<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: photo]]></title>
    <link>http://securityratty.com/tag/photo</link>
    <description></description>
    <pubDate>Fri, 05 Sep 2008 15:40:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links List 9.29.08]]></title>
      <link>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</link>
      <guid>http://securityratty.com/article/48fee769715c390d500bbc1e0ea43623</guid>
      <description><![CDATA[Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/oracle.jpg" border="0" alt="oracle" width="240" height="164" align="left" /> Trade shows, trade shows and more trade shows. VMworld and Interop dominated the stage a couple of weeks ago and then there was the annual Oracle blowout in SF last week. Has anyone gotten any work done lately?? <em>(</em><a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank"><em>image from cdye1</em></a><em>)</em></p>
<p>Does <a href="http://sfcitizen.com/blog/2008/09/24/its-oracles-world-were-just-living-in-it/" target="_blank">Oracle run the world</a>? I would have to say no but Raj (Larry Ellison is his idol) and the 40,000 Oracle customers that descended upon SF last week might beg to differ. What do James Carville and Mary Matalin have to do with enterprise software? Pretty much nothing, except for the fact that they delivered the opening keynote for <a href="http://www.oracle.com/openworld/2008/index.html" target="_blank">Oracle OpenWorld</a>. (And that’s the only and last politically-oriented thing you’ll hear from me as we run up to the election). For a surprisingly funny and extensive photo gallery of the eye-popping event, check out <a href="http://flickr.com/photos/cdye/sets/72157607458101608/" target="_blank">cdye1’s photostream</a> on Flickr.</p>
<p>But UB40, Elvis Costello and Seal aside, Oracle OpenWorld did offer training, certifications, and always entertaining speeches by Ellison. Ben Worthen’s favorite – “<a href="http://blogs.wsj.com/biztech/2008/09/25/larry-ellisons-brilliant-anti-cloud-computing-rant/?mod=djemTECH" target="_blank">Larry Ellison’s Brilliant Anti-Cloud Computing Rant</a>” delivered to analysts on Thursday. From Ben’s slightly-edited excerpt:</p>
<p>“The interesting thing about cloud computing is that we’ve redefined cloud computing to include everything that we already do. I can’t think of anything that isn’t cloud computing with all of these announcements. The computer industry is the only industry that is more fashion-driven than women’s fashion. Maybe I’m an idiot, but I have no idea what anyone is talking about. What is it? It’s complete gibberish. It’s insane. When is this idiocy going to stop?</p>
<p>“We’ll make cloud computing announcements. I’m not going to fight this thing. But I don’t understand what we would do differently in the light of cloud computing other than change the wording of some of our ads. That’s my view.”</p>
<p>So did everyone catch that? Cloud computing is complete gibberish and idiocy, but apparently Oracle’s already been doing enough around it to advertise the fact. I will have my cake and eat it too!</p>
<p>We’ve been pumping out the posts from the shows we went to – let me tell you, live-blogging is hard when you’re trying to share apparently miniscule amounts of bandwidth with 14,000 other attendees – and we have even more to share as we step back, contemplate and describe how some of the announcements, info and especially roadmaps fit into our overall picture over here at ScienceLogic.</p>
<p>For example, we released the results of our annual industry IT survey last week. Twice a year – at FOSE (for Government IT) and at Interop NY (for enterprises) – we take advantage of the fact that we have a big beautiful booth at these shows and offer a fabulous ScienceLogic t-shirt in return for a couple of minutes time with attendees living the <a href="http://blog.sciencelogic.com/why-we-l-o-v-e-tradeshows/03/2008" target="_blank">problems we try to solve</a>. Instead of telling people what their problems and priorities are, we like to ask.<br />
<a href="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008?" target="_blank">Interop NY Survey - Trends and Challenges</a><br />
<a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">Detailed Reports on Trends and Comparison to Government IT</a></p>
<p>And I just had to share this one because it is so bizarre. Are VMware and Paul Maritz guilty of <a href="http://it20.info/blogs/main/archive/2008/09/21/143.aspx" target="_blank">plagiarism</a>? You have to check this out to get even part of the picture. Apparently this guy has posted his slides (we know they are from VMworld 2007 because it says so in the lower-right-hand corner…) which prove that the “virtual datacenter operating system” idea was his idea a year before it showed up on Maritz’s keynote this year. Hmmm. And then after posting all these slides and making all the connections between his presentation and Maritz’s, he says he’s just kidding about the plagiarism. Can anyone sort this out and let me know?</p>
