<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: full-disk]]></title>
    <link>http://securityratty.com/tag/full-disk</link>
    <description></description>
    <pubDate>Tue, 18 Nov 2008 01:15:31 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[What is a Wise Risk Decision Worth? or ISO 27001 KPIs Follow Up]]></title>
      <link>http://securityratty.com/article/4c9a85007f78452901952cf859ffd96d</link>
      <guid>http://securityratty.com/article/4c9a85007f78452901952cf859ffd96d</guid>
      <description><![CDATA[So yesterday I asked readers to comment on thoughts I had that came from a question asked on the ISO 27001 Google Group
How I can communicate the value of an ISO implementation to non-security...]]></description>
      <content:encoded><![CDATA[<p>So yesterday I asked readers to comment on thoughts I had that came from a question asked on the ISO 27001 Google Group:</p>
<blockquote><p>&#8220;How I can communicate the value of an ISO implementation to non-security management?&#8221;</p></blockquote>
<p>This question came to me after one of the posters on the ISO Google Group asked about KPIs for ISO implementation.  Got great responses in <a href="http://riskmanagementinsight.com/riskanalysis/?p=525#comment-33917"><strong>email, blog comments</strong></a>, and on Twitter from current/former CISO folks and consultants and analysts.  Some really great thought and effort, by the way - <strong>thank you</strong>.  It&#8217;s really great to be able to have these sorts of conversations online.</p>
<p>First, I have to point out some resources Brian Honan linked to from Gary Hinson, just because they&#8217;re so cool.  Gary has invested gobs of time and effort to become one of the defacto resources on the ISO (you might also want to read or re-read <strong><a href="http://www.noticebored.com/html/metrics.html">Gary&#8217;s web post on the 7 myths of metrics</a></strong>).   Brian links to an <a href="http://www.iso27001security.com/ISO27k_implementation_guidance_1v1.pdf">implementation guidance document(pdf)</a> and a <a href="http://www.iso27001security.com/ISO27k_security_metrics_examples.pdf">metrics example(pdf)</a> document.</p>
<p>As full of awesomeness as they are, though, these are simply metrics &#8220;mapped&#8221; to the ISO (i.e. the ISO isn&#8217;t a pre-requisite for generating this information).  They are not KPI&#8217;s that express the value of ISO implementation.  Problem is the metrics created here still require some level of &#8220;translation&#8221; in order to create some value statement that data owners can understand.  As <strong><a href="http://www.myrcurial.com/">Myrcurial</a></strong> twittered me &#8220;<span class="entry-content">27001 is orthoganal to process&#8221; meaning (I hope) that metrics have their foundation in events that are generated by processes.  27001 by itself was never meant to create metrics (see above), and so we&#8217;re asking a question the ISO can&#8217;t answer.  But the desire, the need to measure still exists.  To that extent we can google &#8220;ISO compliance&#8221; (whatever that means) and if something can be certifiable or deemed &#8220;compliant&#8221; we can and are &#8220;measuring&#8221;.  But does that have value?</span> Rybolov (<strong><a href="http://www.guerilla-ciso.com/">my favorite Guerilla CISO</a></strong>) wrote:</p>
<blockquote><p><em>&#8220;Whatever you do, don’t start measuring percentage of compliance. Eventually, that’s what all metrics efforts around a framework devolve into.&#8221;</em></p></blockquote>
<p>I have to agree.  Being ISO &#8220;compliant/certified&#8221; has little expressive business value <em>prima facia</em>. I find that one KPI that absolutely asserts value when expressed properly is risk - and similarly  <strong><a href="http://layer8.itsecuritygeek.com//layer8">Shrdlu</a></strong> wrote:</p>
<blockquote><p><em>&#8220;I really have no idea. I personally wouldn’t try to justify an ISO implementation by itself. If I could show traceability on how it affected our overall security risk, then that’s what I’d do.&#8221;</em></p></blockquote>
<p>And that&#8217;s a delightful answer.  That &#8220;traceability&#8221; (geeze-louise Shrdlu - what a word!) is absolutely what I&#8217;m after here.  How do I get that?  <span class="entry-content"> </span></p>
<p><span class="entry-content">If you&#8217;re going to do something with corporate budget (time, money - and goodness knows an ISO implementation is time &amp; money) you better be able to communicate the value.  And while the zealotry for ISO implementation differs from person to person, I have yet to come across someone who says that ISO adoption is totally without value.  It&#8217;s just not apparent what that value of adoption is and how we can measure (metrics) and express it (KPIs).<br />
</span></p>
<p>Jenean Paschalidis wrote what he thought that value was in a very nice email in which he puts a qualitative name on the value of adoption:</p>
<blockquote><p><em>&#8220;Transparency and accountability-this is what all executive/senior management (the company) is on the hook for. ISO provides that. If you want to understand and have confidence in your operations as supported by security (because you will know the who, what, where, when, why and how of a system (human, technical etc.) and you want to be able to trace back why a decision (risk-vetted) had been made - then adoption of this best international practice will assist in providing these answers.&#8221;</em></p></blockquote>
<p>So working with our above thoughts a little here - if we agree with Shrdlu that the only value of an ISO implementation can only be expressed if we can say how said implementation affected our overall security risk - and we agree with Jenean that the primary benefit is an ability to have confidence in operations as supported by security, then&#8230;.</p>
<p><em><strong>The value of the ISO should be expressed as a KPI or set of KPIs that cleary explain how the confidence it generates helps us understand (and then reduce) our risk. </strong></em></p>
<p>If risk is a probability issue,  ISO adoption helps generate confidence in our predictive analytics.  The dollar value the ISO generates (the ultimate KPI) is part of the cost of being able to make wise risk decisions.</p>
<p style="text-align: center;"><strong><span style="color: #ff0000;">So what is that (making wise risk decisions) worth to you?</span></strong></p>
<p style="text-align: center;">
<p><strong><span style="color: #003300;">SOME CONCLUDING THOUGHTS</span></strong><em><span style="color: #003300;"><br />
</span></em></p>
<p>First, it occurs to me that this is a real shame.  In a sense, an inability to generate a quantitative value statement for ISO use is simply more witch-doctory (<em>&#8220;use it because we, the wise men of the tribe say you should&#8221;</em>).  In some future version, the ISO should include some mechanism for measuring and expressing the worth of adoption to the organization (a better reason to use the ISO than &#8220;because we said so&#8221;).</p>
<p><span style="color: #003300;">Second, It should be noted that of Jack Jones&#8217; 3 true value statements from which all metrics/KPIs should point to - we&#8217;re only talking about one of those value statements - the ability to reduce risk.  Using the ISO in an organization most certainly could create operational efficiencies (help us do more with less) - but the ISO isn&#8217;t a standard that creates operational efficiencies as a primary goal, nor does it give implicit direction on how to create operational efficincies.    The ISO folks do, however, play fast and loose with the idea of &#8220;risk&#8221; and &#8220;risk management&#8221; so it&#8217;s within this context that I interpreted our conversation.</span></p>
<p>Finally if you&#8217;re going to hire someone to help you with ISO adoption in your organization, the deliverables you ask for in your RFP/SOW/what-have-you should include quantitative (probability) statments about risk reduction and the creation of operational efficiencies.  If the firms answering can&#8217;t tell you what value their work will be to your company, then drop me a note and I&#8217;ll gladly point you to some friends of RMI&#8217;s that know FAIR &amp; all our Risk Management frameworks and also do great ISO work.</p>
]]></content:encoded>
      <pubDate>Wed, 03 Dec 2008 12:47:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iso">iso</category>
      <category domain="http://securityratty.com/tag/iso google">iso google</category>
      <category domain="http://securityratty.com/tag/iso adoption">iso adoption</category>
      <category domain="http://securityratty.com/tag/iso implementation">iso implementation</category>
      <category domain="http://securityratty.com/tag/iso folks">iso folks</category>
      <category domain="http://securityratty.com/tag/iso adoption helps">iso adoption helps</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/google iso compliance">google iso compliance</category>
      <category domain="http://securityratty.com/tag/iso implementation differs">iso implementation differs</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=527">What is a Wise Risk Decision Worth? or ISO 27001 KPIs Follow Up</source>
    </item>
    <item>
      <title><![CDATA[The "A"]]></title>
      <link>http://securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</link>
      <guid>http://securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</guid>
      <description><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here

