<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: game]]></title>
    <link>http://securityratty.com/tag/game</link>
    <description></description>
    <pubDate>Tue, 21 Oct 2008 09:57:48 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The "A"]]></title>
      <link>http://securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</link>
      <guid>http://securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</guid>
      <description><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here

Generally, most people in Information...]]></description>
      <content:encoded><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here.<br /><br />Generally, most people in Information Security today did not start out as pure Information Security people, they evolved. And where they evolved from gives one a clue as to their mindset and how they see themselves.<br /><br />Some come from an Audit background and you'll recognise these guys from their love of lists and frameworks - they dream of Cobit controls and little boxes that are waiting for ticks. Somehow they have tons of documentation and they know it all and can find it all. They generally drive Volvo's and like order.<br /><br />But most InfoSec guys come from an IT background and it shows. I guess that, having said that, most hackers come from an IT background too. And it shows.<br /><br />Now, lets consider the C-I-A triangle thingum. Quick lesson for those who don't know it - there are three aspects of information that Information Security wishes to preserve - the <span style="font-weight: bold;">C</span>onfidentiality, the <span style="font-weight: bold;">I</span>ntegrity and the <span style="font-weight: bold;">A</span>vailability. From my experience, most IT people are governed by Availability - the "A". In fact, when an IT contract is drawn up - there is no SLI or SLC but there will always be an SLA. With very specific terms, measurements and penalties.<br /><br />If the Firewall crashes and has to be rebuilt. What will the IT manager be most interested in? The A - how fast can you get the traffic moving again?<br /><br />So we have tools to measure uptime in 99.999999999999999s and such and anything that can cause network downtime (or if the network is up and the services such as mail are down - same difference) is taken care of. Spam, worms, viruses etc.<br /><br />I guess that hackers (those that define what we do) are also IT background people. They seem to be more concerned with big-bang, widely deployed DoS attacks and stealing IT resources. At least, they used to be, until they discovered that they could make money from stealing information. Actually, I may be naive but I don't believe that the hackers we have today are the same as those we had in the past... I believe that we have a new generation of hackers - criminals who merely use the Internet to steal money because that it where the money is easiest to steal.<br /><br />The problem is that we were lucky in a way that our old tools worked against the threats that we had - firewalls, antiviruses, etc etc. They don't work against people breaking into our networks and stealing information. For that we need a new generation of Information Security people (or the old generation to update their game)...<br /><br />Here is a quick poll to see which generation you are in:<br /><br />1. What is the one piece of information on your network that your competitors would love to see?<br />2. What is the percentage of mails coming into your network that are spam?<br />3. What mail is going to competitors?<br />4. What is the process for someone to order a pencil?<br />5. What is a blog?<br />6. Who in your organisation uses facebook for business?<br />7. How many of your PCs have up-to-date antivirus?<br />8. What is the worst virus out at the moment?<br />9. Do you believe that your Firewall is configured correctly?<br /><br />The answers are as follows:<br />1. This is ESSENTIAL to know if you want to be in the next generation. And you can't guess this. You may think that it is something financial but most financial information can be guessed by your competitors anyhow. You may think it is a recipe or special way of doing something but any established company has had their recipe ripped off anyhow and can beat any new competitor by competitive pricing. It may be new product information. It may be staff information. It may be the CEO's contact list. Don't guess - find out.<br /><br />2. Who cares? Certainly not the CEO. Maybe the CIO. "We are saving you x amount of bandwidth and your users x amount of time" is nice but won't save the business from closing down due to data loss. Operationalise this and get on with your job.