<p>I’ll tell you who wasn’t kidding when I went by their booth at VMworld – a certain chargeback vendor and VMware “partner” who was quite shocked two months ago when they walked into a meeting with VMware about future roadmap. Apparently, the slides they saw (preview of VMware’s announcement re adding extended chargeback capability within vCenter management services) were mighty might similar to slides they had given in a presentation to VMware about their own roadmap. Coincidence? I’ll let you decide. And I’ll also say, their strategy to combat this – support for Hyper-V coming early in 2009.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oracle openworld">oracle openworld</category>
      <category domain="http://securityratty.com/tag/oracle">oracle</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/annual oracle blowout">annual oracle blowout</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware partner">vmware partner</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/annual industry">annual industry</category>
      <category domain="http://securityratty.com/tag/apparently oracles">apparently oracles</category>
      <source url="http://blog.sciencelogic.com/links-list-92908/09/2008">Links List 9.29.08</source>
    </item>
    <item>
      <title><![CDATA[Show 030 - An Interview with Ken van Wyk]]></title>
      <link>http://securityratty.com/article/0b1369b7e3490f60e22d2ae7d871f6c7</link>
      <guid>http://securityratty.com/article/0b1369b7e3490f60e22d2ae7d871f6c7</guid>
      <description><![CDATA[On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates. Ken was the first employee of CERT and has been an active member of...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Ken van Wyk" title="Ken van Wyk" src="http://www.cigital.com/silverbullet/kvanwyk-125.png" style="padding-left: 7px;" /></p>
<p>On the 30th episode of The Silver Bullet Security Podcast, Gary talks with Ken van Wyk, principal and founder of KRvW Associates.  Ken was the first employee of CERT and has been an active member of FIRST.  Ken and Gary discuss why the discipline of computer science doesn&#8217;t learn from failure like mechanical engineering does, how we&#8217;re making steps backwards in computer security, whether focusing on web applications is a good or bad thing for software security, and Ken&#8217;s recommendation for moderately-priced red wines.</p>
<ul>
<li><a href="http://www.vanwyk.org/ken/">Ken&#8217;s personal page</a></li>
<li><a href="http://www.krvw.com/">KRvW Associates</a></li>
<li><a href="http://www.cert.org/">CERT</a></li>
<li><a href="http://www.first.org/">FIRST</a></li>
<li><a href="http://www.securecoding.org/"><em>Secure Coding</em></a></li>
<li><a href="http://oreilly.com/catalog/9780596001308/"><em>Incident Response</em></a></li>
<li><a href="http://www.securecoding.org/list/">SC-L mailing list</a></li>
<li><a href="http://www.cigital.com/justiceleague/2007/07/06/from-the-foreword-to-secure-programming-with-static-analysis/">From the foreword to Secure Programming with Static Analysis</a> - blog entry with photo of Tacoma Narrows Bridge</li>
<li><a href="http://finance.google.com/finance?chdnp=1&#038;chdd=1&#038;chds=1&#038;chdv=1&#038;chvs=maximized&#038;chdeh=0&#038;chdet=1222200000000&#038;chddm=166345&#038;q=NYSE:TJX&#038;ntsp=0">TJX&#8217;s stock increase since the January 2007 security breach</a></li>
<li><a href="http://www.buildsecurityin.com/">The Addison-Wesley Software Security Series</a></li>
<li><a href="http://www.google.com/search?hl=en&#038;client=opera&#038;rls=en&#038;hs=fdc&#038;sa=X&#038;oi=spell&#038;resnum=0&#038;ct=result&#038;cd=1&#038;q=barbara+d%27asti&#038;spell=1">Barbara D&#8217;Asti wines</a></li>
</ul>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 17:23:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/van wyk">van wyk</category>
      <category domain="http://securityratty.com/tag/tjxs stock increase">tjxs stock increase</category>
      <category domain="http://securityratty.com/tag/barbara dasti wines">barbara dasti wines</category>
      <category domain="http://securityratty.com/tag/tacoma narrows bridge">tacoma narrows bridge</category>
      <category domain="http://securityratty.com/tag/kens personal page">kens personal page</category>
      <category domain="http://securityratty.com/tag/red wines">red wines</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/gary talks">gary talks</category>
      <source url="http://www.cigital.com/silverbullet/show-030/">Show 030 - An Interview with Ken van Wyk</source>
    </item>
    <item>
      <title><![CDATA[Enhanced Domain Protection Services Emerge]]></title>
      <link>http://securityratty.com/article/7acf5055cb56782b95c8c264468b8373</link>
      <guid>http://securityratty.com/article/7acf5055cb56782b95c8c264468b8373</guid>
      <description><![CDATA[Registrars are beginning to offer new services to protect against domain name loss. Are they worth it? Well, they're worth something, but maybe not all the money being charged. Yesterday, Domain Name...]]></description>
      <content:encoded><![CDATA[Registrars are beginning to offer new services to protect against domain name loss. Are they worth it? Well, they're worth something, but maybe not all the money being charged.

