<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: enforce]]></title>
    <link>http://securityratty.com/tag/enforce</link>
    <description></description>
    <pubDate>Mon, 23 Jun 2008 09:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Dems were for Web 2.0 before they were against it]]></title>
      <link>http://securityratty.com/article/3c7208b75cc88c431e97fe0b20cdcd01</link>
      <guid>http://securityratty.com/article/3c7208b75cc88c431e97fe0b20cdcd01</guid>
      <description><![CDATA[zenpundit aka Mark Safranski on the congressional Democrats war on Web 2.0



Nor was one of the leading Web 2.0 experts, Clay Shirky, reassured either, writing at
Open House Project : They can...]]></description>
      <content:encoded><![CDATA[<p><a href="http://zenpundit.com/?p=2785">zenpundit</a> aka Mark Safranski on the congressional Democrats <a href="http://pajamasmedia.com/blog/congress-debates-muzzling-congressmen-online/">war on Web 2.0</a></p><br><div><span style="font-family: Verdana; line-height: normal; "><p style="margin-top: 0px; margin-right: 10px; margin-bottom: 10px; margin-left: 10px; color: #000000; padding-left: 0px; padding-right: 0px; font-size: 13px; line-height: 16px; "></p><blockquote><p>Nor was one of the leading Web 2.0 experts, Clay Shirky, reassured either, writing at</p><blockquote style="display: inline !important; "><p><a href="http://groups.google.com/group/openhouseproject/browse_thread/thread/1e8d9aa1c7a903d8" style="color: #02446a; text-decoration: underline; ">Open House Project</a>: “They can enforce it the way we enforce parking rules, which is to miss most violations, and then bring in draconian enforcement of enough violations to have a chilling effect. This will also allow the Rules Committee to wield enforcement selectively as a stick.” Representative Capuano, who has described the internet as “a necessary evil,” would be one of the enforcers and he is part of a larger Democratic House leadership whose speaker, Nancy Pelosi, also supports a revival of the long-defunct “Fairness Doctrine” that made it unprofitable for broadcast networks to permit robust political expression on air.</p></blockquote></blockquote><p></p><p style="margin-top: 0px; margin-right: 10px; margin-bottom: 10px; margin-left: 10px; color: #000000; padding-left: 0px; padding-right: 0px; font-size: 13px; line-height: 16px; "></p><blockquote><p>...</p></blockquote><p></p><p style="margin-top: 0px; margin-right: 10px; margin-bottom: 10px; margin-left: 10px; color: #000000; padding-left: 0px; padding-right: 0px; font-size: 13px; line-height: 16px; "></p><blockquote><p>More ominous still would be the precedent of the U.S. government designating “official” external websites — imagine having the power to select “official” newspapers — that would have to hew to House regulations and be as free as possible from political or commercial advertising. Given the ubiquity of blogads, most blogs, bulletin boards, and discussion forums would be shut out of the conversation with our nation’s elected officials. Essentially, Capuano is demanding that the internet adapt itself to the House of Representatives instead of the House adapting to the reality of the internet.</p></blockquote>Looks like a good diversion from normal critical DC wealth destroying activities, and baseball steroid and NFL team filming practices investigations,<p></p></span></div>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 16:57:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/house">house</category>
      <category domain="http://securityratty.com/tag/house regulations">house regulations</category>
      <category domain="http://securityratty.com/tag/house project">house project</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/internet adapt">internet adapt</category>
      <category domain="http://securityratty.com/tag/select official newspapers">select official newspapers</category>
      <category domain="http://securityratty.com/tag/long-defunct fairness doctrine">long-defunct fairness doctrine</category>
      <category domain="http://securityratty.com/tag/representative capuano">representative capuano</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/dems-were-for-web-20-before-they-were-against-it.html">Dems were for Web 2.0 before they were against it</source>
    </item>
    <item>
      <title><![CDATA[D.C. Police Detective Arressted for Propositioning a "Prostitute".]]></title>
      <link>http://securityratty.com/article/5764d3c57a7c61891d6d10d70473d035</link>
      <guid>http://securityratty.com/article/5764d3c57a7c61891d6d10d70473d035</guid>
      <description><![CDATA[Some time clients call us up and ask if we can send them off-duty cops for Executive Protection assignments. My first inclination is to tell them why we are reluctant to use off-duty police
...]]></description>
      <content:encoded><![CDATA[Some time clients call us up and ask if we can send them off-duty cops for Executive Protection assignments.  My first inclination is to tell them why we are reluctant to use off-duty police. <br /><span id="fullpost"><br />Yesterday, WTOP radio reported that a Detective Wheeler from the Washington D.C. Metropolitan Police had been arrested for trying to hire a Prostitute.  Unfortunately for Detective Wheeler, the "prostitute" was an undercover Police Detective herself.<br /><br />The story gets better, however.  It seems that Detective Wheeler is assigned to the Vice Unit.  For those of you who don't know what a Vice Unit does, they set up "stings" and dress female Police officers to look like prostitutes in order to arrest those who try and do business with "prostitutes".  One wonders if Detective Wheeler should be charged with the prostituion charge or one involving gross stupidity. <br /><br />Just becaause a Police officer carries a gun, does not mean that this qualifies him or her to do everything security related.  While most of them are decent, hard working indivduals, there are also some who break laws and circumvent the system for their own benefit.  When you hire an "off-duty cop", you do not know what you are getting.  Perhaps you will get a bad apple(s) who will do more harm than good.  Afterall, what way is there to vet them?<br /><br />A professional security company like ours, train their own people and enforce from day one a strong sense of Ethics.  We have a zero policy for any behaviour that might be detrimental to us or the client.  On the rare occassion when someone does something that we do not condone, they are terminated.  There is no room for Union intervention or "three strikes, you're out" or any other delaying tactic.  <br /><br />Our reputation is too important.  Then again, we do not have "jobs for life" but must instead earn buisness by constantly performing.  The next time you need a security person, keep this in mind.          <br /></span><div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sat, 12 Jul 2008 14:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/detective wheeler">detective wheeler</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security person">security person</category>
      <category domain="http://securityratty.com/tag/professional security company">professional security company</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/vice unit">vice unit</category>
