<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: job-seekers]]></title>
    <link>http://securityratty.com/tag/job-seekers</link>
    <description></description>
    <pubDate>Wed, 25 Jun 2008 13:52:40 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[U.S. Arms Dealer Tests Legal Bounds in Middle East Arms Bazaar]]></title>
      <link>http://securityratty.com/article/a494b708fadf3d4f453c6495d8064dc2</link>
      <guid>http://securityratty.com/article/a494b708fadf3d4f453c6495d8064dc2</guid>
      <description><![CDATA[Former congressman Curt Weldon is helping broker deals between Russian and Ukranian weapons suppliers and the Iraqi and Libyan governments as part of his new job with a private American defense...]]></description>
      <content:encoded><![CDATA[<p>
Former congressman Curt Weldon is helping broker deals between Russian and Ukranian weapons suppliers and the Iraqi and Libyan governments as part of his new job with a private American defense consulting firm, Wired.com has learned. 
</p>

<p>
Weldon, who is currently being investigated by the FBI over alleged corruption during his time in office, visited Libya in March to discuss a possible military deal, according to a letter describing the trip from Weldon to <a href="http://www.ds-pa.com/">Defense Solutions</a> CEO Timothy Ringgold. In May, Weldon, together with Ringgold and another company representative, traveled to Moscow to discuss working with Russia's weapons-export agency on arms sales to the Middle East.
</p>

<p>
Both trips were part of the company's effort to tap into the growing -- and often legally murky -- market for selling weapons from former Eastern Bloc countries to the Middle East and Afghanistan.
</p>



<div id="embed" style="margin: 0px 0px 15px 15px; float: right; width: 250px; height: auto;">

<img src="http://www.wired.com/images/article/full/2008/07/weldon_350px.jpg" width="250px" alt="Curt Weldon">

<div id="caption">

Ex-Rep. Curt Weldon, R-Penn., is helping broker deals between Russian weapons suppliers and the Iraqi and Libyan governments through his company, Defense Solutions.<br />
<em>Photo: H. Rumph Jr/AP</em>

</div> 

</div>

<p>
The Russians want to sell weapons to Iraq directly, but "must go slow on Iraq because of political reasons" and want to work with an "intermediary" like Defense Solutions, CEO Ringgold subsequently wrote to colleagues. "They have not spoken with any American company that can offer the quid pro quo that we can or that has the connections in Russia that we have," he boasted.
</p>



<p>
A few years ago, an American company proposing to sell weapons to Libya might have triggered a congressional hearing. So, too, would have a proposal to conduct arms deals with Russia, which the United States has accused of selling high-tech weapons to Syria and Iran. 
</p>

<p>However, U.S. government efforts to rapidly equip countries like Afghanistan and Iraq -- which have largely Soviet-origin weapons -- have created legal ambiguities and loopholes in export controls that didn't exist in years past and given rise to a new class of arms trade middlemen. So, even though both Libya and the Russian arms export agency are on official U.S. blacklists, government officials and analysts involved in weapons sales say the rules have become unclear as the push to equip allies in the global war on terror has blazed new but uncertain legal ground. 
</p>




<p>
Eagerly stepping into that virgin territory is <a href="http://www.ds-pa.com/">Defense Solutions</a>, a Pennsylvania-based company that is carving out a small but lucrative niche in a new international arms bazaar. The firm boasts as its advisors a number of influential Washington insiders, such as retired General Barry McCaffrey, the former White House drug czar.
</p>

<p>
Helping the firm make key connections is Curt Weldon, a former Republican congressman from Pennsylvania at the center of an FBI investigation into alleged conflicts of interest during his time in office.  Weldon, now a key executive at Defense Solutions, is working with the company to set up these weapons deals.
</p>

<div id="embed" style="margin: 0px 0px 15px 15px; float: right; width: 350px; height: auto;">

<img src="http://www.wired.com/images/article/full/2008/07/btr_60_350px.jpg" alt="">

<div id="caption">

Defense Solutions has also proposed refurbishing Libya's BTR-60 armored personnel carriers, according to a sales proposal seen by Wired.com. Defense Solutions denies drafting a sales proposal to Libya.

</div> 

</div>

<p>
It's an unusual, if not an entirely unexpected chapter for Weldon, whose time in office included frequent trips to Russia. As an influential member of the House Armed Services Committee, Weldon pushed for multibillion-dollar defense programs, like ballistic missile defense, and earned a reputation as a foreign policy gadfly, boasting of his contacts with officials in nations labeled by the administration as "rogue states" such as Libya and North Korea. Weldon's wild claims about a 9/11 cover-up and his sensationalist book warning of an Iranian terror plot, sometimes earned him official scorn and public ridicule, but it was accusations that he steered contracts to Eastern European businesses linked to his daughter's lobbying firm that drew the government's attention.
</p>


<!--pagebreak-->
<p>
Weldon was voted out of office in 2006 just weeks after the FBI raided his daughter's home, and that of one of her associates.
</p>

<p>
Weldon did not respond to e-mails and phone requests to be interviewed or comment for this article. But in a 2006 interview, before the FBI probe was public, Weldon spoke enthusiastically about setting up a "front company" to work with the Russian arms agency, Rosoboronexport. Weldon hoped this company could sell weapons to the Middle East, and other regions, particularly to countries where the U.S. has strained relations. He claimed the director of Rosoboronexport approached him to work with "an American company that would act as a front for weapons these nations want to buy."
</p>

<p>
Weldon called the proposal an "unbelievable offer."
</p>

<p>
The administration, he acknowledged at the time, did not welcome the idea of an American company selling Russian weapons to potentially unfriendly countries. But two years later, Weldon, now a private citizen and chief strategic officer for Defense Solutions, appears to be working on precisely that sort of deal. And whether illegal or not, Defense Solutions' business represents a new phenomenon in the international arms trade business.
</p>

<p>
In years past arms brokers -- firms or individuals who serve as middlemen to facilitate weapons sales between countries -- were largely the stuff of spy thrillers. Unlike traditional American defense companies, like Lockheed Martin or Boeing, which typically sell weapons directly to NATO countries or other governments regarded as friendly to the United States, brokers are often small outfits run by people with sometimes questionable experience and reputations they will sell to anyone. One of the most infamous arms brokers, a Russian named <a href="http://en.wikipedia.org/wiki/Victor_Bout">Viktor Bout</a>, is charged by the United States, United Nations, Interpol and others of funneling arms to terrorists and rebels around the world. He was recently arrested in Thailand. The United States is requesting his extradition on charges of supplying arms to a terrorist organization.
</p>

<div id="embed" style="margin: 0px 0px 15px 15px; float: right; width: 350px; height: auto;">

<img src="http://www.wired.com/images/article/full/2008/07/bmp_1_350px.jpg" alt="" />

<div id="caption">

Two Marines lower the trim vane on the front of an Iraqi BMP-1 mechanized infantry combat vehicle that was captured during Operation Desert Storm. The American defense consulting firm Defense Solutions has proposed refurbishing Libya's aging fleet of BMP-1s. Defense Solutions denies drafting a sales proposal to Libya.

