<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: hold]]></title>
    <link>http://securityratty.com/tag/hold</link>
    <description></description>
    <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Hosting Meets the Cloud Debate Part II]]></title>
      <link>http://securityratty.com/article/3a3393b304f09ea17d212e2f5b730d65</link>
      <guid>http://securityratty.com/article/3a3393b304f09ea17d212e2f5b730d65</guid>
      <description><![CDATA[I have to say that Part II of this session was much anticipated after the lively interaction yesterday. It turned out to be less of a debate and more like a fireside chat. (image from pro.corbis.com...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="220" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0024.jpg" width="323" align="left" border="0" />I have to say that Part II of this session was much anticipated after the lively interaction yesterday. It turned out to be less of a debate and more like a fireside chat. <a href="http://pro.corbis.com/images/CB042667.jpg?size=572&amp;uid=%7bDA13F798-FDA1-4B54-BFA9-4B15492E024F%7d" target="_blank">(image from pro.corbis.com)</a></p>
<p>The analysts paired up today:   <br />Antonio Piraino (<a href="http://www.t1r.com/" target="_blank">Tier1 Research</a>)    <br /><a href="http://the451group.com/about/bio_detail.php?eid=113" target="_blank">William Fellows</a> (<a href="http://the451group.com/" target="_blank">The 451 Group</a>)</p>
<p><em>My usual disclaimers on live-blogging: doesn&#8217;t include everything covered (just what was most interesting to me) and had to paraphrase some answers because I simply cannot type that fast. </em></p>
<p><strong>Quick definition of Cloud Computing     <br /></strong><strong>WF:</strong> The cloud is a continuum of grid, virtualization and utility done right. It is about provisioning services instead of servers; flexible computing instead of fixed assets. Done right, the cloud abstracts users from the complexity of grid. <a href="http://www.the451group.com/images/content/ice/ice_iceberg.jpg">Cloud computing is IT as a service</a>. Cloud computing is the Third Way &#8211; not entirely in-house or outsourced, but an optimized hybridized version of both. In light of the Goldman Sachs report out resetting IT spending forecast from up 6% to down 1%, don&#8217;t underestimate the ability for enterprises to move from capex to opex by buying cloud computing instead of building it themselves.</p>
<p>The 451 Group conducted a survey on cloud computing in March, and then revisited it a month ago. Some interesting results:</p>
<ul>
<li>84% have no plans to develop an internal cloud. 5% had no answer to this question. And for the 10% who did answer &#8211; the uses for a private/internal cloud were the same as those for a public cloud. </li>
<li>Top 6 vendors they look to help them develop an internal cloud: <a href="http://www.alleyinsider.com/2008/11/microsoft-s-smart-cloud-catch-up-plan-three-years-of-free-software-msft-" target="_blank">Microsoft</a>, <a href="http://topnews.in/ibm-expand-its-cloud-computing-efforts-285364" target="_blank">IBM</a>, Cisco, HP, Oracle, VMware </li>
</ul>
<p><strong><em>Is it all &#8220;upside&#8221; when it comes to cloud computing?       <br /></em></strong><strong>     <br />WF:</strong> Watch out for the Trojan horse, the red flag. What about the software needed to manage all this stuff? Any management software needs to take a holistic approach to solve the problem.</p>
<p><strong>AP:</strong> Increased management requirements and capability &#8211; this is actually a great story for managed hosters who can hold your hand while getting you up into the cloud. Hosters alleviate the pain points, and this is why we&#8217;re going to see continued growth and focus in the managed hosting sector.</p>
<p><strong>WF:</strong> I would argue that they&#8217;re too expensive. <a href="http://tech.blorge.com/Structure:%20/2008/10/25/amazons-ec2-cloud-moves-into-production/" target="_blank">Look at Amazon</a> &#8211; 10 cents a hit adds up.</p>
<p><strong>AP:</strong> It&#8217;s almost impossible to do an apples-to-apples comparison between cloud providers. One reason is that they charge differently. I&#8217;d say that when you&#8217;re talking about the big cloud providers, you are right &#8211; that they are expensive over the long-term, but for use in the short-term, they can be optimal.</p>
<p><strong>WF:</strong> The cloud is setting big expectations. Can IT deliver? It&#8217;s nice to talk about &#8220;shared resources for the greater good&#8221; but in any organization, you will still run into issues of power and control! Plus it&#8217;s still early days for resolution of regulatory issues and compliance around the cloud.</p>
<p><strong>Final Thoughts</strong></p>
<p><strong>AP:</strong> Think of the opportunities of using cloud computing resources in the areas of testing and pre-production &#8211; short-term use/environment (quick up/quick down), inexpensive, opex not capex. We&#8217;re already seeing the cloud fostering much innovation.</p>
<p><strong>WF:</strong> &#8220;It&#8217;s okay to fall in love with the term.&#8221; It is real but keep the expectations lower and realistic.</p>
