<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: importantly]]></title>
    <link>http://securityratty.com/tag/importantly</link>
    <description></description>
    <pubDate>Wed, 23 Jul 2008 20:13:54 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Commercialization of Anti Debugging Tactics in Malware]]></title>
      <link>http://securityratty.com/article/91955d7bc08228b99c0f5fa478c039b5</link>
      <guid>http://securityratty.com/article/91955d7bc08228b99c0f5fa478c039b5</guid>
      <description><![CDATA[Commoditization or commercialization, Themida or Code Virtualizer, individually crypting or outsourcing to an experienced malware crypting service offering discounts on a volume basis next to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SN0BFks8GsI/AAAAAAAACMQ/J_vLiffz110/s1600-h/figure_multiple.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="128" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SN0BFks8GsI/AAAAAAAACMQ/bz624nz5JbE/s200-R/figure_multiple.jpg" width="200" /></a><a href="http://ddanchev.blogspot.com/2008/09/commoditization-of-anti-debugging.html">Commoditization</a> or commercialization, Themida or Code Virtualizer, individually crypting or outsourcing to an experienced malware crypting service offering discounts on a volume basis next to detection rates of the crypted binary offered by a trusted online scanner that is NOT distributing the samples to the vendors? These are just some of the questions malware authors often ask themselves, while others distribute pirated copies of Code Virtualizer urging everyone to start taking advantage of commercial anti-reverse engineering tools to make their malware harder to analyze. Once again, just like we've seen before, a legitimate commercial application can come handy in the hands of the wrong people :<br />
<br />
"<i>Code Virtualizer will convert your original code (Intel x86 instructions) into Virtual Opcodes that will only be understood by an internal Virtual Machine. Those Virtual Opcodes and the Virtual Machine itself are unique for every protected application, avoiding a general attack over Code Virtualizer. Code Virtualizer can protect your sensitive code areas in any x32 and x64 native PE files (like executable files/EXEs, system services, DLLs , OCXs , ActiveX controls, screen savers and device drivers).</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SN0CPwG9MzI/AAAAAAAACMY/lB8WtKqycj4/s1600-h/cvprotopt.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="149" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SN0CPwG9MzI/AAAAAAAACMY/kgSYpWIHW2E/s200-R/cvprotopt.png" width="200" /></a><i>Code Virtualizer can generate multiple types of virtual machines with a different instruction set for each one. This means that a specific block of Intel x86 instructions can be converted into different instruction set for each machine, preventing an attacker from recognizing any generated virtual opcode after the transformation from x86 instructions. The following picture represents how a block of Intel x86 instructions is converted into different kinds of virtual opcodes, which could be emulated by different virtual machines.</i><br />
<br />
<i>When an attacker tries to decompile a block of code that was protected by Code Virtualizer, he will not find the original x86 instructions. Instead, he will find a completely new instruction set which is not recognized by him or any other special decompiler. This will force the attacker to go through the extremely hard work of identifying how each opcode is executed and how the specific virtual machine works for each protected application. Code Virtualizer totally obfuscates the execution of the virtual opcodes and the study of each unique virtual machine in order to prevent someone from studying how the virtual opcodes are executed.</i>"<br />
<br />
With Cyber-as-a-Service business model becoming increasingly common, the entire <a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">quality assurance model in respect to malware</a> is slowly maturing from individual malware crypting propositions, where the seller of the service is basically taking advantage of a diverse set of public/private tools, into DIY web services offering crypting discounts on a volume basis, and perhaps most importantly - improving the customer's experience by letting him take advantage of the inventory of crypting tools and bypassing verification services. Within the tool's inventory are naturally lots of (pirated) commercial anti-reverse engineering tools.<br />
<br />
As we've seen before, whenever someone starts commercializing what used to be a self-selving process, others will either follow, or disintermediate their services by persistently releasing crypting tools for free in the wild. At the end of the day, it's all a matter of how serious they're about commercializing this market segment, and taking into consideration that a spamming vendor is offering malware crypting services "in between" the rest of the services in their portfolio, this underground cash cow is yet to prove itself in the long term.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wJDSL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wJDSL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QoCNL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QoCNL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e4uxl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e4uxl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sXqbl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sXqbl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=khiOL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=khiOL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2cQ2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2cQ2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HiSTl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HiSTl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/406651187" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 12:55:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/machine">machine</category>
