<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: led]]></title>
    <link>http://securityratty.com/tag/led</link>
    <description></description>
    <pubDate>Thu, 17 Jul 2008 06:10:12 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[SDL and the XSS Filter]]></title>
      <link>http://securityratty.com/article/ce479edf032699e552a4cb52750d1f63</link>
      <guid>http://securityratty.com/article/ce479edf032699e552a4cb52750d1f63</guid>
      <description><![CDATA[Steve Lipner here. When the Internet Explorer team posted the announcement about the XSS Filter feature in IE8 I asked some other members of the SDL blog team why arent we talking about the new XSS...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Steve Lipner here.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>When the Internet Explorer team posted the announcement about the </FONT><A href="http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx"><FONT face=Calibri color=#0000ff size=3>XSS Filter feature in IE8</FONT></A><FONT size=3><FONT face=Calibri> <SPAN style="mso-spacerun: yes">&nbsp;</SPAN>I asked some other members of the SDL blog team “why aren’t we talking about the new XSS Filter feature on the SDL blog?” &nbsp;Bryan and Jeremy said something like “that’s a mitigation that only applies to specific clients and a subset of attacks”.&nbsp; So we didn’t cross-reference IE’s XSS Filter post on the SDL blog at the time.&nbsp; Instead, I agreed to write a subsequent post about the relationship of XSS Filter to the SDL and to the ways that our SDL and security science teams think about improving product security.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>For those of you who aren’t familiar with XSS Filter, a brief summary is that it is a client-side defense against reflected cross-site scripting (XSS) attacks.&nbsp; It works by recognizing that reflected XSS attacks inject script into the string that the browser sends to the targeted web server.&nbsp; If the server doesn’t neuter or strip out the injected script, it gets sent back to the browser and executed in the context of the target web page.&nbsp; Bad things then happen.&nbsp; At a high level, XSS Filter remembers the string that the browser sent to the server, and looks at the server’s response to see if any of the script was actually in that string.&nbsp; If it was, then XSS Filter decides that it got there because it was injected by an XSS attack and blocks the script from executing.&nbsp; The rest of the web page renders as usual.&nbsp; This is a vastly oversimplified sketch of XSS Filter – for details, see the post by David Ross, inventor of XSS Filter on the </FONT><A href="http://blogs.technet.com/swi/archive/2008/08/19/ie-8-xss-filter-architecture-implementation.aspx"><FONT face=Calibri color=#0000ff size=3>Security Vulnerability Research and Defense blog</FONT></A><FONT size=3><FONT face=Calibri>.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>So what does XSS Filter have to do with the SDL?&nbsp; Well, for almost nine years, since XSS was first discovered at Microsoft, we’ve been trying to figure out effective ways to reduce vulnerability to XSS attacks.&nbsp; Our focus has been on improving the ways that web page developers code their pages, and we’ve developed a lot of tools and techniques for making web content safer from XSS attacks and for detecting XSS vulnerabilities in live pages.&nbsp; The SDL requires the use of many of these tools and techniques, and we’re sure we’ve prevented a lot of XSS vulnerabilities from being introduced into Microsoft web pages as a result.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT size=3><FONT face=Calibri>But while we identify (and the SDL requires) measures that allow developers to avoid classes of vulnerabilities, we also look to identify more sweeping solutions that can either 1) eliminate classes of vulnerabilities, 2) reduce their severity, or 3) reduce the likelihood of attacks being successful.&nbsp; The process usually starts from deep understanding of a class of vulnerabilities and attacks, and then we broaden defenses from there.&nbsp; In the case of XSS Filter, David’s years of work researching XSS led him to come up with an approach that blocks many of the most common vulnerabilities to reflected attacks found on the web today.&nbsp; The solution is compatible with existing web pages (doesn’t “break the web”) and thus we were able to enable it by default for users of Internet Explorer 8.&nbsp; Because it’s a client-side mitigation, it will help protect users from attacks even though the sites they visit may be vulnerable to XSS.&nbsp; <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Our work on buffer overrun defenses follows a somewhat similar pattern – we started by prescribing coding techniques, banning the use of some APIs, and building tools that detect coding constructs that look like buffer overruns.&nbsp; As we gained a deeper understanding of how buffer overruns can be exploited, we enhanced the </FONT><A href="http://msdn.microsoft.com/en-us/library/8dbf701c(VS.80).aspx"><FONT face=Calibri size=3>/GS compiler flag</FONT></A><FONT face=Calibri size=3> and added </FONT><A href="http://blogs.msdn.com/michael_howard/archive/2006/05/26/address-space-layout-randomization-in-windows-vista.aspx"><FONT face=Calibri color=#0000ff size=3>ASLR</FONT></A><FONT size=3><FONT face=Calibri> in a quest to cause classes of exploits to fail even if a buffer overrun remains.&nbsp; We’re not yet close to eliminating the SDL requirements for use of tools and coding techniques, but the SDL also requires the use of the mitigations to reduce the severity of vulnerabilities that slip past.&nbsp; Will we ever get to the point where the mitigating technologies are so strong that we can relax the coding requirements?&nbsp; Maybe not, but we will continue to introduce technologies that reduce the chances of a successful attack.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>Similarly, in the case of XSS, even after IE8 ships, the SDL will continue to require the use of safe web site coding practices and tools such as the </FONT><A href="http://msdn.microsoft.com/en-us/library/aa973813.aspx"><FONT face=Calibri color=#0000ff size=3>Anti-XSS library</FONT></A><FONT size=3><FONT face=Calibri> both to protect users of browsers other than IE8 and to provide protection in recognition of the fact that XSS Filter is a mitigation or defense in depth rather than a complete solution.