<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: gap]]></title>
    <link>http://securityratty.com/tag/gap</link>
    <description></description>
    <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Gartner Data Center Conference 2008]]></title>
      <link>http://securityratty.com/article/9a247228428224b9e36fa0f0db8d1d84</link>
      <guid>http://securityratty.com/article/9a247228428224b9e36fa0f0db8d1d84</guid>
      <description><![CDATA[The Gartner Data Center Conference kicked off this morning in Las Vegas. Despite the completely packed plane coming out here, Vegas seems quieter and not so crowded. The bartender at Wolfgang Pucks...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="96" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/12/clip-image002.jpg" width="439" border="0" /></p>
<p>The <a href="http://www.gartner.com/it/page.jsp?id=627607" target="_blank">Gartner Data Center Conference</a> kicked off this morning in Las Vegas. Despite the completely packed plane coming out here, Vegas seems quieter and not so crowded. The bartender at Wolfgang Puck&#8217;s Bistro told me they were looking <a href="http://www.datacenterknowledge.com/archives/2008/12/02/at-the-gartner-data-center-conference/" target="_blank">forward to the 1800 people coming</a> to this show to fill the hotel up. As we&#8217;ve noted, the economic crisis is impacting business travel all around.</p>
<p>22% of the attendees at Data Center come from the public sector and government, with 44% coming from very large enterprises of 20K+ employees.</p>
<p>During the <a href="http://www.gartner.com/it/page.jsp?id=603107" target="_blank">Gartner IOM conference</a> in June, some of the most interesting info coming out of it was the quick polls of the audience on a variety of infrastructure and operations management topics. What are enterprises doing? Where are they headed? What&#8217;s important to them? Here are some quick takes from the opening session:</p>
<p>1) What is the largest data center challenge that you currently face?</p>
<ul>
<li><b>Smaller Budgets: 21%</b></li>
<li><b>Power &amp; Cooling: 20%</b></li>
<li>Dealing with the Rate of Technology Change: 15%</li>
<li>Aligning Activities with the Business: 15%</li>
<li>Modernizing Legacy Applications: 10%</li>
<li>Lack of Data Center Space because of Equipment Spread: 9%</li>
<li>How to Source IT Services: 5%</li>
<li>How to Find and Retain Talent: 5%</li>
</ul>
<p>Well, it&#8217;s taken almost a year to be &#8220;official&#8221;, but the National Bureau of Economic Research just announced that <a href="http://www.msnbc.msn.com/id/27999557/" target="_blank">the US has been in a recession since December of 2007</a>. It should come as a surprise to no one that dealing with smaller budgets is top of mind, even for the predominantly larger enterprises attending here. </p>
<p>2) What projects will receive the most funding in 2009?</p>
<ul>
<li><b>Virtualization/Consolidation: 31%</b></li>
<li>Data Center Facilities &#8211; new builds: 17%</li>
<li>IT Operations Process Improvement: 12%</li>
<li>IT Modernization: 7%</li>
<li><b>Green IT: 5%</b></li>
</ul>
<p>Virtualization and (server) consolidation projects are clearly a priority for larger enterprises in 2009. What&#8217;s interesting here is the relatively very low priority of <a href="http://www.devx.com/IT_Innovation/Article/40073?trk=DXRSS_LATEST" target="_blank">Green IT projects</a> &#8211; in spite of the importance to attendees of getting power and cooling costs under control. Perhaps there&#8217;s a gap here between what&#8217;s often the hype of Green IT and practical considerations for data center managers when it comes to power and cooling management.</p>
<p>3) Where are you with server consolidation projects?</p>
<ul>
<li>No Plans: 3%</li>
<li>Looking at it now and will start in next 2 years: 13%</li>
<li><b>In process now: 58%</b></li>
<li><b>Have already completed server consolidation project: 26%</b></li>
</ul>
<p>Larger enterprises are consolidating servers with a quarter of attendees already having gone through the process at least once. And according to poll #2, this trend will definitely continue.</p>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 15:55:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/enterprises">enterprises</category>
      <category domain="http://securityratty.com/tag/predominantly larger enterprises">predominantly larger enterprises</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/server consolidation projects">server consolidation projects</category>
      <category domain="http://securityratty.com/tag/data center managers">data center managers</category>
      <category domain="http://securityratty.com/tag/consolidation projects">consolidation projects</category>
      <category domain="http://securityratty.com/tag/data center facilities">data center facilities</category>
      <category domain="http://securityratty.com/tag/larger enterprises">larger enterprises</category>
      <source url="http://blog.sciencelogic.com/gartner-data-center-conference-2008/12/2008">Gartner Data Center Conference 2008</source>
    </item>
    <item>
      <title><![CDATA[Antivirus programs unreliable during critical coverage gap]]></title>
      <link>http://securityratty.com/article/930c383ad645931f263414c483f485d8</link>
      <guid>http://securityratty.com/article/930c383ad645931f263414c483f485d8</guid>
      <description><![CDATA[Antivirus companies typically bill themselves as offering critical protection when you need it most, but the timeliness of the protection is a matter of concern. There's some reason to suspect AV...]]></description>
      <content:encoded><![CDATA[Antivirus companies typically bill themselves as offering critical protection when you need it most, but the timeliness of the protection is a matter of concern. There's some reason to suspect AV companies may be moving too slowly on this one, with a majority of scanners failing to detect malware up to three days after it's seen on the web.<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/d_EQLwK497I" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 22:00:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/protection">protection</category>
      <category domain="http://securityratty.com/tag/antivirus companies">antivirus companies</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/critical protection">critical protection</category>
      <category domain="http://securityratty.com/tag/detect malware">detect malware</category>
      <category domain="http://securityratty.com/tag/suspect">suspect</category>
      <category domain="http://securityratty.com/tag/reason">reason</category>
      <category domain="http://securityratty.com/tag/concern">concern</category>
      <category domain="http://securityratty.com/tag/days">days</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/d_EQLwK497I/Antivirus_programs_unreliable_during_critical_coverage_gap">Antivirus programs unreliable during critical coverage gap</source>
    </item>
    <item>
      <title><![CDATA[The Future of Ephemeral Conversation]]></title>
      <link>http://securityratty.com/article/1474b03de8a1d60cdf0aa28759ddce93</link>
      <guid>http://securityratty.com/article/1474b03de8a1d60cdf0aa28759ddce93</guid>
      <description><![CDATA[When he becomes president, Barack Obama will have to give up his BlackBerry. Aides are concerned that his unofficial conversations would become part of the presidential record, subject to subpoena and...]]></description>
      <content:encoded><![CDATA[<p>When he becomes president, Barack Obama will have to <a href="http://www.nytimes.com/2008/11/16/us/politics/16blackberry.html">give up</a> his BlackBerry.  Aides are concerned that his unofficial conversations would become part of the presidential record, subject to subpoena and eventually made public as part of the country's historical record.</p>