      <category domain="http://securityratty.com/tag/time clients call">time clients call</category>
      <category domain="http://securityratty.com/tag/prostitute">prostitute</category>
      <category domain="http://securityratty.com/tag/executive protection assignments">executive protection assignments</category>
      <source url="http://www.thebulletproofblog.com/2008/07/dc-police-detective-arressted-for.html">D.C. Police Detective Arressted for Propositioning a "Prostitute".</source>
    </item>
    <item>
      <title><![CDATA[OWASP Talk Q&A Notes]]></title>
      <link>http://securityratty.com/article/81fb1dfdb408580202cb30b424d72c9c</link>
      <guid>http://securityratty.com/article/81fb1dfdb408580202cb30b424d72c9c</guid>
      <description><![CDATA[On Monday I did a talk on Web Services security at the MSP OWASP. The talk was ok, but not as good as at RSA because I Brian Chess did a better job with some of the stories than me. What was really...]]></description>
      <content:encoded><![CDATA[<p>On Monday I did a talk on Web Services security at the MSP OWASP. The talk was ok, but not as good as at RSA because I Brian Chess did a better job with some of the stories than me. What was really good though was a number of questions and answers afterwards.</p><div><br><div>One person asked the old chestnut - "do we need to care about web services security if we are inside the firewall?" Now, I have heard this question many, many times in different ways, and this time my brain just shorted out, I basically said that I am not sure what difference it really makes. You don't get security from a firewall, you may get the ability to fire someone if they do something bad, but in most companies there is no "wall" and there sure isn't any "fire", at most they are speed bumps. I am *not* saying to remove them, they are part and parcel of how you operate a network but they are not really providing any additional security. Network firewalls are thought of as a security tools because they began as a security innovation and they are paid for out of the security budget.</div><br>

<p><br>
<a href="http://1raindrop.typepad.com/photos/uncategorized/2008/05/19/innovatecompare_2.png"><img  alt="Innovatecompare_2" title="Innovatecompare_2" src="http://1raindrop.typepad.com/1_raindrop/images/2008/05/19/innovatecompare_2.png" width="300" height="167" border="0"></a></p>
<div><a href="http://1raindrop.typepad.com/1_raindrop/2007/02/thinking_about_.html">Robert Garigue</a> said several years ago that network firewalls are part of network hygiene like brushing your teeth. Information security should not have to help people brush their teeth, and instead should operate like a dentist helping groups work more complex and risky issues. I have advised CISOs at several companies to off load the network firewall jockeys out of infosec and into network groups. Sometimes they listen. If so, the infosec group can focus on other issues instead of managing a Visio-driven "security" device. </div><br><div>Why Visio? Well, the main security property from a firewall is the scary flames and brick wall on Visio. And how do you know whether or not to open up a port? You just open the org chart (in Visio) and find the level of the person who is requesting the port be opened. If VP Then Yes. Is this security? Hardly.</div><br><div>So one last time - Web Services are used to provide access to your main systems (which live on mainframes, big RDBMS, SAP, ERP, CRM, and so on) these are the keys to the kingdom, and lots of apps need them. The whole point of Web Services is to make it easier to talk to them. So "inside" or "outside" the firewall, do you need to care about authentication, authorization, and auditing on the systems that run your entire business???</div><br><div>Another interesting question from the Q &amp; A from <a href="http://hursk.com/">Jon Passki</a> was on XML Security Gateways. We talked a fair bit about their utility in solving the aforementioned authentication, authorization, and auditing problems. I pulled up <a href="http://www.vordel.com/products/vx_gateway/">Vordel's gateway</a> and showed how to build security workflows to deploy security as a service. Jon asked could I ever imagine a Web services security architecture without a gateway? I said I think that they are not always the starting point but mid to long term they are definitely in basically any effective security architecture I can think of. Having a place to deploy, manage, and enforce policy that is separate the code solves a lot of real world problems. People are hung up on thinking about Web services programming like it has to be Web app programming (this happens in REST a lot), but there is another school of successful web apps, arguably the most successful, and its called email. </div><br><div>Email app architecture looks nothing like web app design. You wouldn't read every email sent to your address would you? Of course not, it goes through spam filters, virus checkers and so on. Further its a message oriented paradigm, and you know that unless its signed/encrypted with PGP/GPG security is suspect at best. So yeah, I think gateways are an hugely important part of a Web Services security architecture.</div><br><div>Finally, I can also not imagine going live when you are supporting multiple protocols and token types without a good testing strategy. Mark O'Neill recently <a href="http://radio.weblogs.com/0111797/2008/07/07.html#a115">blogged</a> something I recommend to all my clients - namely make sure you have security specific test cases, test harnesses and testing tools, like for example <a href="http://www.vordel.com/products/soapbox/">Vordel's Soapbox</a>.</div><br></div>]]></content:encoded>
      <pubDate>Fri, 11 Jul 2008 11:36:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/additional security">additional security</category>
      <category domain="http://securityratty.com/tag/security workflows">security workflows</category>
      <category domain="http://securityratty.com/tag/security innovation">security innovation</category>
      <category domain="http://securityratty.com/tag/effective security architecture">effective security architecture</category>
      <category domain="http://securityratty.com/tag/web services">web services</category>
      <category domain="http://securityratty.com/tag/gateways">gateways</category>
      <category domain="http://securityratty.com/tag/web services security">web services security</category>
      <category domain="http://securityratty.com/tag/xml security gateways">xml security gateways</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/owasp-talk-qa-notes.html">OWASP Talk Q&amp;A Notes</source>
    </item>
    <item>
      <title><![CDATA[Kill Switches and Remote Control]]></title>
      <link>http://securityratty.com/article/6faff6d8aced2811984a7463136f6b3a</link>
      <guid>http://securityratty.com/article/6faff6d8aced2811984a7463136f6b3a</guid>
      <description><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now...]]></description>
      <content:encoded><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now everyone else wants to get their hooks into your gear.

