<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: painful]]></title>
    <link>http://securityratty.com/tag/painful</link>
    <description></description>
    <pubDate>Tue, 22 Apr 2008 18:17:55 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Poor security quality in software. Someone is watching over me.]]></title>
      <link>http://securityratty.com/article/5d5ac42e7f537f2a4fe1612773543dc3</link>
      <guid>http://securityratty.com/article/5d5ac42e7f537f2a4fe1612773543dc3</guid>
      <description><![CDATA[Last week, Ben Worthen of the Wall Street Journal had a conversation with Howard Schmidt about the vulnerabilities in purchased software while Howard was waiting on line to have his iPhone upgraded...]]></description>
      <content:encoded><![CDATA[<p>Last week, Ben Worthen of the Wall Street Journal had a <a href="http://blogs.wsj.com/biztech/2008/07/21/buggy-software-is-your-fault-too/?mod=djemTECH">conversation</a> with Howard Schmidt about the vulnerabilities in purchased software while Howard was waiting on line to have his iPhone upgraded.</p>
<p>Howard Schmidt, who was once the CSO of Microsoft, knows a thing or two about vendors shipping insecure software.  He offers this advice relating to his iPhone, &#8220;Just because a piece of software was distributed through Apple’s App Store, don’t assume that it is vulnerability free.&#8221;  I think that sums up the problem pretty well.  Customers assume the software they are getting is vulnerability free until it is proved otherwise.</p>
<p>If it&#8217;s distributed by the Apple Store it is coming from a trusted brand. &#8220;It must be secure&#8221;, many think.  The same thinking is used by people who install social networking applets and give them access to their personal data.  Someone, somewhere is taking care of the software security so I don&#8217;t have to.  It must be the platform provider, the store, some industry body, my antivirus provider, or maybe even the government.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/07/mall-security.jpg"><img class="size-medium wp-image-147 alignright" title="Mall Security" src="http://www.veracode.com/blog/wp-content/uploads/2008/07/mall-security-300x184.jpg" alt="" width="300" height="184" /></a></p>
<p>You can see how this thinking pervades the consumer space because there are regulatory bodies governing all other aspects of safety and security in our personal lives.  I&#8217;m safe in a plane or car because the government is looking out for me with standards and testing requirements.  I am safe in the mall parking lot because the men in the white SUV are patrolling.</p>
<p>This thinking also pervaded the b2b space.  I talk to companies which are outsourcing critical applications to offshore development companies and they assume that security testing is taking place as part of the development process.  I ask them if they have made security quality part of the requirements of the project and they say no.  Then I ask them what evidence does the offshore developer provide to demonstrate they have a certain level of security quality in the software they are producing and they tell me they have never asked.</p>
<p>I can tell you what would happen if they did ask because I have also spoken with the offshore developers.  They have no evidence.  Their concern is getting the software functionality done on time and on budget. They consider fixing security vulnerabilities, once discovered, rework which the customer pays for.  So not only are they not looking for vulnerabilities and relying on the customer to find them, they are charging the customer to fix the problems.  The customer has to this date accepted this model.</p>
<p>The same goes for commercial off the shelf software and open source.  Surely the developers writing the software are trained in secure software engineering.  Surely commercial software companies are using 3rd parties to test their software just like the banks have the big 4 audit their accounting or auto manufacturers submit to testing by the <a href="http://www.nhtsa.dot.gov/">NHTSA</a>. And of course open source has &#8220;many eyes&#8221; reviewing the code for security defects and informing the developers.  The customer has accepted a model where this is almost never true.</p>
<p>But times are changing and it is partially due to the availability of software that can automate the process of looking for security vulnerabilities. David Rice, the author of <a href="http://www.geekonomicsbook.com/">&#8220;Geekanomics: The Real Cost of Insecure Software&#8221;</a> was <a href="http://beastorbuddha.com/2008/07/29/talking-with-david-rice-insecure-software-implications-regulation-vendors-making-change-and-other-things/">interviewed recently by Drazin Drazic his Beast or Buddha blog</a>.  He said the trend is toward a future of secure software and automated security analysis is one of the sparks:</p>
<blockquote><p><strong>BorB: I recently wrote in a post that little is changing. We are not learning from the lessons of the past. There are few, if any new technologies that exist today, that we have great faith and trust in as being secure now, and expecting them to continue to be secure in the future. Any solutions to even basic security issues need a starting point and a significant change to current thinking, and even then, it will takes years to see the impacts of this. What are your thoughts on this? Are we seeing anything at present to make us more confident of the future?</strong></p>
<p>DR: It is true that it takes years to see the positive impacts of a change of mindset. And we are in the unfortunate position of repeating many old lessons.</p>
<p>At base, human history is a collection of exhaustive, expensive, and protracted engagements; only the relentless survive and have a chance at succeeding (notice no guarantee here). Confronting some of our most complex problems like highway safety, nuclear proliferation, or insecure software is painful, difficult, complicated, and troublesome. Human endeavors of any significance are like this. But we must do it. The inertia of culture and status quo is difficult to overcome, but overcome it we can; otherwise, we would not have the better parts of the world we enjoy today.</p>
<p>I believe the technology space is no different. We are just a little dazed and bewildered by all the changes technology has introduced so quickly and on such a grand scale. For every change we react to, another two or three rapidly appear.</p>
<p>I do see sparks of hope emerging. In the United States some members of government are beginning to understand the problem and are willing to start discussing how to approach insecure software from a policy perspective. On the technology front, companies like Ounce, Fortify, and Veracode are beginning to give software buyers an automated method of evaluating assurance levels of software. While not complete in and of themselves, these solutions are, as I stated, “sparks” that can help us progress down paths that were once not easily open to us.</p>
<p>As for the larger issue of cyber security, which software assurance is only a part of, society has a lot of adjusting to do. The Internet is a new environment for many still, and many more to come. There is a learning curve that must be confronted. It took the United States almost 80 years to develop the highway system we know and enjoy today. Nearly $400 billion was spent on this endeavor with hundreds of thousands of lives lost. As this shows, learning how to govern and navigate a new environment is expensive. Failing to learn even more so.</p></blockquote>
<p>Independent, automated, and repeatable software security testing is an essential component of a safe and secure online environment.  Without it we are stuck with the assumption of vendors perfoming software security as our imaginary security blanket that allows us to operate in the current online world.</p>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 10:51:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/approach insecure software">approach insecure software</category>
      <category domain="http://securityratty.com/tag/insecure software">insecure software</category>
      <category domain="http://securityratty.com/tag/repeatable software security">repeatable software security</category>
      <category domain="http://securityratty.com/tag/secure online environment">secure online environment</category>
      <category domain="http://securityratty.com/tag/environment">environment</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/secure software">secure software</category>
      <category domain="http://securityratty.com/tag/software assurance">software assurance</category>
      <source url="http://www.veracode.com/blog/?p=145">Poor security quality in software. Someone is watching over me.</source>
    </item>
    <item>
      <title><![CDATA[Poor Security Quality In Software; Someone Is Watching Over Me]]></title>
      <link>http://securityratty.com/article/aeb219e925a6f8176126d93b8eb2be49</link>
      <guid>http://securityratty.com/article/aeb219e925a6f8176126d93b8eb2be49</guid>