<br /><br />3. Good to know. I'm sure that if you told your CEO/CIO "Last week we detected 5 large emails going to our competitors from inside our R&amp;D department" you'd have his full attention.<br /><br />4. Good to know. Who does the ordering? Who does the okaying? Who does the paying? If you know all of this then you know how business works. And when things go wrong - you'll be able to help.<br /><br />5. And do you want your staff to use them? And if they do, what can they put on them? What are they puting on them?<br /><br />6. This is an interesting question because Facebook is usually an issue of "The A" (productivity). But it can be an issue of C and I.<br /><br />7. Who cares? Again, this is an operational issue. Viruses that jump onto your radar are usually ones that attack "the A" but its the ones that are pushing information out of your organisation that are sneaky enough not to have sgnatures and not to be discovered. You will have PCs without up-to-date antivirus and you will have viruses. The trick is not to let your information be stolen by viruses. Also, keep backups so if a PC does get wiped out - you can get the information back again (but this is an operational issue again).<br /><br />8. Trick question - the answer is - the one you don't know about. Old generation InfoSec guys can rattle off names of viruses that are all in the top 10 at the moment.. New generation viruses are targetted and usually do their worst before a pattern is out.<br /><br />9. Old generation answer - yes. New generation answer - who cares? Information flows all over including in and out of the Firewall. Firewalls also usually rely on port security but most everything runs on port 80 anyhow so the Firewall should be configured but it doesn't kep us safe - more work needs to be done for that.<br /><br />I find that it is not very easy to move from old generation to new generation InfoSec. The main difference is that old generation was very technical and appealed to the technical nature of computer geeks. The new generation is business oriented and requires more interaction with people, more meetings, more time with people. Ouch.<br /><br />There will always be a place for technical people in Information Security but as the tools mature and "just work" there is less demand. And a background in technology is very useful when the technical guys try to "BS" you.<br /><br />And "the A" is very important too. Protecting your network from being brought down. Protecting information from disappearing. Stopping viruses. Etc. But the new generation will need to consider "the I" and "the C" as well because the attacks against these and the importance of protecting information against disclosure or manipulation will increase.<br /><br />This post was done to add my voice to what Rich says so quickly and concisely in the <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">securosis blog</a>.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/471338550" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 10:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/generation infosec guys">generation infosec guys</category>
      <category domain="http://securityratty.com/tag/infosec guys">infosec guys</category>
      <category domain="http://securityratty.com/tag/information security people">information security people</category>
      <category domain="http://securityratty.com/tag/guys">guys</category>
      <category domain="http://securityratty.com/tag/staff information">staff information</category>
      <category domain="http://securityratty.com/tag/technical guys">technical guys</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/471338550/a.html">The "A"</source>
    </item>
    <item>
      <title><![CDATA[Schneier for TSA Administrator]]></title>
      <link>http://securityratty.com/article/5e368a8d3abaf29420cf0da59287f1d2</link>
      <guid>http://securityratty.com/article/5e368a8d3abaf29420cf0da59287f1d2</guid>
      <description><![CDATA[It's been suggested . For the record, I don't want the job. Since the election, the newspapers and Internet have been flooded with unsolicited advice for President-elect Barack Obama. I'll go ahead...]]></description>
      <content:encoded><![CDATA[<p>It's been <a href="http://www.foxnews.com/story/0,2933,453093,00.html">suggested</a>. For the record, I don't want the job.</p>

<blockquote>Since the election, the newspapers and Internet have been flooded with unsolicited advice for President-elect Barack Obama. I'll go ahead and add mine.

