<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: happy]]></title>
    <link>http://securityratty.com/tag/happy</link>
    <description></description>
    <pubDate>Thu, 07 Aug 2008 11:45:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[They give you love unconditionally, give it back!]]></title>
      <link>http://securityratty.com/article/dc79d741eec08cebd598608ce1b0df41</link>
      <guid>http://securityratty.com/article/dc79d741eec08cebd598608ce1b0df41</guid>
      <description><![CDATA[Just a lil blurb for this great volunteer organization that gets animals that are doomed to die from shelters and finds them homes


clipped from www.petfinder.com

Trails of Happy Tails


Trails of...]]></description>
      <content:encoded><![CDATA[<div > Just a lil blurb for this great volunteer organization that gets animals that are doomed to die from shelters and finds them homes. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/DD6AE7C0-7D1E-484A-ABDE-857905DAF31D/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/fb6874a3-c9f8-4878-85f9-353d9fab0934/DD6AE7C0-7D1E-484A-ABDE-857905DAF31D/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.petfinder.com/shelters/CA1191.html" href="http://www.petfinder.com/shelters/CA1191.html" style="font-size: 11px;">www.petfinder.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.petfinder.com/shelters/CA1191.html -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Trails of Happy Tails</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.petfinder.com/shelters/CA1191.html --><br />
Trails of Happy Tails is a 501c3 non-profit animal rescue organization strictly ran by volunteers.  We mainly rescue dogs and cats from the Merced County Animal Shelter.   We work with many different rescue groups throughout the state, placing thousands of abandoned, neglected, and unwanted animals.  We&#8217;ve reduced the euthanasia rate from 70% to 35%.</td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/DD6AE7C0-7D1E-484A-ABDE-857905DAF31D/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 11:00:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/happy tails">happy tails</category>
      <category domain="http://securityratty.com/tag/rescue dogs">rescue dogs</category>
      <category domain="http://securityratty.com/tag/county animal shelter">county animal shelter</category>
      <category domain="http://securityratty.com/tag/rescue">rescue</category>
      <category domain="http://securityratty.com/tag/trails">trails</category>
      <category domain="http://securityratty.com/tag/volunteer organization">volunteer organization</category>
      <category domain="http://securityratty.com/tag/animals">animals</category>
      <category domain="http://securityratty.com/tag/lil blurb">lil blurb</category>
      <category domain="http://securityratty.com/tag/thousands">thousands</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=588">They give you love unconditionally, give it back!</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogic Makes it Onto the Inc 500 List of Fastest-Growing Private Companies in US]]></title>
      <link>http://securityratty.com/article/13adee3492b3b68c7eae4ade342986fb</link>
      <guid>http://securityratty.com/article/13adee3492b3b68c7eae4ade342986fb</guid>
      <description><![CDATA[Just the facts maam
Rank on Inc. 500: #350
Three-year revenue growth: 840
Rank on Top 100 DC-area companies: #27
DC area ranked #1 for most companies on the Inc. 500 list; #2 for most companies on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/08/inc500-logo.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="203" alt="inc500_logo" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/inc500-logo-thumb.jpg" width="244" border="0"></a> </p>
<p>Just <a href="link http://www.inc.com/inc5000/2008/articles/introduction.html" target="_blank">the facts</a> ma’am:</p>
<ul>
<li><a href="link to http://www.inc.com/inc5000/2008/company-profile.html?id=200803500" target="_blank">Rank on Inc. 500: #350</a>
<li>Three-year revenue growth: 840%
<li><a href="http://www.inc.com/inc5000/2008/lists/washington-arlington-alexandria-dc-va-md-wv.html?o=0&amp;c=200803500" target="_blank">Rank on Top 100 DC-area companies: #27</a>
<li>DC area ranked #1 for most companies on the Inc. 500 list; #2 for most companies on the Inc. 5000 list (behind NYC)
<li>2<sup>nd</sup> fastest-growing software company in the DC area (Note: we got categorized as IT Services but of course we really fall under “Software”. They never seem to have a “Technology Appliances” category…)</li>
</ul>
<p><a href="http://www.sciencelogic.com/pressrelease_20080820.htm" target="_blank">Read the full press release here</a>.
<p>We’re loving it because of the awards we’ve applied for over the last few years and haven’t won. (Or maybe only I care about this since I had to fill out all those applications. Hmmm, I’m sensing a pattern here…) But in this case, it’s all about the numbers.
<p>We love this part of our story because it comes down to customers actually believing in you and your product enough to plunk down the money – and keep coming back for more once you prove yourself the first time. It’s not about the hype or the latest flash in the pan or “sponsorship” or how much money some VC gives you. It comes down to you, your product and your happy customers.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:45:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/dc-area companies">dc-area companies</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/software company">software company</category>
      <category domain="http://securityratty.com/tag/happy customers">happy customers</category>
      <category domain="http://securityratty.com/tag/three-year revenue growth">three-year revenue growth</category>
      <category domain="http://securityratty.com/tag/technology appliances category">technology appliances category</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <source url="http://blog.sciencelogic.com/sciencelogic-makes-it-onto-the-inc-500-list-of-fastest-growing-private-companies-in-us/08/2008">ScienceLogic Makes it Onto the Inc 500 List of Fastest-Growing Private Companies in US</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hacking Injunction Lifted]]></title>
      <link>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</link>
      <guid>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</guid>
      <description><![CDATA[Earlier today, the US District Court dealt a victory to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at...]]></description>
      <content:encoded><![CDATA[<p>Earlier today, the US District Court <a href="http://www.eff.org/press/archives/2008/08/19">dealt a victory</a> to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at <a href="http://defcon.org/">DEFCON 16</a>.  In summary:</p>
<blockquote><p>The lawsuit claimed that the students&#8217; planned presentation would violate the Computer Fraud and Abuse Act (CFAA) by enabling others to defraud the MBTA of transit fares. A different federal judge, meeting in a special Saturday session, ordered the trio not to disclose for ten days any information that could be used by others to get free subway rides.</p>
<p>&#8220;The judge today correctly found that it was unlikely that the CFAA would apply to security researchers giving an academic talk,&#8221; said EFF Staff Attorney Marcia Hofmann. &#8220;A presentation at a security conference is not some sort of computer intrusion. It&#8217;s protected speech and vital to the free flow of information about computer security vulnerabilities. Silencing researchers does not improve security &#8212; the vulnerability was there before the students discovered it and would remain in place regardless of whether the students publicly discussed it or not.&#8221;</p></blockquote>
<p>This sets a good precedent for future cases, and perhaps next time a similar situation arises, a judge will not be so quick to issue a gag order.  It&#8217;s not a happy ending yet though, as the <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/mbta-v-anderson-complaint.pdf">original lawsuit</a> is still in effect.</p>
<p>As Chris Wysopal <a href="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">pointed out last week</a>, the MBTA&#8217;s ire is misdirected.  Rather than suing the vendor who sold them the defective system, they sued and attempted to silence the students who discovered the weakness.  This is 2008, not 1988 &#8212; did they honestly think a gag order would prevent the information from reaching the general public?   The DEFCON presentation was already available on the <a href="http://en.wikipedia.org/wiki/Series_of_tubes">Intertubes</a> prior to the injunction being issued, and the MBTA attorneys included a copy of the confidential whitepaper with their filing, thereby making it public.  </p>
<p>I guess you wouldn&#8217;t expect that a transit authority would have paid any attention to the<a href="http://www.schneier.com/blog/archives/2005/07/cisco_harasses.html">Ciscogate fiasco</a> from a few years ago. <a href="http://cryptome.org/lynn-cisco-jpg.htm">That presentation</a> never got out either, did it?  All that taxpayer money the MBTA spent on ridiculous lawsuits and restraining orders could have been put toward fixing the security flaws.  What a concept.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 01:49:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mbta">mbta</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/students publicly">students publicly</category>
      <category domain="http://securityratty.com/tag/defcon presentation">defcon presentation</category>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/mbta hackers">mbta hackers</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/judge">judge</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/">MBTA Hacking Injunction Lifted</source>
    </item>
    <item>
      <title><![CDATA[Spammers Take A Cheap Shot...]]></title>
      <link>http://securityratty.com/article/2bd234de99d23ff4b013abce95e7d324</link>
      <guid>http://securityratty.com/article/2bd234de99d23ff4b013abce95e7d324</guid>
      <description><![CDATA[I'm on holiday this week, but thought I'd better give this a mention anyway (plus, when did being on holiday ever stop me from posting stuff on blogs, right

