<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: money]]></title>
    <link>http://securityratty.com/tag/money</link>
    <description></description>
    <pubDate>Wed, 20 Aug 2008 01:49:55 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Stigma Enigma, Revisited]]></title>
      <link>http://securityratty.com/article/c238be0f778cce325c4423b05b36b9e3</link>
      <guid>http://securityratty.com/article/c238be0f778cce325c4423b05b36b9e3</guid>
      <description><![CDATA[Recently my pal Bill Pytlovany (of WinPatrol fame) wrote an article on his blog asking &quot;What's Wrong With Toolbars

I wrote something along similar lines way back in 2005 , and it's vaguely depressing...]]></description>
      <content:encoded><![CDATA[
        Recently my pal Bill Pytlovany (of WinPatrol fame) wrote an <a href="http://billpstudios.blogspot.com/2008/08/what-wrong-with-toolbars.html">article</a> on his blog asking "What's Wrong With Toolbars"?<br /><br />I wrote something along similar lines <a href="http://www.revenews.com/chrisboyd/the-stigma-enigma/">way back in 2005</a>, and it's vaguely depressing to see how little has apparently changed. I'm not going to quote myself, but rather compare and contrast Bills experiences (and those of his commentators) with the person who posted a comment to my entry, which I quote below in full:<br /><br /><div class="comment-content">
                                                <p><i>"Unfortunately,
the few 'honest' toolbars have indeed taken the wrath of users as a
result of the spyware, parasite, adware and other creepy applications
of an otherwise good technology.</i></p>
<p><i>What's interesting is that, as far as my own toolbar system goes,
I've had offers from clients all over the world to develop different
kinds of toolbars -- and without fail -- it is the US-based companies
that seem most willing to cross the line and request applications that
I simply refuse to develop.</i></p>
<p><i>We're talking about features like:</i></p>
<p><i>- Forced Install<br />
- Hidden Install<br />
- Report all URLs back<br />
- Report all searches back<br />
- Forcibly and hidden set home page<br />
- Forcibly and hidden set default search engine<br />
- Forcibly generate un-blockable pop-ups<br />
- Install and run hidden executables<br />
- Bypass all security and anti-virus tools<br />
- The list goes on...</i></p>
<p><i>What's sad is that I'm able to generate the most powerful and
incredibly useful toolbars imaginable. Ones that can save countless
hours of time and effort. Ones that can be customized on a per-user
basis to make the Internet and use of ones's own computer a pleasure.</i></p>
<p><i>However, there will always be people around who's sole motivation is the almighty dollar -- and who will do ANYTHING to get it.</i></p>
<p><i>These people don't care about you, your wants, your needs, your
security or safety -- as long as they can line their pockets with your
money, or by taking advantage of actions you perform (even one lousy
click!).</i></p>
<p><i>They'll infect your machine, using whatever means necessary, and they won't stop -- EVER."</i><br /><br />The "industry" has certainly cleaned up since then, but the insistence on wanting to cram a toolbar on every PC, ever, remains. I must admit to being kind of disturbed that none of these companies seemingly want to take "No" for an answer - instead of leaving alone, they keep coming back every month or so. Of course, given the potential for mass moneymaking that's on offer I can't say I'm entirely surprised...<br /></p>
                    </div><br /> 
        
    ]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 10:58:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/toolbars imaginable">toolbars imaginable</category>
      <category domain="http://securityratty.com/tag/toolbars">toolbars</category>
      <category domain="http://securityratty.com/tag/forcibly">forcibly</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/toolbar">toolbar</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <category domain="http://securityratty.com/tag/contrast bills experiences">contrast bills experiences</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/toolbar system">toolbar system</category>
      <source url="http://blog.spywareguide.com/2008/08/the-stigma-enigma-revisited.html">The Stigma Enigma, Revisited</source>
    </item>
    <item>
      <title><![CDATA[HP Hires 140,000 to Get Rid of Your Job]]></title>
      <link>http://securityratty.com/article/1b40a911042fda84f13e9dbc287cf501</link>
      <guid>http://securityratty.com/article/1b40a911042fda84f13e9dbc287cf501</guid>
      <description><![CDATA[HP completed its $13.25 billion acquisition of EDS today
Can HP-EDS put its money where its mouth is? EDS profit margin, pre-acquisition, was under 6%. The former EDS CEO, now heading the combined...]]></description>
      <content:encoded><![CDATA[<p>HP completed its $13.25 billion acquisition of EDS today. </p>
<p>Can HP-EDS put its money where its mouth is? EDS profit margin, pre-acquisition, was under 6%. The former EDS CEO, now heading the combined outsourcing unit, expects to leverage HP automation tools to cut costs and improve that margin.</p>
<p>But Rod Bourgeois, an analyst at Sanford Bernstein says, &#8220;It&#8217;s not like HP has automation tools that weren&#8217;t at <a href="http://online.wsj.com/article/SB121971997812971951.html?mod=hps_us_whats_news">EDS&#8217;s disposal before</a>.&#8221;</p>
<p>But this brings up a good point. EDS and 140,000 new bodies notwithstanding, HP seems to be positioning itself to do a big <a href="http://blogs.wsj.com/biztech/2008/08/26/the-key-to-h-p-eds-automation/?mod=djemTECH">automation push in the marketplace</a>. </p>