Generally, most people in Information...]]></description>
      <content:encoded><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here.<br /><br />Generally, most people in Information Security today did not start out as pure Information Security people, they evolved. And where they evolved from gives one a clue as to their mindset and how they see themselves.<br /><br />Some come from an Audit background and you'll recognise these guys from their love of lists and frameworks - they dream of Cobit controls and little boxes that are waiting for ticks. Somehow they have tons of documentation and they know it all and can find it all. They generally drive Volvo's and like order.<br /><br />But most InfoSec guys come from an IT background and it shows. I guess that, having said that, most hackers come from an IT background too. And it shows.<br /><br />Now, lets consider the C-I-A triangle thingum. Quick lesson for those who don't know it - there are three aspects of information that Information Security wishes to preserve - the <span style="font-weight: bold;">C</span>onfidentiality, the <span style="font-weight: bold;">I</span>ntegrity and the <span style="font-weight: bold;">A</span>vailability. From my experience, most IT people are governed by Availability - the "A". In fact, when an IT contract is drawn up - there is no SLI or SLC but there will always be an SLA. With very specific terms, measurements and penalties.<br /><br />If the Firewall crashes and has to be rebuilt. What will the IT manager be most interested in? The A - how fast can you get the traffic moving again?<br /><br />So we have tools to measure uptime in 99.999999999999999s and such and anything that can cause network downtime (or if the network is up and the services such as mail are down - same difference) is taken care of. Spam, worms, viruses etc.<br /><br />I guess that hackers (those that define what we do) are also IT background people. They seem to be more concerned with big-bang, widely deployed DoS attacks and stealing IT resources. At least, they used to be, until they discovered that they could make money from stealing information. Actually, I may be naive but I don't believe that the hackers we have today are the same as those we had in the past... I believe that we have a new generation of hackers - criminals who merely use the Internet to steal money because that it where the money is easiest to steal.<br /><br />The problem is that we were lucky in a way that our old tools worked against the threats that we had - firewalls, antiviruses, etc etc. They don't work against people breaking into our networks and stealing information. For that we need a new generation of Information Security people (or the old generation to update their game)...<br /><br />Here is a quick poll to see which generation you are in:<br /><br />1. What is the one piece of information on your network that your competitors would love to see?<br />2. What is the percentage of mails coming into your network that are spam?<br />3. What mail is going to competitors?<br />4. What is the process for someone to order a pencil?<br />5. What is a blog?<br />6. Who in your organisation uses facebook for business?<br />7. How many of your PCs have up-to-date antivirus?<br />8. What is the worst virus out at the moment?<br />9. Do you believe that your Firewall is configured correctly?<br /><br />The answers are as follows:<br />1. This is ESSENTIAL to know if you want to be in the next generation. And you can't guess this. You may think that it is something financial but most financial information can be guessed by your competitors anyhow. You may think it is a recipe or special way of doing something but any established company has had their recipe ripped off anyhow and can beat any new competitor by competitive pricing. It may be new product information. It may be staff information. It may be the CEO's contact list. Don't guess - find out.<br /><br />2. Who cares? Certainly not the CEO. Maybe the CIO. "We are saving you x amount of bandwidth and your users x amount of time" is nice but won't save the business from closing down due to data loss. Operationalise this and get on with your job.<br /><br />3. Good to know. I'm sure that if you told your CEO/CIO "Last week we detected 5 large emails going to our competitors from inside our R&amp;D department" you'd have his full attention.<br /><br />4. Good to know. Who does the ordering? Who does the okaying? Who does the paying? If you know all of this then you know how business works. And when things go wrong - you'll be able to help.<br /><br />5. And do you want your staff to use them? And if they do, what can they put on them? What are they puting on them?<br /><br />6. This is an interesting question because Facebook is usually an issue of "The A" (productivity). But it can be an issue of C and I.<br /><br />7. Who cares? Again, this is an operational issue. Viruses that jump onto your radar are usually ones that attack "the A" but its the ones that are pushing information out of your organisation that are sneaky enough not to have sgnatures and not to be discovered. You will have PCs without up-to-date antivirus and you will have viruses. The trick is not to let your information be stolen by viruses. Also, keep backups so if a PC does get wiped out - you can get the information back again (but this is an operational issue again).<br /><br />8. Trick question - the answer is - the one you don't know about. Old generation InfoSec guys can rattle off names of viruses that are all in the top 10 at the moment.. New generation viruses are targetted and usually do their worst before a pattern is out.<br /><br />9. Old generation answer - yes. New generation answer - who cares? Information flows all over including in and out of the Firewall. Firewalls also usually rely on port security but most everything runs on port 80 anyhow so the Firewall should be configured but it doesn't kep us safe - more work needs to be done for that.<br /><br />I find that it is not very easy to move from old generation to new generation InfoSec. The main difference is that old generation was very technical and appealed to the technical nature of computer geeks. The new generation is business oriented and requires more interaction with people, more meetings, more time with people. Ouch.<br /><br />There will always be a place for technical people in Information Security but as the tools mature and "just work" there is less demand. And a background in technology is very useful when the technical guys try to "BS" you.<br /><br />And "the A" is very important too. Protecting your network from being brought down. Protecting information from disappearing. Stopping viruses. Etc. But the new generation will need to consider "the I" and "the C" as well because the attacks against these and the importance of protecting information against disclosure or manipulation will increase.<br /><br />This post was done to add my voice to what Rich says so quickly and concisely in the <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">securosis blog</a>.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/471338550" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 10:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/generation infosec guys">generation infosec guys</category>
      <category domain="http://securityratty.com/tag/infosec guys">infosec guys</category>
      <category domain="http://securityratty.com/tag/information security people">information security people</category>