I was surprised to see this posted to the...]]></description>
      <content:encoded><![CDATA[
        I'm on holiday this week, but thought I'd better give this a mention anyway (plus, when did being on holiday ever stop me from posting stuff on blogs, right?)<br /><br />I was surprised to see this posted to the comments section of the <a href="http://sunbeltblog.blogspot.com/">Sunbelt Blog</a>:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spgspam1.gif" src="http://blog.spywareguide.com/images/spgspam1.gif" class="mt-image-none" style="" height="144" width="359" /></span><br /> <div><br />I was about as surprised as The Dean was!<br /><br />To quote a further post from The Dean:<br /><br /><i>"Well, that's weird. Isn't spywareguide Paperghost's blog? I know he
wouldn't spam here. And, the link on the first comment goes to a 404
page."</i><br /><br />So, we have someone spamming with broken English, dropping links to 404 pages on Spywareguide. Curious.<br /><br />Now, I did have some suspicions on this - for starters, the recent blogs regarding the pirate movie websites that pop Zango installers just hit a few <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=privacy&amp;articleId=9112881&amp;taxonomyId=84&amp;intsrc=kc_top">news</a> <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">websites</a>. As <a href="http://blog.spywareguide.com/2008/08/another-site-hiding-pirate-mov.html">this article</a> mentions, a lot of the sites involved in this are from Asian regions - China, Indonesia etc. I couldn't help but notice the name of the poster was "Tam" - a common name in certain parts of Asia.<br /><br />Coincidence? Or a possible affiliate not too happy about this being highlighted? Well, a quick email later and the results for the spammer are in:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spgspam2.gif" src="http://blog.spywareguide.com/images/spgspam2.gif" class="mt-image-none" style="" height="185" width="430" /></span>
<br /><br />A potentially forged Reverse DNS aside, it's a strange thing indeed that they just happen to resolve to Vietnam given that a good portion of these sites are in Asia, isn't it?<br /><br />I think I'll see if any are owned by someone called "Tam".<br /><br />When I return from my holiday, of course....<br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 10:24:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/holiday">holiday</category>
      <category domain="http://securityratty.com/tag/pop zango installers">pop zango installers</category>
      <category domain="http://securityratty.com/tag/sunbelt blog">sunbelt blog</category>
      <category domain="http://securityratty.com/tag/blogs">blogs</category>
      <category domain="http://securityratty.com/tag/spywareguide paperghost">spywareguide paperghost</category>
      <category domain="http://securityratty.com/tag/recent blogs">recent blogs</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/spywareguide">spywareguide</category>
      <category domain="http://securityratty.com/tag/news websites">news websites</category>
      <source url="http://blog.spywareguide.com/2008/08/spammers-take-a-cheap-shot.html">Spammers Take A Cheap Shot...</source>
    </item>
    <item>
      <title><![CDATA[Memo to the President]]></title>
      <link>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</link>
      <guid>http://securityratty.com/article/f55b7cd26cfc6057b3118e4828224bba</guid>
      <description><![CDATA[Obama has a cyber security plan
It's basically what you would expect : Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure,...]]></description>
      <content:encoded><![CDATA[<p>Obama has a cyber security plan.</p>

