<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: cowan]]></title>
    <link>http://securityratty.com/tag/cowan</link>
    <description></description>
    <pubDate>Mon, 10 Mar 2008 04:36:33 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[UAC, an Excellent Description and Discussion by Crispin Cowan]]></title>
      <link>http://securityratty.com/article/137e1bc1882a9842d670e593ad1c3929</link>
      <guid>http://securityratty.com/article/137e1bc1882a9842d670e593ad1c3929</guid>
      <description><![CDATA[I was excited when Dr. Crispin Cowan joined the company a while back - what security person wouldn't be! As one of the key drivers behind StackGuard , Linux Security Modules and co-founder of Immunix,...]]></description>
      <content:encoded><![CDATA[<p>&nbsp;<img height="156" src="http://www.crispincowan.com/crispin_small.gif" width="117" align="left"></p> <p>&nbsp;</p> <p>&nbsp;</p> <p>&nbsp;</p> <p>I was excited when Dr. <a href="http://crispincowan.com/">Crispin Cowan</a> joined the company a while back - what security person wouldn't be!&nbsp; As one of the key drivers behind <a href="http://www.usenix.org/publications/library/proceedings/sec98/full_papers/cowan/cowan_html/cowan.html">StackGuard</a>, <a href="http://crispincowan.com/lsm-usenix02.pdf">Linux Security Modules</a> and co-founder of Immunix, which produced <a href="http://en.wikipedia.org/wiki/AppArmor">AppArmor</a> - few people are as <a href="http://blogs.msdn.com/crispincowan/about.aspx">qualified</a> as Dr. Cowan to talk about security features and security boundaries.</p> <p>So, when he asks "<a href="http://blogs.msdn.com/crispincowan/archive/2008/04/28/uac-desert-topping-or-floor-wax.aspx">Is UAC a convenience feature, or a security feature</a>?", I would say it is worth reading at least twice.&nbsp; And if my recommendation is not good enough for you, let me share this quote that might entice you to <a href="http://blogs.msdn.com/crispincowan/archive/2008/04/28/uac-desert-topping-or-floor-wax.aspx">go read the whole thing</a>:</p> <blockquote> <p><em>It is correct to say that UAC’s features are convenience features, in that it is <b>much</b> more convenient to respond to a UAC prompt than it is to have to switch to a separate desktop, log in as an administrator to do the administrative tasks, log out and then return to your standard user session. Whether one views a UAC prompt as a convenience or a nuisance depends on whether you compare it against running as a Standard User, or against running as a full Administrator: vs. running as Standard User UAC is a convenience feature that compromises security, but vs. running as an Administrator as was the default in XP UAC is a security enhancement.</em> <p><em>But does that mean that UAC is not a security feature? No. UAC, in all of its forms, including Silent Mode, provides some obstacles to attacks, and so so it is always a security feature. UAC in operation does nothing other than to say “no” to some access requests, and so it cannot be anything <b>but</b> a security feature.</em></p></blockquote> <p>Of course, it is always nice when someone shares your own opinion.&nbsp; As I've said in the past, <a href="http://blogs.technet.com/security/archive/2006/08/24/449938.aspx">security features do not have to be perfect</a> in order to provide security value.&nbsp; UAC definitely falls into that category.&nbsp; And, as is my wont, I'm now going to go off and see if I can find some (imperfect, most likely) way to measure that value...</p> <p>Regards ~ Jeff</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3054256" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 12 May 2008 18:07:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/uac">uac</category>
      <category domain="http://securityratty.com/tag/standard user uac">standard user uac</category>
      <category domain="http://securityratty.com/tag/standard user">standard user</category>
      <category domain="http://securityratty.com/tag/uac prompt">uac prompt</category>
      <category domain="http://securityratty.com/tag/security feature">security feature</category>
      <category domain="http://securityratty.com/tag/convenience feature">convenience feature</category>
      <category domain="http://securityratty.com/tag/convenience">convenience</category>
      <category domain="http://securityratty.com/tag/cowan">cowan</category>
      <category domain="http://securityratty.com/tag/crispin cowan">crispin cowan</category>
      <source url="http://blogs.technet.com/security/archive/2008/05/12/uac-an-excellent-description-and-discussion-by-crispin-cowan.aspx">UAC, an Excellent Description and Discussion by Crispin Cowan</source>
