<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: colorado]]></title>
    <link>http://securityratty.com/tag/colorado</link>
    <description></description>
    <pubDate>Mon, 21 Jul 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Colorado state Web site dishes out SSNs of CEOs, other top execs]]></title>
      <link>http://securityratty.com/article/38389f9466aa560a5a32928c8d9d1b56</link>
      <guid>http://securityratty.com/article/38389f9466aa560a5a32928c8d9d1b56</guid>
      <description><![CDATA[A privacy advocate says the Web site of the Colorado secretary of state is making available the Social Security numbers and other personal data of CEOs, company chairmen, board members and other...]]></description>
      <content:encoded><![CDATA[A privacy advocate says the Web site of the Colorado secretary of state is making available the Social Security numbers and other personal data of CEOs, company chairmen, board members and other senior executives at some of the country's largest companies.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6e4e0b54be3ae09e48749460614c729c:4jva6ma4aV7%2B7YYJF2VB2Av8M0ah7JGjUu7frzZe8yUC8ktW9NKvUEPYPzt72ZVJDVzr72%2Frqyu4'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7a3412e315a2dfcb11747659f2ef3de6:bV1uCDg2YkDeDVv5IHULrF8N2VYAEoflso3yPZ2870gCsBtl9GF5zjKXKUYJo7SSxIwbu%2FqzbrIjmQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:dfa227d60d11c299b2c72172e57dc4d4:KLAma7RJGlnQriIZlqUch5MXLRMFOOVQDt5TYJgCzjhxOvIuIlGQaQWYbHrw6MheCn7lAL2MCxk5yw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1266008cbbdfe4dc785afe6fb347590f:BnB1rOVgXrRAIDVT60O7vm39pRf7v8pW9XWGzVulMfbZPQX%2BOdmKoBDoTmBnvRi4WENXdYcK%2FRioPg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=1cf7d71890ccfb26dd1aaccac2e44ca7" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=1cf7d71890ccfb26dd1aaccac2e44ca7" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/senior executives">senior executives</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/ceos">ceos</category>
      <category domain="http://securityratty.com/tag/colorado secretary">colorado secretary</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/board">board</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=1cf7d71890ccfb26dd1aaccac2e44ca7">Colorado state Web site dishes out SSNs of CEOs, other top execs</source>
    </item>
    <item>
      <title><![CDATA[Colorado state Web site dishes out SSNs of top execs]]></title>
      <link>http://securityratty.com/article/dda6487c212c8e71f2a2cbf6a4923f96</link>
      <guid>http://securityratty.com/article/dda6487c212c8e71f2a2cbf6a4923f96</guid>
      <description><![CDATA[The Web site of the Colorado Secretary of State is making available the Social Security numbers and other personal data of numerous CEOs, company chairmen, presidents, board members and other senior...]]></description>
      <content:encoded><![CDATA[The Web site of the Colorado Secretary of State is making available the Social Security numbers and other personal data of numerous CEOs, company chairmen, presidents, board members and other senior executives at some of the country's largest companies, a privacy advocate said.]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/senior executives">senior executives</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/numerous ceos">numerous ceos</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/colorado secretary">colorado secretary</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/board">board</category>
      <source url="http://www.networkworld.com/news/2008/100808-colorado-state-web-site-dishes.html?fsrc=rss-security">Colorado state Web site dishes out SSNs of top execs</source>
    </item>
    <item>
      <title><![CDATA[The Resolution Will Not Be Televised]]></title>
      <link>http://securityratty.com/article/aafbdad14f05dbfb9ed7011d64981e7f</link>
      <guid>http://securityratty.com/article/aafbdad14f05dbfb9ed7011d64981e7f</guid>
      <description><![CDATA[Wow






1-meter simulated resolution from aerial imagery of Colorado Capitol and Downtown Denver









































5-meter simulated resolution from...]]></description>
      <content:encoded><![CDATA[<p><a href="http://radar.oreilly.com/2008/09/watch-geoeye-1-launch-tomorrow.html">Wow</a></p><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px; "></span><br /><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e555056e368834-pi" style="float: left;"><img alt="200809051615" class="at-xid-6a00d83451c75869e200e555056e368834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e555056e368834-320wi" style="margin: 0px 5px 5px 0px;" /></a>
<p>
</p></div>
<p></p><br />
1-meter simulated resolution from aerial imagery of Colorado Capitol and Downtown Denver