Yesterday, Domain Name Wire revealed that <a href="http://domainnamewire.com/2008/09/23/godaddy-files-patent-for-domain-name-hijack-protection/">GoDaddy has filed for a patent for "Domain Name Hijack Protection."</a> The basic idea of the service is that domain name transfer-out requests are automatically ignored. The customer gets a notice that the request was received and ignored. The user then has the option of turning off the service, and must supply photo ID in order to do it. Comments on the Domain Name Wire article say it's an intentionally cumbersome process, which certainly works out well for GoDaddy, but I'm not so sure I'd call this innovative.

This application may be related to <a href="https://www.godaddy.com/gdshop/protect/landing.asp?ci=9004">GoDaddy's Protected Registration service</a>, which similarly protects against casual transfers, a service they call Deadbolt Transfer Protection. In order to perform a transfer, more thorough verification procedures are required, probably involving genuine human beings.

GoDaddy also claims to protect the domain in case of billing problems, such as "credit card expiration, failed billing or outdated contact information." If your domain expires and cannot be renewed because the credit card expired or some other such reason the domain will be placed in "invalid, protected status" for up to one year. In other words, it will be taken off-line, but not made available for anyone else to register. If you've parked it you may not notice, but if you're using the domain you will, because it won't work anymore. At this point you can go back to GoDaddy and make things right. All this costs $24.99 a year, which is a lot of money compared to the base registration. You'd be much better off with a standard domain lock and just being responsible about your domains and reading the e-mail GoDaddy sends you.

And thanks to <a href="http://www.domainnamenews.com/registrars/moniker-launches-domainmaxlock/2452">DomainNameNews for reporting</a> that Moniker, a registrar aimed at higher-volume domain name owners, has launched <a href="http://www.moniker.com/maxlock/">their DomainMaxLock service</a>.

DomainMaxLock, like GoDaddy's Deadbolt, makes you provide more stringent identification for transfers. According to the company you must:
<UL>
<LI>Provide a government I.D. number for verification of your identity.
<LI>Set up custom security questions and answers, further safeguarding your domain assets.
<LI>Provide special verification instructions and artifacts to ensure that your unique business or ownership interests are protected.
<LI>When you request that your domains be unlocked, our security team works directly with you to verify all of the above off-line - further eliminating risks of doing business in an online world! </LI>
</UL>
It's essentially an admission of the failure of automated services with respect to security. The idea is we can trust humans in person, not software. The service costs $34.95 per domain per year for a limited time, but the cost will increase later to $59.99.

