<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: plenty]]></title>
    <link>http://securityratty.com/tag/plenty</link>
    <description></description>
    <pubDate>Thu, 11 Sep 2008 15:29:05 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Microsoft Begins the MS08-067 Post-Mortem]]></title>
      <link>http://securityratty.com/article/8b1a636e03c8882d65a7f324bcded81f</link>
      <guid>http://securityratty.com/article/8b1a636e03c8882d65a7f324bcded81f</guid>
      <description><![CDATA[It's finger-pointing time. Who let the infamous MS08-067 RPC bug through? Did the vaunted Microsoft Security Development Lifecycle fail? Did people approve the code when they shouldn't have? Microsoft...]]></description>
      <content:encoded><![CDATA[It's finger-pointing time.

Who let the infamous MS08-067 RPC bug through? Did the vaunted Microsoft Security Development Lifecycle fail? Did people approve the code when they shouldn't have?

<a href="http://www.webbuyersguide.com/company/66/Microsoft&kc=eweekarticle110308&src=eweekarticle110308">Microsoft</a> has already begun examining these questions in <a href="http://blogs.msdn.com/sdl/archive/2008/10/22/ms08-067.aspx" target="_blank">an entry on the SDL blog.</a> The problem, the blog seems to conclude, is the complexity of the code. It's just really hard to find bugs of this nature. To have found it would have been lucky. Michael Howard, the SDL guru and blogger, isn't really pointing fingers, although commenters on the blog are.

It's a prime example of what I wrote about not long ago when I said <a href="http://www.eweek.com/c/a/Security/Still-Overflowing-After-All-These-Years/">buffer overflows would never go away.</a> The examples we all see of what overflows are and how to stop them are fairly simple things: Allocate a buffer of size b, read 2*b bytes into it. In this case, there were two problems making the problem significantly more complex: The overflow happens inside a loop, during which pointer arithmetic is done. This alone makes it harder to identify for humans to identify the bug and perhaps impossible for tools to identify it without incurring a large incidence of false positives. Stack-checking also failed in this instance.

Howard called the code in question "reasonably complex" and said at a later date he would publish source code from the function. He said Microsoft's automated tools wouldn't find this bug in this type of code. Some comments on the blog asked him whether this complexity is, in and of itself, a problem. Perhaps manual code reviews should have rejected it. Howard didn't go this far, but I sense, in between the lines, that maybe he feels the same.

As a programmer I've seen this sort of code plenty of times and written it myself. The code may have seemed particularly efficient or just plain cool to the programmer, but complex loops with pointer arithmetic sound inherently like asking for trouble. I've written before that Microsoft has a long-term way of writing for the next generation of hardware, and CPU processing power is becoming absurdly cheap. Perhaps an implementation that is slower than necessary, but clear in its operation, is the better choice. Then leave the optimizing to compilers. It's actually an old argument.

Another thing Howard remarks on is the failure of Microsoft's fuzzing tools in this instance. All he says is they didn't find it and they'll work on that, and they are always working on their fuzzing tools. Fuzzing is cool and this episode shows how there's always more work to do in it. <a href="http://blogs.securiteam.com/index.php/archives/1151" target="_blank">Aviram on the SecuriTeam blog relates </a>how over two years ago famous researcher Dave Aitel said his fuzzer found no more bugs in the MS RPC code, so there must not be any. This was probably tongue-in-cheek, but even so, Aitel's probably biting his tongue now.