 <a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e554e8103f8833-pi" style="float: left;"><img alt="200809051616" class="at-xid-6a00d83451c75869e200e554e8103f8833 selected " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e554e8103f8833-320pi" style="margin: 0px 0px 5px 5px;" title="200809051616" /></a>
 <br />

</div><br /><br /><br /><br /><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><div><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 19px;"><br /></span></div><p>.5-meter simulated resolution from <a href="http://geoeye.com/CorpSite/">GeoEye</a></p>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 19:59:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/resolution">resolution</category>
      <category domain="http://securityratty.com/tag/downtown denver">downtown denver</category>
      <category domain="http://securityratty.com/tag/colorado capitol">colorado capitol</category>
      <category domain="http://securityratty.com/tag/aerial imagery">aerial imagery</category>
      <category domain="http://securityratty.com/tag/5-meter">5-meter</category>
      <category domain="http://securityratty.com/tag/1-meter">1-meter</category>
      <category domain="http://securityratty.com/tag/geoeye">geoeye</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/the-resolution-will-not-be-televised.html">The Resolution Will Not Be Televised</source>
    </item>
    <item>
      <title><![CDATA[Senator Obama's security concerns]]></title>
      <link>http://securityratty.com/article/ce6e50c5b4d179e0d726e937841e4dde</link>
      <guid>http://securityratty.com/article/ce6e50c5b4d179e0d726e937841e4dde</guid>
      <description><![CDATA[It appears as if the authorities in Colorado are trying to down play the reported assassination plot of Senator Obama. Question is; how real was it


It would certainly appear that the suspects were...]]></description>
      <content:encoded><![CDATA[It appears as if the authorities in Colorado are trying to down play the reported assassination plot of Senator Obama.  Question is; how real was it?<br /><span id="fullpost"><br /> <br />It would certainly appear that the suspects were preparing for something out of the ordinary as they were reported as having a bullet proof vest and a high powered rifle with telescopic scope in their possession when apprehended.  The fact that one of the them was described by his cohort as a "white supremist" who did not believe that a man of color could be the President of the U.S.A. is surely telling.<br /><br />These three criminals were caught in much the same manner as the domestic terrorist, Timothy McVeigh.  A dilgent policeman was doing his duty and pulled over the first suspect on a traffic stop.  Some may call that luck, but having been a former Law Enforcement officer, I look upon it as good Police work.  Many others might have not noticed the one little sign that made that officer suspicious and prompted him to check out the driver of the van.<br /><br />That is why security can never rest.  Whether it is foiling a potential terrorist plot or finding a child who has been abducted, we must always remain vigilant.  It is a shame that there are those who believe a man is inferior based upon the color of his skin.  It is even more terrible to realize that such a person would be willing to kill another based on racial hatred.  <br /><br />Unfortunately, this is a sad fact of life and steps need to be taken to thwart those disturbed individuals.  Was this latest episode a non-event or by dismissing it are we attempting to sweep the shame of racism under the carpet?  I for one, don't think that we should take these warnings lightly.  Afterall, it has been 45 years and people still debate the assassination of JFK.  We still hear it being said that Lee Harvey Oswald was incapable of carrying out the killing himself.<br /><br />I recently watched a documentary on the assassination of Robert Kennedy, produced on the 40th anniversary of his death.  When interviewed, the brother of the asssassin claims that his brother was too nice a guy to do something so awful. The fact of the matter however, is that both Kennedys were brutally gunned down.  I am sure it is something that nobody ever wants to see repeated.  <br /><br />Let us hope that whomever succeeds as President in November has a long and healthy Presidency and helps to allevitae the problems that have been piling up.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 29 Aug 2008 14:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/assassination">assassination</category>
      <category domain="http://securityratty.com/tag/senator obama">senator obama</category>
      <category domain="http://securityratty.com/tag/assassination plot">assassination plot</category>
      <category domain="http://securityratty.com/tag/potential terrorist plot">potential terrorist plot</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <category domain="http://securityratty.com/tag/law enforcement officer">law enforcement officer</category>