</div> 

</div>

<p>
But ironically, Iraq has fueled a new market for these professional middlemen; the United States is funneling billions of dollars into modernizing Iraq's army so that the country's government can fend for itself after coalition troops withdraw. And Iraq's largely Soviet-equipped military is a natural market for Eastern European countries brimming with old or out-of-date equipment they would like to unload. The middlemen, in these cases, serve a key role by allowing the U.S. government to do business with an American company, which in turn buys equipment from Eastern Bloc countries in deals worth hundreds of millions of dollars, much of it financed with U.S. taxpayer dollars.
</p>

<p>
One of Defense Solutions' sales -- a deal to sell Hungarian-owed T-72 tanks to Iraq in 2005 -- was typical of these new foreign military sales. But on the more questionable side is the company's plans to work with Rosoboronexport, which is barred from doing business with the U.S. government, and Libya, which is still on the State Department's arms embargo list. 
</p>

<p>
The Eastern European-Middle East arms-brokering business, while in some cases sanctioned by the U.S. government, has run into problems, including outright corruption and quality. Defense contractor Dale Stoffel, the president of Wye Oak Technology, and another American were gunned down in Iraq in December 2004 after Stoffel alleged that the Iraqi Ministry of Defense was involved in a kickback scheme. Like Defense Solutions, the company Stoffel worked for was refurbishing the Iraq's army Eastern Bloc equipment.
</p>

<p>
Another problem is quality. Weapons from the former Soviet Bloc, which the U.S. military euphemistically calls "nonstandard equipment," have been flagged as substandard, acknowledges Brigadier General Charles Luckey, who is in charge of security assistance at <a href="http://www.mnstci.iraq.centcom.mil/">Multi-National Security Transition Command-Iraq</a>. In an interview from Iraq, Brigadier General Luckey said: "One of the frustrating things about buying nonstandard [weapons], is that I'm the guy who has to deal with the fact that some broker I've never heard of allowed weapons to get to Iraq before they were inspected."
</p>

<div id="embed" style="margin: 0px 0px 15px 15px; float: right; width: 350px; height: auto;">

<img src="http://www.wired.com/images/article/full/2008/07/tank_350px.jpg" alt="" />

<div id="caption">

Defense Solutions is carving a new niche in the arms trade, selling Soviet-made weapons to Middle Eastern countries like Afghanistan and Iraq. Defense Solutions sold Hungarian-owed T-72 tanks to Iraq in 2005.

</div> 

</div>


<p>
In one high-profile case, Iraqi officials alleged that a corrupt firm sold them $400 million in shoddy helicopters from Poland. More recently, a company led by a 21-year-old and a former masseur was offered a U.S. government contract worth nearly $300 million to sell ammunition to Afghanistan. The ammunition turned out to be outdated and of dubious origin and several people connected with the company have been indicted. A congressional investigation concluded that the company, which was on a State Department watch list, was able to take advantage of regulatory loopholes by using middlemen.
</p>

<p>
For those concerned about illicit arms trade, this new wave of weapons deals is rife with the potential for corruption and abuse, but for companies eager to pursue markets once regarded as dubious, it represents a lucrative business opportunity.  The problem in these cases, according to those familiar with arms sales, is that it's no longer clear what's legal and what's not.
</p>
<!--pagebreak-->
<p>
Rachel Stohl, an expert on international arms trade and a senior analyst at Center for Defense Information, says that in many ways, the rush to equip Iraq has led the United States to throw caution to the wind. She points to a report by the Government Accountability Office last year that found that some 190,000 weapons sold to Iraq have gone missing. "I think the reality is we won't know, until way after the fact, about all of these irregularities with the Iraq weapons provision program," she said. "We were providing them all these assault rifles that have gone missing. Why? They were not following the standard procedures that were in place."
</p>

<p>
But Iraq and Afghanistan aren't the only markets available to arms brokers like Defense Solutions. The gradual normalization of relations with Libya opens another door into a quasi-legal area of sales. 
</p>

<p>
Like Iraq, Libya has a substantial arsenal of Soviet-origin military weapons, offering a potential market for brokers working with Russia and other former Soviet states. But even when there's not an outright ban, sales to the Middle East are often fraught with controversy, particularly to countries like Libya, which was under international sanction for more than a decade. Even as sanctions against it have been lifted, European companies proposing to sell arms to Libya have faced steep criticism, particularly since the country is still ruled by dictator Muammar Gaddafi, who took power in a military coup in 1969. 
</p>

<p>
While the United States lifted Libya's "state sponsor of terrorism" designation in 2006, other restrictions, such as on the sale of arms, remain in place. A State Department spokesperson confirmed that exports of "lethal munitions" to Libya, such as tanks or related equipment, are still banned, although sales of nonlethal equipment are now allowed on a case-by-case basis.
</p>

<p>
In late March, Weldon traveled to Libya for a weeklong trip at the invitation of the <a href="http://gdf.org.ly/index.php?lang=ar&Page=101&lang=en">Gaddafi Foundation</a>, a group run by the son of Libya's leader, and the chairman of Libya's foreign affairs committee, according to <a href="http://blog.wired.com/defense/files/libya_trip_report.doc">the report he sent to Defense Solutions</a> (.pdf), a copy of which was obtained by Wired.com. The trip reports states: "Agreement reached for Weldon to quickly return to Libya for meetings with son [of Libyan leader Gaddafi] Morti regarding defense and security cooperation."
</p>

<p>
A document dated April 16, just two weeks after Weldon's trip, outlines Defense Solutions' proposal to Libya to refurbish the country's fleet of armored vehicles, including its T-72 tanks, BMP-1 infantry fighting vehicles, and BTR-60 armored personnel carriers. A copy of the sales proposal, also provided to Wired.com, is on Defense Solutions' letterhead, appears to bear the signature of company CEO Timothy Ringgold, and is addressed to Libya's defense procurement council. "Defense Solutions is committed to delivering a full end-to-end solution to its clients," the proposal states. "Besides refurbishing these vehicles, we are capable of providing a full logistics support package, including a two year supply of spare parts, maintenance and repair services, and operator, maintenance, and repair training."
</p>

<p>
In an interview with Wired.com, Ringgold admitted that he's interested in doing business in Libya and confirms receiving Weldon's trip report from Libya, but denies drafting or signing an arms-sale proposal. "I've never made such a document to Libya," Ringgold insisted, after being read the proposal, and told that his signature is on it.
</p>