      <category domain="http://securityratty.com/tag/guys">guys</category>
      <category domain="http://securityratty.com/tag/staff information">staff information</category>
      <category domain="http://securityratty.com/tag/technical guys">technical guys</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/471338550/a.html">The "A"</source>
    </item>
    <item>
      <title><![CDATA[Blurring the Lines Between Managed Service Provider and Cloud Computing]]></title>
      <link>http://securityratty.com/article/23238e9889824f8ebd65b8a0149c5f4a</link>
      <guid>http://securityratty.com/article/23238e9889824f8ebd65b8a0149c5f4a</guid>
      <description><![CDATA[VMware made big announcements at their VMworld conference back in September, talking about adding on a slew of virtualization management functionality to a revamped vCenter and extending into the...]]></description>
      <content:encoded><![CDATA[<p>VMware made big announcements at their <a href="http://www.vmworld.com/index.jspa" target="_blank">VMworld conference</a> back in September, talking about adding on a slew of virtualization management functionality to a revamped vCenter and extending into the “cloud” with vCloud services. Like most people, I had a lot of skepticism about what vCloud really meant; was this just more hype trying to take advantage of the cloud computing buzz? Certainly CEO Paul Maritz came from this world and virtualization itself (and especially vMotion) is an enabling technology for cloud computing. But how ready were VMware and its ecosystem of partner vendors to actually fulfill on the promise?</p>
<p>So I was very interested when I heard that <a href="http://opusinteractive.com/" target="_blank">Opus Interactive</a>, a customer of ours, had “joined the VMware vCloud initiative as a <a href="http://www.opusinteractive.com/news_detail.asp?item=40" target="_blank">VMware Service Provider</a>”. I talked to Eric Hulbert, CTO of Opus Interactive, to get some details directly from the source.</p>
<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0025.jpg" border="0" alt="clip_image002" width="202" height="74" align="left" /></p>
<p>Eric shared our own caution about making “cloud-ready” announcements. There have simply been too many companies talking about cloud solutions that lack any substance – usually based on definitions of cloud computing that are hazy or just too broad. The backlash against the cloud hype is often quite justified. But in Opus’ case, there are real components that if they don’t add up to a “full” cloud computing solution just yet, are well on their way – and enabled by <a href="http://www.vmware.com/partners/vip/service-providers/" target="_blank">VMware’s program for service providers</a> (VSPP).</p>
<p>Opus Interactive is <a href="http://www.viddler.com/explore/sciencelogic/videos/3" target="_blank">serious about virtualization</a>, which is an indispensable tool in their stated goal of creating a high-density micro-data center with the smallest footprint possible. They are 100% wind-powered and have already virtualized much of their data center, reducing the amount of hardware necessary to run the business and driving down costs to produce even more competitive advantage in a crowded marketplace.</p>
<p>VSPP for vCloud provides a rental model of VMware licenses – e.g., for Enterprise ESX or VDI. VMware Service Providers report on their customers’ virtual machines (vm) and pay only for what is actually used. This model lets Opus Interactive quickly spin up a vm to get a new customer up and running in about an hour and stay very cost competitive at the same time; Opus offers their <a href="http://opusinteractive.com/vClustr.asp" target="_blank">vClustr entry-level virtual server</a> for only $99.</p>
<p>Cost-effective, rapidly scalable computing “on-demand” based on shared resources, managed by “expert” third-parties, enabled by virtualization technology and pay-per-use vm licenses. Cloud computing? Instead of thinking about a single definition of cloud computing, perhaps it’s more relevant as the market matures to think about a continuum of cloud computing. And by that definition, Opus Interactive is providing cloud services, enabled by VMware’s VSP program. Next on the schedule, automated provisioning and perhaps in the future, API’s that make it even easier for application developers to test and deploy apps on Opus Interactive’s cloud platform – which, by the way, uses <a href="http://www.sciencelogic.com/products.htm" target="_blank">EM7</a> for its core management solution.</p>
]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 11:20:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud hype">cloud hype</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/cloud-ready announcements">cloud-ready announcements</category>
      <category domain="http://securityratty.com/tag/cloud solutions">cloud solutions</category>
      <category domain="http://securityratty.com/tag/announcements">announcements</category>
      <category domain="http://securityratty.com/tag/vmware vcloud initiative">vmware vcloud initiative</category>
      <category domain="http://securityratty.com/tag/ready">ready</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <source url="http://blog.sciencelogic.com/blurring-the-lines-between-managed-service-provider-and-cloud-computing/11/2008">Blurring the Lines Between Managed Service Provider and Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[Arkansas Couple Sues McDonalds for Using Private Nude Photos in Online Ads]]></title>
      <link>http://securityratty.com/article/51fc8263d6d9f3cfbdbd51da0e6e8237</link>
      <guid>http://securityratty.com/article/51fc8263d6d9f3cfbdbd51da0e6e8237</guid>
      <description><![CDATA[When an Arkansas couple visited a local McDonalds in June, they got more than just their favorite burger. The couple apparently left their cell phone at the store, and even though it was returned,...]]></description>
      <content:encoded><![CDATA[<p>When an Arkansas couple visited a local McDonald&#8217;s in June, they got more than just their favorite burger. The couple apparently left their cell phone at the store, and even though it was returned, their personal information had already been compromised&#8211;and put online along with nude photos:</p>
<blockquote><p>Staff promised to keep the phone safely until [the couple came to retrieve it].</p>
<p>However, after Philip Sherman retrieved the phone, his wife began receiving threatening calls and messages from strangers. This caused the Shermans’ to become suspicious about what had occurred with the phone.</p>
<p>Soon afterward the Shermans’ found the private photos that Tina Sherman had sent to her husband’s phone published on the Internet along with their names, address, and phone numbers. Pictures of Tina Sherman were altered to contain McDonald’s franchise logos, along with slogans such as, “I’m lovin’ it,” and “Hot as McDonald’s coffee.” The photos were located on several different sites online, but have since been removed.</p></blockquote>
<p>The Shermans are suing for over 3 million dollars in damages, along with relocation costs.</p>
<p>Read the <a rel="nofollow" target="_blank" href="http://www.ecanadanow.com/news/curiosity/couple-to-sue-mcdonalds-after-racy-photo-stolen-20081125.html">full article</a> here.</p>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 09:38:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/arkansas couple">arkansas couple</category>
