<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: coffee]]></title>
    <link>http://securityratty.com/tag/coffee</link>
    <description></description>
    <pubDate>Tue, 02 Sep 2008 10:55:47 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Is That a Coffee Table or a Munition?]]></title>
      <link>http://securityratty.com/article/bcc3ebc100f5b51c419148587e587e92</link>
      <guid>http://securityratty.com/article/bcc3ebc100f5b51c419148587e587e92</guid>
      <description><![CDATA[One of the standard software security prescriptions for the SDLC is to data classification and enforce least privilege. From a security perspective this sounds fantastic, especially on a whiteboard....]]></description>
      <content:encoded><![CDATA[<p>One of the standard software security prescriptions for the SDLC is to data classification and enforce least privilege. From a security perspective this sounds fantastic, especially on a whiteboard. When the rubber meets the real world road, things often turn out slightly different.&#0160;</p><br /><div>It turns out that it is hard to conduct business with excessive granularity.</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e201053619a7a7970b-pi" style="display: inline;"><a href="http://www.economist.com/displaystory.cfm?story_id=11965352"><img alt="D3408BB1" class="at-xid-6a00d83451c75869e201053619a7a7970b " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e201053619a7a7970b-320wi" /></a></a><span style="font-family: &#39;Trebuchet MS&#39;; ">
</span> <br /></div><br /><div>Here is an <a href="http://www.economist.com/displaystory.cfm?story_id=11965352">article</a> from The Economist on the challenges of space technology, commercialization and information sharing. This is widely applicable to corporate information security policies:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-weight: bold; line-height: normal; ">Gravity is not the main obstacle for America’s space business. Government is</span></p><p><span style="font-family: Verdana; line-height: normal; ">IN THE spring of 2006 Robert Bigelow needed to take a stand on a trip to Russia to keep a satellite off the floor. The stand was made of aluminium. It had a circular base and legs. It was, says the entrepreneur and head of Bigelow Aerospace in Nevada, “indistinguishable from a common coffee table”. Nonetheless, the American authorities told Mr Bigelow that this coffee table was part of a satellite assembly and so counted as a munition. During the trip it would have to be guarded by two security officers at all times.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal;"><br /></span><span style="font-family: Verdana; line-height: normal; ">Exporting technology has always presented a dilemma for America. The country leads the world in most technologies and some of these give it a military advantage. If export rules are too lax, foreign powers will be able to put American technology in their systems, or copy it. But if the rules are too tight, then it will stifle the industries that depend upon sales to create the next generation of technology.</span><br /><span style="font-family: Verdana; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal; ">It is a difficult balance to strike and critics charge that America has erred on the side of stifling. They claim that overly strict export controls have so damaged the space industry that America’s national security is now threatened by its dwindling leadership in space technology. The system, they complain, fails to distinguish between militarily sensitive hardware that should be controlled and widely available commercial technologies, such as lithium-ion batteries and solar cells. The zealous application of the export rules is the American space industry’s biggest handicap.</span></p></blockquote><div><span style="font-family: Verdana; font-weight: bold; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal; ">Read the whole thing its fascinating. So what started off as well intentioned asset protection eventually compromised the most important asset of all - strategic advantage.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal;">So what&#39;s a better model? I am partial to think about these sorts of problems as free trade agreements. Each integration point should have a set of policies, and enforcement mechanisms that also include compensating transactions.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal;">For example, did you know that in the US you can buy companies that trade on other exchanges through ADRs? You buy the ADR of say a French Telco which trades on a European exchange only you buy the ADR on the NYSE or Nasdaq. Then the French Telco issues you a dividend because you are a shareholder, but the French government withholds the dividend for foreign owners. Yet because there is a free trade agreement between the two countries, the US lets you write off the unreceived portion of the dividend on your taxes. (this may or may not be the case in US-France just an example). Anyway, its not a silver bullet but its an interesting strategy.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 09:40:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/coffee table">coffee table</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/american technology">american technology</category>
      <category domain="http://securityratty.com/tag/free trade agreement">free trade agreement</category>
      <category domain="http://securityratty.com/tag/trade">trade</category>
      <category domain="http://securityratty.com/tag/space technology">space technology</category>
      <category domain="http://securityratty.com/tag/french telco issues">french telco issues</category>
      <category domain="http://securityratty.com/tag/common coffee table">common coffee table</category>
      <category domain="http://securityratty.com/tag/information security policies">information security policies</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/is-that-a-coffee-table-or-a-munition.html">Is That a Coffee Table or a Munition?</source>
    </item>
    <item>
      <title><![CDATA[Arkansas Couple Sues McDonalds for Using Private Nude Photos in Online Ads]]></title>
      <link>http://securityratty.com/article/51fc8263d6d9f3cfbdbd51da0e6e8237</link>
      <guid>http://securityratty.com/article/51fc8263d6d9f3cfbdbd51da0e6e8237</guid>
      <description><![CDATA[When an Arkansas couple visited a local McDonalds in June, they got more than just their favorite burger. The couple apparently left their cell phone at the store, and even though it was returned,...]]></description>
      <content:encoded><![CDATA[<p>When an Arkansas couple visited a local McDonald&#8217;s in June, they got more than just their favorite burger. The couple apparently left their cell phone at the store, and even though it was returned, their personal information had already been compromised&#8211;and put online along with nude photos:</p>
<blockquote><p>Staff promised to keep the phone safely until [the couple came to retrieve it].</p>
<p>However, after Philip Sherman retrieved the phone, his wife began receiving threatening calls and messages from strangers. This caused the Shermans’ to become suspicious about what had occurred with the phone.</p>
<p>Soon afterward the Shermans’ found the private photos that Tina Sherman had sent to her husband’s phone published on the Internet along with their names, address, and phone numbers. Pictures of Tina Sherman were altered to contain McDonald’s franchise logos, along with slogans such as, “I’m lovin’ it,” and “Hot as McDonald’s coffee.” The photos were located on several different sites online, but have since been removed.</p></blockquote>
<p>The Shermans are suing for over 3 million dollars in damages, along with relocation costs.</p>
<p>Read the <a rel="nofollow" target="_blank" href="http://www.ecanadanow.com/news/curiosity/couple-to-sue-mcdonalds-after-racy-photo-stolen-20081125.html">full article</a> here.</p>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 09:38:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/arkansas couple">arkansas couple</category>
      <category domain="http://securityratty.com/tag/couple">couple</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/nude photos">nude photos</category>
      <category domain="http://securityratty.com/tag/photos">photos</category>
      <category domain="http://securityratty.com/tag/phone safely">phone safely</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/husbands phone">husbands phone</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/465465087/">Arkansas Couple Sues McDonalds for Using Private Nude Photos in Online Ads</source>
    </item>
    <item>
      <title><![CDATA[The Future of Ephemeral Conversation]]></title>
      <link>http://securityratty.com/article/1474b03de8a1d60cdf0aa28759ddce93</link>
      <guid>http://securityratty.com/article/1474b03de8a1d60cdf0aa28759ddce93</guid>
      <description><![CDATA[When he becomes president, Barack Obama will have to give up his BlackBerry. Aides are concerned that his unofficial conversations would become part of the presidential record, subject to subpoena and...]]></description>
      <content:encoded><![CDATA[<p>When he becomes president, Barack Obama will have to <a href="http://www.nytimes.com/2008/11/16/us/politics/16blackberry.html">give up</a> his BlackBerry.  Aides are concerned that his unofficial conversations would become part of the presidential record, subject to subpoena and eventually made public as part of the country's historical record.</p>

