<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: check]]></title>
    <link>http://securityratty.com/tag/check</link>
    <description></description>
    <pubDate>Thu, 18 Sep 2008 23:12:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[John Strand's videos on Evilegrade, Samurai, Hacker Defender and other topics (Blackhills Security)]]></title>
      <link>http://securityratty.com/article/dbee1ca962fdc5a756d91e8af56f2d89</link>
      <guid>http://securityratty.com/article/dbee1ca962fdc5a756d91e8af56f2d89</guid>
      <description><![CDATA[I had the pleasure to meet John Strand tonight at the pre- LouisvilleInfosec dinner. Great guy, and fun to talk to. Made me realize there's a lot of stuff I need to learn about. Check out his videos...]]></description>
      <content:encoded><![CDATA[I had the pleasure to meet John Strand tonight at the pre-<a href="http://www.louisvilleinfosec.com/">LouisvilleInfosec</a> 
dinner. Great guy, and fun to talk to. Made me realize there's a lot of stuff I 
need to learn about. Check out&nbsp; his videos at the link above. I hope to 
have his keynote from the conference up at my site shortly.
<p><a href="http://feedads.googleadservices.com/~a/oISkiX6KESnE3bmXs6yKRivmMBw/a"><img src="http://feedads.googleadservices.com/~a/oISkiX6KESnE3bmXs6yKRivmMBw/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/YQWVEAuyKkE" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 18:28:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/john strand tonight">john strand tonight</category>
      <category domain="http://securityratty.com/tag/site shortly">site shortly</category>
      <category domain="http://securityratty.com/tag/videos">videos</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/hope">hope</category>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/pleasure">pleasure</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/YQWVEAuyKkE/Videos.html">John Strand's videos on Evilegrade, Samurai, Hacker Defender and other topics (Blackhills Security)</source>
    </item>
    <item>
      <title><![CDATA[Check if Your Gmail is Hacked with Activity Monitor]]></title>
      <link>http://securityratty.com/article/fa33eb29ef4aa58abfcbb608de742ecb</link>
      <guid>http://securityratty.com/article/fa33eb29ef4aa58abfcbb608de742ecb</guid>
      <description><![CDATA[This time I want to go over one new Gmail feature. It watches your account and displays a notification when someone else logs into your account. Basically a nice little feature from Gmail team that...]]></description>
      <content:encoded><![CDATA[This time I want to go over one new Gmail feature. It watches your account and displays a notification when someone else logs into your account. Basically a nice little feature from Gmail team that lets you check if someone has hacked into your Gmail account.]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 03:30:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gmail account">gmail account</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/gmail feature">gmail feature</category>
      <category domain="http://securityratty.com/tag/feature">feature</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/gmail team">gmail team</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/nice">nice</category>
      <source url="http://digg.com/security/Check_if_Your_Gmail_is_Hacked_with_Activity_Monitor">Check if Your Gmail is Hacked with Activity Monitor</source>
    </item>
    <item>
      <title><![CDATA[Be careful what hand you play, and when you play it]]></title>
      <link>http://securityratty.com/article/3f792de863bd77b5be976522d12fce8f</link>
      <guid>http://securityratty.com/article/3f792de863bd77b5be976522d12fce8f</guid>
      <description><![CDATA[Yet another analogy from the credit crunch shows us security folks that even if we changed jobs we probably wouldn't be able to escape our frustrations. The executive branch is currently trying to win...]]></description>
      <content:encoded><![CDATA[Yet another analogy from the credit crunch shows us security folks that even if we changed jobs we probably wouldn't be able to escape our frustrations. 

The executive branch is currently trying to win over Congress and convince them to hand over a large sum of money, or else something really bad is going to happen. This is a situation I'm sure many security folks have found themselves in, albeit under less extreme circumstances.

