<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: contrary]]></title>
    <link>http://securityratty.com/tag/contrary</link>
    <description></description>
    <pubDate>Wed, 25 Jun 2008 16:55:59 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[(ISC)2s Newest Cash Cow: The CSSLP Certification]]></title>
      <link>http://securityratty.com/article/4d2aae6d17ac0d88114660137a62c55f</link>
      <guid>http://securityratty.com/article/4d2aae6d17ac0d88114660137a62c55f</guid>
      <description><![CDATA[Earlier this week, during the OWASP AppSec 2008 Conference , the people behind the ubiquitous CISSP certification announced their latest creation the Certified Software Security Lifecycle Professional...]]></description>
      <content:encoded><![CDATA[<p>Earlier this week, during the <a href="http://www.owasp.org/index.php?title=OWASP_NYC_AppSec_2008_Conference">OWASP AppSec 2008 Conference</a>, the people behind the ubiquitous CISSP certification announced their latest creation &#8212; the <a href="http://isc2.org/csslp">Certified Software Security Lifecycle Professional</a> (CSSLP).  In front of a captive audience waiting for a 42&#8243; plasma TV to be raffled, the <a href="http://blog.isc2.org/isc2_blog/tipton/index.html">Executive Director of (ISC)2</a> outlined this new certification designed to appeal to application security professionals.  To his credit, Mr. Tipton stated very clearly that the CSSLP is not intended to measure one&#8217;s technical skillset.  Unfortunately, it&#8217;s inevitable that employers will treat it as such.</p>
<p>You can read all the details on their website (except for the part about the certification not being a measure of practical skills).  From what I can tell, the CSSLP is just the CISSP with different CBKs, or Common Bodies of Knowledge.  As with the CISSP, they are going for broad knowledge, not depth.  Starting in June 2009, you can get certified by taking a paper exam, likely a multiple choice test similar to the CISSP.  Why June?  Because the test isn&#8217;t even written yet &#8212; I&#8217;ve heard from several sources that they are actively soliciting their existing pool of CISSPs to help write test questions.</p>
<p>Ah, but what if you can&#8217;t wait that long and want to get certified <i>right away</i>?  You&#8217;re in luck. If you act before March 31, 2009, you can get grandfathered in without even having to take the exam!  That&#8217;s right, they call it the <a href="https://www.isc2.org/cgi-bin/content.cgi?category=1691">CSSLP Experience Assessment</a>, and here are the requirements:</p>
<div style="float:right; margin-left: 15px"><a href="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money.jpg"><img src="http://www.veracode.com/blog/wp-content/uploads/2008/09/101-hand_with_money-191x300.jpg" alt="" title="101-hand_with_money" width="191" height="300" class="alignright size-medium wp-image-372 photoborder" /></a></div>
<ul>
<li>Upload a resume showing three years of experience related to software security, or four years if you don&#8217;t have a college degree</li>
<li>Write short essays (500 words maximum) discussing four CBKs of your choice</li>
<li>Get a CISSP to vouch for you</li>
<li>Pay $650</li>
<p>
</ul>
<p>Let&#8217;s examine these requirements one at a time.</p>
<p><b>Three years of experience</b>.  (ISC)2 doesn&#8217;t provide any requirements on depth of experience, other than citing the broadly-defined CBKs.  Considering they are targeting everyone from software developers to security assessors to business analysts (yes, really), chances are they are going to accept any experience that is even tangential to the SDLC or software security.</p>
<p><b>Short essays on four of the CBKs</b>.  I asked the (ISC)2 exhibitors specifically what they are looking for to satisfy this requirement, and they said the essays should be a general discussion of the CBK topic, <i>optionally</i> citing your personal experience in that area if you have any.  This messaging is not quite aligned with the website guidance, which states that the essays should be &#8220;Accomplishment Records&#8221; which are self-reported descriptions of experience.  Either way, with a maximum essay length of 500 words, it&#8217;s pretty obvious that substance is not (ISC)2&#8217;s first priority.  Here&#8217;s one data point for you: I spoke to someone who has already submitted the CSSLP Experience Assessment, and he said it took about an hour to write the essays.</p>
<p><b>Get a CISSP to vouch for you</b>.  Actually this can be any (ISC)2 certified person, not just CISSPs.  Contrary to what you&#8217;d expect, though, the person isn&#8217;t vouching for your skillset so much as they are confirming that the attestations on your resume are accurate.</p>
<p><b>Pay $650</b>.  You knew it was coming.  After all, there is money to be made.  How is it that qualifying for the CSSLP through professional experience should cost $650?  If you&#8217;re taking the written exam, fair enough, (ISC)2 does incur the cost of administering and grading that exam (even though the <a href="http://www.scantron.com/datacollection/scanners.aspx">Scantron machine</a> is probably paid off by now).  But $650 for the submitted-online Experience Assessment?  If we assume that the person reading these essay submissions makes a rather generous $100k per year, then $650 accounts for roughly a day and a half.  Will it really take that long to read a <i>maximum</i> of 2,000 words and pass judgment?  Of course not.  (ISC)2 wants to get as many people as possible to qualify based on &#8220;experience&#8221;, seeding the initial pool of CSSLPs and netting them $650 per head for doing next to nothing.</p>
<p>As <a href="http://www.ljkushner.com/about_mstr.html">Lee Kushner</a> stated during his OWASP AppSec presentation (<i>7 Habits of Highly Effective Career Managers</i>), &#8220;the more people who own a cert, the less relevant it becomes.&#8221;  Irrelevant &#8212; that&#8217;s exactly what the CISSP has become, and it&#8217;s exactly where the CSSLP is headed.  Meanwhile, (ISC)2 will sit back and watch while you and your employers continue to fill their coffers.</p>
<p>In closing, let me acknowledge that this blog entry probably comes across as judgmental.  I accept that.  I&#8217;m not ranting against the idea of certifications, though admittedly <a href="http://www.veracode.com/blog/2008/04/not-a-cissp/">I&#8217;m not a fan of them either</a>.  I am disappointed that (ISC)2, an organization with tremendous influence, could have created something more meaningful but chose not to. Why bother when people will just fork over the cash anyway?</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 11:08:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/csslp">csslp</category>
      <category domain="http://securityratty.com/tag/csslp experience assessment">csslp experience assessment</category>
      <category domain="http://securityratty.com/tag/experience assessment">experience assessment</category>
      <category domain="http://securityratty.com/tag/certification">certification</category>
      <category domain="http://securityratty.com/tag/experience">experience</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/personal experience">personal experience</category>
      <category domain="http://securityratty.com/tag/ubiquitous cissp certification">ubiquitous cissp certification</category>