<p>This reality of the information age might be particularly stark for the president, but it's no less true for all of us.  Conversation used to be ephemeral.  Whether face-to-face or by phone, we could be reasonably sure that what we said disappeared as soon as we said it. Organized crime bosses worried about phone taps and room bugs, but that was the exception.  Privacy was just assumed.</p>

<p>This has changed.  We chat in e-mail, over SMS and IM, and on social networking websites like Facebook, MySpace, and LiveJournal.  We blog and we Twitter.  These conversations -- with friends, lovers, colleagues, members of our cabinet -- are not ephemeral; they <a href="http://www.schneier.com/essay-109.html">leave their own electronic trails</a>.</p>

<p>We know this intellectually, but we haven't truly internalized it.  We type on, engrossed in conversation, forgetting we're being recorded and those recordings might come back to haunt us later.</p>

<p>Oliver North learned this, way back in 1987, when messages he thought he had deleted were saved by the White House PROFS system, and then subpoenaed in the Iran-Contra affair.  Bill Gates learned this in 1998 when his conversational e-mails were provided to opposing counsel as part of the antitrust litigation discovery process.  Mark Foley learned this in 2006 when his instant messages were <a href="http://abcnews.go.com/WNT/BrianRoss/story?id=2509586">saved and made public</a> by the underage men he talked to.  Paris Hilton learned this in 2005 when her cell phone account was <a href="http://www.washingtonpost.com/wp-dyn/content/article/2005/05/19/AR2005051900711.html">hacked</a>, and Sarah Palin learned it earlier this year when her Yahoo e-mail account was hacked.  Someone in George W. Bush's administration learned this, and <a href="http://www.cnn.com/2007/POLITICS/04/13/white.house.email/index.html">millions of e-mails</a> went mysteriously and conveniently missing.</p>