These verification services are similar in many ways to those performed by CAs (certificate authorities). Since GoDaddy is also one of those, it's likely they can get better utilization out of that staff by offering such services.
<p><a href="http://feedads.googleadservices.com/~a/FCZhqYUdUonhGhpMKWK6obfrCas/a"><img src="http://feedads.googleadservices.com/~a/FCZhqYUdUonhGhpMKWK6obfrCas/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/8Vacprz_ezY" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 04:23:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/domain">domain</category>
      <category domain="http://securityratty.com/tag/standard domain lock">standard domain lock</category>
      <category domain="http://securityratty.com/tag/higher-volume domain">higher-volume domain</category>
      <category domain="http://securityratty.com/tag/domain assets">domain assets</category>
      <category domain="http://securityratty.com/tag/domain expires">domain expires</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/domainmaxlock service">domainmaxlock service</category>
      <category domain="http://securityratty.com/tag/godaddy">godaddy</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/8Vacprz_ezY/enhanced_domain_protection_services_emerge.html">Enhanced Domain Protection Services Emerge</source>
    </item>
    <item>
      <title><![CDATA[Eye-Fi Adds Upgrade Track at Yearly Fee]]></title>
      <link>http://securityratty.com/article/3e1647519eaf22ed342316fc64fccf49</link>
      <guid>http://securityratty.com/article/3e1647519eaf22ed342316fc64fccf49</guid>
      <description><![CDATA[The Wi-Fi sharing digital memory card Eye-Fi adds another option for its product line: If you've purchased or plan to purchase an Eye-Fi, starting 5-Oct-2008, you can upgrade the model of card you...]]></description>
      <content:encoded><![CDATA[<p><strong><a href="http://www.eye.fi/news/press-releases/">The Wi-Fi sharing digital memory card Eye-Fi adds another option for its product line:</a></strong> If you've purchased or plan to purchase an Eye-Fi, starting 5-Oct-2008, you can upgrade the model of card you purchased by paying a yearly subscription fee. This provides more of a try-and-see mode for Eye-Fi's slightly more expensive offerings.</p>

<p>Eye-Fi divided its Wi-Fi SD card line-up into three parts earlier in the year: Home, which transfers to a computer ($80); Share, which uploads to a computer and to Eye-Fi's servers, which relay them to gallery, print, and social services ($100); and Explore, which ties in Wi-Fi positioning and one year of a Wayport hotspot subscription for uploads ($130). I wrote <strong><a href="http://wifinetnews.com/archives/008418.html">a long review of the Eye-Fi Explore</a></strong> on 12-Aug-2008.</p>

<p><img src="http://wifinetnews.com//images/2008/eye-fi_cards_sharer_sm.jpg" align="right"/>If you bought a Home, you can upgrade to the Share service for $10 per year, and if you bought either a Home or Share, you can add geotagging for $15 per year and hotspot access for $15 per year. It's a smart move, since original Eye-Fi card buyers already had a firmware upgrade that converted their card into a Share model; they'll now be able upgrade to the full featureset. This is something I thought the company was offering at launch months ago, and I speculated it would be easy to add.</p>

<p>Eye-Fi also added two new photo sharing services: Apple's MobileMe and AdoramaPix. I cannot think of any other firm that Apple has partnered with to allow direct MobileMe uploads, although this may be technically less a big deal than it sounds. But I believe it's unique--only the iPhone and iPhoto software can transfers images into MobileMe's galleries; I'll need to investigate further. It's a good feather in Eye-Fi's cap.</p>

