<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: difficulty]]></title>
    <link>http://securityratty.com/tag/difficulty</link>
    <description></description>
    <pubDate>Tue, 01 Jul 2008 15:03:10 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Rational Risk Management, Angry Italians, and Irrational Security Analysts]]></title>
      <link>http://securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</link>
      <guid>http://securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</guid>
      <description><![CDATA[Hope you all had a great weekend. I had meant to point you earlier to a FAIR analysis that Chris Hayes did over at his Blog . But Ive been a little busy, and before I could mention it, Stuart King put...]]></description>
      <content:encoded><![CDATA[<p>Hope you all had a great weekend.  I had meant to point you earlier to a <strong><a href="http://risktical.com/2008/11/06/security-template-exception-part-2-%E2%80%93-the-assessment/">FAIR analysis that Chris Hayes did over at his Blog</a></strong>.  But I&#8217;ve been a little busy, and before I could mention it, Stuart King <strong><a href="http://www.computerweekly.com/blogs/stuart_king/2008/11/ive-written-up-a-report.html">put up a kind of angry response</a></strong> on his ComputerWorld blog.  Snark aside, there are a couple of other really troubling aspects of Stuart&#8217;s reaction to Chris&#8217; analysis that I thought we could talk about this morning.</p>
<blockquote><p>The problem is that (Chris&#8217; analysis is) completely impractical. I&#8217;ll take a recent, and fairly typical situation as an example. I was taking issue with the manner in which remote access was being provisioned for a third party vendor to connect to a system hosted by one of our European business units. To cut a long story short, it was not only a breach of policy but highly insecure. I wanted the access to be disconnected, the business unit director wanted my risk assessment. And he didn&#8217;t want to wait for it.</p>
<p>To quote Chris Hayes, spending time on working out <em> <strong>the expected effectiveness of controls, over a given timeframe, as measured against a baseline level of force </strong></em>was not going to pacify an angry Italian fearful that my decision was going to cost him money. He wanted my explanation of the risk and more importantly, what I was going to offer as a solution to keep his business functioning</p></blockquote>
<p>As Chris is someone who actually does this for a living in a large company, and this is typical of his actual day job, I really find Stuart&#8217;s &#8220;impractical&#8221; comment to be, um, misinformed.</p>
<p>Also, I think Stuart mistakes the purpose of a risk analysis.  The purpose of the risk analysis is not to force someone to be &#8220;secure&#8221;, but to provide knowledge for decision making.  Using it as a &#8220;hammer&#8221; to knock in the nail of your personal risk tolerance impairs efficiency and in the long run retards &#8220;security&#8221; as it creates political resentment.  Seriously, who cares if something might violate policy or not in a pre-implementation discussion?  Policies are not stone tablets handed down from on high, they are state-in-time codification of the <em><strong>data owners </strong></em>risk tolerance.  This risk tolerance changes sometimes, and that&#8217;s OK.</p>
<p>To that extent, I appreciate (and I&#8217;m sure Chris does, as well) that risk analysis does not create rationality in the data owner.  Someone who sees you as a speedbump on the route to progress they may not be ready to appreciate your point of view even if it is stated in the most rational manner possible.   But it&#8217;s worth noting (and Stuart&#8217;s example is indicative of this point) that <em><strong>risk analysis does not create rationality in the analyst, either</strong></em>.  If one is being so &#8220;security minded&#8221; as to ignore the risk tolerance of the business owner - we&#8217;re bound to get a reaction similar to that Stuart encountered.  In fact, a practical risk analysis like Chris performed on his blog, done in 30 minutes, should identify the critical point of disagreement between Stuart and the data owner (again, Stuart doesn&#8217;t own the data, the agitated Italian does).</p>
<p>But let&#8217;s stay rational and open to alternatives to what Chris offers.  Stuart states his approach to risk analysis as:</p>
<blockquote><p>When I need to document a risk assessment I use a very simple form: list the threats, state the level of vulnerability, list the associated operational costs and potential revenue hits. High, medium, or low risk? Describe the controls and options. Write up who needs to do what, and how much of their time it&#8217;s going to take. Job done.</p></blockquote>
<p>At first glance, I don&#8217;t think what Chris has done is any less efficient, and it provides greater insight (using Frequency and Capability instead of just &#8216;listing the threats&#8217;).  But what is key here is that Chris&#8217; approach is consistent and defensible.  Less generous risk geeks and CSO&#8217;s I know would have no little difficulty with Stuart&#8217;s approach.  But to particularly answer Stuart&#8217;s main objection (impracticality) I would offer that with practice, Chris&#8217; work is probably quicker and easier than Stuart&#8217;s described process as it eliminates much of the ambiguity an immature risk analysis creates - reducing the need for further discussion and arguments with data owners (regardless of disposition or nationality).</p>