<p><a href="http://www.infoworld.com/article/08/05/13/What-does-the-HP-EDS-deal-really-mean_1.html?source=fssr">Of course this makes sense</a> &#8211; we&#8217;ve talked before about what a critical role automation is going to have in managing the rapidly evolving &#8220;dynamic&#8221; data center. Technologies like virtualization and cloud computing needs are pushing out the limits of real-time resources management in the data center; management tools must perform faster, integrate with more solutions across the spectrum of IT infrastructure and be smart enough to do much of this on their own.</p>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 09:47:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eds">eds</category>
      <category domain="http://securityratty.com/tag/hp-eds">hp-eds</category>
      <category domain="http://securityratty.com/tag/eds ceo">eds ceo</category>
      <category domain="http://securityratty.com/tag/eds profit margin">eds profit margin</category>
      <category domain="http://securityratty.com/tag/margin">margin</category>
      <category domain="http://securityratty.com/tag/dynamic data center">dynamic data center</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/automation tools">automation tools</category>
      <category domain="http://securityratty.com/tag/real-time resources management">real-time resources management</category>
      <source url="http://blog.sciencelogic.com/hp-hires-140000-to-get-rid-of-your-job/08/2008">HP Hires 140,000 to Get Rid of Your Job</source>
    </item>
    <item>
      <title><![CDATA[Thoughts on Token Security]]></title>
      <link>http://securityratty.com/article/e520684c06df65bce8e1084919798c74</link>
      <guid>http://securityratty.com/article/e520684c06df65bce8e1084919798c74</guid>
      <description><![CDATA[RSnake has a piece up on Token Security which raises some good points, but also misses some perspective. Firstly any article that makes a serious attempt at mitigating FUD is most welcome, especially...]]></description>
      <content:encoded><![CDATA[<p>RSnake has a piece up on <a href="http://www.darkreading.com/blog.asp?blog_sectionid=403">Token Security</a> which raises some good points, but also misses some perspective. Firstly any article that makes a serious attempt at mitigating FUD is most welcome, especially in a space that is as overloaded as identity. That <span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">said, I think RSnake is taking too narrow of a view, specifically B2C, on federation and tokens</span><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">. It is true that works on the web eventually filters into the enterprise, but it is also true that sometimes that things that start out as enterprise technologies later become cost effective on the web. So I would not assume that the current status quo on the web will hold. I don&#39;t think it will, the identity problems are too big and there is too much money at stake.</span></p><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I encourage you to read his article, here are some of my thoughts<br /></span><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;consumers hate tokens.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Except that people use atm cards every day. Consumers will absolutely be inconvenienced, if there is some value created. The problem today is not the token, its the lack of a value proposition to the person you are inconveniencing.&#160;</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Everyone wants to be the single federation platform for everyone else.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">This will never work. and that&#39;s a good thing. i think most companies already realize this though. I think the walled garden model has gone the way of the dodo.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Federation will never work. It won’t work because the single most important consumer Web applications in the world are scared of it. Banks hate the concept because it becomes a weakest link in the chain problem.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Federation works quite well. have a look at google for one example. The reason banks hate federation is that their infosec people have a </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">mainframe mindset</span></a><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">, they are focused only on resource protection. the problem is they dont run mainframes on closed networks, they went and connected it to the web and so now they need to think about subject and claim security not just resource security. its not hatred its a lack of understanding stemming from a legacy mindset.</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Linking up identity providers and relying parties into a federation has been a solved problem for quite some time.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Tokens don’t actually solve most security problems, like man-in-the-middle, phishing, and keystroke-logging malware.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Rule 1. there are no silver bullets in security</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Rule 2. dont forget rule 1</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">but...</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...there is a rule 3</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">rule 3. just because a security mechanism doesnt solve all of our problems doesnt mean its worthless.