      <category domain="http://securityratty.com/tag/couple">couple</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/nude photos">nude photos</category>
      <category domain="http://securityratty.com/tag/photos">photos</category>
      <category domain="http://securityratty.com/tag/phone safely">phone safely</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/husbands phone">husbands phone</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/465465087/">Arkansas Couple Sues McDonalds for Using Private Nude Photos in Online Ads</source>
    </item>
    <item>
      <title><![CDATA[Localizing Cybercrime - Cultural Diversity on Demand Part Two]]></title>
      <link>http://securityratty.com/article/6fa5c311a11504a21120c6a907e03041</link>
      <guid>http://securityratty.com/article/6fa5c311a11504a21120c6a907e03041</guid>
      <description><![CDATA[It's where you advertise your services, and how you position yourself that speak for your intentions, of course, &quot;between the lines&quot;. There's a common misunderstanding that in order for a malware...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SSv52TmaA2I/AAAAAAAACec/W3ErlbR-fSo/s1600-h/translation_service_cybercrime.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SSv52TmaA2I/AAAAAAAACec/W3ErlbR-fSo/s200/translation_service_cybercrime.JPG" /></a> It's where you advertise your services, and how you position yourself that speak for your intentions, of course, "between the lines". There's a common misunderstanding that in order for a malware campaigner or scammer to launch a localized attack speaking the native language of their potential victims, they need to speak the local language. This misconception is largely based on the fact that a huge number of people remain unaware on how core strategic business practices have been in operation across the cybercrime underground for the last couple of years.<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Outsourcing the localization process</a> (translation services for spam/phishing/malware campaigns) has been happening for a while, courtsy of DIY servics ensuring complete anonymity of their customers. Interestingly, the translators may in fact be unaware that the advertising channels the service is using is directly attracting everyone from the bottom to the top of the cybercriminal food chain as a customer. Sometimes, it's services like this that open a new market segment covering an untapped opportunity, with this particular service already pointing out that it's charging cheaper than their competitors.<br />
<br />
"<i>We offer our services in translation. We are only competent translators profile higher education. Service is working with all types of texts. Languages available at this time of Russian, English, German. Average translation of the text takes up to 10 hours (usually much faster) through the full automation of the order and payment. <b>Just want to note that we do not keep any logs on IP and does not require registration</b>. In addition you can remove your order from the database after his execution. In addition to running more than 1000 translations already, we can use all the lessons learned to be more effective in our services. Prices vary depending on the complexity of the topic covered.</i><br />
<br />
<i><b>Prices and deadlines:  </b><br />
* Standard - the deadline is not more than 24 hours. Prices depend on the direction and guidance from the 'Order'.&nbsp;</i><br />
<i>* Term - work on your translation begins precedence. The price of the 50% more than the standard translation. Prices also depend on the direction and guidance from the 'Order'. <br />
<br />
The cost of the transfer depends on the amount of work. The workload is measured in symbols. In calculating the characters are shown letters and numbers. Punctuation do not count. Minimum order 100 characters.</i>"<br />
<br />
I'm particularly curious how is a contractor(translator) going to react to a situation when a large scale malware campaign speaking several different languages tell a fake story that the contractor might have recently translated for them. With the employer positioning itself as a fully legitimate company, whereas its customers requesting localized version of texts for the spam/phishing/malware campaigns are the "usual suspects", the contractors would continue allowing cybercriminals the opportunity to build more authenticity within their campaigns.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">A Localized Bankers Malware Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/lonely-polinas-secret.html">Lonely Polina's Secret</a> (Localized malware campaign)<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jtrxN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jtrxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MlKUN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MlKUN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x6kTn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x6kTn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NtZ5n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NtZ5n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=11AEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=11AEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KL4TN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KL4TN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BB2Un"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BB2Un" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/465119206" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 05:55:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/translation">translation</category>
      <category domain="http://securityratty.com/tag/standard translation">standard translation</category>
      <category domain="http://securityratty.com/tag/average translation">average translation</category>
      <category domain="http://securityratty.com/tag/translation services">translation services</category>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/bankers malware campaign">bankers malware campaign</category>
      <category domain="http://securityratty.com/tag/prices">prices</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/prices vary">prices vary</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/465119206/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand Part Two</source>
    </item>
    <item>
      <title><![CDATA[ Here Comes Everybody Review]]></title>
      <link>http://securityratty.com/article/639cf7107fd08bc70488e1f27a8ec2a3</link>
      <guid>http://securityratty.com/article/639cf7107fd08bc70488e1f27a8ec2a3</guid>
      <description><![CDATA[In 1937, Ronald Coase answered one of the most perplexing questions in economics: if markets are so great, why do organizations exist? Why don't people just buy and sell their own services in a market...]]></description>
      <content:encoded><![CDATA[<p>In 1937, Ronald Coase answered one of the most perplexing questions in economics: if markets are so great, why do organizations exist? Why don't people just buy and sell their own services in a market instead? Coase, who won the 1991 Nobel Prize in Economics, answered the question by noting a market's transaction costs: buyers and sellers need to find one another, then reach agreement, and so on. The Coase theorem implies that if these transaction costs are low enough, direct markets of individuals make a whole lot of sense. But if they are too high, it makes more sense to get the job done by an organization that hires people. </p>