The people with the check books seldom know anything about what you're doing. Congress is full of politicians, not economists or experts on the banking system. They need to rely on their gut feeling to do the right thing. Same thing with your management, <B>so it's up to you to guide them towards the right decision -- in their language</b>...
]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security folks">security folks</category>
      <category domain="http://securityratty.com/tag/check books seldom">check books seldom</category>
      <category domain="http://securityratty.com/tag/congress">congress</category>
      <category domain="http://securityratty.com/tag/extreme circumstances">extreme circumstances</category>
      <category domain="http://securityratty.com/tag/credit crunch">credit crunch</category>
      <category domain="http://securityratty.com/tag/executive branch">executive branch</category>
      <category domain="http://securityratty.com/tag/hand">hand</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/analogy">analogy</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1358">Be careful what hand you play, and when you play it</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.29.08]]></title>
      <link>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</link>
      <guid>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</guid>
      <description><![CDATA[Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/oracle.jpg" border="0" alt="oracle" width="240" height="164" align="left" /> Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work done lately?? <em>(</em><a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank"><em>image from cdye1</em></a><em>)</em></p>
<p>Does <a href="http://sfcitizen.com/blog/2008/09/24/its-oracles-world-were-just-living-in-it/" target="_blank">Oracle run the world</a>? I would have to say no but Raj (Larry Ellison is his idol) and the 40,000 Oracle customers that descended upon SF last week might beg to differ. What do James Carville and Mary Matalin have to do with enterprise software? Pretty much nothing, except for the fact that they delivered the opening keynote for <a href="http://www.oracle.com/openworld/2008/index.html" target="_blank">Oracle OpenWorld</a>. (And that’s the only and last politically-oriented thing you’ll hear from me as we run up to the election). For a surprisingly funny and extensive photo gallery of the eye-popping event, check out <a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank">cdye1’s photostream</a> on Flickr.</p>
<p>But UB40, Elvis Costello and Seal aside, Oracle OpenWorld did offer training, certifications, and always entertaining speeches by Ellison. Ben Worthen’s favorite – “<a href="http://blogs.wsj.com/biztech/2008/09/25/larry-ellisons-brilliant-anti-cloud-computing-rant/?mod=djemTECH" target="_blank">Larry Ellison’s Brilliant Anti-Cloud Computing Rant</a>” delivered to analysts on Thursday. From Ben’s slightly-edited excerpt:</p>
<p>“The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion-driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?</p>
<p>“We’ll make cloud computing announcements. I’m not going to fight this thing. But I don’t understand what we would do differently in the light of cloud computing other than change the wording of some of our ads. That’s my view.”</p>
<p>So did everyone catch that? Cloud computing is complete gibberish and idiocy, but apparently Oracle’s already been doing enough around it to advertise the fact. I will have my cake and eat it too!</p>
<p>We’ve been pumping out the posts from the shows we went to – let me tell you, live-blogging is hard when you’re trying to share apparently miniscule amounts of bandwidth with 14,000 other attendees – and we have even more to share as we step back, contemplate and describe how some of the announcements, info and especially roadmaps fit into our overall picture over here at ScienceLogic.</p>
<p>For example, we released the results of our annual industry IT survey last week. Twice a year – at FOSE (for Government IT) and at Interop NY (for enterprises) – we take advantage of the fact that we have a big beautiful booth at these shows and offer a fabulous ScienceLogic t-shirt in return for a couple of minutes time with attendees living the <a href="http://blog.sciencelogic.com/why-we-l-o-v-e-tradeshows/03/2008" target="_blank">problems we try to solve</a>. Instead of telling people what their problems and priorities are, we like to ask.<br />
<a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008?" target="_blank">Interop NY Survey - Trends and Challenges</a><br />
<a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">Detailed Reports on Trends and Comparison to Government IT</a></p>
<p>And I just had to share this one because it is so bizarre. Are VMware and Paul Maritz guilty of <a href="http://it20.info/blogs/main/archive/2008/09/21/143.aspx" target="_blank">plagiarism</a>? You have to check this out to get even part of the picture. Apparently this guy has posted his slides (we know they are from VMworld 2007 because it says so in the lower-right-hand corner…) which prove that the “virtual datacenter operating system” idea was his idea a year before it showed up on Maritz’s keynote this year. Hmmm. And then after posting all these slides and making all the connections between his presentation and Maritz’s, he says he’s just kidding about the plagiarism. Can anyone sort this out and let me know?</p>
<p>I’ll tell you who wasn’t kidding when I went by their booth at VMworld – a certain chargeback vendor and VMware “partner” who was quite shocked two months ago when they walked into a meeting with VMware about future roadmap. Apparently, the slides they saw (preview of VMware’s announcement re adding extended chargeback capability within vCenter management services) were mighty might similar to slides they had given in a presentation to VMware about their own roadmap. Coincidence? I’ll let you decide. And I’ll also say, their strategy to combat this – support for Hyper-V coming early in 2009.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oracle openworld">oracle openworld</category>
      <category domain="http://securityratty.com/tag/oracle">oracle</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/annual oracle blowout">annual oracle blowout</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware partner">vmware partner</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/annual industry">annual industry</category>
      <category domain="http://securityratty.com/tag/apparently oracles">apparently oracles</category>
      <source url="http://blog.sciencelogic.com/links-list-92908/09/2008">Links List 9.29.08</source>
    </item>
    <item>
      <title><![CDATA[Have CrackBerry, Will Travel]]></title>
      <link>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</link>
      <guid>http://securityratty.com/article/c96f50744fe7be879c793f14bd28e183</guid>
      <description><![CDATA[Blogger: Dan Blum
It is no surprise for us to hear loose lips flapping in India about a capability to decrypt Blackberry and other carrier traffic
After all, weve done basic threat analysis for years...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>It is no surprise for us to hear loose lips flapping in India about <a href="http://economictimes.indiatimes.com/At_last_govt_cracks_BlackBerry_code/articleshow/3510719.cms">a capability to decrypt Blackberry and other carrier traffic</a>.</p>