      <description><![CDATA[Last week, Ben Worthen of the Wall Street Journal had a conversation with Howard Schmidt about the vulnerabilities in purchased software while Howard was waiting on line to have his iPhone upgraded...]]></description>
      <content:encoded><![CDATA[<p>Last week, Ben Worthen of the Wall Street Journal had a <a href="http://blogs.wsj.com/biztech/2008/07/21/buggy-software-is-your-fault-too/?mod=djemTECH">conversation</a> with Howard Schmidt about the vulnerabilities in purchased software while Howard was waiting on line to have his iPhone upgraded.</p>
<p>Howard Schmidt, who was once the CSO of Microsoft, knows a thing or two about vendors shipping insecure software.  He offers this advice relating to his iPhone, &#8220;Just because a piece of software was distributed through Apple’s App Store, don’t assume that it is vulnerability free.&#8221;  I think that sums up the problem pretty well.  Customers assume the software they are getting is vulnerability free until it is proved otherwise.</p>
<p>If it&#8217;s distributed by the Apple Store it is coming from a trusted brand. &#8220;It must be secure&#8221;, many think.  The same thinking is used by people who install social networking applets and give them access to their personal data.  Someone, somewhere is taking care of the software security so I don&#8217;t have to.  It must be the platform provider, the store, some industry body, my antivirus provider, or maybe even the government.</p>
<p><a href="http://www.veracode.com/blog/wp-content/uploads/2008/07/mall-security.jpg"><center><img class="size-medium wp-image-147 alignright photoborder" title="Mall Security" src="http://www.veracode.com/blog/wp-content/uploads/2008/07/mall-security-300x184.jpg" alt="" width="300" height="184" /></center></a></p>
<p>You can see how this thinking pervades the consumer space because there are regulatory bodies governing all other aspects of safety and security in our personal lives.  I&#8217;m safe in a plane or car because the government is looking out for me with standards and testing requirements.  I am safe in the mall parking lot because the men in the white SUV are patrolling.</p>
<p>This thinking also pervaded the b2b space.  I talk to companies which are outsourcing critical applications to offshore development companies and they assume that security testing is taking place as part of the development process.  I ask them if they have made security quality part of the requirements of the project and they say no.  Then I ask them what evidence does the offshore developer provide to demonstrate they have a certain level of security quality in the software they are producing and they tell me they have never asked.</p>
<p>I can tell you what would happen if they did ask because I have also spoken with the offshore developers.  They have no evidence.  Their concern is getting the software functionality done on time and on budget. They consider fixing security vulnerabilities, once discovered, rework which the customer pays for.  So not only are they not looking for vulnerabilities and relying on the customer to find them, they are charging the customer to fix the problems.  The customer has to this date accepted this model.</p>
<p>The same goes for commercial off the shelf software and open source.  Surely the developers writing the software are trained in secure software engineering.  Surely commercial software companies are using 3rd parties to test their software just like the banks have the big 4 audit their accounting or auto manufacturers submit to testing by the <a href="http://www.nhtsa.dot.gov/">NHTSA</a>. And of course open source has &#8220;many eyes&#8221; reviewing the code for security defects and informing the developers.  The customer has accepted a model where this is almost never true.</p>
<p>But times are changing and it is partially due to the availability of software that can automate the process of looking for security vulnerabilities. David Rice, the author of <a href="http://www.geekonomicsbook.com/">&#8220;Geekanomics: The Real Cost of Insecure Software&#8221;</a> was <a href="http://beastorbuddha.com/2008/07/29/talking-with-david-rice-insecure-software-implications-regulation-vendors-making-change-and-other-things/">interviewed recently by Drazin Drazic his Beast or Buddha blog</a>.  He said the trend is toward a future of secure software and automated security analysis is one of the sparks:</p>
<blockquote><p><strong>BorB: I recently wrote in a post that little is changing. We are not learning from the lessons of the past. There are few, if any new technologies that exist today, that we have great faith and trust in as being secure now, and expecting them to continue to be secure in the future. Any solutions to even basic security issues need a starting point and a significant change to current thinking, and even then, it will takes years to see the impacts of this. What are your thoughts on this? Are we seeing anything at present to make us more confident of the future?</strong></p>
<p>DR: It is true that it takes years to see the positive impacts of a change of mindset. And we are in the unfortunate position of repeating many old lessons.</p>
<p>At base, human history is a collection of exhaustive, expensive, and protracted engagements; only the relentless survive and have a chance at succeeding (notice no guarantee here). Confronting some of our most complex problems like highway safety, nuclear proliferation, or insecure software is painful, difficult, complicated, and troublesome. Human endeavors of any significance are like this. But we must do it. The inertia of culture and status quo is difficult to overcome, but overcome it we can; otherwise, we would not have the better parts of the world we enjoy today.</p>
<p>I believe the technology space is no different. We are just a little dazed and bewildered by all the changes technology has introduced so quickly and on such a grand scale. For every change we react to, another two or three rapidly appear.</p>
<p>I do see sparks of hope emerging. In the United States some members of government are beginning to understand the problem and are willing to start discussing how to approach insecure software from a policy perspective. On the technology front, companies like Ounce, Fortify, and Veracode are beginning to give software buyers an automated method of evaluating assurance levels of software. While not complete in and of themselves, these solutions are, as I stated, “sparks” that can help us progress down paths that were once not easily open to us.</p>
<p>As for the larger issue of cyber security, which software assurance is only a part of, society has a lot of adjusting to do. The Internet is a new environment for many still, and many more to come. There is a learning curve that must be confronted. It took the United States almost 80 years to develop the highway system we know and enjoy today. Nearly $400 billion was spent on this endeavor with hundreds of thousands of lives lost. As this shows, learning how to govern and navigate a new environment is expensive. Failing to learn even more so.</p></blockquote>
<p>Independent, automated, and repeatable software security testing is an essential component of a safe and secure online environment.  Without it we are stuck with the assumption of vendors perfoming software security as our imaginary security blanket that allows us to operate in the current online world.</p>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 10:51:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/approach insecure software">approach insecure software</category>
      <category domain="http://securityratty.com/tag/insecure software">insecure software</category>
      <category domain="http://securityratty.com/tag/repeatable software security">repeatable software security</category>
      <category domain="http://securityratty.com/tag/secure online environment">secure online environment</category>
      <category domain="http://securityratty.com/tag/environment">environment</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/secure software">secure software</category>
      <category domain="http://securityratty.com/tag/software assurance">software assurance</category>
      <source url="http://www.veracode.com/blog/2008/07/poor-security-quality-in-software-someone-is-watching-over-me/">Poor Security Quality In Software; Someone Is Watching Over Me</source>
    </item>
    <item>
      <title><![CDATA[Quick thoughts on using the iPhone 3G]]></title>
      <link>http://securityratty.com/article/7e0dbb56452b0c71a5581a5ba7926361</link>
      <guid>http://securityratty.com/article/7e0dbb56452b0c71a5581a5ba7926361</guid>
      <description><![CDATA[So I got my iPhone 3G on Friday morning and have been using it for a few days now. I have never used one before, don't use an iPod or even a Mac computer. The iPhone was incredibily easy to use and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So I got my iPhone 3G on Friday morning and have been using it for a few days now. I have never used one before, don't use an iPod or even a Mac computer.&nbsp; The iPhone was incredibily easy to use and without using and manuals quickly had a most everything working and downloaded a bunch of apps from the app store.&nbsp; </p>

