<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dan]]></title>
    <link>http://securityratty.com/tag/dan</link>
    <description></description>
    <pubDate>Mon, 20 Oct 2008 04:32:28 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Economics of Finding and Fixing Vulnerabilities in Distributed Systems ]]></title>
      <link>http://securityratty.com/article/8a34266a61546df04c75d0de7416a33d</link>
      <guid>http://securityratty.com/article/8a34266a61546df04c75d0de7416a33d</guid>
      <description><![CDATA[The Economics of Finding and Fixing Vulnerabilities in Distributed Systems
Quality of Protection Keynote
Alexandria, VA
October 27. 2008

Gunnar Peterson
Managing Principal, Arctec Group
Blog:...]]></description>
      <content:encoded><![CDATA[<div>The Economics of Finding and Fixing Vulnerabilities in Distributed Systems&#0160;</div><div><a href="http://qop-workshop.org/Program.htm">Quality of Protection Keynote</a></div><div>Alexandria, VA</div><div>October 27. 2008</div><br /><div>Gunnar Peterson</div><div>Managing Principal, Arctec Group</div><div>Blog: http://1raindrop.typepad.com</div><br /><div>When Andy Ozment asked me over the summer to do this talk at QoP, I knew back in August that the topic I wanted to address was security and economics. So to that end I would like to start by thanking all of our friends on Wall Street and here in Washington DC for providing such a rich tapestry of recent events that I can speak to.</div><br /><div>Like many people in this industry, my focus on security was fundamentally altered by Dan Geer&#39;s speech &quot;Risk Management is Where the Money Is&quot;[1], there are not many people who can call a ten year shot in the technology business, but Dan Geer did. The talk revolutionized the security industry. Since that speech, the security market, the vendors, consultants, and everyone else has realized that security is really about risk management.</div><br /><div>Of course, saying that you are managing risk and actually managing risk are two different things. Warren Buffett started off his 2007 shareholder letter [2] talking about financial institutions&#39; ability to deal with the subprime mess in the housing market saying, &quot;You don&#39;t know who is swimming naked until the tide goes out.&quot; In our world, we don&#39;t know whose systems are running naked, with no controls, until they are attacked. Of course, by then it is too late.</div><br /><div>So the security industry understands enough about risk management that the language of risk has permeated almost every product, presentation, and security project for the last ten years. However, a friend of mine who works at a bank recently attended a workshop on security metrics, and came away with the following observation - &quot;All these people are talking about risk, but they don&#39;t have any assets.&quot; You can&#39;t do risk management if you don&#39;t know your assets.</div><br /><div>Risk management requires that you know your assets, that on some level you understand the vulnerabilities surrounding your assets, the threats against those, and efficacy of the countermeasures you would like to use to separate the threat from the asset. But it starts with assets. Unfortunately, in the digital world these turn out to be devilishly hard to identify and value.</div><br /><div>Recent events have taught us again, that in the financial world, Warren Buffett has few peers as a risk manager. I would like to take the first two parts of this talk looking at his career as a way to understand risk management and what we can infer for our digital assets.</div><br /><div>Warren Buffett&#39;s evolution as an investor can be broken up into two parts. He began his career very much influenced by Ben Graham, who sought to buy &quot;cheap stocks&quot;, comparing the price of the stock to value of the company&#39;s assets, and placing many, diversified bets on companies whose share price was below the total assets. Note that the businesses may have been of unremarkable quality, but when the price was right Graham would buy in, wait for it to rise and then sell. This was the dawn of value investing.</div><br /><div>Buffett&#39;s later career departed from Graham&#39;s strict, statistical measures, where he sought to buy into companies that were selling at a fair price, but were also high quality businesses. We will examine high quality in Part 2 of this talk, but first we go to Part 1 which is asset value.</div><br /><div>Why does a talk on finding and fixing vulnerabilities start with valuing assets? The reason is that vulnerabilities are everywhere, we are literally marinating in them. Interesting vulnerabilities are attached to high value assets. In a world that quite literally presents us with too much information, we need screens to sift out what is worth paying attention to. &#0160;You can run your vulnerability assessment tool of choice on your system, and come back with hundreds or thousands of vulnerabilities, but which ones should you pay attention to and act on? The first part of answering this question is asset value.</div><br /><div>When Warren Buffett was 19 years old studying at the University of Nebraska, he read Ben Graham&#39;s book &quot;The Intelligent Investor&quot;, Buffett said he thought it was the best book on investing he has ever read and still feels that way today. In the Intelligent Investor Graham lays out the framework of value investing. Specifically, Graham talks about three concepts - Mr. Market, a stock is a piece of a business, and Margin of Safety.</div><br /><div>Mr. Market is a fictional, teaching device invented by Graham. You imagine that you have a somewhat manic depressive business partner called Mr. Market. Every day, Mr. Market comes into the office and offers you quotes on companies, some days he is in a good mood and the prices are high, other days he is gloomy and prices are low. The market is a quote machine, for quoting prices, not a value assessment machine. Your job is to wait for the right price, and you are free to take as many passes and be as patient as you would like, Mr. Market will just show up the next day and throw out a new price.&#0160;</div><br /><div>Graham used Mr. Market to teach us the separation between a price of a stock, and the value of a company. The second big concept from Intelligent Investor is that buying a stock is buying a small piece of the underlying business. You are not buying a roulette chip, or a number that fluctuates in the newspaper every day, rather you are buying a piece of the company&#39;s existing and future cash flow. What the stock market says General Electric is worth yesterday, today or tomorrow is separate from GE&#39;s actual ability to generate cash flow.</div><br /><div>The last big concept in &quot;The Intelligent Investor&quot; and the one seemingly most applicable to information security is the Margin of Safety. Graham&#39;s margin of safety involved calculating the intrinsic value of a business and then buying stock where the market cap of a company is less than its intrinsic value. So if a company has $100 million in assets and a market capitalization of $75 million, then an investor would get a 25% margin of safety. Ideally, Graham wanted to buy stocks that were selling for one half of their book value, i.e. with a 50% margin of safety. Graham said that buying stocks without a margin of safety, above their book value, speculation, not investing.</div><br /><div>So price is readily available, but how do we calculate intrinsic value so that we can ascertain the margin of safety? Graham used quantitative statistical measures, relying heavily on the company&#39;s book value, like its hard assets. What would it take for a competitor to reproduce the company&#39;s assets - its factories, distribution system, and so on. The difference between the book value of the assets and market cap is the margin of safety.</div><br /><div>What can we learn in information security from this quantitative approach? Where price and value are readily ascertainable we should build countermeasures and eliminate on vulnerabilities that give our assets a wide margin of safety. Since budgets are not unlimited we should prefer vulnerabilities that are cheap to find, cheap to fix.</div><br /><div>First to the asset question, information security budgets like all IT budgets are crufty, they are not a reflection of today&#39;s top issues and priorities so much as an accumulating snowball of decisions, legacy contracts, and solution attempts to yesteryear&#39;s problems. Today the normal Information Security budget is just a legacy artifact from bygone years when the network was the purported greatest vulnerability. If you were around in 1995, you remember the great gnashing of gears as the enterprises opened up their networks, connected their back ends to the Web and began to transact business in the giant virtual space.</div><br /><div>The security people huffed and puffed that it was dangerous but there was simply too much money to be made, so businesses went ahead. The security people would not go down without a fight and insisted on countermeasures. They got two - the network firewall and SSL. The firewall was used to separate the average Fortune 500s network of hundreds of thousands of machines, employees, consultants, and partners from the web at large. SSL was used to protect the network channel between the web server and the client browser. so the network firewall separated the network segments, and SSL in effect encrypted the last mile of many million complex transactions and computations.</div><br /><div>In 1995, this seemed like a good security architecture. When we built out these security architectures, the eCommerce market was derided as a toy. Amazon famously lost money for years - losing a little on every transaction but making it up in volume. When the market is nascent, a quaint security architecture offers cost effective protection. But what about 2008? Those cute little eCommerce buggers have grown they even make profits now - market caps measured in the tens of billions, accumulating large cash hordes, no debt, and the largest ones are in better financial shape than the financial services players that kicked sand in their face in the dotcom era.&#0160;</div><br /><div>And its not just eCommerce, the &quot;real&quot; economy Fortune 500 types are all connected as well. Directly and indirectly the Web is seeping into all businesses. Major changes from when the security architecture of the web was built out. But has the security architecture changed to reflect these new business realities? Not a bit of it!</div><br /><div>We can use the book value of the IT budget investments and the book value of the Information Security investments to see what kind of Margins of Safety Information Security groups are engineering.</div><br /><div>Let&#39;s look at some market data, Gary McGraw reviewed the numbers [2] in software security for 2007, breaking down software security sectors like tools and services. Here is a summary of his findings on software security tools:</div><br /><div>&quot;One of the most important developments in the software security market can be seen in the tools space which, combined, almost doubled to $150-180 million. Top of list are two major acquisitions that closed in 2007: Watchfire&#39;s purchase by IBM (somewhere in the range of $120-150 million on 2006 revenue of $26 million) and SPI Dynamics&#39;s purchase by HP (for around $100 million on 2006 revenue of $21.2 million).</div><br /><div>...</div><br /><div>The black box space was flat in 2007, with IBM/Watchfire checking in at $24.1 million and HP/SPI Dynamics earning $22.3 million. Smaller companies in the space, including Cenzic, Codenomicon, WhiteHat and the like had combined revenues around $12.5 million (a growth of 25%, though Cenzic grew 16% and WhiteHat 52%). Most of the growth &quot;hiccup&quot; in the black box market can be attributed to the serious challenges posed by any acquisition. So far 2008 looks to be back on track from a growth perspective in the black box testing space. The global reach that IBM and HP offer are already making a big difference.</div><br /><br /><div>On a more positive note, static analysis tools for code review grew at a healthy clip in 2007 into a $91.9 million dollar market. Fortify was up 83% to $29.2 million. Klocwork grew over 60% to $26 million. Coverity grew over 50% to $27.2 million. Ounce Labs tripled their revenue to $9.5 million.&quot;</div><br /><div>These are very nice growth numbers, what company doesn&#39;t want 83% growth? However, the let&#39;s look at the total picture and compare the software security countermeasures against other security mechanisms. Gary McGraw&#39;s estimate shows the software security space coming in at $150 Million total, yet we see a company like Checkpoint that won the network security war in 1995 with earnings of around $900 Million! One single network security vendor is 6 times bigger than the entire software security space, in what alternate universe does this make sense?</div><br /><div>This is where we begin to see that decisions in the People&#39;s Republic of Information Security have no real risk management thinking, they truly are swimming naked and hoping the tide doesn&#39;t go out.