<p>This reality of the information age might be particularly stark for the president, but it's no less true for all of us.  Conversation used to be ephemeral.  Whether face-to-face or by phone, we could be reasonably sure that what we said disappeared as soon as we said it. Organized crime bosses worried about phone taps and room bugs, but that was the exception.  Privacy was just assumed.</p>

<p>This has changed.  We chat in e-mail, over SMS and IM, and on social networking websites like Facebook, MySpace, and LiveJournal.  We blog and we Twitter.  These conversations -- with friends, lovers, colleagues, members of our cabinet -- are not ephemeral; they <a href="http://www.schneier.com/essay-109.html">leave their own electronic trails</a>.</p>

<p>We know this intellectually, but we haven't truly internalized it.  We type on, engrossed in conversation, forgetting we're being recorded and those recordings might come back to haunt us later.</p>

<p>Oliver North learned this, way back in 1987, when messages he thought he had deleted were saved by the White House PROFS system, and then subpoenaed in the Iran-Contra affair.  Bill Gates learned this in 1998 when his conversational e-mails were provided to opposing counsel as part of the antitrust litigation discovery process.  Mark Foley learned this in 2006 when his instant messages were <a href="http://abcnews.go.com/WNT/BrianRoss/story?id=2509586">saved and made public</a> by the underage men he talked to.  Paris Hilton learned this in 2005 when her cell phone account was <a href="http://www.washingtonpost.com/wp-dyn/content/article/2005/05/19/AR2005051900711.html">hacked</a>, and Sarah Palin learned it earlier this year when her Yahoo e-mail account was hacked.  Someone in George W. Bush's administration learned this, and <a href="http://www.cnn.com/2007/POLITICS/04/13/white.house.email/index.html">millions of e-mails</a> went mysteriously and conveniently missing.</p>

<p>Ephemeral conversation is dying.</p>

<p>Cardinal Richelieu famously said, :If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged."  When all our ephemeral conversations can be saved for later examination, different rules have to apply.  Conversation is not the same thing as correspondence.  Words uttered in haste over morning coffee, whether spoken in a coffee shop or thumbed on a Blackberry, are not official pronouncements.  Discussions in a meeting, whether held in a boardroom or a chat room, are not the same as answers at a press conference.  And privacy isn't just about having something to hide; it <a href="http://www.schneier.com/essay-114.html">has enormous value</a> to democracy, liberty, and our basic humanity.</p>

<p>We can't turn back technology; electronic communications are here to stay and <a href="http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_controversy">even our voice conversations are threatened</a>.  But as technology makes our conversations less ephemeral, we need laws to step in and safeguard ephemeral conversation.  We need a comprehensive data privacy law, protecting our data and communications regardless of where it is stored or how it is processed. We need laws forcing companies to keep it private and delete it as soon as it is no longer needed.  Laws requiring ISPs to store e-mails and other personal communications are exactly what we don't need.</p>

<p>Rules pertaining to government need to be different, because of the <a href="http://www.schneier.com/essay-208.html">power differential</a>.  Subjecting the president's communications to eventual public review increases liberty because it reduces the government's power with respect to the people.  Subjecting our communications to government review decreases liberty because it reduces our power with respect to the government.  The president, as well as other members of government, need some ability to converse ephemerally -- just as they're allowed to have unrecorded meetings and phone calls -- but more of their actions need to be subject to public scrutiny.</p>

<p>But laws can only go so far.  Law or no law, when something is made public it's too late.  And many of us like having complete records of all our e-mail at our fingertips; it's like our offline brains.</p>

<p>In the end, this is cultural.</p>

<p>The Internet is the greatest generation gap since rock and roll.  We're now witnessing one aspect of that generation gap: the younger generation chats digitally, and the older generation treats those chats as written correspondence.  Until our CEOs blog, our Congressmen Twitter, and our world leaders send each other LOLcats &ndash; until we have a Presidential election where both candidates have a complete history on social networking sites from before they were teenagers&ndash; we aren't fully an information age society.</p>

<p>When everyone leaves a public digital trail of their personal thoughts since birth, no one will think twice about it being there.  Obama might be on the younger side of the generation gap, but the rules he's operating under were written by the older side.  It will take another generation before society's tolerance for digital ephemera changes.</p>

<p>This essay <a href="http://online.wsj.com/article/SB122722381368945937.html">previously appeared</a> on <ui>The Wall Street Journal</a> website (not the print newspaper), and is an update of <a href="http://www.schneier.com/essay-129.html">something I wrote previously</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=jPWiN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=jPWiN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=hlUTN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=hlUTN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 11:06:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ephemeral conversation">ephemeral conversation</category>
      <category domain="http://securityratty.com/tag/conversation">conversation</category>
      <category domain="http://securityratty.com/tag/safeguard ephemeral conversation">safeguard ephemeral conversation</category>
      <category domain="http://securityratty.com/tag/ephemeral">ephemeral</category>
      <category domain="http://securityratty.com/tag/ephemeral conversations">ephemeral conversations</category>
      <category domain="http://securityratty.com/tag/conversations">conversations</category>
      <category domain="http://securityratty.com/tag/generation">generation</category>
      <category domain="http://securityratty.com/tag/generation gap">generation gap</category>
      <category domain="http://securityratty.com/tag/public scrutiny">public scrutiny</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_future_of_e.html">The Future of Ephemeral Conversation</source>
    </item>
    <item>
      <title><![CDATA[What's Happiness Got to Do With It?]]></title>
      <link>http://securityratty.com/article/141d4a55a5d3195a7aaaa7ca4b3a3c7e</link>
      <guid>http://securityratty.com/article/141d4a55a5d3195a7aaaa7ca4b3a3c7e</guid>
      <description><![CDATA[Gartner's own John Pescatore has issued a 12 world post
The best security program is at the business with the happiest customers