OnStar will soon include the <a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=202400922">ability</a> for the police to shut off your engine remotely. Buses are getting the <a href="http://www.nypost.com/seven/06082008/news/regionalnews/busting_terror_114567.htm">same capability</a>, in case terrorists want to re-enact the movie <cite>Speed</cite>. The Pentagon wants a kill switch <a href="http://blog.wired.com/defense/2008/06/the-pentagons-n.html">installed</a> on airplanes, and is worried about potential enemies <a href="http://spectrum.ieee.org/may08/6171">installing</a> kill switches on their own equipment. 

Microsoft is doing some of the most creative thinking along these lines, with something it's calling "<a href="http://arstechnica.com/news.ars/post/20080611-microsoft-patent-brings-miss-manners-into-the-digital-age.html">Digital Manners Policies</a>." According to its <a href="http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PG01&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.html&r=1&f=G&l=50&s1=%2220080125102%22.PGNR.&OS=DN/20080125102&RS=DN/20080125102">patent application</a>, DMP-enabled devices would accept broadcast "orders" limiting capabilities. Cellphones could be remotely set to vibrate mode in restaurants and concert halls, and be turned off on airplanes and in hospitals. Cameras could be prohibited from taking pictures in locker rooms and museums, and recording equipment could be disabled in theaters. Professors finally could prevent students from texting one another during class. 

The possibilities are endless, and very dangerous. Making this work involves building a nearly flawless hierarchical system of authority. That's a difficult security problem even in its simplest form. Distributing that system among a variety of different devices -- computers, phones, PDAs, cameras, recorders -- with different firmware and manufacturers, is even more difficult. Not to mention delegating different levels of authority to various agencies, enterprises, industries and individuals, and then enforcing the necessary safeguards.

Once we go down this path -- giving one device authority over other devices -- the security problems start piling up. Who has the authority to limit functionality of my devices, and how do they get that authority? What prevents them from abusing that power? Do I get the ability to override their limitations? In what circumstances, and how? Can they override my override?

How do we prevent this from being abused? Can a burglar, for example, enforce a "no photography" rule and prevent security cameras from working? Can the police enforce the same rule to avoid another Rodney King incident? Do the police get "superuser" devices that cannot be limited, and do they get "supercontroller" devices that can limit anything? How do we ensure that only they get them, and what do we do when the devices inevitably fall into the wrong hands?

It's comparatively easy to make this work in closed specialized systems -- OnStar, airplane avionics, military hardware -- but much more difficult in open-ended systems. If you think Microsoft's vision could possibly be securely designed, all you have to do is look at the dismal effectiveness of the various copy-protection and digital-rights-management systems we've seen over the years. That's a similar capabilities-enforcement mechanism, albeit simpler than these more general systems.

And that's the key to understanding this system. Don't be fooled by the scare stories of wireless devices on airplanes and in hospitals, or visions of a world where no one is yammering loudly on their cellphones in posh restaurants. This is really about media companies wanting to exert their control further over your electronics. They not only want to prevent you from surreptitiously recording movies and concerts, they want your new television to enforce good "manners" on your computer, and not allow it to record any programs. They want your iPod to politely refuse to copy music to a computer other than your own. They want to enforce <em>their</em> legislated definition of manners: to control what you do and when you do it, and to charge you repeatedly for the privilege whenever possible. 

"Digital Manners Policies" is a marketing term. Let's call this what it really is: Selective Device Jamming. It's not polite, it's dangerous. It won't make anyone more secure -- or more polite.