</div><br /><div>Let&#39;s look at network assets. Obviously Cisco is the biggest, they earned $39.5 Billion last year. Pretty stellar. So spending $900 Million (Checkpoint) to defined $39.5 Billion seems like a pretty good deal.</div><br /><div>Except, let&#39;s compare software security spending - last year Microsoft earned $60 Billion, SAP $16 billion, and Oracle $22 Billion. So that is about $98 Billion in just three vendors and you are going to &quot;defend&quot; that with allocating $150 Million worth of software security tools?</div><br /><div>On the network side we are buying $900 million of security countermeasures (Checkpoint firewalls) to protect $39.5 billion worth of Cisco gear, about 2.3% of the network investment goes to security.</div><br /><div>On the software side, we are buying $150 million of security countermeasures (like static analysis and black box scanners) to protect $98 billion of software (you know the stuff that runs the whole business), roughly coming to about 0.2% of the software budget goes to security.</div><br /><div>This is very disturbing. From a prioritization standpoint The People&#39;s Republic of Information Security is misaligned by an order of magnitude at least. Next time you read about a data breach, or see an auditor&#39;s report with thousands of findings you won&#39;t have to wonder how it happened. It happened because Information Security doesn&#39;t have its eye on the ball, it invests in network security not because those controls have greater efficacy (the whole point of networks is they are dumb), no, they invest in network firewalls because they bought a bunch in 1995, some more in 1998, and heck they just kept buying them, the Checkpoint rep kept showing up and taking CISOs out to play golf, contracts got renewed, and poof - there goes the security budget.</div><br /><div>Consider that software security tools could grow 50% a year for five years and still be half of where Checkpoint is today.</div><br /><div>The optimistic way of looking at all this data is that there is major room for growth for software security, if you take network security as a target for a mature industry and assume that 2.3% is a reasonable margin of safety, then the software security space should evolve to around 2% of the software space meaning that it should evolve into a $2 billion space around fifteen times larger than it is today. Unprotected assets will either be protected or will cease to be assets, VCs get your check books ready.</div><br /><div>My friend Brian Chess has a nice way of looking at this he says 2007 was the turning point - &quot;the first year there was a bigger market for products that help you get code right than there was for products that help you demonstrate a problem exists.&quot;</div><br /><div>Now I am not suggesting that Information Security budgets have to be aligned with IT budget one for one, but I do think that looking at the overall IT budget is the starting point. If Information Security has a more cost effective security mechanism they should deploy it, but the starting point should be aligned to the business. Businesses spend most of their money on software, and there are very good reasons - competitive advantage, increased revenues and lower costs. Information Security spends most of its money on network security, and there is no good reason why, except that it was a seemingly good idea in 1995. You really don&#39;t have to go beyond the book value of IT investment as a whole versus Information Security to see a stunning disparity. Information Security&#39;s job is to deliver a Margin of Safety to the business, but they are not.&#0160;</div><br /><div>To deliver a real Margin of Safety to the business, I propose the following based on a defense in depth mindset. Break the IT budget into the following categories:</div><br /><div>- Network: all the resources invested in Cisco, network admins, etc.</div><div>- Host: all the resources invested in Unix, Windows, sys admins, etc.</div><div>- Applications: all the resources invested in developers, CRM, ERP, etc.</div><div>- Data: all the resources invested in databases, DBAs, etc.</div><br /><div>Tally up each layer. If you are like most business you will probably find that you spend most on Applications, then Data, then Host, then Network.</div><br /><div>Then do the same exercise for the Information Security budget:</div><br /><div>- Network: all the resources invested in network firewalls, firewall admins, etc.</div><div>- Host: all the resources invested in Vulnerability management, patching, etc.</div><div>- Applications: all the resources invested in static analysis, black box scanning etc.</div><div>- Data: all the resources invested in database encryption, database monitoring, etc.</div><br /><div>Again, tally each up layer. If you are like most business you will find that you spend most on Network, then Host, then Applications, then Data. Congratulations, Information Security, you are diametrically opposed to the business!</div><br /><div>Its not just about alignment for alignment&#39;s sake, its about applying controls as a way to have a Margin of Safety properly placed so that when not if there is a failure on a higher value asset you are relatively better positioned to deal with it.&#0160;</div><br /><div>The pure statistical approach can only take us so far. Buffett said he would be a lot poorer if all he did was listen to Ben Graham. Book value is great to see the diametric opposition mentioned above, but it doesn&#39;t really tell us much about the efficacy of the security mechanisms.</div><br /><div>What we do get out of this statistical approach is a screen. The asset value screen filters out subjective opinion and narrows the field for where we need to dig in to do the high value, time consuming analytical work.</div><br /><div>The second part of Warren Buffett&#39;s career and the second part of this talk leave behind pure statistical measures. In Warren Buffett&#39;s case he was joined by a guy named Charlie Munger who talked him out of the pure Ben Graham approach. Charlie Munger has a saying - &quot;a great business at a fair price beats a fair business at a great price.&quot; Where Graham was focused on price and margin of safety, Munger wants a fair price but also a high quality business. This lead to Warren Buffett&#39;s company Berkshire Hathaway investing in companies like Coca Cola, Wells Fargo, and American Express, where the prices were far from dirt cheap (as Graham would have wanted), but the long term returns were outstanding.</div><br /><div>In our world of Information Security, we start by aligning our priorities with the business using the thumbnail defense in depth approach, but then we would like to invest in high quality, effective controls.</div><br /><div>To get at the notion of control quality and effectiveness, I am going to start part 2 of this talk with a brief history of software. The first web software was just static HTML, but web software really got interesting when developers started creating dynamic websites using CGI an PERL.</div><br /><div>Once websites were hooked up to company databases and were not just serving static content, the security people realized they needed a security architecture, and they sprung into action. What they came up was was model that divided the world into &quot;good stuff&quot; which was comprised of all their networks, systems, and data; and then there was everything else the &quot;bad stuff&quot; on the Internet. So job one of the early days Internet security architecture was to separate all your good stuff (i.e. your network) for the bad stuff (the Internet). To do this the security people used a sophisticated tool called Visio to draw a flaming brick wall on the network diagram, and this flaming brick wall was supposed to keep the good stuff and the bad stuff separate.</div><br /><div>The security people also realized that the data and session tokens that they served up from their Web server would have to traverse the &quot;bad&quot; neighborhood called the Internet, so they added one more security mechanism to secure the last mile of the transaction - SSL between the browser and the Web server.</div><br /><div>And this was the state of the art security architecture used circa 1995 to protect the earliest dynamic web applications.</div><br /><div>What happened next was that the dotcom boom started to happen and businesses realized they could make some real money on the Web, the web apps started to get more sophisticated, more personalization, richer session experiences and so on. This led the Java people to create JSP and the Microsoft people to create ASP, and of course the PERL people to create even greasier PERL scripts, all of this in the effort to pooling resources and sessions on the Web server. The security people defended this new application programming model with network firewall and SSL.</div><br /><div>Around 1998, developers began building out more distributed N tier or 3 tier applications that separated the business logic layer, the presentation layer and the data access layer. Among other things, your web application could seamlessly integrate data from multiple back ends systems. Let&#39;s say you have pricing data in Oracle, order data in SAP, and customer data in a Mainframe. You write separate data access objects, apply business logic in the middle tier and then you tie it all together in a friendly user interface. At this point the web applications are beginning to integrate across departments and geographic boundaries, huge critical chunks of the business are now connected to the web. How did the security people defend this part of the business? They applied the same 1995 security architecture - network firewall and SSL.</div><br /><div>Around 1999-2000 timeframe businesses relied on web applications for major parts of the revenue, and the apps were built in different technologies like Java and Microsoft technologies, but the customer didn&#39;t care (still doesn&#39;t), the customer wanted (and still wants) data access and functionality. So to integrate the disparate technologies, SOAP and XML were deployed so that Microsoft could talk to Java and so Websphere could talk to Weblogic and so on. And, oh yes, SOAP and XML were used to connect B2B networks so partners in a supply chain and business process can exchange data and interoperate. &#0160;SOAP and XML present a fundamentally new programming model based on a message document style integration, where XML is used to mesh together data and functionality across platforms. SOAP and XML have no security model by default for authentication, authorization, and confidentiality. How did the security people deal with this? They kept the security architecture the same as they had in 1995 - network firewalls and SSL.</div><br /><div>The software world did not stop innovating in 2000 of course, in the last few years we have seen Web services and XML form the basis of baroque and powerful SOAs and simple REST applications. We have seen Web 2.0 come on the scene, and entirely new networked applications built on top of that.</div><br /><div>What we have not seen, is a single meaningful change in security architecture in 13 years. Developers have evolved, businesses have increasingly bet their entire business models on the web and they have increased security budgets. But what has the security architecture as its deployed in the field got to show for all of this? More firewalls and more SSL connections.</div><br /><div>Since Information Security has proven incapable of evolving, it is time to learn from a discipline that has mastered innovation - software development, and yes, I will step back in case the lightning bolts hits.</div><br /><div>What does software development focus on these days? Well, let&#39;s look at Service Oriented Architecture (SOA), all hype aside I look at SOA as a set of technologies that delivers three things:</div><br /><div>Virtualization: we want Beijing, Bangalore and Boston to communicate.</div><br /><div>Interoperability: we want our .Net stuff to talk to our java stuff.</div><br /><div>Reusability: how many order/claim/pricing/customer systems does one company need?</div><br /><div>To build out their SOA, developers separated the application interface from its implementation. So you can host the interface in a variety of locations, but its separate from the application logic and data.</div><br /><div>This is also a useful trick for putting services like SOAP through the firewall. SOAP was designed as a firewall friendly protocol. When SOAP first came out, Bruce Schneier said calling SOAP a firewall friendly protocol is like having a skull friendly bullet. Which is a great line and explains why his books fly off the shelves, it does not explain, why security people think an architecture designed in 1995 is the one we should be using today. Maybe the problem is not that the developers figured out how to go through the firewall to get the data their customers want, maybe the problem is that the firewall is the sum total of the security architecture, and it never adapted.</div><br /><div>A big part of this problem is that we have left Newton&#39;s world behind and entered Einstein&#39;s universe. Mainframes are Newton’s world, we have THE computer, THE price, THE record and so on.