<p>Finally the irony of Stuart&#8217;s post is that the reason he had this confrontation may in fact be because he was incapable of bringing a salient model for risk to the table, one that identified the factors that create risk and developed a defensible belief statement concerning risk.   We&#8217;ll never know if one would have helped him in this isolated instance, but I can tell you that in organizations like Chris&#8217;, good risk models and strong risk anlayses create operational efficiencies, reduce costs, and streamlines intra-departmental communications.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 13:43:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk tolerance">risk tolerance</category>
      <category domain="http://securityratty.com/tag/risk models">risk models</category>
      <category domain="http://securityratty.com/tag/practical risk analysis">practical risk analysis</category>
      <category domain="http://securityratty.com/tag/strong risk anlayses">strong risk anlayses</category>
      <category domain="http://securityratty.com/tag/generous risk geeks">generous risk geeks</category>
      <category domain="http://securityratty.com/tag/immature risk analysis">immature risk analysis</category>
      <category domain="http://securityratty.com/tag/quote chris hayes">quote chris hayes</category>
      <category domain="http://securityratty.com/tag/chris hayes">chris hayes</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=520">Rational Risk Management, Angry Italians, and Irrational Security Analysts</source>
    </item>
    <item>
      <title><![CDATA[Saved by SaaS: Data backup via software as a service]]></title>
      <link>http://securityratty.com/article/1ccc2dbc192adf243aa44f3ec3c9dd5f</link>
      <guid>http://securityratty.com/article/1ccc2dbc192adf243aa44f3ec3c9dd5f</guid>
      <description><![CDATA[SaaS data backup is becoming an increasingly attractive option for many companies that have difficulty with in-house backup. SaaS providers handle support and maintenance of a variety of applications...]]></description>
      <content:encoded><![CDATA[SaaS data backup is becoming an increasingly attractive option for many companies that have difficulty with in-house backup. SaaS providers handle support and maintenance of a variety of applications over the Internet without requiring their clients to invest in any servers or install software on-site.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1abdf4f18ff6dda9a90283fb7b3e8c53:m1I%2Boss1okw%2BW%2BDgsf1bSNzlQjEhC9b1cDhiTRKU4jbJWwWcmqDYHuQC6W5L3U%2BDLVtmm4r19Ftf'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:63195fa65154eb7c9f82b4058bdb73f1:lWC7pR0V0TX6w0hzjfJxjizzo%2BKZ8Z3p4Gr6EWFYVOSOkmJIlhB5An7spSPmFVx%2FTC6b9DG6u%2F1%2F8A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ae1333c9b75150ba58ce64a4f6e62c53:74TIj0K5qYbqbfio1rcNuhZ13PBZIxvp2niPJwY%2Bie2IOoBv0R0Ft6WVGOYCPAsH7oizcxQ%2Bj13BqA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2ddbf6978d160c23c34af27f34f092db:3XcCP3DCsCqnz51pWpjHSAWzhB0VFxTSATZ4SbONSKZMvu%2F6xKB8XiyKLvRe6DS8487MZzDjJE9x4A%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=9656ce5584e9fb21da19c3d93a247f12" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=9656ce5584e9fb21da19c3d93a247f12" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/install software on-site">install software on-site</category>
      <category domain="http://securityratty.com/tag/saas data backup">saas data backup</category>
      <category domain="http://securityratty.com/tag/increasingly attractive option">increasingly attractive option</category>
      <category domain="http://securityratty.com/tag/in-house backup">in-house backup</category>
      <category domain="http://securityratty.com/tag/variety">variety</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/difficulty">difficulty</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9656ce5584e9fb21da19c3d93a247f12">Saved by SaaS: Data backup via software as a service</source>
    </item>
    <item>
      <title><![CDATA[SDL Sessions at BlueHat]]></title>
      <link>http://securityratty.com/article/bddb4f5b0c8437f73140811dafbc6401</link>
      <guid>http://securityratty.com/article/bddb4f5b0c8437f73140811dafbc6401</guid>
      <description><![CDATA[Bryan here. Last January, I wrote a post on this blog bemoaning the difficulty of making security interesting and sexy to developers. Applied research conferences generally place a much greater...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Bryan here. Last January, I wrote a post on this blog bemoaning the difficulty of making security interesting and “</FONT><A href="http://blogs.msdn.com/sdl/archive/2008/01/29/sexy-development-lifecycle.aspx"><FONT face=Calibri color=#0000ff size=3>sexy</FONT></A><FONT face=Calibri size=3>” to developers. Applied research conferences generally place a much greater emphasis on revealing new vulnerabilities and new attack techniques, and much less emphasis on educating people on how to actually fix those vulnerabilities. I was at </FONT><A href="http://www.rsaconference.com/"><FONT face=Calibri color=#0000ff size=3>RSA Conference</FONT></A><FONT size=3><FONT face=Calibri> last April, and I attended a session by a very well-regarded, high-profile security researcher. He gave an eloquent and educational presentation on the dangers of a significant new attack vector, but all the prescriptive guidance he gave for dealing with the threat amounted to something like, “If you’re worried about this kind of thing, talk to your browser manufacturer.” No offense to this presenter, but if I’m going to listen to 70 minutes of discussion of a dangerous threat, I want to leave the room with a clear understanding of what I can do to solve the problem! It’s not enough just to know that the problem exists.