<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: farmers]]></title>
    <link>http://securityratty.com/tag/farmers</link>
    <description></description>
    <pubDate>Sat, 16 Feb 2008 01:49:17 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</link>
      <guid>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</guid>
      <description><![CDATA[Are you ready for more 419 missives

Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick &quot;Robert Mugabe&quot; themed mail and, er, someone called &quot;Captain Frank Bojo&quot;...]]></description>
      <content:encoded><![CDATA[
        Are you ready for more 419 missives?<br /><br />Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick "Robert Mugabe" themed mail and, er, someone called "Captain Frank Bojo" after the jump...<br /> 
        Subject:<br />HELLO DEAR<br />From:<br />"abavanagift13 Gazeta.pl" &lt;abavanagift13@gazeta.pl&gt;<br />Date:<br />Sat, 21 Jun 2008 12:26:24 +0000<br />BCC:<br /><br />Hello Dear,<br />&nbsp;<br />&nbsp;My name is Blessing Abavana, the elder daughter of Mr. paul Abavana of Zimbabwe, I am 17 years old with my younger brother (Micheal), we are in Ghana as refuge/asylum since we lost our parents because of the recent war that occurred in our country.please do go through this web page for better understanding with full details:<br />&nbsp;<br />&nbsp;http://www.rte.ie/news/2000/0418/zimbabwe.html<br />&nbsp;<br />&nbsp;I am looking for one&nbsp; who will honestly assist my younger brother and I to realize our inherited funds into your account and as well as invest it into a lucrative business.<br />&nbsp;<br />During the recent war against the farmers in Zimbabwe from the supporters of our President, Robert Mugabe to claim all the white -owned farms to his party members and his followers, he ordered all the white farmers to surrender all their farms to his party members and his followers.<br />&nbsp;<br />&nbsp;My father being one of the few rich and successful black farmers in our country was also victimized because of his opposition to Mugabe's policies. And because he did not support Mugabe's ideas, Mugabe's supporters invaded my father's farm and burnt everything in the farm, killed my father and made away with a lot of items in my father's farm. This action was taken because my late father felt the growing tension on the farm issue, but I guess he never anticipated the tragedy that brought their brutal and sudden death.<br />&nbsp;<br />&nbsp;However with the benefit of hindsight, owing to the looming but deteriorating crisis in my country, Zimbabwe, my father, before his unfortunate death deposited with International Commercial Bank (ICB) here in Accra Ghana the sum of US$ 35MUsd (Thirty Five Million United States Dollars), with the sole aim of acquiring and buying some dredging equipments in setting up of a dredging firm with his partner. With his death and all his assets seized at home and accounts frozen, the family is now in a very difficult situation.<br />&nbsp;<br />&nbsp;After the death of my father, my brother and I escaped to the Republic of Ghana where he had deposited the money in the Bank . And we were permitted to reside here as Political Refugees.<br />&nbsp;<br />&nbsp;So Because of our present and unpleasant status here we decided to contact an overseas firm / individual that can assist us to move this money out Of Ghana because, as asylum seekers, we are not allowed to operate any financial transaction of such amount within Ghana and also to assist in providing me and my brother a permanent residential permit in your country after the money must have been transferred to your account.<br />&nbsp;<br />We have agreed to offer you 30% of the total sum for your assistance, and the rest will be for my brother and I, to Invest in your country under your assistant<br />&nbsp;<br />All I want you to do is to furnish me with the below information including your readiness to assist me achieve this transaction for investment purposes in your country under your supervision. Kindly re-confirm to me the followings:<br /><br />1) Your Full Name:<br />2) Phone, Fax and Mobile<br />3) Profession, Age and Marital Status.<br />4) Nationality<br />&nbsp;<br />&nbsp;I have to re-assure you that this transaction is 100% risk free and should be treated with absolute confidentiality. All the vital documentation/certification that has to do with the origin of the fund is with me for the security reasons.And I will send them to you when we progress.And I guarantee you that this fund is not government fund, drug money, or from arms deals.