</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I see this with security consultants all the time, they playa hate on static analysis or some scanning tool where they can find hundreds of things the tool doesn&#39;t. Fair point except 99.9999% of IT can&#39;t and won&#39;t find them. Engineering is about solving one incremental problem at a time.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Oh yes, and finally, consumers are going to have to carry around 13 of them just to make sure they can log into whatever they need to log into since no one will federate.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">This misses the point of federation. i carry around one atm card its up to banks, Visa, Cirrus and so on to make sure i get my cash. the funny thing about banks not understanding federation is that they have the bet example right in front of their noses, the problem is its in a different department so they never see it.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Global federation is nowhere near a solid concept in the consumer space, despite what the vendors will try to sell you.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">rule 4. do your own due diligence</span></p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Tokens and federation are important building blocks for our digital future. I will leave you with a </span><a href="http://1raindrop.typepad.com/1_raindrop/2007/01/integrated_tran.html"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">story</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> that</span><a href="http://en.wikipedia.org/wiki/Robert_Morris_%28cryptographer%29"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> Robert Morris Sr.</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> told at Defcon several years ago:</span></div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;This is a long term problem. If you work on it and make any progress against it, you&#39;ll find yourself much smarter at the far end, than you were at the near end.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When I was in Norway about 5 years ago, I was there very close to the summer solstice. I was wandering around town at 2 o&#39;clock in the morning and there was plenty of light out. You come to a sign that says New Minsk about 60 km and it points south.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">And I ask the lady &quot;what country is this?&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">She scratched her head for a bit, and said &quot;well I think its Norway&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I said &quot;well who plows the roads?&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;well Norway does, but he have to pay them.&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">There is a triple boundary in this town that I was in between Norway, Finland and Russia.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">But what I did there, was, I had a card about wallet size, I stuck it into a machine, I punched in four digits, and it gave me about 2,000 krone, whatever the hell that is.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Now there are a lot of participants in that transaction. When I put a card into that machine, punch in a pin, and it gurgles for awhile, and finally gives me, a fairly large amount of money. There are a lot of participants in that transaction. The bank that owned the machine that gave me the money, it gave some money away -- that bank wants it back. The pin is necessary to convince my own bank that I&#39;m me. But I don&#39;t want my pin to be broadcast all over the world. My bank in the us, it hasn&#39;t really given out or taken in any money, really. But there is a lot of credits involved here. Somebody needs to charge somebody else for having more money&#160;available. Even though there was actually no cash transfer.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">And the problem that I have in mind is</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- who are all the participants in an ATM transaction?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- what do those participants need to satisfy their problems?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- how is that in fact done?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In a general way, does the atm system actually work in some reasonable sense? To which the answer is by the way: yes. The atm system damn well works. With extremely high reliability and accuracy. It surprises me. Its quite a bit different than voting machines.</span></p></blockquote>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 12:35:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/global federation">global federation</category>
      <category domain="http://securityratty.com/tag/federation">federation</category>
      <category domain="http://securityratty.com/tag/single federation platform">single federation platform</category>
      <category domain="http://securityratty.com/tag/security mechanism">security mechanism</category>
      <category domain="http://securityratty.com/tag/resource security">resource security</category>
      <category domain="http://securityratty.com/tag/security consultants">security consultants</category>
      <category domain="http://securityratty.com/tag/consumer web applications">consumer web applications</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/thoughts-on-token-security.html">Thoughts on Token Security</source>
    </item>
    <item>
      <title><![CDATA[Open Letter to Verizon Wireless]]></title>