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>So, in conjunction with the </FONT><A href="http://blogs.technet.com/bluehat/"><FONT face=Calibri size=3>BlueHat</FONT></A><FONT size=3><FONT face=Calibri> team, I am pleased to announce that the SDL team will be organizing the sessions for the second day of the fall BlueHat conference. The BlueHat SDL sessions will be laser-focused on not just describing vulnerabilities but also solving them. Every attendee should leave every presentation with a clear idea of exactly what he or she needs to do to protect themselves from the threat that was discussed during the session.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>The sessions will begin, appropriately, with the topic of secure design. Danny Dhillon of </FONT><A href="http://www.emc.com/"><FONT face=Calibri size=3>EMC</FONT></A><FONT face=Calibri size=3> and the SDL team’s own Adam Shostack will each present their organization’s approach to threat modeling. As a bonus, Adam will also be demonstrating the new </FONT><A href="http://download.microsoft.com/download/1/5/0/150636A9-9EA8-4D00-9E6B-2723F4C188B4/Microsoft%20SDL%20Threat%20Modeling%20Tool%203.0.pdf"><FONT face=Calibri size=3>SDL Threat Modeling tool</FONT></A><FONT face=Calibri size=3> that you might have heard about </FONT><A href="http://blogs.msdn.com/sdl/archive/2008/09/16/sdl-press-tour-announcements.aspx"><FONT face=Calibri size=3>last week</FONT></A><FONT size=3><FONT face=Calibri>. <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Next up is Matt Miller, a recent and very welcome </FONT><A href="http://blogs.msdn.com/michael_howard/archive/2008/08/18/matt-miller-joins-the-security-science-team.aspx"><FONT face=Calibri size=3>addition</FONT></A><FONT face=Calibri size=3> to the Microsoft Security Science team. Matt has a fantastic presentation on the evolution of buffer overflow attacks and on the corresponding development of overflow mitigations. From there we will switch gears to look at some managed code implementation issues: </FONT><A href="http://www.isecpartners.com/"><FONT face=Calibri size=3>iSEC Partners</FONT></A><FONT size=3><FONT face=Calibri>’ Scott Stender and Alex Vidergar will demonstrate coding techniques to mitigate elusive concurrency vulnerabilities in web applications.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>At this point we will have covered the Design and Implementation phases of the SDL; where better to go from here than Verification? One of the most important activities in the Verification phase is fuzzing, and we have a trio of security experts from the Microsoft Security Science team to talk about it. Jason Shirk, Lars Opstad, and Dave Weinstein will answer three of the most common fuzzing questions: How should I fuzz? When have I fuzzed enough? And what do I do now that I’ve fuzzed? <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Finally, we will wrap up the Verification phase talks with a return appearance to BlueHat by </FONT><A href="http://www.stachliu.com/"><FONT face=Calibri size=3>Stach &amp; Liu</FONT></A><FONT size=3><FONT face=Calibri>’s Vinnie Liu. Vinnie will compare different approaches to security verification – static code analysis, blackbox analysis, and manual code review – and make recommendations as to when each approach is best used.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Even if you can’t make it in to BlueHat in person, you can still watch the sessions via streaming media on </FONT><A href="http://technet.microsoft.com/"><FONT face=Calibri color=#0000ff size=3>TechNet</FONT></A><FONT face=Calibri size=3>. Additionally, webcast interviews with the speakers – condensed “Cliff’s Notes” versions of their full presentations – will be posted on </FONT><A href="http://channel9.msdn.com/Search/Default.aspx?Term=bluehat"><FONT face=Calibri color=#0000ff size=3>Channel 9</FONT></A><FONT size=3><FONT face=Calibri>. And we’ll be continuing the BlueHat tradition of inviting speakers and other industry notables to guest blog about their topics and the latest security trends. More information on all of these resources will be posted here when it becomes available.<o:p></o:p></FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8965212" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 12:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/bluehat">bluehat</category>
      <category domain="http://securityratty.com/tag/sessions">sessions</category>
      <category domain="http://securityratty.com/tag/sdl team">sdl team</category>
      <category domain="http://securityratty.com/tag/sdl threat">sdl threat</category>
      <category domain="http://securityratty.com/tag/bluehat sdl sessions">bluehat sdl sessions</category>
      <category domain="http://securityratty.com/tag/bluehat conference">bluehat conference</category>
      <category domain="http://securityratty.com/tag/verification phase talks">verification phase talks</category>
      <category domain="http://securityratty.com/tag/verification phase">verification phase</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/09/25/sdl-sessions-at-bluehat.aspx">SDL Sessions at BlueHat</source>
    </item>
    <item>
      <title><![CDATA[The Importance of Trust]]></title>
      <link>http://securityratty.com/article/a237a38c2b93a16a5d0702327c562838</link>
      <guid>http://securityratty.com/article/a237a38c2b93a16a5d0702327c562838</guid>
      <description><![CDATA[As an instructor and trainer, I am constantly reinforcing the importance of living by one's word