<br />&nbsp;<br />&nbsp;I will detail you more about&nbsp; the bank&nbsp; immediately I receive your acceptance response. I hope this is the beginning of a prosperous relationship between us.Thanks and God bless you<br />&nbsp;<br />Regards<br /><br />Blessing/Micheal Abavana<br /><br /><b>(Wow, spectacularly sick. Not that we're expecting scammers to have any morals, of course).</b><br /><br />*********************************************************************************************<br /><br /><br />Subject:<br />Lycos Online Lottery Notification<br />From:<br />"LHOUTY MOHAMMED HASSANE" &lt;mhlhouty@menara.ma&gt;<br />Date:<br />Sun, 22 Jun 2008 02:42:53 -0000<br />BCC:<br /><br />LYCOS LOTTERY ONLINE<br />8th Floor<br />1 Stephen Street<br />London<br />W1T 1AL<br />&nbsp;<br />WINNING NOTIFICATION<br />This is to inform you that your email address has won the Lycos Lottery for the year 2008. your email has won you the sum of ?952,350.00 (Nine Hundred And Fifty Two Thousand, Three Hundred And Fifty pounds sterling).<br />You are advised to keep this notice confidential to avoid misinterpretation of funds and unauthorize claims, cheating or fraud.<br />To claim your funds please contact us with the information below.<br />Name: Dr. George Stevenson<br />Tel:+447031991681<br />Email:lycosclaimsdpt@gmail.com<br />&nbsp;<br />It is mandatory that you send us your full names, address, phone number,<br />age, sex and occupation to enable us arrange your claim.<br />&nbsp;<br />Note: Winners were selected through a computer ballot system drawn from Microsoft users from company and individual email addresse users. All winning must be claimed not later than 21 working days from the time of notification. After this date all unclaimed funds will be returned to European Union Treasury as unclaimed funds.<br />&nbsp;<br />Congratulations from mambers and staff of Lycos<br />Lhouty Mohammed Hassane.<br />Lycos Lottery Co-ordinator<br /><br /><b>(A "Lycos Lottery" and they're using a GMail address? Doh).</b><br /><br />*********************************************************************************************<br /><br />Subject:<br />Yukos Oil<br />From:<br />Mr. Timinskiy Vladimir &lt;grooves@bellnet.ca&gt;<br />Date:<br />Wed, 25 Jun 2008 5:38:17 -0400<br />To:<br />&lt;info@yukos.org&gt;<br /><br />I have a profiling amount in an excess of US$100.5M, which I seek you in accommodating for me. You will be rewarded with 4% .If intrested, please reply me for moredetails...&lt;tvlad4@gmail.com&gt;<br />Regards<br />Mr. Timinskiy Vladimir<br /><br /><b>(Short. Sweet. Pointlessly fake).</b><br /><br />*******************************************************************************<br /><br />Subject:<br />Immediate Release of Your FUND Via ATM CARD<br />From:<br />"Mr. Mark Louis" &lt;francois.lapeyronie@wanadoo.fr&gt;<br />Date:<br />Wed, 25 Jun 2008 01:45:09 -0700<br />To:<br />undisclosed-recipients:;<br /><br />SUBJECT: Immediate Release of Your FUND Via ATM CARD<br /><br />Attention: ATM Card Beneficiary,<br /><br />I wish to use this medium to inform you that your CONTRACT/INHERITANCE Paymen of USD$10,000,000.00 (Ten Million United States Dollars) from CENTRAL BANK<br />OF NIGERIA have been RELEASED and APPROVED for onward transfer to you via an ATM CARD which you will use to withdraw all the USD$10,000,000.00 in any<br />ATM SERVICE MACHINE in any part of the world, but the maximum you can withdraw in a day is USD$10,000.00 Only.<br /><br />We have mandated IBTC CHARTERED BANK PLC, to send you the ATM CARD and PIN NUMBER which you will use to withdraw all your USD$10 Million Dollars in<br />any ATM SERVICE MACHINE in any part of the world. You are therefore advice to contact the Head of ATM CARD Department of IBTC CHARTERED BANK PLC;<br /><br />Contact Person: Dr. Olu James<br />Office email address:&nbsp;&nbsp; pcfc_nigeria@yahoo.com<br />Private: +2347084501007<br />Office:018969906<br /><br />Tell Dr. Olu James that you received a message from the CENTRAL BANK OF NIGERIA. Instructing him to send you the ATM CARD and PIN NUMBER which you will use<br />to withdraw your USD$10 Million Dollars in any ATM SERVICE MACHINE in any part of the world, also send him your direct phone number and contact address<br />where you want him to send the ATM CARD and PIN NUMBER to you. We are very sorry for the plight you have gone through in the past years. Thanks for adhering to this instruction and once again accept our congratulations.