<p>Economists have long understood the corollary concept of Coase's ceiling, a point above which organizations collapse under their own weight -- where hiring someone, however competent, means more work for everyone else than the new hire contributes. Software projects often bump their heads against Coase's ceiling: recall Frederick P. Brooks Jr.'s seminal study, <cite>The Mythical Man-Month</cite> (Addison-Wesley, 1975), which showed how adding another person onto a project can slow progress and increase errors. </p>

<p>What's new is something consultant and social technologist Clay Shirky calls &quot;Coase's Floor,&quot; below which we find projects and activities that aren't worth their organizational costs -- things so esoteric, so frivolous, so nonsensical, or just so thoroughly unimportant that no organization, large or small, would ever bother with them. Things that you shake your head at when you see them and think, &quot;That's ridiculous.&quot;</p>

<p>Sounds a lot like the Internet, doesn't it? And that's precisely Shirky's point. His new book, <a href="http://www.amazon.com/exec/obidos/ASIN/1594201536/counterpane/"><cite>Here Comes Everybody: The Power of Organizing Without Organizations</cite></a>, explores a world where organizational costs are close to zero and where ad hoc, loosely connected groups of unpaid amateurs can create an encyclopedia larger than the Britannica and a computer operating system to challenge Microsoft's. </p>

<p>Shirky teaches at New York University's Interactive Telecommunications Program, but this is no academic book. Sacrificing rigor for readability, <cite>Here Comes Everybody</cite> is an entertaining as well as informative romp through some of the Internet's signal moments -- the Howard Dean phenomenon, Belarusian protests organized on LiveJournal, the lost cellphone of a woman named Ivanna, Meetup.com, flash mobs, Twitter, and more -- which Shirky uses to illustrate his points. </p>

<p>The book is filled with bits of insight and common sense, explaining why young people take better advantage of social tools, how the Internet affects social change, and how most Internet discourse falls somewhere between dinnertime conversation and publishing. </p>

<p>Shirky notes that &quot;most user-generated content isn't 'content' at all, in the sense of being created for general consumption, any more than a phone call between you and a sibling is 'family-generated content.' Most of what gets created on any given day is just the ordinary stuff of life -- gossip, little updates, thinking out loud -- but now it's done in the same medium as professionally produced material. Unlike professionally produced material, however, Internet content can be organized after the fact.&quot; </p>

<p>No one coordinates Flickr's 6 million to 8 million users. Yet Flickr had the first photos from the 2005 London Transport bombings, beating the traditional news media. Why? People with cellphone cameras uploaded their photos to Flickr. They coordinated themselves using tools that Flickr provides. This is the sort of impromptu organization the Internet is ideally suited for. Shirky explains how these moments are harbingers of a future that can self-organize without formal hierarchies. </p>

<p>These nonorganizations allow for contributions from a wider group of people. A newspaper has to pay someone to take photos; it can't be bothered to hire someone to stand around London underground stations waiting for a major event. Similarly, Microsoft has to pay a programmer full time, and <cite>Encyclopedia Britannica</cite> has to pay someone to write articles. But Flickr can make use of a person with just one photo to contribute, Linux can harness the work of a programmer with little time, and Wikipedia benefits if someone corrects just a single typo. These aggregations of millions of actions that were previously below the Coasean floor have enormous potential. </p>