<p>[...]</p>

<p>And by "revamp," I mean "start over." Most security experts agree that the rigmarole we go through at the airport is mere security theater, designed not to make us safer, but to make us feel safer by making it increasingly inconvenient to fly. TSA's approach to security is too reactionary -- too set on preventing attacks and attempted attacks that have already happened. And please, whatever you do, resist the temptation to let TSA workers unionize. Security from terror attacks should be a federal jobs program. You need the authority to fire underperforming screeners quickly and effortlessly. Three game-changing possibilities to head up TSA: security guru Bruce Schneier, Cato Institute security and technology scholar Jim Harper, or Ohio State University's John Mueller.</blockquote></p>

<p>Although I'd be happy to see either Jim or John with it.</p>

<p>I don't want it because it's too narrow.  I think the right thing for the government to do is to give the TSA a lot less money.  I'd rather they defend against the broad threat of terrorism than focus on the narrow threat of airplane terrorism, and I'd rather they defend against the myriad of threats that face our society than focus on the singular threat of terrorism.  But the head of the TSA can't have those opinions; he has to take the money he's given and perform the specific function he's assigned to perform.  Not very much fun, really.</p>

<p>But I'd be happy to advise whoever Obama choses to head the TSA.</p>

<p>The job of the nation's CTO would be more interesting, but I don't think I <a href="http://weblog.infoworld.com/robertxcringely/archives/2008/11/the_once_and_fu.html">want</a> <a href="http://blogs.computerworld.com/obama_cto">it</a>, either.  (Have you seen the <a href="http://www.nytimes.com/2008/11/13/us/politics/13apply.html">screening process</a>?)</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=lxRoN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=lxRoN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=doEjN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=doEjN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 10:46:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tsa">tsa</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/mere security theater">mere security theater</category>
      <category domain="http://securityratty.com/tag/cato institute security">cato institute security</category>
      <category domain="http://securityratty.com/tag/tsa workers">tsa workers</category>
      <category domain="http://securityratty.com/tag/security experts agree">security experts agree</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/terror attacks">terror attacks</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/schneier_for_ts.html">Schneier for TSA Administrator</source>
    </item>
    <item>
      <title><![CDATA[AVG does the right thing]]></title>
      <link>http://securityratty.com/article/a55f0b98170ac94a9e869e1e416a1a54</link>
      <guid>http://securityratty.com/article/a55f0b98170ac94a9e869e1e416a1a54</guid>
      <description><![CDATA[Although I still believe AVG was careless with their recent release, I respect their willingness to put &quot;some skin in the...]]></description>
      <content:encoded><![CDATA[Although I still believe AVG was careless with their recent release, I respect their willingness to put "some skin in the game."]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 05:14:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/avg">avg</category>
      <category domain="http://securityratty.com/tag/recent release">recent release</category>
      <category domain="http://securityratty.com/tag/skin">skin</category>
      <category domain="http://securityratty.com/tag/willingness">willingness</category>
      <category domain="http://securityratty.com/tag/respect">respect</category>
      <category domain="http://securityratty.com/tag/game">game</category>
      <category domain="http://securityratty.com/tag/careless">careless</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/avg-does-the-right-thing-28300">AVG does the right thing</source>
    </item>
    <item>
      <title><![CDATA[AVG does the right thing (Updated)]]></title>
      <link>http://securityratty.com/article/5bc6d6bdeb342d410b140b8c5032c5ff</link>
      <guid>http://securityratty.com/article/5bc6d6bdeb342d410b140b8c5032c5ff</guid>
      <description><![CDATA[Although I still believe AVG was careless with their recent release, I respect their willingness to put &quot;some skin in the...]]></description>
      <content:encoded><![CDATA[Although I still believe AVG was careless with their recent release, I respect their willingness to put "some skin in the game."]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 05:14:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/avg">avg</category>
      <category domain="http://securityratty.com/tag/recent release">recent release</category>
      <category domain="http://securityratty.com/tag/skin">skin</category>
      <category domain="http://securityratty.com/tag/willingness">willingness</category>
      <category domain="http://securityratty.com/tag/respect">respect</category>
      <category domain="http://securityratty.com/tag/game">game</category>