This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/06/securitymatters_0626">originally appeared</a> in Wired.com.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JiKwGJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JiKwGJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=aXm5MJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=aXm5MJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 02:48:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wireless devices">wireless devices</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/devices inevitably">devices inevitably</category>
      <category domain="http://securityratty.com/tag/digital manners policies">digital manners policies</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/prevent security cameras">prevent security cameras</category>
      <category domain="http://securityratty.com/tag/difficult security">difficult security</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/prevent students">prevent students</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/kill_switches_a.html">Kill Switches and Remote Control</source>
    </item>
    <item>
      <title><![CDATA[Symantec's Network-Based NAC]]></title>
      <link>http://securityratty.com/article/bdbd7433d55560c26d1c9ef1bc5869bd</link>
      <guid>http://securityratty.com/article/bdbd7433d55560c26d1c9ef1bc5869bd</guid>
      <description><![CDATA[Yes, you read it right - Symantec (as in the software vendor) has a network-based (as in the hardware) NAC. Once you get over the title, keep reading
If you read my blog, or know me, you probably know...]]></description>
      <content:encoded><![CDATA[<p><strong>Yes, you read it right</strong>- <a class="offsite-link-inline" href="http://www.symantec.com/" target="_blank">Symantec</a>&nbsp;(as in the software vendor) has a network-based (as in the hardware) NAC. Once you get over the title, keep reading. </p><p>If you read my blog, or know me, you probably know I do NOT like software (and it usually doesn&#8217;t like me). So, I&#8217;d be the first to jump on the <em>&#8216;anti-software-peer-based-NAC&#8217; </em>train, but I think we have to be informed before we jump to conclusions and hop on any trains. </p><p>Mirage&#8217;s recent blog post on Symantec&#8217;s <a class="offsite-link-inline" href="http://www.mirageblog.com/cto/2008/06/silly-snacs.html" target="_blank">&#8216;Silly SNAC&#8217;</a> was certainly a result of a mis- (or un-) informed person. Tim did a much better job on his mention of SNAC in the <a class="offsite-link-inline" href="http://www.networkworld.com/newsletters/vpn/2008/060208nac1.html?nladname=060308security:networkaccesscontrolal&code=nlnac141990" target="_blank">NWW blog</a>, but all the dots still aren&#8217;t connected. It proves the point that sometimes we (as bloggers) tend to write based on a feeling and sometimes don&#8217;t dig for the fact. </p><p>So, in an effort to make sure I understood this new peer-based NAC, I reached out to <a class="offsite-link-inline" href="http://www.linkedin.com/pub/0/67/617" target="_blank">Patrick Wheeler</a>, Symantec&#8217;s Senior Product Manager for Network and Endpoint Security. Based on my conversations with him, and a pretty detailed investigation into the options and configurations of their NAC products, I have some slightly more informed opinion to share with you now. </p><p><strong>Symantec has a variety of NAC enforcement components and options</strong>. I&#8217;m going to keep all the software-type-stuff out of this conversation for the time being. They have (among other things) the <strong>NAC Enforcer</strong>, an appliance similar to the other NAC controllers we see from traditional hardware vendors. Just like it&#8217;s counterparts, Symantec&#8217;s NAC Enforcer can be configured for DHCP, inline or 802.1X based enforcement. </p><p>The piece that&#8217;s different is the integration of the NAC Enforcer with Symantec&#8217;s Endpoint Protection Manager server that hosts the policies for the NAC. It&#8217;s similar to the management-enforcement configuration we see from other vendors, only the management piece is housed on a server instead of another appliance. </p><p><span class="full-image-float-right"><img style="width: 343px; height: 197px" alt="SNAC_snippit1b.jpg" src="http://www.securityuncorked.com/storage/SNAC_snippit1b.jpg?__SQUARESPACE_CACHEVERSION=1214796728100" /></span>And, just as other vendors offer some type of endpoint integrity agent, the Symantec agent comes in the form of the Symantec NAC Client, which can be used by itself, or integrated with the Symantec Endpoint Protection Client for an even more robust feature-set. (The Endpoint Protection Client offers some additional host-based firewall features that the NAC can leverage). </p><p><strong>So, what about the Peer-Based NAC?</strong> Ah, well that&#8217;s just the first iteration&nbsp;of a &#8216;vision&#8217; to address mobile corporate users. If employees have laptops in an ad-hoc situation outside of the enterprise infrastructure (and therefore, outside of&nbsp;enterprise enforcement), then the peer-based NAC can port the enforcement rules set at the &#8216;mothership&#8217; and enforce them individually.&nbsp;The peer-based NAC can protect mobile assets in their most vulnerable situation, outside the security of the corporate network. But, the rules are still set centrally and the peer-based NAC&nbsp;was designed to be&nbsp;just one step towards an added layer of protection, not as a replacement for network-based NAC. </p><p><strong>For now, I&#8217;ll stay off the hate train</strong>, since the peer-based NAC is more of a supplement to a more robust traditional NAC solution. If they move to a fully-host-enforced product, I&#8217;ll buy my tickets&#8230;</p><p><span class="sizeLess20">Image shown is copyright of Symantec Corporation.</span> </p><p># # #</p>
]]></content:encoded>
      <pubDate>Sun, 29 Jun 2008 23:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/nac enforcement components">nac enforcement components</category>
      <category domain="http://securityratty.com/tag/nac controllers">nac controllers</category>
      <category domain="http://securityratty.com/tag/nac products">nac products</category>
      <category domain="http://securityratty.com/tag/nac enforcer">nac enforcer</category>
      <category domain="http://securityratty.com/tag/symantecs nac enforcer">symantecs nac enforcer</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/symantec nac client">symantec nac client</category>
      <category domain="http://securityratty.com/tag/symantec corporation">symantec corporation</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/6/30/symantecs-network-based-nac.html">Symantec's Network-Based NAC</source>
    </item>
    <item>
      <title><![CDATA[Maybe the NAC used car salesman can claim them as a customer too? In NAC quality counts!]]></title>
      <link>http://securityratty.com/article/d80f68ce6e6808f9d06f6e7946e4e4a0</link>
      <guid>http://securityratty.com/article/d80f68ce6e6808f9d06f6e7946e4e4a0</guid>
      <description><![CDATA[Dark Reading had a good article today talking about GuideWorks , the TV Guide/Comcast joint venture's 2 year odyssey with NAC, which finds them finally starting to see some good results. I immediately...]]></description>