      <category domain="http://securityratty.com/tag/cissp">cissp</category>
      <source url="http://www.veracode.com/blog/2008/09/isc2s-newest-cash-cow-csslp/">(ISC)2s Newest Cash Cow: The CSSLP Certification</source>
    </item>
    <item>
      <title><![CDATA[Streaming SQL Approaches Insist in Ignoring Causality by PatternStorm]]></title>
      <link>http://securityratty.com/article/46fcc325a183e0e5f0b350bcc9aeb6b5</link>
      <guid>http://securityratty.com/article/46fcc325a183e0e5f0b350bcc9aeb6b5</guid>
      <description><![CDATA[The following excellent discussion is reposted from Streaming SQL approaches insist in ignoring causality by PatternStorm
The recent paper Towards a Streaming SQL Standard by Oracle and Streambase...]]></description>
      <content:encoded><![CDATA[<blockquote><p>The following excellent discussion is reposted from <a href="http://www.thecepblog.com/wp-admin/#p452">Streaming SQL approaches insist in ignoring causality</a> by PatternStorm.</p></blockquote>
<p>The recent paper &#8220;<a href="http://www.cs.brown.edu/%7Eugur/streamsql.pdf" target="_blank">Towards a Streaming SQL Standard</a>&#8221; by Oracle and Streambase unifies and generalizes two different execution models of Streaming SQL: Oracle&#8217;s and StreamBase&#8217;s.</p>
<p>While it&#8217;s true that the generalization succeeds in overcoming the unability of both execution models of producing correct results for astonishing simple queries (showing evidence of the actual limitations of these two Streaming SQL languages) it is also true that the generalization is closer to being overly complex than natural and intuitive.</p>
<p>The root cause behind the actual limitations of these two Streaming SQL languages is that their execution models &#8220;hardcode&#8221; the way events can be related to each other: in the Oracle case events are partially ordered by timestamp, in the StreamBase case events are totally ordered by time of arrival. These design decisions (natural in a stream oriented lamguage) have strong implications on what queries can be answered correctly, particularly when these queries involve joins of derived streams.</p>
<p>The generalization, of course, mainly consists in providing a new operator that allows the user to establish custom ordering relationships among the events (the SPREAD operator), which is good news but takes us to the fundamental issue: event processing cannot be reduced to stream processing, that is, to the processing of events that are totally or partially ordered by a pre-defined relationship (as Oracle and StreamBase actual implementations do), on the contrary, no particular ordering can be assumed because the user needs to be able to order the events in different ways in order to solve different problems. This is what event processing is about and the paper provides evidence that Streaming SQL approaches have found the need to move towards that direction and are having trouble in their way.</p>
<p>For instance, one of the queries used in the paper as an example of a query that StreamBase cannot solve (but Oracle can) is the following: correlate the stream that contains the total number of cars on the road for each time interval with the stream that contains the total average speed of the cars on the road for each time interval in order to detect the situation where the avergae speed is below 45 and the total number of cars is two or more. This query can be very easily and more robustly solved if you order the events by causality rather than by time, that is, if you have each position report update the average speed stream and the total number of cars stream and then you causally relate each position report to the new average speed event and the new total number of cars event that it generates; then the query is just a matter of detecting all report speeds that are causally related both to an average speed event below 45 and a total number of cars event of two or more (notice that this approach is more robust than Oracle&#8217;s time-based one because it works without requiring derived streams to be synchronized with the report speed stream)</p>
<p>Conclusions:</p>
<ul>
<li>Event Processing is a generalization of Stream Processing (as the paper shows)</li>
<li>Event Processing requires providing the ability to the user of creating custom relationships among events and then define patterns/queries using those custom relationships.</li>
<li>Causality is more often than not a more robust and easier criteria to order events than time or order of arrival.</li>
<li>Event Processing Languages should support causality.</li>
</ul>
<p>Regards,<br />
PatternStorm</p>
]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 10:25:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/sql approaches insist">sql approaches insist</category>
      <category domain="http://securityratty.com/tag/cars stream">cars stream</category>
      <category domain="http://securityratty.com/tag/stream">stream</category>
      <category domain="http://securityratty.com/tag/average speed event">average speed event</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/sql languages">sql languages</category>
      <category domain="http://securityratty.com/tag/languages">languages</category>
      <category domain="http://securityratty.com/tag/cars event">cars event</category>
      <source url="http://www.thecepblog.com/2008/09/05/streaming-sql-approaches-insist-in-ignoring-causality-by-patternstorm/">Streaming SQL Approaches Insist in Ignoring Causality by PatternStorm</source>
    </item>
    <item>
      <title><![CDATA[On The History of Event Processing: Global Network Monitoring]]></title>
      <link>http://securityratty.com/article/0a39883e48015e3b5b486ebc5391de1e</link>
      <guid>http://securityratty.com/article/0a39883e48015e3b5b486ebc5391de1e</guid>
      <description><![CDATA[In A Short History of Complex Event Processing. Part 1: Beginnings , David Luckham opens his history discussion by saying
Event processing has been going on for more than fifty years
However, in On...]]></description>
      <content:encoded><![CDATA[<p>In <a title="A Short History of Complex Event Processing.  Part 1: Beginnings" rel="bookmark" href="http://complexevents.com/?p=321">A Short History of Complex Event Processing. Part 1: Beginnings</a>, David Luckham opens his history discussion by saying;</p>
<blockquote><p>&#8220;Event processing has been going on for more than fifty years.&#8221;</p></blockquote>
<p>However, in <a href="http://epthinking.blogspot.com/2008/08/on-event-processing-as-discipline-and.html" target="_blank">On Event Processing as a Discipline and Some Subsets</a> another colleague mistakenly blogs,</p>
<blockquote><p><em>&#8220;&#8230; <span>people who dealt in this area [network management and event correlation] have never investigated event processing in the larger sense (e.g. looking at additional patterns), and this area has also not spawned the event processing discipline.&#8221;</span></em></p></blockquote>
<p>If you examine just one page from the <a href="http://pavg.stanford.edu/cep/" target="_blank">CEP history at Stanford</a>, researchers there outlined their view of the future applications for CEP, as follows:</p>
<ul>
<li>Instant Insight  - hierarchical event viewing applied to the Enterprise IT layer.