      <category domain="http://securityratty.com/tag/inferior based">inferior based</category>
      <category domain="http://securityratty.com/tag/lee harvey oswald">lee harvey oswald</category>
      <category domain="http://securityratty.com/tag/bullet proof vest">bullet proof vest</category>
      <source url="http://www.thebulletproofblog.com/2008/08/senator-obamas-security-concerns.html">Senator Obama's security concerns</source>
    </item>
    <item>
      <title><![CDATA[When the shoe is on the other foot]]></title>
      <link>http://securityratty.com/article/70ffaafe90e77eabd152a83a018b3487</link>
      <guid>http://securityratty.com/article/70ffaafe90e77eabd152a83a018b3487</guid>
      <description><![CDATA[About to head over to morning sessions of Black Hat (OK, it started at 8am, but that is just an uncivil time for Las Vegas). Before I do, let me give you a quick recap of my first night on Black Hat....]]></description>
      <content:encoded><![CDATA[<p>About to head over to morning sessions of Black Hat (OK, it started at 8am, but that is just an uncivil time for Las Vegas).  Before I do, let me give you a quick recap of my first night on Black Hat. I didn’t get in until 10pm and got to my hotel about 11.  Looked up a few security twits and saw that Mitchell Ashley, Martin McKeay, JJ and Ryan Russell were at the Cleopatra Barge at Caesars.  I headed over there and met up.  The night was on!</p>  <p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/pussycat-dolls-lounge.jpg"><img title="pussycat-dolls-lounge" style="border-right: 0px; border-top: 0px; margin: 5px 5px 5px 10px; border-left: 0px; border-bottom: 0px" height="192" alt="pussycat-dolls-lounge" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/pussycat-dolls-lounge_thumb.jpg" width="240" align="right" border="0"></img></a> We had a quick drink and then headed over to the club Pure, where Fortify was having a party.  Some how or another JJ, Ryan and I got to the VIP entrance and were headed in.  Martin had to go upstairs and change out of his shorts.  Mitchell that Colorado country bumpkin was not allowed in because he was wearing sandals.  What to do?  Leave Mitchell outside, all of us not go in? I went back to my old club hopping days for the answer. I went  in with JJ.  Went to the bar, took off my shoes and gave them to JJ.  While I stood there in socks, she brought the shoes out to Mitchell, who put them on and got in the club.  Watching JJ sneak out the shoes and Mitchell walk in holding his sandals was pretty funny.   But it worked.  We got away from the Fortify party as it was way too crowded.  We found ourselves in my favorite part of Pure, the Pussycat Doll Lounge.  Five minutes later out came the Pussycats.  They put on a very hot show that had us all dancing and shouting.  </p>  <p>After that we went to my usual late night spot at Black Hat, the Augustus cafe for breakfast.  We met up with the Mogul and Hoff, who joined us.  By now it was like 2:30am Vegas time (5:30 east coast time) and it was time for bed.  I am staying at Paris, so had a nice walk but they did give me a LeMans suite which is very nice.  I still get a little confused by rooms with bidets, but it is fun.</p>  <p>Well off to Black Hat for some learning!</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=27Z8hl"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=27Z8hl" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=jgRz8K"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=jgRz8K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=5ikxYK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=5ikxYK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=EuLGtK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=EuLGtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Se9E4K"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Se9E4K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=jXFKVk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=jXFKVk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Y2sUOk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Y2sUOk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/357490562" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 06:16:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/uncivil time">uncivil time</category>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/mitchell">mitchell</category>
      <category domain="http://securityratty.com/tag/east coast time">east coast time</category>
      <category domain="http://securityratty.com/tag/mitchell walk">mitchell walk</category>
      <category domain="http://securityratty.com/tag/mitchell ashley">mitchell ashley</category>
      <category domain="http://securityratty.com/tag/pure">pure</category>
      <category domain="http://securityratty.com/tag/club pure">club pure</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/357490562/when-the-shoe-i.html">When the shoe is on the other foot</source>