<br /><br />Best Regards.<br />Mr. Mark Louis.<br />Executive Governor,<br /><br />Central Bank of Nigeria {CBN}.<br /><br /><b>(Ah, the old "Let's lure them in with the magical bank card" trick).</b><br /><br /><br />******************************************************************************************<br /><br />Subject:<br />CONTACT THE FEDEX COMPANY FOR YOUR FUNDS<br />From:<br />"SAMUEL DUNBAR" &lt;samuel_dunbar0013@ig.com.br&gt;<br />Date:<br />Fri, 20 Jun 2008 12:33:43 +0100<br />BCC:<br /><br />Dear Friend,<br /><br />Compliment of the new year, I have been waiting for you since to come down here and pick your Bank Draft which my boss left with me before he travelled to England but I did not hear from you since that time till today. I went to the bank to confirm whether the draft is getting close to expire as it had been long time my boss issued the draft. The director of the bank told me that before the draft will get to you, that it will expire. Then I told him to help me and cash the cashier bank draft of $1,500.000.00 to cash payment.<br /><br />However, I have successfully cashed the draft and packaged it in a box and have registered it in the Fedex Express Company Service here in Benin Republic because I will travell to see my boss in England and will not come back till August 20th 2008. You have to contact the Fedex Express Company Service to know when they will deliver your package to your address. I have paid for the delivering charges and insurance fees. The only money you have to send to them is their security keeping feeswhich is USD$135.00 USD to receive your package. Don't be deceived by any body.<br /><br />This is their Contact Address;<br />Attn: Cheif Mr. George Kobra (Director)<br />Tel:&nbsp; +229-9799 2240<br />E-mail: fc.bj@sify.com<br /><br />Send them your contacts information to enable them locate you<br />&nbsp;immediately they arrived in your country with your package.<br /><br />This is the information they needed from you.<br /><br />1. Your full name:.....<br />2. Your shipping/home address:.....<br />3. Your tel no #......<br />4. Your current office tel no #<br />5. A copy of your passport.<br /><br />Try to contact them as soon as possible to avoid increasement of the security keeping fees Note; I didn't tell the Fedex Express Company Service that it's money inside the box, I registered it as a church of a Church Minister Materials. This is to avoid delay or any upfront problem during the delivery. So, do not let them know that the package contents money. Do let me know as soon as you received your package. You will contact&nbsp; me only through e-mail as my phone is no longe available now that I am out from our country. Contact me at samdunbar1986@yahoo.com and I will reply as soon as I can.<br />I wish you and your family Long Life,<br />Prosperity and Happy 2008.<br /><br />Thanks and Remain Blessed.<br /><br />Yours sincerely,<br />Mr.Samuel Dunbar<br />(Secretary)<br /><br /><b>(Honestly, if you contact FedEx they'll give you tons of money....)</b><br /><br />****************************************************************************************<br /><br />That's your lot for another week....<br />
    ]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:29:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/central bank">central bank</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/magical bank card">magical bank card</category>
      <category domain="http://securityratty.com/tag/bank draft">bank draft</category>
      <category domain="http://securityratty.com/tag/email address">email address</category>
      <category domain="http://securityratty.com/tag/office email address">office email address</category>
      <category domain="http://securityratty.com/tag/bank immediately">bank immediately</category>
      <category domain="http://securityratty.com/tag/lycos lottery">lycos lottery</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <source url="http://blog.spywareguide.com/2008/06/your-419-mail-roundup.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[Canadian farmer personal information on stolen CCGA laptop]]></title>
      <link>http://securityratty.com/article/59ad7c04243f6352dc04e5847a1515dd</link>
      <guid>http://securityratty.com/article/59ad7c04243f6352dc04e5847a1515dd</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/4/08