Integrity, Honor, Loyalty - all of these fine characteristics are the building blocks upon which...]]></description>
      <content:encoded><![CDATA[As an instructor and trainer, I am constantly reinforcing the importance of living by one's word.  <br /><span id="fullpost"><br />Integrity, Honor, Loyalty - all of these fine characteristics are the building blocks upon which reputations are raised.  It is of the utmost importance in any walk of life to "live by your word", but in the security profession - especially where the protecting of life is concerned, it is everything. <br /></span><br />I attended National Stadium last night and watched the Washington Nationals beat the New York Mets.  I was fortunate to have been invited to enjoy the game from the president's box.  During the pre-dinner networking, I ran into a business owner whom I had met a few years previously.  He had been introduced to me at that time as his business involved him being around some area celebrity sporting stars.<br /><br />Being interested in a chance to possibly offer executive protection services to these stars, I arranged to meet with this business owner to discuss how we might be able to assist one another.  I remember it was during the winter and the roads were a little suspect in places as I drove the 25-30 miles to be closer to his location.  <br /><br />I arrived a little early, as is my custom and waited for him to arrive.  It became clear after about an hour that he was experiencing some difficulty or had some other reason for being so late.  I left a few voice mails and called it quits after around 90 minutes.  He never returned any of my calls but when I reached him about a week later he admitted that something else had come up.  Unfortunately, he did not think it worth his while to let me know this with a phone call.<br /><br />So, here I am last night and this same person is introduced to me once again.  Maybe he didn't remember back three years ago because he started to tell me about some connection that he knew that may be a "good fit" for my company.  His small talk fell on deaf ears.  He had already lost all credibility with me and eventhough I have not thought about it once in the inetrvening years, as soon as I saw him it came back as clear as day.<br /><br />In his book; "The Speed of Trust", the author Stephen M.R. Covey sums it up best - "keeping commitments is based on the principles of integrity, performance, courage and humility.  It is the perfect balance of character and competence. Particularly, it involves integrity (character) and your ability to do what you say you are going to do (competence)."<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 15:46:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/importance">importance</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business owner">business owner</category>
      <category domain="http://securityratty.com/tag/integrity">integrity</category>
      <category domain="http://securityratty.com/tag/involves integrity">involves integrity</category>
      <category domain="http://securityratty.com/tag/utmost importance">utmost importance</category>
      <category domain="http://securityratty.com/tag/competence">competence</category>
      <category domain="http://securityratty.com/tag/security profession">security profession</category>
      <category domain="http://securityratty.com/tag/deaf ears">deaf ears</category>
      <source url="http://www.thebulletproofblog.com/2008/09/importance-of-trust.html">The Importance of Trust</source>
    </item>
    <item>
      <title><![CDATA[Reputation Damage & Measurement]]></title>
      <link>http://securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</link>
      <guid>http://securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</guid>
      <description><![CDATA[Reputation damage can be one of the most difficult concepts to build measurements around. In fact, it can be difficult to develop the actual metrics for the measurements, as well. Damage to things...]]></description>
      <content:encoded><![CDATA[<p>Reputation damage can be one of the most difficult concepts to build measurements around.  In fact, it can be difficult to develop the actual metrics for the measurements, as well.  Damage to things like &#8220;corporate reputation&#8221; and &#8220;goodwill&#8221; and &#8220;brand equity&#8221; can be difficult to wrap even reasonable dollar estimates around (When I use FAIR, I really only care to use one metric when describing loss magnitudes - the almighty currency).</p>
<p>Complicating factors is the impact (or lack thereof) of incidents on stock price.  Many researchers who identify themselves with the <strong><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787">New School of Information Security</a></strong> (yours truly included) want to immediately look at stock price as a bell-weather metric for incident impact.  I think this stems from our days of slinging FUD, back when we could scream &#8220;Buy a firewall or we&#8217;ll have an incident and you&#8217;ll be on the front page of the paper and the stock price will go down!&#8221;  But these days notable incidents seem to suggest that the impact on stock price for an incident is short lived.  <em><strong>With qualifications, of course.</strong></em></p>
<p>So what would/should we make of this from <a href="http://www.money.co.uk/article/1001229-12-million-wiped-off-helphire-stock-after-malicious-gmail-sent-to-clients.htm">Money.co.uk</a>?</p>
<p style="text-align: center;"><strong>£12million ($24m) Wiped off Helphire Stock after Malicious Email Sent to Clients</strong></p>
<blockquote><p>Car hire firm Helphire have taken Google to court after a malicious email sent from a Gmail account saw their shares plummet £12million in a single day.</p>
<p>The Bath-based business who specialise in providing replacement cars to &#8216;no-fault&#8217; drivers involved in accidents on behalf of car insurance companies, initiated legal proceedings against the search engine giant as part of their attempt to find out who is responsible for sending the defamatory mailing.</p>
<p>Google are now known to have complied with the court order and have controversially supplied details of the email account and ISP used by the meddler.</p>
<p>Written under the psudoname Peter Franks, the 1200 word email is know to have been sent from a gmail account that was opened specifically for this purpose and closed a few minutes after the damage had been done&#8230;</p>
<p>&#8230;The misdemeanour couldn’t have come at a worse time for the struggling firm who have undergone a £45million rights issue and seen a 75% drop in the value of their stock already this year.</p></blockquote>
<p>That last paragraph, for me, explains some of the difficulty in tying reputation damage to stock decreases.  It&#8217;s like when you read the headlines from Bloomberg about why the days stocks (or commodity) prices are up or down.  You know, the &#8220;Oil closes $3 higher on news that a notable South American dictator has a rather unpleasant boil in a very uncomfortable area&#8221; type of headlines.  You really do have to question the causality and correlation.  So in the Helphire case above - is this new drop in stock really because of the email sent?  If so, should we view that $24mil number as an independent data point to describe this sort of attack on reputation, or is the magnitude aggravated due to the long-term trend of stock price?</p>
<p>Even when we have &#8220;Objective Data&#8221; (an in-joke for Adam S.) like this decline in stock price, it is really difficult to provide any sort of precise estimate or measurement - about the future, present or past.  The best we can do is use ranges, distributions, that are reasonable based on evidence and observation.</p>
<p>So it&#8217;s worth filing away this sort of datum for future use - while dutifully acknowledging the qualifiers we might place around it.</p>
<p>So the questions I ask here - what should we make of this new information, and how should we view the $24million drop - they&#8217;re not rhetorical.  I am very interested in your views and welcome your comments!</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:33:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stock">stock</category>
      <category domain="http://securityratty.com/tag/helphire stock">helphire stock</category>
      <category domain="http://securityratty.com/tag/reputation damage">reputation damage</category>
      <category domain="http://securityratty.com/tag/reputation">reputation</category>
      <category domain="http://securityratty.com/tag/stock price">stock price</category>
      <category domain="http://securityratty.com/tag/damage">damage</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email account">email account</category>
      <category domain="http://securityratty.com/tag/malicious email">malicious email</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=387">Reputation Damage &amp; Measurement</source>
    </item>
    <item>
      <title><![CDATA[TSA Follies]]></title>
      <link>http://securityratty.com/article/f014b8f845713a3e6bc73c172d773b7c</link>
      <guid>http://securityratty.com/article/f014b8f845713a3e6bc73c172d773b7c</guid>
      <description><![CDATA[They break planes : Citing sources within the aviation industry, ABC News reports an overzealous TSA employee attempted to gain access to the parked aircraft by climbing up the fuselage... reportedly...]]></description>
      <content:encoded><![CDATA[<p>They <a href="http://www.aero-news.net/index.cfm?ContentBlockID=340a79d6-839a-470d-b662-944325cea23d">break planes</a>:</p>