      <category domain="http://securityratty.com/tag/careless">careless</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/avg-does-the-right-thing-updated-28300">AVG does the right thing (Updated)</source>
    </item>
    <item>
      <title><![CDATA[What is the best way to find a P.I.?]]></title>
      <link>http://securityratty.com/article/bb16c0a3d53b183cada5d6e7ad1483d5</link>
      <guid>http://securityratty.com/article/bb16c0a3d53b183cada5d6e7ad1483d5</guid>
      <description><![CDATA[Where would you find a good P.I.? Should you even settle for good? Wouldn't it make more sense to find a great one? PInow.com Investigation news gave some useful pointers in their editorial yesterday...]]></description>
      <content:encoded><![CDATA[Where would you find a good P.I.?  Should you even settle for good?  Wouldn't it make more sense to find a great one?  <a href="http://www.pinow.com/news/2008/11/12/pis-weigh-in-on-hiring-pis/#comment-19525">PInow.com Investigation news </a>gave some useful pointers in their editorial yesterday.<br /><span id="fullpost"><br />I decided to write about this after seeing a request on a local listserve.  I wrote and advised the person that it would be difficult to judge the quality of the investigator by such a general posting.  To my amazement, the reply came back; "I know...some time I just post the job, close my eyes and hope for the best".<br /></span><br />Hope for the best? Surely nobody would say such a thing to their client when they are getting that retainer.  I can understand "hoping" for the weekend to be dry if you are having a picnic, or "hoping" that your football team wins the game on Sunday...but "hoping" an investigator does a decent job? <br /><br />One of the better and more professional way to find a reputable investigator or investigaive agency, is to contact a local State association such as <a href="http://www.piava.org/">PIAVA (www.piava.org</a>), or an international association such as the <a href="http://www.cii2.org/">Council of International Investigators (www.cii2.org). </a>Members of these associations have not only been carefully vetted, but they are held accountable since their professional reputations are riding on every assignment.<br /><br />Good investigators can help your attorny win that child custody case, save the company from a false suit by an unethical employee claiming a make believe injury, help you find the fraudster that ran off with the company's clients or funds and  many other useful tasks.  A bad one can take your money and give you next to nothing in return.  <br /><br />Please make sure you only ever hire the good ones.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 02:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/investigator">investigator</category>
      <category domain="http://securityratty.com/tag/reputable investigator">reputable investigator</category>
      <category domain="http://securityratty.com/tag/decent job">decent job</category>
      <category domain="http://securityratty.com/tag/international association">international association</category>
      <category domain="http://securityratty.com/tag/local listserve">local listserve</category>
      <category domain="http://securityratty.com/tag/local">local</category>
      <category domain="http://securityratty.com/tag/association">association</category>
      <category domain="http://securityratty.com/tag/professional">professional</category>
      <category domain="http://securityratty.com/tag/football team wins">football team wins</category>
      <source url="http://www.thebulletproofblog.com/2008/11/what-is-best-way-to-find-pi.html">What is the best way to find a P.I.?</source>
    </item>
    <item>
      <title><![CDATA[Show 032 - An Interview with Jeremiah Grossman]]></title>
      <link>http://securityratty.com/article/b0449f2ccd72f29ee2665301bb7c2d9e</link>
      <guid>http://securityratty.com/article/b0449f2ccd72f29ee2665301bb7c2d9e</guid>
      <description><![CDATA[The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman. Gary and Jeremiah discuss clickjacking, cross-site request...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Jeremiah Grossman" title="Jeremiah Grossman" src="http://www.cigital.com/silverbullet/jgrossman-125.png" style="padding-left: 7px;" /></p>
<p>The 32nd episode of The Silver Bullet Security Podcast features founder and Chief Technology Officer of WhiteHat Security, Jeremiah Grossman.  Gary and Jeremiah discuss clickjacking, cross-site request forgery, why 50% of web problems can&#8217;t be discovered reliably automatically, and which conferences Jeremiah most enjoyed on his 2008 world tour.</p>
<ul>
<li><a href="http://jeremiahgrossman.blogspot.com/">Jeremiah Grossman</a></li>
<li><a href="http://jeremiahgrossman.blogspot.com/2008/10/clickjacking-web-pages-can-see-and-hear.html">Clickjacking</a></li>
<li><a href="http://www.webadminblog.com/index.php/2008/09/24/new-0day-browser-exploit-clickjacking-owasp-appsec-nyc-2008/">Adobe 0-day Browser Exploit</a></li>
<li><a href="http://www.freedom-to-tinker.com/sites/default/files/csrf.pdf">Cross-Site Request Forgeries: Exploitation and Prevention</a> [PDF]</li>
<li><a href="http://www.cs.princeton.edu/sip/pub/spoofing.php3">Web Spoofing: An Internet Con Game</a> by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach.</li>