</div><br /><div>As Pat Helland explained [4,5], Mainframes are Newron&#39;s world, but Distributed computing is Einstein’s world. More specifically in the Einstein world of distributed computing - &quot;Computers don’t make decisions, computers try &#0160;to make decisions.&quot; Our computers don&#39;t really make a decision, they say you can buy this book from Amazon at this price, we have it in stock and will deliver on such and such a date. But the warehouse runs out, the pallet gets dropped in the warehouse, your boo is crushed, and the package is stolen off your front step. The computer confirmed your transaction, but the real world intervened.</div><br /><div>So we don&#39;t have iron clad decisions, instead its all about Memories (last time I checked your book was in stock), Guesses (we should be able to ship on this date) and Apologies (sorry the forklift ran over your book)</div><br /><div>Translating this into security, security mechanisms don’t make policy-based decisions, security mechanisms try to make policy-based decisions</div><br /><div>Some examples of memories, guesses and apologies in security</div><br /><div>Memories</div><div>Security Policies - for example Triple A policy</div><div>Triple A policies can memorize a map of subjects, objects, and roles. They can even replicate these memories and play them back at runtime to try to make policy enforcement decisions.</div><br /><div>Guesses</div><div>Security Policy Enforcement Decision</div><div>Unfortunately, while the policy enforcement decisions can be based on memorized logic, the decision itself is still a guess, even in the case of Triple A. Any guesses why? Because, the authentication process itself is a guess. It happens to be a guess that you then bind to a principal so it looks very official once you bind your guess to a Kerberos ticket or SAML assertion, but it still a guess.</div><br /><div>Apologies</div><div>Giant Global Bank is sorry your account was compromised!</div><div>And this leads to lots and lots of apologies by companies with poor access control models.</div><br /><div>Some additional examples of information security memories, guesses and apologies.</div><br /><div>Example Memories - Triple A Security Policies, Audit logs, User account information , Authorization Logic - concrete mapping Subject, Resource, Condition, Action</div><br /><div>Example Guesses - Security Policy Enforcement Decision Points, Authentication Logic, Monitoring, detection, fraud response</div><br /><div>Example Apologies - Identity Management tools - provisioning, deprovisioning, Reimburse customer for fraud losses, Compensating Transaction - Giant Global Bank is still sorry your account was compromised!</div><br /><div>The point of this is that security memories, guesses and apologies utilize different processes, different people, and different capabilities to be effective.</div><br /><div>What trends can we identify to lead us toward better qualitative analysis based on the best practices of virtualization, interoperability and reusability.</div><br /><div>Virtualization</div><div>Finding Vulnerabilities in a Virtualized World is a problem because applications are more configured than coded. Runtime behavior and structure not apparent due to weak typing and inversion of control.</div><br /><div>Result - finding bugs becomes harder. Action - use screens to target finding time and resources</div><br /><div>Fixing Vulnerabilities in a Virtualized World is a problem because how do I locate the controls when interfaces run in Beijing, Bangalore and Boston?</div><br /><div>Result - synchronization and/or replication of security policy is problematic. Action - decentralized policy enforcement points and policy decision points. &#0160;</div><br /><div>Interoperability</div><div>Finding interoperable vulnerabilities</div><div>XSS - Javascript is an equal opportunity offender - interoperability for developers and attackers alike.</div><br /><div>Fixing interoperable vulnerabilities</div><div>App servers, ESBs, and services are the attacker’s red carpet to your enterprise, right into your book of business. Interoperable access control can be leveraged across the enterprise.</div><br /><div>Use XML signature for authentication and integrity&#0160;</div><br /><div>&lt;SOAP:Envelope&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;SOAP:Header&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">		</span>&lt;WSSE:Security&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">			</span>&lt;ds:Signature&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">				</span>&lt;ds:Reference URI=‘#body’&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">		</span>&lt;/WSSE:Security&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;/SOAP:Header&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;SOAP:Body wsu:Id=‘body’&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">		</span>…</div><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;/SOAP:Body&gt;</div><div>&lt;SOAP:Envelope&gt;</div><br /><div>Use XML encryption to protect sensitive data, don&#39;t pass sensitive data in the clear</div><br /><div>&lt;?xml version=&#39;1.0&#39; encoding=&#39;UTF-8&#39;?&gt;</div><div>&lt;soapenv:Envelope xmlns:soapenv=&quot;http://schemas.xmlsoap.org/soap/envelope/&quot;&gt;</div><br /><div>&lt;soapenv:Body&gt;&lt;ns1:echo xmlns:ns1=&quot;http://sample01.samples.rampart.apache.org&quot;&gt;</div><br /><div><span class="Apple-tab-span" style="white-space:pre">	</span>&lt;param0&gt;My Credit Card Number&lt;/param0&gt;</div><div>&lt;/ns1:echo&gt;</div><div>&lt;/soapenv:Body&gt;</div><div>&lt;/soapenv:Envelope&gt;</div><br /><div>Encrypt the data</div><br /><div>&#0160;&lt;wsse:Security xmlns:wsse=&quot;http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd&quot; soapenv:mustUnderstand=&quot;1&quot;&gt;…</div><div>&#0160;&#0160; &#0160; &#0160; &#0160; &#0160; &#0160;&lt;xenc:EncryptedKey Id=&quot;EncKeyId-3020592&quot;&gt;</div><div>&#0160;&#0160; &#0160; &#0160; &#0160; &#0160; &#0160; &#0160; &lt;xenc:EncryptionMethod Algorithm=&quot;http://www.w3.org/2001/04/xmlenc#rsa-1_5&quot; /&gt;</div><div><span class="Apple-tab-span" style="white-space:pre">		</span> &lt;xenc:CipherValue&gt;</div><div>XNQ0a4legiie5mWFxO6CQkk2hhldYNnKroObue/LXS/VYtvaTgMbCujhGExDi+vlkU//Qc2/T6mx0WVTmBMT3z8rogha8jD+nS9Zr2Bc3CwoTh2lh8wL3D0DEu91iwJT9JByLGXvt7v9lyuxK0ooDOYEClsH974CPmTs3tBC+GQ=</div><div><span class="Apple-tab-span" style="white-space:pre">		</span>&lt;/xenc:CipherValue&gt; &#0160; &#0160; &#0160; &#0160; &#0160; &#0160; &#0160;&#0160;</div><div>&lt;/xenc:CipherData&gt;</div><br /><div>To ensure that these controls are applied use automated tools like static analysis to scan for security mechanism use and coverage.</div><br /><div>In terms of reusability findings and fixes consider two bug findings</div><br /><div>Session management bug: session state is passed around to every component, service and user. Makes for many high priority findings in audit report, also the fix is required on virtually every program</div><br /><div>Data validation bug: Data access object (DAO) has a SQL injection hole. One major high priority finding in report. DAO used by many business logic classes, one fix location serves many classes&#0160;</div><br /><div>To bring these factors together, I generally use a scorecard index [6], so you can measure such things as transport security, message security, threat protection and so on. The hard work in developing the index is developing a useful scale. A scale for XML tokens could use the following</div><br /><div>0: no token</div><div>1: hashed token</div><div>2: hashed and signed token</div><div>3: hashed and signed token from standard authoritative source</div><br /><div>An example scale for XML validation could use:</div><br /><div>0: no validation</div><div>1: schema validation</div><div>2: schema validation against hardened schema</div><div>3: schema validation against standard, hardened schema</div><br /><div>These indexed scales are used to show maturity across the factors in the scorecard. The first part of the talk described value, the value assessment is used to focus time and effort on high value assets. The value assessment can be determined quantitatively. There is hard analytical work to qualitatively determine the scorecard, index, and scales, the quantitative value assessment is used to screen out high value targets for these endeavors. The scoring index is used to track progress and improve quality over time. In the best case scenario, automated tools are used to perform the checks described in the index, and once security is automated just like software developers we may see security innovation make progress in years not decades.</div><br /><div>Thank you for your time.</div><br /><div>1 &quot;Risk Management is where the Money Is&quot; by Dan Geer,&#0160;<a href="http://catless.ncl.ac.uk/Risks/20.06.html">http://catless.ncl.ac.uk/Risks/20.06.html</a></div><br /><div>2 Berkshire Hathaway 2007 Shareholder Letter by Warren Buffett, <a href="http://www.berkshirehathaway.com/letters/2007ltr.pdf">http://www.berkshirehathaway.com/letters/2007ltr.pdf</a></div><br /><div>3 &quot;Software [In]security: Software Security Demand Rising, by Gary McGraw</div><div><a href="http://www.informit.com/articles/article.aspx?p=1237978">http://www.informit.com/articles/article.aspx?p=1237978</a></div><br /><div>4 &quot;SOA and Newton&#39;s Universe&quot; by Pat Helland, <a href="http://blogs.msdn.com/pathelland/archive/2007/05/20/soa-and-newton-s-universe.aspx">http://blogs.msdn.com/pathelland/archive/2007/05/20/soa-and-newton-s-universe.aspx</a></div><br /><div>5 &quot;Memories, Guesses and Apologies&quot; by Pat Helland, <a href="http://blogs.msdn.com/pathelland/archive/2007/05/15/memories-guesses-and-apologies.aspx">http://blogs.msdn.com/pathelland/archive/2007/05/15/memories-guesses-and-apologies.aspx</a></div><br /><div>6 &quot;Web Servicres Security Checklist&quot; by Gunnar Peterson, <a href="http://arctecgroup.net/pdf/WebServicesSecurityChecklist.pdf">http://arctecgroup.net/pdf/WebServicesSecurityChecklist.pdf</a></div>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 19:47:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security spends">information security spends</category>
      <category domain="http://securityratty.com/tag/safety information security">safety information security</category>
      <category domain="http://securityratty.com/tag/versus information security">versus information security</category>
      <category domain="http://securityratty.com/tag/information security budgets">information security budgets</category>
      <category domain="http://securityratty.com/tag/information security budget">information security budget</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/software security space">software security space</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/the-economics-of-finding-and-fixing-vulnerabilities-in-distributed-systems-.html">The Economics of Finding and Fixing Vulnerabilities in Distributed Systems </source>
    </item>
    <item>
      <title><![CDATA[CISSPs Lend me your ears]]></title>
      <link>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</link>
      <guid>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</guid>
      <description><![CDATA[Art of Information Security endorses Dan Houser for(ISC)²Board of Directors
The CISSP isundoubtablyone of the most, if not the most, important professional certifications in Information Security....]]></description>
      <content:encoded><![CDATA[<p><strong>Art of Information Security endorses Dan Houser for (ISC)² Board of Directors</strong></p>
<p>The CISSP is undoubtably one of the most, if not the most, important professional certifications in Information Security. Many organizations and practitioners rely on it as evidence of a solid foundation and track record in Information Security. But the CISSP is only one of the many ways that the (ISC)² attempts to fulfill its mission of developing the Information Security profession.</p>
<p>Board membership is a role of governance, guidance, and passion. Let&#8217;s briefly explore how Dan&#8217;s track record and past contributions demonstrate his qualification for this post, and possibly your vote.</p>
<p><strong>Passion</strong></p>
<p>Dan is someone who has a passion for promoting and developing the talent needed to continue to grow and mature our profession. Anyone who has seen Dan speak at conferences, local chapter meetings, or in one of his classes knows how passionate Dan is! But anyone who takes the time to approach him knows that he is no ideologue or zealot; Dan is always interested in improving his own understanding, and then sharing that knowledge with others.</p>
<p>Dan has a long track record as a contributor - as a &#8220;giver&#8221; - to the profession. In addition to teaching over a dozen CISSP review courses, he has also served on multiple (ISC)² committees, is one of the authors of the ISSAP Body of Knowledge (cryptography), and has published primary research on professional certifications. He is also the founder of the monthly Columbus, Ohio Information Security MBA (Masters of Beer Appreciation) meeting - a professional roundtable that attracts practitioners from across the state.</p>
<p><strong>Governance and Guidance <br />
</strong></p>