<blockquote>Citing sources within the aviation industry, ABC News reports an overzealous TSA employee attempted to gain access to the parked aircraft by climbing up the fuselage... reportedly using the Total Air Temperature (TAT) probes mounted to the planes' noses as handholds.

<p>"The brilliant employees used an instrument located just below the cockpit window that is critical to the operation of the onboard computers," one pilot wrote on an American Eagle internet forum. "They decided this instrument, the TAT probe, would be adequate to use as a ladder."</blockquote></p>

<p>They <a href="http://www.cnn.com/2008/US/08/19/tsa.watch.list/index.html?iref=mpstoryview">harass innocents</a>:</p>

<blockquote>James Robinson is a retired Air National Guard brigadier general and a commercial pilot for a major airline who flies passenger planes around the country.

<p>He has even been certified by the Transportation Security Administration to carry a weapon into the cockpit as part of the government's defense program should a terrorist try to commandeer a plane.</p>

<p>But there's one problem: James Robinson, the pilot, has difficulty even getting to his plane because his name is on the government's terrorist "watch list."</blockquote></p>

<p>It's easy to <a href="http://edition.cnn.com/2008/US/08/19/tsa.watch.list/index.html">sneak by them</a>:</p>

<blockquote>The third-grader has been on the watch list since he was 5 years old. Asked whether he is a terrorist, he said, "I don't know."

<p>Though he doesn't even know what a terrorist is, he is embarrassed that trips to the airport cause a ruckus, said his mother, Denise Robinson.</p>

<p>[...]</p>

<p>Denise Robinson says she tells the skycaps her son is on the list, tips heavily and is given boarding passes. And booking her son as "J. Pierce Robinson" also has let the family bypass the watch list hassle.</blockquote></p>

<p>And <a href="http://www.i-hacked.com/content/view/267/48/">here's</a> how to sneak lockpicks past them.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=8fHJ7K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=8fHJ7K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LcgXdK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LcgXdK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 05:12:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flies passenger planes">flies passenger planes</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/planes">planes</category>
      <category domain="http://securityratty.com/tag/list hassle">list hassle</category>
      <category domain="http://securityratty.com/tag/sneak lockpicks past">sneak lockpicks past</category>
      <category domain="http://securityratty.com/tag/james robinson">james robinson</category>
      <category domain="http://securityratty.com/tag/denise robinson">denise robinson</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <category domain="http://securityratty.com/tag/pilot">pilot</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/tsa_follies.html">TSA Follies</source>
    </item>
    <item>
      <title><![CDATA[Think "liability" if you want to stay out of trouble.]]></title>
      <link>http://securityratty.com/article/d9485be5d4b45a749942f44d816889ae</link>
      <guid>http://securityratty.com/article/d9485be5d4b45a749942f44d816889ae</guid>
      <description><![CDATA[I speak a lot about liability, but not everyone gets it

I have seen medical doctors, dentists, business people of all walks of life and lawyers (it is surprising how many lawyers disregard...]]></description>
      <content:encoded><![CDATA[I speak a lot about liability, but not everyone gets it.<br /><span id="fullpost"><br />I have seen medical doctors, dentists, business people of all walks of life and lawyers (it is surprising how many lawyers disregard liability)pay little attention to potential lawsuits.  The latest category to leave themselves open, have been auctioneers. <br /></span><br />The current foreclosure crisis has meant that many properties are being auctioned off.  We have been providing security officers at some of the properties in order to make sure that people do not try to steal or commit vandalism when viewing the houses.  There was an incident recently in which a bidder decided to withdraw his offer after his bid became the winning bid.  He probaly got cold feet.<br /><br />While he should not have reneged on his offer to buy the property, it was a civil matter best left to civil remedy.  Unfortunately, the auctioneers involved decided to take the law into their own hands and would not let the man leave the property.  The man became anxious and informed them that he was having difficulty breathing and needed to go to his car for his asthma medication.  <br /><br />Was this true?  Maybe, maybe not - but would it be wise to gamble with a person's health when you already had their personal details and you could easily have obtained his vehicle registration if he decided to leave?<br />Thankfully, our security officer knew better that to get involved with blocking the man's way.  The auctioneers stood in front of his vehicle and yelled at him.  Eventually the man drove off.     <br /><br />If you represent a financial institution, a law firm or an auctioneering firm, you need to think twice before you act inappropriately.  I have no doubt that had that man had a serious attack and if he died as a result, his next of kin would have sued for umpteen millions.  When it comes to situations like this, you need to think rationally and realize what is involved.  What was the worse thing that could have happened when the person decided to renege on his offer?  <br /><br />Apparently, he would have signed forms and the like and most probably he could be sued civilly for not fulfilling his obligations after delivering the winning bid.  At the end of the day, the note holder would be in a strong position.  Even if the person had given false information and could not be subsequently located, all they had to do was to put the property back on the market.  What could that have cost, a couple of thousand in extra advertising and the like?  That would have been much better than having to pay the next of kin many millions - not to mention the bad publicity.<br /><br />We talk a lot about liability because it is a very real threat.  Think "threat mitigation".  Those who do not, may pay a very high price.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 21:12:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/liability">liability</category>
      <category domain="http://securityratty.com/tag/lawyers disregard liability">lawyers disregard liability</category>
      <category domain="http://securityratty.com/tag/law firm">law firm</category>
      <category domain="http://securityratty.com/tag/auctioneers stood">auctioneers stood</category>
      <category domain="http://securityratty.com/tag/auctioneers">auctioneers</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/lawyers">lawyers</category>
      <category domain="http://securityratty.com/tag/property">property</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://www.thebulletproofblog.com/2008/08/think-liability-if-you-want-to-stay-out.html">Think "liability" if you want to stay out of trouble.</source>
    </item>
    <item>
      <title><![CDATA[Have you googled, HR security breaches lately?]]></title>
      <link>http://securityratty.com/article/891bb72b417d85643a8bd1df738baf4f</link>
      <guid>http://securityratty.com/article/891bb72b417d85643a8bd1df738baf4f</guid>
      <description><![CDATA[Blogger: Randall Gamby
As briefly mentioned in a Burton Group IdPS blog and a ZDNet Australia published article on July 3, 2008, HR data from Google was stolen from one of their previous HR outsource...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>As briefly mentioned in a Burton Group <a href="http://bgidps.typepad.com/bgidps/2008/07/physician-heal.html">IdPS blog</a> and a ZDNet Australia published <a href="http://www.zdnet.com.au/news/security/soa/Stolen-Google-s-employee-records-/0,130061744,339290305,00.htm">article</a> on July 3, 2008, HR data from Google was stolen from one of their previous HR outsource partners.&nbsp; It seems that the partner, Colt Express Outsource Partners, had equipment stolen that contained HR data from some of its clients, including Google.&nbsp; The data was unencrypted and stored on systems that were apparently portable.</p>