<p>It's basically what <a href="http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.php">you</a> would <a href="http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php">expect</a>: Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure, spend money on enforcement, establish national standards for securing personal data and data-breach disclosure, and work with industry and academia to develop a bunch of needed technologies.</p>

<p>I could comment on the plan, but with security the devil is always in the details -- and, of course, at this point there are few details.  But since he brought up the topic -- McCain supposedly is "<a href="http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/article/112566/">working on the issues</a>" as well -- I have three pieces of policy advice for the next president, whoever he is. They're too detailed for campaign speeches or even position papers, but they're essential for improving information security in our society.  Actually, they apply to national security in general.  And they're things only government can do.</p>

<p>One, use your immense buying power to improve the security of commercial products and services. One property of technological products is that most of the cost is in the development of the product rather than the production. Think software: The first copy costs millions, but the second copy is free.</p></p>

<p>You have to secure your own government networks, military and civilian. You have to buy computers for all your government employees. Consolidate those contracts, and start putting explicit security requirements into the RFPs. You have the buying power to get your vendors to make serious security improvements in the products and services they sell to the government, and then we all benefit because they'll include those improvements in the same products and services they sell to the rest of us. We're all safer if information technology is more secure, even though the bad guys can <a href="http://www.schneier.com/blog/archives/2008/05/dualuse_technol_1.html">use it, too</a>.

<p>Two, <a href="http://www.schneier.com/essay-141.html">legislate results and not methodologies</a>. There are a lot of areas in security where you need to pass laws, where the <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">security externalities</a> are such that the market fails to provide adequate security. For example, software companies who sell insecure products are exploiting an externality just as much as chemical plants that dump waste into the river. But a bad law is worse than no law. A law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not.  <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security"> Mandating</a> <a href="http://www.schneier.com/essay-025.html">software</a> <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">liabilities</a> for software failures is <a href=http://www.schneier.com/essay-116.html">good</a>, detailing how is not. Legislate for the results you want and implement the appropriate penalties; let the market figure out how -- that's what markets are good at.  </p>

<p>Three, broadly invest in research. Basic research is risky; it doesn't always pay off. That's why companies have stopped funding it. Bell Labs is gone because nobody could afford it after the AT&T breakup, but the root cause was a desire for higher efficiency and short-term profitability -- not unreasonable in an unregulated business. Government research can be used to balance that by funding long-term research.  </p>

<p>Spread those research dollars wide. Lately, most research money has been <a href="http://query.nytimes.com/gst/fullpage.html?res=9F04E1DB113FF931A35757C0A9639C8B63">redirected</a> through DARPA to near-term military-related projects; that's not good. Keep the earmark-happy Congress from <a href="http://www.ostp.gov/pdf/1pger_earmark.pdf">dictating</a> how the money is spent. Let the NSF, NIH and other funding agencies decide how to spend the money and don't try to micromanage.  Give the national laboratories lots of freedom, too. Yes, some research will sound silly to a layman. But you can't predict what will be useful for what, and if funding is really peer-reviewed, the average results will be much better. Compared to corporate tax breaks and other subsidies, this is chump change.</p>

<p>If our research capability is to remain vibrant, we need more science and math students with decent elementary and high school preparation. The declining interest is partly from the perception that scientists don't get rich like lawyers and dentists and stockbrokers, but also because science isn't valued in a country full of creationists. One way the president can help is by trusting scientific advisers and not overruling them for political reasons.</p>

<p>Oh, and get rid of those post-9/11 restrictions on student visas that are <a href="http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.pdf">causing</a> (.pdf) so many top students to do their graduate work in Canada, Europe and Asia instead of in the United States. Those restrictions will <a href="http://www.aau.edu/research/Gast.pdf">hurt us</a> immensely in the long run.</p>

<p>Those are the three big ones; the rest is in the details. And it's the details that matter. There are lots of serious issues that you're going to have to tackle: data privacy, data sharing, data mining, government eavesdropping, government databases, use of Social Security numbers as identifiers, and so on. It's not enough to get the broad policy goals right. You can have good intentions and enact a good law, and have the whole thing completely gutted by two sentences sneaked in during rulemaking by some lobbyist.</p>