<p>Ephemeral conversation is dying.</p>

<p>Cardinal Richelieu famously said, :If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged."  When all our ephemeral conversations can be saved for later examination, different rules have to apply.  Conversation is not the same thing as correspondence.  Words uttered in haste over morning coffee, whether spoken in a coffee shop or thumbed on a Blackberry, are not official pronouncements.  Discussions in a meeting, whether held in a boardroom or a chat room, are not the same as answers at a press conference.  And privacy isn't just about having something to hide; it <a href="http://www.schneier.com/essay-114.html">has enormous value</a> to democracy, liberty, and our basic humanity.</p>

<p>We can't turn back technology; electronic communications are here to stay and <a href="http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_controversy">even our voice conversations are threatened</a>.  But as technology makes our conversations less ephemeral, we need laws to step in and safeguard ephemeral conversation.  We need a comprehensive data privacy law, protecting our data and communications regardless of where it is stored or how it is processed. We need laws forcing companies to keep it private and delete it as soon as it is no longer needed.  Laws requiring ISPs to store e-mails and other personal communications are exactly what we don't need.</p>

<p>Rules pertaining to government need to be different, because of the <a href="http://www.schneier.com/essay-208.html">power differential</a>.  Subjecting the president's communications to eventual public review increases liberty because it reduces the government's power with respect to the people.  Subjecting our communications to government review decreases liberty because it reduces our power with respect to the government.  The president, as well as other members of government, need some ability to converse ephemerally -- just as they're allowed to have unrecorded meetings and phone calls -- but more of their actions need to be subject to public scrutiny.</p>

<p>But laws can only go so far.  Law or no law, when something is made public it's too late.  And many of us like having complete records of all our e-mail at our fingertips; it's like our offline brains.</p>

<p>In the end, this is cultural.</p>

<p>The Internet is the greatest generation gap since rock and roll.  We're now witnessing one aspect of that generation gap: the younger generation chats digitally, and the older generation treats those chats as written correspondence.  Until our CEOs blog, our Congressmen Twitter, and our world leaders send each other LOLcats &ndash; until we have a Presidential election where both candidates have a complete history on social networking sites from before they were teenagers&ndash; we aren't fully an information age society.</p>

<p>When everyone leaves a public digital trail of their personal thoughts since birth, no one will think twice about it being there.  Obama might be on the younger side of the generation gap, but the rules he's operating under were written by the older side.  It will take another generation before society's tolerance for digital ephemera changes.</p>