    </item>
    <item>
      <title><![CDATA[Crispin Cowan's Blog]]></title>
      <link>http://securityratty.com/article/0b9dd3a12c985d23b6412ab7eec8febe</link>
      <guid>http://securityratty.com/article/0b9dd3a12c985d23b6412ab7eec8febe</guid>
      <description><![CDATA[Ralph here, I wanted to let everyone know that Crispin Cowan has just started his own blog . Keep an eye on it for some great posts in the...]]></description>
      <content:encoded><![CDATA[<P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Arial','sans-serif'">Ralph here, I&nbsp;wanted to let everyone know that <A href="http://blogs.msdn.com/michael_howard/archive/2008/01/17/crispin-cowan-joins-the-windows-security-team.aspx" mce_href="http://blogs.msdn.com/michael_howard/archive/2008/01/17/crispin-cowan-joins-the-windows-security-team.aspx">Crispin Cowan</A> has just started his own <A href="http://blogs.msdn.com/crispincowan/default.aspx" mce_href="http://blogs.msdn.com/crispincowan/default.aspx">blog</A>. Keep an eye on it for some great posts in the future.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></SPAN></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8438099" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 11:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/crispin cowan">crispin cowan</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/future">future</category>
      <category domain="http://securityratty.com/tag/eye">eye</category>
      <category domain="http://securityratty.com/tag/ralph">ralph</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/04/29/crispin-cowan-s-blog.aspx">Crispin Cowan's Blog</source>
    </item>
    <item>
      <title><![CDATA[Dave Cowan of Bessemer says mid-market is the new battleground for security]]></title>
      <link>http://securityratty.com/article/9d29a834d792f015007ef9b5ff352e0c</link>
      <guid>http://securityratty.com/article/9d29a834d792f015007ef9b5ff352e0c</guid>
      <description><![CDATA[Brad Feld turned me on to this interview of Dave Cowan of Bessemer Ventures on Red Herring TV. Dave and Brad have co-invested in several deals, Postini being one of them. Dave speaks about his recent...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p> <a href="http://www.feld.com/" target="_blank">Brad Feld</a> turned me on to this interview of Dave Cowan of Bessemer Ventures on Red Herring TV.&nbsp; Dave and Brad have co-invested in several deals, Postini being one of them.&nbsp; Dave speaks about his recent involvement in a 100+ million dollar round in Perimeter Securtity, the MSSP aimed at mid-market and SMBs.&nbsp; Dave and Bessemer have invested in many security companies over they years and he has a well honed view into the space.&nbsp; His comments are that security is saturated at the top of the pyramid, meaning the Fortune 2000 and large government accounts.&nbsp; He thinks the real opportunity is at the mid-market.&nbsp; Not surprising given his recent Perimeter investment.</p>

<p>From my perspective though, I have to agree.&nbsp; I think the mid-market is a much more dynamic marketplace for security.&nbsp; You know what they say about the Fortune 500? There are only 500 of them.&nbsp; Anyway, here is the interview, but be advised the security talk is only for about the first half of the show.&nbsp; The rest is on VC stuff.</p>

<div class="wlWriterSmartContent" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:547231bf-21d8-4a76-9f5c-0d662c91730e" style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"><div><embed name="flashObj" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash" src="http://services.brightcove.com/services/viewer/federated_f8/1263947866" width="486" height="412" type="application/x-shockwave-flash" bgcolor="#FFFFFF" flashvars="videoId=1388771269&amp;playerId=1263947866&amp;viewerSecureGatewayURL=https://services.brightcove.com/services/amfgateway&amp;servicesURL=http://services.brightcove.com/services&amp;cdnURL=http://admin.brightcove.com&amp;domain=embed&amp;autoStart=false&amp;" base="http://admin.brightcove.com" seamlesstabbing="false" swliveconnect="true"></embed></div></div></div>
]]></content:encoded>
      <pubDate>Mon, 10 Mar 2008 05:32:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/dave">dave</category>
      <category domain="http://securityratty.com/tag/dave cowan">dave cowan</category>
      <category domain="http://securityratty.com/tag/mid-market">mid-market</category>
      <category domain="http://securityratty.com/tag/bessemer">bessemer</category>
      <category domain="http://securityratty.com/tag/security companies">security companies</category>
      <category domain="http://securityratty.com/tag/dave speaks">dave speaks</category>