      <category domain="http://securityratty.com/tag/specific virtual machine">specific virtual machine</category>
      <category domain="http://securityratty.com/tag/internal virtual machine">internal virtual machine</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/sensitive code">sensitive code</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/unique virtual machine">unique virtual machine</category>
      <category domain="http://securityratty.com/tag/original code">original code</category>
      <category domain="http://securityratty.com/tag/code virtualizer">code virtualizer</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/406651187/commercialization-of-anti-debugging.html">The Commercialization of Anti Debugging Tactics in Malware</source>
    </item>
    <item>
      <title><![CDATA[One Mans Frustrations With Risk Management]]></title>
      <link>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</link>
      <guid>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</guid>
      <description><![CDATA[Chris, who is a male in Government C&amp;A has a blog with a wonderful title: How is that Assurance Evidence
Id love to have another blog even more specific - Ok, that Assurance is Evidence Of What,...]]></description>
      <content:encoded><![CDATA[<p>Chris, who is a male in Government C&amp;A has a blog with a wonderful title:<a href="http://howisthatassuranceevidence.blogspot.com/"> How is that Assurance Evidence? </a></p>
<p>I&#8217;d love to have another blog even more specific - &#8220;Ok, that Assurance is Evidence <em><strong>Of What, Exactly</strong></em>?</p>
<p>Today he has a great article called:</p>
<p><a name="2599135121032652210"></a></p>
<h2 class="title"><a href="http://howisthatassuranceevidence.blogspot.com/2008/09/whats-matter-with-risk-management.html">What&#8217;s the matter with Risk Management?</a></h2>
<p><em>And &#8220;in short, it&#8217;s everything.&#8221;</em> It pretty much sums up why I had to grow to re-evaluate how our industry does risk, risk management, approaches controls &amp; vulnerability and find a new way.   A couple of things jump out at me in reading Chris&#8217; article:</p>
<p><strong>1.)  Just because that Deming cycle sucks and is full of unknowns doesn&#8217;t mean &#8220;risk&#8221; doesn&#8217;t exist, nor that it isn&#8217;t of primary importance.</strong> Nor does it mean that in the absence of model &amp; methodology, we won&#8217;t be &#8220;doing&#8221; risk analysis anyway - just in an ad hoc method and completely from &#8220;the gut&#8221;.</p>
<p>Our industry calls these unstructured risk analysis &#8220;Best Practices&#8221;, as it&#8217;s an easy and convenient way of sweeping the unknowns under the rug of bureaucracy and enforcing it via peer pressure.</p>
<p><strong>2.)  What this &#8220;suckiness&#8221; does mean is that your model and methodology aren&#8217;t helping you.</strong> As Chris intimates, there is too much uncertainty in the inputs for his model (they are, in the language of Bayesians - too subjective to be useful priors).</p>
<p>Take for example how we might be approaching the &#8220;controls&#8221; part of our analysis.  Chris writes:</p>
<blockquote><p><em>&#8220;2.  What are the controls that we have to employ?<br />
800-53, ISO 27001, PCI, etc.</em></p>
<p><em>Still kinda good, but we basically know that ISO is relatively voluntary and NIST supplies a control catalog and not policies. So here we have to take the control catalog, and mash our policies into it.&#8221;</em></p></blockquote>
<p>I wouldn&#8217;t call this &#8220;kinda good&#8221; at all :)  These control catalogs only provide a hierarchy within which to look for evidence of  our ability to resist an attacker.  They are incapable of making any claim about the effectiveness of the controls when they are operated at 100% efficiency, or more importantly, what % efficiency our specific organization operates at.</p>
<p>Let&#8217;s use <a href="http://risktical.com/initech-inc/">Chris Hayes&#8217; Initech as our fictional example</a>.</p>
<p>Initech has a control (a back door on a loading dock).  Now the locks on the door are 100% capable of locking the door.  This is different than saying that they are capable of frustrating all but the top 5% of lockpicking burgalars.  It is also diffferent than saying that in a sample of several &#8220;walk around audits&#8221; the doors are left open 20% of the time (they are not in compliance with policy 100% of the time).  Even worse, that 80% of the time the door is not propped open?  Yeah, tailgating is a known issue.</p>
<p>So we have several different variables here that we need to account for (and it&#8217;s just a door).  But the analogy stands that most &#8220;risk management&#8221; methodologies are &#8220;We have a door, yes/no?&#8221; And most GRC platforms, when asked for their &#8220;opinion&#8221; will simply say &#8220;door is needed&#8221; or, even worse, &#8220;a door policy is needed&#8221;.</p>