      <link>http://securityratty.com/article/33861048df9fa12f13bd8d46690d0a5b</link>
      <guid>http://securityratty.com/article/33861048df9fa12f13bd8d46690d0a5b</guid>
      <description><![CDATA[After receiving no support from agents at the Verizon Wireless store or by agents on the phone, I decided to write them and make it an open letter. Its no secret that Verizon has a great network, but...]]></description>
      <content:encoded><![CDATA[<P><FONT size=2><FONT face=Verdana>After receiving no support from agents at the Verizon Wireless store or by agents on the phone, I decided to write them and make it an open letter.<SPAN>&nbsp; </SPAN>It&#8217;s no secret that Verizon has a great network, but it&#8217;s also no secret that their phone selection stinks.<SPAN>&nbsp; </SPAN>I don&#8217;t want to leave them and am hoping that whatever little bad press I can cause will encourage them to resolve the issue.<SPAN>&nbsp; </SPAN>If not, I&#8217;m tapping out.<SPAN>&nbsp; </SPAN>For 3 years I have hated my phone and loved their network.<SPAN>&nbsp; </SPAN>I&#8217;m ready to feel mediocre about both.<SPAN>&nbsp; </SPAN>Here it goes: </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>I am currently without a phone and would appreciate a speedy reply. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>I have been a Verizon Wireless customer for over 5 years and my monthly bill easily averages over $200 during that time frame.<SPAN>&nbsp; </SPAN>While I love your network, I have been completely unsatisfied by your selection of phones.<SPAN>&nbsp; </SPAN>It is a stretch to say that my last phone worked&#8212;it had a feature called a battery that allowed me to switch from the car charger to my office charger without dying.<SPAN>&nbsp; </SPAN>And I waited&#8212;under duress&#8212;until I was allowed to purchase a new phone with the discount. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>My current phone has a wonderful battery life, but this is the 4th time the charger has snapped off in the phone.<SPAN>&nbsp; </SPAN>The phone is fine, but I keep paying $30 for new chargers.<SPAN>&nbsp; </SPAN>I refuse to purchase another or wait until February when I will be eligible for a new phone.<SPAN>&nbsp; </SPAN>You sold a phone with a design flaw, and I&#8217;m not even asking for a refund or a free phone.<SPAN>&nbsp; </SPAN>Just allow me to take a chance on a new one at the 2 year contract renewal rate.<SPAN>&nbsp; </SPAN></FONT></FONT>
<P><FONT size=2><FONT face=Verdana><SPAN></SPAN></FONT></FONT><FONT size=2><FONT face=Verdana>If not, I will gladly pay the early termination fee and leave Verizon.<SPAN>&nbsp; </SPAN>On general principle, I will spend more money canceling my account with you than I would likely receive as a discount on a new phone.<SPAN>&nbsp; </SPAN>As a customer, I consider it unacceptable that you sell inferior phones and leave me with no recourse. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>The first time I waited haplessly to become eligible for a new phone.<SPAN>&nbsp; </SPAN>I will not suffer a second time.<SPAN>&nbsp; </SPAN>If you don&#8217;t like the fact that you will end up losing money by allowing me to purchase a new phone early, I suggest you take it up your vendors who supply you with awful products.<SPAN>&nbsp; </SPAN>I can promise you that we will both lose more money if you don&#8217;t. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>Sincerely, </FONT></FONT>
<P><FONT face=Verdana size=2>Eric Marvets</FONT></P><img src ="http://marvets.com/blog/aggbug/12205.aspx" width = "1" height = "1" />]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 11:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/phone workedit">phone workedit</category>
      <category domain="http://securityratty.com/tag/free phone">free phone</category>
      <category domain="http://securityratty.com/tag/current phone">current phone</category>
      <category domain="http://securityratty.com/tag/verizon">verizon</category>
      <category domain="http://securityratty.com/tag/phone selection stinks">phone selection stinks</category>
      <category domain="http://securityratty.com/tag/verizon wireless store">verizon wireless store</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/verizon wireless customer">verizon wireless customer</category>
      <source url="http://marvets.com/blog/archive/2008/08/25/12205.aspx">Open Letter to Verizon Wireless</source>
    </item>
    <item>
      <title><![CDATA[Straight Talking Warren Buffett]]></title>
      <link>http://securityratty.com/article/c3eda8d642477dccc307b946fd1f4926</link>
      <guid>http://securityratty.com/article/c3eda8d642477dccc307b946fd1f4926</guid>
      <description><![CDATA[For those who did not hear Warren Buffett being interviewed last Friday morning on CNBC, he did not beat about the bush when talking about the former Presidential hopeful, John Edwards

Mr. Buffett...]]></description>