Happiness? Really? That's the measure of program effectiveness? I...]]></description>
      <content:encoded><![CDATA[<p>Gartner&#39;s own John Pescatore has issued a 12 world <a href="http://blogs.gartner.com/john_pescatore/2008/10/28/twelve-word-tuesday-measuring-security-program-effectiveness/">post:</a></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 17px; ">The best security program is at the business with the happiest customers.</span></p></blockquote><br /><div>Happiness? Really? That&#39;s the measure of program effectiveness? I would see those 12 words and raise them one word (13 if you&#39;re scoring at home):</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>There&#39;s a fine line between happy customers and playing piano in a bordello.</p></blockquote><br /><div>I mean the people running hedge funds and derivative books at AIG, Lehman and friends had lots of happy customers for the last decade!</div><br /><div>To me the happy customer is a classic IT copout &quot;we just did what the &quot;business&quot; asked&quot;. Like we&#39;re just a bystander or something. Its our job to create business value and be business like. We should seek to <span style="font-style: italic;">empower</span> out customers, not make them happy.&#0160;</div><br /><div>Please understand I am not that guy who says IT security has to be the &quot;bad cops&quot; who deny everything the business wants to do. Just saying it is our job to raise the bar where we can. Raising the bar does not always create super happy customers in the short run, but it does empower companies.</div><br /><div>Unfortunately, playing piano in the bordello is what a lot of security groups do and even big analyst firms. The path of least resistance ain&#39;t always the way. Here is an example. I was at a client many years ago, they wanted to build a big Identity Management solution, so of course they wrote a big RFI got responses from Sun, IBM, Oracle and friends. The bids were in the $3-5 million range. Pretty big projects for an Infosec team. So what do you do? Call up a big analyst firm and get some advice, right?</div><br /><div>A week goes by and we get an audience with the &quot;guru&quot; from the Big Analyst Firm. The client has pretty detailed requirements, what systems they want to connect to, what use cases they are looking to solve for, &#0160;and so on. We anxiously await the knowledge the analyst is about to transfer to us. His response was as follows - &quot;what kind of shop are you? IBM shop? Oracle shop?&quot; &quot;Ummm...we are a huge company we have everything.&quot; &quot;Well if you are more of a IBM shop you should go with them. If you are more of a Oracle shop you should go with them.&quot; That was the extent of a 30 minute conversation. True story.</div><br /><div>Of course, the one value proposition of the Big Analyst Firms is that they supposedly can tell you what everyone else is supposedly doing. There is some value in this I grant you. And it does make for happy customers because even when you force your customers to change, you can say &quot;Well geez, I know its hard but the Big Analyst Firm says that everyone is doing it.&quot; But is this security improvement?</div><br /><div>Back in 2004, I went to a great security conference, it was Information Security Decisions (<a href="http://infosecurityconference.techtarget.com/conference/index.html">they are back in Chicago next week</a>). It was in Chicago, downtown on the river. Tom Davern even took us all out on a boat for lunch one day. Anyway, there was one truly great talk there. It wasn&#39;t Fred Cohen debating <a href="http://cigital.com/justiceleague/">Gary McGraw</a> on application security which was outstanding (in which Fred uttered the memorable line &quot;I agree with Gary everywhere he agrees with me.&quot; (Gary won the debate, his best line - &quot;We know how to win the software security war, but we don&#39;t know how to manage the peace&quot; still the problem today actually)) It wasn&#39;t Pete Lindstrom showing his security metrics framework (which is still a great starting point). it wasn&#39;t Dan Geer&#39;s fireside chat.</div><br /><div>The truly great talk, though, was by the now departed <a href="http://1raindrop.typepad.com/1_raindrop/2007/02/thinking_about_.html">Robert Garigue</a>. It was called &quot;Its the End of the CISO as I Know It, (And I Feel Fine).&quot; The whole end to end talk was wonderful, there are several things in there that I still use every single day like the separate security models for Infostructure and Infrastructure but the point I want to talk about is the CISO role.</div><br /><div>Garigue talked about the two most prevalent CISO models - the jester and the bad cop. The jester CISO</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; ">Sees a lot</span><br /><span style="color: #333333; line-height: 19px; ">Can tell the king he has no clothes</span><br /><span style="color: #333333; line-height: 19px; ">Can tell the king he really is ugly</span><br /><span style="color: #333333; line-height: 19px; ">Does not get killed by the king</span><br /><span style="color: #333333; line-height: 19px; ">Nice to have around but…how much security improvement comes from this ?</span></p></blockquote><p><span style="color: #333333; line-height: 19px;"><br /></span></p><div><span style="color: #333333; line-height: 19px;">The jester has happy customers! At least for awhile.</span></div><div><span style="color: #333333; line-height: 19px;"><br /></span></div><div><span style="color: #333333; line-height: 19px;">Again I grant you bad cop is not the way to go either (and while this already long post could read harsh on John Pescatore&#39;s pithy summary, I give him a lot of points for saying that security needs to be customer conscious).</span></div><div><span style="color: #333333; line-height: 19px;"><br /></span></div><div><span style="color: #333333; line-height: 19px;">We have all seen bad cop CISOs who</span></div><div><span style="color: #333333; line-height: 19px;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; ">Changes happened faster that he was able to move</span><br /><span style="color: #333333; line-height: 19px; ">Did not read the signs</span><br /><span style="color: #333333; line-height: 19px; ">Good intentions went unfulfilled</span><br /><span style="color: #333333; line-height: 19px; ">A brutal way to ending a promising career</span><br /><span style="color: #333333; line-height: 19px; ">Sad to have around but…how much security improvement comes from this ?</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px;"><br /></span></p></blockquote><p><span style="color: #333333; line-height: 19px;"></span></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">Obviously these models of CISOs are not solving our information security problems. Instead Dr. Garigue points us to Charlemagne as a better model</p><blockquote style="margin-top: 10px; margin-bottom: 10px; "><p>King of the Franks and Holy Roman Emperor; conqueror of the Lombards and Saxons (742-814) - reunited much of Europe after the Dark Ages.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">He set up other schools, opening them to peasant boys as well as nobles. Charlemagne never stopped studying. He brought an English monk, Alcuin, and other scholars to his court - encouraging the development of a standard script.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">He set up money standards to encourage commerce, tried to build a Rhine-Danube canal, and urged better farming methods. He especially worked to spread education and Christianity in every class of people.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">He relied on Counts, Margraves and Missi Domini to help him.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">Margraves - Guard the frontier districts of the empire. Margraves retained, within their own jurisdictions, the authority of dukes in the feudal arm of the empire.