<p><strong>AP:</strong> I agree with you. The reality is that the cloud is driving a very fundamental underlying platform change. This is not just a term or something that will fall out of fashion. There&#8217;s a real need to build trust in the cloud and leveraging shared resources in this way &#8211; so use the cloud computing term cautiously; don&#8217;t abuse it and make the cloud seem like IT&#8217;s new toy.</p>
]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 18:35:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/public cloud">public cloud</category>
      <category domain="http://securityratty.com/tag/cloud providers">cloud providers</category>
      <category domain="http://securityratty.com/tag/cloud abstracts users">cloud abstracts users</category>
      <category domain="http://securityratty.com/tag/privateinternal cloud">privateinternal cloud</category>
      <category domain="http://securityratty.com/tag/internal cloud">internal cloud</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/pre-production short-term useenvironment">pre-production short-term useenvironment</category>
      <category domain="http://securityratty.com/tag/short-term">short-term</category>
      <source url="http://blog.sciencelogic.com/hosting-meets-the-cloud-debate-part-ii/11/2008">Hosting Meets the Cloud Debate Part II</source>
    </item>
    <item>
      <title><![CDATA[Links List 10.31.08]]></title>
      <link>http://securityratty.com/article/9428945f69b50703993282159a9d8676</link>
      <guid>http://securityratty.com/article/9428945f69b50703993282159a9d8676</guid>
      <description><![CDATA[Happy Halloween

What an interesting time to hold a technology conference. The DLA Piper Global Technology Leaders Summit last week brought together CXOs from Amazon, Walmart.com, Stanford, Safeway,...]]></description>
      <content:encoded><![CDATA[<p><b>Happy Halloween!</b>
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/10/em7-pumpkin.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="184" alt="EM7_pumpkin" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/em7-pumpkin-thumb.jpg" width="244" border="0"></a>
<p>What an interesting time to hold a technology conference. The <a href="http://www.eweek.com/c/a/IT-Management/CxOs-Get-Together-for-Candid-OfftheRecord-Chat/?kc=EWKNLNAV10272008STR3" target="_blank">DLA Piper Global Technology Leaders Summit last week</a> brought together CXOs from Amazon, Walmart.com, Stanford, Safeway, Microsoft, Sun, Cisco and others to discuss the state of IT in general and how the economy is impacting it. Some highlights:<br />
<blockquote>
<p>&#8220;Cloud computing for large enterprises is a dead duck, in the opinion of several venture capital firms.&#8221;</p>
</blockquote>
<p>&nbsp;<br />
<blockquote>
<p>&#8220;The current slowdown in the U.S. macroeconomy is definitely going to hurt the IT industry, as it will most of the nation&#8217;s businesses, for at least the next year and most likely into the next two years.&#8221;</p>
</blockquote>
<p>&nbsp;
<p><a href="http://blogs.eweek.com/storage_station/content/general/netapp_cancels_first_user_conference_cites_travel_issues.html" target="_blank">NetApp cancelled its first user conference</a> slated for 2009 citing economy-driven restrictions on <a href="http://www.btnonline.com/businesstravelnews/headlines/frontpage_display.jsp?vnu_content_id=1003875472" target="_blank">business travel</a>.
<p>We recently wrote about the possible <a href="http://blog.sciencelogic.com/are-there-recession-proof-it-products/10/2008" target="_blank">upside for MSPs</a> in this economic downtown. A <a href="http://www.infoworld.com/article/08/10/29/Recession_set_to_boost_outsourcing_1.html?source=NLC-TB&amp;cgd=2008-10-30" target="_blank">survey from EquaTerra</a> of more than 200 outsourcing service suppliers announced that “more than 40 percent of those polled had seen increased demand levels, despite the economic downturn.” The survey suggests that outsourcing projects are changing, with a strong focus on quick return on investment replacing longer-term initiatives to improve end-to-end business processes, according to InfoWorld. So as we saw during <a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008" target="_blank">our own surveys</a> this year, it looks like IT will spend time and money against the practical projects that should and could get done and not taking on ITIL and CMDB projects.
<p>Jonathan Schwartz as a puppet talking about open source and his ponytail. The driest Sesame Street take-off you’ll ever see. Check out the <a href="http://www.techcrunchit.com/2008/10/14/continuous-partial-innovation/" target="_blank">video here</a>. For those of you playing a drinking game at home, “ponytail”.
<p>Denise Dubie <a href="http://www.networkworld.com/newsletters/nsm/2008/102708nsm2.html?nlhtnsm=ts_102908&amp;nladname=102908networksystemsmanagemental" target="_blank">posted a follow up</a> to her article <a href="http://www.networkworld.com/community/node/33996" target="_blank">Novell’s Managed Objects buy</a>, and shared insights from different commenters, including <a href="http://www.networkworld.com/community/node/33996#comment-191253" target="_blank">yours truly</a>.
<p>One of our favorites, the IT Skeptic was <a href="http://www.johnmwillis.com/itil/5-questions-for-the-itskeptic/" target="_blank">featured on John Willis’ blog</a> this week, answering some questions about CMDB, ITSMF and more. He also provided his insight into IBM Tivoli, although he “tries to stay non-partisan”.
