<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: forescout]]></title>
    <link>http://securityratty.com/tag/forescout</link>
    <description></description>
    <pubDate>Wed, 03 Oct 2007 02:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[When is 4 out of 5 stars is not 4 out of 5 stars or do I have a car for you!]]></title>
      <link>http://securityratty.com/article/e9877b84765f2874457cb3dd3cdfa96b</link>
      <guid>http://securityratty.com/article/e9877b84765f2874457cb3dd3cdfa96b</guid>
      <description><![CDATA[After my used car salesman of NAC series I was going to give Ray and the gang a break. But the depths they sink to just never cease to amaze me! Today I received a Google alert on NAC with a link to a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>After my “<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/the-used-car-sa.html">used car salesman of NAC</a>” series I was going to give Ray and the gang a break.&nbsp; But the depths they sink to just never cease to amaze me! Today I received a Google alert on NAC with a <a href="http://www.sourcewire.com/releases/rel_display.php?relid=40444&amp;hilite=">link to a press release</a> announcing the NAC used car sales guys continuing to deliver best in class security management solutions, yada, yada, yada.&nbsp; The basis for this claim was that “SC Magazine awarded ForeScout’s CounterACT a four-out-of-five star rating, lauding the product’s ability to “function like a firewall, an IPS and a NAC device all rolled into one”.&nbsp; They wrapped some customer quote (that had nothing to do with the SC magazine story) and voila!, can they put you in this car today? </p>

<p>So why do I call this out? No, no sour grapes here.&nbsp; Actually StillSecure Safe Access received the same 4 out of 5 stars and when we dig into the rating here are some interesting facts:</p>

<p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/forescout.jpg"><img title="forescout" height="301" alt="forescout" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/forescout_thumb.jpg" width="197" border="0" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" /></a>&nbsp; <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/stillsecure%20sc%20mag_1.jpg"><img title="stillsecure sc mag" height="329" alt="stillsecure sc mag" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/stillsecure%20sc%20mag_thumb_1.jpg" width="195" border="0" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" /></a><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/slimy_salesguy_1.jpg"><img title="slimy_salesguy" height="240" alt="slimy_salesguy" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/slimy_salesguy_thumb_1.jpg" width="170" border="0" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; MARGIN: 0px 0px 0px 40px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" /></a> </p>

<p>In actuality, our friends the used car salesmen only received a 2 star rating in ease of use, a 2 star rating in documentation and a 3 star rating in support.&nbsp; In contrast <a href="http://www.scmagazineus.com/StillSecure-Safe-Access/Review/2460/">StillSecure Safe Access</a> received 5 stars across the board, except for a 4 star grade in documentation.&nbsp; How both products finish up with a 4 star rating overall based upon this is frankly baffling to me. I think it has more to do with the reviewer not wanting to spank any of the products too badly.&nbsp; I have already asked for a clarification and will let you know what I find out.&nbsp; But being a slick marketing machine, I thought it the height of chutzpah that they would put out a release around this, considering the best buy and editors choice were two different products.&nbsp; But I guess that is why they did not have a quote or a link to the <a href="http://www.scmagazineus.com/ForeScout-Technologies-CounterACT/Review/2457/">actual review</a>.&nbsp; The review starts out with this memorable quote, “The ForeScout CounterACT was the device which took the most time to install and configure.”&nbsp; Later on the reviewers had this to say, “The second part of the configuration was far more difficult. The initial screens for the GUI made us feel lost and we immediately began looking for the documentation CD.”&nbsp; Now does that sound like a review to be touting?&nbsp; Only those master car salesman would seek to put out a press release trumpeting the results of this review.&nbsp; They are counting by wrapping enough other quotes (and frankly who knows about those) around it, no one will bother to dig into the facts here. Hey, thats what you guys pay me for, telling it like it is!</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=Vt7jr0"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=Vt7jr0" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BcRnNJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BcRnNJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JYqH5J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JYqH5J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=82rLAJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=82rLAJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=dMvV1J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=dMvV1J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BWbDPj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BWbDPj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2I5Scj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2I5Scj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/342141149" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 19:47:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/master car salesman">master car salesman</category>
      <category domain="http://securityratty.com/tag/car salesman">car salesman</category>
      <category domain="http://securityratty.com/tag/car sales guys">car sales guys</category>
      <category domain="http://securityratty.com/tag/nac device">nac device</category>
      <category domain="http://securityratty.com/tag/star">star</category>
      <category domain="http://securityratty.com/tag/star grade">star grade</category>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/products">products</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/342141149/when-is-4-out-o.html">When is 4 out of 5 stars is not 4 out of 5 stars or do I have a car for you!</source>
    </item>
    <item>
      <title><![CDATA[When is 4 out of 5 stars not 4 out of 5 stars or do I have a car for you!]]></title>
      <link>http://securityratty.com/article/c7f2260d59e070e01911cb7ea5ecaf69</link>
      <guid>http://securityratty.com/article/c7f2260d59e070e01911cb7ea5ecaf69</guid>
      <description><![CDATA[After my ??? used car salesman of NAC ??? series I was going to give Ray and the gang a break. But the depths they sink to just never cease to amaze me! Today I received a Google alert on NAC with a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>After my ???<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/the-used-car-sa.html">used car salesman of NAC</a>??? series I was going to give Ray and the gang a break.&nbsp; But the depths they sink to just never cease to amaze me! Today I received a Google alert on NAC with a <a href="http://www.sourcewire.com/releases/rel_display.php?relid=40444&amp;hilite=">link to a press release</a> announcing the NAC used car sales guys continuing to deliver best in class security management solutions, yada, yada, yada.&nbsp; The basis for this claim was that ???SC Magazine awarded ForeScout???s CounterACT a four-out-of-five star rating, lauding the product???s ability to ???function like a firewall, an IPS and a NAC device all rolled into one???.&nbsp; They wrapped some customer quote (that had nothing to do with the SC magazine story) and voila!, can they put you in this car today? </p>