<p>So what does this mean for all of us?&nbsp; </p>

<p>First, it shows that even large SaaS companies like Google can be bitten by a lack of security at their partners, just like many of us can.&nbsp; Burton Group has been warning clients for a long time about the dangers of sending confidential information to outsource partners without proper security and audit processes in place. Of course this should also be backed by strong contractual language.&nbsp; </p>

<p>Second, be prepared to pay.&nbsp; Even if Google had breach mitigation terms in their contract, Colt Express announced that it was in financial difficulty. So Google has had to pay for financial reporting and other compensation to its own employees, even though Google did nothing wrong.&nbsp; </p>

<p>Third, a Google representative stated &quot;We take the security of our employees very seriously and require outside vendors to meet appropriate security standards. We review and update these standards on an on-going basis.”&nbsp; Does this mean that Google doesn’t require encryption of its confidential information since encryption of the data was not deployed at Colt Express?&nbsp; When working with third parties, whether it’s financial data or confidential personal data, this information needs to be protected from unauthorized access. One of the simplest ways is encrypting the data while at rest, regardless of where it’s located.&nbsp; </p>

<p>Final, the Colt Express breach brings to mind a question Burton Group is always asking: “What is your exit strategy if the contract is terminated with your outsourcing partner?”&nbsp; A lot of effort is expended in creating an outsourcing agreement around use and protection of data, but what happens when the contract is ended?&nbsp; Do you obtain and retain the information the outsource partner maintained?&nbsp; Do you have the outsource partner destroy the information and any archives of it (and verify this was done)?&nbsp; Do you create a custodial contract with the outsourcing partner for them to maintain the information and archives on your behalf (ensuring the data is properly protected)?&nbsp; As was found in this incident, after their contract with Google was terminated the outsourcing partner apparently retained the employee data unencrypted on their servers. This was the fatal mistake that allowed the breach to occur.</p>

<p>So as you work with your outsourcing and SaaS vendors, you should not only consider how day-to-day operations should be secured to maintain the confidentiality of your data. You should also think about how that data is being maintained over time, and what are your procedures should the unthinkable happen if your partner allows your data to be compromised.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/329819020" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 05:38:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/employee data">employee data</category>
      <category domain="http://securityratty.com/tag/outsource partner destroy">outsource partner destroy</category>
      <category domain="http://securityratty.com/tag/outsource partner">outsource partner</category>
      <category domain="http://securityratty.com/tag/confidential personal data">confidential personal data</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/financial data">financial data</category>
      <category domain="http://securityratty.com/tag/partner">partner</category>
      <category domain="http://securityratty.com/tag/partner apparently">partner apparently</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/329819020/have-you-google.html">Have you googled, HR security breaches lately?</source>
    </item>
    <item>
      <title><![CDATA[Have you googled, ???HR security breaches??? lately?]]></title>
      <link>http://securityratty.com/article/bf3d37721214cbdc7177cde027bf8732</link>
      <guid>http://securityratty.com/article/bf3d37721214cbdc7177cde027bf8732</guid>
      <description><![CDATA[Blogger: Randall Gamby
As briefly mentioned in a Burton Group IdPS blog and a ZDNet Australia published article on July 3, 2008, HR data from Google was stolen from one of their previous HR outsource...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>As briefly mentioned in a Burton Group <a href="http://bgidps.typepad.com/bgidps/2008/07/physician-heal.html">IdPS blog</a> and a ZDNet Australia published <a href="http://www.zdnet.com.au/news/security/soa/Stolen-Google-s-employee-records-/0,130061744,339290305,00.htm">article</a> on July 3, 2008, HR data from Google was stolen from one of their previous HR outsource partners.&nbsp; It seems that the partner, Colt Express Outsource Partners, had equipment stolen that contained HR data from some of its clients, including Google.&nbsp; The data was unencrypted and stored on systems that were apparently portable.</p>

<p>So what does this mean for all of us?&nbsp; </p>

<p>First, it shows that even large SaaS companies like Google can be bitten by a lack of security at their partners, just like many of us can.&nbsp; Burton Group has been warning clients for a long time about the dangers of sending confidential information to outsource partners without proper security and audit processes in place. Of course this should also be backed by strong contractual language.&nbsp; </p>

<p>Second, be prepared to pay.&nbsp; Even if Google had breach mitigation terms in their contract, Colt Express announced that it was in financial difficulty. So Google has had to pay for financial reporting and other compensation to its own employees, even though Google did nothing wrong.&nbsp; </p>

<p>Third, a Google representative stated &quot;We take the security of our employees very seriously and require outside vendors to meet appropriate security standards. We review and update these standards on an on-going basis.???&nbsp; Does this mean that Google doesn???t require encryption of its confidential information since encryption of the data was not deployed at Colt Express?&nbsp; When working with third parties, whether it???s financial data or confidential personal data, this information needs to be protected from unauthorized access. One of the simplest ways is encrypting the data while at rest, regardless of where it???s located.&nbsp; </p>