<p>This essay <a href="http://online.wsj.com/article/SB122722381368945937.html">previously appeared</a> on <ui>The Wall Street Journal</a> website (not the print newspaper), and is an update of <a href="http://www.schneier.com/essay-129.html">something I wrote previously</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=jPWiN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=jPWiN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=hlUTN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=hlUTN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 11:06:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ephemeral conversation">ephemeral conversation</category>
      <category domain="http://securityratty.com/tag/conversation">conversation</category>
      <category domain="http://securityratty.com/tag/safeguard ephemeral conversation">safeguard ephemeral conversation</category>
      <category domain="http://securityratty.com/tag/ephemeral">ephemeral</category>
      <category domain="http://securityratty.com/tag/ephemeral conversations">ephemeral conversations</category>
      <category domain="http://securityratty.com/tag/conversations">conversations</category>
      <category domain="http://securityratty.com/tag/generation">generation</category>
      <category domain="http://securityratty.com/tag/generation gap">generation gap</category>
      <category domain="http://securityratty.com/tag/public scrutiny">public scrutiny</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_future_of_e.html">The Future of Ephemeral Conversation</source>
    </item>
    <item>
      <title><![CDATA[Blogging from DeepSec 2008 in Vienna]]></title>
      <link>http://securityratty.com/article/295cd975846e9f76da4909bf958b0713</link>
      <guid>http://securityratty.com/article/295cd975846e9f76da4909bf958b0713</guid>
      <description><![CDATA[I am already back stateside from DeepSec and I am now flying to CSI 35th in DC; finally I had time to prepare my DeepSec blog post
First, I enjoyed DeepSec conference and I am grateful for the...]]></description>
      <content:encoded><![CDATA[<p>I am already back stateside from <a href="https://deepsec.net/schedule/">DeepSec</a> and I am now flying to <a href="http://www.csiannual.com">CSI 35th</a> in DC; finally I had time to prepare my <a href="https://deepsec.net/schedule/">DeepSec</a> blog post.</p>  <p>First, I enjoyed <a href="https://deepsec.net/schedule/">DeepSec</a> conference and I am grateful for the invitation to speak there. I love European conferences – and not only for having <em>infinitely</em> (with that being an <em>under</em>-statement of the year) superior coffee during breaks :-)&#160; In particular, I liked the audience for my presentation (slides will be posted here soon) and I think the audience liked my material and myself too :-)</p>  <p>What also impressed me a lot was Ivan Ristic speech, which was the second day keynote. He started by simply stating that ‘security industry has failed’ and that ‘a desktop is lost.’ His proof was in typical numbers like “75% of corporate systems are infected with at least 1 malware piece per system”, “1 million of malware types” and “25,000 unique malware samples a day seen.”&#160; However, he then broadened the subject and talked about how not only “a trusted desktop” is gone, but the entire world of “trust everything [on a system], all the time” is gone (his ideas were similar to what I planned to present in <a href="http://chuvakin.blogspot.com/2008/10/on-hitb-2008-conference.html">my HITB 2008 presentation</a> about “the 0wned world”)</p>  <p>I also like how he positioned all those “security user prompts” (in Vista and even before) as a proof that security technologies have failed and now we have to rely on the user to make security decisions (which will obviously fail as well since users are now fully conditioned to “see a chunk of technical mumbo-jumbo, then click OK”)</p>  <p>It was also interesting how he connected a lot of security failures to his “#1 reason: all programs run with all privileges of the user that runs them.”&#160; In fact, he illustrated it by reminding the audience that “everybody runs untrusted code every day today [web browser + Javascript, etc] while nobody did this 30 years ago.”&#160; He also beat up blackisting as an approach to security (but then again, everybody does it today :-)) - what was interesting that he opined that “we will spend the next 10 years proving that whitelisting will fail just as we spent previous 10 years proving that blacklisting fail.” His main point was that global “onslaught” of whitelisting and code signing will kill all sorts of useful things AND provide little security. </p>  <p>He then called for everybody to think about solving the hard, possibly non-sexy problems. This is the part where I could have used more details :-)</p>  <p>So, a fun speech (even though my telling of it is a bit jumbled… check out his slides whenever they are posted) – and a fun conference overall. Worth a 12 hour flight :-)</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=82qhN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=82qhN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=zSLaN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=zSLaN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=UnExN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=UnExN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/455651650" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 19:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security decisions">security decisions</category>
      <category domain="http://securityratty.com/tag/deepsec">deepsec</category>
      <category domain="http://securityratty.com/tag/security industry">security industry</category>
      <category domain="http://securityratty.com/tag/security user prompts">security user prompts</category>
      <category domain="http://securityratty.com/tag/security technologies">security technologies</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/deepsec conference">deepsec conference</category>
      <category domain="http://securityratty.com/tag/security failures">security failures</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/455651650/blogging-from-deepsec-2008-in-vienna.html">Blogging from DeepSec 2008 in Vienna</source>
    </item>
    <item>
      <title><![CDATA[Sleep more and live longer]]></title>
      <link>http://securityratty.com/article/9f762fb9b67dbcb8db8c308caea29d19</link>
      <guid>http://securityratty.com/article/9f762fb9b67dbcb8db8c308caea29d19</guid>
      <description><![CDATA[An interesting study was discussed on WTOP radio today