<p>
In addition to the Libyan arms-deal document, Wired.com has also reviewed copies of e-mails from Ringgold discussing the Libyan deal.
</p>

<p>
While Ringgold denies proposing an arms sale to Libya, he is open about speaking with Rosoboronexport, which has been on a U.S. government sanctions list since 2006, after the Russian state agency allegedly violated the Iran and Syria Nonproliferation Act. An April e-mail provided to Wired.com describes Ringgold, Weldon and Stephan Minikes, a senior advisor to Defense Solutions and a former ambassador, meeting with Rosoboronexport. The conversations included a number of potential deals, including supplying Mi-17 helicopters to Afghanistan and spare parts for Iraq's infantry fighting vehicles. Ringgold wrote to colleagues following the visit, describing the meetings as a "spectacular success," saying the Russian agency "has the ability to undercut all cost proposals from brokers."
</p>

<p>
Ringgold confirmed those discussions and said that his company has sought to do business with Rosoboronexport. Asked whether Ringgold considers his dealings with Russia to be legal, he argued that U.S. companies could work with Rosoboronexport on a "case-by-case" basis. "The particular purpose of the meeting we had -- and I want to be crystal clear -- was in response to a U.S. government requirement," he said.
</p>

<p>
A number of officials at the State Department and in the Pentagon, when contacted for this article, could not say whether working with Rosoboronexport is legal or not. A Pentagon spokeswoman said she was familiar with the issue, but deferred the question to the State Department. When asked about Rosoboronexport's status on the blacklist, John Herzberg, a State Department spokesman replied: "What's on there is on there."
</p>

<p>
Asked whether, given the ban, there was any way a company could legally work with Rosoboronexport, as Ringgold suggested, Herzberg provided an equivocal answer. "At the stage of the process we're at, I'm unable to give you an answer," he said. "You can try elsewhere in government, and maybe they'll be braver than me."
</p>

<p>
In an interview from Iraq, General Luckey conceded it was a murky area, but said, "My understanding is they are currently on our no-go list." 
</p>

<p>
The confusion over debarred parties has even led the U.S. government into its own legal tangles, according to Jim McAleese, a Washington attorney who specializes in government contracting and foreign military sales. Because the Russian government violated U.S. nonproliferation laws, even NASA had to go to Congress to ensure it could work with Russia on Soyuz flights to the international space station. "What I'm warning you about is, don't be surprised by the confusion," McAleese said. "There are a whole bunch of different statutes that were adopted piecemeal and were never intended to be reconciled."
</p>

<p>
But it's the very ambiguity of the law that troubles those who monitor export control. "It's highly unusual to do anything with the Russians, particularly Rosoboronexport," said Scott Jones, director of Export Control Programs at the <a href="http://www.uga.edu/cits/">Center for International Trade and Security</a> at the University of Georgia. 
</p>

<p>
Legal or not, reputable American companies simply don't want to work with banned entities, Jones said, for fear of risking their reputations and business. "Even if it's not an outright prohibition, most companies don't want to put themselves in a liability situation that has really bad PR … and they stay away from it," Jones said. "But if that's your business, pimping out arms from the U.S. or Russia, that's the way it works, and you push as much as possible."
</p>

<p>
Finding any U.S. defense company working with the Russian government at this point would be "remarkable," Jones added.
</p>

<p>
In the meantime, the future for Weldon is unclear. The FBI investigation continues and Weldon's former chief of staff recently pleaded guilty to a conspiracy charge and is cooperating with the government, notes Melanie Sloan, the executive director of <a href="http://www.citizensforethics.org/">Citizens for Responsibility and Ethics in Washington</a>, which filed a complaint against Weldon in 2004. Sloan speculated that Weldon may be charged with "honest service fraud" for misusing his office for personal gain. "It's an easier standard than bribery," she said. "I wouldn't be surprised [if he's charged] with bribery, but I think it will be honest services fraud."
</p>

<p>
Ringgold insists that he and Weldon are on the right side of the law. "Everything we do is in strict compliance with international and U.S. law and we operate only in the best interests of the U.S. government," he said. "I didn't serve 30 years in the United States Army to throw that away on a whim."
</p>