<p>So why do I call this out? No, no sour grapes here.&nbsp; Actually StillSecure Safe Access received the same 4 out of 5 stars and when we dig into the rating here are some interesting facts:</p>

<p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/forescout.jpg"><img title="forescout" height="301" alt="forescout" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/forescout_thumb.jpg" width="197" border="0" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" /></a>&nbsp; <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/stillsecure%20sc%20mag_1.jpg"><img title="stillsecure sc mag" height="329" alt="stillsecure sc mag" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/stillsecure%20sc%20mag_thumb_1.jpg" width="195" border="0" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" /></a><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/slimy_salesguy_1.jpg"><img title="slimy_salesguy" height="240" alt="slimy_salesguy" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/slimy_salesguy_thumb_1.jpg" width="170" border="0" style="BORDER-RIGHT: 0px; BORDER-TOP: 0px; MARGIN: 0px 0px 0px 40px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px" /></a> </p>

<p>In actuality, our friends the used car salesmen only received a 2 star rating in ease of use, a 2 star rating in documentation and a 3 star rating in support.&nbsp; In contrast <a href="http://www.scmagazineus.com/StillSecure-Safe-Access/Review/2460/">StillSecure Safe Access</a> received 5 stars across the board, except for a 4 star grade in documentation.&nbsp; How both products finish up with a 4 star rating overall based upon this is frankly baffling to me. I think it has more to do with the reviewer not wanting to spank any of the products too badly.&nbsp; I have already asked for a clarification and will let you know what I find out.&nbsp; But being a slick marketing machine, I thought it the height of chutzpah that they would put out a release around this, considering the best buy and editors choice were two different products.&nbsp; But I guess that is why they did not have a quote or a link to the <a href="http://www.scmagazineus.com/ForeScout-Technologies-CounterACT/Review/2457/">actual review</a>.&nbsp; The review starts out with this memorable quote, ???The ForeScout CounterACT was the device which took the most time to install and configure.???&nbsp; Later on the reviewers had this to say, ???The second part of the configuration was far more difficult. The initial screens for the GUI made us feel lost and we immediately began looking for the documentation CD.???&nbsp; Now does that sound like a review to be touting?&nbsp; Only those master car salesman would seek to put out a press release trumpeting the results of this review.&nbsp; They are counting by wrapping enough other quotes (and frankly who knows about those) around it, no one will bother to dig into the facts here. Hey, thats what you guys pay me for, telling it like it is!</p></div>
]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 18:55:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/master car salesman">master car salesman</category>
      <category domain="http://securityratty.com/tag/car salesman">car salesman</category>
      <category domain="http://securityratty.com/tag/car sales guys">car sales guys</category>
      <category domain="http://securityratty.com/tag/star">star</category>
      <category domain="http://securityratty.com/tag/star grade">star grade</category>
      <category domain="http://securityratty.com/tag/nac device">nac device</category>
      <category domain="http://securityratty.com/tag/review">review</category>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/when-is-4-out-o.html">When is 4 out of 5 stars not 4 out of 5 stars or do I have a car for you!</source>
    </item>
    <item>
      <title><![CDATA[NAC vendors loading up fuel in the tank]]></title>
      <link>http://securityratty.com/article/f001c361adbb0d4afa3001e1e8042446</link>
      <guid>http://securityratty.com/article/f001c361adbb0d4afa3001e1e8042446</guid>
      <description><![CDATA[First it was Bradford Networks announcing they had raised another 8 million dollars in venture funding to help them break out beyond the edu market. Now comes word that Forescout has raised a like...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>First it was Bradford Networks <a href="http://www.networkworld.com/newsletters/vpn/2008/062308nac2.html">announcing</a> they had raised another 8 million dollars in venture funding to help them break out beyond the edu market. Now <a href="http://www.pehub.com/article/articledetail.php?articlepostid=13059">comes word</a> that Forescout has raised a like amount&nbsp; amount of additional capital. This was based upon a 80% growth rate for Forescout.&nbsp; This is well below the numbers I have seen Ray, Ken and Gordon throw about in interviews and at presentations.&nbsp; &nbsp;I guess you can spin all you want about how many customers you have or have won, but when it comes to raising cash, you can't play as <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/the-used-car-sa.html">fast and loose</a> as you do in your marketing.</p>

<p>Also this is a series E round for Forescout and brings their total raise to 44 million dollars.&nbsp; That makes for a tough number to make work.&nbsp; They need to roll some hard ways to make that bet pay off.&nbsp; I was led to understand they just raised 6 million last September.&nbsp; That makes 14 million in a little under a year.&nbsp; Can you spell big B-U-R-N.&nbsp; </p>