It seems that two Swedish doctors conducted a sleep study between 1987 and 2006. Their findings have been published in the New England School of...]]></description>
      <content:encoded><![CDATA[An interesting study was discussed on WTOP radio today.<br /><span id="fullpost"><br />It seems that two Swedish doctors conducted a sleep study between 1987 and 2006.  Their findings have been published in the New England School of Medicine's records.<br /></span><br />They discovered that 5% more heart attacks were recorded the Monday after clocks go forward.  At the same time, there were less heart attacks documented on the Monday following the weekend period when clocks go backward.<br /><br />The findings indicate the importance of getting a good night's rest.  When the clocks are set forward an hour, people lose an hour of sleep.  That was the time when more heart attacks were found to have occurred.<br /><br />In the field of security, it is not always possible to get enough rest.  Many times it is necessary to work a 12 hour shift and then drive home afterwards.  If this is the case, the officer/agent should make sure that he/she gets adequate rest when they are off duty.<br /><br />Unfortunately, there are other elements that add to a less than healthy lifestyle such as; drinking a lot of coffee, not eating balanced meals, lack of exercise, etc.  Armed with the knowledge that sleep is so vital to our health, it is more important now than ever to ensure that we are taking proper care of ourselves.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 00:16:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/heart attacks">heart attacks</category>
      <category domain="http://securityratty.com/tag/hour">hour</category>
      <category domain="http://securityratty.com/tag/hour shift">hour shift</category>
      <category domain="http://securityratty.com/tag/forward">forward</category>
      <category domain="http://securityratty.com/tag/rest">rest</category>
      <category domain="http://securityratty.com/tag/set forward">set forward</category>
      <category domain="http://securityratty.com/tag/clocks">clocks</category>
      <category domain="http://securityratty.com/tag/drive home">drive home</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <source url="http://www.thebulletproofblog.com/2008/10/sleep-more-and-live-longer.html">Sleep more and live longer</source>
    </item>
    <item>
      <title><![CDATA[How to set up a cross-platform network]]></title>
      <link>http://securityratty.com/article/da1c704e0be1bf4edcc34e034ca9d5c2</link>
      <guid>http://securityratty.com/article/da1c704e0be1bf4edcc34e034ca9d5c2</guid>
      <description><![CDATA[Your business--and the computers that power it--may have started with an idea that popped into your head while you sat in front of your laptop, freeloading off of the local coffee shop's wireless...]]></description>
      <content:encoded><![CDATA[Your business--and the computers that power it--may have started with an idea that popped into your head while you sat in front of your laptop, freeloading off of the local coffee shop's wireless network. But you can't work out of the Java Hut forever.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:611e197a85322f1fe64e58532ec9b94b:ImWTBhoFss6SkUUnxABuNGuO8Z%2F81mxpWRqqES%2BAS%2BqxEp5uMrQbcQCs9W9v3HJ3L15T3ZGtFoWv'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:52136fa7008316a63f8c5dc0da5f2629:9BQbyVvyONljXfi1kRWkXcVtK8tH7Flt7psNCIVx5AcVhNXhLoye5F1o10JY1JHjte0FMABCLscfHw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:51b3761f90efbb31909090f892b822ca:aKCXLjurwrI30V74qS6XNJnVAK2SkVybWp0Ugm9dS%2FxOCXYnluAi6AdS81vQx0e9Z8Cb9L8HQSmg1g%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:36c3be40504f376b9070c556dd16feda:KxIXdKglJXauwCyJzEmPWyi7W2bRDzrrBgqiyjCXiNiUT%2FRuwAVPn2KAB7aqm8vo2NbhOimjQjcsDw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=3dadfc9de11ebbc4fcb4beeabb3c5b05" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=3dadfc9de11ebbc4fcb4beeabb3c5b05" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 01:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/java hut forever">java hut forever</category>
      <category domain="http://securityratty.com/tag/local coffee shop">local coffee shop</category>
      <category domain="http://securityratty.com/tag/wireless network">wireless network</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/head">head</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/power">power</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=3dadfc9de11ebbc4fcb4beeabb3c5b05">How to set up a cross-platform network</source>
    </item>
    <item>
      <title><![CDATA[On Being Informative, or Seeing Through The Fog]]></title>
      <link>http://securityratty.com/article/525775c15c5a11217da6325a35c96ec8</link>
      <guid>http://securityratty.com/article/525775c15c5a11217da6325a35c96ec8</guid>
      <description><![CDATA[UPDATE: @MYRCURIAL from the great site Liquidmatrix says that I need to post the following warning
YOU MAY NOT WANT TO PROCESS THIS PRIOR TO YOUR 11TH CUP OF COFFEE