<ul>
<li><a href="http://pavg.stanford.edu/cep/instantinsightpaper.pdf">Analysing business processes</a></li>
</ul>
</li>
<li><a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt" target="_blank">Network Level Monitoring and Management</a></li>
<li><a href="http://pavg.stanford.edu/ID/">Cyber Security: Network Intrusion Detection</a></li>
<li>Enterprise Monitoring and Management</li>
<li><a href="http://pavg.stanford.edu/cep/final-version-131102.pdf">Modeling and Simulation of Collaborative Business Processes </a></li>
<li>Business Policy Monitoring</li>
<li>Analysis and Debugging of Distributed Systems</li>
</ul>
<p>These applications areas mentioned by Stanford researchers, including Professor Luckham, support and validate our recent discussion <a title="Magic Quadrant for IT Event Correlation and Analysis, 2007" rel="bookmark" href="http://www.thecepblog.com/2008/08/26/magic-quadrant-for-it-event-correlation-and-analysis-2007/"><span style="color: #105cb6;">Magic Quadrant for IT Event Correlation and Analysis, 2007</span></a> where we concluded that <em>&#8220;event correlation and event analysis is Gartner’s closest magic quadrant (MQ)  [...] relates directly to complex event processing (and event processing in general).&#8221;  </em></p>
<p>If you take a detailed look at the 1999 CEP presentation, <a href="http://pavg.stanford.edu/cep/netviewer-presentation.ppt" target="_blank">Defeating Large Scale Attacks: Technology and Strategies for Global Network Monitoring</a> you will readily see that our colleagues are incorrect when they says that event correlational and network management folks have never investigated event processing in the &#8220;larger sense&#8221;.  For example, the 1999 slides above, Stanford, slide 6, is titled &#8220;Complex Event Processing,&#8221; defining CEP from the application perspective of event correlation;</p>
<p><em>Complex Event Processing</em></p>
<ul>
<li>Accept network ‘events’ from any source
<ul>
<li>CISCO NetFlow FlowCollector, tcpdump</li>
</ul>
</li>
<li>Correlates events based on content and temporal relationship between events</li>
<li>Event Processing Agents (EPAs) connected in an Event Processing Network (EPNs)</li>
<li>Both post-mortem and real-time processing</li>
</ul>
<p>This single event correlational project example from David&#8217;s team at Stanford examined the challenging event correlation problems in the context of hierarchical events, maps, patterns, visualization tools, event processing models, patterns languages, network management abstraction layers, and more.  Those core event processing problems from this 1999 example, very large and complex then, still exist today and are much more large and complex - precisely why it is called &#8220;complex event processing.&#8221;</p>
<p>It is quite obvious, in just this one example, that many folks have been looking at event correlation as a motivating application for event processing, in a larger context, for a long time, contrary to what our colleagues write in their &#8220;history of event processing&#8221; posts.  </p>
<p>In a future post I will completely debuke these event processing &#8220;history revisionists.&#8221;   I will illustrate very clearly how the history of event processing goes back at least a decade, and perhaps two (twenty years) before the history outlined in posts like <a href="http://epthinking.blogspot.com/2008/08/on-research-and-practice-in-event.html" target="_blank">On Research and Practice in Event Processing</a> and <a href="http://www.eventstreamprocessing.com/cep-history.htm" target="_blank">The History of Complex Event Processing</a>. </p>
<p>David Luckam stated that the art-and-science of event processing goes back around 50 years. </p>
<p>I am not sure I will go all the way back to 1960 in my next post on the history of event processing.  However,  I will go back at least to the early days of Internet Protocol (IP) networking and illustrate why distributed IP networking, network management and network security, is one of the key  motivating factors for what we now call &#8220;event processing&#8221; and &#8220;complex event processing.&#8221;</p>
]]></content:encoded>
      <pubDate>Sat, 30 Aug 2008 06:17:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event correlational">event correlational</category>
      <category domain="http://securityratty.com/tag/event correlation problemsin">event correlation problemsin</category>
      <category domain="http://securityratty.com/tag/core event">core event</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/event correlation">event correlation</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/hierarchical event">hierarchical event</category>
      <source url="http://www.thecepblog.com/2008/08/30/on-the-history-of-event-processing-global-network-monitoring/">On The History of Event Processing: Global Network Monitoring</source>
    </item>
    <item>
      <title><![CDATA[Mental Illness and Murder]]></title>
      <link>http://securityratty.com/article/4f62b3b52324708a482cbc269844a4db</link>
      <guid>http://securityratty.com/article/4f62b3b52324708a482cbc269844a4db</guid>
      <description><![CDATA[Contrary to popular belief, homocide due to mental illness is declining , at least in England and Wales: The rate of total homicide and the rate of homicide due to mental disorder rose steadily until...]]></description>
      <content:encoded><![CDATA[<p>Contrary to popular belief, homocide due to mental illness is <a href="http://bjp.rcpsych.org/cgi/content/abstract/193/2/130">declining</a>, at least in England and Wales:</p>

<blockquote>The rate of total homicide and the rate of homicide due to mental disorder rose steadily until the mid-1970s. From then there was a reversal in the rate of homicides attributed to mental disorder, which declined to historically low levels, while other homicides continued to rise.</blockquote>

<p><a href="http://www.scribd.com/doc/4805076/Homicide-due-to-mental-disorder-in-England-and-Wales-over-50-years">Paper</a> and <a href="http://www.rcpsych.ac.uk/pressparliament/pressreleases2008/bank2008/prhomicide.aspx">press release</a>.</p>

<p><a href="http://www.badscience.net/2008/08/the-news-you-didnt-read/">Remember this</a> the next time you read a newspaper article about how scared everyone is because some  patients escaped from a mental institution:</p>

<blockquote>We are convinced by the media that people with serious mental illnesses make a significant contribution to murders, and we formulate our approach as a society to tens of thousands of people on the basis of the actions of about 20. Once again, the decisions we make, the attitudes we have, and the prejudices we express are all entirely rational, when analysed in terms of the flawed information we are fed, only half chewed, from the mouths of morons.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=rabo5K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=rabo5K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=6B4baK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=6B4baK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 11:23:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mental disorder">mental disorder</category>
      <category domain="http://securityratty.com/tag/mental illness">mental illness</category>