<p>
Asked if Weldon is still working for the company, Ringgold replied: "Absolutely, proudly so." 
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=3c1b81ed8ecb441b359b5fd6e6dec750" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=3c1b81ed8ecb441b359b5fd6e6dec750" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=f5EjSJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=f5EjSJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zYmkhj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zYmkhj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=S9Ojfj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=S9Ojfj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=xPEQRJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=xPEQRJ" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=OTsesJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OTsesJ" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=wFj1Jj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=wFj1Jj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=OExjrj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OExjrj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=DKk6TJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=DKk6TJ" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/326164069" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/326164070" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 03 Jul 2008 18:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/arms brokers">arms brokers</category>
      <category domain="http://securityratty.com/tag/brokers">brokers</category>
      <category domain="http://securityratty.com/tag/infamous arms brokers">infamous arms brokers</category>
      <category domain="http://securityratty.com/tag/defense">defense</category>
      <category domain="http://securityratty.com/tag/firm defense solutions">firm defense solutions</category>
      <category domain="http://securityratty.com/tag/arms">arms</category>
      <category domain="http://securityratty.com/tag/arms trade">arms trade</category>
      <category domain="http://securityratty.com/tag/international arms trade">international arms trade</category>
      <category domain="http://securityratty.com/tag/russian weapons suppliers">russian weapons suppliers</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/326164070/defense_solutions">U.S. Arms Dealer Tests Legal Bounds in Middle East Arms Bazaar</source>
    </item>
    <item>
      <title><![CDATA[The Governments Top Hackers?]]></title>
      <link>http://securityratty.com/article/a278ca43d573699cd7a0146f62317f26</link>
      <guid>http://securityratty.com/article/a278ca43d573699cd7a0146f62317f26</guid>
      <description><![CDATA[Popular Mechanics recently published an article about the NSA Red Team , which caught my interest, having been a part of that organization for a short stint back in early 2000. The article does a...]]></description>
      <content:encoded><![CDATA[<p>Popular Mechanics recently published an article about the <a href="http://www.popularmechanics.com/technology/military_law/4270420.html">NSA Red Team</a>, which caught my interest, having been a part of that organization for a short stint back in early 2000.  The article does a decent job of describing the Red Team&#8217;s charter, which is essentially to attack DOD targets in an attempt to simulate real adversaries, not unlike a consultant running a pen test against a corporation.  The rules of engagement are similar to most pen tests: don&#8217;t DoS the target, don&#8217;t install malware, generally be non-destructive.  </p>
<p>Disappointingly, the author sprinkles the usual super-secret uber-hacker spin throughout the article to make the Red Team seem mysterious and exclusive, with untouchable talent.  It&#8217;s a little misleading. For starters, there&#8217;s the predictable question about success rates:</p>
<blockquote><p>I’d heard from one of the Department of Defense clients who had previously worked with the NSA red team that OWNSAVAOG and his team had a success rate of close to 100 percent. “We don’t keep statistics on that,” OWNSAVAOG insisted when I pressed him on an internal measuring stick.</p></blockquote>
<p>This is one of those statements that is difficult for the average reader to interpret.  It&#8217;s intended to make the team sound like a crack squad of hackers, but in reality it&#8217;s the same statistic that every security consultancy cites during sales calls.  The truth is, there&#8217;s a lot of wiggle room on what is considered &#8220;getting in&#8221; to the target.  For example, some would say that brute forcing an FTP server and downloading some FOUO (For Official Use Only) documents constitutes penetrating the target.  Others would disagree.</p>
<p>How about personnel? I thought this was an englightening and accurate statement from the unnamed NSA source:</p>
<blockquote><p>And like any good geek at a desk talking to a guy with a really cool job, I wondered just where the NSA finds the members of its superhacker squad. “The bulk is military personnel, civilian government employees and a small cadre of contractors,” OWNSAVAOG says. The military guys mainly conduct the ops (the actual breaking and entering stuff), while the civilians and contractors mainly write code to support their endeavors. For those of you looking for a gig in the ultrasecret world of red teaming, this top hacker says the ideal profile is someone with “technical skills, an adversarial mind-set, perseverance and imagination.”</p></blockquote>
<p>He basically admits that the team consists mostly of people who &#8220;run the tools&#8221; and only a handful that actually write the tools or do anything cutting-edge.  It shouldn&#8217;t be that surprising; just as in any large consulting organization, you have some people who run scanners/tools and aren&#8217;t expected to be terribly analytical.  While the Red Team almost certainly has some superstars, on the whole it is similar in both skillset and composition to a typical consultancy or enterprise security team.</p>
<p>In terms of attracting and retaining top talent, the Red Team faces the same challenges as the rest of the information security industry, with the built-in disadvantage of the <a href="http://www.opm.gov/oca/08tables/pdf/DCB.pdf">government pay scale</a>.  If that wasn&#8217;t bad enough, they also have to <i>compete with themselves</i> (i.e. the rest of the NSA) for already scarce resources.  Given these challenges, how could one realistically expect the Red Team to be as advanced as the article portrays?</p>
<p>Finally, let&#8217;s dispel the &#8220;super-secret&#8221; notion &#8212; unless things have changed significantly, the majority of Red Team operations are unclassified.  Granted, detailed information is guarded, but you can find reports summarizing <a href="http://www.fas.org/irp/crs/RL30735.pdf">past operations</a> if you dig around a bit.  One would expect that an operation intended to be truly secretive would never make its way into Google search results.</p>
<p>I want to conclude by saying that this post is not intended to cast the Red Team itself in a negative light.  I enjoyed my time there and had the opportunity to work with some smart people.   The Red Team&#8217;s goals are worthy and noble; clearly, state-sponsored cyberterrorism is a <a href="http://www.spiegel.de/international/germany/0,1518,550212,00.html">growing</a> <a href="http://www.crn.com/security/208403765">concern</a> and as a country we should be as prepared as possible.  But realize that we have a long way to go.</p>
]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 14:40:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/nsa red team">nsa red team</category>
      <category domain="http://securityratty.com/tag/red team">red team</category>
      <category domain="http://securityratty.com/tag/team sound">team sound</category>
      <category domain="http://securityratty.com/tag/red team operations">red team operations</category>
      <category domain="http://securityratty.com/tag/nsa">nsa</category>
      <category domain="http://securityratty.com/tag/red">red</category>
      <category domain="http://securityratty.com/tag/red teams charter">red teams charter</category>
      <category domain="http://securityratty.com/tag/enterprise security team">enterprise security team</category>
      <source url="http://www.veracode.com/blog/?p=117">The Governments Top Hackers?</source>
    </item>
    <item>
      <title><![CDATA[SP 800-53A Now Finally Final]]></title>
      <link>http://securityratty.com/article/5dfd935d866322acbf482eda2099739d</link>
      <guid>http://securityratty.com/article/5dfd935d866322acbf482eda2099739d</guid>
      <description><![CDATA[The perpetual draft document, SP 800-53A, has been officially released after 3 years. Check out the announcement from NIST here