<p>Security is both subtle and complex, and -- unfortunately -- it doesn't readily lend itself to normal legislative processes. You're used to finding consensus, but security by consensus rarely works. On the internet, security standards are much worse when they're developed by a consensus body, and much better when someone just does them. This doesn't always work -- a lot of crap security has come from companies that have "just done it" -- but nothing but mediocre standards come from consensus bodies.  The point is that you won't get good security without pissing someone off: The information broker industry, the voting machine industry, the telcos. The normal legislative process makes it hard to get security right, which is why I don't have much optimism about what you can get done.</p>

<p>And if you're going to appoint a cyber security czar, you have to give him actual budgetary authority -- otherwise he won't be able to get anything done, either.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/08/securitymatters_0807">originally appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=LZGCXK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=LZGCXK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=56vyIK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=56vyIK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 02:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/security improvements">security improvements</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/government research">government research</category>
      <category domain="http://securityratty.com/tag/cyber security plan">cyber security plan</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/memo_to_the_pre.html">Memo to the President</source>
    </item>
    <item>
      <title><![CDATA[From one geek to another, back up your data!]]></title>
      <link>http://securityratty.com/article/fdb53a2502a0c3d137a21f96b877f364</link>
      <guid>http://securityratty.com/article/fdb53a2502a0c3d137a21f96b877f364</guid>
      <description><![CDATA[Hello all, hope all is well
Last week my wifes puter went BSOD. I ended up doing the Ghost restore back to day one. As I began to put her puter back together with her favorite programs, I hoped she...]]></description>
      <content:encoded><![CDATA[<p>Hello all, hope all is well.</p>
<p>Last week my wifes puter went BSOD. I ended up doing the Ghost restore back to day one. As I began to put her puter back together with her favorite programs, I hoped she had a current backup of her emails and Firefox favs put away somewhere.</p>
<p>She did! I was a happy toad! But for some reason, the backups were not compatible with the restore options with Firefox and Thunderbird.</p>
<p>So she lost all her emails for the last 2 months. The Firefox favs and settings are not a worry so much, but those emails she lost, sad.</p>
<p>So I come to you today thru the zeros and ones of the Internet to tell you,,,,,</p>
<p>Back up you data and make sure the restore options will work. Now I use Mozy and Ive had to do a restore with it in the past and it works great. So dont just be satisfied that you have backups, make sure the restore will work! Try it out. Do a backup and then right away, restore the data and check it.</p>
<p>Heres the <a title="Mozy" href="http://www.mozy.com/?ref=3f9a896b&amp;kbid=38419&amp;m=4&amp;i=77" target="_blank">Mozy</a> link I promote on <a title="SpywareBiz.com" href="http://www.spywarebiz.com/" target="_blank">SpywareBiz.com</a>, give it a try.</p>
]]></content:encoded>
      <pubDate>Sat, 09 Aug 2008 12:02:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/restore">restore</category>
      <category domain="http://securityratty.com/tag/ghost restore">ghost restore</category>
      <category domain="http://securityratty.com/tag/restore options">restore options</category>
      <category domain="http://securityratty.com/tag/firefox favs">firefox favs</category>
      <category domain="http://securityratty.com/tag/firefox">firefox</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/mozy link">mozy link</category>
      <category domain="http://securityratty.com/tag/current backup">current backup</category>
      <category domain="http://securityratty.com/tag/wifes puter">wifes puter</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=544">From one geek to another, back up your data!</source>
    </item>
    <item>
      <title><![CDATA[Black Hat wrap up - secure@microsoft, booth babes and bloggers]]></title>
      <link>http://securityratty.com/article/bd7d7b3698d05a16a10cc4d0a21e2bfd</link>
      <guid>http://securityratty.com/article/bd7d7b3698d05a16a10cc4d0a21e2bfd</guid>
      <description><![CDATA[You can read plenty of other blogs about some of the great presentations at Black Hat. So I thought I would take another angle and talk about some of the other stuff that may be important to you
1....]]></description>
      <content:encoded><![CDATA[<p></p>  <p>You can read plenty of other blogs about some of the great presentations at Black Hat.  So I thought I would take another angle and talk about some of the other stuff that may be important to you.</p>  <p>1.  <a href="mailto:secure@microsoft.com"><font face="Courier"><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/Picture%20049.jpg"><img title="Picture 049" style="border-right: 0px; border-top: 0px; margin: 5px 10px 5px 0px; border-left: 0px; border-bottom: 0px" height="184" alt="Picture 049" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/Picture%20049_thumb.jpg" width="244" align="left" border="0"></img></a></font><font face="Courier New">secure@microsoft.com</font></a> – This years hottest party was again the Microsoft party.  This year it was at the LAX club in the Luxor.  As usual there were quite a number of people at the door who thought they could talk their way in or worse yet were told they “were one the list”.  I was happy to be able to go and saw many of the usual suspects there as well. I had to leave the party early to go catch my red eye flight home, so went right to the airport from the party.  As I wrote earlier, Microsoft is trying really hard on security.  But I couldn’t help but notice the irony of this grainy, lousy picture of the DJ booth at the party.  If you can, notice the computers that the <a href="mailto:secure@microsoft.com">secure@microsoft.com</a> DJs are using. That’s right they are Macs!