Carrying on from yesterdays post a...]]></description>
      <content:encoded><![CDATA[<p>==================================</p>
<p>UPDATE:  @MYRCURIAL from the great site <strong><a href="http://www.liquidmatrix.org/blog/">Liquidmatrix</a></strong> says that<strong> <a href="http://twitter.com/myrcurial/status/980493800">I need to post the following warning</a></strong>:</p>
<p><span class="entry-content"> YOU MAY NOT WANT TO PROCESS THIS PRIOR TO YOUR 11TH CUP OF COFFEE</span></p>
<p>==================================</p>
<p>Carrying on from yesterday&#8217;s post a bit, I&#8217;m happy to admit that Chris&#8217; poem is right: we don&#8217;t have nearly the information we need now when we&#8217;re supposed to have &#8220;control&#8221; over our assets, putting things in a hosted/asp/cloud/buzzword model ain&#8217;t going to help our quest for visibility. My intention was/is to show that you need visibility (in part one) and then today explain that unfortunately, that&#8217;s only half the picture.</p>
<p>Today&#8217;s follow-on is about the fact that whatever visibility we can contractually enforce (be it in the &#8220;cloud&#8221; or in our own perimeter) has to be informative (Amrit, this is why I was plugging you with those variance questions on Twitter yesterday).  That is, we can ask whatever IT department (ours, theirs, whomever) for all sorts of information, and maybe they&#8217;ll even give it to us.  But we&#8217;re not really ready to:</p>
<ul>
<li>Know what to ask for</li>
<li>Use it to create wisdom</li>
</ul>
<p>A really salient example of this from outside IT hit my browser this morning.  Now it&#8217;s not at all my intention to be political or endorse one candidate over another.  Those who know me know I&#8217;m fiercely independent.  But this morning there&#8217;s a headline on a well-read news website about how one candidate is now &#8220;+2&#8243; over another in a Gallup poll of &#8220;likely voters&#8221;. The source is <a href="http://www.gallup.com/poll/111124/Gallup-Daily-Likely-Voters-Traditional.aspx"><strong>here</strong></a>.</p>
<p><a href="http://www.gallup.com/poll/111124/Gallup-Daily-Likely-Voters-Traditional.aspx"><img class="alignnone" title="Gallup +2" src="http://www.riskmanagementinsight.com/media/images/weblog/gallup.jpg" alt="" width="597" height="452" /></a></p>
<p>That is a screen grab from Gallup&#8217;s website that shows the &#8220;+2&#8243;.   I have to ask - how informative is this information?  Part of the problem is that Gallup&#8217;s methods are hidden as some sort of &#8220;secret sauce&#8221; (their <strong><a href="http://www.gallup.com/poll/111268/How-Gallups-likely-voter-models-work.aspx">FAQ section</a></strong> doesn&#8217;t help much, either).  But regardless of the quality of the measurement, this &#8220;+2&#8243; has no context - we don&#8217;t really know what this information means with regards to an actual election.  Nor is there any predictive element (I hate the using the word predictive, but it&#8217;s common nomenclature - so there you go).  We don&#8217;t have what we need from this Gallup poll to create wisdom about the ability of either candidate to be elected.</p>
<p>Allow me show you what I mean by way of contrast.  Take a look at Nate Silver&#8217;s work at <strong><a href="http://www.fivethirtyeight.com/">http://www.fivethirtyeight.com/</a></strong>.  Now I&#8217;ve been long familiar with Nate due to his work in baseball.  He&#8217;s been at these sorts of &#8216;predictive&#8217; analytics around our shared passion: creating wisdom from baseball statistics.</p>
<p>What Nate is doing at 538 is applying that acumen from his baseball work to the political process.  He&#8217;s breaking down the vote not just on popularity among likely voters, but in the context of the electoral college, accounting for variance and uncertainty, running Monte Carlo simulations and taking into account all sorts of polling information.  The result is really quite amazing. Here&#8217;s just one graph he presents - it&#8217;s the most similar to the Gallup one above, but you should really visit the site to understand the difference in quality of information and to check out the predictive elements he creates.</p>
<p><a href="http://www.fivethirtyeight.com/"><img class="alignnone" src="http://www.riskmanagementinsight.com/media/images/weblog/538.jpg" alt="" width="376" height="377" /></a></p>
<p><strong>NOT ALL INFORMATION IS CREATED EQUAL</strong>, <em>AND NOT ALL  JUDGMENTS ARE CREATED EQUALLY</em></p>
<p>And take a look at the contrast, here:</p>
<p>On one hand you have Gallup giving us a &#8220;+2&#8243; advantage to a particular candidate.  Now Gallup themselves draws no conclusion but, as digested, how many readers do you think take this as evidence that the election is *really* close?</p>
<p>On the other hand, 538&#8217;s predictions show a 348/189 electoral college split, and one candidate winning 96% of the time in simulated elections.  That doesn&#8217;t seem close at all!</p>
<p><strong>RISK MANAGEMENT</strong></p>
<p>It is these predictive elements that we need in order to make better strategy and decisions.  I&#8217;ve been talking in the past about risk management&#8217;s inability to link current state to systemic causes, and this &#8220;context&#8221; is what predictive analytics provide.  We might have all sorts of visibility into our environment, and measurement of various amounts of variability that visibility gives us. But unless we have context to create wisdom, it&#8217;s all just, as Chris says, &#8220;machinations&#8221;.  <em><strong>We have to move beyond &#8220;+2&#8243;.<br />
</strong></em></p>
<p>So Cloud/Grid/Utility/ASP/TimeShare/Whatever you want to call it - security will have to clean up our own mess first before we can do a good job with or without a perimeter.  Once we can start moving beyond &#8220;+2&#8243; statements, then we can know what sort of visibility we require into an ability to Prevent, Detect, and Respond.</p>