<p>In addition to past experience serving on (ISC)² committees, which I assume led to the current board&#8217;s nomination, Dan has served on numerous Boards of Directors including local and regional community organizations, ISSA chapters,and several Toastmasters clubs. </p>
<p><strong>Personal Experiences</strong></p>
<p>I have known Dan for almost three yeas. Dan and I have collaborated on a number or projects, including a half-day Cryptographic Controls Seminar and a full-day Identity Management Architecture class. It is my feeling that when you collaborate, work closely, and travel with someone, you really get to know them. You get to do more than hear about their College Sweethearts (which, for Dan, is Rebecca, his wife of 21 years), but you also get to understand their ethics, how they really conduct themselves, how they deal with stress, etc.</p>
<p>Given the entire picture, the understanding that I have of Dan Houser, I can think of no one better suited to representing, guiding and developing the (ISC)². I have voted for Dan, and I hope that you will consider doing the same.</p>
<p>Here is the voting link for (ISC)²: <a href="https://webportal.isc2.org/custom/votenow.aspx%20" onclick="javascript:pageTracker._trackPageview('/outbound/article/https://webportal.isc2.org/custom/votenow.aspx%20');" target="_blank">https://webportal.isc2.org/custom/votenow.aspx</a></p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/105/cissps-lend-me-your-ears/" >CISSPs&#8230; Lend me your ears&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/456765137" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 01:15:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dan">dan</category>
      <category domain="http://securityratty.com/tag/dan houser">dan houser</category>
      <category domain="http://securityratty.com/tag/dan foralmostthree yeas">dan foralmostthree yeas</category>
      <category domain="http://securityratty.com/tag/dans track record">dans track record</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/track record">track record</category>
      <category domain="http://securityratty.com/tag/information security profession">information security profession</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/profession">profession</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/456765137/">CISSPs Lend me your ears</source>
    </item>
    <item>
      <title><![CDATA[Show 032 - An Interview with Jeremiah Grossman]]></title>
      <link>http://securityratty.com/article/b0449f2ccd72f29ee2665301bb7c2d9e</link>
      <guid>http://securityratty.com/article/b0449f2ccd72f29ee2665301bb7c2d9e</guid>
      <description><![CDATA[The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman. Gary and Jeremiah discuss clickjacking, cross-site request...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Jeremiah Grossman" title="Jeremiah Grossman" src="http://www.cigital.com/silverbullet/jgrossman-125.png" style="padding-left: 7px;" /></p>
<p>The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman.  Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can&#8217;t be discovered reliably automatically, and which conferences Jeremiah most enjoyed on his 2008 world tour.</p>
<ul>
<li><a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a></li>
<li><a href="http://jeremiahgrossman.blogspot.com/2008/10/clickjacking-web-pages-can-see-and-hear.html">Clickjacking</a></li>
<li><a href="http://www.webadminblog.com/index.php/2008/09/24/new-0day-browser-exploit-clickjacking-owasp-appsec-nyc-2008/">Adobe 0-day Browser Exploit</a></li>
<li><a href="http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf">Cross-Site Request Forgeries: Exploitation and Prevention</a> [PDF]</li>
<li><a href="http://www.cs.princeton.edu/sip/pub/spoofing.php3">Web Spoofing: An Internet Con Game</a> by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2007/05/web-application-scan-o-meter.html">Web application scan-o-meter</a></li>
<li><a href="http://1.bp.blogspot.com/_JdybrokZBAk/SO_rUc-ebPI/AAAAAAAABOY/dKbFPJfv1Cs/s1600-h/badgewall.jpg">The &#8220;Wall of Fame&#8221;</a></li>
</ul>
<p></p>
]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 23:17:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/jeremiah grossman">jeremiah grossman</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/web application scan-o-meter">web application scan-o-meter</category>
      <category domain="http://securityratty.com/tag/chief technology officer">chief technology officer</category>
      <category domain="http://securityratty.com/tag/internet con game">internet con game</category>
      <category domain="http://securityratty.com/tag/whitehat security">whitehat security</category>
      <category domain="http://securityratty.com/tag/conferences jeremiah">conferences jeremiah</category>
      <category domain="http://securityratty.com/tag/32nd episode">32nd episode</category>
      <category domain="http://securityratty.com/tag/prevention pdf">prevention pdf</category>
      <source url="http://www.cigital.com/silverbullet/show-032/">Show 032 - An Interview with Jeremiah Grossman</source>
    </item>
    <item>
      <title><![CDATA[Hosting meets the cloud]]></title>
      <link>http://securityratty.com/article/5ce6d3370e235e215b980a588e616472</link>
      <guid>http://securityratty.com/article/5ce6d3370e235e215b980a588e616472</guid>
      <description><![CDATA[Im out at The 451 Group Client Conference in Boston, lovely Boston. Its been over ten years since I lived here, but somehow Boston always has a feel of home
After meetings and calls, I was finally...]]></description>
      <content:encoded><![CDATA[<p>I’m out at <a href="http://clientconference.the451group.com/na/2008/" target="_blank">The 451 Group Client Conference</a> in Boston, lovely Boston. It’s been over ten years since I lived here, but somehow Boston always has a feel of home.</p>
<p>After meetings and calls, I was finally able to slip into a conference session – just in time to catch uber-smart analysts Rachel Chalmers (<a href="http://the451group.com/" target="_blank">The 451 Group</a>) and Dan Golding (<a href="http://tier1research.com/" target="_blank">Tier1 Research</a>) engage in a lively and not-so-mock debate on “<a href="http://clientconference.the451group.com/na/2008/agenda.html" target="_blank">Hosting Meets the Cloud</a>”.</p>
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0021.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 5px; border-right-width: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image002-thumb.jpg" border="0" alt="clip_image002" width="240" height="157" align="left" /></a>Now this doesn’t cover the entire debate – and part II is coming tomorrow. But what it does cover is the most interesting questions (to me) and paraphrase the points made by the analysts. I thought they both had very interesting points and more similarities than differences in the end; the real difference is how they thought about the issues and through what lens – for Rachel it was the enterprise and for Dan it was managed hosting providers.<em> (</em><a href="http://images.inmagine.com/img/inspirestock/ispc037/ispc037046.jpg" target="_blank"><em>image from inmagine</em></a><em>)</em></p>
<p><strong><em>Question: What is a cloud and why?</em></strong></p>
<p><strong>Dan:</strong> Shared infrastructure leveraged/run by third parties for the benefit of enterprises, developers, etc. This is not a new idea – just recently “rebranded.” Given all the discussion and disagreement over this now, what will the cloud end up looking like?</p>
<p><strong>Rachel:</strong> The cloud is “IT infrastructure as a service” down to the level of a server operating system. Take the example of <a href="http://www.cmswatch.com/Trends/1418-Cloud-computing---Ellison-rants,-others-reap?source=RSS" target="_blank">Amazon web services</a> – in this case it’s not just the infrastructure but also the internal processes built around service delivery, e.g., provisioning, that are being exposed as a commodity to external customers.</p>
<p><strong><em>Dan’s Question for Rachel: In your opinion, how much is the <a href="http://computerworld.co.nz/news.nsf/devt/74F46C52ACB5316CCC2574F9007B3A37" target="_blank">cloud a fad versus CIOs</a> really trying to solve a problem?</em></strong></p>
<p><strong>Rachel:</strong> For the practical, roll-up-your-sleeves types of CIOs – those coming up from the engineering ranks – that I talk to, the cloud is real, as opposed to SOA and middleware.</p>
<p><strong><em>What about “internal” cloud computing – built and maintained by an enterprise versus a third-party provider?</em></strong></p>
<p><strong>Dan:</strong> Cloud computing is done by providers for customers. Certainly there are <a href="http://www.mashget.com/2008/11/02/salesforcecom-extends-cloud-computing-service/" target="_blank">enterprises that have made internal computing investments</a>, e.g., for publishing, large-scale phone systems, etc - but they were stupid ideas made by companies that have too much money. A better question here is does it make any sense for an enterprise to create their own cloud? While an enterprise can play at it, they can’t do it cost-effectively, not in a way that a third party provider can do it.</p>
<p><strong>Rachel:</strong> Many CIOs have “managed-hoster” envy – for things like chargeback and billing that hosters understand a do better. Of course there has been a rise in automation and virtualization tools in the enterprise which may not be as efficient and built for scalability as a hoster can achieve, but what is important is that they are customized/specialized for that business.</p>
<p><strong>Dan:</strong> Can you give a specific example of optimization to make it worthwhile for enterprises to do it themselves?</p>
<p><strong>Rachel:</strong> One example is sovereignty. The privacy laws around financial and healthcare information are not the same everywhere. Clouds and their geographically-dispersed data centers don’t necessarily have “national” borders. This is definitely a concern for the CIO that has to <a href="http://www.intomobile.com/2008/11/10/security-are-you-comfortable-sharing-your-information-with-%E2%80%98the-cloud%E2%80%99.html" target="_blank">comply with regulations in their industry around privacy protection</a>, for instance. Another example is security. Dow Chemical does a lot of work via joint ventures and has a need to provide but lock down desktops given to contractors as corporate workspaces. For their level of security, they need to “own” their computing resources.</p>
<p><strong>Dan:</strong> But why can’t someone like <a href="http://sungard.com/" target="_blank">SunGard</a> provide that as they do for many other large companies?</p>
<p><strong>Rachel:</strong> It comes down to a question of trust.</p>
<p><strong><em>Do people trust their hosting providers?</em></strong></p>
<p><strong>Dan</strong>: Yes. Whether it’s for a content delivery network or collocation, hosting the customers of hosting providers are some of the largest companies in the world in industries like energy and financial services. Give me a case when there was a major security issue with a hosting company. In fact, managed hosting providers usually provide better security than enterprises are capable of.</p>
<p><strong><em>And a question provided by an attendee from EMC: A few years ago, this would have been <a href="http://www.symmetrymagazine.org/breaking/2008/10/24/computing-in-a-grid-or-a-cloud/" target="_blank">a grid discussion. How is the cloud different</a>?</em></strong></p>
<p><strong>Rachel</strong>: Grid computing ended up being applicable only for niches – which I predicted. The real opportunity for everyone else with the cloud only comes up when you combine the kinds of automation tools (originally developed for grid computing) with x86 virtualization.</p>
<p><strong>Dan</strong>: I agree. Grid was a niche play. There were very few orgs that needed it and that the economics worked for. There were very few enterprises for whom it made sense to build their own for. The cloud is shared/leveraged versus grid computing. It economically makes sense in a way grid never did.</p>
]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 18:38:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/internal cloud">internal cloud</category>
      <category domain="http://securityratty.com/tag/grid">grid</category>
      <category domain="http://securityratty.com/tag/grid discussion">grid discussion</category>
      <category domain="http://securityratty.com/tag/rachel">rachel</category>
      <category domain="http://securityratty.com/tag/dan">dan</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/enterprise">enterprise</category>
      <category domain="http://securityratty.com/tag/versus grid">versus grid</category>
      <source url="http://blog.sciencelogic.com/hosting-meets-the-cloud/11/2008">Hosting meets the cloud</source>
    </item>
    <item>
      <title><![CDATA[What's Happiness Got to Do With It?]]></title>
      <link>http://securityratty.com/article/141d4a55a5d3195a7aaaa7ca4b3a3c7e</link>
      <guid>http://securityratty.com/article/141d4a55a5d3195a7aaaa7ca4b3a3c7e</guid>
      <description><![CDATA[Gartner's own John Pescatore has issued a 12 world post
The best security program is at the business with the happiest customers