<p><strong>3.)  Criticality and the Source of Value is all messed up in these Risk Management models.<br />
</strong></p>
<p>Chris writes:</p>
<blockquote><p><em>Someone wants me to tell them which boxes are more critical than others. This is mainly because of budgetary or operational reasons. To which I usually say &#8220;All of them, it is a system after all&#8221;.</em></p></blockquote>
<p>This literally made me laugh out loud.  And <strong><a href="http://riskmanagementinsight.com/riskanalysis/?p=383">this sort of &#8220;rate the firewall as Risk = 500 but rate the actual business application as Risk = 157&#8243; thing is</a></strong> also endemic.  Now Chris is very smart here.  He correctly identifies that the value is tied to the business process the systems support, and not to a specific box.  Oh, we scan at the specific box level - but because of the nature of systemic failures - all the boxes in the process are inexorably interrelated.</p>
<p>One of the reasons I really like FAIR is that the losses are quantified (or qualified) based not on some amorphous value of the box or the process itself, but<strong> losses are linked to the actions that the threat will take. </strong> Take systems in a highly regulated industries as an example.  Usually the most probable losses aren&#8217;t due to system compromise per se, but in the disclosure the compromise causes (regulators are a threat source, after all).  But many &#8220;risk management&#8221; methodologies will say &#8220;online banking is worth $2 billion, the value of the systems is therefore $2 billion&#8221;.  And suddenly we&#8217;re telling executive management that there&#8217;s a 60% probability that they&#8217;ll lose $2 billion.</p>
<p><strong>4.)  If the primary source of prior information for your &#8220;risk management&#8221; methodology is a vulnerability scanner</strong> - <em><strong>you&#8217;re doing it wrong</strong></em>.  Chris writes:</p>
<blockquote><p><em>So we ran a scan and now we have a report. A snapshot in time to make all decisions. Where did these vulnerability ratings come from? Do I even know if my system is at risk? What if I spend my time on vulnerabilities that have no threat?</em></p></blockquote>
<p>So first, my thoughts are that actual &#8220;vulnerability&#8221; must be a comparison of the force a threat can apply, and our ability to resist that force (this is a probability statement, btw).</p>
<p>Changing your thinking about vulnerability now helps us understand the problem in several new ways.  First, you can start to divorce yourself from the scanner.  After all, the scanner is simply providing you with current state information that is usually just relevant variance from policy. It doesn&#8217;t really tell you about real &#8220;weakness in a system&#8221; because the system is an interrelated mess of people, processes and IT assets.</p>
<p><strong>5.)  Finally, most &#8220;risk management&#8221; approaches just *don&#8217;t* do a good job of helping us understand the how&#8217;s and why&#8217;s of <em>managing</em> <em>risk</em>.</strong> In the past, I&#8217;ve referred to these standards as really being &#8220;issue management&#8221; because they are at their heart, an act of discovery - a formal process around gathering prior information.  They are not, in and of themselves, capable of linking the issues discovered to the root cause.  And these root causes?  Yeah, they&#8217;re the things that create &#8220;risk&#8221;.  Not a threat, not a vulnerability, not the existence of an asset - the amount of risk that we have stems from our capability to manage it.</p>
<p>So Chris, I completely agree - but I wouldn&#8217;t give up yet.  There actually are a few of us who are focused on what you suggest:</p>
<blockquote><p>Where to go from here: A fundamental revamp of how to deal with Risk. Where risk professionals focus on the treating the sickness and not the symptoms, and come up with some new success/actionable metrics.</p></blockquote>
<p>Chris, there&#8217;s nothing I want to do more than that.</p>
]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:05:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management methodologies">risk management methodologies</category>
      <category domain="http://securityratty.com/tag/risk management approaches">risk management approaches</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management methodology">risk management methodology</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk professionals focus">risk professionals focus</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/specific">specific</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=447">One Mans Frustrations With Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Biotech Platforms]]></title>
      <link>http://securityratty.com/article/45651b9a0decddecc758c652995e074f</link>
      <guid>http://securityratty.com/article/45651b9a0decddecc758c652995e074f</guid>
      <description><![CDATA[It is interesting to see the notion of tech platforms play out in other fields. Specifically, the biotech field is all abuzz on platforms. For example Exelixis' oncology platform built on kinase...]]></description>