]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 10:18:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gallup">gallup</category>
      <category domain="http://securityratty.com/tag/gallup poll">gallup poll</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/electoral college split">electoral college split</category>
      <category domain="http://securityratty.com/tag/predictive analytics provide">predictive analytics provide</category>
      <category domain="http://securityratty.com/tag/predictive analytics">predictive analytics</category>
      <category domain="http://securityratty.com/tag/electoral college">electoral college</category>
      <category domain="http://securityratty.com/tag/wisdom">wisdom</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=503">On Being Informative, or Seeing Through The Fog</source>
    </item>
    <item>
      <title><![CDATA[Gloria Jeans Coffee Website, gloriajeans.com, Hacked, Atleast 511 Customers Credit Crads Details Stolen]]></title>
      <link>http://securityratty.com/article/3a2ba3b8fb714ffe3875487c8f86aca2</link>
      <guid>http://securityratty.com/article/3a2ba3b8fb714ffe3875487c8f86aca2</guid>
      <description><![CDATA[Earlier this month, gloriajeans.com website was the subject of an attack that allowed an unknown person or persons to obtain the addresses and credit card numbers of 511 of the customers as they were...]]></description>
      <content:encoded><![CDATA[Earlier this month, gloriajeans.com website was the subject of an attack that allowed an unknown person or persons to obtain the addresses and credit card numbers of 511 of the customers as they were placing orders on the site. According to New Hampshire State Attorney General, Gloria Jeans Coffee (Gloria Jean&#8217;s) recently experienced a data [...]]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 17:49:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gloria jeans">gloria jeans</category>
      <category domain="http://securityratty.com/tag/gloria jeans coffee">gloria jeans coffee</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/unknown person">unknown person</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/gloriajeans">gloriajeans</category>
      <category domain="http://securityratty.com/tag/attorney">attorney</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <source url="http://cyberinsecure.com/gloria-jeans-coffee-website-gloriajeanscom-hacked-atleast-511-customers-credit-crads-details-stolen/">Gloria Jeans Coffee Website, gloriajeans.com, Hacked, Atleast 511 Customers Credit Crads Details Stolen</source>
    </item>
    <item>
      <title><![CDATA[RNC]]></title>
      <link>http://securityratty.com/article/be0e55d9cb445eec42568a38816bb728</link>
      <guid>http://securityratty.com/article/be0e55d9cb445eec42568a38816bb728</guid>
      <description><![CDATA[Yup, we have the RNC here in MN. Downtown is locked down pretty tight, you would need the combined powers of Chuck Norris and Bruce Schneier to even get a cup of coffee down there. Here is the round...]]></description>
      <content:encoded><![CDATA[<p>Yup, we have the RNC here in MN. Downtown is locked down pretty tight, you would need the combined powers of Chuck Norris and <a href="http://geekz.co.uk/schneierfacts/">Bruce Schneier</a> to even get a cup of coffee down there. Here is the round up from <a href="http://www.economist.com/blogs/freeexchange/2008/09/above_the_fold_251.cfm">The Economist&#39;s blog</a></p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal; ">You&#39;ll have to pardon me this morning if the round-up seems a bit off. I&#39;m still a little stunned at the spectacle of an arena full of (seemingly sober and sane) adults chanting, &quot;Drill, baby, drill&quot;.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal;"><br /></span><span style="font-family: Verdana; line-height: normal; ">So let&#39;s see, what&#39;s in the news? Well, last night Republicans trotted out a Massachusetts venture capitalist and governor, the former mayor of New York City, former executives of eBay and HP, and an Alaskan neophyte pol who as mayor of a small town delivered $4,000 in federal pork for every man, woman, and child, in railing against coastal elites and Washington politics, while supporting a candidate who&#39;s been in the Senate for 26 years.</span></p></blockquote>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 07:34:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts venture capitalist">massachusetts venture capitalist</category>
      <category domain="http://securityratty.com/tag/alaskan neophyte pol">alaskan neophyte pol</category>
      <category domain="http://securityratty.com/tag/washington politics">washington politics</category>
      <category domain="http://securityratty.com/tag/bruce schneier">bruce schneier</category>
      <category domain="http://securityratty.com/tag/rnc">rnc</category>
      <category domain="http://securityratty.com/tag/federal pork">federal pork</category>
      <category domain="http://securityratty.com/tag/drill">drill</category>
      <category domain="http://securityratty.com/tag/round-up">round-up</category>
      <category domain="http://securityratty.com/tag/pretty tight">pretty tight</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/rnc.html">RNC</source>
    </item>
    <item>
      <title><![CDATA[While I Was Out: Compendium of the Last Week's News]]></title>
      <link>http://securityratty.com/article/9b2e491a24c669b08b8cfdf0d0df0b47</link>
      <guid>http://securityratty.com/article/9b2e491a24c669b08b8cfdf0d0df0b47</guid>
      <description><![CDATA[You wouldn't listen, but continued to generate products, news stories, and analysis about wireless networking in my absence: Here's the run down of the last week or so's Wi-Fi and wireless stories....]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><strong>You wouldn't listen, but continued to generate products, news stories, and analysis about wireless networking in my absence:</strong> Here's the run down of the last week or so's Wi-Fi and wireless stories. (Yes, I enjoyed my time off.)</p>