<p>Finally, Eye-Fi says they'll release tweaked firmware on 5-Oct as well that will double the speed of photo transfers from their cards to a computer on the local network.</p>]]></content:encoded>
      <pubDate>Mon, 22 Sep 2008 18:07:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eye-fi">eye-fi</category>
      <category domain="http://securityratty.com/tag/upgrade">upgrade</category>
      <category domain="http://securityratty.com/tag/eye-fi explore">eye-fi explore</category>
      <category domain="http://securityratty.com/tag/explore">explore</category>
      <category domain="http://securityratty.com/tag/direct mobileme uploads">direct mobileme uploads</category>
      <category domain="http://securityratty.com/tag/share service">share service</category>
      <category domain="http://securityratty.com/tag/mobileme">mobileme</category>
      <category domain="http://securityratty.com/tag/share">share</category>
      <category domain="http://securityratty.com/tag/transfers">transfers</category>
      <source url="http://wifinetnews.com/archives/008453.html">Eye-Fi Adds Upgrade Track at Yearly Fee</source>
    </item>
    <item>
      <title><![CDATA[VMworld 2008 Keynote with Paul Maritz]]></title>
      <link>http://securityratty.com/article/27088f9fffd4d9e8619b6768dd0513fa</link>
      <guid>http://securityratty.com/article/27088f9fffd4d9e8619b6768dd0513fa</guid>
      <description><![CDATA[Traveling towards VMworld 2008
I, along with thousands of others, wended my way through a vast dimly lit cavern of a place helped along by the strangely surreal sight of ushers in black waving wispy...]]></description>
      <content:encoded><![CDATA[<p><em><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; margin: 5px; border-right-width: 0px" height="160" alt="paulmaritzvmware" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/paulmaritzvmware.jpg" width="240" align="left" border="0" /> Traveling towards VMworld 2008</em></p>
<p>I, along with thousands of others, wended my way through a vast dimly lit cavern of a place helped along by the strangely surreal sight of ushers in black waving wispy red flags to guide us not to the empty seats in front of us, but to the ones 50 yards on. (Ah Vegas, my feet hurt already.) Perhaps the point was to live in the moment, soak in the pre-rock concert atmosphere complete with a hip and cool soundtrack ripped off from Apple commercials. (Do they all use the same ad firm?) A better way to build the anticipation for, yes, the kickoff keynote session at <a href="http://www.vmworld.com/conferences/2008/" target="_blank">VMworld 2008</a>. (<em><a href="http://www.flickr.com/photos/jumpingshark/2862470725/" target="_blank">photo credit: lodev</a>)</em></p>
<p>To the sounds of <a href="http://www.youtube.com/watch?v=PEinqCHPY08" target="_blank">Hey Ya</a> (Shake it like a Polaroid picture), we shifted forward in our uncomfortable temporary seating placed, as at all tech conferences, too close for all but the skinny girls. The moment was here &#8211; one of those videos started playing on the dozen or so huge monitors floating above the convention crowd. You know this video; you&#8217;ve probably seen it before from HP or someone like that. One of those videos with instrumental Coldplay music in the background with time <a href="http://www.hp.com/hpinfo/newsroom/hpads/" target="_blank">lapse/speeded-up video</a> of people in motion and floating captions dropping into the images that leave you with a slight smile on your face as you &#8220;get&#8221; the relationship between image and text. (Do they all use the same ad firm?)</p>
<p>And here he is, announced like a Vegas headliner, <a href="http://vmblog.com/archive/2008/07/23/forbes-interviews-vmware-ceo-paul-maritz-after-financial-analyst-call.aspx" target="_blank">Paul Maritz, the new CEO of VMware</a>. Hmm. After all that hype, I rather expected someone in a black turtleneck and jeans to come out. Instead here&#8217;s this guy with pleat-front pants and an admittedly cool accent (New Zealand?) who looks a little like Al from Home Improvement. Not that there&#8217;s anything wrong with that &#8211; everyone likes Al.</p>
<p><em>And then the real fun begins.</em></p>
<ul>
<li>30 years ago, Paul Maritz started off his business career as a developer </li>
<li>10 years ago, VMware was founded by <a href="http://blog.sciencelogic.com/diane-greene-ousted-from-vmware/07/2008" target="_blank">Diane</a> <a href="http://virtualization.com/news/2008/07/08/diane-greene-vmware-paul-maritz/" target="_blank">Greene</a> and <a href="http://www.cio-weblog.com/50226711/found_rosenblum_leaves_vmware.php" target="_blank">Mendel</a> <a href="http://blog.sciencelogic.com/another-vmware-founder-leaves/09/2008" target="_blank">Rosenblum</a> (BTW, 10 seconds spent showing a slide with cartoon-ized images of the founders, &#8220;thanks for what you did for the company for the past 10 years&#8221;. 10 seconds after 10 years&#8230;but maybe more would have been hypocritical&#8230;) </li>