      <content:encoded><![CDATA[<p>Dark Reading had a <a href="http://www.darkreading.com/document.asp?doc_id=157719&amp;f_src=darkreading_section_296">good article today</a> talking about <a class="zem_slink" title="GuideWorks" href="http://en.wikipedia.org/wiki/GuideWorks" rel="wikipedia">GuideWorks</a>, the TV Guide/Comcast joint venture's 2 year odyssey with NAC, which finds them finally starting to see some good results. I immediately went to the website of the <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/the-used-car-sa.html">NAC used car salesman</a> to see if they claimed them as a NAC customer too, but didn't see anything yet. But with those guys you never know. <br><br>Seriously though folks, this story is a classic NAC story. GuideWorks had guests and unmanaged users visiting their offices all the time. When they would ask to plug in they were told sorry, wait till you get back to your hotel. Over time this answer became unacceptable and they realized they needed a way to give these people a way to get on the net and get their email while keeping their network secure. This very same need drives many initial NAC deployments.<br><br>Like many other NAC customers they wanted something easy, not add major overhead or network changes and easy to administer. Again straight out of the NAC playbook. In the Summer of '06 they began a pilot of the Tipping Point NAC product which is based on the old Roving Planet technology. Now Roving Planet was more of a wireless security company, but near the end they rebranded themselves as NAC and Tipping Point uses that with their IPS devices to enforce. Best of all for GuideWorks the price was sub 10k. <br><br>Here is where the other side of NAC comes in. This is what the article says:</p><blockquote><p><em><p>While NAC tools are often advertised as plug-and-play, GuideWorks found that the NAC setup required a high level of networking expertise. Fortunately, the Inglewood site had plenty of technical expertise because that’s where many of the company’s developers are stationed. In addition, GuideWorks put one of its front-desk employees in charge of setting up new accounts. But because her technical background was limited, the company had to walk her through a learning curve. </p>

<p>Now the company is planning to deploy the system at its Radnor office, which will be a bit more challenging since there’s less technical expertise there, and that office gets a greater number of visitors. So GuideWorks has been on the search for employees to support the NAC system there. The company expects to have NAC up and running there by the end of the summer. </p></em></p>

</blockquote><p>So 2 years after trial they are rolled out in one office and have to hire employees to support the NAC system at the next office. This was a problem with many of the failed NAC companies over the last few years and I think the problem with this Tipping Point solution. Just providing guest access should not be that hard! Yes the StillSecure Safe Access solution would have been much easier and faster to implement, but to be fair, any of the leading NAC solutions would have been up and running easier as well. </p>

<p>While this article was supposed to serve as reference and case study for the Tipping Point NAC solution, it is far from inspiring. If I were a customer looking into NAC, I don't think this would make run out and look at the Tipping Point solution. Moral of the story is, just because you made a good IPS doesn't mean you have a very good NAC product. When it comes to something like NAC, quality counts and buying a 2nd tier solution can cost you in time to implementation and total cost of ownership.</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/2c864e8d-b43a-4e14-9fdc-9ac4835bc27b/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=2c864e8d-b43a-4e14-9fdc-9ac4835bc27b" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none"></img></a></div>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=ia7VDL"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=ia7VDL" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=bjKsGI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=bjKsGI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DxCrYI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DxCrYI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YQ1SAI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YQ1SAI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wD2I6I"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wD2I6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=FSLeNi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=FSLeNi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2QntYi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2QntYi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/321785853" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 19:36:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/customer">customer</category>
      <category domain="http://securityratty.com/tag/nac solution">nac solution</category>
      <category domain="http://securityratty.com/tag/nac solutions">nac solutions</category>
      <category domain="http://securityratty.com/tag/nac tools">nac tools</category>
      <category domain="http://securityratty.com/tag/nac setup">nac setup</category>
      <category domain="http://securityratty.com/tag/initial nac deployments">initial nac deployments</category>
      <category domain="http://securityratty.com/tag/nac playbook">nac playbook</category>
      <category domain="http://securityratty.com/tag/nac companies">nac companies</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/321785853/maybe-the-nac-u.html">Maybe the NAC used car salesman can claim them as a customer too? In NAC quality counts!</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: I've Seen the Future, and It Has a Kill Switch]]></title>
      <link>http://securityratty.com/article/b9aa8529e116abf92778a4755495e63d</link>
      <guid>http://securityratty.com/article/b9aa8529e116abf92778a4755495e63d</guid>
      <description><![CDATA[It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now...]]></description>
      <content:encoded><![CDATA[<p>It used to be that just the entertainment industries wanted to control your computers -- and televisions and iPods and everything else -- to ensure that you didn't violate any copyright rules. But now everyone else wants to get their hooks into your gear.
</p><p>
OnStar will soon include the <a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=202400922">ability</a> for the police to shut off your engine remotely. Buses are getting the <a href="http://www.nypost.com/seven/06082008/news/regionalnews/busting_terror_114567.htm">same capability</a>, in case terrorists want to re-enact the movie <cite>Speed</cite>. The Pentagon wants a kill switch <a href="http://blog.wired.com/defense/2008/06/the-pentagons-n.html">installed</a> on airplanes, and is worried about potential enemies <a href="http://spectrum.ieee.org/may08/6171">installing</a> kill switches on their own equipment. 
</p><p>
Microsoft is doing some of the most creative thinking along these lines, with something it's calling "<a href="http://arstechnica.com/news.ars/post/20080611-microsoft-patent-brings-miss-manners-into-the-digital-age.html">Digital Manners Policies</a>." According to its <a href="http://appft1.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PG01&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.html&r=1&f=G&l=50&s1=%2220080125102%22.PGNR.&OS=DN/20080125102&RS=DN/20080125102">patent application</a>, DMP-enabled devices would accept broadcast "orders" limiting capabilities. Cellphones could be remotely set to vibrate mode in restaurants and concert halls, and be turned off on airplanes and in hospitals. Cameras could be prohibited from taking pictures in locker rooms and museums, and recording equipment could be disabled in theaters. Professors finally could prevent students from texting one another during class. 