      <content:encoded><![CDATA[<p>It is interesting to see the notion of tech platforms play out in other fields. Specifically, the biotech field is <a href="http://www.hammerstockblog.com/genentech’s-new-shiny-platform/">all </a><a href="http://www.hammerstockblog.com/exelixis-as-a-platform-company/">abuzz</a> on platforms. For example Exelixis&#39; oncology platform built on kinase inhibitors.</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">Having a validated drug discovery platform is the first and most important criterion for defining a good platform company. The platform is typically comprised of a combination of technology, experienced personnel and intellectual property that can generate a stream of drug candidates. Most importantly, investing should be done only after a product of the platform&#160;<span>demonstrates</span>&#160;activity&#160;<span>in clinical trials.&#160;</span>Having a clinically validated product is not a guarantee for future success of the platform nor does it mean that the specific agent will reach the market, but it does imply that one or more of the platform’s products stand a reasonable chance of becoming a commercial drug. A validated platform may increase overall success rates, yet the odds of a particular drug candidate to make it all the way to approval are still low.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Exelixis is active in the ever growing market of kinase inhibitors (KIs) for the treatment of cancer, that is, drugs that block the activity of kinases in cancer cells. Cancer cells are often described as cells that are out of control: They proliferate quickly, ignore death signals, invade nearby tissues and eventually metastasize to distant organs. These disease onset and advancement are associated with processes such as cell growth, motility and blood-vessel formation, which are governed by a complex network made of kinases. Thus, blocking these processes by inhibiting the relevant kinases has emerged as one of the most attractive approaches to fighting cancer.<br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Together with monoclonal antibodies, kinase inhibitors represent a paradigm shift in cancer treatment from cytotoxic agents to targeted therapies, a trend that is constantly growing. Like antibodies for cancer, kinase inhibitors target tumors while sparing healthy cells and consequently lead to better activity with fewer side effects. Kinase inhibitors, however, possess several advantages over antibodies. The most evident advantage is that KIs can hit targets inside the cell while antibodies can only bind targets presented on the cell surface, so internal targets are approachable only by KIs. Another advantage is the fact that KIs can be given orally, which is a major factor in terms of patient convenience, especially given the typical long treatment duration associated with targeted therapies. Another advantage, which will be later discussed in the article, is the ability to produce KIs that hit several targets at once.<br /></span></p></blockquote><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Read the whole thing </span><a href="http://www.hammerstockblog.com/exelixis-as-a-platform-company/">here</a><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">.&#160;</span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Speaking a software guy, the thing that is interesting to me here is that the platform approach allows a biotech to aggregate a large database of tests and test results to refine products across a range of targets and delivery mechanisms. Its just data. Cancer versus Moore&#39;s law? Puh-leeze.</span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 06:08:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/drug">drug</category>
      <category domain="http://securityratty.com/tag/treatment">treatment</category>
      <category domain="http://securityratty.com/tag/cancer treatment">cancer treatment</category>
      <category domain="http://securityratty.com/tag/commercial drug">commercial drug</category>
      <category domain="http://securityratty.com/tag/platforms">platforms</category>
      <category domain="http://securityratty.com/tag/drug discovery platform">drug discovery platform</category>
      <category domain="http://securityratty.com/tag/platform">platform</category>
      <category domain="http://securityratty.com/tag/cells">cells</category>
      <category domain="http://securityratty.com/tag/cancer cells">cancer cells</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/biotech-platforms.html">Biotech Platforms</source>
    </item>
    <item>
      <title><![CDATA[What's Going on Between Asprox and Rock Phish? ]]></title>
      <link>http://securityratty.com/article/fc95ce7833adc3cdfb7b5c321e80348a</link>
      <guid>http://securityratty.com/article/fc95ce7833adc3cdfb7b5c321e80348a</guid>
      <description><![CDATA[When a small phishing gang decides to upgrade its infrastructure, it is often done in a quick and dirty fashion. The transition is almost immediate, and often buggy and unprofessional. But what...]]></description>
      <content:encoded><![CDATA[When a small phishing gang decides to upgrade its infrastructure, it is often done in a quick and dirty fashion. The transition is almost immediate, and often buggy and unprofessional. But what happens when a gang on the scale of the Rock Phish group decides to abandon its old methods and upgrade its botnet infrastructure? It is done slowly, smoothly but most importantly -- professionally. 