<p><a href="http://www.informationweek.com/news/services/data/showArticle.jhtml?articleID=210200880"><strong>Fourth US airline to go Wi-Fi:</strong></a> Aircell says they have a fourth airline--after American, Delta, and Virgin America--on board for its in-flight Wi-Fi service. The aerial broadband provider's latest partner will be announced soon. Aircell's service went live in 15 American Airlines planes two weeks ago, and there's been a surprising lack of reporting from regular travelers or journalists since the big splash at the launch.</p>

<p><a href="http://seattlepi.nwsource.com/business/376308_software25.html"><strong>Microsoft, two universities research methods for better Wi-Fi handoff for vehicles:</strong></a> The researchers developed a method they call Vi-Fi, writes the Seattle Post-Intelligencer's Todd Bishop, which allows a system to maintain connections with several base stations at once, using a primary access point for traffic until a discontinuity is predicted or encountered. This allows seamless handoffs and continuous voice conversations. </p>

<p><a href="http://www.nytimes.com/2008/08/24/technology/24digi.html?_r=1&oref=slogin"><strong>Speaking of autos and Wi-Fi, concerns raised about Chrysler's in-car Wi-Fi option:</strong></a> Randall Stross wrote nearly two weeks ago in The New York Times about the problem of distraction. With the Internet at your fingertips, can you restrain yourself? The only problem with the humorous and accurate analysis is that millions of business travelers have 3G access via laptop cards already, so you'd think we'd already be seeing the bad effects of automotive area networks.</p>

<p><a href="http://www.omaha.com/index.php?u_page=2798&u_sid=10415031"><strong>A Wi-Fi booster can't post availability signs on highway:</strong></a> The Nebraska town of Louisville has free Wi-Fi downtown, and wanted to post "Visitor Wi-Fi" on a highway sign as another amenity. The state highway department has a policy that doesn't allow the promotion of Wi-Fi, because they believe they'd be inundated. A resident who runs a local Internet firm installed his own signs on the highway; the roads department removed them; he remounted them; they were removed again. The idea of zoning and mounting a billboard apparently hasn't come to the city officials' minds (or perhaps they're prohibited).</p>

<p><a href="http://www.lisburntoday.co.uk/news/PRIMARY-PULLS-PLUG-ON-WIFI.4435678.jp"><strong>The folks spreading misinformation about Wi-Fi health effects cause Ulster school to disable network:</strong></a> I can understand why non-technical folks might think that Wi-Fi has been proven to be unsafe, given the kind of information that's available on the Internet about wireless safety. While there are ongoing studies about the safety of cellular signals--and I'm convinced at this point there's no increased risk to an adult's health by using a cell phone--there is no specific and credible research linked to Wi-Fi, which broadcasts signals at a far lower level than a cell phone, most of the time in most uses.</p>

<p><a href="http://blog.seattlepi.nwsource.com/thebigblog/archives/147374.asp"><strong>Washington state shuts down rest-area Wi-Fi:</strong></a> The $3 for 15 minutes, $7 per day, or $30 per month Wi-Fi service at 28 of Washington's 42 rest areas has been turned off after a year for lack of use. Figures. The fees charged by Parsons and Road Connect aren't unreasonable for a nationally scoped plan, but are ridiculous for limited use. States should either bite the bullet and offer these service for free, partner with national roaming operators who can resell service into large networks of business travelers, or use ads to support the service. Highways in remote areas can typically pick up cell data networks, and ongoing costs should be minimal to operate such networks.</p>

<p><a href="http://www.techworld.com/news/index.cfm?RSS&NewsID=103501"><strong>IEEE approves fast-roaming standard, 802.11r:</strong></a> This new standard is designed to improve the handoff of devices between base stations. This is accomplished in part by allowing base stations to communicate security and quality of service information so that a VoIP over WLAN phone can immediately reassociate without the delay of authentication and other handshaking.</p>

<p><a href="http://www.marketwatch.com/news/story/freefi-networks-releases-figures-wi-fi/story.aspx?guid={5252EF0E-2563-42B7-8A95-2F893580E6F6}&dist=hppr"><strong>Denver airport sees 7,000 connections on a single day last week due to Democratic National Convention:</strong></a> FreeFi released the usage figures recently to show how their service is operating. The network started with about 600 daily users when the switchover from fee to free happened 10 months ago, and now carries about 3,500 daily connections.</p>

<p><a href="http://www.centredaily.com/living/travel/story/804003.html"><strong>Coffee Bean & Tea Leaf goes free:</strong></a> The chain of about 700 cafes will have free Wi-Fi installed by now in all its company-owned stores (about 300).</p>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 10:55:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/in-car wi-fi option">in-car wi-fi option</category>
      <category domain="http://securityratty.com/tag/wi-fi handoff">wi-fi handoff</category>
      <category domain="http://securityratty.com/tag/free wi-fi downtown">free wi-fi downtown</category>
      <category domain="http://securityratty.com/tag/month wi-fi service">month wi-fi service</category>
      <category domain="http://securityratty.com/tag/rest-area wi-fi">rest-area wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi booster">wi-fi booster</category>
      <category domain="http://securityratty.com/tag/in-flight wi-fi service">in-flight wi-fi service</category>
      <source url="http://wifinetnews.com/archives/008428.html">While I Was Out: Compendium of the Last Week's News</source>
    </item>
  </channel>
</rss>