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">Missi Domini - Messengers of the King.</p></blockquote><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">This is the way forward! Find software security champions in the architecture and development groups,help them understand the real security issues. They will find solutions you have not thought of. Same for DBAs, same for business analysts even. Its all about beating the bushes, education, and decentralizing security services. Specifically, he points out this important mandate for IT security</p><p></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; ">Knowledge of risky things is of strategic value</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; ">How to know today tomorrow’s unknown ?</span><br /><span style="color: #333333; line-height: 19px; ">How to structure information security processes in an organization so as to identify and address the NEXT categories of risks ?</span></p></blockquote><p><span style="color: #333333; line-height: 19px;"></span></p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">To me this is our mandate and measure of effectiveness. Empower our customers, educate, and create business value. If I am a CISO &#0160;I don&#39;t want 20 people reporting to me who do firewall ruleset changes. I want one champion in 20 different groups - development teams, architects, DBAs, business analysts.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; ">A concrete example, infosec can continue to go along with the herd and follow the &quot;what everyone else is doing architecture&quot; meanwhile developers are connecting <span style="font-style: italic;"><span style="font-weight: bold;">every single thing</span></span> in your business to the Web. I have been doing integration and new technology projects for a long time, and let me tell you - Change does not always create happy customers in the short run. But the chart below shows that information security is maybe more concerned with not causing waves rather than adapting.</p><p style="margin-top: 10px; margin-bottom: 10px; text-align: left; "></p>
<div><a href="http://1raindrop.typepad.com/photos/uncategorized/2008/05/19/innovatecompare_2.png"><img alt="Innovatecompare_2" border="0" height="167" src="http://1raindrop.typepad.com/1_raindrop/images/2008/05/19/innovatecompare_2.png" title="Innovatecompare_2" width="300" /></a><p></p></div><div>How long can developers evolve, connect everything and security people not change anything? Herb Stein said, &quot;things that can&#39;t go on forever, don&#39;t. &quot;At some point these chickens are coming home to roost, there is a yawning gap between rapidly evolution connecting the enterprise and the 13 year old and counting security architecture that &quot;Everyone else is using&quot; and when those chicken come home to roost you may not have happy customers then. Here is my 12 words:</div><br /><p></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 17px; ">The best security program is at the business with sustainable competitive advantage.</span></p></blockquote>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 07:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information security decisions">information security decisions</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/software security champions">software security champions</category>
      <category domain="http://securityratty.com/tag/architecture">architecture</category>
      <category domain="http://securityratty.com/tag/security architecture">security architecture</category>
      <category domain="http://securityratty.com/tag/security metrics framework">security metrics framework</category>
      <category domain="http://securityratty.com/tag/super happy customers">super happy customers</category>
      <category domain="http://securityratty.com/tag/happy customers">happy customers</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/whats-happiness-got-to-do-with-it-1.html">What's Happiness Got to Do With It?</source>
    </item>
    <item>
      <title><![CDATA[Links List 10.17.08]]></title>
      <link>http://securityratty.com/article/794a0935dd027c6a33ce5d3ef58fb2e3</link>
      <guid>http://securityratty.com/article/794a0935dd027c6a33ce5d3ef58fb2e3</guid>
      <description><![CDATA[Novell announced this week its intent to purchase Managed Objects . We really didnt see this coming. Novell? Cant quite figure out the master plan here. I mean, they said theyd acquire PlateSpin back...]]></description>
      <content:encoded><![CDATA[<p>Novell announced this week its <a href="http://www.networkworld.com/community/node/33996">intent to purchase Managed Objects</a>. We really didn’t see this coming. Novell? Can’t quite figure out the master plan here. I mean, they said they’d acquire <a href="http://dcsblog.burtongroup.com/data_center_strategies/2008/02/novell-makes-a.html">PlateSpin</a> back in February which made a lot of sense for bridging the gap of physical to virtual and building out a management portfolio beyond ZENworks Orchestrator. But Managed Objects? CMDBs? In this economy? We have to think back to the survey [link to survey post] we just did at Interop NY and the low scores – on importance and actual deployments – that CMDBs got. When it comes to tightening the belt, CMDBs kinda fell off the list. We’ll be looking forward to future announcements to see how this plays out. </span></p>
<p>Martin MC Brown at ComputerWorld has a great post on <a href="http://blogs.computerworld.com/capacity_planning_and_the_cloud">capacity planning and cloud computing</a>. He discusses a new book “The Art of Capacity Planning”. The problem with the current model of data center management is that often a large number of machines may sit relatively idle while waiting for the traffic spike that causes them to be used. This is a problem because it’s simply a waste of time and resources on a whole number of levels. Enter the cloud – or at least the “hope of cloud computing”.</span></p>
<p>Numbers – what do they really mean? IDC released a statement with a whole bunch of them from their “<a href="http://www.idc.com/getdoc.jsp;jsessionid=FT0ISDWWAPJ4SCQJAFDCFFAKBEAVAIWD?containerId=prUS21473108">Worldwide Quarterly Server Virtualization Tracker</a>”. <span> </span>The most interesting stat: x86 Virtualization License Market Standings. VMware owns 44% of the market, but Microsoft, in its first quarter of general availability for Microsoft Hyper-V (plus Virtual Server 2005), has <a href="http://www.virtualization.info/2008/10/microsoft-already-took-23-of.html">23% of the market</a> of new shipments. </span></p>
]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 23:26:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/data center management">data center management</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/microsoft hyper-v">microsoft hyper-v</category>
      <category domain="http://securityratty.com/tag/cmdbs">cmdbs</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/virtual server">virtual server</category>
      <category domain="http://securityratty.com/tag/survey post">survey post</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://blog.sciencelogic.com/links-list-101708/10/2008">Links List 10.17.08</source>
    </item>
    <item>
      <title><![CDATA[ePolicing - Tomorrow the world?]]></title>
      <link>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</link>
      <guid>http://securityratty.com/article/a75f8d8e609ad56200d2ab52efd2041c</guid>
      <description><![CDATA[This week has finally seen an announcement that the Police Central e-crime Unit (PCeU) is to be funded by the Home Office. However, the largesse amounts to just 3.5 million of new money spread over...]]></description>