The RSA FraudAction Research Labs recently gathered information that indicates major changes in the tactics employed by the Rock Phish gang. We have reason to believe that the gang is replacing its phishing infrastructure, and upgrading it to an advanced <a href="http://www.honeynet.org/papers/ff/fast-flux.html">Fast-Flux</a> botnet. <B>We also believe that this new infrastructure belongs to none other than the infamous Asprox Botnet, which has recently been spreading itself using surges of SQL injection attacks...</b>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/rock phish">rock phish</category>
      <category domain="http://securityratty.com/tag/gang">gang</category>
      <category domain="http://securityratty.com/tag/gang decides">gang decides</category>
      <category domain="http://securityratty.com/tag/rock phish gang">rock phish gang</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/botnet infrastructure">botnet infrastructure</category>
      <category domain="http://securityratty.com/tag/infrastructure belongs">infrastructure belongs</category>
      <category domain="http://securityratty.com/tag/infamous asprox botnet">infamous asprox botnet</category>
      <category domain="http://securityratty.com/tag/decides">decides</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1338">What's Going on Between Asprox and Rock Phish? </source>
    </item>
    <item>
      <title><![CDATA[Real Artists Ship]]></title>
      <link>http://securityratty.com/article/da6631c856e43a023c66515e59fbce16</link>
      <guid>http://securityratty.com/article/da6631c856e43a023c66515e59fbce16</guid>
      <description><![CDATA[For a number of reasons I follow emerging economies, the biggies being China and India. The BRIC countries (Brazil, Russia, India, and China) generally get lumped in together as the &quot;next big thing&quot;,...]]></description>
      <content:encoded><![CDATA[<p>For a number of reasons I follow emerging economies, the biggies being China and India. The BRIC countries (Brazil, Russia, India, and China) generally get lumped in together as the &quot;next big thing&quot;, but they are at very, very different stages of development and more importantly are taking different paths. You can easily think of software security as an emerging discipline - despite a lot of talk and papers about Saltzer and Schroeder, we really don&#39;t have this stuff figured out.&#160;</p><br /><div>So China is following a well worn path similar to South Korea, Japan, and the early US. India is taking a totally different and unproven path towards growth. Tata Motors has been innovative in building the cheapest car - the Tata Nano which is a $2500 car, and<a href="http://1raindrop.typepad.com/1_raindrop/2008/01/to-those-about.html"> engineering triumph</a>, driven by a mantra that an engineer would stand behind &quot;do we really need that?&quot;</div><br /><div>Now the progress to executing on this is <a href="http://www.nytimes.com/2008/09/03/world/asia/03tata.html?_r=1&amp;ref=world&amp;oref=slogin">held back</a> by India&#39;s dysfunctional environment:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal; ">In a tale rich with incongruities, the Communist-run government of West Bengal State invited the&#160;<a href="http://topics.nytimes.com/top/news/business/companies/tata_group/index.html?inline=nyt-org" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; text-decoration: none; color: #006683; " title="More articles about the Tata Group.">Tata Group</a>, a symbol of Indian capitalism, to set up its plant in an area called Singur. It acquired 1,000 acres from farmers on the company’s behalf.</span><br /><span style="font-family: Verdana; font-style: italic; line-height: normal; ">As the project advanced, some farmers who had sold their land demanded it back. The main state-level opposition party, the Trinamool Congress, led protests demanding that the land be returned. Most people sympathetic to Tata accused the opposition of inducing the farmers to protest, while Tata’s critics said the farmers had legitimate grievances.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal;"><br /></span><span style="font-family: Verdana; font-style: italic; line-height: normal; ">The issue simmered for months. But in recent days, protesters began surrounding the plant, blocking roads and preventing Tata workers from reaching the plant. “The existing environment of obstruction, intimidation and confrontation has begun to impact the ability of the company to convince several of its experienced managers to relocate and work in the plant,” Tata said in a statement on Tuesday.</span><br /><span style="font-family: Verdana; font-style: italic; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal; ">The halt to the plant has caused many Indian business people to warn of a chilling effect on investment in the country. It is also unclear how Tata will be able to keep the Nano’s cost so low, since part of the affordable price reflects the company’s savings on the land in Singur.</span></p></blockquote><p><span style="font-family: Verdana; font-style: italic; line-height: normal;"><br /><div><span style="font-style: normal; "><a href="http://voxeu.org/index.php?q=node/1585">Arvind Subramanian</a>&#160;compares China and India&#39;s trajectories:</span><br /></div><div><span style="font-style: normal;"><br /></span></div></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal; ">There is a fundamental asymmetry between state and markets. It is easier to create markets than it is to create state capacity or to prevent its deterioration. Creating markets is a lot about letting go, establishing a reasonable policy framework, and allowing the natural hustling instinct to take over. In other words, hustling is the natural state. Building state capacity, on the other hand, is quite different. It involves overcoming collective action problems, mediating conflict, creating accountability mechanisms where outputs are multiple and fuzzy and links between inputs and outputs murky, and contending with the deep imprints of history. In Weber’s memorable words, building public institutions is like the “slow boring of hard boards”.