<p>The thing about both of these raises is that in the present market, just like the gas you put in your own tank, the gas these NAC vendors are putting in their tank is I am sure quite expensive!</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/466535e7-abd7-4096-8a5e-110f9bc56504/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=466535e7-abd7-4096-8a5e-110f9bc56504" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 09:09:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/million dollars">million dollars</category>
      <category domain="http://securityratty.com/tag/nac vendors">nac vendors</category>
      <category domain="http://securityratty.com/tag/tank">tank</category>
      <category domain="http://securityratty.com/tag/forescout">forescout</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/additional capital">additional capital</category>
      <category domain="http://securityratty.com/tag/gas">gas</category>
      <category domain="http://securityratty.com/tag/total raise">total raise</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/nac-vendors-loa.html">NAC vendors loading up fuel in the tank</source>
    </item>
    <item>
      <title><![CDATA[NAC vendors loading up fuel in the tank]]></title>
      <link>http://securityratty.com/article/4b38b013dc6b0d45330cbf5eb19a0c44</link>
      <guid>http://securityratty.com/article/4b38b013dc6b0d45330cbf5eb19a0c44</guid>
      <description><![CDATA[First it was Bradford Networks announcing they had raised another 8 million dollars in venture funding to help them break out beyond the edu market. Now comes word that Forescout has raised a like...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>First it was Bradford Networks <a href="http://www.networkworld.com/newsletters/vpn/2008/062308nac2.html">announcing</a> they had raised another 8 million dollars in venture funding to help them break out beyond the edu market. Now <a href="http://www.pehub.com/article/articledetail.php?articlepostid=13059">comes word</a> that Forescout has raised a like amount&nbsp; amount of additional capital. This was based upon a 80% growth rate for Forescout.&nbsp; This is well below the numbers I have seen Ray, Ken and Gordon throw about in interviews and at presentations.&nbsp; &nbsp;I guess you can spin all you want about how many customers you have or have won, but when it comes to raising cash, you can't play as <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/the-used-car-sa.html">fast and loose</a> as you do in your marketing.</p>

<p>Also this is a series E round for Forescout and brings their total raise to 44 million dollars.&nbsp; That makes for a tough number to make work.&nbsp; They need to roll some hard ways to make that bet pay off.&nbsp; I was led to understand they just raised 6 million last September.&nbsp; That makes 14 million in a little under a year.&nbsp; Can you spell big B-U-R-N.&nbsp; </p>

<p>The thing about both of these raises is that in the present market, just like the gas you put in your own tank, the gas these NAC vendors are putting in their tank is I am sure quite expensive!</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/466535e7-abd7-4096-8a5e-110f9bc56504/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=466535e7-abd7-4096-8a5e-110f9bc56504" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=7GG8Zf"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=7GG8Zf" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=83dswJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=83dswJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=eKzpjJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=eKzpjJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JstsVJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JstsVJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=1uC5UJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=1uC5UJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=vXgF6j"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=vXgF6j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=r2MOoj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=r2MOoj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/325042102" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 08:09:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/million dollars">million dollars</category>
      <category domain="http://securityratty.com/tag/nac vendors">nac vendors</category>
      <category domain="http://securityratty.com/tag/tank">tank</category>
      <category domain="http://securityratty.com/tag/forescout">forescout</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/additional capital">additional capital</category>
      <category domain="http://securityratty.com/tag/gas">gas</category>
      <category domain="http://securityratty.com/tag/total raise">total raise</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/325042102/nac-vendors-loa.html">NAC vendors loading up fuel in the tank</source>
    </item>
    <item>
      <title><![CDATA[The used car salesmen of NAC and the BNBB]]></title>
      <link>http://securityratty.com/article/cd36c880e9816f61480c0090b87f3fc4</link>
      <guid>http://securityratty.com/article/cd36c880e9816f61480c0090b87f3fc4</guid>
      <description><![CDATA[Few occupations have such a low reputation as used car salespeople. Well OK maybe lawyers ;-). For the most part though used car sales people are not really as bad as they are made out to be or...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/slimy_salesguy.jpg"><img height="240" alt="slimy_salesguy" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/slimy_salesguy_thumb.jpg" width="170" align="left" border="0" style="BORDER-TOP-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; MARGIN: 0px 10px 5px 0px; BORDER-RIGHT-WIDTH: 0px" /></a>Few occupations have such a low reputation as used car salespeople.&nbsp; Well OK maybe lawyers ;-).&nbsp; For the most part though used car sales people are not really as bad as they are made out to be or perhaps as bad as they used to be. Yes, there is the &quot;what do I have to do to put you in this car today&quot; attitude, but by and large - lemon laws, consumer protection rules and truth in advertising regs have taken some of the snake oil out of the fast and loose way of doing business which earned them their reputation.&nbsp; Who doesn't hear or read an ad today for cars without the &quot;fine print&quot; being mentioned.</p>

<p>In the world of NAC though we have no such protections built in it seems. It is very much &quot;caveat emptor&quot; - buyer beware.&nbsp; NAC companies can pretty much say what they want, claim what they will.&nbsp; How is a prospective customer supposed to know the truth?&nbsp; Some say you can check references, but even then much like someone applying for a job, do they ever give a reference who is not going say something nice about them? The easy answer of course is try it for yourself. There is no substitute for actually kicking the tires. </p>

<p>Here is another idea I was thinking about, I call it the Better NAC Business Bureau (BNBB).&nbsp; Its mission is to shine a spotlight on some of the dark alleys and rat holes that some NAC vendors do business in.&nbsp; The same way the used car salesmen of the world have been rehabilitated, lets do the same with NAC marketing!&nbsp; </p>