<p>Over all, the iPhone just is really nice to use and in many ways very easy, polished and intuitive. In other ways, it is still missing some key features in my book:</p>

<ol><li>Sort and filter email be date, sender, etc.</li>

<li>Select more than one mail at a time to delete, move, copy.&nbsp; Yes I know you can go to edit and select messages to work on, but you still have to select them one at a time. In <a class="zem_slink" title="Windows Mobile" href="http://microsoft.com/windowsmobile/" rel="homepage">Windows Mobile</a> you can just run your finger over multiple messages to complete this.</li>

<li>Deleting duplicate contacts in bulk.&nbsp; Doing them one at a time is just painful</li>

<li>A task manager. I would like to see some list that shows me which apps are running, how many resources they are using, battery usage and stuff like that.&nbsp; Also to shut down running apps</li>

<li>Better calendar integration. I tried to click on and open calendar items, but just does not seem to work.</li>

<li>The battery sucks! I am not getting more than about 6 to 7 hours of battery time. I think I have to turn off the push for my Exchange email.&nbsp; This is much less that I was getting on my Windows Mobile phone. </li></ol>

<p>I do like the phone, the iPod MP3 and camera and the overall &quot;feel&quot; of the phone. Went to the Apple store in the maill (which was jam packed) and bought a rubberized case, but was unable to get a phone car charger for it yet.&nbsp; I ordered one for 5 bucks on Amazon and will see it if works.</p>

<p>All in all, things are OK but I am going to withhold my final verdict for a while yet.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-13579_3-9994744-37.html?hhTest=1&amp;part=rss&amp;subj=news">What iPhone? Apple earnings (still) about the Mac</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.tuaw.com/2008/07/21/mod-your-dock-to-work-with-iphone-3g/">Mod your dock to work with iPhone 3G</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.sauria.com/blog/2008/07/20/my-initial-iphone-experience/">My initial iPhone experience</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/85ef20ad-b620-4d16-9f87-17955147e8a7/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=85ef20ad-b620-4d16-9f87-17955147e8a7" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 05:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/phone car charger">phone car charger</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/initial iphone experience">initial iphone experience</category>
      <category domain="http://securityratty.com/tag/windows mobile phone">windows mobile phone</category>
      <category domain="http://securityratty.com/tag/windows mobile">windows mobile</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/battery time">battery time</category>
      <category domain="http://securityratty.com/tag/select messages">select messages</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/quick-thoughts.html">Quick thoughts on using the iPhone 3G</source>
    </item>
    <item>
      <title><![CDATA[Quick thoughts on using the iPhone 3G]]></title>
      <link>http://securityratty.com/article/0cfe5d9fddb01551dfe3d3dcb40ee176</link>
      <guid>http://securityratty.com/article/0cfe5d9fddb01551dfe3d3dcb40ee176</guid>
      <description><![CDATA[So I got my iPhone 3G on Friday morning and have been using it for a few days now. I have never used one before, don't use an iPod or even a Mac computer. The iPhone was incredibily easy to use and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So I got my iPhone 3G on Friday morning and have been using it for a few days now. I have never used one before, don't use an iPod or even a Mac computer.&nbsp; The iPhone was incredibily easy to use and without using and manuals quickly had a most everything working and downloaded a bunch of apps from the app store.&nbsp; </p>