<li><a href="http://jeremiahgrossman.blogspot.com/2007/05/web-application-scan-o-meter.html">Web application scan-o-meter</a></li>
<li><a href="http://1.bp.blogspot.com/_JdybrokZBAk/SO_rUc-ebPI/AAAAAAAABOY/dKbFPJfv1Cs/s1600-h/badgewall.jpg">The &#8220;Wall of Fame&#8221;</a></li>
</ul>
<p></p>
]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 23:17:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/jeremiah grossman">jeremiah grossman</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/web application scan-o-meter">web application scan-o-meter</category>
      <category domain="http://securityratty.com/tag/chief technology officer">chief technology officer</category>
      <category domain="http://securityratty.com/tag/internet con game">internet con game</category>
      <category domain="http://securityratty.com/tag/whitehat security">whitehat security</category>
      <category domain="http://securityratty.com/tag/conferences jeremiah">conferences jeremiah</category>
      <category domain="http://securityratty.com/tag/32nd episode">32nd episode</category>
      <category domain="http://securityratty.com/tag/prevention pdf">prevention pdf</category>
      <source url="http://www.cigital.com/silverbullet/show-032/">Show 032 - An Interview with Jeremiah Grossman</source>
    </item>
    <item>
      <title><![CDATA[Game on!]]></title>
      <link>http://securityratty.com/article/811075c6e59d5ec00b606569ae49ba5d</link>
      <guid>http://securityratty.com/article/811075c6e59d5ec00b606569ae49ba5d</guid>
      <description><![CDATA[In my last blog, we looked at increasing complexity on the part of both the good guys who are building legitimate businesses and on the part of the bad guys who are building a dark network of sorts...]]></description>
      <content:encoded><![CDATA[<p>In my last blog, we looked at  increasing complexity on the part of both the &ldquo;good&rdquo; guys who are building  legitimate businesses and on the part of the &ldquo;bad guys&rdquo; who are building a  &ldquo;dark network&rdquo; of sorts that is remarkably like the first.&nbsp; Today, I&rsquo;d like to dig into that and look at  a system for explaining this; and I thought I&rsquo;d use the phrase we used playing  street hockey in my youth in <a href="http://en.wikipedia.org/wiki/Canada">Canada</a> when the cars cleared the road, and  the game got serious again: <B>game on!</b>...</p>]]></content:encoded>
      <pubDate>Tue, 04 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/game">game</category>
      <category domain="http://securityratty.com/tag/bad guys">bad guys</category>
      <category domain="http://securityratty.com/tag/guys">guys</category>
      <category domain="http://securityratty.com/tag/dark network">dark network</category>
      <category domain="http://securityratty.com/tag/street hockey">street hockey</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/youth">youth</category>
      <category domain="http://securityratty.com/tag/complexity">complexity</category>
      <category domain="http://securityratty.com/tag/cars">cars</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1380">Game on!</source>
    </item>
    <item>
      <title><![CDATA[Links List 10.31.08]]></title>
      <link>http://securityratty.com/article/9428945f69b50703993282159a9d8676</link>
      <guid>http://securityratty.com/article/9428945f69b50703993282159a9d8676</guid>
      <description><![CDATA[Happy Halloween

What an interesting time to hold a technology conference. The DLA Piper Global Technology Leaders Summit last week brought together CXOs from Amazon, Walmart.com, Stanford, Safeway,...]]></description>
      <content:encoded><![CDATA[<p><b>Happy Halloween!</b>
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/10/em7-pumpkin.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="184" alt="EM7_pumpkin" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/em7-pumpkin-thumb.jpg" width="244" border="0"></a>
<p>What an interesting time to hold a technology conference. The <a href="http://www.eweek.com/c/a/IT-Management/CxOs-Get-Together-for-Candid-OfftheRecord-Chat/?kc=EWKNLNAV10272008STR3" target="_blank">DLA Piper Global Technology Leaders Summit last week</a> brought together CXOs from Amazon, Walmart.com, Stanford, Safeway, Microsoft, Sun, Cisco and others to discuss the state of IT in general and how the economy is impacting it. Some highlights:<br />
<blockquote>
<p>&#8220;Cloud computing for large enterprises is a dead duck, in the opinion of several venture capital firms.&#8221;</p>
</blockquote>
<p>&nbsp;<br />
<blockquote>
<p>&#8220;The current slowdown in the U.S. macroeconomy is definitely going to hurt the IT industry, as it will most of the nation&#8217;s businesses, for at least the next year and most likely into the next two years.&#8221;</p>
</blockquote>
<p>&nbsp;
<p><a href="http://blogs.eweek.com/storage_station/content/general/netapp_cancels_first_user_conference_cites_travel_issues.html" target="_blank">NetApp cancelled its first user conference</a> slated for 2009 citing economy-driven restrictions on <a href="http://www.btnonline.com/businesstravelnews/headlines/frontpage_display.jsp?vnu_content_id=1003875472" target="_blank">business travel</a>.