<li>a retrospective of centralized vs. decentralized computing initiatives from the 1960&#8217;s to today </li>
<li>of course VMware milestones from 1998 to today </li>
<li>and then an analyst-ready diagram showing the product roadmap (to be delivered in 2009) with, you guessed it, finally a connection between <a href="http://advice.cio.com/laurianne_mclaughlin/vmworld_ceo_maritz_outlines_broad_plans_for_cloud_and_client" target="_blank">VMware and cloud computing</a> (remember Maritz&#8217;s cloud-computing company was bought by EMC just a couple of years ago and that&#8217;s the section he headed up at EMC before being brought into VMware). </li>
</ul>
<p><em>Forward Looking</em></p>
<p>2008 (and probably much of 2009) will be a very busy year for VMware. If you believe the roadmap, <a href="http://www.uberpulse.com/us/2008/09/vmwares_ambitious_expansion_plan.php" target="_blank">VMware seems to be taking on the management of everything</a> &#8211; from chargeback and capacity planning to virtual storage and virtual networking (more to come on just what the planned vStorage and vNetwork will deliver) &#8211; but all of it VMware-centric. As <a href="http://blog.sciencelogic.com/vmware-is-better-than-microsoft/09/2008" target="_blank">we said in an earlier post,</a> they&#8217;ve moved away from &#8220;defending&#8221; the hypervisor business proposition to focusing on management services on top of their own hypervisor platform. Revenue pressures must be excruciating &#8211; who wants to be a public company these days?</p>
<p>The best part of that new &#8220;Virtual Data Center Operating System&#8221; <a href="http://www.vmware.com/technology/virtual-datacenter-os/" target="_blank">diagram/roadmap</a> was the addition (and I mean addition) of something called <a href="http://vmetc.com/2008/09/16/vmwares-vcloud-iniatives-the-vision-for-the-next-10-years/" target="_blank">Cloud vServices</a>. (Did anyone else find it odd that <a href="http://virtualization.com/news/2008/09/15/vcloud-vmware-to-be-cloud-computing-provider-too-but-inside-your-private-dc-and-not-tomorrow/" target="_blank">Cloud vServices</a> is kind of on its own in the Infrastructure vServices area? AND, I&#8217;ll have to get the other version of the diagram/roadmap I actually saw at the show because that one shows an inexplicable 4<sup>th</sup> box in the Application vServices area titled &#8220;&#8230;&#8221;. Really. Maybe to balance out the addition of <a href="http://www.itpro.co.uk/606237/vmwares-paul-maritz-goes-on-offence" target="_blank">Cloud vServices?</a>)</p>
<p>What was clear is that the move from VirtualCenter to vCenter &#8211;and the new vServices for rolled-up management of <a href="http://www.virtualization.info/2008/09/live-from-vmworld-2008-day-2-vmware.html" target="_blank">virtualization components</a>/capability to span multiple <a href="http://blogs.zdnet.com/virtualization/?p=542" target="_blank">VirtualCenters</a> (or future vCenters) for reporting, monitoring and management at scale &#8211; has been in the works for a bit (but in tech time, that could mean 6 months), but the cloud stuff&#8230;not so much.</p>
<p>Beyond the very high-level speak appropriate to a keynote (100+ service provider partners for off-premise cloud&#8230;suspended VM&#8217;s that you don&#8217;t have to pay for until you need it), the details are uber-fuzzy. There was a session that Dave went to which was supposed to shed more light, but when questions were asked about how it really works, the answers seemed to be TBD. Does anyone know more? If VMware really has figured out practical cloud computing for enterprises, kudos to them. But I fear they&#8217;re <a href="http://news.cnet.com/8301-13505_3-10042463-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">like everyone else</a> (except maybe AT&amp;T) and are still working out the details.</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 15:00:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vservices">vservices</category>
      <category domain="http://securityratty.com/tag/infrastructure vservices">infrastructure vservices</category>
      <category domain="http://securityratty.com/tag/cloud vservices">cloud vservices</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/vmware milestones">vmware milestones</category>
      <category domain="http://securityratty.com/tag/keynote">keynote</category>
      <category domain="http://securityratty.com/tag/vmware-centric">vmware-centric</category>
      <category domain="http://securityratty.com/tag/paul maritz">paul maritz</category>
      <source url="http://blog.sciencelogic.com/vmworld-2008-keynote-with-paul-maritz/09/2008">VMworld 2008 Keynote with Paul Maritz</source>
    </item>
    <item>
      <title><![CDATA[Identity Farming]]></title>
      <link>http://securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</link>
      <guid>http://securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up. </p>