      <category domain="http://securityratty.com/tag/homicide due">homicide due</category>
      <category domain="http://securityratty.com/tag/homocide due">homocide due</category>
      <category domain="http://securityratty.com/tag/popular belief">popular belief</category>
      <category domain="http://securityratty.com/tag/mental institution">mental institution</category>
      <category domain="http://securityratty.com/tag/newspaper article">newspaper article</category>
      <category domain="http://securityratty.com/tag/press release">press release</category>
      <category domain="http://securityratty.com/tag/low levels">low levels</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/mental_illness.html">Mental Illness and Murder</source>
    </item>
    <item>
      <title><![CDATA[Sorry CharlieCard, Your Security Model Is Broken]]></title>
      <link>http://securityratty.com/article/f11af6f7a39f4309ead15fadb8a610f7</link>
      <guid>http://securityratty.com/article/f11af6f7a39f4309ead15fadb8a610f7</guid>
      <description><![CDATA[It sure seems like the CharlieCard , which is used by the Boston subway system, has a serious security weakness. The MBTA has sued 3 MIT students to stop them from giving a planned talk at DEFCON...]]></description>
      <content:encoded><![CDATA[<p>It sure seems like the <a href="http://www.mbta.com/fares_and_passes/charlie/">CharlieCard</a>, which is used by the Boston subway system, has a serious security weakness.  The MBTA has <a href="http://www.theregister.co.uk/2008/08/09/defcon_speakers_sued/">sued 3 MIT students</a> to stop them from giving a planned  talk at DEFCON.</p>
<p>Doesn&#8217;t this seem backwards to you?  Shouldn&#8217;t the MBTA be suing the vendor who sold them the flawed system?  Security problems go away by mandating independant security testing before a product is accepted, not by trying to get security researchers to be quiet.  This is a good example of how the reactive approach doesn&#8217;t work.  The flaws are still in the system and suing researchers has just <a href="http://en.wikipedia.org/wiki/Streisand_effect">shined a bright light</a> on them.</p>
<p><strong>Update 08/09/2008 6:00pm EST:</strong></p>
<p>The <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9112160&amp;intsrc=news_ts_head">EFF is appealing the injunction</a> which is blocking the students from speaking about the results of their testing.</p>
<p>A telling quote from Kurt Opsahl, staff attorney at the EFF gets to the heart of the issue:</p>
<blockquote><p>&#8220;Courts have found that the First Amendment covers these things. We believe that this is a protected speech activity. When you discuss security issues, if you are telling the truth, that is something that should be protected.&#8221;</p></blockquote>
<p>Apparently the MBTA has known about this problem since at least March, 2008 when a graduate student from the University of Virginia announced <a href="http://www.boston.com/business/articles/2008/03/06/t_card_has_security_flaw_says_researcher/">he was able to break the encryption system</a>.</p>
<p>The U of VA researcher gave an interview where he described why security by obscurity is not a valid security approach for a cryptosystem:</p>
<blockquote><p><strong>Q:</strong> What are your thoughts on security by obscurity? Is NXP using this method of protection?</p>
<p><strong>A:</strong> Security-through-obscurity hardly ever works. The lack of proper peer-review often even hurts the security of the system. Our Mifare work discovered several vulnerabilities that could be fixed without increasing the cost of the cards. NXP did for a long time rely on obscurity for the security of some of their products, but now decided against this outdated design approach and instead bases the security of newer RFID cards on publicly scrutinized cryptography and independent evaluations.</p>
<p><strong>Q:</strong> Can you explain &#8220;Kerckhoffs Principle&#8221; and why it applies to your work?</p>
<p><strong>A:</strong> Kerchoff, who lived in the 19th century, observed that keeping anything secret is really hard. So instead of relying on the secrecy of your whole system, it would a lot easier to only rely on the secrecy of a small secret key. Security systems should hence be publicly known and analyzed, and only the key should be secret. When properly realised for RFID cards, Kerchoff&#8217;s principle means that by analyzing their own cards, thieves cannot compromise your cards. This is contrary to our Mifare work, where we only analyzed a few copies of the the secret algorithm that is found in all cards and were consequently able affect the security of all the other billion cards out there.</p></blockquote>
<p>The MBTA not only accepted a security system which relied on security by obscurity but once accepting this flawed model must try to maintain this obscurity with the court system.</p>
<p>The documents detailing the presentation are <a href="http://www.tgdaily.com/content/view/38817/108/">here.</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 Aug 2008 10:57:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/valid security approach">valid security approach</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/encryption system">encryption system</category>
      <category domain="http://securityratty.com/tag/boston subway system">boston subway system</category>
      <category domain="http://securityratty.com/tag/discuss security issues">discuss security issues</category>
      <category domain="http://securityratty.com/tag/court system">court system</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <source url="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">Sorry CharlieCard, Your Security Model Is Broken</source>
    </item>
    <item>
      <title><![CDATA[IT - Show Me Where to Spend the Money]]></title>
      <link>http://securityratty.com/article/ea924250c185f9c7e0ba67e917813f6e</link>
      <guid>http://securityratty.com/article/ea924250c185f9c7e0ba67e917813f6e</guid>
      <description><![CDATA[A recent Goldman Sachs report explains the results of the companys survey of 100 IT execs (mostly CIOs). IT spending growth will slip from 7 percent to 5 percent in 2008
An interesting excerpt
CIOs...]]></description>
      <content:encoded><![CDATA[<p>A <a href="http://news.cnet.com/8301-13505_3-9986239-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">recent Goldman Sachs report</a> explains the results of the company’s survey of 100 IT execs (mostly CIOs). IT spending growth will slip from 7 percent to 5 percent in 2008.</p>
<p>An interesting excerpt:</p>
<blockquote><p>“CIOs have emphasized to us that they are buying on a need versus want basis, are often downsizing deals to fit with current budget constraints…In fact, contrary to general tightening in spending, purchases with an especially compelling ROI are being accelerated in the current environment.”</p></blockquote>
<p>Hmm. Certainly we all understand prioritizing what to buy on need versus want– my friend who runs an art gallery that has only sold one piece in the past 2 months can certainly explain it. I “need” that Picasso? But does it take the entire economy slowing down before CIOs, even at Fortune 100 companies, to focus on ROI? So it’s not surprising what showed up at the top of the list for spending priorities for 2008-2009:</p>