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>But we’ll also be keeping our eyes open (and doing active research) in the quest for an even more effective defense – whether client or server side – that eliminates XSS for good.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face=Calibri size=3>This post is a little far afield from the normal content of the SDL blog, but I thought it was important to provide a picture of the role of security science and security research in defining SDL requirements and in making major improvements in software security.&nbsp; You can read more about our work in security science in the </FONT><A href="http://blogs.technet.com/swi/default.aspx"><FONT face=Calibri color=#0000ff size=3>Security Vulnerability Research and Defense blog</FONT></A><FONT size=3><FONT face=Calibri>.</FONT></FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8900490" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 11:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss filter">xss filter</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/xss led">xss led</category>
      <category domain="http://securityratty.com/tag/anti-xss library">anti-xss library</category>
      <category domain="http://securityratty.com/tag/xss attack">xss attack</category>
      <category domain="http://securityratty.com/tag/xss attacks">xss attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/xss filter remembers">xss filter remembers</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/08/27/sdl-and-the-xss-filter.aspx">SDL and the XSS Filter</source>
    </item>
    <item>
      <title><![CDATA[Software Security Market]]></title>
      <link>http://securityratty.com/article/0adbf216425dc6d24bde35c8640002aa</link>
      <guid>http://securityratty.com/article/0adbf216425dc6d24bde35c8640002aa</guid>
      <description><![CDATA[Information Security budgets are pretty crufty , they are an accumulation of decisions but the analysis that led to these decisions is rarely revisited, it just snowballs. So the normal Information...]]></description>
      <content:encoded><![CDATA[<p>Information Security budgets are pretty <a href="http://en.wikipedia.org/wiki/Cruft">crufty</a>, they are an accumulation of decisions but the analysis that led to these decisions is rarely revisited, it just snowballs. So the normal Information Security budget is just a legacy artifact of when the network was the greatest vulnerability. <a href="http://www.cigital.com/~gem/">Gary McGraw&#160;</a><a href="http://www.informit.com/articles/article.aspx?p=1237978">took a pass</a> at reviewing the numbers in software security, breaking down software security sectors like tools and services (note to Gary - I think <a href="http://www.aspectsecurity.com/">Aspect</a> does more than just training!). This is great work by Gary to get these numbers to see the real changes occuring in software security. Here were his findings on software security tools:</p><div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px; ">One of the most important developments in the software security market can be seen in the tools space which, combined, almost doubled to $150-180 million. Top of list are two major acquisitions that closed in 2007: Watchfire&#39;s purchase by IBM (somewhere in the range of $120-150 million on 2006 revenue of $26 million) and SPI Dynamics&#39;s purchase by HP (for around $100 million on 2006 revenue of $21.2 million).</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px;">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px; ">The black box space was flat in 2007, with IBM/Watchfire checking in at $24.1 million and HP/SPI Dynamics earning $22.3 million. Smaller companies in the space, including Cenzic, Codenomicon, WhiteHat and the like had combined revenues around $12.5 million (a growth of 25%, though Cenzic grew 16% and WhiteHat 52%). Most of the growth &quot;hiccup&quot; in the black box market can be attributed to the serious challenges posed by any acquisition. So far 2008 looks to be back on track from a growth perspective in the black box testing space. The global reach that IBM and HP offer are already making a big difference.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px;"><br /></span><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px; ">On a more positive note, static analysis tools for code review grew at a healthy clip in 2007 into a $91.9 million dollar market. Fortify was up 83% to $29.2 million. Klocwork grew over 60% to $26 million. Coverity grew over 50% to $27.2 million. Ounce Labs tripled their revenue to $9.5 million.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><br /></blockquote><div><br /><div>These are very nice growth numbers, what company doesn&#39;t want 83% growth? However, the total picture is not so good. Gary&#39;s estimate shows the software security space coming in at $150 Million total, yet we see a company like Checkpoint that won the network security war in 1995 with earnings of around $900 Million! One single network security vendor is 6 times bigger than the entire software security space?!? Complete UTTER Madness!</div><br /><div>This is the stupefying, stultifying effects of budget cruft, where the decisions made in <a href="http://1raindrop.typepad.com/1_raindrop/2007/10/network-securit.html">The People&#39;s Republic of Information Security</a> have no bearing on reality of threats or even a business case.</div><br /><div>Let&#39;s look at networks. Obviously Cisco is the biggest, they earned $39.5 Billion last year. Pretty stellar. So spending $900 Million (Checkpoint) to defined $39.5 Billion seems like a pretty good deal.</div><br /><div>Except, let&#39;s compare software security spending - last year Microsoft earned $60 Billion, SAP $16 billion, and Oracle $22 Billion. So that is about $98 Billion and you are going to &quot;defend&quot; that with allocating $150 Million worth of software security tools?</div><br />