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal;"><br /></span><span style="font-family: Verdana; font-style: italic; line-height: normal; ">In that light, China’s task of improving its private sector seems easier to accomplish than India’s task of arresting institutional decline. So, while China and India can probably both count on more years of high growth, the odds still favour China pulling off that feat than India. That, and not just the meagre medal tally, should be what India mulls over after the Beijing Olympics.</span></p></blockquote><div><span style="font-family: Verdana; font-style: italic; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal; ">The Economist </span><a href="http://www.economist.com/blogs/freeexchange/2008/09/the_passion_of_the_tata.cfm">summarizes</a><span style="font-family: Verdana; line-height: normal; ">:</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal; ">It&#39;s easier to liberalise a functional state than it is to functionalise a dysfunctional one, of any ideological stripe.</span></p></blockquote><p><span style="font-family: Verdana; line-height: normal;"><br /></span></p><div><span style="font-family: Verdana; line-height: normal;">What does all this have to do with ostensibly the topic at hand - Information Security? Well Tata Motors had the innovation but they didn&#39;t have the deployment model, at least not yet. More to the point, a lot of software security gets driven by infosec groups but real change is only coming when its driven by the development group. Why? Development groups are functional, they ship code.&#160;A lot of the success in software security is predicated by who you choose to partner with, it is more effective and easier to add security into a functional development group that ships code.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 07:23:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tata">tata</category>
      <category domain="http://securityratty.com/tag/tata workers">tata workers</category>
      <category domain="http://securityratty.com/tag/tata motors">tata motors</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/india">india</category>
      <category domain="http://securityratty.com/tag/india mulls">india mulls</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/functional development">functional development</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/real-artists-ship.html">Real Artists Ship</source>
    </item>
    <item>
      <title><![CDATA[Education and the willingness of parents ot insure their childs online safety is paramount]]></title>
      <link>http://securityratty.com/article/62f8d39bb7a731e55237495c7b654a1f</link>
      <guid>http://securityratty.com/article/62f8d39bb7a731e55237495c7b654a1f</guid>
      <description><![CDATA[I agree with alot of both the Point and Counterpoint articles by Alan and Mary. The Counterpoint article is at this link. http://www.internetevolution.com/author.asp?doc id=162622&amp;f src=ieupdate

...]]></description>
      <content:encoded><![CDATA[<div > I agree with alot of both the Point and Counterpoint articles by Alan and Mary.<br/>The Counterpoint article is at this link.<br/><a href="http://www.internetevolution.com/author.asp?doc_id=162622&amp;f_src=ieupdate" rel="nofollow" target="_blank">http://www.internetevolution.com/author.asp?doc_id=162622&amp;f_src=ieupdate</a><br/> </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/B42C1E85-7ED5-44B2-8D4B-724E807F2ABE/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/ee0189c8-87a3-495d-9556-11ffce26cd81/B42C1E85-7ED5-44B2-8D4B-724E807F2ABE/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659" href="http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659" style="font-size: 11px;">www.internetevolution.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659 --><DIV><SPAN class="gray header biggest"><A href="http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659&#038;"><I>Point</I>: The Fantasy of a &#8216;Childproof&#8217; Internet</A></SPAN></DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659 --><DIV><br />
One problem is that content filtering software simply isn&#8217;t good enough.?Yes, software blocks many child porn sites, but it also allows some sites to get through.?Also, child porn sites are typically very good at evading filters.?Just as importantly, the software mandated for schools and public libraries doesn&#8217;t just ban child porn, it bans thousands of sites.?Does the software company investigate the thousands of sites it blocks??Does it know whether a child engaged in illicit activity on a Website is 16, 18, or 21 years old?</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/B42C1E85-7ED5-44B2-8D4B-724E807F2ABE/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_020908115811"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=020908115811&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=020908115811&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=020908115811&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_020908115811" /></a></P>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 19:58:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/child porn sites">child porn sites</category>
      <category domain="http://securityratty.com/tag/child">child</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/software blocks">software blocks</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software simply">software simply</category>
      <category domain="http://securityratty.com/tag/ban child porn">ban child porn</category>
      <category domain="http://securityratty.com/tag/blocks">blocks</category>
      <category domain="http://securityratty.com/tag/software company">software company</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=601">Education and the willingness of parents ot insure their childs online safety is paramount</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[VCsChoosing How to Invest]]></title>