<p>Inexplicable. HP posted <a href="http://blogs.wsj.com/biztech/2008/10/27/h-p-commercializes-halloween-with-monsters-that-speak-technobabble/" target="_blank">Halloween-themed videos about datacenters</a> on YouTube this week. Unlike the great <a href="http://www.youtube.com/watch?v=MSqXKp-00hM" target="_blank">IBM videos about the mainframe</a>, these videos speak techno-babble without tempering the lingo with being funny or tongue-in-cheek. Various frightening creatures share information on service management processes and discuss virtualization techniques to help consolidate hardware. Scary.</p>
]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 18:10:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/projects">projects</category>
      <category domain="http://securityratty.com/tag/practical projects">practical projects</category>
      <category domain="http://securityratty.com/tag/discuss virtualization techniques">discuss virtualization techniques</category>
      <category domain="http://securityratty.com/tag/discuss">discuss</category>
      <category domain="http://securityratty.com/tag/cmdb projects">cmdb projects</category>
      <category domain="http://securityratty.com/tag/cmdb">cmdb</category>
      <category domain="http://securityratty.com/tag/ibm videos">ibm videos</category>
      <category domain="http://securityratty.com/tag/videos">videos</category>
      <category domain="http://securityratty.com/tag/survey suggests">survey suggests</category>
      <source url="http://blog.sciencelogic.com/links-list-103108/10/2008">Links List 10.31.08</source>
    </item>
    <item>
      <title><![CDATA[Horrible Identity Theft Story]]></title>
      <link>http://securityratty.com/article/f6aa9e7e35ce5059c270859223c6299c</link>
      <guid>http://securityratty.com/article/f6aa9e7e35ce5059c270859223c6299c</guid>
      <description><![CDATA[This is a story of how smart people can be neutralized through stupid procedures. Here's the part of the story where some poor guy's account get's completely f-ed. This thief had been bounced to the...]]></description>
      <content:encoded><![CDATA[<p>This is a <a href="http://consumerist.com/5069018/how-outsourced-call-centers-are-costing-millions-in-identity-theft">story</a> of how smart people can be neutralized through stupid procedures.</p>

<blockquote>Here's the part of the story where some poor guy's account get's completely f-ed. This thief had been bounced to the out-sourced to security so often that he must have made a check list of any possible questions they would ask him. Through whatever means, he managed to get the answers to these questions. Now when he called, he could give us the information we were asking for, but by this point we knew his voice so well that we still tried to get him to security. It worked like this: We put him on hold and dial the extension for security. We get a security rep and start to explain the situation; we tell them he was able to give the right information, but that we know is the same guy that's been calling for weeks and we are certain he is not the account holder. They begrudgingly take the call. Minutes later another one of us gets a call from a security rep saying they are giving us a customer who has been cleared by them. And here the thief was back in our department. For those of us who had come to know him, the fight waged on night after night.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Sd5NM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Sd5NM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qFwaM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qFwaM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 09:10:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security rep">security rep</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/guy">guy</category>
      <category domain="http://securityratty.com/tag/account holder">account holder</category>
      <category domain="http://securityratty.com/tag/poor guy">poor guy</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/stupid procedures">stupid procedures</category>
      <category domain="http://securityratty.com/tag/call">call</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/horrible_identi.html">Horrible Identity Theft Story</source>
    </item>
    <item>
      <title><![CDATA[Phreaknic 12 (2008) Hacker Con]]></title>
      <link>http://securityratty.com/article/4f1c46cc8d2c53438d8656355e1bfa74</link>
      <guid>http://securityratty.com/article/4f1c46cc8d2c53438d8656355e1bfa74</guid>
      <description><![CDATA[New Video: Phreaknic 12 (2008) Hacker Con

This is a quick and dirty video documentary of the things that when on around the talks and event at Phreaknic 12 (2008). Don't watch if you get sick at...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</FONT></B></a>
<p></p>