<p>Over all, the iPhone just is really nice to use and in many ways very easy, polished and intuitive. In other ways, it is still missing some key features in my book:</p>

<ol><li>Sort and filter email be date, sender, etc.</li>

<li>Select more than one mail at a time to delete, move, copy.&nbsp; Yes I know you can go to edit and select messages to work on, but you still have to select them one at a time. In <a class="zem_slink" title="Windows Mobile" href="http://microsoft.com/windowsmobile/" rel="homepage">Windows Mobile</a> you can just run your finger over multiple messages to complete this.</li>

<li>Deleting duplicate contacts in bulk.&nbsp; Doing them one at a time is just painful</li>

<li>A task manager. I would like to see some list that shows me which apps are running, how many resources they are using, battery usage and stuff like that.&nbsp; Also to shut down running apps</li>

<li>Better calendar integration. I tried to click on and open calendar items, but just does not seem to work.</li>

<li>The battery sucks! I am not getting more than about 6 to 7 hours of battery time. I think I have to turn off the push for my Exchange email.&nbsp; This is much less that I was getting on my Windows Mobile phone. </li></ol>

<p>I do like the phone, the iPod MP3 and camera and the overall &quot;feel&quot; of the phone. Went to the Apple store in the maill (which was jam packed) and bought a rubberized case, but was unable to get a phone car charger for it yet.&nbsp; I ordered one for 5 bucks on Amazon and will see it if works.</p>

<p>All in all, things are OK but I am going to withhold my final verdict for a while yet.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-13579_3-9994744-37.html?hhTest=1&amp;part=rss&amp;subj=news">What iPhone? Apple earnings (still) about the Mac</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.tuaw.com/2008/07/21/mod-your-dock-to-work-with-iphone-3g/">Mod your dock to work with iPhone 3G</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.sauria.com/blog/2008/07/20/my-initial-iphone-experience/">My initial iPhone experience</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/85ef20ad-b620-4d16-9f87-17955147e8a7/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=85ef20ad-b620-4d16-9f87-17955147e8a7" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=9KiZv6"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=9KiZv6" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=IOYoQJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=IOYoQJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=mSxf2J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=mSxf2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=OhjTRJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=OhjTRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=vXaNrJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=vXaNrJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=3F1Amj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=3F1Amj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=RXYnnj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=RXYnnj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/342550630" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 04:36:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/phone car charger">phone car charger</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/initial iphone experience">initial iphone experience</category>
      <category domain="http://securityratty.com/tag/windows mobile phone">windows mobile phone</category>
      <category domain="http://securityratty.com/tag/windows mobile">windows mobile</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/battery time">battery time</category>
      <category domain="http://securityratty.com/tag/select messages">select messages</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/342550630/quick-thoughts.html">Quick thoughts on using the iPhone 3G</source>
    </item>
    <item>
      <title><![CDATA[Gonzo: Two Thumbs In and Up]]></title>
      <link>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</link>
      <guid>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</guid>
      <description><![CDATA[Just saw the Hunter S. Thompson movie - Gonzo , and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view...]]></description>
      <content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Hunter_S._Thompson"></a><a style="float: left;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-pi"><img  class="at-xid-6a00d83451c75869e200e553c045c48834 " alt="180px-Gonzo_citation" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-320wi" style="margin: 0px 5px 5px 0px;"></a> Just saw the Hunter S. Thompson movie - <a href="http://www.rottentomatoes.com/m/gonzo_the_life_and_work_of_dr_hunter_s_thompson/">Gonzo</a>, and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view of the high highs and the low lows. Weaves in writing, politics, and fame seamlessly.

I have never really had as much fun as early on in my career in the early-mid 90s I was a web programmer in Aspen, hacking CGI/PERL. Among the most fun things was building and running HST's site. My boss, Ed, was his neighbor. Ed was also seriously allergic to bees. One day he was alone in his house and got stung. He was dying. Luckily Hunter was due over to his house to watch a basketball game, walked in and called 911. My boss woke up in the ambulance with Hunter pounding on him chest and screaming at him. Ed said - "Waking up to that face screaming at me, I didn't know if I was alive or dead."