</p>  <p>2. A new low for booth babes – What would a Shimel review of a trade show be without a booth babe rant.  Hey I recognize it is Vegas and all, but EdgeOS went way over the line this year.  A booth babe dressed as a Las Vegas showgirl or some other type of costume makes a statement.  I personally don’t like exploiting woman to make that statement, but I understand.  However, these guys had woman who were dressed so raunchy and classless, that I could not bring myself to post a picture of them.  Come on guys!  You want to resort to the booth babe thing (and BTW I think the Black Hat crowd does not respond to that), at least have a little class.  These girls looked like street walkers and do you and your company no favors.  Is that really the image you want to promote?  Grow up!</p>  <p>3.  The Security Bloggers Network – We are back!  With the end of the Black Hat show, the SBN is going back to being the<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/securitybloggers.gif"><img title="securitybloggers" style="margin: 5px 5px 5px 10px" height="147" alt="securitybloggers" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/securitybloggers_thumb.gif" width="112" align="right" border="0"></img></a> SBN.  The old logo is back and our promotion with Black Hat is at an end.  However, I want to personally thank so many of you SBN members who blogged about Black Hat.  The Black Hat marketing folks made it a point to come over to me and thank us for the overwhelming support and help of the community.  Our network delivered big time with them and they are already thinking about ways we can work together next year.  I will keep you all posted on that.</p>  <p>We have several new promotions we are working on with the SBN and will have more on that soon. Also, we learned some valuable lessons.  Next time we will work with the network members more closely in doing these affiliations.  Also, for any show like this we need to have an official bloggers get together.  Not because we don’t want to buy our own drinks (thanks to Chris Hoff for doing more than his share in picking up a big bar tab), but frankly we need to reserve a place that has enough space for us.  Security bloggers are big time. We have a great community of people who get together. Lets make it better.</p>  <p>I have some other ideas around the SBN I am working on too and want to form a committee to help. If you are a member and want to get involved, please drop me a line or comment.</p>  <p>Anyway, another year of Black Hat is in the books. It was a good one and I can’t wait until next year!</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=mqB9CC"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=mqB9CC" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=rP6xlK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=rP6xlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=fhzqOK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=fhzqOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=roBQzK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=roBQzK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=yW5ceK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=yW5ceK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=zosCbk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=zosCbk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=XDP8lk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=XDP8lk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/359668026" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:46:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/booth">booth</category>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/booth babes">booth babes</category>
      <category domain="http://securityratty.com/tag/booth babe rant">booth babe rant</category>
      <category domain="http://securityratty.com/tag/black hat crowd">black hat crowd</category>
      <category domain="http://securityratty.com/tag/security bloggers network">security bloggers network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/security bloggers">security bloggers</category>
      <category domain="http://securityratty.com/tag/booth babe">booth babe</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/359668026/black-hat-wrap.html">Black Hat wrap up - secure@microsoft, booth babes and bloggers</source>
    </item>
    <item>
      <title><![CDATA[Listening to the evidence]]></title>
      <link>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</link>
      <guid>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</guid>
      <description><![CDATA[Last week the House of Commons Culture, Media and Sport Select Committee published a report of their inquiry into Harmful content on the Internet and in video games . They make a number of...]]></description>
      <content:encoded><![CDATA[<p>Last week the <a href="http://www.parliament.uk/parliamentary_committees/culture__media_and_sport.cfm">House of Commons Culture, Media and Sport Select Committee</a> published a report of their inquiry into &#8220;<a href="http://www.publications.parliament.uk/pa/cm200708/cmselect/cmcumeds/353/353.pdf">Harmful content on the Internet and in video games</a>&#8220;. They make a number of recommendations including a self-regulatory body to set rules for Internet companies to force them to protect users; that sites should provide a &#8220;watershed&#8221; so that grown-up material cannot be viewed before 9pm; that YouTube should screen material for forbidden content; that &#8220;<a href="http://www.spiked-online.com/index.php?/site/article/4633/">suicide websites</a>&#8221; should be blocked; that ISPs should be forced to block child sexual abuse image websites whatever the cost, and that blocking of bad content was generally desirable.</p>
<p>You will discern a certain amount of enthusiasm for blocking, and for a &#8220;<a href="http://www.yes-minister.com/polterms.htm#Politicians">something must be done</a>&#8221; approach. However, in coming to their conclusions, they do not, in my view, seem to have listened too hard to the evidence, or sought out expertise elsewhere in the world&#8230;<br />
<span id="more-351"></span><br />