<p>This is a quick and dirty video documentary of the things that when on around the talks and event at <a href="http://www.phreaknic.info">Phreaknic 12 </a>(2008). Don't watch if you get sick at shaky cam movies like Blair Witch or Cloverfield. A rough timeline of the content in the video is as follows: </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Intro and leaving Louisville with Brian. Morgellon talks about hacking the <a href="http://dailyduino.com/">Arduino</a> micro controller platform.&nbsp;Sorteal talks about the LiVes Open Source video editor. AT&amp;T Batman building by night. Mojo-JoJo soldering some stuff for the shooting range. The patron gods of hackerdom. Registration. Con swag overview. Morgellon&nbsp; gets his discreet logic on. AK-47 building with HandGrip and Buttstock. Froggy talks up Notacon, which I plan to go to next year. Skydog explains the Jware chair toss event, and then we compete. Rootwars hacker wargames. I ask <a href="http://dualcoremusic.com/nerdcore/">Int80 about using his nerdcore</a> music in some of my videos. NotLarry explains rootwars. Some iPhone hacking with <a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner. I do a little <a href="http://www.irongeek.com/i.php?page=security/bluecasing1">Bluecaseing/Warnibbling </a>with the Bluetooth on my Nokia n810. John, Lee, Brian and I go to the German restaurant. I blind DOSman with the light from my camera and check out what folks are doing with the <a href="http://dailyduino.com/">Arduinos</a> Droops brought for folks to play with. I check back in on R00tW4rz. I blind Droops. I talk Ettercap filters with <a href="http://www.rmccurdy.com/">operat0r</a>. USB door key fun with the <a href="http://dailyduino.com/">Arduino</a>. More breadboard fun. Nokia n810 + Ettercap Filter + Lemon-part = win. <a href="http://dualcoremusic.com/nerdcore/">Int80</a> gets down with his own bad self, and the rest of Phreaknic. I find an energy drink with protein. Folks play with the hardware keyloggers I brought, and we have some epic fail with the IBM Model M + USB adapter + Mac OS 10.5. <a href="http://www.winnschwartau.com/">Winn Schwartau</a> joins in on the keylogger fun. <a href="http://www.packetsniffers.org/">DOSman and Zack</a> use a directional antenna from the 9th floor to search downtown Nashville for WiFi access points. Zoom in on Al. John and Lee eat jerky. <a href="http://www.hak5.org/">Daren and Shannon from Hak5</a> blind me this time. :) Then they do a quick interview. I interview <a href="http://www.digome.com/">TRiP</a> about the legalities of wardriving, sniffing and leaving your access point open so you have plausible deniability of copyright infringement (most likely it won't hold water in court if you are a computer geek). I give Hak5 Daren beef jerky. <a href="http://www.offensive-security.com/">Ziplock</a> had more con badges than God. I meet up with Iridium. I talk with Nightcarnage about the audio/video setup at Phreaknic. As I predicted, the <a href="http://www.shmoo.com/~gdead/Site/Home.html">Potters</a> won the WiFi Race. I say why this was the best Phreaknic ever. Using green lasers on crack dealers. Techno in the dark, the Aiptek action HD does not do well in low light. Nicodemius shows off his Minority Report like multi-touch table. Hula hoop contest. I check back in with Jeff Cotton and his USB keyed door. I strap on my gear to leave the con. Brian and I do a wrap up of our thoughts on Phreaknic 2008.</p>
<p><a href="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/a"><img src="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/H4w0W-ygK2s" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 02:59:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/con">con</category>
      <category domain="http://securityratty.com/tag/phreaknic">phreaknic</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/con swag overview">con swag overview</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/sorteal talks">sorteal talks</category>
      <category domain="http://securityratty.com/tag/hacker con">hacker con</category>
      <category domain="http://securityratty.com/tag/lee eat jerky">lee eat jerky</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/H4w0W-ygK2s/i.php">Phreaknic 12 (2008) Hacker Con</source>
    </item>
    <item>
      <title><![CDATA[CLOUD COMPUTING - STORMY WEATHER?]]></title>
      <link>http://securityratty.com/article/197c984b8e2d41f0d4763ab1993fed11</link>
      <guid>http://securityratty.com/article/197c984b8e2d41f0d4763ab1993fed11</guid>
      <description><![CDATA[Lots being written about the Cloud , most of it quite dark and gloomy . In fact Im surprised, that Hoff hasnt got a preso spooled up called The Toxic Cloud or something similarly ominous for his next...]]></description>
      <content:encoded><![CDATA[<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/teXOPAFMOp0&amp;hl=en&amp;fs=1" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/teXOPAFMOp0&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p>Lots being <strong><a href="http://techbuddha.wordpress.com/2008/08/29/saas-and-cloud-computing-change-the-cia-paradigm/">written</a></strong> about <strong><a href="http://lastinfirstout.blogspot.com/2008/10/cloud-outsourcing-moved-up-stack.html">the Cloud</a></strong>, most of it quite <a href="http://rationalsecurity.typepad.com/blog/2008/10/will-you-all-please-shut-up-about-securing-the-cloudno-such-thing.html#trackback">dark and gloomy</a>.  In fact I&#8217;m surprised, that Hoff hasn&#8217;t got a preso spooled up called &#8220;The Toxic Cloud&#8221; or something similarly ominous for his next speaking tour.<br />
That said, <strong><a href="http://www.economist.com/opinion/displayStory.cfm?source=hptextfeature&amp;story_id=12471098">the Economist does a great job distilling the issue</a></strong> into a simple statement -</p>
<blockquote><p>Cloud computing is a trade-off between sovereignty and efficiency.</p></blockquote>
<p>Let me ask you -  if you had to put your money on one of those horses, considering your average profit-preoccupied business, which would it be?  I&#8217;d put my bottom dollar on the thoroughbred named &#8220;Cost Center Reduction&#8221;, to place.</p>
<p><strong>WHO ARE WE TO STAND IN THE WAY OF &#8220;PROGRESS&#8221;?</strong></p>
<p>I&#8217;m always fond of Jack&#8217;s rule that the role of information risk management boils down to three deceptively simple premises:</p>
<ul>
<li>Reduce Risk.</li>
<li>Reduce Loss.</li>
<li>Create Operational Efficiencies.</li>
</ul>