Seeing the movie it was also great to see a lot of the Woody Creek folks again like George Stranahan, who lovingly said about Hunter - "my friend and neighbor who never paid his rent, broke up my marriage and taught my children to smoke dope. "

Of course, there was no way he could match his early productivity and this is true of almost all artists. Most of the last two decades were wasted from a writing standpoint. However his <a href="http://proxy.espn.go.com/espn/page2/story?id=1250751">piece</a> written on 9/11 is as good as its gets:

</p><blockquote><p>
	The towers are gone now, reduced to bloody rubble, along with all hopes for Peace in Our Time, in the United States or any other country. Make no mistake about it: We are At War now -- with somebody -- and we will stay At War with that mysterious Enemy for the rest of our lives. 	
	</p></blockquote><blockquote><p>It will be a Religious War, a sort of Christian Jihad, fueled by religious hatred and led by merciless fanatics on both sides. It will be guerilla warfare on a global scale, with no front lines and no identifiable enemy. Osama bin Laden may be a primitive "figurehead" -- or even dead, for all we know -- but whoever put those All-American jet planes loaded with All-American fuel into the Twin Towers and the Pentagon did it with chilling precision and accuracy. The second one was a dead-on bullseye. Straight into the middle of the skyscraper. 	
	</p></blockquote><blockquote><p>Nothing -- even George Bush's $350 billion "Star Wars" missile defense system -- could have prevented Tuesday's attack, and it cost next to nothing to pull off. Fewer than 20 unarmed Suicide soldiers from some apparently primitive country somewhere on the other side of the world took out the World Trade Center and half the Pentagon with three quick and costless strikes on one day. The efficiency of it was terrifying. 	
	</p></blockquote><blockquote><p>We are going to punish somebody for this attack, but just who or what will be blown to smithereens for it is hard to say. Maybe Afghanistan, maybe Pakistan or Iraq, or possibly all three at once. Who knows? Not even the Generals in what remains of the Pentagon or the New York papers calling for WAR seem to know who did it or where to look for them. 	
	</p></blockquote><blockquote><p>This is going to be a very expensive war, and Victory is not guaranteed -- for anyone, and certainly not for anyone as baffled as George W. Bush. All he knows is that his father started the war a long time ago, and that he, the goofy child-President, has been chosen by Fate and the global Oil industry to finish it Now. He will declare a National Security Emergency and clamp down Hard on Everybody, no matter where they live or why. If the guilty won't hold up their hands and confess, he and the Generals will ferret them out by force. 	
	</p></blockquote><blockquote><p>Good luck. He is in for a profoundly difficult job -- armed as he is with no credible Military Intelligence, no witnesses and only the ghost of Bin Laden to blame for the tragedy.
	
</p></blockquote><p>


One unintended lesson I take away from Hunter's life is how important patience is. Obama is a politician and may yet disappoint us all, but I gotta believe Hunter would be seriously impressed. If he had waited another couple of years, he may have seen a lot of the stuff he fought for in 1968 and 72 come to fruition. Sometimes you are just 36-40 years ahead of your time and you have to be ok with that and figure out how to deal if possible. (Note - it sure sometimes feels this way in software security).

Speaking of security:

</p><blockquote>
	<p><a href="http://www.ram.org/contrib/security.html">Security</a> 	
	</p></blockquote><blockquote><p>by Hunter S. Thompson (1955). 	
	</p></blockquote><blockquote><p>Security ... what does this word mean in relation to life as we know it today? For the most part, it means safety and freedom from worry. It is said to be the end that all men strive for; but is security a utopian goal or is it another word for rut? 	
	</p></blockquote><blockquote><p>Let us visualize the secure man; and by this term, I mean a man who has settled for financial and personal security for his goal in life. In general, he is a man who has pushed ambition and initiative aside and settled down, so to speak, in a boring, but safe and comfortable rut for the rest of his life. His future is but an extension of his present, and he accepts it as such with a complacent shrug of his shoulders. His ideas and ideals are those of society in general and he is accepted as a respectable, but average and prosaic man. But is he a man? has he any self-respect or pride in himself? How could he, when he has risked nothing and gained nothing? What does he think when he sees his youthful dreams of adventure, accomplishment, travel and romance buried under the cloak of conformity? How does he feel when he realizes that he has barely tasted the meal of life; when he sees the prison he has made for himself in pursuit of the almighty dollar? If he thinks this is all well and good, fine, but think of the tragedy of a man who has sacrificed his freedom on the altar of security, and wishes he could turn back the hands of time. A man is to be pitied who lacked the courage to accept the challenge of freedom and depart from the cushion of security and see life as it is instead of living it second-hand. Life has by-passed this man and he has watched from a secure place, afraid to seek anything better What has he done except to sit and wait for the tomorrow which never comes? 	
	</p></blockquote><blockquote><p>Turn back the pages of history and see the men who have shaped the destiny of the world. Security was never theirs, but they lived rather than existed. Where would the world be if all men had sought security and not taken risks or gambled with their lives on the chance that, if they won, life would be different and richer? It is from the bystanders (who are in the vast majority) that we receive the propaganda that life is not worth living, that life is drudgery, that the ambitions of youth must he laid aside for a life which is but a painful wait for death. These are the ones who squeeze what excitement they can from life out of the imaginations and experiences of others through books and movies. These are the insignificant and forgotten men who preach conformity because it is all they know. These are the men who dream at night of what could have been, but who wake at dawn to take their places at the now-familiar rut and to merely exist through another day. For them, the romance of life is long dead and they are forced to go through the years on a treadmill, cursing their existence, yet afraid to die because of the unknown which faces them after death. They lacked the only true courage: the kind which enables men to face the unknown regardless of the consequences. 	
	</p></blockquote><blockquote><p>As an afterthought, it seems hardly proper to write of life without once mentioning happiness; so we shall let the reader answer this question for himself: who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed?
</p></blockquote><p>

A ship is safest at port, but thats not why we build ships. 
</p>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 06:10:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/sought security">sought security</category>
      <category domain="http://securityratty.com/tag/personal security">personal security</category>
      <category domain="http://securityratty.com/tag/national security emergency">national security emergency</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/expensive war">expensive war</category>
      <category domain="http://securityratty.com/tag/war">war</category>
      <category domain="http://securityratty.com/tag/hunter">hunter</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/gonzo-two-thumbs-in-and-up.html">Gonzo: Two Thumbs In and Up</source>
    </item>
    <item>
      <title><![CDATA[Curious Factoid on Hated Creations]]></title>
      <link>http://securityratty.com/article/4cf64d41972d288adbdd76b989e40840</link>
      <guid>http://securityratty.com/article/4cf64d41972d288adbdd76b989e40840</guid>
      <description><![CDATA[I did this super-fun webcast today, looking at the results of 4th SANS Annual Log Management Survey ( webcast , PDF survey results