Organization
Government of Canada

Contractor/Consultant/Branch
Canadian Canola Growers Association (CCGA

Victims
Farmers

Number Affected...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/ccga.jpg" align="right" height="82" width="168"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/4/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.gc.ca/home.html">Government of Canada</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.ccga.ca/OrganizationHome.htm">Canadian Canola Growers Association (CCGA)</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Farmers<br><br><span style="font-weight: bold;">Number Affected:</span><br>~32,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"social insurance numbers, bank account numbers and other data"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"OTTAWA, June 5 (UPI) -- Prairie farmers in Canada are upset the federal government waited two months to tell them a laptop computer containing their personal data was missing."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.winnipegfreepress.com/breakingnews/story/4182176p-4771903c.html">Winnipeg Free Press</a> <br><a href="http://www.cbc.ca/consumer/story/2008/06/05/canola-information.html">CBC News</a> <br><a href="http://www.upi.com/Top_News/2008/06/05/Personal_data_on_32000_farmers_missing/UPI-66311212671633/">United Press International</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Lindsay Wiebe, Winnipeg Free Press<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>About 32,000 Canadian farmers are on the alert after learning a laptop containing their financial information has been stolen.<br><br>The laptop was stolen when a programmer working for the Canadian Canola Growers Association took the machine off-site for routine maintenance.<br><span style="font-style: italic;">[Evan] No offense to programmers, but in my experience the ways they use information can be some of the most dangerous threats to information security.&nbsp; There is no reason for a programmer to EVER have access to confidential production information.&nbsp; Programmers should only be permitted to work with scrubbed information in a test and/or development environment.</span><br><br>CCGA general manager Rick White described the theft as a classic "smash and grab."<br><span style="font-style: italic;">[Evan] Also classic as in another organization that either does not know how or is unwilling to properly secure confidential information.</span><br><br>The laptop has the bank account numbers and social insurance numbers of farmers who applied for Agriculture Canada's advance payments program, which is administered by the CCGA on behalf of the federal government.<br><br>Although the theft happened March 30, Canadians weren't sent letters until last week informing them<br><br>The federal department has sent letters out to all farmers affected by the theft.<br><br>The letter said the laptop was stolen from an undisclosed, remote location in Manitoba.<br><br>"We treat this very seriously," White said. "This is an unfortunate incident, a very low-risk one."<br><span style="font-style: italic;">[Evan] Mr. White is probably not well versed in risk analysis.&nbsp; Or incident response for that matter.</span><br><br>the strict security measures being used on the laptop reduce the chances of information being misused, White said.<br><span style="font-style: italic;">[Evan] Like what?</span><br><br>"There was a very strong password protection on it, [and] there was a biometric fingerprint reader on it," he said. "That would prohibit anyone other than the user or the person with the password to access the data on the laptop."<br><span style="font-style: italic;">[Evan] These are "strict security measures"?&nbsp; My emphatic answer is NO!&nbsp; These "strict security measures" are easily bypassed.</span><br><br>but the data was not encrypted<br><span style="font-style: italic;">[Evan] The missing piece of the puzzle.&nbsp; Why go through all of the (self-proclaimed) "strict security measures" and not employ encryption.&nbsp; What you get with full-disk encryption is pre-boot authentication and this defeats the boot to CD attack.