Google/YouTube told them that 10 hours of video was posted every minute, and the amount is increasing. In the oral evidence session an MP helpfully suggested: &#8220;That video content is tagged. You do not need to look at every single minute of video content. Surely you could have people who would look at the video content which is tagged with labels which suggest it could be inappropriate.&#8221; Of course &#8220;<a href="http://lostria.blogspot.com/2008/01/fertility-slaps.html">happy_slapping.wmv</a>&#8221; or &#8220;<a href="http://www.phrases.org.uk/meanings/bunny-boiler.html">fluffy_bunnies.avi</a>&#8221; must always contain exactly what it says on the tin (<a href="http://en.wikipedia.org/wiki/Not%21">not!</a>) but unaccountably Google said it was a &#8220;fair suggestion&#8221;, so perhaps my cynicism is misplaced.</p>
<p>However, back to blocking.</p>
<p>I submitted <a href="http://www.cl.cam.ac.uk/~rnc1/080129-cms.pdf">some evidence of my own</a>, which the committee summarised, reasonably accurately:</p>
<blockquote><p>Dr Richard Clayton, a researcher in the Security Group of the Computer Laboratory at Cambridge University and author of several academic papers on methods for blocking access to Internet content, pointed out that there was no single blocking method which was both inexpensive and discerning enough to block access to only one part of a large website (such as FaceBook). In his view, the fatal flaw of all network-level blocking schemes was the ease with which they could be overcome, either by encrypting content or by the use of proxy services hosted outside the UK.</p></blockquote>
<p>The committee&#8217;s conclusion, having read this was:</p>
<blockquote><p>At a time of rapid technological change, it is difficult to judge whether blocking access to Internet content at network level by Internet service providers is likely to become ineffective in the near future. However, this is not a reason for not doing so while it is still effective for the overwhelming majority of users.</p></blockquote>
<p>which I suppose logically means that the committee thinks that blocking should now be discarded as a policy option &#8212; but somehow I think that isn&#8217;t their intended meaning.</p>
<p>The Committee should perhaps have a look at <a href="http://www.acma.gov.au/webwr/_assets/main/lib310554/isp-level_internet_content_filtering_trial-report.pdf">this Australian report</a>, which found that ISP level content filtering (and in Australia the politicians want to use ISP level filtering to provide a child-friendly Internet) did work (up to a point) at Tier 3 (the smallest) ISPs. The <a href="http://en.wikiquote.org/wiki/Evelyn_Waugh#Scoop_.281938.29">up-to-a-point</a> is that unlike previous tests the systems didn&#8217;t completely wreck the browsing experience by slowing it down. However, the systems blocked only 85-98% of illegal material and similar percentages of material suitable for adults but not for younger children. Interestingly some products were better at different categories.</p>
<p>Getting that many sites wrong is really quite significant, so it&#8217;s difficult to see this as a ringing endorsement for blocking the web. Additionally, the Australian report found that the blocking was useless on &#8220;non-web&#8221; protocols (such as peer-to-peer) and their report specifically didn&#8217;t consider cost, or ease of circumvention &#8212; so it&#8217;s not just UK politicians not wanting to consider evidence on that topic!</p>
<p>Finally, I should note that the Culture Media and Sport Committee has also ignored some rather more recent academic work. The MPs have put into their report that they were horrified to discover that child sexual abuse images took 24 hours to remove in the UK. What (should they ever learn of it) will they make of the recent discovery by <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and myself that shows that if the website is hosted abroad then <a href="http://www.lightbluetouchpaper.org/2008/06/11/slow-removal-of-child-sexual-abuse-image-websites/">a month is more to be expected</a>?</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 20:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/isp level content">isp level content</category>
      <category domain="http://securityratty.com/tag/video games">video games</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/bad content">bad content</category>
      <category domain="http://securityratty.com/tag/video content">video content</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/evidence">evidence</category>
      <category domain="http://securityratty.com/tag/child-friendly internet">child-friendly internet</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/08/listening-to-the-evidence/">Listening to the evidence</source>
    </item>
    <item>
      <title><![CDATA[The Four Horsemen of CLeopatra's Barge]]></title>
      <link>http://securityratty.com/article/1b20cf9bfdb87d0ef87e844686ac5d49</link>
      <guid>http://securityratty.com/article/1b20cf9bfdb87d0ef87e844686ac5d49</guid>
      <description><![CDATA[One of the more interesting session I went to yesterday was a talk by Chris Hoff called &quot; The Four Horsemen of the Virtualization Apocalypse .&quot; (If you've never read Hoff's blog, you should check it...]]></description>
      <content:encoded><![CDATA[<img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="151" alt="hoff-4horsemen" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/TheFourHorsemenofCLeopatrasBarge_AA28/hoff-4horsemen_3.png" width="200" align="left" border="0">  <p>One of the more interesting session I went to yesterday was a talk by <a href="http://rationalsecurity.typepad.com/about.html" target="_blank">Chris Hoff</a> called "<a href="https://www.blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Hoff">The Four Horsemen of the Virtualization Apocalypse</a>."&nbsp; (If you've never read Hoff's blog, you should check it out at <a title="http://rationalsecurity.typepad.com/" href="http://rationalsecurity.typepad.com/">http://rationalsecurity.typepad.com/</a>.)</p> <p>I thought I was keeping a close eye on security and virtualization issues, but this talk illustrated how wide and varied the topic really is.&nbsp; This was not about Blue Pill and it wasn't about having security monitors in the hypervisor - instead he focused on how virtualizing physical devices (e.g. switches, systems) will cause lots of problems for security architects and administrators.</p> <p>Briefly, here are the four horsemen:</p> <ul> <li>Conquest - Translating your physical capacity planning implementation to virtual devices probably won't work.  <li>Death - Virtualized networks lack several physical attributes assumed by security applications and high-availability devices today - you'll probably have to re-architect it all to get the same functionality, which might not even be possible in your new virtual world  <li>War - Adding security VAs takes away precious resources that could have been used to dynamically add VMs.&nbsp; It is a war of resources.  <li>Famine - With all of the redesigning and accommodation happening, security costs are going to eat into any savings you make on server consolidation.</li></ul> <p>Now, if you want to read the much more thorough version, see Hoff's original post <a href="http://rationalsecurity.typepad.com/blog/2008/04/the-four-horsem.html" target="_blank">here</a>.</p> <p>&nbsp;</p> <p>Okay, how does this all relate to the title of my post?&nbsp; Not much.&nbsp; However, <em><strong>much</strong></em> later on day one, things really started rolling.</p> <p>After being crowded out of the Shadow Bar, a bunch of us ended up over at <a href="http://www.vegas.com/nightlife/bars/casafuente.html">Casa Fuente</a> (A cigar bar in Caesars forum).&nbsp; Five minutes after arriving, someone spilled a drink in my lap, big fun!&nbsp; It turns out that it was <a href="http://www.stepto.com" target="_blank">Stepto's</a> birthday, and Hoff makes sure everyone has a drink and we all sing happy birthday to Stepto.&nbsp; Check out part of it, courtesy of <a href="http://blog.uncommonsensesecurity.com/" target="_blank">Jack Daniel</a>:</p> <p> <object type="application/x-shockwave-flash" height="300" width="400" data="http://www.flickr.com/apps/video/stewart.swf?v=55430" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000">     <embed type="application/x-shockwave-flash" src="http://www.flickr.com/apps/video/stewart.swf?v=55430" bgcolor="#000000" allowfullscreen="true" flashvars="intl_lang=en-us&amp;photo_secret=100e925a17&amp;photo_id=2742128920" height="300" width="400"></embed></object> </p> <p>Immediately after the toast, <a href="http://securityuncorked.squarespace.com/security-uncorked/">Jennifer Jabbusch</a> knocks over a table, falls to the floor and begins having a seizure. Stepto rushes over, trying to help, and just about that time, she flips over and starts laughing - total fakeout! Everybody bursts out laughing. </p> <p>Shortly after that, they closed for the night and kicked us out and we all headed over to Cleopatra's Barge. There weren't enough seats or tables for us, but I noticed that the "reserved" barge seating was empty. Drawing upon a clever technique (i.e. sometimes called "asking") I social engineered a waitress into letting us have the reserved area. Within mere minutes, several security geeks are on the dance floor, doing us proud. </p> <p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="260" alt="hoff-cleopatra2" src="http://blogs.technet.com/blogfiles/security/WindowsLiveWriter/TheFourHorsemenofCLeopatrasBarge_AA28/hoff-cleopatra2_6.jpg" width="200" align="right" border="0"></p> <p>This leads me to the Four Horsemen of Cleopatra's Barge.&nbsp; (Though I was out there too, I am excluding myself since simply because I can.)</p> <ul> <li>JJ, for leadership</li> <li>Hoff, who owned the dance floor.</li> <li>Ryan Naraine, for getting low, low, low</li> <li>David, for letting his hair down.</li></ul> <p>Though our collective dancing does not signal the end of the world, it certainly capped an excellent day</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3102312" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 16:36:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security architects">security architects</category>
      <category domain="http://securityratty.com/tag/security vas takes">security vas takes</category>
      <category domain="http://securityratty.com/tag/security geeks">security geeks</category>
      <category domain="http://securityratty.com/tag/security costs">security costs</category>
      <category domain="http://securityratty.com/tag/hoff">hoff</category>
      <category domain="http://securityratty.com/tag/chris hoff">chris hoff</category>
      <category domain="http://securityratty.com/tag/barge">barge</category>
      <category domain="http://securityratty.com/tag/floor">floor</category>
      <source url="http://blogs.technet.com/security/archive/2008/08/07/the-four-horsemen-of-cleopatra-s-barge.aspx">The Four Horsemen of CLeopatra's Barge</source>
    </item>
    <item>
      <title><![CDATA[Memo to Next President: How to Get Cyber Security Right]]></title>
      <link>http://securityratty.com/article/3cc71e9b8aab182bc3e96444e8660442</link>
      <guid>http://securityratty.com/article/3cc71e9b8aab182bc3e96444e8660442</guid>
      <description><![CDATA[Obama has a cyber security plan
It's basically what you would expect : Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure,...]]></description>
      <content:encoded><![CDATA[<p>
Obama has a cyber security plan.
</p><p>
It's basically what <a href="http://www.barackobama.com/2008/07/16/remarks_of_senator_barack_obam_95.php">you</a> would <a href="http://www.barackobama.com/2008/07/16/fact_sheet_obamas_new_plan_to.php">expect</a>: Appoint a national cyber security advisor, invest in math and science education, establish standards for critical infrastructure, spend money on enforcement, establish national standards for securing personal data and data-breach disclosure, and work with industry and academia to develop a bunch of needed technologies.
</p><p>
I could comment on the plan, but with security the devil is always in the details -- and, of course, at this point there are few details.  But since he brought up the topic -- McCain supposedly is "<a href="http://www.scmagazineus.com/Cybersecurity-and-the-presidential-campaign/article/112566/">working on the issues</a>" as well -- I have three pieces of policy advice for the next president, whoever he is. They're too detailed for campaign speeches or even position papers, but they're essential for improving information security in our society.  Actually, they apply to national security in general.  And they're things only government can do.
</p><p>
One, use your immense buying power to improve the security of commercial products and services. One property of technological products is that most of the cost is in the development of the product rather than the production. Think software: The first copy costs millions, but the second copy is free.</p>