    </item>
    <item>
      <title><![CDATA[Friday Squid Blogging: Burning Squid]]></title>
      <link>http://securityratty.com/article/24011ae7f556662f88a57230d56a7b84</link>
      <guid>http://securityratty.com/article/24011ae7f556662f88a57230d56a7b84</guid>
      <description><![CDATA[At the June Apogaea regional Burning Man event in Colorado, they burned a wooden/cloth giant squid. Before the burn, participants could crawl into the base of the body and turn a massive kaleidoscope...]]></description>
      <content:encoded><![CDATA[<p>At the June <a href="http://www.apogaea.com/">Apogaea</a> regional Burning Man event in Colorado, they burned a wooden/cloth giant squid.  Before the burn, participants could crawl into the base of the body and turn a massive kaleidoscope with sun shining in the top.   (<a href="http://www.flickr.com/search/?q=apogaea+squid">Pictures</a> of the squid and its demise.  A <a href="http://www.flickr.com/photos/luki_pa/2592726418/in/pool-apogaea">picture</a> from the inside.)</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=2w5TRJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=2w5TRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=2J4JqJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=2J4JqJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 12:10:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/squid">squid</category>
      <category domain="http://securityratty.com/tag/woodencloth giant squid">woodencloth giant squid</category>
      <category domain="http://securityratty.com/tag/june apogaea regional">june apogaea regional</category>
      <category domain="http://securityratty.com/tag/massive kaleidoscope">massive kaleidoscope</category>
      <category domain="http://securityratty.com/tag/body">body</category>
      <category domain="http://securityratty.com/tag/participants">participants</category>
      <category domain="http://securityratty.com/tag/demise">demise</category>
      <category domain="http://securityratty.com/tag/inside">inside</category>
      <category domain="http://securityratty.com/tag/picture">picture</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/friday_squid_bl_132.html">Friday Squid Blogging: Burning Squid</source>
    </item>
    <item>
      <title><![CDATA[SSO Summit Wrap Up]]></title>
      <link>http://securityratty.com/article/f95d236237bbd04ba2c6565ed7ec3dca</link>
      <guid>http://securityratty.com/article/f95d236237bbd04ba2c6565ed7ec3dca</guid>
      <description><![CDATA[More notes from SSO Summit - to recap I can't stress enough how a 50-200 person conference comprised of around 50-60% enterprise folk (instead of just vendors and *cough* consultants) is ideal. Real,...]]></description>
      <content:encoded><![CDATA[<div>More notes from <a href="http://">SSO Summit</a> - to recap I can't stress enough how a 50-200 person conference comprised of around 50-60% enterprise folk (instead of just vendors and *cough* consultants) is ideal. Real, in depth conversations instead of just "where is the party" a la RSA. Also, this conference has a laser focus on SSO, so all 150 of us are able to look through the prism from lots of angles.</div><br><div>Some additional takeaways<a href="http://vquill.com/"></a></div><br><div><a href="http://vquill.com/">Dave Kearns</a> has serious moderator skillz. </div><br><div>You can tell all the Mac users because they have to have their laptops plugged in at all times (Mr. Jobs paging <a href="http://www.businessweek.com/technology/content/jan2006/tc20060109_432937.htm">Mr. Clayton Christensen</a>)<a href="http://www.xmlgrrl.com/blog/"></a></div><br><div><a href="http://www.xmlgrrl.com/blog/">Eve Maler</a> can really sing</div><br><div>One of the prettiest drives through Colorado is <a href="http://maps.google.com/maps?f=d&amp;hl=en&amp;geocode=10530055749613058705,39.629820,-106.417830%3B5743054738505757598,39.099384,-106.292979%3B17892979726654583514,39.186180,-106.809980%3B853448514458598310,39.365980,-107.052220%3B9267843558044898835,38.885840,-107.587610&amp;saddr=idaho+springs,+co&amp;daddr=39.612036,-105.913696+to:I-70+W+%4039.629820,+-106.417830+to:US-24+%4039.099384,+-106.292979+to:CO-82%2FE+Cooper+Ave+%4039.186180,+-106.809980+to:CO-82+%4039.365980,+-107.052220+to:CO-133+%4038.885840,+-107.587610+to:Mesa+Verde,+Dolores,+CO&amp;mra=dpe&amp;mrcr=0&amp;mrsp=1&amp;sz=10&amp;via=1,2,3,4,5,6&amp;doflg=ptm&amp;sll=39.298174,-105.578613&amp;sspn=0.664203,0.954437&amp;ie=UTF8&amp;ll=39.298174,-105.578613&amp;spn=0.664203,0.954437&amp;z=10">here</a></div><br><div>I did my presentation on Security Token Servers today. Bob Brandt from 3M spoke on Federation at 3M, its quite interesting to think about the mix of all these technologies the same way 3M's products are composed from a grid of technologies. I see STS playing role here, enabling us to get interop across multiple token types. Bob also mentioned that the business doesn't _ask_ for SSO any more; they expect it. He mentioned (and I have seen the same) much greater SAML adoption and awareness by customers and partners. And I quite liked his quote - "If you are a SAAS vendors and you  are not supporting SAML you won't be in business very long."