Happiness? Really? That's the measure of program effectiveness? I...]]></description>
      <content:encoded><![CDATA[<p>Gartner&#39;s own John Pescatore has issued a 12 world <a href="http://blogs.gartner.com/john_pescatore/2008/10/28/twelve-word-tuesday-measuring-security-program-effectiveness/">post:</a></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 17px; ">The best security program is at the business with the happiest customers.</span></p></blockquote><br /><div>Happiness? Really? That&#39;s the measure of program effectiveness? I would see those 12 words and raise them one word (13 if you&#39;re scoring at home):</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>There&#39;s a fine line between happy customers and playing piano in a bordello.</p></blockquote><br /><div>I mean the people running hedge funds and derivative books at AIG, Lehman and friends had lots of happy customers for the last decade!</div><br /><div>To me the happy customer is a classic IT copout &quot;we just did what the &quot;business&quot; asked&quot;. Like we&#39;re just a bystander or something. Its our job to create business value and be business like. We should seek to <span style="font-style: italic;">empower</span> out customers, not make them happy.&#0160;</div><br /><div>Please understand I am not that guy who says IT security has to be the &quot;bad cops&quot; who deny everything the business wants to do. Just saying it is our job to raise the bar where we can. Raising the bar does not always create super happy customers in the short run, but it does empower companies.</div><br /><div>Unfortunately, playing piano in the bordello is what a lot of security groups do and even big analyst firms. The path of least resistance ain&#39;t always the way. Here is an example. I was at a client many years ago, they wanted to build a big Identity Management solution, so of course they wrote a big RFI got responses from Sun, IBM, Oracle and friends. The bids were in the $3-5 million range. Pretty big projects for an Infosec team. So what do you do? Call up a big analyst firm and get some advice, right?</div><br /><div>A week goes by and we get an audience with the &quot;guru&quot; from the Big Analyst Firm. The client has pretty detailed requirements, what systems they want to connect to, what use cases they are looking to solve for, &#0160;and so on. We anxiously await the knowledge the analyst is about to transfer to us. His response was as follows - &quot;what kind of shop are you? IBM shop? Oracle shop?&quot; &quot;Ummm...we are a huge company we have everything.&quot; &quot;Well if you are more of a IBM shop you should go with them. If you are more of a Oracle shop you should go with them.&quot; That was the extent of a 30 minute conversation. True story.</div><br /><div>Of course, the one value proposition of the Big Analyst Firms is that they supposedly can tell you what everyone else is supposedly doing. There is some value in this I grant you. And it does make for happy customers because even when you force your customers to change, you can say &quot;Well geez, I know its hard but the Big Analyst Firm says that everyone is doing it.&quot; But is this security improvement?</div><br /><div>Back in 2004, I went to a great security conference, it was Information Security Decisions (<a href="http://infosecurityconference.techtarget.com/conference/index.html">they are back in Chicago next week</a>). It was in Chicago, downtown on the river. Tom Davern even took us all out on a boat for lunch one day. Anyway, there was one truly great talk there. It wasn&#39;t Fred Cohen debating <a href="http://cigital.com/justiceleague/">Gary McGraw</a> on application security which was outstanding (in which Fred uttered the memorable line &quot;I agree with Gary everywhere he agrees with me.&quot; (Gary won the debate, his best line - &quot;We know how to win the software security war, but we don&#39;t know how to manage the peace&quot; still the problem today actually)) It wasn&#39;t Pete Lindstrom showing his security metrics framework (which is still a great starting point). it wasn&#39;t Dan Geer&#39;s fireside chat.</div><br /><div>The truly great talk, though, was by the now departed <a href="http://1raindrop.typepad.com/1_raindrop/2007/02/thinking_about_.html">Robert Garigue</a>. It was called &quot;Its the End of the CISO as I Know It, (And I Feel Fine).&quot; The whole end to end talk was wonderful, there are several things in there that I still use every single day like the separate security models for Infostructure and Infrastructure but the point I want to talk about is the CISO role.</div><br /><div>Garigue talked about the two most prevalent CISO models - the jester and the bad cop. The jester CISO</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; ">Sees a lot</span><br /><span style="color: #333333; line-height: 19px; ">Can tell the king he has no clothes</span><br /><span style="color: #333333; line-height: 19px; ">Can tell the king he really is ugly</span><br /><span style="color: #333333; line-height: 19px; ">Does not get killed by the king</span><br /><span style="color: #333333; line-height: 19px; ">Nice to have around but…how much security improvement comes from this ?</span></p></blockquote><p><span style="color: #333333; line-height: 19px;"><br /></span></p><div><span style="color: #333333; line-height: 19px;">The jester has happy customers! At least for awhile.</span></div><div><span style="color: #333333; line-height: 19px;"><br /></span></div><div><span style="color: #333333; line-height: 19px;">Again I grant you bad cop is not the way to go either (and while this already long post could read harsh on John Pescatore&#39;s pithy summary, I give him a lot of points for saying that security needs to be customer conscious).</span></div><div><span style="color: #333333; line-height: 19px;"><br /></span></div><div><span style="color: #333333; line-height: 19px;">We have all seen bad cop CISOs who</span></div><div><span style="color: #333333; line-height: 19px;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; ">Changes happened faster that he was able to move</span><br /><span style="color: #333333; line-height: 19px; ">Did not read the signs</span><br /><span style="color: #333333; line-height: 19px; ">Good intentions went unfulfilled</span><br /><span style="color: #333333; line-height: 19px; ">A brutal way to ending a promising career</span><br /><span style="color: #333333; line-height: 19px; ">Sad to have around but…how much security improvement comes from this ?</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px;"><br /></span></p></blockquote><p><span style="color: #333333; line-height: 19px;"></span></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">Obviously these models of CISOs are not solving our information security problems. Instead Dr. Garigue points us to Charlemagne as a better model</p><blockquote style="margin-top: 10px; margin-bottom: 10px; "><p>King of the Franks and Holy Roman Emperor; conqueror of the Lombards and Saxons (742-814) - reunited much of Europe after the Dark Ages.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">He set up other schools, opening them to peasant boys as well as nobles. Charlemagne never stopped studying. He brought an English monk, Alcuin, and other scholars to his court - encouraging the development of a standard script.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">He set up money standards to encourage commerce, tried to build a Rhine-Danube canal, and urged better farming methods. He especially worked to spread education and Christianity in every class of people.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">He relied on Counts, Margraves and Missi Domini to help him.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">Margraves - Guard the frontier districts of the empire. Margraves retained, within their own jurisdictions, the authority of dukes in the feudal arm of the empire.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">Missi Domini - Messengers of the King.</p></blockquote><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">This is the way forward! Find software security champions in the architecture and development groups,help them understand the real security issues. They will find solutions you have not thought of. Same for DBAs, same for business analysts even. Its all about beating the bushes, education, and decentralizing security services. Specifically, he points out this important mandate for IT security</p><p></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; ">Knowledge of risky things is of strategic value</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; ">How to know today tomorrow’s unknown ?</span><br /><span style="color: #333333; line-height: 19px; ">How to structure information security processes in an organization so as to identify and address the NEXT categories of risks ?</span></p></blockquote><p><span style="color: #333333; line-height: 19px;"></span></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">To me this is our mandate and measure of effectiveness. Empower our customers, educate, and create business value. If I am a CISO &#0160;I don&#39;t want 20 people reporting to me who do firewall ruleset changes. I want one champion in 20 different groups - development teams, architects, DBAs, business analysts.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">A concrete example, infosec can continue to go along with the herd and follow the &quot;what everyone else is doing architecture&quot; meanwhile developers are connecting <span style="font-style: italic;"><span style="font-weight: bold;">every single thing</span></span> in your business to the Web. I have been doing integration and new technology projects for a long time, and let me tell you - Change does not always create happy customers in the short run. But the chart below shows that information security is maybe more concerned with not causing waves rather than adapting.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "></p>
<div><a href="http://1raindrop.typepad.com/photos/uncategorized/2008/05/19/innovatecompare_2.png"><img alt="Innovatecompare_2" border="0" height="167" src="http://1raindrop.typepad.com/1_raindrop/images/2008/05/19/innovatecompare_2.png" title="Innovatecompare_2" width="300" /></a><p></p></div><div>How long can developers evolve, connect everything and security people not change anything? Herb Stein said, &quot;things that can&#39;t go on forever, don&#39;t. &quot;At some point these chickens are coming home to roost, there is a yawning gap between rapidly evolution connecting the enterprise and the 13 year old and counting security architecture that &quot;Everyone else is using&quot; and when those chicken come home to roost you may not have happy customers then. Here is my 12 words:</div><br /><p></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 17px; ">The best security program is at the business with sustainable competitive advantage.</span></p></blockquote>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 07:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information security decisions">information security decisions</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/software security champions">software security champions</category>
      <category domain="http://securityratty.com/tag/architecture">architecture</category>
      <category domain="http://securityratty.com/tag/security architecture">security architecture</category>
      <category domain="http://securityratty.com/tag/security metrics framework">security metrics framework</category>
      <category domain="http://securityratty.com/tag/super happy customers">super happy customers</category>
      <category domain="http://securityratty.com/tag/happy customers">happy customers</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/whats-happiness-got-to-do-with-it-1.html">What's Happiness Got to Do With It?</source>
    </item>
    <item>
      <title><![CDATA[Three years of Blue Box podcasts....]]></title>
      <link>http://securityratty.com/article/cc61b7549892d897fdca3fb3d3366a42</link>
      <guid>http://securityratty.com/article/cc61b7549892d897fdca3fb3d3366a42</guid>
      <description><![CDATA[Today is a special day for me. It was three years ago on October 24, 2005, that Blue Box Podcast #1 was uploaded . It was an 11-minute episode where I talked about... Skype security, SIP security,...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml">Today is a special day for me.  It was three years ago on October 24, 2005, that <a href="http://www.blueboxpodcast.com/2005/10/blue_box_podcas.html">Blue Box Podcast #1 was uploaded</a>.  It was an 11-minute episode where I talked about... Skype security, SIP security, IETF, VOIPSA and some other VoIP security news.....   (Hmmm... sounds  lot like our <em>recent</em> shows, too, eh?)