</span><br><br>Agriculture Canada spokesman Sean Malone said there were security features on the laptop, but a sophisticated hacker could likely bypass them.<br><span style="font-style: italic;">[Evan] No sophistication required.&nbsp; A novice could figure it out with Google, a CD, and 15 minutes.</span><br><br>So far, there have been no reports of identity theft among the farmers, the report said.<br><br>Pitblado LLP privacy lawyer Brian Bowman said the CCGA and agriculture department deserve credit for notifying people of the breach -- a move not required by Manitoba law.<br><span style="font-style: italic;">[Evan] Just because CCGA is not required by law, doesn't mean that they deserve any credit for notification.&nbsp; The information belongs to the victims not CCGA, and as owners of the information don't you think they should be informed of an incident that has the potential affect them personally?</span><br><br><span style="font-weight: bold;">Victim Reaction:</span><br>"If they're devilish enough to steal a computer, maybe they're devilish enough to do something with the information," <br><br>"What frustrates me is that they've treated this like it's no skin off their back,"<br><br>"They've known this since then and they're only getting the letters out now?"<br><br>"I don't want to find out a mortgage has been taken out on our farm."<br><br><span style="font-weight: bold;">Commentary:</span><br>It is bad enough for an organization to lose confidential information on a poorly protected laptop, but what makes this more troubling is the apparent fact that they still view the practice that led to the breach as a low risk.&nbsp; Clueless and sad. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Government of Canada:<br>December, 2007 - <a href="http://breachblog.com/2007/12/05/passport.aspx">Passport Canada web site suffers serious breach</a> <br>November, 2007 - <a href="http://breachblog.com/2007/11/26/servicecanada.aspx">Service Canada stolen laptop affects more than 1,600</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/08/ccga.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 08 Jun 2008 15:32:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/laptop affects">laptop affects</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/strict security measures">strict security measures</category>
      <category domain="http://securityratty.com/tag/ccga">ccga</category>
      <category domain="http://securityratty.com/tag/laptop computer">laptop computer</category>
      <source url="http://breachblog.com/2008/06/08/ccga.aspx">Canadian farmer personal information on stolen CCGA laptop</source>
    </item>
    <item>
      <title><![CDATA[Securing Virtual Environments Through Partnerships]]></title>
      <link>http://securityratty.com/article/25a154081192f4f83515088806957470</link>
      <guid>http://securityratty.com/article/25a154081192f4f83515088806957470</guid>
      <description><![CDATA[Im back from the RSA 2008 Security Show in San Francisco and it was another great year of business development activity for security vendors. It felt like there was a decent amount of end user...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong><o:p></o:p></strong>I’m back from the RSA 2008 Security Show in San Francisco
and it was another great year of business development activity for security
vendors. It felt like there was a decent
amount of end user customers at the show but a lot more vendors touting their
wares and looking to do work with each other. I sat and listened to many vendors complain about this however and listened
to them complain about how they spend money year after year for these shows and
rarely get to talk to customers. It felt
to them that they hear more from other vendors that come up to their booth asking
about partnering or OEM’ing there technology. Well, this does get old pretty fast when you are looking to sell product
to justify your existence but for me it was refreshing to talk with other
companies about partnering. I had the
opportunity to talk to customers also but it was really exciting for me to have
partnership discussions.