<p>But a flash mob is still a mob. In a world where the Coasean floor is at ground level, all sorts of organizations appear, including ones you might not like: violent political organizations, hate groups, Holocaust deniers, and so on. (Shirky's discussion of teen anorexia support groups makes for very disturbing reading.) This has considerable implications for security, both online and off. </p>

<p>We never realized how much our security could be attributed to distance and inconvenience -- how difficult it is to recruit, organize, coordinate, and communicate without formal organizations. That inadvertent measure of security is now gone. Bad guys, from hacker groups to terrorist groups, will use the same ad hoc organizational technologies that the rest of us do. And while there has been some success in closing down individual Web pages, discussion groups, and blogs, these are just stopgap measures. </p>

<p>In the end, a virtual community is still a community, and it needs to be treated as such. And just as the best way to keep a neighborhood safe is for a policeman to walk around it, the best way to keep a virtual community safe is to have a virtual police presence. </p>

<p>Crime isn't the only danger; there is also isolation. If people can segregate themselves in ever-increasingly specialized groups, then they're less likely to be exposed to alternative ideas. We see a mild form of this in the current political trend of rival political parties having their own news sources, their own narratives, and their own facts. Increased radicalization is another danger lurking below the Coasean floor. </p>

<p>There's no going back, though. We've all figured out that the Internet makes freedom of speech a much harder right to take away. As Shirky demonstrates, Web 2.0 is having the same effect on freedom of assembly. The consequences of this won't be fully seen for years. </p>

<p><cite>Here Comes Everybody</cite> covers some of the same ground as Yochai Benkler's <cite>Wealth of Networks</cite>. But when I had to explain to one of my corporate attorneys how the Internet has changed the nature of public discourse, Shirky's book is the one I recommended.</p>

<p>This essay <a href="http://www.spectrum.ieee.org/sep08/6631">previously appeared</a> in <i>IEEE Spectrum</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=wZmPN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=wZmPN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xDcAN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xDcAN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 04:39:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/shirky">shirky</category>
      <category domain="http://securityratty.com/tag/shirky notes">shirky notes</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/virtual community safe">virtual community safe</category>
      <category domain="http://securityratty.com/tag/organizations collapse">organizations collapse</category>
      <category domain="http://securityratty.com/tag/internet content">internet content</category>
      <category domain="http://securityratty.com/tag/internet discourse falls">internet discourse falls</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/here_comes_ever.html"> Here Comes Everybody Review</source>
    </item>
    <item>
      <title><![CDATA[Raffys Visualization Book]]></title>
      <link>http://securityratty.com/article/f4265f82839e3f66c8b6b3a78d7fa468</link>
      <guid>http://securityratty.com/article/f4265f82839e3f66c8b6b3a78d7fa468</guid>
      <description><![CDATA[Here is my long-overdue book review for Applied Security Visualization by Raffy Marty
First, here is what my early endorsement for the book said (can be found on the inside cover of the book
Amazingly...]]></description>
      <content:encoded><![CDATA[<p>Here is my long-overdue book review for <a href="http://www.amazon.com/Applied-Security-Visualization-Raffael-Marty/dp/0321510100">“Applied Security Visualization“&#160; by Raffy Marty</a>.</p>  <p>First, here is what my early endorsement for the book said (can be found on the inside cover of the book):</p>  <p>“Amazingly useful (and fun to read!) book that does justice to this&#160; somewhat esoteric subject - and this is coming from a long-time&#160; visualization skeptic! What is most impressive that&#160; this book is&#160; actually 'hands-on-useful,&quot; not conceptual, with examples usable by&#160; readers in their daily jobs. Chapter 8 on insiders is my favorite!”</p>  <p>What else do I think of the book, apart from the fact that it is awesome? :-)</p>  <p>First, I have to admit that I used to argue with Raffy about usefulness of visualization. I was burned by having to look at bad “visualization” tools and would take <em>an ugly, meaningful table over an ugly, meaningless picture</em> any day now. Thus, I was a visualization skeptic. Buy you know what? The book does justice to visualization really well, and it explains when to use it and when not to use it.</p>  <p>The book gives just the right amount of visualization theory, which is not onerous to read at all (unlike some other books), as well as other visualization basics. The fun starts at Chapter 4, where he covers&#160; the process from data to useful pictures. This actually explains why some visualization are useful and some are not; if you just jam data into a graphing program, there is a good chance that it would not be too useful. If you follow the ideas from Ch4, it is more likely to be useful.</p>  <p>Ch5 and 6 cover network data analysis: logs, packets, flows. This is what most people usually try to visualize; this book goes beyond “worms and scans” into nice visuals of email traffic, wireless and even vulnerability data (I found the latter slightly confusing). Ch7 covers “compliance”, which, in this case, covers all sorts of fun things, from risk assessment to database log visualization.&#160; As I said, Ch8 is my favorite: I agree that insider tracking MAY be the area where visualization tools and approaches beat others. In Ch9, the book covers a few visualization tools; obviously, including the author’s AfterGlow.</p>  <p>So, to summarize, get the book if you have any connection to security AND data analysis. In fact, it is very likely that if you are doing security, you’d have to do data analysis at some point and so will benefit from reading the book. And, yes, it does come with a CD full of visualization tools (DAVIX).</p>  <p>BTW, I am posting it <a href="http://www.amazon.com/Applied-Security-Visualization-Raffael-Marty/dp/0321510100">at Amazon</a> as well.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wgwyN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wgwyN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ADZPN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ADZPN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=N8CKN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=N8CKN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/460098463" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 11:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visualization">visualization</category>
      <category domain="http://securityratty.com/tag/visualization tools">visualization tools</category>
      <category domain="http://securityratty.com/tag/bad visualization tools">bad visualization tools</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/database log visualization">database log visualization</category>
      <category domain="http://securityratty.com/tag/security visualization">security visualization</category>
      <category domain="http://securityratty.com/tag/long-time visualization skeptic">long-time visualization skeptic</category>
      <category domain="http://securityratty.com/tag/long-overdue book review">long-overdue book review</category>
      <category domain="http://securityratty.com/tag/book covers">book covers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/460098463/raffys-visualization-book.html">Raffys Visualization Book</source>
    </item>
    <item>
      <title><![CDATA[Political Changes for IP Law and Technology]]></title>
      <link>http://securityratty.com/article/8d0c726dee223a40ed7b7097c568283e</link>
      <guid>http://securityratty.com/article/8d0c726dee223a40ed7b7097c568283e</guid>
      <description><![CDATA[Naturally with the economic turmoil and political transition, some changes are in the works for the way technology is governed on a Federal level
For one thing, the House Judiciarys Subcommittee on...]]></description>
      <content:encoded><![CDATA[<p>Naturally with the economic turmoil and political transition, some changes are in the works for the way technology is governed on a Federal level:</p>
<p>For one thing, the House Judiciary&#8217;s Subcommittee on the Internet, Courts and IP will be losing its control over IP Law, which will be handled at the <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081117-internet-ip-legislation-gets-promoted-to-house-big-leagues.html">full House level </a>in the future:</p>
<blockquote><p>According to a committee aide who spoke with Ars on background, the decision was driven by simple numbers: as interest in IP issues has grown in recent years, so has the SCIIP. Handling them at the full committee level allows all the members to get their fingers in the pie. The swap also recognizes the complexity of legislation affecting IP, and avoids the need to get half the Judiciary Committee caught up with the subcommittee&#8217;s discussions.</p></blockquote>
<p>Instead the Subcommittee will reign over anti-trust issues&#8211;some fear that this will be a victory for content holders, while other experts argue the fears are unfounded.</p>
<p>What other changes are in the works, and who will play the largest role in determining the future of technology law? Well, if you have some ideas, you can nominate yourself or other people for Ars Technica&#8217;s &#8220;<a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081118-whos-top-in-tech-policy-our-new-people-to-watch-list.html">People to Watch</a>&#8221; list.</p>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 08:48:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/ars technicas people">ars technicas people</category>
      <category domain="http://securityratty.com/tag/ars">ars</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/subcommittee">subcommittee</category>
      <category domain="http://securityratty.com/tag/house judiciarys subcommittee">house judiciarys subcommittee</category>
      <category domain="http://securityratty.com/tag/technology law">technology law</category>
      <category domain="http://securityratty.com/tag/anti-trust issuessome fear">anti-trust issuessome fear</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/458756012/">Political Changes for IP Law and Technology</source>
    </item>
    <item>
      <title><![CDATA[Skein and SHA-3 News]]></title>
      <link>http://securityratty.com/article/cc81d2d4853466933826ebdeeef07d52</link>
      <guid>http://securityratty.com/article/cc81d2d4853466933826ebdeeef07d52</guid>
      <description><![CDATA[There are two bugs in the Skein code. They are subtle and esoteric, but they're there. We have revised both the reference and optimized code -- and provided new test vectors -- on the Skein website ....]]></description>
      <content:encoded><![CDATA[<p>There are two bugs in the Skein code.  They are subtle and esoteric, but they're there.  We have revised both the reference and optimized code -- and provided new test vectors -- on the <a href="http://www.schneier.com/skein.html">Skein website</a>.  A <a href="http://www.schneier.com/skein.pdf">revision of the paper</a> -- Version 1.1 -- has new IVs, new test vectors, and also fixes a few typos in the paper.</p>