<p>Jonathan Zar joined me a week later on <a href="http://www.blueboxpodcast.com/2005/11/blue_box_podcas.html">Blue Box Podcast #2</a> and we've been going ever since.  We've now produced over 112 episodes, had close to 245,000 downloads of our various shows, met some amazing people, learned a lot along the way... and hopefully helped you all learn a lot out there as well.

<p>Thank you to all of you who have joined with us on this journey... whether you've listened to our show from the very beginning (and we know of a couple of you who have) or have only recently joined in... <em>thank you</em>!

<p>And now... on to the next three years...  :-)


<!-- Technorati Tags Start -->
<p>Technorati Tags:
<a href="http://technorati.com/tag/blue%20box" rel="tag">blue box</a>, <a href="http://technorati.com/tag/bluebox" rel="tag">bluebox</a>, <a href="http://technorati.com/tag/dan%20york" rel="tag">dan york</a>, <a href="http://technorati.com/tag/danyork" rel="tag">danyork</a>, <a href="http://technorati.com/tag/jonathan%20zar" rel="tag">jonathan zar</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/voipsa" rel="tag">voipsa</a>
</p>
<!-- Technorati Tags End --></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=OCOyT6"><img src="http://feeds.feedburner.com/~a/BlueBox?i=OCOyT6" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=I5uhM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=I5uhM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=f4w9M"><img src="http://feeds.feedburner.com/~f/BlueBox?i=f4w9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Nsx0M"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Nsx0M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=FD20M"><img src="http://feeds.feedburner.com/~f/BlueBox?i=FD20M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=PfrRm"><img src="http://feeds.feedburner.com/~f/BlueBox?i=PfrRm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=lfcHM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=lfcHM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/431331276" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 17:35:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/sip security">sip security</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/blue box podcast">blue box podcast</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/jonathan zar">jonathan zar</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/431331276/three-years-of-blue-box-podcasts.html">Three years of Blue Box podcasts....</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #85: Internet phone calls and terrorism, Georgia Tech report on Emerging Cyber Security Threats, phone jamming, 802.1X-REV, 802.1AE, VoIP sec]]></title>
      <link>http://securityratty.com/article/cb989104e329dbb2131be2e5f8569ab2</link>
      <guid>http://securityratty.com/article/cb989104e329dbb2131be2e5f8569ab2</guid>
      <description><![CDATA[Synopsis: Blue Box #85: Internet phone calls and terrorism, Georgia Tech report on Emerging Cyber Security Threats, phone jamming, 802.1X-REV, 802.1AE, VoIP security news and more
Welcome to Blue Box:...]]></description>
      <content:encoded><![CDATA[<p><strong>Synopsis:</strong> Blue Box #85: Internet phone calls and terrorism, Georgia Tech report on Emerging Cyber Security Threats, phone jamming, 802.1X-REV, 802.1AE, VoIP security news and more

</p><hr></hr><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #85, a 32-minute podcast  from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.    </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-085-2008-10-17.mp3" rel="enclosure">Download the show here</a> (MP3, 15 MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.  </p>

 

<p>You may also listen to this podcast right now:</p> 

<p><object data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-085-2008-10-17.mp3" height="20" type="application/x-shockwave-flash" width="200"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-085-2008-10-17.mp3&amp;bgcolor=#FFFFFF"></param></object> </p> 

<p><strong>Show Content:</strong></p> 
 


	



<div>


<div>

</div>
</div><ul>
 <li>00:20 - Intro to the show, contact information and how to provide comments.  Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Three-year anniversary of Blue Box coming up on October 24th - any thoughts you'd like to share with us? (Please send them to us by October 23rd.)</li>
		