</p>

<p class="MsoNormal">Why? Well over at Montego Networks where we are focusing on securing
a new type of network (one that’s virtual) we believe in security through partnerships.
Securing virtual environments is like exploring new frontier or a planned
venture to Mars. Research scientists, chemists,
doctors, collective minds and in this case a unity of security vendors we feel
is the best approach to getting ready for this venture to the new Virtual World.</p>



<p class="MsoNormal"><img width="239" height="174" src="file:///C:/Users/JOHNPE~1/AppData/Local/Temp/msohtmlclip1/01/clip_image002.jpg" v:shapes="_x0000_i1026" /></p>

<p class="MsoNormal"><o:p></o:p></p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/04/13/earthpic.jpg" onclick="window.open(this.href, '_blank', 'width=640,height=400,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img width="100" height="62" border="0" alt="Earthpic" title="Earthpic" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/04/13/earthpic.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
 </p>

<p class="MsoNormal">Virtual Environments need to be studied jointly in order to understand
the new security risks, performance impacts and how to effectively secure it.&nbsp; Montego Networks plans to do that and has
announced its HyperVSecurity Alliance at RSA and has joined forces with
Cyberoam, Lancope StillSecure and Plixer International in an effort to provide
Anti-Malware, Network Access Control, Intrusion Prevention, Behavioral Analysis
and Network Monitoring for the virtual environment. </p>





<p class="MsoNormal">See:<o:p>&nbsp;</o:p></p>

<p class="MsoNormal"><a href="http://www.montegonetworks.com/node/54">http://www.montegonetworks.com/node/54</a></p>







<p class="MsoNormal"><a href="http://www.eweek.com/c/a/Security/Partnerships-are-Key-in-Virtualization-Security/">http://www.eweek.com/c/a/Security/Partnerships-are-Key-in-Virtualization-Security/</a><o:p>&nbsp;</o:p></p>

<p class="MsoNormal">By establishing this type of alliance research engineers and
vendors will be able to journey to the new Virtual Datacenter with all of the
needed components and insight on securing networks. At the epicenter of this alliance is a security
frame work designed by Montego Networks that allows various technologies to
plug in to the center of the virtual environment which is the switching
infrastructure.</p>





<p class="MsoNormal">Through Montego Networks HyperSwitch, which has the ability
see virtual network communication between systems (virtual desktops &amp;
servers), a frame work is created that allows for user defined policy that can send
traffic off to various places. An
example of this is via the HyperSwitches Policy Based Switching engine which
allows a user to create a policy that dictates that all email traffic will be
directed to an Anti-Virus Gateway or its NetFlow capability which exports flow
information to a Behavioral Analysis Engine.<o:p>&nbsp;</o:p></p>

<p class="MsoNormal">After these various systems do what they do with the data,
they are also able to respond back to the frame work via an API called NSCP (Network
Security Control Protocol) to instruct it to tack appropriate action. This could be an IDS system invoking a
firewall policy or a Behavioral Analysis system telling the frame work to
throttle back (slow down) a users traffic flow. The possibilities are limitless!</p>





<p class="MsoNormal">So, much like the frontier to the USA from England where we
needed Doctors, Lawyers, Law Enforcement, Builders and Farmers, virtualization
needs a coalition of security forces that can provide Anti-Virus, IPS,
Firewall, Network Monitoring, Behavioral Analysis, etc. etc.&nbsp; <o:p>&nbsp;</o:p></p>

<p class="MsoNormal">The goal is to all co-exist in the virtual environment vs.
fight for the same piece of land. I
think this makes sense because all is needed in the virtual world!</p>



<p class="MsoNormal">Stay tuned, as the alliance will get bigger and stronger and
give customers choice and independence as they look to secure the virtual
datacenter. Learn your ABC’s! Anything But Cisco, Let Freedom Ring! </p>

<p class="MsoNormal"><o:p>&nbsp;</o:p></p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/04/13/freedom.jpg" onclick="window.open(this.href, '_blank', 'width=118,height=118,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img width="200" height="200" border="0" alt="Freedom" title="Freedom" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/04/13/freedom.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
</p>

<p class="MsoNormal"><img width="116" height="116" border="0" src="file:///C:/Users/JOHNPE~1/AppData/Local/Temp/msohtmlclip1/01/clip_image004.jpg" v:shapes="_x0000_i1025" /></p>