Even though many levels of tools and procedures put in place to prevent such vulnerabilities failed to do so, it would be a mistake to say the system failed altogether. This vulnerability, just about the worst class of bug we ever get, comes with significant mitigating factors, and is probably, as a practical matter, not exploitable on Windows Vista and Server 2008. Not everything failed.
<p><a href="http://feedads.googleadservices.com/~a/TOAsgjkEp3a_sBJoijuoWeC3U0s/a"><img src="http://feedads.googleadservices.com/~a/TOAsgjkEp3a_sBJoijuoWeC3U0s/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/yYUo7KKMw0Q" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 10:41:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/code plenty">code plenty</category>
      <category domain="http://securityratty.com/tag/publish source code">publish source code</category>
      <category domain="http://securityratty.com/tag/manual code reviews">manual code reviews</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/rpc code">rpc code</category>
      <category domain="http://securityratty.com/tag/securiteam blog">securiteam blog</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/howard remarks">howard remarks</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/yYUo7KKMw0Q/microsoft_begins_the_ms08-067_post-mortem.html">Microsoft Begins the MS08-067 Post-Mortem</source>
    </item>
    <item>
      <title><![CDATA[Microsoft, Oracle get busy plugging security holes]]></title>
      <link>http://securityratty.com/article/4a465a4c5758e2e39589308aa2cb8e39</link>
      <guid>http://securityratty.com/article/4a465a4c5758e2e39589308aa2cb8e39</guid>
      <description><![CDATA[Microsoft and Oracle both gave IT managers plenty of software patches to apply -- 11 in Microsoft's monthly batch of fixes, and 36 in Oracle's quarterly set of...]]></description>
      <content:encoded><![CDATA[Microsoft and Oracle both gave IT managers plenty of software patches to apply -- 11 in Microsoft's monthly batch of fixes, and 36 in Oracle's quarterly set of updates.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0e41cd7abbfd56bb456043b22c083731:%2B1IZ7AktsAP1ctzJaEsIeQ%2BKKE1C6frR8LnNATGS8%2FJNqXRLyHkrSi0KOEp%2BA0xnr5cmgrHrxKQQ'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7b30d61de554eb1a4d22ac2f2fff65b4:WwM8pATinvEH6dvh2Z%2F5v4C1g1p3Gb6xDqBJqeRtL4IHDZJOqbJLA%2Bek2Wqg4vpNbvIkWBp42iPD6g%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:83b74556852c047cc9b06b0d883bea3a:bzoHhFsJ3Q5vDM8dbyrYS3EQItsIsLNTCmo4VQwJ%2BuMj%2FA6xzmnTBXI8KJlU1GJsYt3zQPXO4KDEfw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9641a7bdd0709107dc924248bbde528f:QukjiG0ELoQnkw2kLRFBR%2FaSgSnoMkltAR2Lgsh3pKJHkCdrfqTXeTjkO8MLiPvi1%2BQImlX%2BD5U3VQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=673c19cb5e182409c16dae42db929a4f" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=673c19cb5e182409c16dae42db929a4f" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oracle">oracle</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/managers plenty">managers plenty</category>
      <category domain="http://securityratty.com/tag/quarterly set">quarterly set</category>
      <category domain="http://securityratty.com/tag/software patches">software patches</category>
      <category domain="http://securityratty.com/tag/monthly batch">monthly batch</category>
      <category domain="http://securityratty.com/tag/apply">apply</category>
      <category domain="http://securityratty.com/tag/fixes">fixes</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=673c19cb5e182409c16dae42db929a4f">Microsoft, Oracle get busy plugging security holes</source>
    </item>
    <item>
      <title><![CDATA[Google miffs admins, IT boosts Street]]></title>
      <link>http://securityratty.com/article/0711c044c77f310f395a891d5b431a56</link>
      <guid>http://securityratty.com/article/0711c044c77f310f395a891d5b431a56</guid>
      <description><![CDATA[Google annoyed administrators when it made changes to Google Apps &quot;Start&quot; portal pages without letting them know it was updating layout and functionality of those pages. Some administrators reported...]]></description>
      <content:encoded><![CDATA[Google annoyed administrators when it made changes to Google Apps "Start" portal pages without letting them know it was updating layout and functionality of those pages. Some administrators reported at a discussion forum that they were swamped with angry calls from end users who couldn't access Gmail accounts. On a slightly brighter note, Google reported solid quarterly earnings, as did IBM and Intel, but there's plenty of room for concern about the current quarter and coming quarters. Meanwhile, Mozilla continues work on its mobile browser, code-named Fennec, which was released in alpha this week for use on Nokia Internet tablets.]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google apps">google apps</category>
      <category domain="http://securityratty.com/tag/solid quarterly earnings">solid quarterly earnings</category>
      <category domain="http://securityratty.com/tag/portal pages">portal pages</category>
      <category domain="http://securityratty.com/tag/nokia internet tablets">nokia internet tablets</category>
      <category domain="http://securityratty.com/tag/access gmail accounts">access gmail accounts</category>
      <category domain="http://securityratty.com/tag/slightly brighter note">slightly brighter note</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <category domain="http://securityratty.com/tag/discussion forum">discussion forum</category>