<p>After all, we’ve done basic threat analysis for years and it was only months ago that I was brought into a company-wide CISO meeting at a U.S. defense contractor to help them hash out their travel policy for mobile devices. Going into the meeting, I knew their policy restricted taking devices to a list of countries considered dangerous – but there was an exemption for BlackBerries.</p>

<p>Our research uncovered that BlackBerry is pretty secure in most respects. It has transport encryption along with optional password protection, remote kill, disk encryption, and S/MIME encryption. Viruses have not flourished on this functionally limited and closed platform. Few if any third party add on programs are required for additional protection. Nonetheless, I went into the meeting prepared to talk with the CISOs about the risks and security limitations of life on BlackBerry.</p>

<p>Was the BlackBerry exemption reasonable? At the time, BlackBerry transport encryption was not known to have been broken (to be fair, the article listed above still qualifies as rumor, not certainty of breakage). However, I pointed out that it is dangerous to assume well-equipped attackers like military or intelligence organizations can’t crack transport encryption. And even if they haven’t cracked the BlackBerry network and whole disk encryption features, sophisticated adversaries have other attack paths. Check out Neal Stephenson’s excellent book <a href="http://www.amazon.com/Cryptonomicon-Neal-Stephenson/dp/0060512806/ref=pd_bbs_sr_1?ie=UTF8&amp;s=books&amp;qid=1222262354&amp;sr=1-1">Cryptonomicon</a> for a description of how a talented adversary might “see” your keystrokes and screen images through a motel room wall, for example.</p>

<p>If one of your employees – such as a key scientist, project manager, or executive – is targeted for surveillance and is carrying sensitive data through certain countries, one could argue that he or she had better undergo serious counter-intelligence training.&nbsp; Learn to spot and shake tails, sneak into dark alleys for that BlackBerry fix. Learn to paper the closet with layers of aluminum foil and send messages in the dark. Defend that BlackBerry with encryption, long passphrases, and kung fu. But unless James Bond is running your company, I doubt this is what your executives have in mind for the next business trip!</p>

<p>Assuming your organization’s lower level employees are like needles in a haystack and won’t be bothered could be an exercise in wishful thinking. It is always possible that nation states are monitoring some or all of the airwaves. Not so long ago the NSA had a massive a covert surveillance program in place. Years before the government was reportedly snarfing up terabytes of emails and crunching them through a program called Carnivore. And of course, selective monitoring of people on watch lists continues on a large scale. This is just the surveillance we know about in the U.S. We suspect there’s more behind the scenes and especially in countries such as China. Even if you train your non-specifically-targeted low level employees to write and speak in search-keyword-free code, the carnivore programs of the world are pretty good at sniffing out those interesting needles – such as descriptions of your business plans, manufacturing processes, and trade secrets.</p>

<p>Sound paranoid? I admit that I don’t know what the probabilities of being targeted or monitored are – just that it can happen. It’s the height of arrogance to believe that a nation state can’t get your information if they’ve targeted it and you’re within their borders. And it’s dangerous to rely on security by obscurity when medium or high consequence information must be protected.</p>