</div>
]]></content:encoded>
      <pubDate>Sun, 13 Apr 2008 12:06:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/virtual network communication">virtual network communication</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/montego networks plans">montego networks plans</category>
      <category domain="http://securityratty.com/tag/virtual datacenter">virtual datacenter</category>
      <category domain="http://securityratty.com/tag/montego networks">montego networks</category>
      <category domain="http://securityratty.com/tag/virtual environment">virtual environment</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/269553477/securing-virtua.html">Securing Virtual Environments Through Partnerships</source>
    </item>
    <item>
      <title><![CDATA[Securing Virtual Environments Through Partnerships]]></title>
      <link>http://securityratty.com/article/a22b83da886e5d484c284d696b6d50be</link>
      <guid>http://securityratty.com/article/a22b83da886e5d484c284d696b6d50be</guid>
      <description><![CDATA[I???m back from the RSA 2008 Security Show in San Francisco and it was another great year of business development activity for security vendors. It felt like there was a decent amount of end user...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong><o:p></o:p></strong>I???m back from the RSA 2008 Security Show in San Francisco
and it was another great year of business development activity for security
vendors. It felt like there was a decent
amount of end user customers at the show but a lot more vendors touting their
wares and looking to do work with each other. I sat and listened to many vendors complain about this and listened
to them complain about how they spend money year after year for these shows and
rarely get to talk to customers. It felt
to them that they hear more from other vendors that come up to their booth asking
about partnering or OEM???ing their technology. Well, this does get old pretty fast when you are looking to sell product
to justify your existence but for me it was refreshing to talk with other
companies about partnering. I had the
opportunity to talk to customers also but it was really exciting for me to have
partnership discussions.



</p>

<p class="MsoNormal">Why? Well over at Montego Networks where we are focusing on securing
a new type of network (one that???s virtual) we believe in security through partnerships.
Securing virtual environments is like exploring new frontier or a planned
venture to Mars. Research scientists, chemists,
doctors, collective minds and in this case a unity of security vendors we feel
is the best approach to getting ready for this venture to the new Virtual World.</p>



<p class="MsoNormal"><img width="239" height="174" src="file:///C:/Users/JOHNPE~1/AppData/Local/Temp/msohtmlclip1/01/clip_image002.jpg" v:shapes="_x0000_i1026" /></p>

<p class="MsoNormal"><o:p></o:p></p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/04/13/earthpic.jpg" onclick="window.open(this.href, '_blank', 'width=640,height=400,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img width="100" height="62" border="0" alt="Earthpic" title="Earthpic" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/04/13/earthpic.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
 </p>

<p class="MsoNormal">Virtual Environments need to be studied jointly in order to understand
the new security risks, performance impacts and how to effectively secure it.&nbsp; Montego Networks plans to do that and has
announced its HyperVSecurity Alliance at RSA and has joined forces with
Cyberoam, Lancope StillSecure and Plixer International in an effort to provide
Anti-Malware, Network Access Control, Intrusion Prevention, Behavioral Analysis
and Network Monitoring for the virtual environment. </p>





<p class="MsoNormal">See:<o:p>&nbsp;</o:p></p>

<p class="MsoNormal"><a href="http://www.montegonetworks.com/node/54">http://www.montegonetworks.com/node/54</a></p>







<p class="MsoNormal"><a href="http://www.eweek.com/c/a/Security/Partnerships-are-Key-in-Virtualization-Security/">http://www.eweek.com/c/a/Security/Partnerships-are-Key-in-Virtualization-Security/</a><o:p>&nbsp;</o:p></p>

<p class="MsoNormal">By establishing this type of alliance research engineers and
vendors will be able to journey to the new Virtual Datacenter with all of the
needed components and insight on securing networks. At the epicenter of this alliance is a security
frame work designed by Montego Networks that allows various technologies to
plug in to the center of the virtual environment which is the switching
infrastructure.</p>