<p>We recently wrote about the possible <a href="http://blog.sciencelogic.com/are-there-recession-proof-it-products/10/2008" target="_blank">upside for MSPs</a> in this economic downtown. A <a href="http://www.infoworld.com/article/08/10/29/Recession_set_to_boost_outsourcing_1.html?source=NLC-TB&amp;cgd=2008-10-30" target="_blank">survey from EquaTerra</a> of more than 200 outsourcing service suppliers announced that “more than 40 percent of those polled had seen increased demand levels, despite the economic downturn.” The survey suggests that outsourcing projects are changing, with a strong focus on quick return on investment replacing longer-term initiatives to improve end-to-end business processes, according to InfoWorld. So as we saw during <a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008" target="_blank">our own surveys</a> this year, it looks like IT will spend time and money against the practical projects that should and could get done and not taking on ITIL and CMDB projects.
<p>Jonathan Schwartz as a puppet talking about open source and his ponytail. The driest Sesame Street take-off you’ll ever see. Check out the <a href="http://www.techcrunchit.com/2008/10/14/continuous-partial-innovation/" target="_blank">video here</a>. For those of you playing a drinking game at home, “ponytail”.
<p>Denise Dubie <a href="http://www.networkworld.com/newsletters/nsm/2008/102708nsm2.html?nlhtnsm=ts_102908&amp;nladname=102908networksystemsmanagemental" target="_blank">posted a follow up</a> to her article <a href="http://www.networkworld.com/community/node/33996" target="_blank">Novell’s Managed Objects buy</a>, and shared insights from different commenters, including <a href="http://www.networkworld.com/community/node/33996#comment-191253" target="_blank">yours truly</a>.
<p>One of our favorites, the IT Skeptic was <a href="http://www.johnmwillis.com/itil/5-questions-for-the-itskeptic/" target="_blank">featured on John Willis’ blog</a> this week, answering some questions about CMDB, ITSMF and more. He also provided his insight into IBM Tivoli, although he “tries to stay non-partisan”.
<p>Inexplicable. HP posted <a href="http://blogs.wsj.com/biztech/2008/10/27/h-p-commercializes-halloween-with-monsters-that-speak-technobabble/" target="_blank">Halloween-themed videos about datacenters</a> on YouTube this week. Unlike the great <a href="http://www.youtube.com/watch?v=MSqXKp-00hM" target="_blank">IBM videos about the mainframe</a>, these videos speak techno-babble without tempering the lingo with being funny or tongue-in-cheek. Various frightening creatures share information on service management processes and discuss virtualization techniques to help consolidate hardware. Scary.</p>
]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 18:10:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/projects">projects</category>
      <category domain="http://securityratty.com/tag/practical projects">practical projects</category>
      <category domain="http://securityratty.com/tag/discuss virtualization techniques">discuss virtualization techniques</category>
      <category domain="http://securityratty.com/tag/discuss">discuss</category>
      <category domain="http://securityratty.com/tag/cmdb projects">cmdb projects</category>
      <category domain="http://securityratty.com/tag/cmdb">cmdb</category>
      <category domain="http://securityratty.com/tag/ibm videos">ibm videos</category>
      <category domain="http://securityratty.com/tag/videos">videos</category>
      <category domain="http://securityratty.com/tag/survey suggests">survey suggests</category>
      <source url="http://blog.sciencelogic.com/links-list-103108/10/2008">Links List 10.31.08</source>
    </item>
    <item>
      <title><![CDATA[Building for the future]]></title>
      <link>http://securityratty.com/article/2e6a271b2efc04aa1206540bbaa55678</link>
      <guid>http://securityratty.com/article/2e6a271b2efc04aa1206540bbaa55678</guid>
      <description><![CDATA[For most IT leaders, bound by long-standing infrastructure choices and loads of legacy systems, it's little more than a parlor...]]></description>