<p>What can be done? If key personnel can't dispense with the BlackBerry (or any other email device) during international travel to those countries where information may be most at risk, they (the users) should limit communications to what they’d feel comfortable uttering over a potentially-monitored telephone call. Controlling incoming communications – messages sent by others – is a harder problem. Until data loss prevention (DLP) products become more contextually sensitive about the travel issues, it may be best not to synchronize the BlackBerry with the overseas user’s home mailbox. Instead, have the user give out a temporary address for the BlackBerry and warn senders to be discreet. </p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/402766223" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 04:45:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry transport encryption">blackberry transport encryption</category>
      <category domain="http://securityratty.com/tag/transport encryption">transport encryption</category>
      <category domain="http://securityratty.com/tag/exemption">exemption</category>
      <category domain="http://securityratty.com/tag/blackberry exemption reasonable">blackberry exemption reasonable</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/disk encryption features">disk encryption features</category>
      <category domain="http://securityratty.com/tag/blackberry fix">blackberry fix</category>
      <category domain="http://securityratty.com/tag/decrypt blackberry">decrypt blackberry</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/402766223/have-crackberry.html">Have CrackBerry, Will Travel</source>
    </item>
    <item>
      <title><![CDATA[Network World Coverage of ScienceLogic at Interop]]></title>
      <link>http://securityratty.com/article/27b0a46be99117829b3a5801b8947a5d</link>
      <guid>http://securityratty.com/article/27b0a46be99117829b3a5801b8947a5d</guid>
      <description><![CDATA[We were all really excited to have the opportunity to illuminate Sevick and Wetzel about ScienceLogics value proposition at Interop
Yesterday, they posted a terrific blog post about what they saw at...]]></description>
      <content:encoded><![CDATA[<p>We were all really excited to have the opportunity to illuminate Sevick and Wetzel about ScienceLogic’s value proposition at Interop.
<p>Yesterday, they <a href="http://www.networkworld.com/community/node/33059" target="_blank">posted a terrific blog post</a> about what they saw at Interop. Fortunately, ScienceLogic was one of the technologies that they highlighted from the show. I have written earlier posts about <a href="http://blog.sciencelogic.com/whats-up-with-the-washington-posts-biz-section-coverage-of-local-business/05/2008" target="_blank">how difficult it has been</a> to gain smart, insightful coverage for our solutions with technology media.
<p>I have to say that they really got it! And it feels so good. We know that we have a bit of a hidden gem of a product here at ScienceLogic and will be working overtime in the coming months to take our business and products to a “Blue Ocean” environment that will shock and surprise many others in the media. However Sevick and Wetzel will be amongst the first to get a close-up on why and how we will deliver a new paradigm to this marketplace in 2009!
<p>A few excerpts from their post:<br />
<blockquote>
<p>“We noticed yet more specialty network management vendors, leading us to wonder how the market can support such a plethora of them, and we felt empathy for IT teams that have to master yet more interfaces.”
<p>“Application performance management and application acceleration vendors were well represented. Such products play well in today’s climate because they allow enterprises to get the most out of existing IT investments instead of buying more “stuff”. One particularly interesting vendor we talked to was <a href="http://www.sciencelogic.com/">ScienceLogic</a>. They are integrating IT infrastructure and application monitoring into a single, not-very-expensive platform that will serve mainstream business well. This is smart, and we predict they will give the CA’s, BMC’s, HP’s and IBM’s of the world a run for their money.”</p>
</blockquote>
<p>&nbsp;
<p>Check out the <a href="http://www.networkworld.com/community/node/33059" target="_blank">blog post here</a> and keep <a href="http://www.networkworld.com/community/appview" target="_blank">App Performance View</a> on your radar..<a href="http://www.networkworld.com/community/node/33059"></a></p>
]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 11:36:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/terrific blog post">terrific blog post</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/application acceleration vendors">application acceleration vendors</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/sciencelogic">sciencelogic</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/application performance management">application performance management</category>
      <source url="http://blog.sciencelogic.com/network-world-coverage-of-sciencelogic-at-interop/09/2008">Network World Coverage of ScienceLogic at Interop</source>
    </item>
    <item>
      <title><![CDATA[Teaching Hacking at College by Sam Bowne]]></title>
      <link>http://securityratty.com/article/f464683006bea78fdf7801ca7073794b</link>
      <guid>http://securityratty.com/article/f464683006bea78fdf7801ca7073794b</guid>
      <description><![CDATA[This was a DefCon 15 presentation (August 3-5, 2007) by Sam Bowne. Sam does a great job explaining how to teach ethical hacking at a university, and since he gave me a shout out in the video I figured...]]></description>