Now the interesting thing to me is that NIST is working with some other...]]></description>
      <content:encoded><![CDATA[<p>The perpetual draft document, SP 800-53A, has been officially released after 3 years.  Check out the <a href="http://csrc.nist.gov/news_events/index.html#june30" target="_blank">announcement from NIST here</a>.</p>
<p>Now the interesting thing to me is that NIST is working with some other players (DNI comes to mind) on reference implementations of 800-53A.  This is big, so big that I can&#8217;t add enough hyperbole to it.</p>
<p>Why do they need to do reference implementations?  Well, because by itself, SP 800-53A is dangerous if it&#8217;s given to people who &#8220;don&#8217;t get it&#8221;.  By that what I mean is this:</p>
<ul>
<li>SP 800-53 needs tailoring to distill into actual requirements.</li>
<li>SP 800-53A needs a huge amount of tailoring to distill into test cases/procedures that match the tailoring that you did with 800-53.</li>
<li>Taken at face value, 800-53 and 800-53A become the source of &#8220;death by compliance&#8221;.</li>
<li>If you think the auditors could grill you to death with 800-53, 800-53A gives them tons more material.</li>
</ul>
<p>Now time for a war story: I worked on a project where the contractor was having a hard time building a security program, mostly because they didn&#8217;t have the right staff to get the job done.  The government told the contractor to use 800-53A as a starting point, and 6 months of insanity followed with 13 &#8220;security engineers&#8221; in a conference room cranking out documentation that had no basis in reality.  At the end of it all, the contractor handed the Government a bill for $1M.</p>
<p>Now don&#8217;t get me wrong, I like the ideas behind 800-53A, but the first thing you need to know when you start using it is when you shouldn&#8217;t use it:</p>
<ul>
<li>Don&#8217;t run test procedures on every computer you have, use an automated tool and do spot-checks to validate that the automated tool works.</li>
<li>Use less test procedures on low-criticality systems.</li>
<li>&#8220;This procedure is conducted as part of the hardening validation process.&#8221;</li>
<li>Common controls are even more important because you do not want the repetition of effort.</li>
</ul>
<p>And whatever you do, don&#8217;t let 800-53A turn your risk management into a compliance activity.  It has all the potential to do that.</p>
<p style="text-align: center;"><em><img src="http://farm3.static.flickr.com/2276/2204043603_655a617fa3.jpg?v=0" alt="US Government Docs" width="358" height="500" /></em></p>
<p style="text-align: center;"><em>US Government Doc&#8217;s photo by </em><a href="http://www.flickr.com/photos/manchesterlibrary/" target="_blank"><em>Manchester Library</em></a><em>.</em></p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/429&amp;title=SP+800-53A+Now+Finally+Final" title="Add 'SP 800-53A Now Finally Final' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'SP 800-53A Now Finally Final' to Del.icio.us" alt="Add 'SP 800-53A Now Finally Final' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/429&amp;title=SP+800-53A+Now+Finally+Final" title="Add 'SP 800-53A Now Finally Final' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'SP 800-53A Now Finally Final' to digg" alt="Add 'SP 800-53A Now Finally Final' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/429&amp;title=SP+800-53A+Now+Finally+Final" title="Add 'SP 800-53A Now Finally Final' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'SP 800-53A Now Finally Final' to reddit" alt="Add 'SP 800-53A Now Finally Final' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=SP+800-53A+Now+Finally+Final&amp;url=http://www.guerilla-ciso.com/archives/429&amp;version=0.7" title="Add 'SP 800-53A Now Finally Final' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'SP 800-53A Now Finally Final' to Feed Me Links" alt="Add 'SP 800-53A Now Finally Final' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/429" title="Add 'SP 800-53A Now Finally Final' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'SP 800-53A Now Finally Final' to Technorati" alt="Add 'SP 800-53A Now Finally Final' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/429&amp;t=SP+800-53A+Now+Finally+Final" title="Add 'SP 800-53A Now Finally Final' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'SP 800-53A Now Finally Final' to Yahoo My Web" alt="Add 'SP 800-53A Now Finally Final' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/429&amp;title=SP+800-53A+Now+Finally+Final" title="Add 'SP 800-53A Now Finally Final' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'SP 800-53A Now Finally Final' to Stumble Upon" alt="Add 'SP 800-53A Now Finally Final' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/429&amp;title=SP+800-53A+Now+Finally+Final" title="Add 'SP 800-53A Now Finally Final' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'SP 800-53A Now Finally Final' to Google Bookmarks" alt="Add 'SP 800-53A Now Finally Final' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/429" title="Add 'SP 800-53A Now Finally Final' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'SP 800-53A Now Finally Final' to Squidoo" alt="Add 'SP 800-53A Now Finally Final' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/429" title="Add 'SP 800-53A Now Finally Final' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'SP 800-53A Now Finally Final' to Bloglines" alt="Add 'SP 800-53A Now Finally Final' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=zZzAUJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=zZzAUJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=LkJVEj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=LkJVEj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/323993549" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 08:08:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/800-53a">800-53a</category>
      <category domain="http://securityratty.com/tag/government docs photo">government docs photo</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/reference implementations">reference implementations</category>
      <category domain="http://securityratty.com/tag/test procedures">test procedures</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/hard time">hard time</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/perpetual draft document">perpetual draft document</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/323993549/429">SP 800-53A Now Finally Final</source>
    </item>
    <item>
      <title><![CDATA[Symantec's Network-Based NAC]]></title>
      <link>http://securityratty.com/article/bdbd7433d55560c26d1c9ef1bc5869bd</link>
      <guid>http://securityratty.com/article/bdbd7433d55560c26d1c9ef1bc5869bd</guid>
      <description><![CDATA[Yes, you read it right - Symantec (as in the software vendor) has a network-based (as in the hardware) NAC. Once you get over the title, keep reading
If you read my blog, or know me, you probably know...]]></description>
      <content:encoded><![CDATA[<p><strong>Yes, you read it right</strong>- <a class="offsite-link-inline" href="http://www.symantec.com/" target="_blank">Symantec</a>&nbsp;(as in the software vendor) has a network-based (as in the hardware) NAC. Once you get over the title, keep reading. </p><p>If you read my blog, or know me, you probably know I do NOT like software (and it usually doesn&#8217;t like me). So, I&#8217;d be the first to jump on the <em>&#8216;anti-software-peer-based-NAC&#8217; </em>train, but I think we have to be informed before we jump to conclusions and hop on any trains. </p><p>Mirage&#8217;s recent blog post on Symantec&#8217;s <a class="offsite-link-inline" href="http://www.mirageblog.com/cto/2008/06/silly-snacs.html" target="_blank">&#8216;Silly SNAC&#8217;</a> was certainly a result of a mis- (or un-) informed person. Tim did a much better job on his mention of SNAC in the <a class="offsite-link-inline" href="http://www.networkworld.com/newsletters/vpn/2008/060208nac1.html?nladname=060308security:networkaccesscontrolal&code=nlnac141990" target="_blank">NWW blog</a>, but all the dots still aren&#8217;t connected. It proves the point that sometimes we (as bloggers) tend to write based on a feeling and sometimes don&#8217;t dig for the fact. </p><p>So, in an effort to make sure I understood this new peer-based NAC, I reached out to <a class="offsite-link-inline" href="http://www.linkedin.com/pub/0/67/617" target="_blank">Patrick Wheeler</a>, Symantec&#8217;s Senior Product Manager for Network and Endpoint Security. Based on my conversations with him, and a pretty detailed investigation into the options and configurations of their NAC products, I have some slightly more informed opinion to share with you now. </p><p><strong>Symantec has a variety of NAC enforcement components and options</strong>. I&#8217;m going to keep all the software-type-stuff out of this conversation for the time being. They have (among other things) the <strong>NAC Enforcer</strong>, an appliance similar to the other NAC controllers we see from traditional hardware vendors. Just like it&#8217;s counterparts, Symantec&#8217;s NAC Enforcer can be configured for DHCP, inline or 802.1X based enforcement. </p><p>The piece that&#8217;s different is the integration of the NAC Enforcer with Symantec&#8217;s Endpoint Protection Manager server that hosts the policies for the NAC. It&#8217;s similar to the management-enforcement configuration we see from other vendors, only the management piece is housed on a server instead of another appliance. </p><p><span class="full-image-float-right"><img style="width: 343px; height: 197px" alt="SNAC_snippit1b.jpg" src="http://www.securityuncorked.com/storage/SNAC_snippit1b.jpg?