      <source url="http://www.networkworld.com/news/2008/101708-google-miffs-admins-it-boosts.html?fsrc=rss-security">Google miffs admins, IT boosts Street</source>
    </item>
    <item>
      <title><![CDATA[A Cryptographer and a Data Communications Guy Talk About Risk Management]]></title>
      <link>http://securityratty.com/article/5c18b17d022b8a56101fd4b3d13c5f03</link>
      <guid>http://securityratty.com/article/5c18b17d022b8a56101fd4b3d13c5f03</guid>
      <description><![CDATA[Sounds like the beginning of a joke, right? So these two guys walk into a bar
The Bruce Schneier and Marcus Ranum have an article up on TechTarget/Information Security Magazine called, creatively...]]></description>
      <content:encoded><![CDATA[<blockquote><p>Sounds like the beginning of a joke, right?  <em>So these two guys walk into a bar&#8230;</em></p></blockquote>
<p>&#8220;The&#8221; Bruce Schneier and Marcus Ranum have an article up on TechTarget/Information Security Magazine called, creatively enough, &#8220;<span class="homeSplashTitle"><span class="text0"><strong><a href="http://searchsecurity.techtarget.com/magazineFeature/0,296894,sid14_gci1332745_idx1,00.html">Bruce Schenier, Marcus Ranum debate risk management</a>&#8220;. </strong></span></span></p>
<p>Unfortunately, to get to the article, you&#8217;ll have to either already be a subscriber to IT Security, a subscriber to TechTarget, or go through the 20 minute process of signing up by giving TechTarget all sorts of &#8220;market information&#8221; about how you&#8217;re really Brandon Walsh, CSO of &#8220;The Peach Pit&#8221; Industries in Beverly Hills, CA 90210 (phone 714-867-5309).</p>
<p>For those of you who are already a TechTarget person, the link is above.  For those who aren&#8217;t, or those who just don&#8217;t have the time, I&#8217;ll summarize.  The &#8220;debate&#8221; is kind of awkward because both authors seem come to the same conclusion:</p>
<p style="text-align: center;"><em><strong>Risk Management, it&#8217;s something our profession should do, something humans do naturally, it&#8217;s necessary in business, but gosh - we don&#8217;t have enough data.</strong></em></p>
<p>I&#8217;m not a cryptographer.  I don&#8217;t *nearly* have the insight on privacy and politics that Bruce has.  I&#8217;m not deep in IP communications.  I haven&#8217;t got a proven track record of innovation in IP Security products like Marcus has.  But here&#8217;s the thing, I hope you&#8217;ll never hear me pretend that I have the skill set to speak authoritatively on those subjects.  Heck, I wouldn&#8217;t claim to be a &#8220;risk&#8221; expert because I have a some insight into my shortcomings and what is needed to tackle such a complex problem.  But such a tepid article on something that (at least I think) is so important kind of, well, confuses me.</p>
<p>Why is it such a boring article?  I&#8217;m not sure.  Maybe because they&#8217;re just two guys who would rather debate the merits of specific controls or control activities (after all, their penetration testing debate was a huge success), but there&#8217;s no new information in the &#8220;debate&#8221;.  It&#8217;s the same old &#8220;insurance companies know risk because they have scads of data and we don&#8217;t have that&#8221; complaint. You know what?  I&#8217;m tired of hearing that line, so let&#8217;s talk about it.</p>
<p><strong>HOW DO YOU KNOW WE DON&#8217;T HAVE THE AMOUNT OF DATA WE NEED TO DO RISK MANAGEMENT WELL?</strong></p>
<p>Not particularly picking on Marcus, but in the article he uses the common complaint, &#8220;We lack the data to do risk management well.&#8221;  This mantra is repeated to the point where I&#8217;m blase&#8217; about it.  But for some reason, this sentence really jumped out at me this time for two reasons.  It made me ask:</p>
<p>1.)  How do you <em>know</em> we don&#8217;t have the proper amount of data?</p>
<p>2.)  Can we even define &#8220;well&#8221; (i.e. what &#8220;good&#8221; risk management is) yet?</p>
<p>I really don&#8217;t know that the industry, especially concerning IT risk, is mature enough to really conclude that we don&#8217;t know (in the case of the former), nor that we can define (latter), conclusively.</p>
<p><strong>PLAYING THE CONTRARIAN</strong></p>
<p>Just because I&#8217;m feeling kind of zany this morning, let me suggest something.  Maybe there actually is lots of evidence out there for us to use.  Maybe:</p>
<p>1.)  It&#8217;s just that we don&#8217;t have particularly good models that provide context.</p>
<p>2.)  When that evidence isn&#8217;t an obvious phenomena that lends itself to easy measurement, we throw our hands up in disgust and fall back on &#8220;lack of data&#8221;, &#8220;can&#8217;t quantify risk&#8221;, &#8220;best practices work just fine&#8221; or any other number of arguments, no,<em> excuses</em> we use to justify our inability to be precise about the past (more or less the present or future - apologies to Niels Bohr).</p>
<p><strong>IT&#8217;S IN THE WAY THAT YOU USE IT</strong></p>