<p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/bnbb.gif"><img height="141" alt="bnbb" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/bnbb_thumb.gif" width="232" align="right" border="0" style="BORDER-TOP-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-RIGHT-WIDTH: 0px" /></a> With that in mind, the first investigation of the BNBB is in regard to some recent press releases from two NAC vendors.&nbsp; The first <a href="http://www.marketwire.com/mw/release.do?id=869105" target="_blank">press release is from StillSecure</a> and is in regard to Lehigh Valley Hospital and Health Center.&nbsp; It claims that LVHHC is and has been a NAC customer of StillSecure for the past two years and continues to be a customer.&nbsp; The press release has quotes from the CIO of LVHHC.&nbsp; The second <a href="http://www.forescout.com/press_releases/08-009.html" target="_blank">press release</a> and case study is from <a href="http://www.forescout.com/downloads/case_studies/FS-CS-Lehigh.pdf" target="_blank">NAC vendor X</a> .&nbsp; It also claims that LVHHC uses this companies product product for NAC throughout the entire organization.&nbsp; They also have a quote from someone at the organization (OK, not the CIO, but someone).&nbsp; Who to believe?&nbsp; Does LVHHC have two NAC solutions?&nbsp; I doubt it.&nbsp; What to do?&nbsp; </p>

<p>Well we can look at a little history.&nbsp; For instance which of these two NAC companies claimed they did not use Nessus in their NAC product and <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/07/if-you-have-to-.html" target="_blank">than it turned out they did</a>.&nbsp; What company took the infamous TCP reset and tried to peddle it as a &quot;virtual firewall&quot;.&nbsp; Of course there was the time they took out <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/09/security-lumina.html" target="_blank">Google ad words on my name</a>. Yes my friends, it seems that playing fast and loose with marketing claims has earned this company a bit of a used car salesman reputation. But like gas mileage, past performance is not controlling and your performance may vary. </p>

<p>So lets give this company the benefit of the doubt. Maybe in their burning desire to show reference customers they were a little to quick to pull the trigger here.&nbsp; Lets give them a chance to go back and check with their sources and see if they have the facts the straight.&nbsp; If they find out that perhaps they were mistaken about this customer using their product for NAC for over 20,000 users at LVHHC, lets give them a chance to retract or correct the press release and case study.&nbsp; At that the BNBB would close this file without any prejudice.&nbsp; Case closed, the BNBB does its job again. What do you think would be a reasonable time to do this?&nbsp; Two weeks? Three weeks? I'll tell you what, the BNBB is founded on fairness.&nbsp; Lets give them a month.&nbsp; </p>

<p>If after a month though they have not updated the case study and press release we will have a podcast here and we will delve into this further.&nbsp; We are going to find out what the NAC solution there is.&nbsp; Of course Forescout is invited to participate in the podcast and can even bring their own guests if they like.&nbsp; But at the end of the day, there is only one solution being used for NAC at LVHHC and we all are going to find out what that is.&nbsp; That hospital ain't big enough for the both of us! </p>

<p>If you would like to be involved in this podcast or the BNBB drop me a line at <a href="mailto:podcast@stillsecure.com">podcast@stillsecure.com</a></p></div>
]]></content:encoded>
      <pubDate>Mon, 16 Jun 2008 17:03:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/nac solution">nac solution</category>
      <category domain="http://securityratty.com/tag/nac solutions">nac solutions</category>
      <category domain="http://securityratty.com/tag/nac vendor">nac vendor</category>
      <category domain="http://securityratty.com/tag/nac companies">nac companies</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/prospective customer">prospective customer</category>
      <category domain="http://securityratty.com/tag/customer">customer</category>
      <category domain="http://securityratty.com/tag/companies product product">companies product product</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/the-used-car-sa.html">The used car salesmen of NAC and the BNBB</source>
    </item>
    <item>
      <title><![CDATA[The used car salesmen of NAC and the BNBB]]></title>
      <link>http://securityratty.com/article/936d718e5f37edc62b63f2e074ad307e</link>
      <guid>http://securityratty.com/article/936d718e5f37edc62b63f2e074ad307e</guid>
      <description><![CDATA[Few occupations have such a low reputation as used car salespeople. Well OK maybe lawyers ;-). For the most part though used car sales people are not really as bad as they are made out to be or...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/slimy_salesguy.jpg"><img height="240" alt="slimy_salesguy" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/slimy_salesguy_thumb.jpg" width="170" align="left" border="0" style="BORDER-TOP-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; MARGIN: 0px 10px 5px 0px; BORDER-RIGHT-WIDTH: 0px" /></a>Few occupations have such a low reputation as used car salespeople.&nbsp; Well OK maybe lawyers ;-).&nbsp; For the most part though used car sales people are not really as bad as they are made out to be or perhaps as bad as they used to be. Yes, there is the &quot;what do I have to do to put you in this car today&quot; attitude, but by and large - lemon laws, consumer protection rules and truth in advertising regs have taken some of the snake oil out of the fast and loose way of doing business which earned them their reputation.&nbsp; Who doesn't hear or read an ad today for cars without the &quot;fine print&quot; being mentioned.</p>

<p>In the world of NAC though we have no such protections built in it seems. It is very much &quot;caveat emptor&quot; - buyer beware.&nbsp; NAC companies can pretty much say what they want, claim what they will.&nbsp; How is a prospective customer supposed to know the truth?&nbsp; Some say you can check references, but even then much like someone applying for a job, do they ever give a reference who is not going say something nice about them? The easy answer of course is try it for yourself. There is no substitute for actually kicking the tires. </p>