      <content:encoded><![CDATA[<p>This week has finally seen an <a href="http://press.homeoffice.gov.uk/press-releases/new-specialist-ecrime-unit">announcement</a> that the <a href="http://www.met.police.uk/pceu/index.htm">Police Central e-crime Unit</a> (PCeU) is to be funded by the Home Office. However, the largesse amounts to just £3.5 million of new money spread over three years, with the Met putting up a further £3.9 million &#8212; but whether the Met&#8217;s contribution is &#8220;new&#8221; or reflects a move of resources from their existing <a href="http://www.met.police.uk/computercrime/">Computer Crime Unit</a> I could not say.</p>
<p>The announcement is of course Good News &#8212; because once the PCeU is up and running next Spring, it should plug (to the limited extent that £2 million a year can plug) the &#8220;level 2&#8243; eCrime gap that I&#8217;ve <a href="http://www.lightbluetouchpaper.org/2006/02/06/mysterious-and-menacing/">written</a> <a href="http://www.lightbluetouchpaper.org/2006/10/13/mainstreaming-ecrime/">about</a> <a href="http://www.lightbluetouchpaper.org/2007/02/11/soca-we-just-want-your-money/">before</a>. viz: that SOCA tackles &#8220;serious and organised crime&#8221; (level 3), your local police force tackles local villains (level 1), but if criminals operate outside their force&#8217;s area &#8212; and on the Internet this is more likely than not &#8212; yet they don&#8217;t meet SOCA&#8217;s threshold, then who is there to deal with them?</p>
<p>In particular, the PCeU is envisaged to be the unit that deals with the intelligence packages coming from the <a href="http://www.cityoflondon.police.uk/CityPolice/ECD/Fraud/">City of London Fraud Squad&#8217;s</a> new online Fraud Reporting <a href="http://www.kablenet.com/kd.nsf/Frontpage/356DD0A1942F3A998025745F0049092C?OpenDocument">website</a> (once intended to launch in November 2008, now scheduled for Summer 2009).</p>
<p>Of course everyone expects the website to generate more reports of eCrime than could ever be dealt with (even with much more money), so the effectiveness of the PCeU in dealing with eCriminality will depend upon their prioritisation criteria, and how carefully they select the cases they tackle.</p>
<p>Nevertheless, although the news this week shows that the Home Office have finally understood the need to fund more ePolicing, I don&#8217;t think that they are thinking about the problem in a sufficiently global context.</p>
<p>A little history lesson might be in order to explain why.<br />
<span id="more-401"></span></p>
<p>Back in 1930&#8217;s, <a href="http://www.fbi.gov/libref/historic/famcases/clyde/clyde.htm">Bonnie and Clyde</a> and other US bank robbers were using the new-fangled automobile to flee across state lines &#8212; creating jurisdictional problems as a result. The US solution was to make bank robbery (along with auto-theft and other related offences) into federal offences rather keeping them as state-specific infractions. In particular this meant that the FBI could provide federal level policing (tracking down and killing <a href="http://en.wikipedia.org/wiki/John_Dillinger">John Dillinger</a> for example).</p>
<p>We have the same jurisdictional issues dealing with cyberspace, with criminals in one country fleecing consumers in another while using systems hosted in a third. The <a href="http://conventions.coe.int/Treaty/EN/Treaties/Html/185.htm">Convention on Cybercrime</a> addresses part of the problem by trying to ensure international consistency where eLaws are specifically needed (which of course is only the case for small parts of eCriminality, <a href="http://www.opsi.gov.uk/Acts/acts2006/ukpga_20060035_en_1">fraud</a> is fraud whether eEnabled or not). However, there is limited inter-jurisdictional <em>co-ordination</em> for eCrime investigations &#8212; for example <a href="http://www.interpol.int/">Interpol</a> (often <a href="http://en.wikipedia.org/wiki/Interpol#Interpol_in_popular_culture">incorrectly perceived</a> to be international police force)  merely keeps a large database and passes faxes from one place to another.</p>
<p>In practice, most cross-border investigations are done as &#8220;joint operations&#8221; and the jointness is usually very limited &#8212; one force does all the legwork and a liaison officer in the other country deals with local paperwork. There&#8217;s usually a <a href="http://www.phrases.org.uk/meanings/quid-pro-quo.html">quid pro quo</a> element to these joint operations, for budgeting reasons if no other.</p>
<p>What isn&#8217;t happening, or at least only in a handful of very specialised areas, is any international co-operation in setting priorities or selecting cases to pursue. Every country is doing its own thing about eCrime, and there&#8217;s a widespread impression that any criminal who can operate from &#8220;across the state line&#8221; is essentially immune from serious investigation.</p>
<p>We identified this problem last year when we (<a href="http://www.cl.cam.ac.uk/~rja14/">Ross Anderson</a>, <a href="http://www.inf.tu-dresden.de/index.php?node_id=489">Rainer Böhme</a>, <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and <a href="http://www.cl.cam.ac.uk/~rnc1/">myself</a>) wrote a report on <a href="http://www.enisa.europa.eu/doc/pdf/report_sec_econ_&#038;_int_mark_20080131.pdf">Security Economics and the Internal Market</a> for <a href="http://www.enisa.europa.eu/">ENISA</a>. It&#8217;s not an easy one to fix whilst politicians (and populaces) are unwilling to see &#8220;foreign&#8221; police officers operating in their country, and the establishment of a truly international &#8220;cyber police force&#8221; seems equally unlikely.</p>
<p>Our policy proposal to tackle the issue harks back to WWII&#8217;s <a href="http://www.archives.gov/research/holocaust/finding-aid/military/rg-331.html">SHAEF</a>, which has morphed into similar arrangements within <a href="http://www.nato.int/shape/about/background2.htm">NATO</a>. In essence liaison officers from multiple forces would sit around a single table, working with a central coordinator, to set policy and decide which investigations to pursue. They would then communicate back to their own countries, who have specifically budgeted to provide appropriate assistance. So it&#8217;s very like &#8220;joint operations&#8221;, but the scheme is multi-laterial, and has a true command and control function in the centre &#8212; who will quickly learn to shy away from politically sensitive topics and make a real impact on eCriminality.</p>
<p>To summarise then, a <a href="http://www.cartoonbank.com/item/34449">welcome</a> to the Home Office for finally finding a small amount of funding for some country-wide ePolicing; but it&#8217;s well past time to be working on world-wide initiatives.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 13:57:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecrime gap">ecrime gap</category>
      <category domain="http://securityratty.com/tag/ecrime">ecrime</category>
      <category domain="http://securityratty.com/tag/provide federal level">provide federal level</category>
      <category domain="http://securityratty.com/tag/ecrime investigations">ecrime investigations</category>
      <category domain="http://securityratty.com/tag/online fraud">online fraud</category>
      <category domain="http://securityratty.com/tag/level">level</category>
      <category domain="http://securityratty.com/tag/country deals">country deals</category>
      <category domain="http://securityratty.com/tag/deals">deals</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/02/epolicing-tomorrow-the-world/">ePolicing - Tomorrow the world?</source>
    </item>
    <item>
      <title><![CDATA[XSF & XSS: Double your pleasure, double your fun]]></title>
      <link>http://securityratty.com/article/1fae85d8335f0c9fbe56b8858c8692c2</link>
      <guid>http://securityratty.com/article/1fae85d8335f0c9fbe56b8858c8692c2</guid>