<blockquote>Errata: Version 1.1 of the paper, reference, and optimized code corrects an error in which the length of the configuration string was passed in as the size of the internal block (256 bits for Skein-256, 512 for Skein-512, and 1024 for Skein-1024), instead of a constant 256 bits for all three sizes.  This error has no cryptographic significance, but affected the test vectors and the initialization values.  The revised code also fixes a bug in the MAC mode key processing.  This bug does not affect the NIST submission in any way.</blockquote>

<p><a href="http://csrc.nist.gov/groups/ST/hash/sha-3/index.html">NIST has received</a> 64 submissions.  (<a href="http://www.cio.com/article/461164/Amateurs_and_Pros_Vie_to_Build_New_Crypto_Standard">This article</a> interviews one of the submitters, who is fifteen.)  Of those, <a href="http://ehash.iaik.tugraz.at/wiki/The_SHA-3_Zoo">28 are public</a> and six have been broken.  NIST is going through the submissions right now, making sure they are complete and proper.  Their goal is to publish the accepted submissions by the end of the month, in advance of the <a href="http://csrc.nist.gov/groups/ST/hash/timeline.html">Third Cryptographic Hash Workshop</a> to be held in Belgium right after <a href="https://www.cosic.esat.kuleuven.be/fse2009/index.shtml">FSE</a> in February.  They expect to quickly make a first cut of algorithms -- hopefully to about a dozen -- and then give the community about a year of cryptanalysis before making a second cut in 2010.</p>

<p>Lastly, <a href="http://www.darkreading.com/blog/archives/2008/11/bending_skein_c.html">this</a> is a really nice article on Skein.</p>

<blockquote>These submissions make some accommodation to the Core 2 processor. They operate in "<a href="http://en.wikipedia.org/wiki/Little_endian" target="new">little-endian</a>" mode (a quirk of the <a href="http://en.wikipedia.org/wiki/X86" target="new">Intel-like processors</a> that reads some bytes in reverse order). They also allow a large file to be broken into chunks to split the work across multiple processors.