      <content:encoded><![CDATA[This was a DefCon 15 presentation (August 3-5, 2007) by Sam Bowne. Sam does a great job explaining how to teach ethical hacking at a university, and since he gave me a shout out in the video I figured I'd post it up here. Definitely a must watch if you are trying to convince your college's administration that it's a good idea to teach such a course. Check out Sam's site at <a href="http://www.samsclass.info/">http://www.samsclass.info/</a> if you want to use his teaching curriculum.
<p><a href="http://feedads.googleadservices.com/~a/ffKhJm5iX4Lhl_Vt_8kxxORw8rg/a"><img src="http://feedads.googleadservices.com/~a/ffKhJm5iX4Lhl_Vt_8kxxORw8rg/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/elG29TYNdzQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 16:15:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sam">sam</category>
      <category domain="http://securityratty.com/tag/sam bowne">sam bowne</category>
      <category domain="http://securityratty.com/tag/college">college</category>
      <category domain="http://securityratty.com/tag/administration">administration</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/ethical">ethical</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/elG29TYNdzQ/i.php">Teaching Hacking at College by Sam Bowne</source>
    </item>
    <item>
      <title><![CDATA[Interop NY: Hypervisor Quick Poll]]></title>
      <link>http://securityratty.com/article/5f4e1b85bcb4d172e0ed7994ef95ea8e</link>
      <guid>http://securityratty.com/article/5f4e1b85bcb4d172e0ed7994ef95ea8e</guid>
      <description><![CDATA[On the final day of Interop NY 2008 , we conducted a second quick poll of attendees ( check out the first poll on virtualization here ), asking which hypervisors were currently in use. In asking the...]]></description>
      <content:encoded><![CDATA[<p><b><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 0px 10px 10px 0px; border-right-width: 0px" height="99" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/clip-image002.gif" width="91" align="left" border="0"></b>On the final day of <a href="http://www.interop.com/">Interop NY 2008</a>, we conducted a second quick poll of attendees (<a href="http://blog.sciencelogic.com/interop-ny-virtualization-quick-poll/09/2008">check out the first poll on virtualization here</a>), asking which hypervisors were currently in use. In asking the question, we had certain assumptions – mainly that most people were currently using VMware – and that the real question here was to gauge how quickly Microsoft Hyper-V adoption was coming along. The results both confirmed what we thought and surprised us.
<p><b>The Results: </b>
<p><b><i>Which hypervisor(s) are you currently using?</i></b><i></i>
<ul>
<li><b>72%</b> VMware </li>
<li><b>17%</b> Using something else </li>
<li><b>9%</b> Hyper-V and VMware </li>
<li><b>2%</b> Hyper-V </li>
</ul>
<p>(based on 46 responses)
<p>So the VMware responses were in line with what we thought, although I’ve seen numbers up to 90% share of the market. And about 10% are at least playing with Hyper-V – pretty good numbers just a few months out from launch. But look at 17% using a hypervisor other than Hyper-V and VMware!
<p>We know from talking with people that several brought up Xen. I have to tell you that other than from media and analysts, we never hear about Xen (Citrix), which is why we didn’t include it in the survey as a specific selection. Perhaps it took the introduction of Hyper-V, with the attendant marketing juggernaut, to break people of the VMware-only habit. Xen couldn’t really carry that “heterogeneous” hypervisor environment message on its own, but now that Hyper-V is available, the genie’s out of the bottle. Bears watching.
<p>On another note: We were more successful in hanging onto our marbles on day two – people seemed more in tune to the poll and less focused on collecting giveaways than on day one! [Note: no attendees were <a href="http://blog.sciencelogic.com/interop-ny-virtualization-quick-poll/09/2008">irrevocably harmed</a> during the execution of the polls. :)] At Interop Vegas, May 17 – 19, 2009, we’ll be about a year out from Microsoft launching Hyper-V and will make sure to ask the same question then to track changes in hypervisor adoption.</p>
]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 14:30:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware-only habit">vmware-only habit</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/quick poll">quick poll</category>
      <category domain="http://securityratty.com/tag/hypervisor">hypervisor</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/hyper-v">hyper-v</category>
      <category domain="http://securityratty.com/tag/hyper-v pretty">hyper-v pretty</category>
      <category domain="http://securityratty.com/tag/vmware responses">vmware responses</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <source url="http://blog.sciencelogic.com/interop-ny-hypervisor-quick-poll/09/2008">Interop NY: Hypervisor Quick Poll</source>
    </item>
    <item>
      <title><![CDATA[Wakeup Call for Risk Management]]></title>
      <link>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</link>
      <guid>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</guid>
      <description><![CDATA[Blogger: Dan Blum
With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of risk management, it’s important to understand more about what happened, and then draw some parallels to our business risk management and&nbsp; IT risk management situations.</p>