	</ul>
</li>
<li>The Times: "<a href="http://www.timesonline.co.uk/tol/news/uk/crime/article4951864.ece" id="wz0c" title="Internet phone calls are crippling fight against terrorism">Internet phone calls are crippling fight against terrorism</a>" - and <a href="http://voipsa.org/blog/2008/10/16/internet-phone-calls-terrorism-and-finding-the-balance-for-law-enforcement/" id="f.3z" title="my response on the Voice of VOIPSA blog">my response on the Voice of VOIPSA blog</a> </li>
<li>FierceVoIP: "<a href="http://www.fiercetelecom.com/story/uk-crime-fighting-concern-over-voip-calls-social-networks/2008-10-16" id="b1kd" title="UK crimefighting concern over VoIP calls, social networks">UK crimefighting concern over VoIP calls, social networks</a>"  </li>
<li>BBC: <a href="http://news.bbc.co.uk/2/hi/uk_news/7671759.stm" id="ef5t" title="Data powers behind the times">Data powers behind the times</a>  <br>
</li>
<li><a href="http://www.gtiscsecuritysummit.com/pdf/CyberThreatsReport2009.pdf" id="mo0b" title="GA Tech Survey (PDF)">GA Tech Survey (PDF) </a>(link <a href="http://www.techlinks.net/blogs/events/archive/2008/09/25/gtisc-security-summit.aspx" id="a5cx" title="about the GA conference">about the GA conference</a> )</li>
<li>Dark Reading: <a href="http://www.darkreading.com/document.asp?doc_id=166029&amp;WT.svl=news2_1" id="ipct" title="Cellphone Botnets, Blackmailing VOIP &amp; a Healthy Cybercrime Economy">Cellphone Botnets, Blackmailing VOIP &amp; a Healthy Cybercrime Economy</a></li>
<li>bMighty.com: <a href="http://www.bmighty.com/blog/main/archives/2008/10/georgia_techs_s.html" id="dkj." title="Georgia Tech Security Report Scarier Than Its Football Team">Georgia Tech Security Report Scarier Than Its Football Team</a> </li>
<li>cNet: <a href="http://news.cnet.com/8301-1009_3-10067994-83.html" id="f-to" title="Botnets on cell phones in 2009?">Botnets on cell phones in 2009?</a> </li>
<li>telecoms.com: <a href="http://www.telecoms.com/itmgcontent/tcoms/news/articles/20017581221.html" id="r76:" title="Smartphone is a hotbed of security issues">Smartphone is a hotbed of security issues</a> <br>
</li>
<li>VNUnet: <a href="http://www.vnunet.com/vnunet/news/2228330/security-industry-falling" id="znq2" title="Security industry falling behind hackers">Security industry falling behind hackers</a> <br>
</li>
<li>AP: <a href="http://hosted.ap.org/dynamic/stories/P/PHONE_JAMMING?SITE=WSAW&amp;SECTION=HOME&amp;TEMPLATE=DEFAULT" id="pgn:" title="Phone Jamming in NH">Phone Jamming in NH</a> <br>
</li>
<li>GigaOm: <a href="http://gigaom.com/2008/10/17/eef-challenges-telco-immunity-in-court/" id="d_dk" title="EEF Challenges Telco Immunity in Court">EEF Challenges Telco Immunity in Court</a>  <br>
</li>
<li>Information Week: <a href="http://www.informationweek.com/news/infrastructure/ethernet/showArticle.jhtml?articleID=210605169&amp;cid=RSSfeed_IWK_All" id="r.gq" title="New Protocols Secure Layer 2">New Protocols Secure Layer 2</a></li>
<li>Voice of VOIPSA: <a href="http://voipsa.org/blog/2008/10/08/asking-the-cisco-systems-ipics-and-jps-raytheon-acu-2000-experts-questions-36-40/" id="wpk1" title="Asking The Cisco Systems IPICS and JPS Raytheon ACU-2000 Experts: Questions 36-40">Asking The Cisco Systems IPICS and JPS Raytheon ACU-2000 Experts: Questions 36-40</a></li>
<li>Other <a href="http://www.voipsa.org/blog/" id="ogdq" title="Voice of VOIPSA">Voice of VOIPSA</a> articles</li>
<li><a href="http://www.tmcnet.com/usubmit/-snom-technology-ag-snom-820-combines-mature-voip-/2008/10/15/3705379.htm" id="kija" style="color: #551a8b;" title="news release">snom technology AG: snom 820 combines mature VoIP technology with exclusive design</a></li>
<li><a href="http://www.marketwatch.com/news/story/idc-finds-increasing-hype-around/story.aspx?guid=%7B095A1E35-5F22-42D7-A223-53A3E1300419%7D&amp;dist=hppr" id="gddr" title="IDC Finds Increasing Hype Around Unified Communications Is Affecting How Customers Select Telephony Systems and Services">IDC Finds Increasing Hype Around Unified Communications Is Affecting How Customers Select Telephony Systems and Services </a>(interesting movement in the top vendors used  - Nortel out and IBM in)</li>
<li><a href="http://www.tmcnet.com/channels/voice-peering/articles/43001-peerless-voip-peering.htm" id="m:8s" title="Peerless VoIP Peering">Peerless VoIP Peering</a> </li>
<li>Comment (IM) from Christian Wieser
</li>
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list<br>
</li>
<li>Wrap-up of the show<br>
</li>
<li>32:10 - End of show  </li>
</ul>
 

<p>Comments, suggestions and feedback are welcome either as replies to this post  or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.  Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.  You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.  </p> <p>Thank you for listening and please do let us know what you think of the show. </p>
<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=q8ShIv"><img src="http://feeds.feedburner.com/~a/BlueBox?i=q8ShIv" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=7jX2M"><img src="http://feeds.feedburner.com/~f/BlueBox?i=7jX2M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=pTeQM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=pTeQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=qtKhM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=qtKhM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=TU2zM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=TU2zM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Mlwwm"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Mlwwm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=wV3sM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=wV3sM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/429956306" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 10:42:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/internet phone calls">internet phone calls</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/voip calls">voip calls</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/georgia tech report">georgia tech report</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/429956306/blue-box-85-internet-phone-calls-and-terrorism-georgia-tech-report-on-emerging-cyber-security-threats-phone-jamming-802.html">Blue Box #85: Internet phone calls and terrorism, Georgia Tech report on Emerging Cyber Security Threats, phone jamming, 802.1X-REV, 802.1AE, VoIP sec</source>
    </item>
    <item>
      <title><![CDATA[Partial Disclosure - The Good, Bad, and Ugly]]></title>
      <link>http://securityratty.com/article/0f6f787360fca21b1b1d9b08ece3672b</link>
      <guid>http://securityratty.com/article/0f6f787360fca21b1b1d9b08ece3672b</guid>
      <description><![CDATA[There is apparently a bit of fear going around information security circles that the next big trend in the disclosure wars is going to be Partial Disclosure. In the past, the vulnerability research...]]></description>
      <content:encoded><![CDATA[<p>There is apparently a bit of fear going around information security circles that the next big trend in the disclosure wars is going to be &#8220;Partial Disclosure&#8221;. In the past, the vulnerability research community has embraced the concepts of &#8220;Full Disclosure&#8221; and/or &#8220;Non-Disclosure&#8221;. Once those concepts had been sufficiently played out, the general consensus was to move towards &#8220;Responsible Disclosure&#8221; whereby the security researcher responsibly discloses the discovered vulnerability to the vendor and works in a cooperative fashion in an effort to minimize the risk to the general user populous. This has worked well in the vast majority of cases that I have had the pleasure of managing the disclosure process.</p>
<p><b>Partial Disclosure - The Good</b></p>
<p>The responsible disclosure process tends to break down in rare occasions where the vendor doesn&#8217;t want to fix the issue. When this occurs, the researcher is put into a difficult position whereby full disclosure could put users&#8217; systems at high risk of compromise. The other case where partial disclosure becomes an alternative is when the researcher has discovered a design flaw in a protocol or underlying multiple vendor component. Examples of this case include the DNS flaws published this past summer by Dan Kaminsky and the TCP denial of service condition discovered by Robert E. Lee and Jack Louis that is currently in the disclosure process. When the flaw affects a very large number of vendors and the actual problem is located within the underlying protocols that support the communications of the Internet as a whole, one possible solution is to follow a partial disclosure model where phasing the details to the general public can be used to encourage adoption and creation of patches throughout the enormous target audience.</p>
<p><b>Partial Disclosure - The Bad</b></p>
<p>What is driving the fear surrounding partial disclosure is the potential for abuse. When a major flaw is partially disclosed, a number of potential issues may occur. First and foremost, the further along the partial disclosure path we are, the more details will be released to the public, and the higher the probability that someone (either good or bad intentioned) will figure out the exploit and disclose the details. Second, when partially disclosing, the vendor&#8217;s hand is being forced into a situation that could speed up fixes, reduce testing, and cause ripple problems elsewhere within the infrastructure. It is difficult enough to dance the fine time line when doing responsible disclosure, but if we are escalated to the point of partial disclosure, additional fuel is added to the fire.</p>
<p><b>The Ugly</b></p>
<p>The real ugly part of partial disclosure is when we add to the equation the ability to spread fear, uncertainty, and doubt into the normal user community. It is generally well accepted that FUD can be used to drive additional revenue. If it is possible to increase the perceived magnitude of the &#8220;problem&#8221; that your product or service solves, it is possible to directly impact the demand for that product or service. That is the major fear imposed by the growing trend of partial disclosure. By releasing just enough information to trigger wide scale speculation into the flaw, it is possible to create buzz and garner media attention resulting in a lot of speculation and very little hard facts around the issue. The potential for abuse by the security industry at large is enormous.</p>
<p><b>The Fix</b></p>
<p>Some have suggested a group of security researchers be convened to vet the requirement of partial disclosure and to allow for independent peer review of any security research that requires the partial disclosure process. This suggestion leaves questions regarding who would stand on this group and who would be impartial enough to ensure that the right thing was always done regardless of profit potential. It also leaves open the opportunity for member researchers to utilize the information gathered during the vetting process to position themselves to profit from the data upon release. It might be wiser to rely on a higher level authority or government entity to manage this process and use the services of security researchers as required for subject matter expertise. While a group of this type wouldn&#8217;t ensure that all partial disclosure is appropriate, it would hopefully limit the potential for abuse and the ever present chance that people try to profit from the FUD that surrounds the current partial disclosure process.</p>
]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 09:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/partial disclosure">partial disclosure</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/responsible disclosure process">responsible disclosure process</category>
      <category domain="http://securityratty.com/tag/partial disclosure process">partial disclosure process</category>
      <category domain="http://securityratty.com/tag/disclosure">disclosure</category>
      <category domain="http://securityratty.com/tag/partial disclosure model">partial disclosure model</category>
      <category domain="http://securityratty.com/tag/responsible disclosure">responsible disclosure</category>
      <category domain="http://securityratty.com/tag/partial disclosure path">partial disclosure path</category>
      <category domain="http://securityratty.com/tag/disclosure andor non-disclosure">disclosure andor non-disclosure</category>
      <source url="http://www.veracode.com/blog/2008/10/partial-disclosure-the-good-bad-and-ugly/">Partial Disclosure - The Good, Bad, and Ugly</source>
    </item>
    <item>
      <title><![CDATA[Blue Box's 3-year anniversary coming up on Friday... ]]></title>
      <link>http://securityratty.com/article/a116eaf0133996627443234f07d74420</link>
      <guid>http://securityratty.com/article/a116eaf0133996627443234f07d74420</guid>
      <description><![CDATA[It was three years ago Friday, on October 24, 2005, that I uploaded Blue Box Podcast #1 , an 11-minute show where I introduced the show, talked about VoIP security news (To no surprise, I was talking...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml">It was three years ago Friday, on October 24, 2005, that I uploaded <a href="http://www.blueboxpodcast.com/2005/10/blue_box_podcas.html">Blue Box Podcast #1</a>, an 11-minute show where I introduced the show, talked about VoIP security news (To no surprise, I was talking about Skype security!), some projects of VOIPSA and some other podcasts people might find interesting. A week later, on Halloween 2005, Jonathan joined me in <a href="http://www.blueboxpodcast.com/2005/11/blue_box_podcas.html">Blue Box Podcast #2</a> and we were off and running...