</div><table border="1">
<tbody><tr>
<td>
</td>
<td><span style="background-color: #d0d0d0; font-family: &#39;Trebuchet MS&#39;; ">
Network
</span></td>
<td><span style="background-color: #d0d0d0; font-family: &#39;Trebuchet MS&#39;; ">
Software
</span></td>
</tr>
<tr>
<td>
Asset Value
</td>
<td>
$39.5 billion
</td>
<td>
$98 billion
</td>
</tr>
<tr>
<td>
Security Investment
</td>
<td>
$900 Million
</td>
<td>
$150 Million
</td>
</tr>
<tr>
<td>
Security Investment <br />&#160;as a percentage of asset value
</td>
<td>
2.28%
</td>
<td>
0.15%
</td></tr></tbody></table>

<br /><div>This table greatly disturbs me. From a prioritization standpoint The People&#39;s Republic of Information Security is misaligned by orders of magnitude. Next time you read about a data breach, or see an auditor&#39;s report with thousands of findings you won&#39;t have to wonder how it happened. It happened because Information Security doesn&#39;t have its eye on the ball.</div><br /><div>Consider that software security tools could grow 50% a year for five years and still be half of where Checkpoint is today!</div><br />I see the outcomes of backwards looking, crufty decisions by Information Security every day - one or two software security sherpas heading out to work with thousands of developers, meanwhile the network security people sit around and read the newspaper and go home every day at 5.</div><br /><div>The optimistic way of looking at all this data is that there is major room for growth for software security, if you take Checkpoint as a target, then the software security space should evolve to around 2% of the software space meaning that it should evolve into a $2 billion space <span style="font-style: italic;">around fifteen times larger</span> than it is today. Unprotected assets will either be protected or will cease to be assets, VCs get your check books ready.</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 09:18:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software security market">software security market</category>
      <category domain="http://securityratty.com/tag/software security sectors">software security sectors</category>
      <category domain="http://securityratty.com/tag/space">space</category>
      <category domain="http://securityratty.com/tag/tools space">tools space</category>
      <category domain="http://securityratty.com/tag/compare software security">compare software security</category>
      <category domain="http://securityratty.com/tag/software security sherpas">software security sherpas</category>
      <category domain="http://securityratty.com/tag/software security space">software security space</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/software-security-market.html">Software Security Market</source>
    </item>
    <item>
      <title><![CDATA[A Security Assessment of the Internet Protocol]]></title>
      <link>http://securityratty.com/article/ebac4e1107d0d958cc5b67c257c5ea71</link>
      <guid>http://securityratty.com/article/ebac4e1107d0d958cc5b67c257c5ea71</guid>
      <description><![CDATA[Interesting : Preface
The TCP/IP protocols were conceived during a time that was quite different from the hostile environment they operate in now. Yet a direct result of their effectiveness and...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.cpni.gov.uk/Docs/InternetProtocol.pdf">Interesting</a>:</p>

<blockquote><strong>Preface</strong>

<p>The TCP/IP protocols were conceived during a time that was quite different from the hostile environment they operate in now. Yet a direct result of their effectiveness and widespread early adoption is that much of today's global economy remains dependent upon them.</p>

<p>While many textbooks and articles have created the myth that the Internet Protocols (IP) were designed for warfare environments, the top level goal for the DARPA Internet Program was the sharing of large service machines on the ARPANET. As a result, many protocol specifications focus only on the operational aspects of the protocols they specify and overlook their security implications.</p>

<p>Though Internet technology has evolved, the building blocks are basically the same core protocols adopted by the ARPANET more than two decades ago. During the last twenty years many vulnerabilities have been identified in the TCP/IP stacks of a number of systems. Some were flaws in protocol implementations which affect only a reduced number of systems. Others were flaws in the protocols themselves affecting virtually every existing implementation. Even in the last couple of years researchers were still working on security problems in the core  protocols.</p>

<p>The discovery of vulnerabilities in the TCP/IP protocols led to reports being published by a number of CSIRTs (Computer Security Incident Response Teams) and vendors, which helped to raise awareness about the threats as well as the best mitigations known at the time the reports were published.</p>

<p>Much of the effort of the security community on the Internet protocols did not result in official documents (RFCs) being issued by the IETF (Internet Engineering Task Force) leading to a situation in which "known" security problems have not always been addressed by all vendors. In many cases vendors have implemented quick "fixes" to protocol flaws without a careful analysis of their effectiveness and their impact on interoperability.</p>

<p>As a result, any system built in the future according to the official TCP/IP specifications might reincarnate security flaws that have already hit our communication systems in the past.</p>