<p>Here is another idea I was thinking about, I call it the Better NAC Business Bureau (BNBB).&nbsp; Its mission is to shine a spotlight on some of the dark alleys and rat holes that some NAC vendors do business in.&nbsp; The same way the used car salesmen of the world have been rehabilitated, lets do the same with NAC marketing!&nbsp; </p>

<p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/bnbb.gif"><img height="141" alt="bnbb" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/bnbb_thumb.gif" width="232" align="right" border="0" style="BORDER-TOP-WIDTH: 0px; BORDER-LEFT-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; BORDER-RIGHT-WIDTH: 0px" /></a> With that in mind, the first investigation of the BNBB is in regard to some recent press releases from two NAC vendors.&nbsp; The first <a href="http://www.marketwire.com/mw/release.do?id=869105" target="_blank">press release is from StillSecure</a> and is in regard to Lehigh Valley Hospital and Health Center.&nbsp; It claims that LVHHC is and has been a NAC customer of StillSecure for the past two years and continues to be a customer.&nbsp; The press release has quotes from the CIO of LVHHC.&nbsp; The second <a href="http://www.forescout.com/press_releases/08-009.html" target="_blank">press release</a> and case study is from <a href="http://www.forescout.com/downloads/case_studies/FS-CS-Lehigh.pdf" target="_blank">NAC vendor X</a> .&nbsp; It also claims that LVHHC uses this companies product product for NAC throughout the entire organization.&nbsp; They also have a quote from someone at the organization (OK, not the CIO, but someone).&nbsp; Who to believe?&nbsp; Does LVHHC have two NAC solutions?&nbsp; I doubt it.&nbsp; What to do?&nbsp; </p>

<p>Well we can look at a little history.&nbsp; For instance which of these two NAC companies claimed they did not use Nessus in their NAC product and <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/07/if-you-have-to-.html" target="_blank">than it turned out they did</a>.&nbsp; What company took the infamous TCP reset and tried to peddle it as a &quot;virtual firewall&quot;.&nbsp; Of course there was the time they took out <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2007/09/security-lumina.html" target="_blank">Google ad words on my name</a>. Yes my friends, it seems that playing fast and loose with marketing claims has earned this company a bit of a used car salesman reputation. But like gas mileage, past performance is not controlling and your performance may vary. </p>

<p>So lets give this company the benefit of the doubt. Maybe in their burning desire to show reference customers they were a little to quick to pull the trigger here.&nbsp; Lets give them a chance to go back and check with their sources and see if they have the facts the straight.&nbsp; If they find out that perhaps they were mistaken about this customer using their product for NAC for over 20,000 users at LVHHC, lets give them a chance to retract or correct the press release and case study.&nbsp; At that the BNBB would close this file without any prejudice.&nbsp; Case closed, the BNBB does its job again. What do you think would be a reasonable time to do this?&nbsp; Two weeks? Three weeks? I'll tell you what, the BNBB is founded on fairness.&nbsp; Lets give them a month.&nbsp; </p>

<p>If after a month though they have not updated the case study and press release we will have a podcast here and we will delve into this further.&nbsp; We are going to find out what the NAC solution there is.&nbsp; Of course Forescout is invited to participate in the podcast and can even bring their own guests if they like.&nbsp; But at the end of the day, there is only one solution being used for NAC at LVHHC and we all are going to find out what that is.&nbsp; That hospital ain't big enough for the both of us! </p>

<p>If you would like to be involved in this podcast or the BNBB drop me a line at <a href="mailto:podcast@stillsecure.com">podcast@stillsecure.com</a></p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=gEsoZj"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=gEsoZj" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=f2D1QI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=f2D1QI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=yI7JxI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=yI7JxI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=QBdPJI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=QBdPJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=snv2pI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=snv2pI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wDCPki"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wDCPki" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=LsHyKi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=LsHyKi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/313427070" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 16 Jun 2008 16:20:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/nac solution">nac solution</category>
      <category domain="http://securityratty.com/tag/nac solutions">nac solutions</category>
      <category domain="http://securityratty.com/tag/nac vendor">nac vendor</category>
      <category domain="http://securityratty.com/tag/nac companies">nac companies</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/prospective customer">prospective customer</category>
      <category domain="http://securityratty.com/tag/customer">customer</category>
      <category domain="http://securityratty.com/tag/companies product product">companies product product</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/313427070/the-used-car-sa.html">The used car salesmen of NAC and the BNBB</source>
    </item>
    <item>
      <title><![CDATA[Does this sound familiar?]]></title>
      <link>http://securityratty.com/article/01aec6c4f76072adc6f0dd4bc94a55bc</link>
      <guid>http://securityratty.com/article/01aec6c4f76072adc6f0dd4bc94a55bc</guid>
      <description><![CDATA[ForeScout Technologies Expands Buyback Program for Customers Looking to Replace Network Access Control Solutions