<p>So it would seem antithetical to the charter of the Chief Security Officer to stand in the way of progress as embodied by &#8220;cloud computing&#8221; (not to mention dangerous to long-term job security).  And I think that this presents opportunities to discuss strategies for managing risk, strategies that aren&#8217;t too theoretical and have practical application (though actual &#8220;cloud&#8221; use by enterprises may be rare at this point).</p>
<p><strong>ON RISK REDUCTION IN THE CLOUD (or, How To Learn From the Shortcomings of PCI DSS)</strong></p>
<p>The good news is, there&#8217;s already a well-established model for managing the risk around outsourcing the processing of &#8220;confidential&#8221; information.  The bad news is, that model kinda sucks it.</p>
<p>The Payment Card Industry, known as the &#8220;PCI&#8221; or &#8220;<em>meal ticket</em>&#8221; to many in the industry, faced a similar problem with the introduction of GLBA.  As I see it (and I&#8217;m not at all close to the PCI, at all, so this is all just abstract soliloquy) the PCI had one of two choices when faced with the prospect of other people managing their sensitive information:</p>
<ol>
<li>Accept the *massive* amount of GLBA risk their business creates and spend a TON of money to build out the infrastructure (both process and IT) to manage the consumer data themselves (in conjunction with the banks, of course) and never have it grace the computing systems of the retailer.  <em><strong>Or,</strong></em></li>
<li>Transfer the GLBA risk down to the retailer and have them bear the majority of the risk (and cost of reducing risk to a level that might be tolerable to the US Government).</li>
</ol>
<p><span style="color: #999999;"><em>(<a href="http://www.mckeay.net/">Martin</a>, <span style="color: #333333;">you may recall our Twittering about PCI a while back.  This is the crux of my view on the subj.</span>)</em></span></p>
<p>Now fortunately, the CSO&#8217;s of the world are going to be a little more &#8220;invested&#8221; in protecting the information they are stewards over, and unlike the PCI, will remain primarily responsible for the C, I, &amp; A of the data in the Cloud.  The cool thing is, this actually presents a great opportunity to start building a meaningful model for co-management of risk!  In fact, we can take the PCI model of contractual risk transference but modify where it goes all wrong, and start working to create something better.  And we can start by euthanizing some faulty assumptions.</p>
<p><strong>JUST HOW INFORMATIVE IS PCI DSS?</strong></p>
<p>What might be <em><strong>the.greatest.mistake</strong></em> of the standards compliance mentality is the assumption of value for the past-state measurement.  That is, I believe that the CSO needs more than some &#8220;past-state&#8221; assurance in order to understand their risk.    If you look at the concept of &#8220;PCI compliance&#8221; it really is an examination of a past state of nature that is assumed to be relevant to current and future states.   Many people (myself included) are not at all convinced that this past-state is nearly as informative as those who mandate it&#8217;s measurement believe it to be.</p>
<p>That&#8217;s not to condemn past-state measurements as completely non-informative,  they most certainly are useful.  It&#8217;s just that <em><strong>no self-respecting CSO sleeps well because they were deemed &#8220;PCI compliant&#8221;</strong></em> 10 months ago.  They sleep well because they have good visibility into current-state information and confidence in their strategy concerning future-state (based on that visibility and the outcomes of sound IRM models).</p>
<p><strong>MOVING PAST THE VULNERABILITY SCANNER INTO INTELLIGENCE AND WISDOM</strong></p>
<p>So realizing this new importance (to me, at least) concerning visibility and IRM models, I&#8217;m lead to the conclusion that if we are to manage risk in the Cloud, we&#8217;ll have to move beyond &#8220;PCI Compliance&#8221; or the concept that some regular &#8220;audit&#8221; of controls in place at the host is all we need to understand our ability to manage risk.  No, the CSO must have good information concerning current and probable future states.   This is that &#8220;visibility&#8221; I spoke of above.  In fact, we&#8217;ll need significant amounts of <em><strong>piercing, transparent</strong></em> visibility.  And in order to gain that visibility, our insight into Cloud Risk Management must include significant provisions for understanding a joint ability to Prevent/Detect/Respond as well as provisions for managing the risk that one of the participants won&#8217;t provide that visibility or ability via SLA&#8217;s and penalties . These SLA&#8217;s must be expressed in measurable terms (more visibility), and those metrics must have their roots in the things that help understand how we manage risk (those aforementioned IRM models).</p>
<p><strong>THE CLOUD COMPUTING SECURITY SILVER LINING (sorry couldn&#8217;t resist)</strong></p>
<p>As I mentioned earlier, I do see an opportunity to create insight.  The need for visibility and IRM models would allow us to create a &#8220;guidance&#8221; if you&#8217;ll allow me to use the term.  Not a standard or a &#8220;best practice&#8221; to audit by, but simply a reference document that says &#8220;if you&#8217;re going to put information on somebody else&#8217;s systems <em>and still hold some significant responsibility for that information</em>, here&#8217;s the considerations, why they are considerations, and how you might go about collaborating on the management of risk&#8221;.</p>