<p>Final, the Colt Express breach brings to mind a question Burton Group is always asking: ???What is your exit strategy if the contract is terminated with your outsourcing partner????&nbsp; A lot of effort is expended in creating an outsourcing agreement around use and protection of data, but what happens when the contract is ended?&nbsp; Do you obtain and retain the information the outsource partner maintained?&nbsp; Do you have the outsource partner destroy the information and any archives of it (and verify this was done)?&nbsp; Do you create a custodial contract with the outsourcing partner for them to maintain the information and archives on your behalf (ensuring the data is properly protected)?&nbsp; As was found in this incident, after their contract with Google was terminated the outsourcing partner apparently retained the employee data unencrypted on their servers. This was the fatal mistake that allowed the breach to occur.</p>

<p>So as you work with your outsourcing and SaaS vendors, you should not only consider how day-to-day operations should be secured to maintain the confidentiality of your data. You should also think about how that data is being maintained over time, and what are your procedures should the unthinkable happen if your partner allows your data to be compromised.</p></div>
]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 05:38:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/employee data">employee data</category>
      <category domain="http://securityratty.com/tag/outsource partner destroy">outsource partner destroy</category>
      <category domain="http://securityratty.com/tag/outsource partner">outsource partner</category>
      <category domain="http://securityratty.com/tag/confidential personal data">confidential personal data</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/financial data">financial data</category>
      <category domain="http://securityratty.com/tag/partner">partner</category>
      <category domain="http://securityratty.com/tag/partner apparently">partner apparently</category>
      <source url="http://srmsblog.burtongroup.com/2008/07/have-you-google.html">Have you googled, ???HR security breaches??? lately?</source>
    </item>
    <item>
      <title><![CDATA[Cloudsecurity.org Interviews Guido van Rossum: Google App Engine, Python and Security]]></title>
      <link>http://securityratty.com/article/a2cf6f2181968ed75532873c1bdb09fe</link>
      <guid>http://securityratty.com/article/a2cf6f2181968ed75532873c1bdb09fe</guid>
      <description><![CDATA[In this interview, cloudsecurity.org talks to Guido van Rossum about Python , Google App Engine and security
Guido is the creator of the Python programming language and more recently, Google App...]]></description>
      <content:encoded><![CDATA[<p><a title="Guido van Rossum in Google Uniform" href="http://www.python.org/~guido/" target="_blank"><img src="http://www.python.org/~guido/images/IMG_2192.jpg" border="0" alt="Guido Homepage" /></a></p>
<p>In this interview, cloudsecurity.org talks to <a title="Homepage of Guido van Rossum" href="http://www.python.org/~guido/">Guido van Rossum</a> about <a title="Python website" href="http://python.org">Python</a>, <a title="Description of Google AppEngine" href="http://code.google.com/appengine/docs/whatisgoogleappengine.html">Google App Engine</a> and security.</p>
<p>Guido is the creator of the Python programming language and more recently, Google App Engine team member.  His involvement with the App Engine project was pretty late - the code &#8220;was almost ready for release&#8221; when he get involved.  The security architect of App Engine was primarily project lead, <a title="Kevin Gibbs Campfire Transcript" href="http://code.google.com/appengine/articles/cf1-text.html">Kevin Gibbs</a>, supported by the rest of the App Engine crew and the Google Security Team.</p>
<h4>The Interview</h4>
<p><em>cloudsecurity.org: What security principles did you follow for App Engine?<br />
</em></p>
<p>GvR: While I can&#8217;t share any specifics on what we&#8217;re doing to secure App Engine, I can say that the main principle we&#8217;ve followed could be called &#8220;defense in depth&#8221;. We&#8217;re not relying exclusively on a secure interpreter, or any other single security layer, to protect our users.</p>
<p><em>cloudsecurity.org: Please provide some examples of how those principles played out in terms of the current implementation?<br />
</em> <em> </em></p>
<p>GvR: Sorry, we don&#8217;t divulge such information.</p>
<p><em>cloudsecurity.org: What criteria did you apply to Python module selection?</em></p>
<p>GvR: We first looked for modules that were useful and straightforward to audit. If a module was large or complex, we&#8217;d only audit it (fixing things we found) if it was deemed essential or at least useful for a large number of users; otherwise we&#8217;d exclude it.</p>
<p><em>cloudsecurity.org: What do you see as the security risks inherent in exposing an interpreter runtime in a shared environment?<br />
</em></p>
<p>GvR: <span>I presume you&#8217;re asking about risks to users, like providing accidental access to data belonging to another app. We&#8217;ve taken extensive measures to isolate different apps from each other. For example, each app runs in a separate process, and the datastore prevents an app from accessing data belonging to other apps.</span></p>
<p><em>cloudsecurity.org: I recently attended a fascinating talk by <a title="Justin Ferguson" href="http://eusecwest.com/justin-ferguson-interpreter-vm-attacks.html" target="_blank">Justin Ferguson</a> (a Seattle based security consultant) at <a title="eusecwest" href="http://www.eusecwest.com/" target="_blank">eusecwest</a> in London.  He gave a great talk exploring security vulnerabilities in language interpreters and specifically highlighted some security weaknesses in Python App Engine.  What are your thoughts on his research and specifically the Python issues he highlighted?  When do you anticipate they will get fixed?<br />
</em></p>
<p>GvR: We&#8217;ve anticipated all of the possibilities raised in Justin&#8217;s talk, and took measures to protect our users. Justin highlighted weaknesses in Python, but not in App Engine. Furthermore, our security model does not rely solely upon protections within the Python interpreter; there are additional protections that these external analyses have missed.<em><br />
</em><br />
<em>cloudsecurity.org: How do you contain an attacker that exploits bugs in App Engine from exploiting the underlying OS and potentially interfering with other users processes or attacking backend systems?<br />
</em></p>