CUPERTINO, Calif., March 31 /PRNewswire/ -- ForeScout Technologies, the leading...]]></description>
      <content:encoded><![CDATA[<p><em><strong><a href="http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&amp;amp;STORY=/www/story/03-31-2008/0004782715&amp;amp;EDATE=">ForeScout Technologies Expands Buyback Program for Customers Looking to Replace Network Access Control Solutions</a><br></strong><br>CUPERTINO, Calif., <strong>March 31</strong> /PRNewswire/ -- ForeScout Technologies, the leading provider of clientless network access control (NAC) for Fortune 500 enterprises and government organizations, today announced an expansion of its Lockdown Networks buyback program to cover any qualified NAC product from competing vendors including Bradford Networks, Cisco, ConSentry Networks, Juniper Networks, StillSecure, Vernier Networks, and others. This comes after a week of partner requests to apply credit to other NAC products which have not satisfied customer needs in order to migrate to ForeScout's ....</em><br><br>Compared to this:<br><br><strong><a href="http://stillsecure.com/news_events/prdetails.php?id=418">StillSecure Offers Vernier Networks' Customers Dollar-for-Dollar competitive Upgrade on NAC</a>,<br>Competitive Upgrade Program Available to All NAC Customers Seeking a Stable NAC Vendor</strong> <br>(Superior, Colo. – <strong>January 11, 2008</strong>) – StillSecure®, provider of secure network infrastructure software, today announced a Competitive Upgrade program for NAC users that allows customers using products from Vernier Networks and others to easily migrate to StillSecure Safe Access®. The program offers a dollar-for-dollar trade-in up to $100,000 for previously purchased NAC software. Participating companies receive credit for every dollar spent on their current NAC solution, which is automatically applied to their purchase of the Safe Access NAC solution.<br><br>Notice the dates. Hey, you know what the say: Imitation is the sincerest form of flattery!</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=8ZQjcB"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=8ZQjcB" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=W2N1MBF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=W2N1MBF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=EoolZwF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=EoolZwF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=G2kqWgF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=G2kqWgF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Inx8ltF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Inx8ltF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Ge1UvTf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Ge1UvTf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=J5CAzMf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=J5CAzMf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/261654738" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 31 Mar 2008 17:01:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/nac users">nac users</category>
      <category domain="http://securityratty.com/tag/nac software">nac software</category>
      <category domain="http://securityratty.com/tag/nac customers">nac customers</category>
      <category domain="http://securityratty.com/tag/nac product">nac product</category>
      <category domain="http://securityratty.com/tag/nac products">nac products</category>
      <category domain="http://securityratty.com/tag/competitive upgrade program">competitive upgrade program</category>
      <category domain="http://securityratty.com/tag/stable nac vendor">stable nac vendor</category>
      <category domain="http://securityratty.com/tag/competitive upgrade">competitive upgrade</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/261654738/does-this-sound.html">Does this sound familiar?</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and ]]></title>
      <link>http://securityratty.com/article/865f0d1c531f4167af2702f1fd1e0d94</link>
      <guid>http://securityratty.com/article/865f0d1c531f4167af2702f1fd1e0d94</guid>
      <description><![CDATA[Synopsis: Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and more...  

<hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #68, a 46-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3" rel="enclosure">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p>
<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3&amp;bgcolor=#FFFFFF" /></object> </p> <p><strong>Show Content:</strong></p> 
<p><strong>Show Content:</strong></p> 