There is a lot of fun and useful material in both, but here is a...]]></description>
      <content:encoded><![CDATA[I did this super-fun webcast today, looking at the results of 4th  SANS Annual Log Management Survey (<a href="https://www.sans.org/webcasts/show.php?webcastid=91758">webcast</a>, <a href="http://www.sans.org/reading_room/analysts_program/LogMgt_June08.pdf">PDF survey results</a>).<br /><br />There is a lot of fun and useful material in both, but here is a little painful factoid:  <span style="font-style: italic;">73% of people who created their own home-grown log management tools hate them :-)</span><br /><br /><span style="font-weight: bold;">Possibly related posts:</span><br /><ul><li><a href="http://www.slideshare.net/anton_chuvakin/choosing-your-log-management-approach-buy-build-or-outsource/">My presentation on buy vs build vs outsources</a></li><li><a href="http://chuvakin.blogspot.com/2007/10/why-replace-your-baby.html">"Why Replace Your Baby?"</a></li><li><a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2007/11/6_Event_Log_Management_for_PCI_DSS%3A.html">Log Management "Strategy:" Built ->Suffer->Suffer->Suffer</a></li></ul><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=braZDI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=braZDI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bEi2sI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bEi2sI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=G4qcZI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=G4qcZI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/305866505" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 18:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/super-fun webcast">super-fun webcast</category>
      <category domain="http://securityratty.com/tag/pdf survey results">pdf survey results</category>
      <category domain="http://securityratty.com/tag/webcast">webcast</category>
      <category domain="http://securityratty.com/tag/results">results</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/painful factoid">painful factoid</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/strategy">strategy</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/305866505/curious-factoid-on-hated-creations.html">Curious Factoid on Hated Creations</source>
    </item>
    <item>
      <title><![CDATA[Windows Server 2008 implementation tutorial]]></title>
      <link>http://securityratty.com/article/a337699a9c8d00cf7db668b8d4552583</link>
      <guid>http://securityratty.com/article/a337699a9c8d00cf7db668b8d4552583</guid>
      <description><![CDATA[Upgrading your customers' servers to Windows Server 2008 will be much less painful than upgrading their client machines to Vista. Use this tutorial to find out about improvements to the OS and where...]]></description>
      <content:encoded><![CDATA[Upgrading your customers' servers to Windows Server 2008 will be much less painful than upgrading their client machines to Vista. Use this tutorial to find out about improvements to the OS and where your customers could use help.<img src="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~4/285529401" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 07 May 2008 09:48:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <category domain="http://securityratty.com/tag/tutorial">tutorial</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/client machines">client machines</category>
      <category domain="http://securityratty.com/tag/improvements">improvements</category>
      <category domain="http://securityratty.com/tag/painful">painful</category>
      <category domain="http://securityratty.com/tag/servers">servers</category>
      <category domain="http://securityratty.com/tag/vista">vista</category>
      <source url="http://feeds.feedburner.com/~r/WhatisEnterpriseItTipsAndExpertAdvice/~3/285529401/0,295582,sid99_gci1312638,00.html">Windows Server 2008 implementation tutorial</source>
    </item>
    <item>
      <title><![CDATA[Because Hackers Don't Care... (Why Metrics Don't Work)]]></title>
      <link>http://securityratty.com/article/d554c29d4f8e987d1ead6f9a8532dc65</link>
      <guid>http://securityratty.com/article/d554c29d4f8e987d1ead6f9a8532dc65</guid>
      <description><![CDATA[Lets start with some statistics

99% of all workstations with up-to-date antivirus
Antivirus blocks over 99% of all malware