<p>And I think that if we undertake this journey, there is going to be a lot of growth and risk management innovation along the way.  But keen insights into what it means to manage risk will be necessary, and secure and forthright collaboration will be of absolute importance.</p>
<p>I say that last bit because, if these pundits are right about the utility of a hosted computing model - the Cloud will happen regardless of the CSO&#8217;s ability or desire to manage it.</p>
]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 12:46:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management innovation">risk management innovation</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/glba risk">glba risk</category>
      <category domain="http://securityratty.com/tag/glba">glba</category>
      <category domain="http://securityratty.com/tag/reduce risk">reduce risk</category>
      <category domain="http://securityratty.com/tag/risk reduction">risk reduction</category>
      <category domain="http://securityratty.com/tag/toxic cloud">toxic cloud</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=496">CLOUD COMPUTING - STORMY WEATHER?</source>
    </item>
    <item>
      <title><![CDATA[Security analyst warns of 'Google hacking']]></title>
      <link>http://securityratty.com/article/fc52c457f3a3d9a00b9a67fa2d972556</link>
      <guid>http://securityratty.com/article/fc52c457f3a3d9a00b9a67fa2d972556</guid>
      <description><![CDATA[Search engines such as Google are increasingly being used by hackers against Web applications that hold sensitive data, according to a security...]]></description>
      <content:encoded><![CDATA[Search engines such as Google are increasingly being used by hackers against Web applications that hold sensitive data, according to a security expert.]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hold sensitive data">hold sensitive data</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/web applications">web applications</category>
      <category domain="http://securityratty.com/tag/engines">engines</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <category domain="http://securityratty.com/tag/increasingly">increasingly</category>
      <source url="http://www.networkworld.com/news/2008/102708-security-analyst-warns-of-google.html?fsrc=rss-security">Security analyst warns of 'Google hacking'</source>
    </item>
    <item>
      <title><![CDATA[What Happens When Everything is Connected?]]></title>
      <link>http://securityratty.com/article/941a136717078013b7c0408995d4c6ce</link>
      <guid>http://securityratty.com/article/941a136717078013b7c0408995d4c6ce</guid>
      <description><![CDATA[We built out the web before software security was even in its infancy. The Web was almost ten years old before McGraw/Viega, Howard/Leblanc, and van Wyk/Graff's ideas started to take hold in the...]]></description>
      <content:encoded><![CDATA[<p>We built out the web before software security was even in its infancy. The Web was almost ten years old before McGraw/Viega, Howard/Leblanc, and van Wyk/Graff&#39;s ideas started to take hold in the industry, plus we built out the whole web without an identity layer. And now we are eating the bitter back end of all these things</p>
<p>On the flip side, most of your stuff is not connected, we each own about 8,000 things, but only 5 of them are connected to the web. That is a big margin of safety for the offline world, but it is shrinking every day.</p><br />
<p>Now we are starting to see projects like <a href="http://thenextweb.org/2008/09/25/here-comes-everything/">this</a></p><br />
<p><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e2010535baf43a970c-pi" style="FLOAT: left"><img alt="Nabaztag1" class="at-xid-6a00d83451c75869e2010535baf43a970c " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e2010535baf43a970c-120pi" style="MARGIN: 0px 5px 5px 0px" title="Nabaztag1" /></a>&#0160; </p>
<p>“Goal: connect everything</p>
<p>step 1: connect rabbits<br />step 2: connect everything else”</p><br />
<p>So I guess my question is - are we going to connect the next 7,995 things that we each own to the web using the same old, same old - proliferating more poor security design? Or alternatively how do we SAML enable the rabbit in step 1? </p>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 07:39:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/connect rabbits">connect rabbits</category>
      <category domain="http://securityratty.com/tag/connect">connect</category>
      <category domain="http://securityratty.com/tag/poor security design">poor security design</category>
      <category domain="http://securityratty.com/tag/step">step</category>
      <category domain="http://securityratty.com/tag/identity layer">identity layer</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/van wykgraff">van wykgraff</category>
      <category domain="http://securityratty.com/tag/saml enable">saml enable</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/what-happens-when-everything-is-connected.html">What Happens When Everything is Connected?</source>
    </item>
    <item>
      <title><![CDATA[Privacy In the Cloud: Show Me The Money]]></title>
      <link>http://securityratty.com/article/2e805d07b3a60ac9d955f1ff811f3569</link>
      <guid>http://securityratty.com/article/2e805d07b3a60ac9d955f1ff811f3569</guid>
      <description><![CDATA[Privacy is a lot like universal healthcare. Many agree its a good idea in concept, but few people want to pay for it
Richard Stallman - the man that gave us GNU - doesnt trust Cloud providers with his...]]></description>