<p>Producing a secure TCP/IP implementation nowadays is a very difficult task partly because of no single document that can serve as a security roadmap for the protocols.</p>

<p>There is clearly a need for a companion document to the IETF specifications that discusses the security aspects and implications of the protocols, identifies the possible threats, proposes possible counter-measures, and analyses their respective effectiveness.</p>

<p>This document is the result of an assessment of the IETF specifications of the Internet Protocol from a security point of view. Possible threats were identified and, where possible, counter-measures were proposed.  Additionally, many implementation flaws that have led to security vulnerabilities have been referenced in the hope that future implementations will not incur the same problems. This document does not limit itself to performing a security assessment of the relevant IETF specification but also offers an assessment of common implementation strategies.</p>

<p>Whilst not aiming to be the final word on the security of the IP, this document aims to raise awareness about the many security threats based on the IP protocol that have been faced in the past, those that we are currently facing, and those we may still have to deal with in the future. It provides advice for the secure implementation of the IP, and also insights about the security aspects of the IP that may be of help to the Internet operations community.</p>

<p>Feedback from the community is more than encouraged to help this document be as accurate as possible and to keep it updated as new threats are discovered.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=klyypK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=klyypK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xR8bMK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xR8bMK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 03:48:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/assessment">assessment</category>
      <category domain="http://securityratty.com/tag/security assessment">security assessment</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/internet technology">internet technology</category>
      <category domain="http://securityratty.com/tag/internet operations community">internet operations community</category>
      <category domain="http://securityratty.com/tag/protocols">protocols</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/a_security_asse.html">A Security Assessment of the Internet Protocol</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Houston-Fi, ASCII WPA Passphrases, Green Wi-Fi]]></title>
      <link>http://securityratty.com/article/7f30d96346f66d41619e4abd9bae8e7d</link>
      <guid>http://securityratty.com/article/7f30d96346f66d41619e4abd9bae8e7d</guid>
      <description><![CDATA[Houston flips switch on free downtown Wi-Fi: Dwight Silverman of the Houston Chronicle accidentally discovers the soft launch of the network funded by EarthLink's $5m default fee. (The fee was paid...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://blogs.chron.com/techblog/archives/2008/08/it_lives_city_of_houston_turns_on_free_downto.html"><strong>Houston flips switch on free downtown Wi-Fi:</strong></a> Dwight Silverman of the Houston Chronicle accidentally discovers the soft launch of the network funded by EarthLink's $5m default fee. (The fee was paid when they missed a milestone, and the firm later walked away.) The downtown area now has a limited pilot project that's free; the real effort in Houston is supposed to be at 10 housing projects and in parks where service would be used to bridge the digital divide and improve the quality of life. How, exactly, is part of what's being tested.</p>

<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/08/18/MNH312BTS1.DTL&hw=wi+fi&sn=004&sc=589"><strong>That's ASCII, not hex:</strong></a> An article on wardriving raises security hackles by repeating some slightly overheated statements about Wi-Fi security. The article opens with a 63-character ASCII WPA passphrase, which is later described as "hex." (ASCII passphrases in WPA can be up to 63 "printable" characters - ASCII 32 to 127 - while a hex version of a 256-bit TKIP or AES password is 64 hexadecimal digits long.) The article tries to conflate Wi-Fi attacks that led to the largest set of breaches in retail credit-card systems and wardriving, a hobbyist activity that's never been looked on very favorably by law enforcement. The sense of ennui of wardriving pioneers is pretty clear; when Wi-Fi is everywhere and generally secured, it's far less interesting. The wardriver in the article convinced the reporter that a maximum-length WPA passphrase stored on a USB drive for automatic use was the best way to go. But, really, 20 characters containing letters and punctuation and no words found in a dictionary along with changing your network's SSID (network name) provides all the security you'll ever need for a home or small business. (If you need more, deploy WPA/WPA2 Personal.)</p>

<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/08/16/BUA712BH1O.DTL&hw=wi+fi&sn=001&sc=1000"><strong>Green Wi-Fi's Senegal efforts hit snags:</strong></a> The folks at Green Wi-Fi are well motivated, and they're running up against all forms of security theater and bureaucracy both here and in Senegal, where they have an active project. The San Francisco Chronicle notes the group's effort to build solar-powered, self-sustaining Internet access via mesh networked nodes. Getting devices out of the country, clearing customs in Senegal, and hooking up their solar system all hit problems they're working through. As with the One Laptop Per Child program, I see a "build it and they will come" mentality in <a href="http://www.green-wifi.org/"><strong>Green Wi-Fi's mission statement</strong></a>: the notion that providing computing power and Internet access will result in good things, rather than an effort to figure out what good things need to be achieved, and whether computers and the Internet will assist. </p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 06:26:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi attacks">wi-fi attacks</category>
      <category domain="http://securityratty.com/tag/houston">houston</category>
      <category domain="http://securityratty.com/tag/wi-fi security">wi-fi security</category>
      <category domain="http://securityratty.com/tag/free downtown wi-fi">free downtown wi-fi</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/ascii">ascii</category>
      <category domain="http://securityratty.com/tag/security theater">security theater</category>
      <source url="http://wifinetnews.com/archives/008423.html">Wee-Fi: Houston-Fi, ASCII WPA Passphrases, Green Wi-Fi</source>
    </item>
    <item>
      <title><![CDATA[Amber Alerts As Security Theater]]></title>
      <link>http://securityratty.com/article/0d6125e22aa5c6863e853fa8ae428cf9</link>
      <guid>http://securityratty.com/article/0d6125e22aa5c6863e853fa8ae428cf9</guid>
      <description><![CDATA[Interesting analysis : Since its birth 12 years ago after a fatal kidnapping in Texas, Amber Alert has quickly become one of the best-known tools in the national law enforcement arsenal. The warnings...]]></description>
      <content:encoded><![CDATA[<p>Interesting <a href="http://www.boston.com/bostonglobe/ideas/articles/2008/07/20/abducted/">analysis</a>:</p>