__SQUARESPACE_CACHEVERSION=1214796728100" /></span>And, just as other vendors offer some type of endpoint integrity agent, the Symantec agent comes in the form of the Symantec NAC Client, which can be used by itself, or integrated with the Symantec Endpoint Protection Client for an even more robust feature-set. (The Endpoint Protection Client offers some additional host-based firewall features that the NAC can leverage). </p><p><strong>So, what about the Peer-Based NAC?</strong> Ah, well that&#8217;s just the first iteration&nbsp;of a &#8216;vision&#8217; to address mobile corporate users. If employees have laptops in an ad-hoc situation outside of the enterprise infrastructure (and therefore, outside of&nbsp;enterprise enforcement), then the peer-based NAC can port the enforcement rules set at the &#8216;mothership&#8217; and enforce them individually.&nbsp;The peer-based NAC can protect mobile assets in their most vulnerable situation, outside the security of the corporate network. But, the rules are still set centrally and the peer-based NAC&nbsp;was designed to be&nbsp;just one step towards an added layer of protection, not as a replacement for network-based NAC. </p><p><strong>For now, I&#8217;ll stay off the hate train</strong>, since the peer-based NAC is more of a supplement to a more robust traditional NAC solution. If they move to a fully-host-enforced product, I&#8217;ll buy my tickets&#8230;</p><p><span class="sizeLess20">Image shown is copyright of Symantec Corporation.</span> </p><p># # #</p>
]]></content:encoded>
      <pubDate>Sun, 29 Jun 2008 23:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/nac enforcement components">nac enforcement components</category>
      <category domain="http://securityratty.com/tag/nac controllers">nac controllers</category>
      <category domain="http://securityratty.com/tag/nac products">nac products</category>
      <category domain="http://securityratty.com/tag/nac enforcer">nac enforcer</category>
      <category domain="http://securityratty.com/tag/symantecs nac enforcer">symantecs nac enforcer</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/symantec nac client">symantec nac client</category>
      <category domain="http://securityratty.com/tag/symantec corporation">symantec corporation</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/6/30/symantecs-network-based-nac.html">Symantec's Network-Based NAC</source>
    </item>
    <item>
      <title><![CDATA[The 802.1X Hat-Trick]]></title>
      <link>http://securityratty.com/article/09d9695144200f268c18e0c036eec36b</link>
      <guid>http://securityratty.com/article/09d9695144200f268c18e0c036eec36b</guid>
      <description><![CDATA[Well my recent blogging , or lack there of, may have clued you in on my recent hectic travel schedule. Its June, and that means the end of governments fiscal year, so weve been busy little bees at the...]]></description>
      <content:encoded><![CDATA[<p>Well my recent <a href="http://security.squarespace.com/" target="_blank">blogging</a>, or lack there of, may have clued you in on my recent hectic travel schedule. It&#8217;s June, and that means the end of government&#8217;s fiscal year, so we&#8217;ve been busy little bees at the office. (Read my <a href="http://www.securityuncorked.com/security-uncorked/2008/4/2/what-is-8021x-heres-a-technology-primer-for-you.html" target="_blank">primer on 802.1X</a>&nbsp;here.)</p><p><strong>For June, we have an 802.1X <a class="offsite-link-inline" href="http://en.wikipedia.org/wiki/Hat_trick" target="_blank">hat-trick</a>&nbsp;to blame</strong> for my slack blogging habits. Over the past few weeks, I&#8217;ve had back-to-back 802.1X implementations, one wired, one wireless and one with both. Two government customers and one commercial, not in that order. And&nbsp;I&nbsp;even did one semi-training-slash-semi-implementation-quick-start&nbsp;for another&nbsp;customer. </p><p><strong>It&#8217;s been fun, but 1X is always challenging.</strong> The variety of components, the nature of the interactions and the &#8216;newness&#8217; of actual implementations make it difficult to work from any type of cookbook or implementation guide. There are just too many variables. </p><p><strong>When will it be easier?</strong> I think as 1X is more widely implemented in the real world, customers will become more familiar with the concepts and integrators will have more experience to make it go smoothly. For now, everyone has to just take it one step at a time and address issues as they arise. And, for now, I&#8217;ll enjoy the&nbsp;job security that 1X offers ;)</p><p>Luckily, I&#8217;ve&nbsp;had the opportunity to work with a variety of customers and a variety of environments and equipment while hammering out 802.1X. The experience and exposure has certainly given me a unique insight into the issues, complications and solutions that come along with a 1X project. </p><p>At present, I think&nbsp;we&#8217;ve successfully configured 1X on about a dozen different types of equipment, both switches and wireless APs and controllers, from a variety of vendors. It may not sound like much, but in the world of 1X, that&#8217;s quite a variety when you consider each manufacturer has their own &#8216;system&#8217; for configuring 1X and the commands and procedures can vary greatly even from product-to-product from the same vendor. </p><p><strong>Is the 1X streak over?</strong>&nbsp;Not at all. We have several customers with NAC and 802.1X projects that we had to queue up for after June 30. I&#8217;ll keep you posted!</p><p># # #</p><p>&nbsp;</p>
]]></content:encoded>
      <pubDate>Sun, 29 Jun 2008 22:39:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/government customers">government customers</category>
      <category domain="http://securityratty.com/tag/variety">variety</category>
      <category domain="http://securityratty.com/tag/real world">real world</category>
      <category domain="http://securityratty.com/tag/implementations">implementations</category>
      <category domain="http://securityratty.com/tag/wireless aps">wireless aps</category>
      <category domain="http://securityratty.com/tag/actual implementations">actual implementations</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/address issues">address issues</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/6/30/the-8021x-hat-trick.html">The 802.1X Hat-Trick</source>
    </item>
    <item>
      <title><![CDATA[Some firms don't admit security breaches - Geez, ya really think so?]]></title>
      <link>http://securityratty.com/article/b2d48452762f32280c4fe75aaeebe3a0</link>
      <guid>http://securityratty.com/article/b2d48452762f32280c4fe75aaeebe3a0</guid>
      <description><![CDATA[It's not often that security issues make mainstream media outlets. So when I saw this article on cbsnews.com I wanted to see what kind of &quot;investigative journalism&quot; the same folks who do 60 minutes...]]></description>