<ol>
<li>Server Virtualization</li>
<li>Server Consolidation</li>
<li>Cost Cutting</li>
</ol>
<p>At the bottom of the list, grid computing and on-demand computing.</p>
<p>Compare this to <a href="http://blogs.zdnet.com/BTL/?p=4646" target="_blank">last year’s spending survey</a> where the top 10 priorities by rank were:</p>
<ol>
<li>Applications integration</li>
<li>Security</li>
<li>Cost Cutting</li>
<li>BI</li>
<li>ERP</li>
<li>Web-based app development</li>
<li>Datacenter consolidation</li>
<li>Disaster Recovery</li>
<li>Compliance/risk management</li>
<li>Identity and access management</li>
</ol>
<p>So in one year, the very hot “server virtualization” (and quite similar server consolidation) jumped to the top of the spending priority list. Can anyone have predicted just how much mindshare virtualization would capture in such a short time? Virtualization is not a new concept; it just seems that way. What will be # 1 next year?</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=IT+-+Show+Me+Where+to+Spend+the+Money&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fit-show-me-where-to-spend-the-money%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 09:21:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hot server virtualization">hot server virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/mindshare virtualization">mindshare virtualization</category>
      <category domain="http://securityratty.com/tag/server virtualization">server virtualization</category>
      <category domain="http://securityratty.com/tag/server consolidation">server consolidation</category>
      <category domain="http://securityratty.com/tag/similar server consolidation">similar server consolidation</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/priority list">priority list</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://blog.sciencelogic.com/it-show-me-where-to-spend-the-money/07/2008">IT - Show Me Where to Spend the Money</source>
    </item>
    <item>
      <title><![CDATA[Do we need a farm system in the security industry?]]></title>
      <link>http://securityratty.com/article/9bd54e0c74e4d7f5590217159a48aeec</link>
      <guid>http://securityratty.com/article/9bd54e0c74e4d7f5590217159a48aeec</guid>
      <description><![CDATA[Just read a good article by Lisa Vaas on Computerworld titles &quot;When security staffers fail up&quot;. The article talks about some of the challenges that are faced by companies trying to provide proper...]]></description>
      <content:encoded><![CDATA[<p>Just read a <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9104599&amp;pageNumber=4">good article by Lisa Vaas</a> on Computerworld titles "When security staffers fail up". The article talks about some of the challenges that are faced by companies trying to provide proper security. While one of the issues is "bundled badness" which I will talk about later, the bigger problem that Lisa writes about is the profile of our security administrators. It is a familiar story I am afraid. Security people don't do a good job of "humanizing" themselves. Their peers don't understand what they are trying to accomplish and too often we speak in geek terms and try to dictate how people conduct business. As a result we are the "people in the way".<br><br>The next thing Lisa hits on is the obsession with certifications. Too many people think having a CISSP is the be all and end all of security. First of all, you can't hire enough of them and many of them don't have the practical business experience to take it to the next level. Than there is the security "prima donna". They just think they are smarter than everyone else and too many tasks are below them as to elementary. We have all met these types before as well. <br><br>Quickly on the "bundled badness" thing. Lisa rightfully points out that in spite of Mike Rothman's feelings to the contrary, though CIO and CFO types like to buy the bundle and get the jack of all trades suite cheaper than buying best of breeds individually, at the end of the day it is hurting our security. If you are really serious about securing the environment there is a world of difference between buying the bundle of goodness versus best in class tools.<br><br>Ultimately though, what are we to do about getting better security pros in the workplace? Do we need to change the certification process? Should companies have a different profile of who they hire for security positions. Do we need to develop some sort of farm system where security pros can cut their teeth and learn their craft, like the guilds and apprentices of yesteryear? The construction industry used to work like that. Maybe we should consider it too?</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=bEHJbL"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=bEHJbL" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=mx99tJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=mx99tJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=e6dpaJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=e6dpaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YwE32J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YwE32J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Io9IaJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Io9IaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qFI7Kj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qFI7Kj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TYeLwj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TYeLwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/341925149" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 12:17:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security administrators">security administrators</category>
      <category domain="http://securityratty.com/tag/security staffers fail">security staffers fail</category>
      <category domain="http://securityratty.com/tag/security positions">security positions</category>
      <category domain="http://securityratty.com/tag/security people">security people</category>
      <category domain="http://securityratty.com/tag/security pros">security pros</category>
      <category domain="http://securityratty.com/tag/lisa hits">lisa hits</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/lisa">lisa</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/341925149/do-we-need-a-fa.html">Do we need a farm system in the security industry?</source>
    </item>
    <item>
      <title><![CDATA[On Government Employees, Culture, and Survivability]]></title>
      <link>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</link>
      <guid>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</guid>
      <description><![CDATA[A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert. One thing he said still sticks in my mind...]]></description>
      <content:encoded><![CDATA[<p>A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert.  One thing he said still sticks in my mind (obviously paraphrased):</p>