<blockquote>Since its birth 12 years ago after a fatal kidnapping in Texas, Amber Alert has quickly become one of the best-known tools in the national law enforcement arsenal. The warnings are familiar to anyone who watches cable TV news, especially during the summer, when the drumbeat of abduction stories seems to increase. Last year, 227 alerts were issued nationwide, each galvanizing interest in the local community and flooding police with tips. While the particulars of the state systems differ, the goal is the same: to disperse news of a kidnapping as widely and quickly as possible, in the hope that someone will spot the kidnapper before a child is harmed.

<p>The program's champions say that its successes have been dramatic. According to the National Center for Missing and Exploited Children, more than 400 children have been saved by Amber Alerts. Of the 17 children Massachusetts has issued alerts on since it created its system in 2003, all have been safely returned.</p>

<p>These are encouraging statistics -- but also deeply misleading, according to some of the only outside scholars to examine the system in depth. In the first independent study of whether Amber Alerts work, a team led by University of Nevada criminologist Timothy Griffin looked at hundreds of abduction cases between 2003 and 2006 and found that Amber Alerts -- for all their urgency and drama -- actually accomplish little. In most cases where they were issued, Griffin found, Amber Alerts played no role in the eventual return of abducted children. Their successes were generally in child custody fights that didn't pose a risk to the child. And in those rare instances where kidnappers did intend to rape or kill the child, Amber Alerts usually failed to save lives.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=rZkbpK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=rZkbpK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=e2lugK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=e2lugK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 03:59:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alerts">alerts</category>
      <category domain="http://securityratty.com/tag/amber alerts">amber alerts</category>
      <category domain="http://securityratty.com/tag/child custody fights">child custody fights</category>
      <category domain="http://securityratty.com/tag/child">child</category>
      <category domain="http://securityratty.com/tag/abduction">abduction</category>
      <category domain="http://securityratty.com/tag/abduction stories">abduction stories</category>
      <category domain="http://securityratty.com/tag/successes">successes</category>
      <category domain="http://securityratty.com/tag/team led">team led</category>
      <category domain="http://securityratty.com/tag/local community">local community</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/amber_alerts_as.html">Amber Alerts As Security Theater</source>
    </item>
    <item>
      <title><![CDATA[Kenya government increases spending on IT security]]></title>
      <link>http://securityratty.com/article/a93e55e6b8a4f6c7ef99defc854092ce</link>
      <guid>http://securityratty.com/article/a93e55e6b8a4f6c7ef99defc854092ce</guid>
      <description><![CDATA[Increased technology awareness within the Kenyan government has led to increased spending on IT security, said James Kinyua, managing director of Isolutions Associates, the local partner of Kaspersky...]]></description>
      <content:encoded><![CDATA[Increased technology awareness within the Kenyan government has led to increased spending on IT security, said James Kinyua, managing director of Isolutions Associates, the local partner of Kaspersky Lab.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=89423?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=89423?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kenyan government">kenyan government</category>
      <category domain="http://securityratty.com/tag/technology awareness">technology awareness</category>
      <category domain="http://securityratty.com/tag/james kinyua">james kinyua</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/local partner">local partner</category>
      <category domain="http://securityratty.com/tag/kaspersky lab">kaspersky lab</category>
      <category domain="http://securityratty.com/tag/led">led</category>
      <category domain="http://securityratty.com/tag/isolutions">isolutions</category>
      <category domain="http://securityratty.com/tag/director">director</category>
      <source url="http://www.networkworld.com/news/2008/080108-kenya-government-increases-spending-on.html?fsrc=rss-security">Kenya government increases spending on IT security</source>
    </item>
    <item>
      <title><![CDATA[Storage jump helps Symantec boost revenue]]></title>
      <link>http://securityratty.com/article/26394cef45b138681214e7e78a88dcde</link>
      <guid>http://securityratty.com/article/26394cef45b138681214e7e78a88dcde</guid>
      <description><![CDATA[Led by strong sales in its storage and server management group, Symantec on Wednesday reported a 16 percent jump in revenue for its first quarter of fiscal...]]></description>
      <content:encoded><![CDATA[Led by strong sales in its storage and server management group, Symantec on Wednesday reported a 16 percent jump in revenue for its first quarter of fiscal 2009.]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/percent jump">percent jump</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/revenue">revenue</category>
      <category domain="http://securityratty.com/tag/server management">server management</category>
      <category domain="http://securityratty.com/tag/strong sales">strong sales</category>
      <category domain="http://securityratty.com/tag/storage">storage</category>
      <category domain="http://securityratty.com/tag/led">led</category>
      <category domain="http://securityratty.com/tag/quarter">quarter</category>
      <category domain="http://securityratty.com/tag/wednesday">wednesday</category>
      <source url="http://www.networkworld.com/news/2008/073008-storage-jump-helps-symantec-boost.html?fsrc=rss-security">Storage jump helps Symantec boost revenue</source>
    </item>
    <item>
      <title><![CDATA[Another take on reviews]]></title>
      <link>http://securityratty.com/article/bb4067334266eb161a8b27e7207ab070</link>
      <guid>http://securityratty.com/article/bb4067334266eb161a8b27e7207ab070</guid>
      <description><![CDATA[Without putting out misleading press releases , I do want to mention a review that came out today that I was pretty proud of. The folks at Channel Web and CRN put out a review today of StillSecure...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Without <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/when-is-4-out-o.html">putting out misleading press releases</a>, I do want to mention a review that came out today that I was pretty proud of. The folks at Channel Web and CRN put out <a href="http://www.crn.com/security/209101095;jsessionid=4CV2CAHUGZHEMQSNDLRSKHSCJUNN2JVN?pgno=1">a review today</a> of StillSecure Safe Access baked off against two well known competitors, Symantec and Sophos. You can go read the review for yourself for the entire story, but here are the final two paragraphs:</p><blockquote><p><em>After evaluating each of these products, the Test Center found that StillSecure's Safe Access 5.0 slightly outpaced the others, followed by Symantec (NSDQ:</em><a href="http://www.crn.com/tools/quotes/index.jhtml?Page=QUOTE&amp;Ticker=SYMC"><em>SYMC</em></a><em>)'s solution and then Sophos'. </em></p>