      <description><![CDATA[If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less...]]></description>
      <content:encoded><![CDATA[If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less familiar with is <a href="http://www.xssed.com/news/26/Cross-site_framed/" target="_blank">cross-site framing</a>, which largely couples the best of both above-mentioned vulnerabilities. <br />What then, if there's a cross-site framing vulnerability coupled with cross-site scripting in the content offered by the frame? All sorts of problems come to mind: phishing, malware, credential theft; all arguably twice removed from the attacker's source, tucked away in the context of two victim sites.<br />First, I'll discuss the original XSS issue that led to this finding.<br />Recently, I was investigating a flawed parameter in <a href="http://www.openhire.com/" target="_blank">Openhire</a>, a career posting vendor used by major companies like <a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?company_id=15635&version=1" target="_blank">Crate&Barrel</a>, Eileen Fisher, Enterprise, Benjamin Moore, Scottrade, and Getty Images.<br />Most of these sites simply link to the Openhire offering that hosts job postings on their behalf which, in turn, has been crafted to look like the referring site.<br />As an example, here's Scottrade's employment page hosted by Openhire.<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?version=1&company_id=15624" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?version=1&company_id=15624</a></span><br /><br />Standard stuff, looks nicely like the Scottrade site, so everything's cool, right?<br />Wrong? What if someone hosting a service on your behalf suffers a security gap?<br /><span style="font-weight:bold;">You're only as strong as your weakest link!</span><br />Here's the posting for an Application Security Engineer (funny, eh?) at Scottrade as hosted on their behalf by Openhire:<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=976367&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters%3B%3B%3BInformation%20Technology%3B%3B%3BSecurity&startflag=3&CFID=66851845&CFTOKEN=29a95-d12594d4-47d9-49e8-9067-1091bdf68e80" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=976367&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters%3B%3B%3BInformation%20Technology%3B%3B%3BSecurity&startflag=3&CFID=66851845&CFTOKEN=29a95-d12594d4-47d9-49e8-9067-1091bdf68e80</a></span><br /><br />Now here the same job posting spewing massive cookie data:<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3</a></span><br /><br />Screen shot offered below, as the code above will likely be repaired very soon by Openhire. I notified them this past Thursday.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNcebDIT4JI/AAAAAAAAADA/2umzh0wbmmw/s1600-h/Scottrade_Openhire.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNcebDIT4JI/AAAAAAAAADA/2umzh0wbmmw/s320/Scottrade_Openhire.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248697340769067154" /></a><br /><br />It's bad enough when there's an application security hole in code someone else is hosting on your behalf, but what if your method of displaying said code is also at risk? Enter the Getty Images Jobs page.<br /><br /><span style="font-style:italic;"><a href="http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=careeropps&startflag=0&company_id=15531&version=2&CFID=12265212&CFTOKEN=60213778" target="_blank">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=careeropps&startflag=0&company_id=15531&version=2&CFID=12265212&CFTOKEN=60213778</a></span><br /><br />Watch what happens when you pull the Openhire code. Can you say self-replicating frame loop from hell (in Firefox)? Trust me your browser will crash if you leave this running too long. This will likely be fixed soon, so if the URL doesn't work, the screen shot exemplifies the issue.<br /><br /><a href="http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html" target="_blank">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html</a><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SNcqO933d4I/AAAAAAAAADY/SSzLv3ZpiN0/s1600-h/GettyonGetty.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SNcqO933d4I/AAAAAAAAADY/SSzLv3ZpiN0/s320/GettyonGetty.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248710327339022210" /></a><br /><br />What if, instead of Openhire's Getty Images page, or nothing at all (which obviously creates its own issue), we drop in an arbitrary URL?<br />Yep, you guessed it.<br /><span style="font-style:italic;"><br />http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://www.xssed.com/news/26/Cross-site_framed/</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SNcmqF3wQyI/AAAAAAAAADI/EhR6rYOmwlI/s1600-h/Getty_XSF.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SNcmqF3wQyI/AAAAAAAAADI/EhR6rYOmwlI/s320/Getty_XSF.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248706395295990562" /></a><br /><br />Now, bringing it all home for double the pleasure, double the fun, what if we coupled the original Openhire cross-site scripting vuln with Getty Images cross-site frame vuln?<br /><br />It hurts twice as much, in my book.<br /><br /><span style="font-style:italic;">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNco1c6ensI/AAAAAAAAADQ/QaKByEFozTU/s1600-h/Getty%2BScottrade.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNco1c6ensI/AAAAAAAAADQ/QaKByEFozTU/s320/Getty%2BScottrade.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248708789483249346" /></a><br /><br />The lessons learned:<br />1) Ensure your partners are writing secure code on you behalf.<br />2) Ensure that the code you utilize to incorporate said partner's code is also well written. ;-)<br /><br />Double the headache, double the dumb.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html&title=XSF%20&%20XSS:%20Double%20your%20pleasure,%20double%20your%20fun " title="XSF & XSS: Double your pleasure, double your fun ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html" title="XSF & XSS: Double your pleasure, double your fun ">digg</a>]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 17:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/openhire code">openhire code</category>
      <category domain="http://securityratty.com/tag/openhire">openhire</category>
      <category domain="http://securityratty.com/tag/original openhire cross-site">original openhire cross-site</category>
      <category domain="http://securityratty.com/tag/scottrade site">scottrade site</category>
      <category domain="http://securityratty.com/tag/scottrade">scottrade</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/secure code">secure code</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html">XSF &amp; XSS: Double your pleasure, double your fun</source>
    </item>
    <item>
      <title><![CDATA[Sorry, Qantas, No Unfettered Broadband]]></title>
      <link>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</link>
      <guid>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</guid>
      <description><![CDATA[Qantas backs off from earlier plans, changes provider for in-flight broadband: The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.smh.com.au/news/travel/qantas-limits-access-to-web/2008/09/17/1221330929870.html"><strong>Qantas backs off from earlier plans, changes provider for in-flight broadband:</strong></a> The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its in-flight broadband plans. Aeromobile was the provider when the service <a href="http://www.breakingtravelnews.com/article.php?story=2007081609481129&query=qantas"><strong>was tested in second quarter 2007</strong></a>, but OnAir is now described as the airline's partner. This was noted by colleague Fabio Zambelli, who emailed me the news, and <a href="http://www.setteb.it/content/view/4742"><strong>has his own account</strong></a> at 7BIT (in Italian).</p>