      <category domain="http://securityratty.com/tag/security talk">security talk</category>
      <category domain="http://securityratty.com/tag/brad">brad</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/03/dave-cowan-of-b.html">Dave Cowan of Bessemer says mid-market is the new battleground for security</source>
    </item>
    <item>
      <title><![CDATA[Dave Cowan of Bessemer says mid-market is the new battleground for security]]></title>
      <link>http://securityratty.com/article/7cc138b4a845a28abcaff6134888dbeb</link>
      <guid>http://securityratty.com/article/7cc138b4a845a28abcaff6134888dbeb</guid>
      <description><![CDATA[Brad Feld turned me on to this interview of Dave Cowan of Bessemer Ventures on Red Herring TV. Dave and Brad have co-invested in several deals, Postini being one of them. Dave speaks about his recent...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p> <a href="http://www.feld.com/" target="_blank">Brad Feld</a> turned me on to this interview of Dave Cowan of Bessemer Ventures on Red Herring TV.&nbsp; Dave and Brad have co-invested in several deals, Postini being one of them.&nbsp; Dave speaks about his recent involvement in a 100+ million dollar round in Perimeter Securtity, the MSSP aimed at mid-market and SMBs.&nbsp; Dave and Bessemer have invested in many security companies over they years and he has a well honed view into the space.&nbsp; His comments are that security is saturated at the top of the pyramid, meaning the Fortune 2000 and large government accounts.&nbsp; He thinks the real opportunity is at the mid-market.&nbsp; Not surprising given his recent Perimeter investment.</p>

<p>From my perspective though, I have to agree.&nbsp; I think the mid-market is a much more dynamic marketplace for security.&nbsp; You know what they say about the Fortune 500? There are only 500 of them.&nbsp; Anyway, here is the interview, but be advised the security talk is only for about the first half of the show.&nbsp; The rest is on VC stuff.</p>

<div class="wlWriterSmartContent" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:547231bf-21d8-4a76-9f5c-0d662c91730e" style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"><div><embed name="flashObj" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash" src="http://services.brightcove.com/services/viewer/federated_f8/1263947866" width="486" height="412" type="application/x-shockwave-flash" bgcolor="#FFFFFF" flashvars="videoId=1388771269&amp;playerId=1263947866&amp;viewerSecureGatewayURL=https://services.brightcove.com/services/amfgateway&amp;servicesURL=http://services.brightcove.com/services&amp;cdnURL=http://admin.brightcove.com&amp;domain=embed&amp;autoStart=false&amp;" base="http://admin.brightcove.com" seamlesstabbing="false" swliveconnect="true"></embed></div></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=A1X6rb"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=A1X6rb" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=HAQLeyF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=HAQLeyF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=LzDmwFF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=LzDmwFF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=APO2RnF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=APO2RnF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=cnz1W4F"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=cnz1W4F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=bQoizHf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=bQoizHf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YSzksmf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YSzksmf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/248845569" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Mar 2008 04:36:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/dave">dave</category>
      <category domain="http://securityratty.com/tag/dave cowan">dave cowan</category>
      <category domain="http://securityratty.com/tag/mid-market">mid-market</category>
      <category domain="http://securityratty.com/tag/bessemer">bessemer</category>
      <category domain="http://securityratty.com/tag/security companies">security companies</category>
      <category domain="http://securityratty.com/tag/dave speaks">dave speaks</category>
      <category domain="http://securityratty.com/tag/security talk">security talk</category>
      <category domain="http://securityratty.com/tag/brad">brad</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/248845569/dave-cowan-of-b.html">Dave Cowan of Bessemer says mid-market is the new battleground for security</source>
    </item>
  </channel>
</rss>