</p><p>
The possibilities are endless, and very dangerous. Making this work involves building a nearly flawless hierarchical system of authority. That's a difficult security problem even in its simplest form. Distributing that system among a variety of different devices -- computers, phones, PDAs, cameras, recorders -- with different firmware and manufacturers, is even more difficult. Not to mention delegating different levels of authority to various agencies, enterprises, industries and individuals, and then enforcing the necessary safeguards.
</p><p>
Once we go down this path -- giving one device authority over other devices -- the security problems start piling up. Who has the authority to limit functionality of my devices, and how do they get that authority? What prevents them from abusing that power? Do I get the ability to override their limitations? In what circumstances, and how? Can they override my override?
</p><p>
How do we prevent this from being abused? Can a burglar, for example, enforce a "no photography" rule and prevent security cameras from working? Can the police enforce the same rule to avoid another Rodney King incident? Do the police get "superuser" devices that cannot be limited, and do they get "supercontroller" devices that can limit anything? How do we ensure that only they get them, and what do we do when the devices inevitably fall into the wrong hands?
</p><p>
It's comparatively easy to make this work in closed specialized systems -- OnStar, airplane avionics, military hardware -- but much more difficult in open-ended systems. If you think Microsoft's vision could possibly be securely designed, all you have to do is look at the dismal effectiveness of the various copy-protection and digital-rights-management systems we've seen over the years. That's a similar capabilities-enforcement mechanism, albeit simpler than these more general systems.
</p><p>
And that's the key to understanding this system. Don't be fooled by the scare stories of wireless devices on airplanes and in hospitals, or visions of a world where no one is yammering loudly on their cellphones in posh restaurants. This is really about media companies wanting to exert their control further over your electronics. They not only want to prevent you from surreptitiously recording movies and concerts, they want your new television to enforce good "manners" on your computer, and not allow it to record any programs. They want your iPod to politely refuse to copy music a computer other than your own. They want to enforce <em>their</em> legislated definition of manners: to control what you do and when you do it, and to charge you repeatedly for the privilege whenever possible. 
</p><p>
"Digital Manners Policies" is a marketing term. Let's call this what it really is: Selective Device Jamming. It's not polite, it's dangerous. It won't make anyone more secure -- or more polite.
</p>
<p>
---
</p>
<p><em>Bruce Schneier is chief security technology officer of BT, and author of</em> Beyond Fear: Thinking Sensibly About Security in an Uncertain World<em>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=2e7004605a2cfdb2dff6647568035341" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=2e7004605a2cfdb2dff6647568035341" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=TdV5GI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=TdV5GI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=hCKWyi"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=hCKWyi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=P6GE7i"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=P6GE7i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=YY5ZlI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=YY5ZlI" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=rAla0I"><img src="http://feeds.wired.com/~f/wired/politics/security?i=rAla0I" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=DKXIgi"><img src="http://feeds.wired.com/~f/wired/politics/security?i=DKXIgi" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=IE7M8i"><img src="http://feeds.wired.com/~f/wired/politics/security?i=IE7M8i" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=swX5hI"><img src="http://feeds.wired.com/~f/wired/politics/security?i=swX5hI" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/320220918" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/320220920" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/wireless devices">wireless devices</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/prevent security cameras">prevent security cameras</category>
      <category domain="http://securityratty.com/tag/difficult security">difficult security</category>
      <category domain="http://securityratty.com/tag/cameras">cameras</category>
      <category domain="http://securityratty.com/tag/prevent students">prevent students</category>
      <category domain="http://securityratty.com/tag/difficult">difficult</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/320220920/securitymatters_0626">Security Matters: I've Seen the Future, and It Has a Kill Switch</source>
    </item>
    <item>
      <title><![CDATA[Directly connect to your corpnet with IPsec and IPv6]]></title>
      <link>http://securityratty.com/article/8fa825adcf64d7fa728dd4b170277578</link>
      <guid>http://securityratty.com/article/8fa825adcf64d7fa728dd4b170277578</guid>
      <description><![CDATA[Contrary to popular belief, the rumors of my demise have been greatly exaggerated. Well, ok, no actual rumors, but hey, one can dream, huh? My spring calendar was full of events in Asia and Australia,...]]></description>
      <content:encoded><![CDATA[<p>Contrary to popular belief, the rumors of my demise have been greatly exaggerated. Well, ok, no <em>actual</em> rumors, but hey, one can dream, huh? My spring calendar was full of events in Asia and Australia, then TechEd US seemed to suddenly appear out of nowhere! So I've been kinda swamped. I've missed writing here; it's good to get back into the swing.</p>  <p>At TechEd this year, I gave a presentation called <strong>&quot;21st century networking: time to throw away your medieval gateways.&quot;</strong> (Actually, I've given this same talk before, at events in Amsterdam, Brussels, Oslo, and numerous on-campus customer meetings. It's time to bring the knowledge to the masses.)</p>  <p>I described an idea of using IPv6, IPsec, NAP, and group policy to build a pretty slick replacement for clunky VPN gateways. Turns out we've been piloting this very idea on our internal corpnet. Like a good little bunny I got myself enrolled in the thing and -- pardon the unattractive gushing -- this thing <em>rawks!