</div><br><div>Kent Beck says programs are not things, they are shadows of communities. If you look at a big vendors' IDENTITY AND ACCESS MANAGEMENT SUITE - its not a cohesive product so much as a shadow of the big vendors' Visio org chart. Ping's SSO community is fast, light and Ninja; SSO functionality enabling real pros to get stuff done for real use cases. </div><br><div>Its a lot of fun to be at a 1.0 conference, I am pretty sure this will be 2x-3x next year.</div>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 09:41:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sso">sso</category>
      <category domain="http://securityratty.com/tag/sso summit">sso summit</category>
      <category domain="http://securityratty.com/tag/sso functionality">sso functionality</category>
      <category domain="http://securityratty.com/tag/sso community">sso community</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/saas vendors">saas vendors</category>
      <category domain="http://securityratty.com/tag/person conference">person conference</category>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/real">real</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/sso-summit-wrap-up.html">SSO Summit Wrap Up</source>
    </item>
    <item>
      <title><![CDATA[Fugitive spammer dead in apparent murder-suicide]]></title>
      <link>http://securityratty.com/article/5eb33436e1926a40842af2cdf1f91a5d</link>
      <guid>http://securityratty.com/article/5eb33436e1926a40842af2cdf1f91a5d</guid>
      <description><![CDATA[Spammer and escaped convict Eddie Davidson shot his wife and three-year-old daughter before turning the gun on himself Thursday night in Bennet,...]]></description>
      <content:encoded><![CDATA[Spammer and escaped convict Eddie Davidson shot his wife and three-year-old daughter before turning the gun on himself Thursday night in Bennet, Colorado.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=OBwgMQ"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=OBwgMQ" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/345461372" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 07:29:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spammer">spammer</category>
      <category domain="http://securityratty.com/tag/thursday night">thursday night</category>
      <category domain="http://securityratty.com/tag/three-year-old daughter">three-year-old daughter</category>
      <category domain="http://securityratty.com/tag/wife">wife</category>
      <category domain="http://securityratty.com/tag/bennet">bennet</category>
      <category domain="http://securityratty.com/tag/gun">gun</category>
      <category domain="http://securityratty.com/tag/colorado">colorado</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/345461372/article.do">Fugitive spammer dead in apparent murder-suicide</source>
    </item>
    <item>
      <title><![CDATA[SSO Summit Day One Morning Session]]></title>
      <link>http://securityratty.com/article/500327e2eca382c04451c330dcc1e875</link>
      <guid>http://securityratty.com/article/500327e2eca382c04451c330dcc1e875</guid>
      <description><![CDATA[I am at the SSO Summit , high in the Colorado mountains (9200 feet elevation to be exact), the I-70 West sign is one of my favorite road signs. Ping Identity has done a great job putting this...]]></description>
      <content:encoded><![CDATA[<div>I am at the <a href="http://www.ssosummit.com/">SSO Summit</a>, high in the Colorado mountains (9200 feet elevation to be exact), the I-70 West sign is one of my favorite road signs. <a href="http://www.pingidentity.com/">Ping Identity</a> has done a great job putting this together. It is the perfect size around 125 people. Most of the best conferences I have been to have been around 60-150 people. There are a *lot* of enterprises involved here. </div><br><div>John Haggard who has an extensive background in SSO and lately is at Passfaces kicked off the sessions with a SSO history talk. Going through a lot of mainframe centric SSO protocols from the 80s and 90s, I am no expert in these areas and it was fascinating to see the way things vacillated between strength and weakness of SSO protocols.</div><br><div>A couple of points from the presentation:</div><br><div><blockquote><p>The history of SSO is a story of extreme complexities, compromises, vulnerabilities and unintended consequences.</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>SSO is a story of one simple objective - to spin off units of computation work to execute on behalf of an authenticated user without requiring the original user's password.