      <content:encoded><![CDATA[For those who did not hear Warren Buffett being interviewed last Friday morning on CNBC, he did not beat about the bush when talking about the former Presidential hopeful, John Edwards. <br /><span id="fullpost"><br />Mr. Buffett came straight out and accused Mr. Edwards of soliciting and taking money by deceitful means during his unsuccessful Presidential bid earlier this year.  According to Mr. Buffett, John Edwards knew back then that it was only a matter of time before the media uncovered the story of his mistress and alleged love-child.  <br />  <br /></span><br />Unfortunately, this did not stop him from asking suporters to fund his campaign.  Had people knew about the extra-marital affair, they most likely would not have sent in their hard earned dollars as there was no chance that he could continue in the race once the damning news broke.  Mr. Buffett suggested that Edwards should cut back on a few of those expensive haircuts and return those fifty and one hundred dollar donations that came in from ordinary hard working followers.<br /><br />This sentiment rings true for my industry.  At our training courses, we focus on Ethics at the beginning of the course and it runs throughout the training.  Nobody is saying that we are not human and we do not make mistakes - we all do, but covering up the truth to further your own selfish goals is a practice that would probably even disgust the animal Kingdom - except the reptiles possibly.<br /><br />Thank you Mr. Buffett for being so frank and forthright in this era of sterile political correctness.  This is why I enjoy working with successful business people and despise the empty promises and double-talking of policticians, to whatever party they belong.  To those of you in the security world, again I implore you to never forget that your word is your bond and at the end of the day, your reputation will live on after you are long gone.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/edwards">edwards</category>
      <category domain="http://securityratty.com/tag/john edwards">john edwards</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/successful business people">successful business people</category>
      <category domain="http://securityratty.com/tag/sterile political correctness">sterile political correctness</category>
      <category domain="http://securityratty.com/tag/hard">hard</category>
      <category domain="http://securityratty.com/tag/unsuccessful presidential bid">unsuccessful presidential bid</category>
      <category domain="http://securityratty.com/tag/ordinary hard">ordinary hard</category>
      <source url="http://www.thebulletproofblog.com/2008/08/straight-talking-warren-buffett.html">Straight Talking Warren Buffett</source>
    </item>
    <item>
      <title><![CDATA[Cute names can't come to rescue]]></title>
      <link>http://securityratty.com/article/d2fa211d39b867e06c15e58dce810921</link>
      <guid>http://securityratty.com/article/d2fa211d39b867e06c15e58dce810921</guid>
      <description><![CDATA[Most of us have heard the conversations about looming threat to survival Fannie Mae and Freddie Mac. Their names are cute but it can't help fix a bad strategy of making money by dishing out bad loans...]]></description>
      <content:encoded><![CDATA[<P>Most of us have heard the conversations about looming threat to survival&nbsp;Fannie Mae and Freddie Mac. Their names are cute but it can't help fix&nbsp;a bad strategy of making money by dishing out bad loans.</P>
<P>I have had interaction with several security project&nbsp;managers who were very good in creating a buzz around their projects. Projects were given fancy names. The&nbsp;funniest project name&nbsp;I have heard was "Baby Rhino". One day I get an email in my inbox with a subject line which says: Baby Rhino Caputred! - The email&nbsp;got my attention, but the project did not gain any extra respect (because of the name) hardly there was any significant accomplishment in terms of its deliverable.</P>
<P>I would rather stick with project&nbsp;names that signify scope, relevance, meaning and value of&nbsp; a project. It is not bad to market a project, but trying to market a project without delivering value is a gimmick. </P>]]></content:encoded>
      <pubDate>Sat, 23 Aug 2008 19:26:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/names">names</category>
      <category domain="http://securityratty.com/tag/project names">project names</category>
      <category domain="http://securityratty.com/tag/project">project</category>
      <category domain="http://securityratty.com/tag/security project managers">security project managers</category>
      <category domain="http://securityratty.com/tag/bad strategy">bad strategy</category>
      <category domain="http://securityratty.com/tag/bad">bad</category>
      <category domain="http://securityratty.com/tag/baby rhino">baby rhino</category>
      <category domain="http://securityratty.com/tag/bad loans">bad loans</category>
      <category domain="http://securityratty.com/tag/fancy names">fancy names</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/8/23/3852899.html">Cute names can't come to rescue</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.22.08]]></title>
      <link>http://securityratty.com/article/e37289e3f28c0134060472b8a33b4f97</link>
      <guid>http://securityratty.com/article/e37289e3f28c0134060472b8a33b4f97</guid>
      <description><![CDATA[Ah, the opening ceremonies of the Olympics. How spectacular. Is that Li Ning running in the sky with the torch? Oooh, aah. And wait, whats that image on the wall behind him? Looks kinda familiaroops,...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="170" alt="bsod_nest_main2" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/bsod-nest-main2.jpg" width="244" align="left" border="0"> Ah, the opening ceremonies of the Olympics. How spectacular. Is that Li Ning “running” in the sky with the torch? Oooh, aah. And wait, what’s that image on the wall behind him? Looks kinda familiar…oops, it’s an <a href="http://weblog.infoworld.com/robertxcringely/archives/2008/08/geek_week_tk_tk_1.html?source=NLC-NOTES&amp;cgd=2008-08-18" target="_blank">XP blue screen of death</a>….I wonder how much Microsoft paid for advertising during the Olympics?