That is amazing! That is great stuff to show the IT Director, CIO, CSO, mom...]]></description>
      <content:encoded><![CDATA[Lets start with some statistics:<br /><br />99% of all workstations with up-to-date antivirus<br />Antivirus blocks over 99% of all malware.<br /><br />That is amazing! That is great stuff to show the IT Director, CIO, CSO, mom and to put on the wall. But, yet, a company I know (not the one I work for) still managed to get a virus which brought about some painful downtime.<br /><br />The virus was one of the 1% that the antivirus doesn't block and it spread through the organisation like wildfire. Essentially the saving grace was that it infected a small part of the network, brought that down and didn't spread from there. Luck. It was also non-destructive other than network downtime. Luck.<br /><br />The metrics lied.<br /><br />You could say that there was residual risk but it really looks quite small. What is 1% between friends? But that 1% is precisely what any hacker (or virus writer etc) worth his salt is targeting.<br /><br />So, where to from here?<br /><br />I won't throw the baby out with the bathwater. 99% of PCs with antivirus is certainly safer than 50% or 0%. 99% of PCs fully patched is safer then 70% or even 100% of PCs almost fully patched. But 99% of PCs with antivirus is not a guarantee that no virus will find its way to destroying your network. It is important that your boss(es) know this and more important is that <strong>you</strong> know this.<br /><br />And have plans in place when the 1% risk becomes reality.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/280103366" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 29 Apr 2008 09:23:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/antivirus blocks">antivirus blocks</category>
      <category domain="http://securityratty.com/tag/antivirus">antivirus</category>
      <category domain="http://securityratty.com/tag/virus writer">virus writer</category>
      <category domain="http://securityratty.com/tag/virus">virus</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network downtime">network downtime</category>
      <category domain="http://securityratty.com/tag/pcs">pcs</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/residual risk">residual risk</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/280103366/because-hackers-dont-care-why-metrics.html">Because Hackers Don't Care... (Why Metrics Don't Work)</source>
    </item>
    <item>
      <title><![CDATA[Some Burning Logging Questions - Answered!]]></title>
      <link>http://securityratty.com/article/d9d6f72f9a5cc1e9a8b472fe3df3a204</link>
      <guid>http://securityratty.com/article/d9d6f72f9a5cc1e9a8b472fe3df3a204</guid>
      <description><![CDATA[I was wandering down a street and somebody came out and confronted me with these logging questions :-) So I answered them - now I am posting them here since they might be useful for my readers
Q1: For...]]></description>
      <content:encoded><![CDATA[<p>I was wandering down a street and somebody came out and confronted me with these logging questions :-) So I answered them - now I am posting them here since they might be useful for my readers.</p> <p><strong>Q1: For those companies that have successfully implemented enterprise-wide logging, what  were the big nasty surprises that they encountered? </strong> </p><p><strong>A1:</strong>  Here are a few:</p> <ul> <li>political boundaries within the organization: "these are our logs, and you are  not getting them"  </li><li>privacy laws: some logs cannot be collected in some countries; some  cannot cross the border, some cannot be seen by some people, etc. This  is true mostly in EU, less in US.  </li><li>legal blocks: work with legal before deploying any org-wide log  management; legal might try to prevent certain data from ever being  created (for fear of being legally discovered later)  </li><li>log volume: underestimating log volume is common and pretty nasty  </li><li>related to the last one: vendors being "optimistic" about their tool  scalability  </li><li>time synchronization (of course!), specifically, lack thereof.</li></ul> <p> </p> <p><strong>Q2: For those companies that have successfully implemented enterprise-wide logging,  what was their  implementation approach?</strong>  </p><p><strong>A2:</strong> Typically, 2-3 vendor PoC or pilot first.  Then with the chosen vendor: phased approach based on location + type of log source (e.g. firewalls, then routers, then OS, then proxies, etc) + network topology (e.g. DMZ, then internal) + log  source criticality (e.g. critical servers first; the rest next). <a href="http://chuvakin.blogspot.com/2007/01/natural-flow-of-log-management.html%20">This</a> might be handy to look at.<br />  </p><p><strong>Q3: What kind of storage requirements have been experienced by those organizations who have successfully implemented enterprise-wide logging?</strong>  </p><p><strong>A3:</strong> Massive? :-)  </p><p>Here is a simple example: PCI DSS is a bit more aggressive than NERC  since it mandates 1 year of log retention vs NERC 90 days, so: 1 year worth of logs is =  365 days x 24 hours x 3600 seconds x 1 (one!!!) busy firewall with 100 log  messages each second x 200 bytes per message average (e.g. valid for  PIX and ASA devices) = 588 gigabytes / year of raw log data uncompressed (assuming 10x  compression you'd get about 60GB of compressed log data per year)  </p><p>Store it in RDBMS? Multiple it by 2-3. Have an index? Add about 30%.  </p><p>The bottom line is: terabyte is the unit to measure logs.  </p><p>  </p><p><strong>Q4: At the organizations that have successfully implemented enterprise-wide logging, how logging impacted network and system performance? </strong> </p><p><strong>A4: </strong>Too broad a question, so here are a few pointers:  </p><ul> <li><strong>logging</strong> affects performance much more on some types of systems compared to other types: most painful  examples are databases where some people (can't find a link...sorry) report performance  loss of up to 40% if logging all SELECT statements and other data retrieval  commands (you need to log selectively on these); in other cases (e.g. web  servers) there is no performance loss and logging is "always on"  </li><li><strong>log collection</strong>: agents impact system performance (<a href="http://chuvakin.blogspot.com/2008/02/more-on-hating-agents.html">long post on this subjects</a>): a little when they  run (everybody knows this) and A LOT when they crash (few people think  about it - agent software memory leaks are not uncommon); unlike agents,  remote agentless log collection barely affects system performance  (unless you have one of the few esoteric cases)  </li><li><strong>log transfer</strong> and network performance: look for compressed (logs  compress really well), TCP-based transfers; syslogging over UDP uncompressed  has a chance of doing a pipe saturation DoS on your network.  Yes, people say "use a dedicated LAN," but  this is definitely wishful thinking for many. Also, raw UDP syslog in large quantities over WAN  = insanity :-)</li></ul> <p><strong></strong>  </p><p><strong>Q5: What were some successful strategies for obtaining  buy-in from system owners and operators in regards to turning logging on?