<p>	<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li><br />
<li>01:03 - Programming notes:<br />
<ul><li>New comment line &#8211; 206-350-7280</li><br />
<li>Slight web site changes</li><br />
<li>Books from Peter Thermos and Ari Takanen &#8211; anniversary show promotion</li></ul><br />
<li>03:27 - NetworkWorld: <a href="http://www.networkworld.com/news/2007/100107-voip-top-vulnerabilities.html">Top 14 VoIP Vulnerabilities</a> &#8211; and also <a href="http://www.networkworld.com/community/node/20120">this comment in reply</a></li><br />
<li>07:08 - blog.spywareguide.com: <a href="http://blog.spywareguide.com/2007/09/bubblesfor_kids.html">Bubbles&#8230; for Kids!</a>  (spyware that propagates via Skype IM)</li><br />
<li>09:25 - Voice of VoIPSA: <a href="http://voipsa.org/blog/2007/09/25/asterisk-what-would-your-security-roadmap-for-asterisk-be/">What would your security roadmap for Asterisk be?</a> and <a href="http://www.disruptivetelephony.com/2007/10/the-audacity-of.html">3Com to sell/support Asterisk</a></li><br />
<li>18:11 - Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/09/28/voip-hacker-goes-to-jail/">VoIP Hacker Goes to Jail</a> pointing to <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=202101781">Information Week interview with Robert Moore</a> which is similar to the <a href="http://www.thevoicereport.com/TelecomJunkiesArchive-VoIPHacker.html">Telecom Junkies interview</a> I did earlier with Robert Moore.</li><br />
<li>19:14 - Converge!Digest: <a href="http://www.convergedigest.com/bp/bp1.asp?ID=489&#38;ctgy=2">Defending the <span class="caps">IMS </span>Core</a> (sponsored by Sonus)</li><br />
<li>20:56 - Processor: <a href="http://www.processor.com/editorial/article.asp?article=articles/P2939/21p39/21p39.asp&#38;guid">Getting Tough with <span class="caps">P2P</span></a>= which relates to <a href="http://www.disruptivetelephony.com/2007/09/how-using-skype.html">Dan&#8217;s recent issues with using Skype at a hotel</a></li><br />
<li>26:36 - <span class="caps">PC </span>World: <a href="http://www.pcworld.com/businesscenter/article/137797/attack_of_the_killer_bots.html">Attack of the Killer Bots</a></li><br />
<li>28:57 - News Releases<ul><li><a href="http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&#38;STORY=/www/story/10-02-2007/0004674099&#38;EDATE">Sipera Secures $10 Million to Further Advance VoIP/UC Security</a>=</li><br />
<li><a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&#38;newsId=20071001005948&#38;newsLang=en">Bandwidth.com Bands with Acme Packet</a> (finally, security for <span class="caps">SIP</span> trunking!)</li><br />
<li><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/LNM00101102007-1.htm">Radware Unveils Industry First Behavioral Server Protections as Part of its Full Spectrum Protection Technology</a></li><br />
<li><a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&#38;newsId=20071001005119&#38;newsLang=en">Alcatel-Lucent Bolsters its Security Solutions in Worldwide Reseller Agreement with CloudShield Technologies</a></li><br />
<li><a href="http://www.tmcnet.com/comsol/articles/11625-clavister-announces-new-version-its-ip-based-security.htm">Clavister Announces New Version of its IP-Based Security Operating System</a>  (see also <a href="http://www.kauppalehti.fi/4/i/eng/releases/press_release.jsp?selected=other&#38;oid=20070901/11909837707310&#38;lang=EN">press release</a> )</li><br />
<li><a href="http://www.sourcewire.com/releases/rel_display.php?relid=34083&#38;hilite">ForeScout Continues Innovation Leadership with Latest Network Access Control Offering</a>=</li><br />
</ul><br />
<li>32:24 - <a href="http://www.crn.com/networking/202102837">3Com bought by Bain Capital, Huawei</a> </li><br />
<li>34:58 - <a href="http://www.disruptivetelephony.com/2007/10/ebay-pays-530-m.html">Skype <span class="caps">CEO</span> out, eBay takes $1.4 million charge</a></li><br />
<li>37:08 - <a href="http://news.google.com/news?hl=en&#38;ned=us&#38;q=nokia+navteq&#38;btnG=Search+News">Nokia to buy Navteq</a></li><br />
<li>38:26 - Vonage loses patent trial<br /></li><br />
<li>39:29 - Upcoming shows:<br /><ul> <br />
<li>Oct 24-25, New York, USA, <a href="http://www.interop.net/">Interop</a><br />
<li>Oct 29-Nov 1, Boston, <span class="caps">USA</span>, <a href="http://www.von.com/2007/fall_boston/">Fall 2007 <span class="caps">VON</span></a></li></ul> </li><br />
<li>39:58 - Comment (email) from Peter Thermos</li><br />
<li>42:15 - Comment (email) from Frank Leonhardt about Skype malware</li><br />
<li>42:24 - Comments (blog) <a href="http://www.blueboxpodcast.com/2007/08/blue-box-video-.html#comments">about video edition #1</a></li><br />
<li>42:51 - Brief commentary from Dan about using TalkPlus to call a <span class="caps">SIP URI</span> from a cell phone</li><br />
<li>45:39 - Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>46:00 - Wrap-up of the show <br /></li><br />
<li>46:51 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-206-350-7280 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=Uda19a"><img src="http://feeds.feedburner.com/~a/BlueBox?i=Uda19a" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=JGxhshf4"><img src="http://feeds.feedburner.com/~f/BlueBox?i=JGxhshf4" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=dnbU2EeA"><img src="http://feeds.feedburner.com/~f/BlueBox?i=dnbU2EeA" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=2bL8868d"><img src="http://feeds.feedburner.com/~f/BlueBox?i=2bL8868d" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=2zPj6l7R"><img src="http://feeds.feedburner.com/~f/BlueBox?i=2zPj6l7R" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=P6SgLmEN"><img src="http://feeds.feedburner.com/~f/BlueBox?i=P6SgLmEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Lj18nyY3"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Lj18nyY3" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/164629784" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sat, 27 Oct 2007 10:33:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/asterisk">asterisk</category>
      <category domain="http://securityratty.com/tag/asterisk security">asterisk security</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/sellsupport asterisk">sellsupport asterisk</category>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/listener comments">listener comments</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/164629784/synopsisblue-bo.html">Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and </source>
    </item>
    <item>
      <title><![CDATA[Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and ]]></title>
      <link>http://securityratty.com/article/dcb75f646e79c7aff03810543af541c8</link>
      <guid>http://securityratty.com/article/dcb75f646e79c7aff03810543af541c8</guid>
      <description><![CDATA[Synopsis: Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and more
Welcome to Blue Box: The VoIP...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and more...  

<hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #68, a 46-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3" rel="enclosure">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p> 

<p>You may also listen to this podcast right now:</p> 

<p>
<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://ripple.radiotail.com/409/BBP-068-2007-10-03.mp3&amp;bgcolor=#FFFFFF" /></object> </p> <p><strong>Show Content:</strong></p> 
<p><strong>Show Content:</strong></p> 