</em> Here's a brief rundown of the parts you'd configure on <strong>managed clients</strong>:</p>  <ul>   <li>Windows Vista Business (with Software Assurance), Enterprise, or Ultimate editions</li>    <li>That are domain-joined</li>    <li>Users run as <a href="http://blogs.msdn.com/aaron_margosis/" target="_blank">non-admin</a></li>    <li><a href="http://technet.microsoft.com/en-us/windowsserver/grouppolicy/default.aspx" target="_blank">Group policy</a> applies numerous settings</li>    <li><a href="http://technet2.microsoft.com/WindowsVista/en/library/0d75f774-8514-4c9e-ac08-4c21f5c6c2d91033.mspx?mfr=true" target="_blank">UAC</a> is enabled</li>    <li><a href="http://technet2.microsoft.com/WindowsVista/en/library/c61f2a12-8ae6-4957-b031-97b4d762cf311033.mspx?mfr=true" target="_blank">BitLocker</a> is configured to protect confidential information stored offline</li>    <li>The <a href="http://technet.microsoft.com/en-us/network/bb545423.aspx" target="_blank">Windows Firewall</a> is enabled</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb545879.aspx" target="_blank">NAP</a> is used for checking health</li>    <li><a href="http://technet.microsoft.com/en-us/forefront/clientsecurity/default.aspx" target="_blank">Forefront Client Security</a> for keeping malware off the box</li>    <li><a href="http://technet.microsoft.com/en-us/library/bb742533.aspx" target="_blank">Smart cards</a> for strong authentication of users</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb531150.aspx" target="_blank">IPsec</a> is required for connection authentication and traffic encryption</li>    <li><a href="http://technet.microsoft.com/en-us/network/bb530961.aspx" target="_blank">IPv6</a> is required for worldwide Internet connectivity</li>    <li>A DNS suffix search list represents the data center name space</li>    <li>Static IPv6 DNS servers provide name resolution for hosts in the data center</li> </ul>  <p>What does this give you? True <a href="http://www.microsoft.com/mscorp/twc/anywhereaccess/default.mspx" target="_blank">anywhere access</a>, <a href="http://www.microsoft.com/mscorp/execmail/2007/02-06secureaccess.mspx" target="_blank">anywhere in the world</a>, directly to corpnet resources from managed and secure client PCs. The Internet has replaced private WAN links for good reason: enormous cost benefits. The only thing holding us back from fully utilizing this development has been a lack of way to enforce and monitor the security of clients not physically located within the corpnet. Well, those days are over. Now you can build PCs that are trusted just as if they were on the corpnet, without knowing or caring anything about the underlying network connections. And let me tell you, it's as addictive as a few other substances I could mention, but will refrain, since this is (I hope) a family blog :)</p>  <p>Maybe you've heard of the notion of &quot;<a href="http://en.wikipedia.org/wiki/De-perimeterisation" target="_blank">deperimeterization</a>.&quot; Taken to its extreme, I think it's a bit silly. To put a SQL Server directly on the Internet is just plain stupid -- not because I don't think I could keep it protected, but simply because that's unnecessary risk. Only my web server -- and no one else -- should be talking to my SQL Server. But that web server will be in the same subnet as the SQL Server, and IPsec policies used also here will govern who can connect to the SQL Server. <strong>Warning to any and all network DMZs: your days are numbered!</strong></p>  <p>Shrink your perimeter to that which really matters -- your data center. <em>All</em> your clients live (as we would say in the olden days) &quot;on the outside of the firewall.&quot; Now then, there are two kinds of clients. Managed clients, as I described above, establish IPsec-authenticated/encrypted, group-policy-configured, NAP-enforced IPv6 connections directly to corpnet resources without going through any kind of access gateway. The router connecting you to your ISP is fully sufficient for blocking denial of service attempts. Be sure to follow my advice in &quot;<a href="http://blogs.technet.com/steriley/archive/2006/07/10/Configure-your-router-to-block-DOS-attempts.aspx" target="_blank">Configure your router to block DOS attempts</a>,&quot; and then add two more rules to permit incoming port udp/500 and IP protocol 50 over IPv6. That's it. No NATing or other unnatural network acts are required (finally, you can stop lying to your significant other about why you squirrel yourself away in the computer room all those weekend nights).</p>  <p>Unmanaged clients will continue to use IPv4 to access published Web and Win32 applications through a gateway like <a href="http://technet.microsoft.com/en-us/forefront/edgesecurity/bb687299.aspx" target="_blank">IAG</a>. Since you can't trust these clients nor can you trust the data they're throwing at you, you have to inspect and validate at the perimeter. You can take advantage of IAG's <a href="http://www.microsoft.com/forefront/edgesecurity/iag/whitepapers.mspx" target="_blank">application-modifying capabilities</a> to &quot;wrap&quot; security around poorly-written web apps; you can even download an ActiveX control to unmanaged clients to perform some basic health checking, policy enforcement, and cache clearing. None of these eliminates the final requirement to continue inspecting and removing malware from servers where users store data: <a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb734822.aspx" target="_blank">Exchange</a>, <a href="http://technet.microsoft.com/en-us/forefront/serversecurity/bb734828.aspx" target="_blank">SharePoint</a>, <a href="http://www.microsoft.com/forefront/serversecurity/ocs/default.mspx" target="_blank">Office Communications Server</a>, and <a href="http://technet.microsoft.com/en-us/forefront/clientsecurity/default.aspx" target="_blank">file servers</a>.</p>  <p><strong>Machines are mobile, data is mobile.</strong> The mainframes and large desktop PCs of the past posses an effective security attribute: the heaviness of the machines. You couldn't easily saunter out the front door with a PC-AT in your pocket! These days, we all line our pockets with tiny little mobile phones stuffed with 16GB of storage. It's now a fact: data moves. And like water, data moves wherever it can, as rapidly as it can, often beyond your control if you don't prepare for that. With properly-configured and managed clients we can enjoy a single access and authentication experience no matter where the computer is physically located. For example: I can sit in my house and enter '&quot;http://internal-web-site-name&quot; in my browser. The DNS suffix search list adds the appropriate suffix, my browser's resolver performs an IPv6 name lookup, and my computer makes an authenticated and encrypted connection, after it meets the NAP policy, directly to that internal server. Very nice. As far as I'm concerned, there's no difference between the Internet and my corpnet. It's all <em>just there.