<blockquote><p>&#8220;The Afghanis, they live in mud huts, they don&#8217;t have electricity, they are stick-people weighing 85 lbs, and to say that we could bomb them into the stone age would be an advancement in their technology level.  But never underestimate these people, they&#8217;re survivors.  They&#8217;ve survived 35 years of warfare, starting with the Soviets, then they fought a civil war before we arrived on the scene.  Never underestimate their ability to survive, and have respect for them because of who they are.&#8221;</p></blockquote>
<p>Today, I feel the same way about government employees, even more so because it&#8217;s an election year:  they&#8217;re survivors.</p>
<p>Now time for what I see is the &#8220;real&#8221; reason why the government is doing badly (if that&#8217;s what you believe&#8211;opinions differ) at security: it&#8217;s all an issue of culture. I have a friend who converted a year ago to a GS-scale employee and took a class on what motivates government employees. Some of these are obvious:</p>
<ul>
<li>Pride at making a difference</li>
<li>Helping people</li>
<li>Supporting a cause</li>
<li>Gaining unique experience on a global-class scope</li>
<li>Job stability</li>
<li>Retirement benefits</li>
</ul>
<p>And one thing is noticeably absent: better pay and personal recognition.  Hey, sounds like me in the army.</p>
<p style="text-align: center;"><em><img src="http://farm2.static.flickr.com/1348/1470902823_4a5145322e.jpg?v=0" alt="The Companion Family Plan to Survival at Home" width="362" height="500" /></em></p>
<p style="text-align: center;"><em>The Companion Family Plan for Survival at Home photo by <a href="http://www.flickr.com/photos/jikan/" target="_blank">Uh &#8230; Bob</a>.</em></p>
<p>Now I&#8217;m not trying to stereotype, but you need to know the organizational behavior pieces to understand how government security works. And in this case, the typical government employee is about as survival-aware as their Afghani counterpart.</p>
<p>Best advice I ever heard from a public policy wonk: the key to survival in this town is to influence everything you can get your hands on and never have your name actually written on anything.</p>
<p>In other words, don&#8217;t criticize, be nice to everybody even though you think they are a jerk, and avoid saying anything at all because you never know when it will be contrary to the political scene.  The Government culture is a silent culture. That&#8217;s why every day amazing things happen to promote security in the Government and you&#8217;ll never hear about it on the outside.</p>
<p>One of the reasons that I started blogging was to counter the naysayers who say that FISMA is failing and that the Government would succeed if they would just buy their product for technical policy compliance or end-to-end encryption.  Sadly, the true heroes in Government, the people who just do their job every day and try to survive a hostile political environment, are giving credit to the critics because of their silence.</p>
<p>Which brings me to my point:</p>
<p>Yes, my name is Rybolov and I&#8217;m a heretic, but this is the secret to security in the Government:  it&#8217;s cultural at all layers of the personnel stack.  Security (and innovation, now that I think about it) needs a culture of openness where it&#8217;s allowable to make mistakes and/or criticize.  Doesn&#8217;t sound like any government&#8211;local, state, or federal&#8211;that I&#8217;ve ever seen.  However, if you fix the culture, you fix the security.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" alt="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to digg" alt="Add 'On Government Employees, Culture, and Survivability' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to reddit" alt="Add 'On Government Employees, Culture, and Survivability' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=On+Government+Employees%2C+Culture%2C+and+Survivability&amp;url=http://www.guerilla-ciso.com/archives/298&amp;version=0.7" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" alt="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Technorati" alt="Add 'On Government Employees, Culture, and Survivability' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/298&amp;t=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" alt="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" alt="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" alt="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo" alt="Add 'On Government Employees, Culture, and Survivability' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines" alt="Add 'On Government Employees, Culture, and Survivability' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=KQw1LJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=KQw1LJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=8UDDwj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=8UDDwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/341552257" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 09:46:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/government employees">government employees</category>
      <category domain="http://securityratty.com/tag/government security">government security</category>
      <category domain="http://securityratty.com/tag/culture">culture</category>
      <category domain="http://securityratty.com/tag/government culture">government culture</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/typical government employee">typical government employee</category>
      <category domain="http://securityratty.com/tag/promote security">promote security</category>
      <category domain="http://securityratty.com/tag/silent culture">silent culture</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/341552257/298">On Government Employees, Culture, and Survivability</source>
    </item>
    <item>
      <title><![CDATA[Mission Statement for Federation]]></title>
      <link>http://securityratty.com/article/9794bcabb05d5a9a4ad01ef54236e5df</link>
      <guid>http://securityratty.com/article/9794bcabb05d5a9a4ad01ef54236e5df</guid>
      <description><![CDATA[Bruce Sterling (11/20/2001
You know what I want? I don't want a National ID Card. I want a Global Coalition Visa



Like it or not, we've got a huge global diaspora now. It is a fact of life. Nations...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: &#39;times new roman&#39;; font-size: 16px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "></span></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "><a href="http://www.viridiandesign.org/notes/251-300/00283_geeks_and_spooks.html">Bruce Sterling</a> (11/20/2001):</p><blockquote><p>You know what I want? I don&#39;t want a National ID Card. I want a Global Coalition Visa.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>Like it or not, we&#39;ve got a huge global diaspora now. It is a fact of life. Nations with stupid and corrupt politics have seen their clever people brain- drained away, to places where the cops don&#39;t shake you down twice a day. And jet-setters go everywhere. And properly so. If you&#39;re in a true global society, then you spend a lot of your time among aliens. Quite often you are the alien. You might notice that even Al Qaeda is a genuinely multinational group. They gravitated to wicked, lawless places like Sudan, Chechnya and Afghanistan, where the locals shoot you if you ask for a badge.