<p>Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities. </p>

<p>Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them. </p>

<p>There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop. </p>

<p>You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work. </p>

<p>Here's the real question: Do you actually have to show up for any part of your life? </p>

<p>Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China. </p>

<p>Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. Iâm told this is a common idea in Highlander fan fiction. </p>

<p>The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.schneier.com/essay-219.html">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.) </p>

<p>It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary. </p>

<p>Our data shadows can live a perfectly normal life without us.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/09/securitymatters_0904">previously appeared<a> on Wired.com.</p>

<p>EDITED TO ADD (9/9): Interesting <a href="http://www.examiner.com/x-536-Civil-Liberties-Examiner~y2008m9d4-Im-not-myself-today-or-manufacturing-a-new-you">commentary</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YzkGL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YzkGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JDMVL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JDMVL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 01:42:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://securityratty.com/tag/shadows">shadows</category>
      <category domain="http://securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://securityratty.com/tag/photo ids glue">photo ids glue</category>
      <category domain="http://securityratty.com/tag/photo ids">photo ids</category>
      <category domain="http://securityratty.com/tag/identity databases">identity databases</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/identity_farmin.html">Identity Farming</source>
    </item>
    <item>
      <title><![CDATA[Google claims license to user content in multiple products]]></title>
      <link>http://securityratty.com/article/8d3a5f308e7cfd25b73403fe8a9e259a</link>
      <guid>http://securityratty.com/article/8d3a5f308e7cfd25b73403fe8a9e259a</guid>
      <description><![CDATA[Google last week removed some language in its Chrome browser's terms of service that gave the company a license to any material displayed in the browser, but that language remains in several other...]]></description>
      <content:encoded><![CDATA[Google last week removed some language in its Chrome browser's terms of service that gave the company a license to any material displayed in the browser, but that language remains in several other Google products, including its Picasa photo service and its Blogger service.]]></content:encoded>
      <pubDate>Sun, 07 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/blogger service">blogger service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/picasa photo service">picasa photo service</category>
      <category domain="http://securityratty.com/tag/language">language</category>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/google products">google products</category>
      <category domain="http://securityratty.com/tag/language remains">language remains</category>
      <category domain="http://securityratty.com/tag/chrome browser">chrome browser</category>
      <source url="http://www.networkworld.com/news/2008/090808-google-claims-license-to-user.html?fsrc=rss-security">Google claims license to user content in multiple products</source>
    </item>
    <item>
      <title><![CDATA[Cisco 7600 OSR Backbone Router]]></title>
      <link>http://securityratty.com/article/a447dc34e61d2770ab6d723a54abcb31</link>
      <guid>http://securityratty.com/article/a447dc34e61d2770ab6d723a54abcb31</guid>
      <description><![CDATA[For our confused CEO blogger over at StreamBase, who thinks an Internetbackbone router is the small $30 device he set up in his home office, here is a photo of a the Cisco 7600 OSR which of course...]]></description>
      <content:encoded><![CDATA[<p style="text-align: left;">For our confused CEO blogger over at StreamBase, who thinks an Internet backbone router is the small $30 device he set up in his home office, here is a photo of a the <a href="http://newsroom.cisco.com/dlls/prod_022001b.html" target="_blank">Cisco 7600 OSR</a> which of course runs <a href="http://www.cisco.com/en/US/products/sw/iosswrel/products_ios_cisco_ios_software_category_home.html" target="_blank">CISCO IOS</a>.</p>
<p style="text-align: center;"><img style="vertical-align: middle;" src="http://newsroom.cisco.com/ts_images/Cisco-7600-OSR-high.jpg" alt="Cisco 7600 OSR" height="600" /></p>
<p style="text-align: left;">The Cisco 7600 OSR consists of a 256 Gbps switching fabric and a 30 million packets per second (mpps) forwarding engine. Its breadth of IP services comes from Cisco IOS, which provides features such as security, enhanced QoS, and destination sensitive services. In addition, the Cisco 7600 OSR allows the migration of existing port adapters from Cisco 7500 series routers, via the Cisco FlexWAN module, giving service providers one the industry&#8217;s widest array of interface options in any single platform. This provides service providers great flexibility in deploying the Cisco 7600 OSR for a variety of applications, protects their investment in existing systems, and gives them a practical migration path to the New World Optical Internet.</p>
<h3>A Revolutionary Platform For Evolving Networks</h3>
<p>The Cisco 7600 OSR helps service providers break through service and bandwidth barriers today, while designing networks to scale for future growth. The Cisco 7600 OSR achieves this through &#8220;adaptive network processing,&#8221; or the ability to evolve the platform for new IP services without hardware upgrades. Unlike fixed, ASIC-based platforms, which are hardware encoded, the Cisco 7600 OSR relies on the highly flexible Parallel eXpress Forwarding (PXF) technology for scalable performance of services. PXF is a patented, Cisco-developed network processor capable of line-rate IP services delivery that can support new IP services through periodic software upgrades. Each OSM has two PXF processors capable of 12 mpps of IP services delivery per interface card.</p>