<p>However, virtually all of the contest submissions share the performance problem mentioned above. The logic they use won't optimally fit within the constraints of a Intel Core 2 processor. Most will perform as bad or worse than the existing SHA-1 algorithm.</p>

<p>One exception to this is <a href="http://www.schneier.com/skein.html" target="new">Skein</a>, created by several well-known cryptographers and noted pundit <a href="http://www.schneier.com/" target="new">Bruce Schneier</a>. It was designed specifically to exploit all three of the Core 2 execution units and to run at a full 64-bits. This gives it roughly four to 10 times the logic density of competing submissions.</p>

<p>This is what I meant by the <i><a href="http://www.imdb.com/title/tt0133093/" target="new">Matrix</a></i> quote above. They didn't bend the spoon; they bent the crypto algorithm. They moved the logic operations around in a way that wouldn't weaken the crypto, but would strengthen its speed on the Intel Core 2.</p>

<p>In their <a href="http://www.schneier.com/skein.pdf" target="new">paper</a> (PDF), the authors of Skein express surprise that a custom silicon <a href="http://en.wikipedia.org/wiki/Application-specific_integrated_circuit" target="new">ASIC</a> implementation is not any faster than the software implementation. They shouldn't be surprised. Every time you can redefine a problem to run optimally in software, you will reach the same speeds you get with optimized ASIC hardware. The reason software has a reputation of being slow is because people don't redefine the original problem.</blockquote></p>

<p>That's exactly what we were trying to do.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=98JTN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=98JTN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=diffN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=diffN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 03:14:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skein">skein</category>
      <category domain="http://securityratty.com/tag/skein-1024">skein-1024</category>
      <category domain="http://securityratty.com/tag/skein-512">skein-512</category>
      <category domain="http://securityratty.com/tag/skein express surprise">skein express surprise</category>
      <category domain="http://securityratty.com/tag/skein website">skein website</category>
      <category domain="http://securityratty.com/tag/skein code">skein code</category>
      <category domain="http://securityratty.com/tag/submissions share">submissions share</category>
      <category domain="http://securityratty.com/tag/submissions">submissions</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/skein_and_sha-3.html">Skein and SHA-3 News</source>
    </item>
    <item>
      <title><![CDATA[CISSPs Lend me your ears]]></title>
      <link>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</link>
      <guid>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</guid>
      <description><![CDATA[Art of Information Security endorses Dan Houser for(ISC)²Board of Directors
The CISSP isundoubtablyone of the most, if not the most, important professional certifications in Information Security....]]></description>
      <content:encoded><![CDATA[<p><strong>Art of Information Security endorses Dan Houser for (ISC)² Board of Directors</strong></p>
<p>The CISSP is undoubtably one of the most, if not the most, important professional certifications in Information Security. Many organizations and practitioners rely on it as evidence of a solid foundation and track record in Information Security. But the CISSP is only one of the many ways that the (ISC)² attempts to fulfill its mission of developing the Information Security profession.</p>
<p>Board membership is a role of governance, guidance, and passion. Let&#8217;s briefly explore how Dan&#8217;s track record and past contributions demonstrate his qualification for this post, and possibly your vote.</p>
<p><strong>Passion</strong></p>
<p>Dan is someone who has a passion for promoting and developing the talent needed to continue to grow and mature our profession. Anyone who has seen Dan speak at conferences, local chapter meetings, or in one of his classes knows how passionate Dan is! But anyone who takes the time to approach him knows that he is no ideologue or zealot; Dan is always interested in improving his own understanding, and then sharing that knowledge with others.</p>
<p>Dan has a long track record as a contributor - as a &#8220;giver&#8221; - to the profession. In addition to teaching over a dozen CISSP review courses, he has also served on multiple (ISC)² committees, is one of the authors of the ISSAP Body of Knowledge (cryptography), and has published primary research on professional certifications. He is also the founder of the monthly Columbus, Ohio Information Security MBA (Masters of Beer Appreciation) meeting - a professional roundtable that attracts practitioners from across the state.</p>
<p><strong>Governance and Guidance <br />
</strong></p>
<p>In addition to past experience serving on (ISC)² committees, which I assume led to the current board&#8217;s nomination, Dan has served on numerous Boards of Directors including local and regional community organizations, ISSA chapters,and several Toastmasters clubs. </p>
<p><strong>Personal Experiences</strong></p>
<p>I have known Dan for almost three yeas. Dan and I have collaborated on a number or projects, including a half-day Cryptographic Controls Seminar and a full-day Identity Management Architecture class. It is my feeling that when you collaborate, work closely, and travel with someone, you really get to know them. You get to do more than hear about their College Sweethearts (which, for Dan, is Rebecca, his wife of 21 years), but you also get to understand their ethics, how they really conduct themselves, how they deal with stress, etc.</p>
<p>Given the entire picture, the understanding that I have of Dan Houser, I can think of no one better suited to representing, guiding and developing the (ISC)². I have voted for Dan, and I hope that you will consider doing the same.</p>
<p>Here is the voting link for (ISC)²: <a href="https://webportal.isc2.org/custom/votenow.aspx%20" onclick="javascript:pageTracker._trackPageview('/outbound/article/https://webportal.isc2.org/custom/votenow.aspx%20');" target="_blank">https://webportal.isc2.org/custom/votenow.aspx</a></p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/105/cissps-lend-me-your-ears/" >CISSPs&#8230; Lend me your ears&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/456765137" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 01:15:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dan">dan</category>
      <category domain="http://securityratty.com/tag/dan houser">dan houser</category>
      <category domain="http://securityratty.com/tag/dan foralmostthree yeas">dan foralmostthree yeas</category>
      <category domain="http://securityratty.com/tag/dans track record">dans track record</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/track record">track record</category>
      <category domain="http://securityratty.com/tag/information security profession">information security profession</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/profession">profession</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/456765137/">CISSPs Lend me your ears</source>
    </item>
  </channel>
</rss>