<p>The risk management failure in the housing market and on Wall Street had multiple interdependent dimensions:</p>

<ul><li><strong>Mortgage lenders abandoned long standing prudent loan practices</strong>. They made too many loans that buyers might not be able to repay. Exotic instruments like ARMs, option ARMs, and interest only loans proliferated. In many cases, all pretense of lending standards were abandoned, so-called “liar loans” approved.</li>

<li><strong>Capital was grossly over-leveraged</strong>. Mortgage lenders and other financial services packaged loans into securities, which they sold to raise capital to support more lending. Real capital reserve requirements to back loans were reduced. Of course, if borrowers could not repay loans, all or parts of the derivative securities would become worthless.</li>

<li><strong>Risk was aggregated at Fannie Mae, Freddie Mac, and mortgage loan insurance companies</strong>. These companies bought or insured some mortgage loans, providing something of a backstop should loans fail. Government sponsored enterprises (GSEs) Fannie and Freddie in turn became over-leveraged and securities that they sold were in turn repackaged in the murky brew of mortgage-backed securities called collateralized debt obligations (CDOs) and other exotic instruments returning generous yields. </li>

<li><strong>Non-Caveat Emptor.</strong> Institutional wealth funds and financial services firms who should have known better bought securities that had been deliberately structured to obfuscate risk. They bought securities they didn’t understand with buried tranches of toxic subprime loans..</li></ul>

<p>It was a great Ponzi scheme – one that kept working as long as housing prices were going up; the recipients of subprime loans could always flip that house to the next buyer. Everyone made money. As Chuck Prince of Citigroup famously put it during <a href="http://search.ft.com/ftArticle?sortBy=gadatearticle&amp;queryText=chuck+prince+dancing&amp;y=0&amp;aje=true&amp;x=0&amp;id=070710000610&amp;ct=0&amp;page=6&amp;nclick_check=1">a July, 2007 interview</a>: “So long as the music is playing, you’ve got to keep dancing. We’re still dancing.” But one month later, the music stopped. Since then, Citigroup and other financial institutions have taken massive writeoffs with more to come. Wall Street titans like Bear Sterns, Lehman Brothers, Merrill Lynch, and AIG have fallen or been bought out.</p>

<p>What can we learn from this risk management debacle?</p>

<p>As business risk managers and investors, we should ask questions like these:</p>

<ul><li><strong>Does the executive incentive structure of the company encourage managers to dance around risk?</strong> Many Wall Street firms paid senior managers 5 times their salary in bonuses tied to annual growth alone.</li>

<li><strong>Is the company over-leveraged?</strong> Is it borrowing too much money and betting it on ventures with uncertain outcomes?</li>

<li><strong>Are financial models used for risk management realistic?</strong> Earlier, I described the mortgage market of the past few years as a Ponzi scheme, where risk management models must have assumed prices would keep rising. Unlike the dotcom boom whose demise many predicted, very few in the industry foresaw the sharp declines to come in housing prices and sales volumes. Historically, the U.S. housing market has been a steadily rising one, but on the other hand the 2000s saw unprecedented rates of price increases. In reality, what goes up must come down. </li>

<li><strong>Has your company’s risk council ever performed worst case scenario analysis and built adequate reserves?</strong> In the days before economics emerged as a would-be “hard” deterministic science, business leaders may have been more cautious, more aware of and more accepting of uncertainty. Events like the Great Tulip Bubble came once in decades or centuries – not every few years. Note that legendary investor George Soros has proposed a Theory of Reflexivity that, if true, helps explain the recent extremes of boom and bust cycles. This theory holds that market participants model market behaviors based on self-interest, and for a time, their manipulations change the reality of the market – until gravitational forces bring it back to earth. Has the music of ephemeral success played to the backbeat of deterministic-sounding economic models gone to your heads and infected your risk management models? </li>