<p><a href="http://www.onair.aero/index.php?pid=123"><strong>OnAir</strong></a> has so far tested their calling/texting-only service on two aircraft--one operated by Air France, one by TAP Portugal--even though RyanAir announced plans that its planes would started being unwired with the service by late 2007. Still no word on that fleet progress.</p>

<p>Qantas will apparently launch cached Web browsing and limited Web email (probably through a proxy) along with instant messaging, with full Internet service coming "later in 2009." This is clearly due to a lack of satellite coverage that was just remediated a few weeks ago (see below). The first plane with limited service, a new A380, should be in flight 20-October-2008.</p>

<div style="float:right; margin:0px; padding-left: 10px; padding-bottom: 0px;"><p><img src="http://wifinetnews.com//images/2008/SorryQantas.jpg" alt="SorryQantas.jpg" border="0" width="100" height="152"></p><p style="font-size: 10px">I hate in-flight<br/>broadband</p></div>To Qantas' credit, note that each seat on the plane will have a laptop opower socket, a USB port, and a multimedia system that can show 100 movies and 500 TV show episodes, play the contents of 1,000 CDs and 20 radio stations, and offer 80 games. 

<p>The Morning Herald seems to overstate the importance and scope of a complaint filed by the union representing American Airlines' flight attendants. The detailed coverage in the U.S. had more to do with the potential for issues, and likely attendants lack of interest in policing yet another media on the plane. Filtering doesn't work, the attendants probably already know, and this may just be a negotiating point with the airline.</p>

<p>On why Qantas is waiting until late 2009? This requires unwinding how OnAir gets its signal.</p>

<p>Aeromobile and OnAir both rely on Inmarsat satellites for their service. Both companies had several years ago staked their futures on the fourth-generation network Inmarsat was to inaugurate with three satellites that would use beamforming to allow precise delivery of nearly 500 Kbps per receiver, with hundreds or thousands of regions being able to be targeted from a single satellite. Inmarsat's third-gen network--don't confuse this with 3G cellular ground-based networks--can deliver about 64 Kbps per channel.</p>

<p>Now, unfortunately, Inmarsat was three years late on launching its trans-Pacific bird. While the company <a href="http://www.inmarsat.com/About/Newsroom/Press/00021465.aspx?language=EN&textonly=False"><strong>claims 85 percent coverage of the earth</strong></a> and 98 percent coverage of population, there's a big gap over the Pacific that also prevents them from having good overlap between the U.S. and Japan/China/Korea, as well as the southern Pacific, covering Australia. Since the biggest market for long-haul flights would likely be Australia, Japan, and China, traveling trans-Pacific or trans-hemispheric routes, that gap is rather large.</p>

<p>Aeromobile opted to build out a service, deployed only by Emirates airline as far as I can tell, that uses the 3G service since it was available, and most necessary equipment is already installed on most over-water planes. OnAir was waiting for 4G, which has necessitated a long wait, but allowed them to launch in Europe with a seemingly next-generation service. Given that OnAir is controlled by an airline-owned integration firm, SITA, and by Airbus, they're not going anywhere.</p>

<p>Inmarsat finally <a href="http://spaceflightnow.com/proton/i4f3/"><strong>lofted its third satellite on Baikonur Cosmodrome in Kazakhstan</strong></a> on 19-August-2008, and the launch and separation was reported as successful. Previously, the company has needed up to a year to verify and deploy its 4G satellites. (You can <a href="http://forum.nasaspaceflight.com/index.php?topic=12380.105"><strong>read extremely close coverage of the launch</strong></a> at a Web site devoted to space enthusiasm.)</p>

<p>However, the dirty little secret about Inmarsat's BGAN is that it costs a fortune to heft bandwidth across it. Thus, in-flight broadband over BGAN, if it's ever available, is going to be changed on an extremely high per-MB rate. None of the providers want to say this. This is in contrast to Row 44 (and, once, Connexion by Boeing), which relies on leased Ku-band transponders where they can fix costs and they require high volumes to keep per-bit costs efffectively low.</p>

<p>OnAir's launch of calling on Air France's service involves paying a few euros per minute for calls, which might help you understand what data costs could ultimately run.</p>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 06:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/satellite coverage">satellite coverage</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service involves">service involves</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/in-flight broadband plans">in-flight broadband plans</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/inmarsat satellites">inmarsat satellites</category>
      <category domain="http://securityratty.com/tag/inmarsat">inmarsat</category>
      <source url="http://wifinetnews.com/archives/008448.html">Sorry, Qantas, No Unfettered Broadband</source>
    </item>
    <item>
      <title><![CDATA[Cost/Benefit of Terrorism Security]]></title>
      <link>http://securityratty.com/article/3ef2fe47ba64d2a4788b864a136d04e7</link>
      <guid>http://securityratty.com/article/3ef2fe47ba64d2a4788b864a136d04e7</guid>
      <description><![CDATA[The terrifying cost of feeling safer ,&quot; from the Sydney Morning Herald : Sandler and his colleagues conducted an analysis of the costs and benefits of five different approaches to combating terrorism....]]></description>
      <content:encoded><![CDATA[<p>"<a href="http://business.smh.com.au/business/the-terrifying-cost-of-feeling-safer-20080826-435l.html">The terrifying cost of feeling safer</a>," from the <i>Sydney Morning Herald</i>:</p>

<blockquote>Sandler and his colleagues conducted an analysis of the costs and benefits of five different approaches to combating terrorism. I must warn you that, because of the dearth of information, this study is even more reliant on assumptions than usual. Even so, in three cases the cost of the action so far exceeds the benefits that doubts about the reliability of the estimates recede.