<p><em>(</em><a href="http://cache.gizmodo.com/assets/images/gizmodo/2008/08/bsod_nest_main2.jpg" target="_blank"><em>Photo Credit: Gizmodo</em></a><em>)</em>
<p>You lose some. You win some: Of course as NBC’s online partner, Microsoft gets a least a cut of the <a href="http://www.paidcontent.org/entry/419-online-ad-spend-tied-to-olympics-expected-to-reach-100-million/" target="_blank">$100 million dollars in online advertising</a> spent around the Olympics. And the millions of <a href="http://www.businessweek.com/technology/content/aug2008/tc20080820_627259.htm?campaign_id=rss_daily" target="_blank">downloads of Silverlight</a> aren’t too shabby either.
<p>The Internet is Falling! Arbor Networks, a security and network management company, partnered with ninety network services and content providers from around the world to publish an extensive <a href="http://www.circleid.com/posts/88181_largest_study_of_ipv6_traffic/" target="_blank">study of IPv6 traffic</a> on the Internet. Craig Labovitiz, Arbor Networks chief scientist, stated that <a href="http://asert.arbornetworks.com/2008/8/the-end-is-near-but-is-ipv6/" target="_blank">only 900 days were left until the end of the Internet</a>, or at least the exhaustion of IPv4 registry allocations. For the past year, the study shows very little IPv6 traffic – something like 1/100<sup>th</sup> of 1% of Internet traffic. Craig credits this to money issues. “The department of commerce estimates it will cost $25 billion for ISPs to upgrade to native IPv6.”
<p>Blogger <a href="http://blog.jamesurquhart.com/2008/08/cloud-computing-bill-of-rights.html" target="_blank">James Urquhart created a bill of rights for cloud computing</a>. The purpose of the bill is to “help guide would-be cloud customers to those clouds best able to guarantee their freedom.” The blogosphere is a great place to get some open debate going, and I applaud James for trying to make something yet so “cloudy” a bit more clear and concrete. But what’s up with the creating a PAC for this?? (Check out the comments.)
<p>Trying to get by on limited resources? Need more money, staff and the freedom to focus on long-term projects? Sound familiar? Then you just might be in <a href="http://blogs.wsj.com/biztech/2008/08/21/life-is-tough-for-midsize-tech-departments/?mod=djemTECH" target="_blank">IT at a midsize company</a>. (or in marketing at a young but rapidly growing IT company <img src='http://blog.sciencelogic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ) Arrow Enterprise Computing Solutions conducted a survey of 200 tech leaders at midsize companies (500 to 3000 employees). The upside: 61% of those surveyed think they’ll be spending more on IT next year – is this bullish thinking about the economy or how much their own business (rev) will be growing?
<p>Bill Snyder calls Dell “<a href="http://weblog.infoworld.com/tech-bottom-line/archives/2008/08/michael_dell_is.html?source=NLC-DAILY&amp;cgd=2008-08-21" target="_blank">Bozo of the Month</a>” for trying to trademark “cloud computing”. Yikes. Maybe not a “bozo” move but certainly inadvisable given how ubiquitous the term is. Here’s <a href="http://blog.sciencelogic.com/no-trademark-for-cloud-computing/08/2008" target="_blank">our take</a> on it.</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 16:15:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network management company">network management company</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet traffic">internet traffic</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/nbcs online partner">nbcs online partner</category>
      <category domain="http://securityratty.com/tag/ipv6 traffic">ipv6 traffic</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/blogger james urquhart">blogger james urquhart</category>
      <category domain="http://securityratty.com/tag/ninety network services">ninety network services</category>
      <source url="http://blog.sciencelogic.com/links-list-82208/08/2008">Links List 8.22.08</source>
    </item>
    <item>
      <title><![CDATA[Reputation Damage & Measurement]]></title>
      <link>http://securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</link>
      <guid>http://securityratty.com/article/d9577961443ca1c3cd93223077fbca5f</guid>
      <description><![CDATA[Reputation damage can be one of the most difficult concepts to build measurements around. In fact, it can be difficult to develop the actual metrics for the measurements, as well. Damage to things...]]></description>
      <content:encoded><![CDATA[<p>Reputation damage can be one of the most difficult concepts to build measurements around.  In fact, it can be difficult to develop the actual metrics for the measurements, as well.  Damage to things like &#8220;corporate reputation&#8221; and &#8220;goodwill&#8221; and &#8220;brand equity&#8221; can be difficult to wrap even reasonable dollar estimates around (When I use FAIR, I really only care to use one metric when describing loss magnitudes - the almighty currency).</p>
<p>Complicating factors is the impact (or lack thereof) of incidents on stock price.  Many researchers who identify themselves with the <strong><a href="http://www.amazon.com/New-School-Information-Security/dp/0321502787">New School of Information Security</a></strong> (yours truly included) want to immediately look at stock price as a bell-weather metric for incident impact.  I think this stems from our days of slinging FUD, back when we could scream &#8220;Buy a firewall or we&#8217;ll have an incident and you&#8217;ll be on the front page of the paper and the stock price will go down!&#8221;  But these days notable incidents seem to suggest that the impact on stock price for an incident is short lived.  <em><strong>With qualifications, of course.</strong></em></p>