      <content:encoded><![CDATA[<p>It's not often that security issues make mainstream media outlets.  So when I saw <a href="http://www.cbsnews.com/stories/2008/06/27/tech/main4215439.shtml?source=RSSattr=SciTech_4215439">this article on cbsnews.com</a> I wanted to see what kind of "investigative journalism"  the same folks who do 60 minutes would bring to the story. The story takes the particular case of Direct Marketing Services, Inc, the parent company of Montgomery Ward. It does a good job documenting the breach, the discovery of the breach and how the company complied with credit card company rules by notifying Visa, Mastercard, Discover, etc. but did not notify the 51,000 potentially affected customers. It also does a nice job of giving credit to Affinion Group Inc.'s CardCops for spotting and discovering this theft.<br><br>The article than goes on to say that 44 states have passed statues making disclosure and notification of security and confidential breaches to affected consumers mandatory.  The article does caution though that based upon the volume of data being sold in "online black markets", there are many more breaches than we are being told about.  I think it good that CBS bangs the drums on this, but frankly that "evidence" is a bit flimsy.  I also found it gratifying that the article blames the credit card companies themselves for not doing more to publicize these breaches, so that they don't have to issue new cards.  Just goes to prove what has been written before, that in the bigger picture the cost of doing business may include the risk of compromised data and big business has determined that that is a risk worth taking.<br></p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=HEeJ6o"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=HEeJ6o" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=z6XLlI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=z6XLlI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=tQnkYI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=tQnkYI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2WqCEI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2WqCEI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=q88FzI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=q88FzI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=UhJOUi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=UhJOUi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=fje4Oi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=fje4Oi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/322801642" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 29 Jun 2008 12:51:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/breaches">breaches</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <category domain="http://securityratty.com/tag/article blames">article blames</category>
      <category domain="http://securityratty.com/tag/credit card companies">credit card companies</category>
      <category domain="http://securityratty.com/tag/confidential breaches">confidential breaches</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/nice job">nice job</category>
      <category domain="http://securityratty.com/tag/parent company">parent company</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/322801642/some-firms-dont.html">Some firms don't admit security breaches - Geez, ya really think so?</source>
    </item>
    <item>
      <title><![CDATA[Can you hear me now?]]></title>
      <link>http://securityratty.com/article/afde45737ad0a9346c45bdf544337ad3</link>
      <guid>http://securityratty.com/article/afde45737ad0a9346c45bdf544337ad3</guid>
      <description><![CDATA[Verizon released a very interesting Data Breach report that analyzes over 500 forensic reports on their system over a number of years. It is great work by Verizon to gather this data and to publish...]]></description>
      <content:encoded><![CDATA[<p>Verizon released a very interesting <a href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">Data Breach report</a> that analyzes over 500 forensic reports on their system over a number of years. It is great work by Verizon to gather this data and to publish it. Of course a consultant I go into lots of companies where they could learn a lot just by being more open and talking through issues with peers in other companies. Would be great to see other companies follow Verizon's lead.</p><br><div>I suggest you read their report, and I would like to add a little color to their findings from the perspective of the swamp I spend most of my time in - Web services security. Granted it is just one report, but the data run counter to a lot of conventional security "wisdom":</div><br><div><span style="color: #333333; font-size: 12px; line-height: normal; "><span style="text-decoration: underline;"><strong><blockquote><p>Who is behind data breaches? </p></blockquote></strong></span><blockquote><p>73% resulted from external sources<br>18% were caused by insiders <br>39% implicated business partners <br>30% involved multiple parties</p></blockquote></span><br></div><div>The internal/external divide is pretty silly these days, as is companies' recanting "inside the firewall and outside the firewall", I spend most of time hooking things up together precisely _so_ they intereoperate remotely. The firewall is a speed bump at best. At any rate external sources is a primary concern in Web services security, because - hey look our Web service front end just made your Mainframe/As400/Unix DB/ CICS/whatever accessible remotely. This is great from a functionality standpoint, but the issue is that these back end systems were never designed with anything remotely resembling an Internet threat model. Additionally, the Verizon team's findings around business parties and multiple parties strikes at the heart of a number of popular misconceptions in Web services security - "well its just B2B and its behind a firewall."</div><br><br><div><span style="color: #333333; font-size: 12px; line-height: normal; "><span style="text-decoration: underline;"><strong><blockquote><p>How do breaches occur? </p></blockquote></strong></span><blockquote><p><br>62% were attributed to a significant error</p></blockquote><blockquote><p>59% resulted from hacking and intrusions  </p></blockquote><blockquote><p>31% incorporated malicious code </p></blockquote><blockquote><p>22% exploited a vulnerability <br>15% were due to physical threats </p></blockquote></span><br></div><div><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;">A couple of things to note here - malicious code in my opinion is likely to be the biggest problem in Web services security going forward. There is a large gap waiting to be exploited here. You have no control over the other end of the pipe plus a massive attack surface, the only thing lacking is the attacker's ability to find and exploit which I strongly suspect is just a matter of time. Wrt hacking an intrusions we have the remote, passive nature of web security to blame here in Web services world. Paraphrasing </span><span style="color: #333333; font-size: 12px; line-height: normal; "><a href="http://www.aspectsecurity.com/">Jeff Williams</a></span><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;">, the problem is that an attacker can just try an attack if it doesn't work, try again, again, and so on. This partially because of the loosely coupled nature of the systems, but it is also because </span><span style="color: #333333; font-size: 12px; line-height: normal; "><a href="http://1raindrop.typepad.com/1_raindrop/2008/06/mashup-of-the-titans.html">commonly used information security protocols have diverged from reality</a></span><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;"> are modeled using an object-centric mentality, where you "own" the object you are protecting and can afford to put passive controls around.</span></div><div><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;"><br></span></div><div><span style="color: #333333; font-size: 12px; line-height: normal; "><span style="text-decoration: underline;"><strong><blockquote><p>What commonalities exist? </p></blockquote></strong></span><blockquote><p><br>66%  involved data the victim did not know was on the system<br>75%  of breaches were not discovered by the victim  <br>83%  of attacks were not highly difficult <br>85%  of breaches were the result of opportunistic attacks <br>87%  were considered avoidable through reasonable controls </p></blockquote></span></div><div><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;">Many of the attacks against Web Services are not difficult, in my </span><span style="color: #333333; font-size: 12px; line-height: normal; "><a href="http://arctecgroup.net/training.htm">training class</a></span><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;">, we'll typically execute 8-10 different attacks in a two day period. But the big one from this list is the first one - the amazing amount of attack surface offered up by Web services. </span><span style="color: #333333; font-size: 12px; line-height: normal; "><a href="http://isecpartners.com/">Brad Hill</a></span><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;"> has done a good job articulating these issues in SOAP/XML/WS-*, but at an enterprise its even bigger than those standards - the thing is we use Web services to make stuff interoperate, to make stuff reusable, and to virtualize endpoints. Great stuff if what you want to do is decentralize your business, but this creates oceans of space for attackers to roam. When you look beyond the Visio and the IDE view of web services, and get to the runtime there is an amazing amount of detritus left behind by all these layers.</span></div><div><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;"><br></span></div><div><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;"><br></span></div><div><span style="color: #333333; font-family: helvetica; font-size: 12px; line-height: normal;"><br></span></div>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 06:56:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web services">web services</category>