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>But what about all us bright, shiny, world-trading jet setters, huh? There are thirty percent fewer Yankees in Europe this Christmas, and that is bad. Let me pose the problem this way. If I am going into a Japanese restaurant in Japan, I would rather like to be able to haul out some gizmo and flash it at my fellow civilians, and have these kindly people understand with a high degree of likelihood that I am not a mass murderer. On the contrary, I am quite civilized, and I should be brought a beer immediately.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>A platinum VISA card and a five-hundred-dollar suit will almost do that, but those are too easy to forge and steal, plus they are not very democratic. The UN should get together on this. We should have a high level summit about digital hardware support for the crippled tourist economy. Fear and ill treatment shut down tourism faster than anything short of open warfare. That is bad for all of us. Killing off tourism harms our civilization and impoverishes our cultures. People in civilized states shouldn&#39;t routinely treat one another as criminal suspects. I don&#39;t want to get done-over for three hours every time I get off a plane in London. When I go to London, I go with empty suitcases. I don&#39;t plan to stay, but I am better news for the London economy than a lot of the people who live there.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>They should know all that that&#0160;<span style="font-weight: bold; ">before<span style="font-weight: normal; ">&#0160;I get off the plane. My arrival is excellent news for Britain, so I should be treated that way. If this is a new kind of war, I don&#39;t want to be the evil guy hunkered down in the bunker; I want to fly with the boys from Air Assault. I want one of those handy crypto-style Friend-or-Foe IDs.</span></span></p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>These people who normally meet me whenever I am an alien, they don&#39;t need to know my nationality, my home address or my shoe size. They just need to know that, despite being alien, I&#39;m sort-of okay.</p></blockquote><p></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><p style="font-size: small; font-style: normal; font-weight: normal; line-height: 24px; "></p><blockquote><p>I want a democratic, citizen-to-citizen device that will bridge those social barriers and language barriers. I think we could invent devices and means of verification that would strengthen the global social fabric that terrorism wants to rip. It wouldn&#39;t be easy or simple, but it&#39;s not beyond our ingenuity. Our social capital sustains all civilized societies, and it is all about trust. <span style="font-weight: bold;">So let&#39;s invent new methods of trust.</span></p></blockquote><p>I added bold to the last sentence because I think this is the mission statement for building out federation systems.</p><p></p><p></p>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 06:35:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/clever people brain-">clever people brain-</category>
      <category domain="http://securityratty.com/tag/kindly people">kindly people</category>
      <category domain="http://securityratty.com/tag/platinum visa card">platinum visa card</category>
      <category domain="http://securityratty.com/tag/london">london</category>
      <category domain="http://securityratty.com/tag/mission statement">mission statement</category>
      <category domain="http://securityratty.com/tag/london economy">london economy</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/true global society">true global society</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/06/mission-statement-for-federation.html">Mission Statement for Federation</source>
    </item>
    <item>
      <title><![CDATA[Directly connect to your corpnet with IPsec and IPv6]]></title>
      <link>http://securityratty.com/article/8fa825adcf64d7fa728dd4b170277578</link>
      <guid>http://securityratty.com/article/8fa825adcf64d7fa728dd4b170277578</guid>
      <description><![CDATA[Contrary to popular belief, the rumors of my demise have been greatly exaggerated. Well, ok, no actual rumors, but hey, one can dream, huh? My spring calendar was full of events in Asia and Australia,...]]></description>
      <content:encoded><![CDATA[<p>Contrary to popular belief, the rumors of my demise have been greatly exaggerated. Well, ok, no <em>actual</em> rumors, but hey, one can dream, huh? My spring calendar was full of events in Asia and Australia, then TechEd US seemed to suddenly appear out of nowhere! So I've been kinda swamped. I've missed writing here; it's good to get back into the swing.</p>  <p>At TechEd this year, I gave a presentation called <strong>&quot;21st century networking: time to throw away your medieval gateways.&quot;</strong> (Actually, I've given this same talk before, at events in Amsterdam, Brussels, Oslo, and numerous on-campus customer meetings. It's time to bring the knowledge to the masses.)</p>  <p>I described an idea of using IPv6, IPsec, NAP, and group policy to build a pretty slick replacement for clunky VPN gateways. Turns out we've been piloting this very idea on our internal corpnet. Like a good little bunny I got myself enrolled in the thing and -- pardon the unattractive gushing -- this thing <em>rawks!</em> Here's a brief rundown of the parts you'd configure on <strong>managed clients</strong>:</p>  <ul>   <li>Windows Vista Business (with Software Assurance), Enterprise, or Ultimate editions</li>    <li>That are domain-joined</li>    <li>Users run as <a href="http://blogs.msdn.com/aaron_margosis/" target="_blank">non-admin</a></li>    <li><a href="http://technet.microsoft.com/en-us/windowsserver/grouppolicy/default.aspx" target="_blank">Group policy</a> applies numerous settings</li>    <li><a href="http://technet2.microsoft.com/WindowsVista/en/library/0d75f774-8514-4c9e-ac08-4c21f5c6c2d91033.mspx?mfr=true" target="_blank">UAC</a> is enabled</li>    <li><a href="http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx?mfr=true" target="_blank">BitLocker</a> is configured to protect confidential information stored offline</li>    <li>The <a href="http://technet.microsoft.com/en-us/network/bb545423.aspx" target="_blank">Windows Firewall</a> is enabled</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb545879.aspx" target="_blank">NAP</a> is used for checking health</li>    <li><a href="http://technet.microsoft.com/en-us/forefront/clientsecurity/default.aspx" target="_blank">Forefront Client Security</a> for keeping malware off the box</li>    <li><a href="http://technet.microsoft.com/en-us/library/bb742533.aspx" target="_blank">Smart cards</a> for strong authentication of users</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb531150.aspx" target="_blank">IPsec</a> is required for connection authentication and traffic encryption</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb530961.aspx" target="_blank">IPv6</a> is required for worldwide Internet connectivity</li>    <li>A DNS suffix search list represents the data center name space</li>    <li>Static IPv6 DNS servers provide name resolution for hosts in the data center</li> </ul>  <p>What does this give you? True <a href="http://www.microsoft.com/mscorp/twc/anywhereaccess/default.mspx" target="_blank">anywhere access</a>, <a href="http://www.microsoft.com/mscorp/execmail/2007/02-06secureaccess.mspx" target="_blank">anywhere in the world</a>, directly to corpnet resources from managed and secure client PCs. The Internet has replaced private WAN links for good reason: enormous cost benefits. The only thing holding us back from fully utilizing this development has been a lack of way to enforce and monitor the security of clients not physically located within the corpnet. Well, those days are over. Now you can build PCs that are trusted just as if they were on the corpnet, without knowing or caring anything about the underlying network connections. And let me tell you, it's as addictive as a few other substances I could mention, but will refrain, since this is (I hope) a family blog :)</p>  <p>Maybe you've heard of the notion of &quot;<a href="http://en.wikipedia.org/wiki/De-perimeterisation" target="_blank">deperimeterization</a>.