</strong>  </p><p><strong>A5:</strong> OK, also too broad a question, but here are some pointers:</p> <ul> <li>provide them a <em>useful service</em> based on their logs (e.g. performance  measurement, availability monitoring, compromise detection :-), or other security metrics, etc)  </li><li>help them with <em>their compliance mandates</em> (e.g. create reports that  they can show to the auditors that "bug" them)  </li><li>give them <em>tools</em> to <em>better solve their problems</em> (e.g. allow access to a  log management tool so that can investigate issues better, search the logs, check on their users, etc) </li></ul> <p> </p> <p><strong>Q6: How the organizations that have successfully implemented enterprise-wide logging dealt with unusual  devices (=log sources)  that have no log management vendor  support?</strong>  </p><p><strong>A6: </strong>They were in massive pain - if they choose a log management vendor wrong. You need to look for  vendors that have "universal log source support"  with NO requirement for a custom  rules or custom collector/connector/agent development. <a href="http://www.loglogic.com/">Some vendors</a> have generic  text log collectors that can grab and analyze  unknown logs. Typically  this is done via some form of text indexing that works across all logs,  including those from unknown, vertical, esoteric or custom-developed log  sources  </p><p>Hope it was useful!</p><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=37ns1sG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=37ns1sG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=YlGQ9BG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=YlGQ9BG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/276500279" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 12:20:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/raw log data">raw log data</category>
      <category domain="http://securityratty.com/tag/logs compress">logs compress</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/analyze unknown logs">analyze unknown logs</category>
      <category domain="http://securityratty.com/tag/unknown">unknown</category>
      <category domain="http://securityratty.com/tag/data retrieval commands">data retrieval commands</category>
      <category domain="http://securityratty.com/tag/measure logs">measure logs</category>
      <category domain="http://securityratty.com/tag/log data">log data</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/276500279/some-burning-logging-questions-answered.html">Some Burning Logging Questions - Answered!</source>
    </item>
    <item>
      <title><![CDATA[5 Reasons Why IT Security People Shouldnt Ignore Cloud Computing]]></title>
      <link>http://securityratty.com/article/de833bbff5eb513e284f3a9162c86126</link>
      <guid>http://securityratty.com/article/de833bbff5eb513e284f3a9162c86126</guid>
      <description><![CDATA[Youve read the headlines. Youve heard the buzzwords
Cloud Computing just seems like hype, right
But its just another technology getting hyped to the max
The best case scenario is that your analysis is...]]></description>
      <content:encoded><![CDATA[<p><a title="What a job!" href="http://www.flickr.com/photos/54168635@N00/234838351/" target="_blank"><img src="http://farm1.static.flickr.com/90/234838351_6879b2ab3a_m.jpg" border="0" alt="What a job!" /></a></p>
<p>You&#8217;ve read the headlines.  You&#8217;ve heard the buzzwords.  </p>
<p>Cloud Computing just seems like hype, right?  </p>
<p>&#8220;But it&#8217;s just another technology getting hyped to the max&#8221;.</p>
<p>The <em>best case scenario</em> is that your analysis is correct and you can go back to reading Slashdot and Daily Dave (you are reading Daily Dave aren&#8217;t you?).  You can pride yourself on your ability to recognise web hysteria and laugh at the losers that invested, wrote blog posts (!) and dared to take it seriously.</p>
<p>OK.  Now lets flip that around and just say for a moment you&#8217;re wrong - that Cloud Computing turns out to be a huge deal and takes off.  What could that mean for your day job?  No in-house servers to secure?  No in-house security operations to deal with? No in-house penetration tests to run?  No vulnerability assessment tools to run? No incident response where you actually &#8216;do something&#8217;?  </p>
<p>One scenario is you find yourself on a constant round of conference calls with 3rd parties trying to &#8216;pin down&#8217; security in the cloud&#8230;  If you thought handling security issues associated with outsourcing was painful and slow, the Cloud will bring a multitude of competing providers that decision makers can switch from &#8216;digitally&#8217; when the numbers ($$) make sense.</p>
<p>As the person responsible for your employer&#8217;s security arrangements, you may want to consider these 5 reasons for not dismissing Cloud Computing out of hand:</p>
<ul>
<li><strong>Unless you work for an IT company, your employer did not go into business to &#8216;do IT&#8217;.</strong>  They are in business to sell a product or a service - in-house IT may have enabled that up to now but it was out of need rather than desire.  Cloud Computing has hit the cover of popular business magazines - its starting to get on the radar of CEO&#8217;s that ask questions like &#8216;how can I cut my costs?&#8217;, &#8216;how can I make my business more agile?&#8217;.  They may not switch overnight, but once the first goes in a given vertical, the clock is ticking.</li>
<li><strong>The temptation to contractually outsource security responsibility.</strong>  &#8221;Our customer data got stolen from a cloud storage provider - not us - we don&#8217;t run IT!&#8221;.  Sure the buck stops with the org from a regulatory perspective but media coverage around recent data leakages involving 3rd party providers illicits a mixed reaction and thus diffuses the &#8220;reputation issues&#8221; to some extent.</li>
<li><strong>The skills you need to deal with Cloud Security may be different from the skills you have today.</strong>  Your &#8220;window&#8221; on Cloud security will be what the Cloud Provider gives you.  Beyond that you may be able to do an on-site audit from time to time but its a shared facility so no monkey in a cage pen-testing, scanning or filesystem forensic analysis.</li>
<li><strong>There&#8217;s a large cloud forming over the horizon.</strong>  The level of investment by providers doesn&#8217;t bear ignoring.  IBM, Google, Amazon, Microsoft and others are ploughing hundreds of millions of dollars building out data centers specifically for Cloud Computing.</li>
<li><strong>You may just end up working for the Cloud Provider!</strong>  This is something I believe will start happening in the next 2-3 years.  If you need a second opinion, go see <a href="http://taosecurity.blogspot.com/2008/04/cloudsecurityorg.html">Richard Bejtlich&#8217;s blog</a> when he shared his own perspective.</li>
</ul>
<p>What say you?  Hype or pending reality?</p>
<p> </p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/275708788" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Apr 2008 18:17:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/cloud storage provider">cloud storage provider</category>
      <category domain="http://securityratty.com/tag/in-house">in-house</category>
      <category domain="http://securityratty.com/tag/in-house security operations">in-house security operations</category>
      <category domain="http://securityratty.com/tag/cloud security">cloud security</category>
      <category domain="http://securityratty.com/tag/employers security arrangements">employers security arrangements</category>
      <category domain="http://securityratty.com/tag/cloud provider">cloud provider</category>
      <category domain="http://securityratty.com/tag/outsource security responsibility">outsource security responsibility</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/275708788/">5 Reasons Why IT Security People Shouldnt Ignore Cloud Computing</source>
    </item>
  </channel>
</rss>