      <link>http://securityratty.com/article/c4d8ac0dd426afdf9ac1d38d36dad4e8</link>
      <guid>http://securityratty.com/article/c4d8ac0dd426afdf9ac1d38d36dad4e8</guid>
      <description><![CDATA[Don Dodge has a series going on about VCs and why startups fail, and he says VCs say no to startups 99% of the time, yet still choose failing companies 33% of the time or so. Interestingly he compares...]]></description>
      <content:encoded><![CDATA[<p>Don Dodge has a series going on about VCs and why startups fail, and he says VC&#8217;s say no to startups 99% of the time, yet still choose failing companies 33% of the time or so. Interestingly he <a rel="nofollow" target="_blank" href="http://dondodge.typepad.com/the_next_big_thing/2008/08/why-vcs-say-no-99-of-the-time.html">compares </a>the selection process to the way investors choose their stocks &#8211;</p>
<blockquote><p>I would guess that every one of you reading this blog have a stock portfolio with 5 to 10 individual stocks or mutual funds. There are more than 5,000 publicly listed companies to choose from, and another 5,000 mutual funds. But, out of 10,000 possible companies you chose 10 to invest in. Why? Why did you reject the other 9,990 companies? Obviously there are more than 10 good companies to invest in. Other investors chose to invest their money in the other 9,990 companies&#8230;why not you?</p></blockquote>
<p>I suppose the difference must be that many investors aren&#8217;t actively involved in their investments (maybe entrepreneurs are more so, since they have to know a certain investment space quite well)&#8230;</p>
<p>It sounds to me a lot like the editorial selection process for book manuscripts, articles, and so forth &#8212; editors receive a ton of submissions and they have to be choosy. Sometimes they don&#8217;t pick winners; sometimes they pick losers. More importantly, each has a personal style, opinions, preferences, and they are trying to appeal to a certain audience. It&#8217;s interesting to think that VCs are similar but makes sense&#8211;the end question of &#8220;What will be successful&#8221; really depends on the consumer base and industry, and VCs are just people who probably know and prefer to interact with a certain type of consumer base or audience.</p>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 06:23:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/investors chose">investors chose</category>
      <category domain="http://securityratty.com/tag/chose">chose</category>
      <category domain="http://securityratty.com/tag/investors">investors</category>
      <category domain="http://securityratty.com/tag/editorial selection process">editorial selection process</category>
      <category domain="http://securityratty.com/tag/investors choose">investors choose</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/selection process">selection process</category>
      <category domain="http://securityratty.com/tag/choose">choose</category>
      <category domain="http://securityratty.com/tag/mutual funds">mutual funds</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/355545351/">VCsChoosing How to Invest</source>
    </item>
    <item>
      <title><![CDATA[Neosploit Team Leaving the IT Underground]]></title>
      <link>http://securityratty.com/article/813abe559b03df47822588023daf2295</link>
      <guid>http://securityratty.com/article/813abe559b03df47822588023daf2295</guid>
      <description><![CDATA[The Neosploit Team are abandoning support for their Neosploit web exploitation malware kit , citing a negative return on investment as the main reason behind their decision. However, given Neosploit's...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SI-DiMO21SI/AAAAAAAAB-U/9aly5A7EaNE/s1600-h/Finjan_Neosploit_stats.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SI-DiMO21SI/AAAAAAAAB-U/AHkSBZ-vDq8/s200-R/Finjan_Neosploit_stats.png" style="border: 0pt none ;" /></a>The <a href="http://blogs.zdnet.com/security/?p=1598">Neosploit Team are abandoning support for their Neosploit web exploitation malware kit</a>, citing a negative return on investment as the main reason behind their decision. However, given <a href="http://ddanchev.blogspot.com/2008/07/neosploit-malware-kit-updated-with.html">Neosploit's open source nature</a> just like the majority of web malware kits, and the fact that it's slowly, but surely turning into a commodity malware kit just like MPack and Icepack did, greatly contribute to its extended "product lifecycle" :<br />
<br />
"<i>Let’s discuss their business model, how other cybercriminals disintermediated it thereby ruining it, and most importantly, how is it possible that such a popular web malware exploitation kit cannot seem to achieve a positive return on investment (ROI). The short answer is - piracy in the IT underground, and their over-optimistic assumption that high-profit margins can compensate the lack of long-term growth strategy, which in respect to web malware exploitation kits has do with the benefits coming from converging with traffic management tools. Let’s discuss some key points.</i>"<br />
<br />
<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1314">The end of Neosploit malware kit</a>, doesn't mean the end of Neosploit Team, or the sudden migration to other malware kits since they're no longer providing support in the form of new obfuscations and set of exploits to their customers. Their customers have been in fact self-servicing their needs enjoying the modular nature of the kit, the result of which is an unknown number of modified Neosploit kits.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French&nbsp;</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f1z5QJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f1z5QJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7VkrqJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7VkrqJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7RVKZj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7RVKZj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ByTryj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ByTryj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YuSB5J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YuSB5J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=owMSNJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=owMSNJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=82yAwj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=82yAwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/349806900" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 12:09:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/neosploit">neosploit</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/icepack exploitation kit">icepack exploitation kit</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware kits">malware kits</category>