<p class="MsoNormal">Through Montego Networks HyperSwitch, which has the ability
see virtual network communication between systems (virtual desktops &amp;
servers), a frame work is created that allows for user defined policy that can send
traffic off to various places. An
example of this is via the HyperSwitches Policy Based Switching engine which
allows a user to create a policy that dictates that all email traffic will be
directed to an Anti-Virus Gateway or its NetFlow capability which exports flow
information to a Behavioral Analysis Engine.<o:p>&nbsp;</o:p></p>

<p class="MsoNormal">After these various systems do what they do with the data,
they are also able to respond back to the frame work via an API called NSCP (Network
Security Control Protocol) to instruct it to tack appropriate action. This could be an IDS system invoking a
firewall policy or a Behavioral Analysis system telling the frame work to
throttle back (slow down) a users traffic flow. The possibilities are limitless!</p>





<p class="MsoNormal">So, much like the frontier to the USA from England where we
needed Doctors, Lawyers, Law Enforcement, Builders and Farmers, virtualization
needs a coalition of security forces that can provide Anti-Virus, IPS,
Firewall, Network Monitoring, Behavioral Analysis, etc. etc.&nbsp; <o:p>&nbsp;</o:p></p>

<p class="MsoNormal">The goal is to all co-exist in the virtual environment vs.
fight for the same piece of land. I
think this makes sense because all is needed in the virtual world!</p>



<p class="MsoNormal">Stay tuned, as the alliance will get bigger and stronger and
give customers choice and independence as they look to secure the virtual
datacenter. Learn your ABC???s! Anything But 100% Cisco, Let Freedom Ring! </p>

<p class="MsoNormal"><o:p>&nbsp;</o:p></p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/04/13/freedom.jpg" onclick="window.open(this.href, '_blank', 'width=118,height=118,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img width="200" height="200" border="0" alt="Freedom" title="Freedom" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/04/13/freedom.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
</p>

<p class="MsoNormal"><img width="116" height="116" border="0" src="file:///C:/Users/JOHNPE~1/AppData/Local/Temp/msohtmlclip1/01/clip_image004.jpg" v:shapes="_x0000_i1025" /></p>

</div>
]]></content:encoded>
      <pubDate>Sun, 13 Apr 2008 12:06:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/virtual network communication">virtual network communication</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/montego networks plans">montego networks plans</category>
      <category domain="http://securityratty.com/tag/virtual datacenter">virtual datacenter</category>
      <category domain="http://securityratty.com/tag/montego networks">montego networks</category>
      <category domain="http://securityratty.com/tag/virtual environment">virtual environment</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/04/securing-virtua.html">Securing Virtual Environments Through Partnerships</source>
    </item>
    <item>
      <title><![CDATA[A Barn Door Has No ROI]]></title>
      <link>http://securityratty.com/article/fa48109a560888f736899993a781c3ef</link>
      <guid>http://securityratty.com/article/fa48109a560888f736899993a781c3ef</guid>
      <description><![CDATA[When you think about it, farmers know where their assets are better than a lot of us in business. Usually, theyre in the barn. A security geeks interpretation of the term closing the barn door after...]]></description>
      <content:encoded><![CDATA[When you think about it, farmers know where their assets are better than a lot of us in business. Usually, they’re in the barn. A security geek’s interpretation of the term “closing the barn door after the horses have bolted”, would probably be something like “it’s too late to take preventative action after the incident [...]]]></content:encoded>
      <pubDate>Sat, 16 Feb 2008 01:49:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/barn">barn</category>
      <category domain="http://securityratty.com/tag/barn door">barn door</category>
      <category domain="http://securityratty.com/tag/security geeks interpretation">security geeks interpretation</category>
      <category domain="http://securityratty.com/tag/preventative action">preventative action</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/farmers">farmers</category>
      <category domain="http://securityratty.com/tag/assets">assets</category>
      <source url="http://securityviews.com/blog/2008/02/15/a-barn-door-has-no-roi/">A Barn Door Has No ROI</source>
    </item>
  </channel>
</rss>