<p><em>Safe Access 5.0 is robust and customizable, justifying adding a NAC as an extra layer of security. Symantec offers a nice solution, but finds itself more limited than Safe Access 5.0 without deploying agents. Sophos, too, is good, but we were left wanting more. While all the solutions could be fine in particular deployments, functionality led us to choose Safe Access 5.0 first, Symantec second and Sophos third in this comparative review.</em> </p></blockquote><p>???Nuff said on that one!&nbsp; In other NAC news today, Mike Fratto and the Information Week folks have released their <a href="http://www.nac.informationweek.com/">2008 NAC survey</a> and Mike will be doing a follow up webcast on this on Wed, July 23rd.&nbsp; Check out <a href="http://www.informationweek.com/blog/main/archives/2008/07/2008_nac_survey.html">the site</a> for all the details. This report is chock full of great stuff about NAC including vendor profiles.&nbsp; There is a ton of great information there for anyone interested in NAC.</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/c4a3ce90-0e4e-45b2-a851-cc6e12a78be9/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=c4a3ce90-0e4e-45b2-a851-cc6e12a78be9" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 22:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/safe access">safe access</category>
      <category domain="http://securityratty.com/tag/choose safe access">choose safe access</category>
      <category domain="http://securityratty.com/tag/nac survey">nac survey</category>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/nac news">nac news</category>
      <category domain="http://securityratty.com/tag/review">review</category>
      <category domain="http://securityratty.com/tag/information week folks">information week folks</category>
      <category domain="http://securityratty.com/tag/symantec offers">symantec offers</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/another-take-on.html">Another take on reviews</source>
    </item>
    <item>
      <title><![CDATA[Another take on reviews]]></title>
      <link>http://securityratty.com/article/a496a5fcd446dedcd0ee7e3ddda70ced</link>
      <guid>http://securityratty.com/article/a496a5fcd446dedcd0ee7e3ddda70ced</guid>
      <description><![CDATA[Without putting out misleading press releases , I do want to mention a review that came out today that I was pretty proud of. The folks at Channel Web and CRN put out a review today of StillSecure...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Without <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/when-is-4-out-o.html">putting out misleading press releases</a>, I do want to mention a review that came out today that I was pretty proud of. The folks at Channel Web and CRN put out <a href="http://www.crn.com/security/209101095;jsessionid=4CV2CAHUGZHEMQSNDLRSKHSCJUNN2JVN?pgno=1">a review today</a> of StillSecure Safe Access baked off against two well known competitors, Symantec and Sophos. You can go read the review for yourself for the entire story, but here are the final two paragraphs:</p><blockquote><p><em>After evaluating each of these products, the Test Center found that StillSecure's Safe Access 5.0 slightly outpaced the others, followed by Symantec (NSDQ:</em><a href="http://www.crn.com/tools/quotes/index.jhtml?Page=QUOTE&amp;Ticker=SYMC"><em>SYMC</em></a><em>)'s solution and then Sophos'. </em></p>