      <category domain="http://securityratty.com/tag/web services world">web services world</category>
      <category domain="http://securityratty.com/tag/web services security">web services security</category>
      <category domain="http://securityratty.com/tag/data breach report">data breach report</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/massive attack surface">massive attack surface</category>
      <category domain="http://securityratty.com/tag/companies follow verizon">companies follow verizon</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/06/can-you-hear-me-now.html">Can you hear me now?</source>
    </item>
    <item>
      <title><![CDATA[Needed: Agency CSOs]]></title>
      <link>http://securityratty.com/article/88e84c9df459b2e05803d8591fc27913</link>
      <guid>http://securityratty.com/article/88e84c9df459b2e05803d8591fc27913</guid>
      <description><![CDATA[Check out this article by Andy Boots on the Tech Insiders blog
It brings up an interesting point: Agencies do not typically have a CSO-level manager. According to FISMA, each agency has to have a CISO...]]></description>
      <content:encoded><![CDATA[<p>Check out <a href="http://techinsider.nextgov.com/2008/06/real_security_leaders_ignore_mission_security_at_their_organizations_peril.php" target="_blank">this article by Andy Boots </a>on the Tech Insiders blog.</p>
<p>It brings up an interesting point:  Agencies do not typically have a CSO-level manager.  According to FISMA, each agency has to have a CISO whose primary responsibility is information security.</p>
<p>But typically these CISOs do not have any authority over physical security or personnel security:  in reality, they work for the CIO and only have scope over what the CIO manages:  data centers, networks, servers, desktops, applications, and databases.</p>
<p>Except for one thing:  we&#8217;re giving today&#8217;s Government CISO a catalog of controls that contain physical and personnel security.  The &#8220;party line&#8221; that I&#8217;ve gotten from NIST is that the CISOs need to work through the CIO to effect change with the areas that are out of their control.  I personally think it&#8217;s a bunch of bull and that we&#8217;ve given CISOs all of the responsibility and none of the authority that they need to get the job done.  In my world, I call that a &#8220;scapegoat&#8221;.</p>
<p>To be honest, I think we&#8217;re doing a disservice to our CISOs, but the only way to fix it is to either move our existing CISOs out of the CIOs staff and make them true CxOs or write a law creating an agency CSO position just like Clinger-Cohen created the CIO and FISMA created the CISO.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Needed: Agency CSOs' to Del.icio.us" alt="Add 'Needed: Agency CSOs' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Needed: Agency CSOs' to digg" alt="Add 'Needed: Agency CSOs' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Needed: Agency CSOs' to reddit" alt="Add 'Needed: Agency CSOs' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Needed%3A+Agency+CSOs&amp;url=http://www.guerilla-ciso.com/archives/423&amp;version=0.7" title="Add 'Needed: Agency CSOs' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Needed: Agency CSOs' to Feed Me Links" alt="Add 'Needed: Agency CSOs' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/423" title="Add 'Needed: Agency CSOs' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Needed: Agency CSOs' to Technorati" alt="Add 'Needed: Agency CSOs' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/423&amp;t=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Needed: Agency CSOs' to Yahoo My Web" alt="Add 'Needed: Agency CSOs' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Needed: Agency CSOs' to Stumble Upon" alt="Add 'Needed: Agency CSOs' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/423&amp;title=Needed%3A+Agency+CSOs" title="Add 'Needed: Agency CSOs' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Needed: Agency CSOs' to Google Bookmarks" alt="Add 'Needed: Agency CSOs' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/423" title="Add 'Needed: Agency CSOs' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Needed: Agency CSOs' to Squidoo" alt="Add 'Needed: Agency CSOs' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/423" title="Add 'Needed: Agency CSOs' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Needed: Agency CSOs' to Bloglines" alt="Add 'Needed: Agency CSOs' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=JxUDlI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=JxUDlI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=QEC3li"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=QEC3li" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/320498593" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 08:49:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/agency">agency</category>
      <category domain="http://securityratty.com/tag/todays government ciso">todays government ciso</category>
      <category domain="http://securityratty.com/tag/cio">cio</category>
      <category domain="http://securityratty.com/tag/ciso">ciso</category>
      <category domain="http://securityratty.com/tag/cio manages">cio manages</category>
      <category domain="http://securityratty.com/tag/cisos">cisos</category>
      <category domain="http://securityratty.com/tag/agency cso position">agency cso position</category>
      <category domain="http://securityratty.com/tag/personnel security">personnel security</category>
      <category domain="http://securityratty.com/tag/responsibility">responsibility</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/320498593/423">Needed: Agency CSOs</source>
    </item>
    <item>
      <title><![CDATA[Decrease iSeries downtime caused by SAVSYS backup]]></title>
      <link>http://securityratty.com/article/29967fedc4ca3aa4621ceb0074e3bcfd</link>
      <guid>http://securityratty.com/article/29967fedc4ca3aa4621ceb0074e3bcfd</guid>
      <description><![CDATA[It is possible to save time on SAVSYS backups on the AS/400. The SAVSYS command requires that your system be in a restrictive state. The only active job in a restrictive state is the system console....]]></description>
      <content:encoded><![CDATA[It is possible to save time on SAVSYS backups on the AS/400. The SAVSYS command requires that your system be in a restrictive state. The only active job in a restrictive state is the system console. IBM has split the SAVSYS command into three parts, the second and third of which can run when the system is fully active.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/320045960" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 14:17:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/savsys command">savsys command</category>
      <category domain="http://securityratty.com/tag/savsys command requires">savsys command requires</category>
      <category domain="http://securityratty.com/tag/system console">system console</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/active">active</category>
      <category domain="http://securityratty.com/tag/active job">active job</category>
      <category domain="http://securityratty.com/tag/savsys backups">savsys backups</category>
      <category domain="http://securityratty.com/tag/restrictive">restrictive</category>
      <category domain="http://securityratty.com/tag/save time">save time</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/320045960/0,289625,sid3_gci1318861,00.html">Decrease iSeries downtime caused by SAVSYS backup</source>
    </item>
    <item>
      <title><![CDATA[Automatic email for backup job log on AS/400]]></title>
      <link>http://securityratty.com/article/ecbe7bc2e4023fb939b0f73b96fdafbf</link>
      <guid>http://securityratty.com/article/ecbe7bc2e4023fb939b0f73b96fdafbf</guid>
      <description><![CDATA[How to automatically generate an email after the job log on a System i has completed the...]]></description>
      <content:encoded><![CDATA[How to automatically generate an email after the job log on a System i has completed the backup.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/320036106" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 13:52:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/job log">job log</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/backup">backup</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/320036106/0,289625,sid3_gci1318856,00.html">Automatic email for backup job log on AS/400</source>
    </item>
  </channel>
</rss>