<li><strong>Are cost cutting efforts pursued blindly?</strong> Outsourcing and other forays into treacherous global waters may be giving away the crown jewels. Smart companies cut costs, but they do it in smart ways. Smart companies think like intelligence agencies as they parcel out work to different partners with varying levels of dependability, and they check on those partners.</li></ul>

<p>Risk management failures can also occur at the more technical level of IT security. As IT risk managers, we might ask questions like these:</p>

<ul><li><strong>Are the accounting and financial systems your IT department supports under adequate control?</strong> As Fred Cohen wrote in <a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=750">one of our documents</a>: “Many companies use computers to manage financial systems, and despite the Sarbanes-Oxley Act (SOX) claims about accounts being properly kept, there are many attacks on financial systems that remain. For example, most of the largest financial systems in the world running on common financial databases do not use <a href="http://en.wikipedia.org/wiki/Double-entry_bookkeeping">double-entry bookkeeping</a> and are thus susceptible to all manner of frauds by insiders.” We find it troubling that a prudent control dating back to the 12th century is going out of style in the name of convenience and cost cutting. Kind of like credit checking became anachronistic during the housing bubble, eh?</li>

<li><strong>Is the “separation” in your “separation of duty” (SoD) for real?</strong> Sure the SOX auditors are looking for SoD, and maybe you have different administrators with different accounts maintaining different systems or functions. But when they say Western civilization may be but one weak password from collapse they’re not lying. Look what happened to Sarah Palin’s email account! Weak and straggly SoD is a problem across all critical IT systems where deperimiterization and server consolidation may be bringing down protective barriers, identity management is weak, and strong process controls (e.g., where two people must sign on, one perform a critical operation such as backbone router reconfiguration, and the second observe) abandoned in the name of expediency. </li>

<li><strong>Are risks being aggregated to unacceptable levels in centralized control systems?</strong> There are many ways that risks aggregate within enterprise IT infrastructures as we pursue automation and cost cutting. Network risks aggregate when centralized domain name system control is implemented. Application risks aggregate when common infrastructure is shared among applications. And enterprises aggregate platform risks when they use low-assurance endpoints, authentication, and directory systems with single sign-on to access large numbers of resources and don’t separate high consequence systems. </li>

<li><strong>Non-caveat emptor:</strong> Has IT security really done the worst case consequence analysis, attack graphs, and vulnerability analysis to know when putting more eggs in a supposedly stronger basket aggregates risks to an unacceptable level? Or are you depending only on vendor claims about some black box appliance equivalent of a risk-obfuscated CDO security? Caveat emptor (buyer beware) again! (The good news is we’ll keep talking about promoting vendor and product rating systems so you don’t have to do all the detailed product analysis yourself, but that’s another post.)</li></ul>