<p>So what would/should we make of this from <a href="http://www.money.co.uk/article/1001229-12-million-wiped-off-helphire-stock-after-malicious-gmail-sent-to-clients.htm">Money.co.uk</a>?</p>
<p style="text-align: center;"><strong>£12million ($24m) Wiped off Helphire Stock after Malicious Email Sent to Clients</strong></p>
<blockquote><p>Car hire firm Helphire have taken Google to court after a malicious email sent from a Gmail account saw their shares plummet £12million in a single day.</p>
<p>The Bath-based business who specialise in providing replacement cars to &#8216;no-fault&#8217; drivers involved in accidents on behalf of car insurance companies, initiated legal proceedings against the search engine giant as part of their attempt to find out who is responsible for sending the defamatory mailing.</p>
<p>Google are now known to have complied with the court order and have controversially supplied details of the email account and ISP used by the meddler.</p>
<p>Written under the psudoname Peter Franks, the 1200 word email is know to have been sent from a gmail account that was opened specifically for this purpose and closed a few minutes after the damage had been done&#8230;</p>
<p>&#8230;The misdemeanour couldn’t have come at a worse time for the struggling firm who have undergone a £45million rights issue and seen a 75% drop in the value of their stock already this year.</p></blockquote>
<p>That last paragraph, for me, explains some of the difficulty in tying reputation damage to stock decreases.  It&#8217;s like when you read the headlines from Bloomberg about why the days stocks (or commodity) prices are up or down.  You know, the &#8220;Oil closes $3 higher on news that a notable South American dictator has a rather unpleasant boil in a very uncomfortable area&#8221; type of headlines.  You really do have to question the causality and correlation.  So in the Helphire case above - is this new drop in stock really because of the email sent?  If so, should we view that $24mil number as an independent data point to describe this sort of attack on reputation, or is the magnitude aggravated due to the long-term trend of stock price?</p>
<p>Even when we have &#8220;Objective Data&#8221; (an in-joke for Adam S.) like this decline in stock price, it is really difficult to provide any sort of precise estimate or measurement - about the future, present or past.  The best we can do is use ranges, distributions, that are reasonable based on evidence and observation.</p>
<p>So it&#8217;s worth filing away this sort of datum for future use - while dutifully acknowledging the qualifiers we might place around it.</p>
<p>So the questions I ask here - what should we make of this new information, and how should we view the $24million drop - they&#8217;re not rhetorical.  I am very interested in your views and welcome your comments!</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:33:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stock">stock</category>
      <category domain="http://securityratty.com/tag/helphire stock">helphire stock</category>
      <category domain="http://securityratty.com/tag/reputation damage">reputation damage</category>
      <category domain="http://securityratty.com/tag/reputation">reputation</category>
      <category domain="http://securityratty.com/tag/stock price">stock price</category>
      <category domain="http://securityratty.com/tag/damage">damage</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email account">email account</category>
      <category domain="http://securityratty.com/tag/malicious email">malicious email</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=387">Reputation Damage &amp; Measurement</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogic Makes it Onto the Inc 500 List of Fastest-Growing Private Companies in US]]></title>
      <link>http://securityratty.com/article/13adee3492b3b68c7eae4ade342986fb</link>
      <guid>http://securityratty.com/article/13adee3492b3b68c7eae4ade342986fb</guid>
      <description><![CDATA[Just the facts maam
Rank on Inc. 500: #350
Three-year revenue growth: 840
Rank on Top 100 DC-area companies: #27
DC area ranked #1 for most companies on the Inc. 500 list; #2 for most companies on the...]]></description>
      <content:encoded><![CDATA[<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/08/inc500-logo.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="203" alt="inc500_logo" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/inc500-logo-thumb.jpg" width="244" border="0"></a> </p>
<p>Just <a href="link http://www.inc.com/inc5000/2008/articles/introduction.html" target="_blank">the facts</a> ma’am:</p>
<ul>
<li><a href="link to http://www.inc.com/inc5000/2008/company-profile.html?id=200803500" target="_blank">Rank on Inc. 500: #350</a>
<li>Three-year revenue growth: 840%
<li><a href="http://www.inc.com/inc5000/2008/lists/washington-arlington-alexandria-dc-va-md-wv.html?o=0&amp;c=200803500" target="_blank">Rank on Top 100 DC-area companies: #27</a>
<li>DC area ranked #1 for most companies on the Inc. 500 list; #2 for most companies on the Inc. 5000 list (behind NYC)
<li>2<sup>nd</sup> fastest-growing software company in the DC area (Note: we got categorized as IT Services but of course we really fall under “Software”. They never seem to have a “Technology Appliances” category…)</li>
</ul>
<p><a href="http://www.sciencelogic.com/pressrelease_20080820.htm" target="_blank">Read the full press release here</a>.