      <content:encoded><![CDATA[<p><img class="alignright" style="float: right; border: 0; margin: 3px;" src="http://farm3.static.flickr.com/2052/2404940312_e759c4030d_m_d.jpg" alt="Locker" width="180" height="240" />Privacy is a lot like universal healthcare.  Many agree its a good idea in concept, but few people want to pay for it.</p>
<p>Richard Stallman - the man that gave us <a href="http://www.gnu.org/">GNU</a> - <a href="http://www.guardian.co.uk/technology/2008/sep/29/cloud.computing.richard.stallman">doesn&#8217;t trust Cloud providers with his data</a> and says you shouldn&#8217;t either.  Richard believes we should store our private data on our own computers using &#8216;free&#8217; (as in <a href="http://www.gnu.org/gnu/thegnuproject.html">freedom</a>) software.  The ironic part for Richard is that a significant portion of the Cloud is powered by open source software which he indirectly created (think <a href="http://gcc.gnu.org/">gcc</a>).</p>
<p>Richard sees it as a question of control.  Control is important but it isn&#8217;t the only variable.  Rather, I see it as a question of control, competence and economics.</p>
<p>The quick rebuttal to Richards&#8217; view is this: the average computer user is <a href="http://www.stallman.org/photos/rms-full-size.jpg">not as smart as you</a>.  Control is not the same as competence.  Control is about exercising choice, not about requiring everyone in the world to develop sufficient skills to protect complex hardware and software systems (aka their computer) against <a href="http://ddanchev.blogspot.com/">ever increasing threats</a>.</p>
<p>My view is that privacy is not &#8216;free&#8217;.  It comes at a cost.  Whether you run your own systems or rely on someone else to do it, there is a cost.  There is cost in designing and implementing mechanisms to support privacy.  Beyond upfront costs there are ongoing expenditures to ensure privacy is maintained e.g. maintaining access control lists, testing and applying security patches, data leakage prevention etc.  None of these things are &#8216;free&#8217;.</p>
<p>If we agree that privacy costs money then how much is your privacy worth?</p>
<p>Stop for a second - think of a number&#8230;  </p>
<p>Now did we all think of the <a href="http://pbskids.org/sesame/coloring/images/07_grover.gif">same number</a>?</p>
<p>The problem with a one size fits all approach to privacy is that we each place a different value on it.</p>
<p>Checking in on the <a href="http://epic.org/">EPIC</a> site, I saw this:  </p>
<blockquote><p>A new report from <a href="http://www.pewinternet.org/">Pew Internet and American Life Project</a> indicates that &#8220;cloud computing&#8221; applications, such as web-based email and other web apps, are raising new privacy concerns. The report <a href="http://www.pewinternet.org/press_release.asp?r=306" target="_blank">Use of Cloud Computing: Applications and Services</a> found that 69% of online Americans use webmail services, store data online, or use software programs such as word processing applications whose functionality is located on the web. At the same time, &#8220;users report high levels of concern when presented with scenarios in which companies may put their data to uses of which they may not be aware.&#8221; For example, 90% of respondents said that they &#8220;would be very concerned if the company at which their data were stored sold it to another party,&#8221; 80% say &#8220;they would be very concerned if companies used their photos or other data in marketing campaigns,&#8221; and 68% of &#8220;users of at least one of the six cloud applications say they would be very concerned if companies who provided these services analyzed their information and then displayed ads to them based on their actions.&#8221;</p></blockquote>
<p>What does that tell us?</p>
<p>The average (American) Internet user finds Cloud services convenient but has concerns about how their privacy might be affected by Cloud providers actions (duh!).  The survey identifies a lack of awareness in how private data is used in some consumer based Cloud services (consistent with web advertising awareness surveys).  </p>
<p>Unfortunately, the results of this survey are not very actionable.  The survey doesn&#8217;t mention whether these are all &#8216;free&#8217; Cloud services (we can only assume they are) or ask the respondents what their expectations of privacy are and how much they would be willing to pay for different privacy assurance levels. </p>
<p>On a sidenote, respondents were not asked if they had actually read the privacy agreement for the services they signed up to.  But the providers know if they did or not&#8230;  Or at least, they have the data to figure it out.  At sign up time they can measure the time between displaying the privacy agreement and the user clicking &#8216;I accept&#8217;.  If its just a few seconds then its pretty obvious there was more scrolling than reading going on.  But I think we can probably guess the answer without the data ;-).</p>
<p>I believe we need to be able to link expectation of privacy with cost.</p>
<ul>
<li>How much are you willing to pay for privacy?  What level of privacy assurance do you need?</li>
<li>How much is your Cloud Provider paying to protect your privacy today?  What privacy services could they reasonably offer if they had customers willing to pay?  How might this compare with how you manage your private data on your home computer today?</li>
</ul>
<p>The cynical view is that we expect privacy but don&#8217;t want to pay for it.  Its a bit like uptime - there is a parallel universe out there, where internal IT departments allegedly meet their 99.999% uptime SLAs, but when Gmail goes down, the Sergey Brin witchcraft dolls come out.</p>