&quot; Taken to its extreme, I think it's a bit silly. To put a SQL Server directly on the Internet is just plain stupid -- not because I don't think I could keep it protected, but simply because that's unnecessary risk. Only my web server -- and no one else -- should be talking to my SQL Server. But that web server will be in the same subnet as the SQL Server, and IPsec policies used also here will govern who can connect to the SQL Server. <strong>Warning to any and all network DMZs: your days are numbered!</strong></p>  <p>Shrink your perimeter to that which really matters -- your data center. <em>All</em> your clients live (as we would say in the olden days) &quot;on the outside of the firewall.&quot; Now then, there are two kinds of clients. Managed clients, as I described above, establish IPsec-authenticated/encrypted, group-policy-configured, NAP-enforced IPv6 connections directly to corpnet resources without going through any kind of access gateway. The router connecting you to your ISP is fully sufficient for blocking denial of service attempts. Be sure to follow my advice in &quot;<a href="http://blogs.technet.com/steriley/archive/2006/07/10/Configure-your-router-to-block-DOS-attempts.aspx" target="_blank">Configure your router to block DOS attempts</a>,&quot; and then add two more rules to permit incoming port udp/500 and IP protocol 50 over IPv6. That's it. No NATing or other unnatural network acts are required (finally, you can stop lying to your significant other about why you squirrel yourself away in the computer room all those weekend nights).</p>  <p>Unmanaged clients will continue to use IPv4 to access published Web and Win32 applications through a gateway like <a href="http://technet.microsoft.com/en-us/forefront/edgesecurity/bb687299.aspx" target="_blank">IAG</a>. Since you can't trust these clients nor can you trust the data they're throwing at you, you have to inspect and validate at the perimeter. You can take advantage of IAG's <a href="http://www.microsoft.com/forefront/edgesecurity/iag/whitepapers.mspx" target="_blank">application-modifying capabilities</a> to &quot;wrap&quot; security around poorly-written web apps; you can even download an ActiveX control to unmanaged clients to perform some basic health checking, policy enforcement, and cache clearing. None of these eliminates the final requirement to continue inspecting and removing malware from servers where users store data: <a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb734822.aspx" target="_blank">Exchange</a>, <a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb734828.aspx" target="_blank">SharePoint</a>, <a href="http://www.microsoft.com/forefront/serversecurity/ocs/default.mspx" target="_blank">Office Communications Server</a>, and <a href="http://technet.microsoft.com/en-us/forefront/clientsecurity/default.aspx" target="_blank">file servers</a>.</p>  <p><strong>Machines are mobile, data is mobile.</strong> The mainframes and large desktop PCs of the past posses an effective security attribute: the heaviness of the machines. You couldn't easily saunter out the front door with a PC-AT in your pocket! These days, we all line our pockets with tiny little mobile phones stuffed with 16GB of storage. It's now a fact: data moves. And like water, data moves wherever it can, as rapidly as it can, often beyond your control if you don't prepare for that. With properly-configured and managed clients we can enjoy a single access and authentication experience no matter where the computer is physically located. For example: I can sit in my house and enter '&quot;http://internal-web-site-name&quot; in my browser. The DNS suffix search list adds the appropriate suffix, my browser's resolver performs an IPv6 name lookup, and my computer makes an authenticated and encrypted connection, after it meets the NAP policy, directly to that internal server. Very nice. As far as I'm concerned, there's no difference between the Internet and my corpnet. It's all <em>just there.</em></p>  <p>For a while now many of you know I've been speaking and writing, mostly at the conceptual level, about the day when such a way of remote computing will arise. Well, my friends, that day is now. You can indeed build it now, with the products you have. I won't admit it's all peaches and cream: there's a fair number of moving parts here, it's true. But most of these moving parts are parts you're already familiar with: I'm simply encouraging you to move them in a specific way. You'll need to do some custom scripting for client-side connection diagnostics, but that's about it.</p>  <p>My next step is to create a more detailed guide, which I plan to publish through TechNet Magazine. I'm targeting (but not promising) the October issue. The article will include greater details about configuring your infrastructure to support the managed clients I describe.</p>  <p>I've lost track of the swelling number of individual conference attendees and the plethora of email writers who've expressed a desire to build this in their own environments. The one common thread from everyone is &quot;I want to do it now!&quot; Folks, it's really pretty exciting for me to see so many of you ready to cross the chasm from the perdition of paleo-networking (layer upon endless, complex layer of DMZs) into the paradise of flat, simple, cheap, and secure access to information. If you haven't yet, please take the time to read through some of our information (especially Scott Charney's paper) on <a href="http://www.microsoft.com/mscorp/twc/endtoendtrust/default.mspx" target="_blank">end-to-end trust</a>. Friends, the idea I describe above is the plumbing for realizing the end-to-end trust vision.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3078070" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 16:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/directly">directly</category>
      <category domain="http://securityratty.com/tag/corpnet">corpnet</category>
      <category domain="http://securityratty.com/tag/sql server directly">sql server directly</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/end-to-end trust vision">end-to-end trust vision</category>
      <category domain="http://securityratty.com/tag/users store data">users store data</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx">Directly connect to your corpnet with IPsec and IPv6</source>
    </item>
  </channel>
</rss>