<p>We’re loving it because of the awards we’ve applied for over the last few years and haven’t won. (Or maybe only I care about this since I had to fill out all those applications. Hmmm, I’m sensing a pattern here…) But in this case, it’s all about the numbers.
<p>We love this part of our story because it comes down to customers actually believing in you and your product enough to plunk down the money – and keep coming back for more once you prove yourself the first time. It’s not about the hype or the latest flash in the pan or “sponsorship” or how much money some VC gives you. It comes down to you, your product and your happy customers.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:45:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/dc-area companies">dc-area companies</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/software company">software company</category>
      <category domain="http://securityratty.com/tag/happy customers">happy customers</category>
      <category domain="http://securityratty.com/tag/three-year revenue growth">three-year revenue growth</category>
      <category domain="http://securityratty.com/tag/technology appliances category">technology appliances category</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <source url="http://blog.sciencelogic.com/sciencelogic-makes-it-onto-the-inc-500-list-of-fastest-growing-private-companies-in-us/08/2008">ScienceLogic Makes it Onto the Inc 500 List of Fastest-Growing Private Companies in US</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hacking Injunction Lifted]]></title>
      <link>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</link>
      <guid>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</guid>
      <description><![CDATA[Earlier today, the US District Court dealt a victory to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at...]]></description>
      <content:encoded><![CDATA[<p>Earlier today, the US District Court <a href="http://www.eff.org/press/archives/2008/08/19">dealt a victory</a> to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at <a href="http://defcon.org/">DEFCON 16</a>.  In summary:</p>
<blockquote><p>The lawsuit claimed that the students&#8217; planned presentation would violate the Computer Fraud and Abuse Act (CFAA) by enabling others to defraud the MBTA of transit fares. A different federal judge, meeting in a special Saturday session, ordered the trio not to disclose for ten days any information that could be used by others to get free subway rides.</p>
<p>&#8220;The judge today correctly found that it was unlikely that the CFAA would apply to security researchers giving an academic talk,&#8221; said EFF Staff Attorney Marcia Hofmann. &#8220;A presentation at a security conference is not some sort of computer intrusion. It&#8217;s protected speech and vital to the free flow of information about computer security vulnerabilities. Silencing researchers does not improve security &#8212; the vulnerability was there before the students discovered it and would remain in place regardless of whether the students publicly discussed it or not.&#8221;</p></blockquote>
<p>This sets a good precedent for future cases, and perhaps next time a similar situation arises, a judge will not be so quick to issue a gag order.  It&#8217;s not a happy ending yet though, as the <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/mbta-v-anderson-complaint.pdf">original lawsuit</a> is still in effect.</p>
<p>As Chris Wysopal <a href="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">pointed out last week</a>, the MBTA&#8217;s ire is misdirected.  Rather than suing the vendor who sold them the defective system, they sued and attempted to silence the students who discovered the weakness.  This is 2008, not 1988 &#8212; did they honestly think a gag order would prevent the information from reaching the general public?   The DEFCON presentation was already available on the <a href="http://en.wikipedia.org/wiki/Series_of_tubes">Intertubes</a> prior to the injunction being issued, and the MBTA attorneys included a copy of the confidential whitepaper with their filing, thereby making it public.  </p>
<p>I guess you wouldn&#8217;t expect that a transit authority would have paid any attention to the<a href="http://www.schneier.com/blog/archives/2005/07/cisco_harasses.html">Ciscogate fiasco</a> from a few years ago. <a href="http://cryptome.org/lynn-cisco-jpg.htm">That presentation</a> never got out either, did it?  All that taxpayer money the MBTA spent on ridiculous lawsuits and restraining orders could have been put toward fixing the security flaws.  What a concept.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 01:49:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mbta">mbta</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/students publicly">students publicly</category>
      <category domain="http://securityratty.com/tag/defcon presentation">defcon presentation</category>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/mbta hackers">mbta hackers</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/judge">judge</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/">MBTA Hacking Injunction Lifted</source>
    </item>
  </channel>
</rss>