<p>From a provider perspective, the &#8220;cost&#8221; of privacy invariably gets bundled under that line item called &#8216;Information Security&#8217;.  And don&#8217;t be fooled, the cost of privacy in reality is more than the salary of the person employed to be the privacy advocate (if there is one).  If we can&#8217;t see how much our providers are spending on our privacy then how can we judge if they are spending enough?  And what is enough?  And what can I get if I&#8217;m willing to pay a little extra?</p>
<p>Personally, I would rather we get some transparency around privacy costs and assessment of offerings.  However, without a sufficiently sized market of customers willing to pay for privacy assurance and Cloud Providers willing to be more open, I won&#8217;t hold my breath.</p>
<p>What about you?  Would you be prepared to pay for privacy?  Should providers be more transparent about what they do and don&#8217;t do and how they do it?<br />
 <br />
 </p>
<p> </p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/419000947" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 19:49:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud providers">cloud providers</category>
      <category domain="http://securityratty.com/tag/trust cloud providers">trust cloud providers</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/cloud providers actions">cloud providers actions</category>
      <category domain="http://securityratty.com/tag/cloud applications">cloud applications</category>
      <category domain="http://securityratty.com/tag/privacy costs money">privacy costs money</category>
      <category domain="http://securityratty.com/tag/privacy assurance levels">privacy assurance levels</category>
      <category domain="http://securityratty.com/tag/privacy assurance">privacy assurance</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/419000947/">Privacy In the Cloud: Show Me The Money</source>
    </item>
    <item>
      <title><![CDATA[Cali, Nevada, Massachussets Pass Data Security Protections]]></title>
      <link>http://securityratty.com/article/99732cc0002288b5f545b0583dd743e1</link>
      <guid>http://securityratty.com/article/99732cc0002288b5f545b0583dd743e1</guid>
      <description><![CDATA[New protections at the state-wide level are being enacted, covering a wide range of topics from RFID tags to encryption. Heres a look at the states moving forward now
California Our Governator passed...]]></description>
      <content:encoded><![CDATA[<p>New protections at the state-wide level are being enacted, covering a wide range of topics from RFID tags to encryption. Here&#8217;s a look at the states moving forward now:</p>
<p>California &#8212; Our Governator passed a law making it illegal to secretly scan RFID tags</p>
<p>He then killed a bill that would limit the amount of time retailers could hold onto customer information, for the second year in a row.</p>
<p>Nevada &#8212; A new law requires businesses to encrypt customer information sent outside &#8220;the secure system of the business&#8221; except by fax</p>
<p>Massachusetts &#8212; New rules require that organizations that store personal data about its residents must encrypt the data on portable devices starting in 2009.</p>
<p><a rel="nofollow" target="_blank" href="http://voices.washingtonpost.com/securityfix/2008/10/new_state_laws_target_data_enc.html">Brian Krebs </a>at the Washington Post has the nitty gritty about the above new laws.</p>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 05:44:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/encrypt customer information">encrypt customer information</category>
      <category domain="http://securityratty.com/tag/encrypt">encrypt</category>
      <category domain="http://securityratty.com/tag/customer information">customer information</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/store personal data">store personal data</category>
      <category domain="http://securityratty.com/tag/law requires businesses">law requires businesses</category>
      <category domain="http://securityratty.com/tag/rules require">rules require</category>
      <category domain="http://securityratty.com/tag/nevada">nevada</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/414965667/">Cali, Nevada, Massachussets Pass Data Security Protections</source>
    </item>
    <item>
      <title><![CDATA[Anatomy of SQL injection attack]]></title>
      <link>http://securityratty.com/article/886b4b1b3c2fa196604a06176132cc4b</link>
      <guid>http://securityratty.com/article/886b4b1b3c2fa196604a06176132cc4b</guid>
      <description><![CDATA[While there are a number of security risks in the world of electronic commerce, SQL injection is one of the most common Web site attack techniques used to steal customer data such as credit card...]]></description>
      <content:encoded><![CDATA[While there are a number of security risks in the world of electronic commerce, SQL injection is one of the most common Web site attack techniques used to steal customer data such as credit card numbers, hold customer data hostage by encrypting it or destroy data outright.]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://securityratty.com/tag/destroy data outright">destroy data outright</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/customer data">customer data</category>
      <category domain="http://securityratty.com/tag/security risks">security risks</category>
      <category domain="http://securityratty.com/tag/electronic commerce">electronic commerce</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <source url="http://www.networkworld.com/news/tech/2008/100708-tech-update.html?fsrc=rss-security">Anatomy of SQL injection attack</source>
    </item>
  </channel>
</rss>