<p>You have to secure your own government networks, military and civilian. You have to buy computers for all your government employees. Consolidate those contracts, and start putting explicit security requirements into the RFPs. You have the buying power to get your vendors to make serious security improvements in the products and services they sell to the government, and then we all benefit because they'll include those improvements in the same products and services they sell to the rest of us. We're all safer if information technology is more secure, even though the bad guys can <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/blog_securitymatters_0501 ">use it, too</a>.
</p>
<p>Two, <a href="http://www.schneier.com/essay-141.html">legislate results and not methodologies</a>. There are a lot of areas in security where you need to pass laws, where the <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">security externalities</a> are such that the market fails to provide adequate security. For example, software companies who sell insecure products are exploiting an externality just as much as chemical plants that dump waste into the river. But a bad law is worse than no law. A law requiring companies to secure personal data is good; a law specifying what technologies they should use to do so is not.  <a href="http://www.guardian.co.uk/technology/2008/jul/17/internet.security"> Mandating</a> software <a href="http://www.schneier.com/blog/archives/2007/01/information_sec_1.html">liabilities</a> for software failures is <a href=http://www.wired.com/politics/security/commentary/securitymatters/2006/06/71032">good</a>, detailing how is not. Legislate for the results you want and implement the appropriate penalties; let the market figure out how -- that's what markets are good at.  
</p><p>
Three, broadly invest in research. Basic research is risky; it doesn't always pay off. That's why companies have stopped funding it. Bell Labs is gone because nobody could afford it after the AT&T breakup, but the root cause was a desire for higher efficiency and short-term profitability -- not unreasonable in an unregulated business. Government research can be used to balance that by funding long-term research.  
</p><p>
Spread those research dollars wide. Lately, most research money has been <a href="http://query.nytimes.com/gst/fullpage.html?res=9F04E1DB113FF931A35757C0A9639C8B63">redirected</a> through DARPA to near-term military-related projects; that's not good. Keep the earmark-happy Congress from <a href="http://www.ostp.gov/pdf/1pger_earmark.pdf">dictating</a> (.pdf) how the money is spent. Let the NSF, NIH and other funding agencies decide how to spend the money and don't try to micromanage.  Give the national laboratories lots of freedom, too. Yes, some research will sound silly to a layman. But you can't predict what will be useful for what, and if funding is really peer-reviewed, the average results will be much better. Compared to corporate tax breaks and other subsidies, this is chump change.
</p><p>
If our research capability is to remain vibrant, we need more science and math students with decent elementary and high school preparation. The declining interest is partly from the perception that scientists don't get rich like lawyers and dentists and stockbrokers, but also because science isn't valued in a country full of creationists. One way the president can help is by trusting scientific advisers and not overruling them for political reasons.
</p><p>
Oh, and get rid of those post-9/11 restrictions on student visas that are <a href="http://www7.nationalacademies.org/visas/Statement%20on%20Visa%20Problems.pdf">causing</a> (.pdf) so many top students to do their graduate work in Canada, Europe and Asia instead of in the United States. Those restrictions will <a href="http://www.aau.edu/research/Gast.pdf">hurt us</a> (.pdf) immensely in the long run.
</p><p>
Those are the three big ones; the rest is in the details. And it's the details that matter. There are lots of serious issues that you're going to have to tackle: data privacy, data sharing, data mining, government eavesdropping, government databases, use of Social Security numbers as identifiers, and so on. It's not enough to get the broad policy goals right. You can have good intentions and enact a good law, and have the whole thing completely gutted by two sentences sneaked in during rulemaking by some lobbyist.
</p><p>
Security is both subtle and complex, and -- unfortunately -- it doesn't readily lend itself to normal legislative processes. You're used to finding consensus, but security by consensus rarely works. On the internet, security standards are much worse when they're developed by a consensus body, and much better when someone just does them. This doesn't always work -- a lot of crap security has come from companies that have "just done it" -- but nothing but mediocre standards come from consensus bodies.  The point is that you won't get good security without pissing someone off: The information broker industry, the voting machine industry, the telcos. The normal legislative process makes it hard to get security right, which is why I don't have much optimism about what you can get done.
</p><p>
And if you're going to appoint a cyber security czar, you have to give him actual budgetary authority -- otherwise he won't be able to get anything done, either.

<p>
---
</p>

<p><em>Bruce Schneier is chief security technology officer of BT, and author of </em>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<em>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=0ca9e7363b324d8d77996a8ec3f346da" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=0ca9e7363b324d8d77996a8ec3f346da" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=OUzpZK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=OUzpZK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jCsEfk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jCsEfk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Xtv7Xk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Xtv7Xk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ZOA0EK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ZOA0EK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=bpRgSK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=bpRgSK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=3GI8fk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=3GI8fk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=tfYGEk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=tfYGEk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Ed9rWK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Ed9rWK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/358550437" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/358550481" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security standards">security standards</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/security improvements">security improvements</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/cyber security plan">cyber security plan</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/government research">government research</category>
      <category domain="http://securityratty.com/tag/national security">national security</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/358550481/securitymatters_0807">Memo to Next President: How to Get Cyber Security Right</source>
    </item>
  </channel>
</rss>