</em></p>  <p>For a while now many of you know I've been speaking and writing, mostly at the conceptual level, about the day when such a way of remote computing will arise. Well, my friends, that day is now. You can indeed build it now, with the products you have. I won't admit it's all peaches and cream: there's a fair number of moving parts here, it's true. But most of these moving parts are parts you're already familiar with: I'm simply encouraging you to move them in a specific way. You'll need to do some custom scripting for client-side connection diagnostics, but that's about it.</p>  <p>My next step is to create a more detailed guide, which I plan to publish through TechNet Magazine. I'm targeting (but not promising) the October issue. The article will include greater details about configuring your infrastructure to support the managed clients I describe.</p>  <p>I've lost track of the swelling number of individual conference attendees and the plethora of email writers who've expressed a desire to build this in their own environments. The one common thread from everyone is &quot;I want to do it now!&quot; Folks, it's really pretty exciting for me to see so many of you ready to cross the chasm from the perdition of paleo-networking (layer upon endless, complex layer of DMZs) into the paradise of flat, simple, cheap, and secure access to information. If you haven't yet, please take the time to read through some of our information (especially Scott Charney's paper) on <a href="http://www.microsoft.com/mscorp/twc/endtoendtrust/default.mspx" target="_blank">end-to-end trust</a>. Friends, the idea I describe above is the plumbing for realizing the end-to-end trust vision.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3078070" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 16:55:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/directly">directly</category>
      <category domain="http://securityratty.com/tag/corpnet">corpnet</category>
      <category domain="http://securityratty.com/tag/sql server directly">sql server directly</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/end-to-end trust vision">end-to-end trust vision</category>
      <category domain="http://securityratty.com/tag/users store data">users store data</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx">Directly connect to your corpnet with IPsec and IPv6</source>
    </item>
    <item>
      <title><![CDATA[I spy - employees snooping around?]]></title>
      <link>http://securityratty.com/article/d94aacf5df0c049737b72c0e23324678</link>
      <guid>http://securityratty.com/article/d94aacf5df0c049737b72c0e23324678</guid>
      <description><![CDATA[Apparently many employees ( nearly half ) have the habit of snooping around within the company. This according to a new research study by Cyber-Ark . Many gain access using privileged accounts such as...]]></description>
      <content:encoded><![CDATA[Apparently many employees ( nearly half ) have the habit of snooping around within the company. This according to a <a href="http://www.pcworld.com/businesscenter/article/147400/nearly_half_of_it_workers_snoop_in_confidential_files.html">new research study by Cyber-Ark</a>. Many gain access using privileged accounts such as administrator or root passwords, which the research found were not changed that often.<br /><br /><span style="font-style: italic;font-family:&quot;;font-size:85%;"  >"Cyber-Ark said privileged passwords get changed far less frequently than user passwords, with 30 percent being changed every quarter and 9 percent never changed at all, meaning that IT staff who have left an organization could still gain access."</span><br /><br />This is a bit unnerving - most organizations should be following compliance mandates such as SOX to isolate administrator access from content. And using technology to enforce this..<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=H0Al6I"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=H0Al6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=LLodQi"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=LLodQi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=rJCYMI"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=rJCYMI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/318116842" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 09:28:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/user passwords">user passwords</category>
      <category domain="http://securityratty.com/tag/gain access">gain access</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/administrator">administrator</category>
      <category domain="http://securityratty.com/tag/administrator access">administrator access</category>
      <category domain="http://securityratty.com/tag/research study">research study</category>
      <category domain="http://securityratty.com/tag/root passwords">root passwords</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/318116842/i-spy-employees-snooping-around.html">I spy - employees snooping around?</source>
    </item>
    <item>
      <title><![CDATA[Leveraging Data Leak Prevention Technology to Secure Corporate Assets]]></title>
      <link>http://securityratty.com/article/7f1a4c4e8143e85ad6391c57239d66e2</link>
      <guid>http://securityratty.com/article/7f1a4c4e8143e85ad6391c57239d66e2</guid>
      <description><![CDATA[Source: Trend Micro) Protective measures such as VPNs, firewalls, and network monitors provide audit trails and prevent unauthorized external access to information, but they dont address the rising...]]></description>
      <content:encoded><![CDATA[<b>(Source: Trend Micro)</b> Protective measures such as VPNs, firewalls, and network monitors provide audit trails and prevent unauthorized external access to information, but they dont address the rising threat of internal users. Learn how an effective DLP solution can help prevent data leaks and meet compliance regulations such as SB-1386, GLBA, EU DPD, Sarbanes-Oxley, and HIPAA requires intelligent content filtering solutions that enforce security policies.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=ZAFIWX"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=ZAFIWX" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/318310539" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prevent data leaks">prevent data leaks</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/effective dlp solution">effective dlp solution</category>
      <category domain="http://securityratty.com/tag/enforce security policies">enforce security policies</category>
      <category domain="http://securityratty.com/tag/protective measures">protective measures</category>
      <category domain="http://securityratty.com/tag/internal users">internal users</category>
      <category domain="http://securityratty.com/tag/compliance regulations">compliance regulations</category>
      <category domain="http://securityratty.com/tag/external access">external access</category>
      <category domain="http://securityratty.com/tag/trend micro">trend micro</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/318310539/whitepapers.do">Leveraging Data Leak Prevention Technology to Secure Corporate Assets</source>
    </item>
  </channel>
</rss>