<p>Three years later... 84 main Blue Box episodes (with one more recorded) .... 26 Special Editions (with about 10 in the queue)... almost <em>250,000</em> downloads... we're still here and, with an admitted bit of a rough patch this summer, are still going along creating shows and enjoying what we do.

<p>Jonathan and I are planning to record a 3-year show on this coming Friday, October 24th, and if you have any comments you would like us to include in that show, please do get them to us by the end of the day on Thursday, October 23rd.  You can send them to us via:
<ul>
<li>Email to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>
<li>Phone to +1-415-830-5439
<li>Phone via SIP to <a href="sip:bluebox@voipuser.org">sip:bluebox@voipuser.org</a>
</ul>
<p>The show started out 3 years ago as really an experiment in seeing whether or not podcasting could be used to reach out to very specific audiences... and it's been both fun, amazing and interesting to see how well it's done.
<p>Thank you to all of you who have continued to listen and contribute over the years!


<!-- Technorati Tags Start -->
<p>Technorati Tags:
<a href="http://technorati.com/tag/blue%20box" rel="tag">blue box</a>, <a href="http://technorati.com/tag/bluebox" rel="tag">bluebox</a>, <a href="http://technorati.com/tag/voip" rel="tag">voip</a>, <a href="http://technorati.com/tag/voip%20security" rel="tag">voip security</a>, <a href="http://technorati.com/tag/security" rel="tag">security</a>, <a href="http://technorati.com/tag/dan%20york" rel="tag">dan york</a>, <a href="http://technorati.com/tag/jonathan%20zar" rel="tag">jonathan zar</a>, <a href="http://technorati.com/tag/voipsa" rel="tag">voipsa</a>
</p>
<!-- Technorati Tags End --></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=rawl4P"><img src="http://feeds.feedburner.com/~a/BlueBox?i=rawl4P" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=pWXDM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=pWXDM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=eOTOM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=eOTOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=IXAsM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=IXAsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=4qxNM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=4qxNM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=58c0m"><img src="http://feeds.feedburner.com/~f/BlueBox?i=58c0m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=uhaaM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=uhaaM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/426937191" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 15:22:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/blue box podcast">blue box podcast</category>
      <category domain="http://securityratty.com/tag/friday">friday</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <category domain="http://securityratty.com/tag/october 24th">october 24th</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/426937191/blue-boxs-3-yea.html">Blue Box's 3-year anniversary coming up on Friday... </source>
    </item>
    <item>
      <title><![CDATA[Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities from VoIPShield, Skype in China, UCSniff and other new tools, news and more]]></title>
      <link>http://securityratty.com/article/5ad9e83dc3458677a18e9f3f40c0fb21</link>
      <guid>http://securityratty.com/article/5ad9e83dc3458677a18e9f3f40c0fb21</guid>
      <description><![CDATA[Synopsis: Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities from VoIPShield, Skype in China, UCSniff and other new tools, news and more
Welcome to Blue Box: The VoIP Security...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities
from VoIPShield, Skype in China, UCSniff and other new tools, news and
more

</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #84, a 30-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-084-2008-10-10.mp3" rel="enclosure">Download the show here</a> (MP3, MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-084-2008-10-10.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-084-2008-10-10.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 


	<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Three-year anniversary of Blue Box coming up on October 24th - any thoughts you'd like to share with us? (Please send them to us by October 23rd.)</li>
		
	</ul>
</li>

<li><a href="http://www.marketwatch.com/news/story/voipshield-uncovers-new-security-vulnerabilities/story.aspx?guid=%7B956C0D98-121F-4E95-BC14-3B5F448AF25A%7D&amp;dist=hppr">VoIPShield announces new vulnerabilities</a> and <a id="r9se" href="http://www.voipshield.com/research.php" title="http://www.voipshield.com/research.php">http://www.voipshield.com/research.php</a></li>

<li><span style="font-family: Arial;"><a href="http://www.theregister.co.uk/2008/09/30/voip_eavesdropping_tool">http://www.theregister.co.uk/2008/09/30/voip_eavesdropping_tool</a><span style="font-size: 0.8em;">/</span></span></li>

<li><span style="font-family: Arial;"><span style="font-size: 0.8em;">&quot;Sipera Develops VoIP Spy Program - to Prove a Point&quot; - <a title="http://www.voipplanet.com/trends/article.php/3776136" href="http://www.voipplanet.com/trends/article.php/3776136" id="gfhu">http://www.voipplanet.com/trends/article.php/3776136</a></span></span></li>

<li><span style="font-family: Arial;"><span style="font-size: 0.8em;"><a href="http://www.marketwatch.com/news/story/securelogix-announces-free-availability-voip/story.aspx?guid=%7BF1947C89-8177-4FA2-A40E-8D6E021BF558%7D&amp;dist=hppr">SecureLogix Announces Free Availability of VoIP Security Tools</a></span></span></li>

<li>NY Times: Surveillance of Skype Messages Found in China - <a title="http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;partner=rssnyt&amp;pagewanted=print" href="http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;partner=rssnyt&amp;pagewanted=print" id="dnb2">http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;partner=rssnyt&amp;pagewanted=print</a> </li>

<li><a title="http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html" href="http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html" id="i8rz">http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html</a> </li>

<li><a title="http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439" href="http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439" id="ugx5">http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439</a> </li>

<li>Skype CEO's blog post about the issue: <a title="http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html" href="http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html" id="mucu">http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html</a></li>

<li><span style="font-family: Arial;"><a title="http://www.itbusinessedge.com/blogs/top/?p=398" href="http://www.itbusinessedge.com/blogs/top/?p=398">http://www.itbusinessedge.com/blogs/top/?p=398</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.voip-news.com/feature/google-phone-europe-growth-092408/" href="http://www.voip-news.com/feature/google-phone-europe-growth-092408/">http://www.voip-news.com/feature/google-phone-europe-growth-092408/</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.itnewsafrica.com/?p=1269" href="http://www.itnewsafrica.com/?p=1269">http://www.itnewsafrica.com/?p=1269</a></span></li>

<li><span style="font-family: Arial;"><a title="http://news.cnet.com/8301-1009_3-10052393-83.html" href="http://news.cnet.com/8301-1009_3-10052393-83.html">http://news.cnet.com/8301-1009_3-10052393-83.html</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039" href="http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039">http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.itbusinessedge.com/blogs/top/?p=402" href="http://www.itbusinessedge.com/blogs/top/?p=402">http://www.itbusinessedge.com/blogs/top/?p=402</a></span></li>

<li><span style="font-family: Arial;"><a id="tvjh" href="http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/" title="http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/">http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/</a></span></li>

<li><span style="font-family: Arial;"><a title="http://eon.businesswire.com/news/eon/20080924005342/en" href="http://eon.businesswire.com/news/eon/20080924005342/en">http://eon.businesswire.com/news/eon/20080924005342/en</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.crn.com/security/210602442" href="http://www.crn.com/security/210602442">http://www.crn.com/security/210602442</a></span></li>

<li><span style="font-family: Arial;"><a title="http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm" href="http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm">http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html" href="http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html">http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html</a></span></li>

<li>No comments this week.<br />
</li>

<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list<br />
</li>

<li>Wrap-up of the show<br />
</li>

<li>30:26 - End of show&nbsp; </li></ul> <p><em>NOTE: Long-time listeners will note that the show notes above are in a less descriptive form than usual. After almost three years of using one wiki for preparing for our shows, Jonathan and I switched to using a new system and are still working out some of the details that will speed the input into show notes. </em></p>

<p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=vzRu3i"><img src="http://feeds.feedburner.com/~a/BlueBox?i=vzRu3i" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=MSaWM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=MSaWM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Uy3HM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Uy3HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=yGFHM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=yGFHM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=eCUOM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=eCUOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=ZOgKm"><img src="http://feeds.feedburner.com/~f/BlueBox?i=ZOgKm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=5vEnM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=5vEnM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/426417749" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 04:32:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/voipshield">voipshield</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/audio comments">audio comments</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/skype messages">skype messages</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/426417749/blue-box-84-new.html">Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities from VoIPShield, Skype in China, UCSniff and other new tools, news and more</source>
    </item>
  </channel>
</rss>