<p>&#8220;IP+Optical combines the dynamism of the Internet world with the foundation of the transport world, creating an infrastructure that can deliver the services that service providers need,&#8221; said Lele Nardin, vice president of the Internet Systems Business Unit at Cisco. &#8220;Cisco will continue to add innovative solutions on top of this solid foundation to make service providers better equipped to meet the constantly escalating and changing customer demands for new networking services.&#8221;</p>
<h3>Pricing and Availability</h3>
<p>The base Cisco 7600 OSR system is list priced at $73,000 and the entry level system, with interfaces, start at $100,000. The interfaces modules are priced between $27,000 to $180,000. The Cisco 7600 OSR is available now worldwide.</p>
]]></content:encoded>
      <pubDate>Sat, 06 Sep 2008 07:25:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/cisco flexwan module">cisco flexwan module</category>
      <category domain="http://securityratty.com/tag/osr">osr</category>
      <category domain="http://securityratty.com/tag/runs cisco ios">runs cisco ios</category>
      <category domain="http://securityratty.com/tag/base cisco">base cisco</category>
      <category domain="http://securityratty.com/tag/cisco ios">cisco ios</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/destination sensitive services">destination sensitive services</category>
      <category domain="http://securityratty.com/tag/osr system">osr system</category>
      <source url="http://www.thecepblog.com/2008/09/06/cisco-7600-osr-backbone-router/">Cisco 7600 OSR Backbone Router</source>
    </item>
    <item>
      <title><![CDATA[Malicious Facebook Application Might Create A Powerful DoS Botnet]]></title>
      <link>http://securityratty.com/article/db2628ce5e69786106d7a030b0820055</link>
      <guid>http://securityratty.com/article/db2628ce5e69786106d7a030b0820055</guid>
      <description><![CDATA[Researchers at the Institute of Computer Science (ICS) have built a malicious Facebook application as an experiment to demonstrate the possible dangers of social networking applications. The...]]></description>
      <content:encoded><![CDATA[Researchers at the Institute of Computer Science (ICS) have built a malicious Facebook application as an experiment to demonstrate the possible dangers of social networking applications. The proof-of-concept Facebook application can covertly herd users of the popular social network into a powerful botnet that might be malicious.
The demo application, called Photo of the Day, delivers [...]]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 23:26:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious facebook application">malicious facebook application</category>
      <category domain="http://securityratty.com/tag/facebook application">facebook application</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/popular social network">popular social network</category>
      <category domain="http://securityratty.com/tag/covertly herd users">covertly herd users</category>
      <category domain="http://securityratty.com/tag/powerful botnet">powerful botnet</category>
      <category domain="http://securityratty.com/tag/computer science">computer science</category>
      <category domain="http://securityratty.com/tag/demo application">demo application</category>
      <source url="http://cyberinsecure.com/malicious-facebook-application-might-create-a-powerful-dos-botnet/">Malicious Facebook Application Might Create A Powerful DoS Botnet</source>
    </item>
    <item>
      <title><![CDATA[Researchers Use Facebook App to Create Zombie Army]]></title>
      <link>http://securityratty.com/article/798bedf8348492e0aef129ad7d4e6c9f</link>
      <guid>http://securityratty.com/article/798bedf8348492e0aef129ad7d4e6c9f</guid>
      <description><![CDATA[Facebook users who choose to install the wrong third party application could find themselves inducted into a robot computer army controlled by a hacker. At least, that's what a team of Greek computer...]]></description>
      <content:encoded><![CDATA[Facebook users who choose to install the wrong third party application could find themselves inducted into a robot computer army controlled by a hacker. At least, that's what a team of Greek computer researchers proved with their rogue Photo of the Day application.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=d96ef0eaa374f413ab2871474815c4b3" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=d96ef0eaa374f413ab2871474815c4b3" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=08kpL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=08kpL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=doKPl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=doKPl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=2Cawl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=2Cawl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=MzruL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=MzruL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=NYCRL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=NYCRL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=SF5Fl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=SF5Fl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=0asul"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0asul" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=EoS1L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=EoS1L" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/384545347" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/384545349" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 15:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/greek computer researchers">greek computer researchers</category>
      <category domain="http://securityratty.com/tag/robot computer army">robot computer army</category>
      <category domain="http://securityratty.com/tag/day application">day application</category>
      <category domain="http://securityratty.com/tag/party application">party application</category>
      <category domain="http://securityratty.com/tag/rogue photo">rogue photo</category>
      <category domain="http://securityratty.com/tag/facebook users">facebook users</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/choose">choose</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/384545349/researchers-use.html">Researchers Use Facebook App to Create Zombie Army</source>
    </item>
  </channel>
</rss>
