <content:encoded><![CDATA[Ferrum College overhauled people and processes when it implemented user-centric access control.]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/user-centric access control">user-centric access control</category>
      <category domain="http://securityratty.com/tag/ferrum college">ferrum college</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/processes">processes</category>
      <source url="http://www.networkworld.com/supp/2008//100908-trendwatch-access-control-ferrum-college.html?fsrc=rss-security">User-centric security begs for process overhaul</source>
    </item>
    <item>
      <title><![CDATA[Access control: The evolving tool set]]></title>
      <link>http://securityratty.com/article/37490aa9e2883a2a11c78340f7dedf5d</link>
      <guid>http://securityratty.com/article/37490aa9e2883a2a11c78340f7dedf5d</guid>
      <description><![CDATA[Enterprises struggle to find a sweet spot -- in cost, complexity and capability -- for user-centric access...]]></description>
      <content:encoded><![CDATA[Enterprises struggle to find a sweet spot -- in cost, complexity and capability -- for user-centric access control.]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/user-centric access control">user-centric access control</category>
      <category domain="http://securityratty.com/tag/sweet spot">sweet spot</category>
      <category domain="http://securityratty.com/tag/enterprises struggle">enterprises struggle</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/complexity">complexity</category>
      <category domain="http://securityratty.com/tag/capability">capability</category>
      <source url="http://www.networkworld.com/supp/2008//100908-trendwatch-access-control.html?fsrc=rss-security">Access control: The evolving tool set</source>
    </item>
    <item>
      <title><![CDATA[Perimeter-centric Regulations in an Information-centric World]]></title>
      <link>http://securityratty.com/article/272eda748ab593f8af2e44bcd8cb876a</link>
      <guid>http://securityratty.com/article/272eda748ab593f8af2e44bcd8cb876a</guid>
      <description><![CDATA[Last week I took a trip out to our Executive Briefing Centre in Cork, Ireland. I was there to present to senior IT folk from pretty much all of the UKs Police Forces as part of a two-day agenda that...]]></description>
      <content:encoded><![CDATA[<p>Last week I took a trip out to our   Executive Briefing Centre in Cork, Ireland. I was there to present to senior IT   folk from pretty much all of the UK&rsquo;s Police Forces as part of a two-day agenda   that had been lined up for them by my colleagues from many of EMC&rsquo;s   lines-of-business.</p>
<p>I guess there are few other   organisations where the lines between physical and virtual security are brought   so sharply into focus than in one where you are dealing &ndash; first-hand &ndash; with   criminals in the way that our police officers must every day of their working   lives.</p>
<p><B>During our conversations we mused on   various aspects of keeping information secure in such a fluid and volatile   environment...</b>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/two-day agenda">two-day agenda</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/uks police forces">uks police forces</category>
      <category domain="http://securityratty.com/tag/information secure">information secure</category>
      <category domain="http://securityratty.com/tag/police officers">police officers</category>
      <category domain="http://securityratty.com/tag/volatile environment">volatile environment</category>
      <category domain="http://securityratty.com/tag/virtual security">virtual security</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/lines">lines</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1359">Perimeter-centric Regulations in an Information-centric World</source>
    </item>
    <item>
      <title><![CDATA[Fraud Detection in Financial Services Reloaded]]></title>
      <link>http://securityratty.com/article/ded3c6e73beb9af7e3aaa5abae657b06</link>
      <guid>http://securityratty.com/article/ded3c6e73beb9af7e3aaa5abae657b06</guid>
      <description><![CDATA[I read an interesting post bythe former CTO of out-of-business Kaskad Technology , where event processing colleague Colin Clark respectfully disagrees with my assesement of the (lack of) capabilitesin...]]></description>
      <content:encoded><![CDATA[<p>I read an <a href="http://colinclarkeventprocessing.com/?p=154" target="_blank">interesting post</a> by the former CTO of <a href="http://rulecore.com/CEPblog/?p=279" target="_blank">out-of-business Kaskad Technology</a>, where event processing colleague Colin Clark respectfully disagrees with my assesement of the (lack of) capabilites in current-generation &#8220;CEP engines&#8221; for detecting complex fraud in financial services.  I&#8217;ll respond with a quote from my September 2007 post,  <a title="End Users Should Define the CEP Market." rel="bookmark" href="http://www.thecepblog.com/2007/12/17/end-users-should-define-the-cep-market/"><span style="color: #105cb6;">End Users Should Define the CEP Market.</span></a></p>
<blockquote><p><em>&#8220;Experienced end users are very intelligent. </em></p>
<p><em>These end users know the complex event processing problems they need to solve; and they know the limitations of the current COTS approaches marketed by the CEP community.  Even in Thailand, a country many of you might mistakenly think is not very advanced technologically, there are experts in telecommunications (who run large networks) who are working on very difficult fraud detection applications, and they use neural networks and say the results are very good.   However, there is not one CEP vendor, that I know of, who offers true CEP capability in the form of neural nets. </em></p>
<p><em>Almost every major bank, telco, etc. has the same opinion, and the same problem. They need much more capability than streaming joins, selects and rules to solve their complex event processing problems that Dr. Luckham outlined in his book.   The software vendors are attempting to define the CEP market to match their capability; unfortunately, their capabilities do not meet the requirements of the vast majority of end users who have CEP problems to solve.</em></p>
<p><em>If the current CEP platforms were truely solving complex event processing problems, annual sales would be orders of magnitudes higher.  Hence, the users have already voted.   The problem is that the CEP community is not listening.&#8221;</em></p></blockquote>
<p>Not to be overly repetitive,  but the last part of this quote from a year ago is worth highlighting:</p>
<blockquote><p><em>&#8220;If the current CEP platforms were truely solving complex event processing problems, annual sales would be orders of magnitudes higher.  Hence, the users have already voted.   The problem is that the CEP community is not listening.&#8221;</em></p></blockquote>
<p>Frankly speaking, nothing in the &#8220;CEP world&#8221; has changed, technologically speaking, since this September 2007 post was written.  From a sales perspective, we have seen less CEP-related sales in 2008 than in prior years.   If these so called CEP products were actually capability of detecting &#8220;real&#8221; complex network-centric situations (threats) in real-time, they would be selling faster than a cup of ice water in the blazing hot Sahara desert.</p>
<p>Don&#8217;t shoot the messenger.  Build better detection engines!</p>
<p>On the other hand, maybe complex detection is too hard for most of these companies and that is why they focus on routing, mediation and relatively simple rule-based scenarios, versus complex event processing?</p>
]]></content:encoded>
      <pubDate>Sat, 20 Sep 2008 18:36:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/versus complex event">versus complex event</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/cep products">cep products</category>
      <category domain="http://securityratty.com/tag/cep community">cep community</category>
      <category domain="http://securityratty.com/tag/cep vendor">cep vendor</category>
      <category domain="http://securityratty.com/tag/current cep platforms">current cep platforms</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/sales">sales</category>
      <source url="http://www.thecepblog.com/2008/09/20/fraud-detection-in-financial-services-reloaded/">Fraud Detection in Financial Services Reloaded</source>
    </item>
  </channel>
</rss>