<p><em>Safe Access 5.0 is robust and customizable, justifying adding a NAC as an extra layer of security. Symantec offers a nice solution, but finds itself more limited than Safe Access 5.0 without deploying agents. Sophos, too, is good, but we were left wanting more. While all the solutions could be fine in particular deployments, functionality led us to choose Safe Access 5.0 first, Symantec second and Sophos third in this comparative review.</em> </p></blockquote><p>‘Nuff said on that one!&nbsp; In other NAC news today, Mike Fratto and the Information Week folks have released their <a href="http://www.nac.informationweek.com/">2008 NAC survey</a> and Mike will be doing a follow up webcast on this on Wed, July 23rd.&nbsp; Check out <a href="http://www.informationweek.com/blog/main/archives/2008/07/2008_nac_survey.html">the site</a> for all the details. This report is chock full of great stuff about NAC including vendor profiles.&nbsp; There is a ton of great information there for anyone interested in NAC.</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/c4a3ce90-0e4e-45b2-a851-cc6e12a78be9/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=c4a3ce90-0e4e-45b2-a851-cc6e12a78be9" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=G32IJF"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=G32IJF" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=tENksJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=tENksJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=HnMm1J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=HnMm1J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=QXZTJJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=QXZTJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=EnWivJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=EnWivJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=8Cb7wj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=8Cb7wj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=hz7Ipj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=hz7Ipj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/342283768" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 21:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/safe access">safe access</category>
      <category domain="http://securityratty.com/tag/choose safe access">choose safe access</category>
      <category domain="http://securityratty.com/tag/nac survey">nac survey</category>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/nac news">nac news</category>
      <category domain="http://securityratty.com/tag/review">review</category>
      <category domain="http://securityratty.com/tag/information week folks">information week folks</category>
      <category domain="http://securityratty.com/tag/symantec offers">symantec offers</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/342283768/another-take-on.html">Another take on reviews</source>
    </item>
    <item>
      <title><![CDATA[Gonzo: Two Thumbs In and Up]]></title>
      <link>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</link>
      <guid>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</guid>
      <description><![CDATA[Just saw the Hunter S. Thompson movie - Gonzo , and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view...]]></description>
      <content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Hunter_S._Thompson"></a><a style="float: left;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-pi"><img  class="at-xid-6a00d83451c75869e200e553c045c48834 " alt="180px-Gonzo_citation" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-320wi" style="margin: 0px 5px 5px 0px;"></a> Just saw the Hunter S. Thompson movie - <a href="http://www.rottentomatoes.com/m/gonzo_the_life_and_work_of_dr_hunter_s_thompson/">Gonzo</a>, and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view of the high highs and the low lows. Weaves in writing, politics, and fame seamlessly.

I have never really had as much fun as early on in my career in the early-mid 90s I was a web programmer in Aspen, hacking CGI/PERL. Among the most fun things was building and running HST's site. My boss, Ed, was his neighbor. Ed was also seriously allergic to bees. One day he was alone in his house and got stung. He was dying. Luckily Hunter was due over to his house to watch a basketball game, walked in and called 911. My boss woke up in the ambulance with Hunter pounding on him chest and screaming at him. Ed said - "Waking up to that face screaming at me, I didn't know if I was alive or dead."

Seeing the movie it was also great to see a lot of the Woody Creek folks again like George Stranahan, who lovingly said about Hunter - "my friend and neighbor who never paid his rent, broke up my marriage and taught my children to smoke dope. "

Of course, there was no way he could match his early productivity and this is true of almost all artists. Most of the last two decades were wasted from a writing standpoint. However his <a href="http://proxy.espn.go.com/espn/page2/story?id=1250751">piece</a> written on 9/11 is as good as its gets:

</p><blockquote><p>
	The towers are gone now, reduced to bloody rubble, along with all hopes for Peace in Our Time, in the United States or any other country. Make no mistake about it: We are At War now -- with somebody -- and we will stay At War with that mysterious Enemy for the rest of our lives. 	
	</p></blockquote><blockquote><p>It will be a Religious War, a sort of Christian Jihad, fueled by religious hatred and led by merciless fanatics on both sides. It will be guerilla warfare on a global scale, with no front lines and no identifiable enemy. Osama bin Laden may be a primitive "figurehead" -- or even dead, for all we know -- but whoever put those All-American jet planes loaded with All-American fuel into the Twin Towers and the Pentagon did it with chilling precision and accuracy. The second one was a dead-on bullseye. Straight into the middle of the skyscraper. 	
	</p></blockquote><blockquote><p>Nothing -- even George Bush's $350 billion "Star Wars" missile defense system -- could have prevented Tuesday's attack, and it cost next to nothing to pull off. Fewer than 20 unarmed Suicide soldiers from some apparently primitive country somewhere on the other side of the world took out the World Trade Center and half the Pentagon with three quick and costless strikes on one day. The efficiency of it was terrifying. 	
	</p></blockquote><blockquote><p>We are going to punish somebody for this attack, but just who or what will be blown to smithereens for it is hard to say. Maybe Afghanistan, maybe Pakistan or Iraq, or possibly all three at once. Who knows? Not even the Generals in what remains of the Pentagon or the New York papers calling for WAR seem to know who did it or where to look for them. 	
	</p></blockquote><blockquote><p>This is going to be a very expensive war, and Victory is not guaranteed -- for anyone, and certainly not for anyone as baffled as George W. Bush. All he knows is that his father started the war a long time ago, and that he, the goofy child-President, has been chosen by Fate and the global Oil industry to finish it Now. He will declare a National Security Emergency and clamp down Hard on Everybody, no matter where they live or why. If the guilty won't hold up their hands and confess, he and the Generals will ferret them out by force. 	
	</p></blockquote><blockquote><p>Good luck. He is in for a profoundly difficult job -- armed as he is with no credible Military Intelligence, no witnesses and only the ghost of Bin Laden to blame for the tragedy.
	
</p></blockquote><p>


One unintended lesson I take away from Hunter's life is how important patience is. Obama is a politician and may yet disappoint us all, but I gotta believe Hunter would be seriously impressed. If he had waited another couple of years, he may have seen a lot of the stuff he fought for in 1968 and 72 come to fruition. Sometimes you are just 36-40 years ahead of your time and you have to be ok with that and figure out how to deal if possible. (Note - it sure sometimes feels this way in software security).

Speaking of security:

</p><blockquote>
	<p><a href="http://www.ram.org/contrib/security.html">Security</a> 	
	</p></blockquote><blockquote><p>by Hunter S. Thompson (1955). 	
	</p></blockquote><blockquote><p>Security ... what does this word mean in relation to life as we know it today? For the most part, it means safety and freedom from worry. It is said to be the end that all men strive for; but is security a utopian goal or is it another word for rut? 	
	</p></blockquote><blockquote><p>Let us visualize the secure man; and by this term, I mean a man who has settled for financial and personal security for his goal in life. In general, he is a man who has pushed ambition and initiative aside and settled down, so to speak, in a boring, but safe and comfortable rut for the rest of his life. His future is but an extension of his present, and he accepts it as such with a complacent shrug of his shoulders. His ideas and ideals are those of society in general and he is accepted as a respectable, but average and prosaic man. But is he a man? has he any self-respect or pride in himself? How could he, when he has risked nothing and gained nothing? What does he think when he sees his youthful dreams of adventure, accomplishment, travel and romance buried under the cloak of conformity? How does he feel when he realizes that he has barely tasted the meal of life; when he sees the prison he has made for himself in pursuit of the almighty dollar? If he thinks this is all well and good, fine, but think of the tragedy of a man who has sacrificed his freedom on the altar of security, and wishes he could turn back the hands of time. A man is to be pitied who lacked the courage to accept the challenge of freedom and depart from the cushion of security and see life as it is instead of living it second-hand. Life has by-passed this man and he has watched from a secure place, afraid to seek anything better What has he done except to sit and wait for the tomorrow which never comes? 	
	</p></blockquote><blockquote><p>Turn back the pages of history and see the men who have shaped the destiny of the world. Security was never theirs, but they lived rather than existed. Where would the world be if all men had sought security and not taken risks or gambled with their lives on the chance that, if they won, life would be different and richer? It is from the bystanders (who are in the vast majority) that we receive the propaganda that life is not worth living, that life is drudgery, that the ambitions of youth must he laid aside for a life which is but a painful wait for death. These are the ones who squeeze what excitement they can from life out of the imaginations and experiences of others through books and movies. These are the insignificant and forgotten men who preach conformity because it is all they know. These are the men who dream at night of what could have been, but who wake at dawn to take their places at the now-familiar rut and to merely exist through another day. For them, the romance of life is long dead and they are forced to go through the years on a treadmill, cursing their existence, yet afraid to die because of the unknown which faces them after death. They lacked the only true courage: the kind which enables men to face the unknown regardless of the consequences. 	
	</p></blockquote><blockquote><p>As an afterthought, it seems hardly proper to write of life without once mentioning happiness; so we shall let the reader answer this question for himself: who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed?
</p></blockquote><p>

A ship is safest at port, but thats not why we build ships. 
</p>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 06:10:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/sought security">sought security</category>
      <category domain="http://securityratty.com/tag/personal security">personal security</category>
      <category domain="http://securityratty.com/tag/national security emergency">national security emergency</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/expensive war">expensive war</category>
      <category domain="http://securityratty.com/tag/war">war</category>
      <category domain="http://securityratty.com/tag/hunter">hunter</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/gonzo-two-thumbs-in-and-up.html">Gonzo: Two Thumbs In and Up</source>
    </item>
  </channel>
</rss>