<p>	<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!&nbsp; </li><br />
<li>01:03 - Programming notes:<br />
<ul><li>New comment line &#8211; 206-350-7280</li><br />
<li>Slight web site changes</li><br />
<li>Books from Peter Thermos and Ari Takanen &#8211; anniversary show promotion</li></ul><br />
<li>03:27 - NetworkWorld: <a href="http://www.networkworld.com/news/2007/100107-voip-top-vulnerabilities.html">Top 14 VoIP Vulnerabilities</a> &#8211; and also <a href="http://www.networkworld.com/community/node/20120">this comment in reply</a></li><br />
<li>07:08 - blog.spywareguide.com: <a href="http://blog.spywareguide.com/2007/09/bubblesfor_kids.html">Bubbles&#8230; for Kids!</a>  (spyware that propagates via Skype IM)</li><br />
<li>09:25 - Voice of VoIPSA: <a href="http://voipsa.org/blog/2007/09/25/asterisk-what-would-your-security-roadmap-for-asterisk-be/">What would your security roadmap for Asterisk be?</a> and <a href="http://www.disruptivetelephony.com/2007/10/the-audacity-of.html">3Com to sell/support Asterisk</a></li><br />
<li>18:11 - Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2007/09/28/voip-hacker-goes-to-jail/">VoIP Hacker Goes to Jail</a> pointing to <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=202101781">Information Week interview with Robert Moore</a> which is similar to the <a href="http://www.thevoicereport.com/TelecomJunkiesArchive-VoIPHacker.html">Telecom Junkies interview</a> I did earlier with Robert Moore.</li><br />
<li>19:14 - Converge!Digest: <a href="http://www.convergedigest.com/bp/bp1.asp?ID=489&#38;ctgy=2">Defending the <span class="caps">IMS </span>Core</a> (sponsored by Sonus)</li><br />
<li>20:56 - Processor: <a href="http://www.processor.com/editorial/article.asp?article=articles/P2939/21p39/21p39.asp&#38;guid">Getting Tough with <span class="caps">P2P</span></a>= which relates to <a href="http://www.disruptivetelephony.com/2007/09/how-using-skype.html">Dan&#8217;s recent issues with using Skype at a hotel</a></li><br />
<li>26:36 - <span class="caps">PC </span>World: <a href="http://www.pcworld.com/businesscenter/article/137797/attack_of_the_killer_bots.html">Attack of the Killer Bots</a></li><br />
<li>28:57 - News Releases<ul><li><a href="http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=104&#38;STORY=/www/story/10-02-2007/0004674099&#38;EDATE">Sipera Secures $10 Million to Further Advance VoIP/UC Security</a>=</li><br />
<li><a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&#38;newsId=20071001005948&#38;newsLang=en">Bandwidth.com Bands with Acme Packet</a> (finally, security for <span class="caps">SIP</span> trunking!)</li><br />
<li><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/LNM00101102007-1.htm">Radware Unveils Industry First Behavioral Server Protections as Part of its Full Spectrum Protection Technology</a></li><br />
<li><a href="http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&#38;newsId=20071001005119&#38;newsLang=en">Alcatel-Lucent Bolsters its Security Solutions in Worldwide Reseller Agreement with CloudShield Technologies</a></li><br />
<li><a href="http://www.tmcnet.com/comsol/articles/11625-clavister-announces-new-version-its-ip-based-security.htm">Clavister Announces New Version of its IP-Based Security Operating System</a>  (see also <a href="http://www.kauppalehti.fi/4/i/eng/releases/press_release.jsp?selected=other&#38;oid=20070901/11909837707310&#38;lang=EN">press release</a> )</li><br />
<li><a href="http://www.sourcewire.com/releases/rel_display.php?relid=34083&#38;hilite">ForeScout Continues Innovation Leadership with Latest Network Access Control Offering</a>=</li><br />
</ul><br />
<li>32:24 - <a href="http://www.crn.com/networking/202102837">3Com bought by Bain Capital, Huawei</a> </li><br />
<li>34:58 - <a href="http://www.disruptivetelephony.com/2007/10/ebay-pays-530-m.html">Skype <span class="caps">CEO</span> out, eBay takes $1.4 million charge</a></li><br />
<li>37:08 - <a href="http://news.google.com/news?hl=en&#38;ned=us&#38;q=nokia+navteq&#38;btnG=Search+News">Nokia to buy Navteq</a></li><br />
<li>38:26 - Vonage loses patent trial<br /></li><br />
<li>39:29 - Upcoming shows:<br /><ul> <br />
<li>Oct 24-25, New York, USA, <a href="http://www.interop.net/">Interop</a><br />
<li>Oct 29-Nov 1, Boston, <span class="caps">USA</span>, <a href="http://www.von.com/2007/fall_boston/">Fall 2007 <span class="caps">VON</span></a></li></ul> </li><br />
<li>39:58 - Comment (email) from Peter Thermos</li><br />
<li>42:15 - Comment (email) from Frank Leonhardt about Skype malware</li><br />
<li>42:24 - Comments (blog) <a href="http://www.blueboxpodcast.com/2007/08/blue-box-video-.html#comments">about video edition #1</a></li><br />
<li>42:51 - Brief commentary from Dan about using TalkPlus to call a <span class="caps">SIP URI</span> from a cell phone</li><br />
<li>45:39 - Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>46:00 - Wrap-up of the show <br /></li><br />
<li>46:51 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-206-350-7280 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Wed, 03 Oct 2007 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/asterisk">asterisk</category>
      <category domain="http://securityratty.com/tag/asterisk security">asterisk security</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/sellsupport asterisk">sellsupport asterisk</category>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/listener comments">listener comments</category>
      <category domain="http://securityratty.com/tag/listener comment line">listener comment line</category>
      <source url="http://www.blueboxpodcast.com/2007/10/synopsisblue-bo.html">Blue Box #68: Top 14 VoIP Vulnerabilities, Asterisk security, VoIP hacker, IMS, P2P, Skype, industry moves, VoIP security news, listener comments and </source>
    </item>
  </channel>
</rss>