</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>Phishing has always been completely avoidable</p></blockquote></div><br><div>He went through the various incarnations of mainframe SSO from logon id through things like ACF2, VTAM Session managers, terminal emulators, multiplatform access to web access through facades. The implication he drew from this last step are well worth repeating: "Time to rethink everything." Problem is - of course, people don't rethink, they put MQ Series in front of the mainframe and hook a web app in front of that and go. </div><br><div>Finally, he connected some interesting dots to SAML and SOA security issues. </div><br><div><blockquote><p>SSO without strong auth is and always will be simply nuts</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>SAML gets its right</p></blockquote></div><div>His points around common weaknesses in integration in SOA and Web 2.0 technologies for companies that are *not* using SAML were excellent. Of course, I will go into some more details on this tomorrow.</div><br><div>Ping's CTO Patrick Harding took the stage and gave an overview of the next generation of SSO options from Kerberos to present and as is his wont demonstrated various real world strengths and weaknesses, quoted a Gartner analyst (shock!) saying OpenID is the hare and Cardspace is the tortoise. Nice.</div><br><div>Andrew Cameron from GM is speaking now on GM's experiences implementing SSO, and there are a lot of real world lessons learned in his presentation.  Plus my favorite identity architecture, user has Kerberos, services speak SAML. very nice, very scalable. All in all, its my starting point for how to identity in an enterprise. He also spoke about a pet peeve of mine - how to globalize authorization. This is not a problem that vendors have historically attacked with relish. They are very happy to help you solve authentication, but they are perfectly happy to keep their authorization internal either for vendor lock in reasons and/or for sloppy authorization design. This will take a LIberty-esque consortium of enterprises to resolve. </div><br><div>So many conferences are dominated by vendors and consultants who conspire to what I call the "sacred church of things YOU should be doing." Instead this conference is bringing together a great mix of real world in the trenches practitioners who have problems to solve today, with rubber meets the road deployable solutions and an eye towards longer term strategy for SSO and identity.</div>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 09:35:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sso">sso</category>
      <category domain="http://securityratty.com/tag/sso history talk">sso history talk</category>
      <category domain="http://securityratty.com/tag/sso summit">sso summit</category>
      <category domain="http://securityratty.com/tag/mainframe sso">mainframe sso</category>
      <category domain="http://securityratty.com/tag/sso options">sso options</category>
      <category domain="http://securityratty.com/tag/sso protocols">sso protocols</category>
      <category domain="http://securityratty.com/tag/real world">real world</category>
      <category domain="http://securityratty.com/tag/real world lessons">real world lessons</category>
      <category domain="http://securityratty.com/tag/authorization internal">authorization internal</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/sso-summit-day-one-morning-session.html">SSO Summit Day One Morning Session</source>
    </item>
    <item>
      <title><![CDATA[Colorado 'Spam King' walks away from prison camp]]></title>
      <link>http://securityratty.com/article/4498c83010a7c8588bb326a52c3ad739</link>
      <guid>http://securityratty.com/article/4498c83010a7c8588bb326a52c3ad739</guid>
      <description><![CDATA[Convicted penny-stock spammer Eddie Davidson walked away from a federal minimum-security prison camp in Colorado on Sunday, the U.S. Department of Justice said...]]></description>
      <content:encoded><![CDATA[Convicted penny-stock spammer Eddie Davidson walked away from a federal minimum-security prison camp in Colorado on Sunday, the U.S. Department of Justice said Tuesday.]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prison camp">prison camp</category>
      <category domain="http://securityratty.com/tag/colorado">colorado</category>
      <category domain="http://securityratty.com/tag/sunday">sunday</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/justice">justice</category>
      <category domain="http://securityratty.com/tag/federal">federal</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <source url="http://www.networkworld.com/news/2008/072208-colorado-spam-king-walks-away.html?fsrc=rss-security">Colorado 'Spam King' walks away from prison camp</source>
    </item>
  </channel>
</rss>