      <category domain="http://securityratty.com/tag/web malware kits">web malware kits</category>
      <category domain="http://securityratty.com/tag/commodity malware kit">commodity malware kit</category>
      <category domain="http://securityratty.com/tag/source malware">source malware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/349806900/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</source>
    </item>
    <item>
      <title><![CDATA[In the great NAC debate, Snyder KOs Stiennon in the first round!]]></title>
      <link>http://securityratty.com/article/257e5281878e732cc8ef2afaee430827</link>
      <guid>http://securityratty.com/article/257e5281878e732cc8ef2afaee430827</guid>
      <description><![CDATA[Just got done reading the transcript of yesterdays great NAC debate between Joel Snyder and Richard Stiennon. As I predicted Snyder scored a knockout early on and it was mostly over from that point...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/boxer.jpg"><img title="boxer" style="border-right: 0px; border-top: 0px; margin: 0px 0px 5px 5px; border-left: 0px; border-bottom: 0px" height="124" alt="boxer" src="http://www.stillsecureafteralltheseyears.com/ashimmy/WindowsLiveWriter/boxer_thumb.jpg" width="142" align="right" border="0"></img></a> Just got done <a href="http://www.networkworld.com/chat/archive/2008/072308-snyder-stiennon-nac-debate.html">reading the transcript</a> of yesterdays great NAC debate between Joel Snyder and Richard Stiennon.  As I predicted Snyder scored a knockout early on and it was mostly over from that point on.  The knockout came earlier than I expected though, right off the first question.  Each combatant was asked to define NAC and that was when it happened.  Richard brought an EPAC (end point access control) to a NAC fight.  That was akin to him bringing a rubber knife to a gun fight.  A quick bullet between the eyes by Snyder and it was almost painlessly over for Richard.</p>  <p>I have been preaching for some time about what I call complete NAC. That is a complete network access control solution, not just network admission control and certainly not end point access control.  It is not an evil plot to extend Cisco/Microsoft dominance and most importantly Richard, no one and let me say this again, no one has ever said that NAC negates the need for a layered security model.  NAC is just another layer in that model.  Richard’s comments deriding the .edu and .mil markets were also laughable.  Richard, have you ever heard the term military grade?  Are you seriously trying to say that enterprises take security more seriously than the military does?  Come on now Richard.</p>  <p>The bottom line is Joel Snyder is not only a sharp dude technically, but is street savvy enough to run circles around my friend Richard.  He made Richard stay focused on the question at hand, did not let him wander and so Richard had to face reality a bit. I am sure Richard will still say NAC is useless and <a href="http://securityuncorked.squarespace.com/security-uncorked/2008/7/22/hps-nac-what-ive-been-wanting-to-tell-you-but-couldnt.html">will admonish people about hanging out with the likes of the StillSecure</a> crowd, but I guess some things will just never change.  Except, I don’t think Richard will be in anymore of these bouts.  Maybe he can start selling a grill that takes the fat out of meat or perhaps a reality TV show like the other washed up palookas ?</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=ZeWwIp"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=ZeWwIp" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=9TwouJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=9TwouJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JHaO4J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JHaO4J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=vbaihJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=vbaihJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=QDT1DJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=QDT1DJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=jnZSlj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=jnZSlj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=6zfMHj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=6zfMHj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/344260979" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 20:13:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/richard">richard</category>
      <category domain="http://securityratty.com/tag/importantly richard">importantly richard</category>
      <category domain="http://securityratty.com/tag/richard stiennon">richard stiennon</category>
      <category domain="http://securityratty.com/tag/snyder">snyder</category>
      <category domain="http://securityratty.com/tag/friend richard">friend richard</category>
      <category domain="http://securityratty.com/tag/define nac">define nac</category>
      <category domain="http://securityratty.com/tag/nac fight">nac fight</category>
      <category domain="http://securityratty.com/tag/richard stay">richard stay</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/344260979/in-the-great-na.html">In the great NAC debate, Snyder KOs Stiennon in the first round!</source>
    </item>
  </channel>
</rss>