<p>There are many parallels between the monumental risk management failure in the financial markets, and the probable weaknesses in our day to day business risk management and IT risk management. Abandonment of prudent practices for profit; excessive leverage and centralization; ill-constructed risk analysis models; risk obfuscation; and a failure of caveat emptor seem to be common problems. Please take this as a wakeup call to sharpen up the risk management thinking, process, and execution.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/397240912" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 06:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management debacle">risk management debacle</category>
      <category domain="http://securityratty.com/tag/risk management failure">risk management failure</category>
      <category domain="http://securityratty.com/tag/failure">failure</category>
      <category domain="http://securityratty.com/tag/risk management realistic">risk management realistic</category>
      <category domain="http://securityratty.com/tag/business risk management">business risk management</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management situations">risk management situations</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/397240912/wakeup-call-for.html">Wakeup Call for Risk Management</source>
    </item>
    <item>
      <title><![CDATA[About the SDL Pro Network]]></title>
      <link>http://securityratty.com/article/dc28bc3dae82ee1f5322434291949577</link>
      <guid>http://securityratty.com/article/dc28bc3dae82ee1f5322434291949577</guid>
      <description><![CDATA[Hello all, Dave here
I expect that a number of you have seen the announcement and various press articles or Steve Lipner's Tuesday post about our launch of the SDL Threat Modeling Tool 3.0, the SDL...]]></description>
      <content:encoded><![CDATA[Hello all, Dave here... 
<P>I expect that a number of you have seen the <A href="http://www.microsoft.com/presspass/features/2008/sep08/09-16lipnersdl.mspx" mce_href="http://www.microsoft.com/presspass/features/2008/sep08/09-16lipnersdl.mspx">announcement</A> and various press articles or <A href="http://blogs.msdn.com/sdl/archive/2008/09/16/sdl-press-tour-announcements.aspx" mce_href="http://blogs.msdn.com/sdl/archive/2008/09/16/sdl-press-tour-announcements.aspx">Steve Lipner's Tuesday post</A> about our launch of the SDL Threat Modeling Tool 3.0, the SDL Optimization Model and the <A href="http://download.microsoft.com/download/0/E/9/0E9AC448-30B2-4451-9E23-46244AFABB7F/Microsoft%20SDL%20Pro%20Network%20_Fact%20Sheet.pdf" mce_href="http://download.microsoft.com/download/0/E/9/0E9AC448-30B2-4451-9E23-46244AFABB7F/Microsoft%20SDL%20Pro%20Network%20_Fact%20Sheet.pdf">SDL Pro Network</A>.&nbsp; Since I was intimately involved with the creation of the SDL Pro Network, I thought I'd write a few words about our objectives and chat a bit about the thinking behind our partner choices for the pilot phase.</P>
<P>So, what are we hoping to gain by creating a network of security consulting and training experts to work with customers who want to implement the SDL?&nbsp; Generally speaking, this question has a two-part answer:&nbsp; First, Microsoft is, and always will be a partner-driven company - we rely on the skills and capabilities of our partners to provide specialized services and broad geographic coverage for Microsoft products and services.&nbsp; Second, even though there are talented folks in the <A href="http://www.microsoft.com/services/microsoftservices/default.mspx" mce_href="http://www.microsoft.com/services/microsoftservices/default.mspx">Microsoft Services</A> organization, it's clear that we will need help from our partners to scale to meet the demand.&nbsp; I can't tell you how many times the folks on the SDL team have been approached by people - after an executive briefing, or a session at TechEd - asking for guidance in implementing SDL in their own organizations.&nbsp; When we look at the demand and pair it with the geographic diversity of our customer base, it's clear that a partner approach is the right answer.</P>
<P>Now a few words about the partners who will be participating in the pilot phase...</P>
<P>After the decision was made to work with partners on SDL delivery, we had two primary criteria that we had to address; partner quality, and manageability of the SDL Pro Network pilot. We have all seen instances where individuals or consulting organizations have represented themselves to the IT community as having security expertise when in reality the "experts for hire" were simply reading a page or two ahead of the customer in whatever security tome was "in vogue" at the time.&nbsp; </P>
<P>Based on those observations, it was clear that partner "quality" was a critical criterion. &nbsp;Fortunately for us, we didn't have to look far to satisfy our quality bar - many of the companies in the SDL Pro Network pilot have direct experience with executing portions of the SDL on <I>our</I> products, or have delivered services to Microsoft in a security context. Design reviews, code reviews, penetration testing, training&nbsp;and other tasks critical to SDL implementation were (and are) common fare for these folks.</P>
<P>Despite the customer demand for SDL that I alluded to above, starting with a small pilot was the right thing to do; a small group of trusted consultancies supports our imperative for quality and it allows us to pragmatically grow the SDL Pro Network as the market matures. &nbsp;As we continue to evolve and innovate with the SDL, we'll have a strong core of partners to help drive the software security message. </P>
<P>Will we grow the SDL Pro Network?&nbsp; The qualified answer is: "When the market demands it..." - there are a number of talented potential partners who meet the quality bar - and clearly, the need for security in software development will grow to demand additional talented specialists. However, it's our plan to begin with a small set of partners of known expertise, and then respond to growing demand as it materializes.</P>
<P>So there you have it - the nuanced beginning and bright future of the SDL Pro Network...&nbsp; I invite your comments, and encourage you to check in at the <A href="http://www.microsoft.com/sdl" mce_href="http://www.microsoft.com/sdl">SDL Portal</A> as we continue to build out the program</P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8958114" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 23:12:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/sdl pro network">sdl pro network</category>
      <category domain="http://securityratty.com/tag/sdl implementation">sdl implementation</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/sdl delivery">sdl delivery</category>
      <category domain="http://securityratty.com/tag/sdl optimization model">sdl optimization model</category>
      <category domain="http://securityratty.com/tag/quality">quality</category>
      <category domain="http://securityratty.com/tag/partner quality">partner quality</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/09/18/about-the-sdl-pro-network.aspx">About the SDL Pro Network</source>
    </item>
  </channel>
</rss>