<p>Because the loss of life is so low, they measure the benefits of successful counter-terrorism measures in terms of loss of gross domestic product avoided. Trouble is, terrorism does little to disrupt economic growth, as even September 11 demonstrated.</p>

<p>Using the case of the US, Sandler estimates that simply continuing the present measures involves costs exceeding benefits by a factor of at least 10. Adopting additional defensive measures (such as stepping up security at valuable targets) would, at best, entail costs 3.5 times the benefits. Taking more pro-active measures (such as invading Afghanistan) would have costs at least eight times the benefits.</p>

<p>According to Sandler, only greater international co-operation, or adopting more sensitive foreign policies to project a more positive image abroad, could produce benefits greater than their (minimal) costs.</p>

<p>What's that? You don't care what it costs because no one can put a value on saving a human life? Heard of opportunity cost? Taxpayers' money we waste on excessive counter-terrorism measures is money we can't spend reducing the gap between white and indigenous health -- or, if that doesn't appeal, on buying Olympic medals.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=HIz7L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=HIz7L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=8TfcL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=8TfcL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 12 Sep 2008 02:32:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/measures involves costs">measures involves costs</category>
      <category domain="http://securityratty.com/tag/costs">costs</category>
      <category domain="http://securityratty.com/tag/measures">measures</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/benefits">benefits</category>
      <category domain="http://securityratty.com/tag/produce benefits">produce benefits</category>
      <category domain="http://securityratty.com/tag/pro-active measures">pro-active measures</category>
      <category domain="http://securityratty.com/tag/entail costs">entail costs</category>
      <category domain="http://securityratty.com/tag/additional defensive measures">additional defensive measures</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/costbenefit_of.html">Cost/Benefit of Terrorism Security</source>
    </item>
    <item>
      <title><![CDATA[PCI V1.2, a good start but still not enough]]></title>
      <link>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</link>
      <guid>http://securityratty.com/article/b3d495f448e9ce368683c921d97b7c28</guid>
      <description><![CDATA[Blogger: Randall Gamby
Two weeks ago the PCI Security Standards Council released the preliminary details of the PCI Data Security Standard (DSS) V1.2 thats due out in October. While many Analysts and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>Two weeks ago the PCI Security Standards Council released the preliminary details of the <a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">PCI Data Security Standard (DSS) V1.2</a> that’s due out in October.&nbsp; While many Analysts and Reporters have already written on the topic (I’ll be releasing an extensive update on Burton Group’s PCI coverage around the October release date), they really haven’t commented on what’s still not been addressed by the standard for enterprises still working on attaining compliance.</p>

<p>While I applaud the PCI Security Standards Council in further clarifying and adjusting the standard, a lot of work still needs to be done.&nbsp; I receive about one or two PCI questions a week from our clients and they seem to revolve around a couple of topics I’ve yet to see addressed:</p>

<ul><li><strong>Guidelines for selecting a Qualified Security Assessor (QSA)</strong> – while there are a large number of QSA organizations listed on the PCI Security Standards Council web site; they can’t really recommend a particular QSA for an individual organization.&nbsp; This leads a lot of organizations to struggle with determining what criteria they should use in selecting a QSA for their certification.</li>

<li><strong>The role of the QSA</strong> – organizations are also still trying to understand the role of a QSA.&nbsp; Should they get a QSA involved in the gap and remediation process in advance of certification?&nbsp; If so, should it be the same QSA that will do their certification (knowing there’s a risk that the QSA will be pre-disposed to only care about certain vulnerabilities)?</li>

<li><strong>Industry-specific best practices</strong> – while each organization may have different infrastructures, in general, most industries try to be consistent with the major functions they perform.&nbsp; So are credit card transactions handled differently between say, a major retailer with 10,000 POS systems and an insurance company that has hundreds of independent agents receiving remittances? Probably, so what are best practices around these industry-specific configurations?</li>

<li><strong>Virtualized environments</strong> – while the PCI Security Standards Council recognizes that some organizations have moved to virtual services for consolidation and management, the DSS really doesn’t provide guidelines for QSAs to evaluate and certify these environments.</li>

<li><strong>Monitoring and audit</strong> – while the PCI DSS recommends minimum timeframes for scanning, doing pen tests, etc. what are the real levels of monitoring and audit needed for ensuring security?&nbsp; With the Hannaford and Okemo breaches that occurred (both where PCI compliant), neither discovered the problem until months after the breaches had happened.&nbsp; So identifying what should be scanned and tested and if some of this should be on a continuous basis still requires refinement.</li>

<li><strong>PCI as part of an overall security model</strong> – what are the best practices around merging PCI security requirements into an enterprise’s overall security model?&nbsp; Should it be maintained separately? Should some components be integrated with similar security mechanisms?&nbsp; Should PCI be at the top of the security model and other configurations be based upon its requirements?&nbsp; There are really no answers coming forth on this topic and the other question is where will they come from? Surely enterprises won’t expect the PCI Security Standards Council to tell them how to run their security services.</li></ul>

<p>I will be providing Burton Group’s perspective on most of these questions in my upcoming report, but rather than relying on third parties to resolve these, I’d hope that the PCI Security Standards Council will be able to continue to provide answers to the questions they can in future updates, and releases, of the PCI DSS.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/382655858" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:56:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security assessor">security assessor</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/dss">dss</category>
      <category domain="http://securityratty.com/tag/pci security requirements">pci security requirements</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/qsa">qsa</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/382655858/pci-v12-a-good.html">PCI V1.2, a good start but still not enough</source>
    </item>
  </channel>
</rss>