      <content:encoded><![CDATA[For most IT leaders, bound by long-standing infrastructure choices and loads of legacy systems, it's little more than a parlor game. ]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/parlor game">parlor game</category>
      <category domain="http://securityratty.com/tag/legacy systems">legacy systems</category>
      <category domain="http://securityratty.com/tag/infrastructure choices">infrastructure choices</category>
      <category domain="http://securityratty.com/tag/bound">bound</category>
      <category domain="http://securityratty.com/tag/leaders">leaders</category>
      <category domain="http://securityratty.com/tag/loads">loads</category>
      <source url="http://www.networkworld.com/news/2008/102908-bechtel-future.html?fsrc=rss-security">Building for the future</source>
    </item>
    <item>
      <title><![CDATA[New To The Team - Old To The Game]]></title>
      <link>http://securityratty.com/article/e6566b2734036051297af1e2e0797451</link>
      <guid>http://securityratty.com/article/e6566b2734036051297af1e2e0797451</guid>
      <description><![CDATA[Welcome, come on in, have a seat. There is a cold beer in the fridge, help yourself
I may be new to the team, but Im (reasonably) old to the game. My name is Tyler Shields and Im the latest addition...]]></description>
      <content:encoded><![CDATA[<p>Welcome, come on in, have a seat. There is a cold beer in the fridge, help yourself!</p>
<p>I may be new to the team, but I&#8217;m (reasonably) old to the game. My name is Tyler Shields and I&#8217;m the latest addition to the Veracode research team. I started at Veracode in September 2008 as a Senior Security Researcher and have been immediately thrown into the fire. Working for a fast paced, highly energetic company like Veracode, keeps you busy and challenges you every day. I plan to blog on the most interesting pieces of my work with Veracode and hope that you find it enlightening or at the very least entertaining.</p>
<p>In the past I have worked as the security engineer at a .com startup, as an incident response and forensics specialist for the United States Postal Service (think HUGE network), and most recently as a security consultant for @stake and Symantec. I have consulted on engagements for Fortune 500 companies, most major financial institutions, and the highest levels of the United States government. As a consultant my focus was on anything related to application security including, application penetration assessments, product security assessments, secure development lifecycle consulting, and secure application architecture engagements. I lead the @stake/Symantec Application Security Center of Excellence that was used to help guide the knowledge of the global consulting team.  I also spent time as the lead for the Symantec Vulnerability Research program in which a number of interesting vulnerabilities were discovered and publicly released. In my spare time I enjoy reverse engineering and malware research. I recently completed my graduate degree in Information Security/Computer Science from James Madison University in Virginia.</p>
<p>So&#8230; Here&#8217;s to a new job, a new blog poster, and of course lots of fun to come.</p>
]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 09:57:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/veracode">veracode</category>
      <category domain="http://securityratty.com/tag/veracode research team">veracode research team</category>
      <category domain="http://securityratty.com/tag/senior security researcher">senior security researcher</category>
      <category domain="http://securityratty.com/tag/application penetration assessments">application penetration assessments</category>
      <category domain="http://securityratty.com/tag/james madison university">james madison university</category>
      <category domain="http://securityratty.com/tag/consultant">consultant</category>
      <category domain="http://securityratty.com/tag/product security assessments">product security assessments</category>
      <category domain="http://securityratty.com/tag/major financial institutions">major financial institutions</category>
      <source url="http://www.veracode.com/blog/2008/10/new-to-the-team-old-to-the-game/">New To The Team - Old To The Game</source>
    </item>
  </channel>
</rss>