<p>GvR: You are correct that there are strong measures in place, but I&#8217;m not at liberty to discuss details.</p>
<p><em>cloudsecurity.org: Python was the first language to get the App Engine treatment, what language is next and what are some of the language specific security challenges the team has had to deal with?<br />
</em></p>
<p>GvR: Although I can&#8217;t comment on what language is next, we are working on this, and have gotten a lot of great feedback from our developers. As far as language-specific security challenges, they stemmed mostly from the complexity of the Python interpreter. We spent a lot of time auditing this, and did a great deal more than just identifying buffer overflows.  I can also add that Google is actively researching the security of interpreted languages.  Google engineers routinely contribute security fixes to open source projects, including but not limited to Python.<em><br />
</em><br />
<em>cloudsecurity.org: How does the team decide when &#8216;enough is enough&#8217; in terms of hardening the interpreter?<br />
</em> <em> </em></p>
<p>GvR: That&#8217;s not really how we approach it. We realize that security is an ongoing effort, and try to stay ahead of threats through continuous monitoring and testing.</p>
<p><em>cloudsecurity.org: Some <a style="color: #551a8b;" title="commentators" href="http://blog.ianbicking.org/2008/04/13/app-engine-and-pylons/" target="_blank">commentators</a> have suggested that perhaps the difficulty of auditing the implementation led to some modules being more heavily restricted than perhaps necessary.  What are your thoughts on that and what plans, if any, are there to bring back code objects/functions that were eliminated in the initial release?  (with the benefit of hindsight).<br />
</em> <em> </em></p>
<p>GvR: The only thing we are likely to put back is the _ast module, which was not audited based upon an underestimation of its usefulness (see my answer to question #3 above).  We will also put back some dummy functions and other objects whose absence currently prevents some popular frameworks from being loaded without modifications. For example, some harmless functionality in the imp module will come back. We&#8217;re also looking into making urllib2 work (to some extent), though that&#8217;s not really a security issue but merely a matter of API adjustment.</p>
<p><em>cloudsecurity.org: It is reported that Google encourages small groups to go off and create.  How involved were the Google security team with App Engine in terms of design and implementation review/testing?  Given the dynamics, is it possible to have a meaningful security process that shadows the development process?<br />
</em> <em> </em></p>
<p>GvR: The Google Security team is involved in everything we do. They have been extremely helpful.</p>
<p><em>cloudsecurity.org: How can people report security weaknesses they discover in App Engine?  What commitment does Google give in terms of dealing vulnerability reports?<br />
</em> <em> </em></p>
<p>GvR: There is a standard process for submitting security issues. See <a title="http://www.google.com/corporate/security.html" href="http://www.google.com/corporate/security.html" target="_blank">http://www.google.com/corporate/security.html</a>. Google moves very fast to protect its users when a verifiable security vulnerability is reported.<span><em><br />
</em></span><br />
<em>cloudsecurity.org: One concern is the potential misuse of App Engine to exploit security vulnerabilities in visitors browsers.  This is not a new problem per se, shared hosting providers know all about this.  But with Google and other Cloud providers, the scalability potential is much higher.  What are your thoughts on this and what pro-active steps is Google taking to detect and terminate evil apps?<br />
</em> <em> </em></p>
<p>GvR: This is high on our list of concerns. We deal with this through a combination of restrictions on what you can do (e.g. certain HTTP headers and ports are off-limits) and, again, monitoring.</p>
<p><em>cloudsecurity.org: Beyond App Engine, what role do you think Python will play in the Cloud both now and in the future?<br />
</em> <em> </em></p>
<p>GvR: Sorry, I&#8217;m not prone to philosophizing about the future.</p>
<p><em>cloudsecurity.org: Trust is often cited as a barrier to enterprise adoption of Cloud Computing.  What role do you personally think Google can play in building that trust?<br />
</em> <em> </em></p>
<p>GvR: I think trust is built up over a long period of experience. Our actions in terms of being open to our users will be the most important factor in establishing trust. Of course, Google&#8217;s reputation also helps: everybody understands that Google doesn&#8217;t want its name associated with a bad product.</p>
<p><em>cloudsecurity.org: Looking at the Cloud Computing landscape beyond Google, what are your thoughts on the current state of Cloud Computing and Security?<br />
</em></p>
<p>GvR: It&#8217;s obvious that Cloud Computing is only just taking off. The next few years will be very exciting.</p>
<p><em>cloudsecurity.org: Lastly, what are some of your favourite App Engine apps?<br />
</em></p>
<p>GvR: There are too many to enumerate. If you insist on a highlight, well, I like Rietveld (<a title="http://codereview.appspot.com" href="http://codereview.appspot.com/" target="_blank">http://codereview.appspot.com</a>), a tool for collaborative code review which I (largely) wrote myself. It is open source and includes some essential components from Mondrian, a similar internal tool which I created before I joined the App Engine team.</p>
<h4><strong>Thanks</strong></h4>
<p>My thanks to Guido for his time and sharing his views.</p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/324271347" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 15:03:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/app engine">app engine</category>
      <category domain="http://securityratty.com/tag/google app engine">google app engine</category>
      <category domain="http://securityratty.com/tag/app">app</category>
      <category domain="http://securityratty.com/tag/app engine treatment">app engine treatment</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/app engine project">app engine project</category>
      <category domain="http://securityratty.com/tag/app engine crew">app engine crew</category>
      <category domain="http://securityratty.com/tag/secure app engine">secure app engine</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/324271347/">Cloudsecurity.org Interviews Guido van Rossum: Google App Engine, Python and Security</source>
    </item>
  </channel>
</rss>