<p>Now I actually am happy to acknowledge that we don&#8217;t have enough data to be precise.  You, me, even smart guys like Marcus and Bruce - we&#8217;ll never be able to &#8220;engineer&#8221; risk management.  But you know what?  Neither can Insurance companies.  Sure, there are plenty of places where they have enough data to apply a traditional frequentist approach to risk valuations.   But there are plenty of times Insurers actually insure and they don&#8217;t have centuries or decades of data.  There are plenty of times when they rely on the &#8220;estimates&#8221; of subject matter experts.  There are many times they have enough information to be <em><strong>accurate</strong></em> rather than precise, and that&#8217;s good enough for them.</p>
<p>For that matter, it&#8217;s worth noting that there are plenty of scientific disciplines that have to deal in imprecise prior information, or evidence that&#8217;s fraught with uncertainty (what Ranum calls &#8220;squishy&#8221;, and what I&#8217;ve heard real honest to goodness physicists call &#8220;noisy&#8221;).  Unfortunately, we&#8217;re going to be like them.  Until we can read minds and predict the future, there will always be uncertainty in our measurements and posterior conclusions.  The trick is in how you deal with it and express it.  And while I really don&#8217;t know how much time Marcus or Bruce have really spent in the deep end on the subject of risk and its management - I have seen people doing brilliant things around risk (though they just aren&#8217;t mainstream).  Whether the tools are Bayesian methods, Monte Carlo engines, reductionist models of complex problems, there are risk analysts trying to deal with the problem.  These analysts are applying scientific method(s) and developing reasonable approaches to a very complex problem.  <em><strong>There are people trying, and our body of knowledge is growing</strong></em>, growing well beyond &#8220;gee, I haven&#8217;t got an obvious solution so I&#8217;ll blame it on lack of data&#8221;.  Heck, I&#8217;ve seen readers of this blog suggest Douglas Hubbard&#8217;s book in other security forums!<span style="color: #ff0000;">*</span></p>
<p><strong>I&#8217;VE GOT YOUR DATA RIGHT HERE&#8230;</strong></p>
<p>But we don&#8217;t have enough data?  I have to ask, how much more do we need?  I mean crikey, JPMC just visited our ISSA chapter claiming, like, a bajillion events an hour.  There&#8217;s not one, but several companies out there that will want to tell you about how they have deep &#8220;insight&#8221; into the attacker community.  The boundaries of IT Risk losses are pretty well established by events that happen to public companies.  We have pretty mature testing/assessment tools and methodologies now that help us test our ability to resist the force an attacker can apply to us.  So what part of the Threat Landscape, Asset (Controls) Landscape, or Loss Magnitude landscape is too incomplete (and what are you doing to find the information you need)?</p>
<p><strong>SO WHY DO WE FAIL?</strong></p>
<p>Which brings me to a final, somewhat depressing conclusion.  Maybe there&#8217;s data, and maybe we&#8217;re starting to see the means to use it.  But in the end I do have to agree with Marcus that the vast majority of the infosec world *is* doing a really, really bad job with regards to &#8220;risk&#8221; and &#8220;risk management&#8221;.  The majority of people I know consider GRC to be a cruel, expensive joke.  Risk Assessment Methodologies tend to be built on the faulty premise that if we create a repeatable process, our measurements and conclusions will magically become accurate and wise.  Risk models tend to be factors loosely measured by ordinal scales and then somehow &#8220;multiplied&#8221; together to create a relatively meaningless qualitative value.  The State of the Union here is not good.  But after reading such a superficial treatment of an important and complex subject, I am left wondering if Bruce and Marcus were the right people to write about risk management in a mainstream publication.  As Inspector Callahan says, &#8220;<strong><a href="http://www.youtube.com/watch?v=cZNlraF0xec">A man&#8217;s got to know his limitations</a></strong>.&#8221;</p>
<p>===============================</p>
<p><span style="color: #ff0000;">*</span> <em>Speaking of which, if you want to do one cost effective thing to address your uncertainty - go find Douglas Hubbard&#8217;s book. It&#8217;s even got a nice recommendation from Peter Tippett.  The book is called &#8220;How To Measure Anything&#8221; - the title sounds rather hyperbolic, but there are good techniques in it we can use to identify useful information and refine our ability to frame that qualitative information into quantitative values. The key is how Hubbard has you deal with your uncertainty.  For those of you who are more scientific minded and want to dig deep into the subject, I have on good authority that E.T. Jaynes &#8220;Probability Theory, The Logic of Science&#8221; is a rather under appreciated work.</em></p>
]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 11:32:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/engineer risk management">engineer risk management</category>
      <category domain="http://securityratty.com/tag/methodologies">methodologies</category>
      <category domain="http://securityratty.com/tag/risk assessment methodologies">risk assessment methodologies</category>
      <category domain="http://securityratty.com/tag/risk models">risk models</category>
      <category domain="http://securityratty.com/tag/risk analysts">risk analysts</category>
      <category domain="http://securityratty.com/tag/models">models</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=487">A Cryptographer and a Data Communications Guy Talk About Risk Management</source>
    </item>
    <item>
      <title><![CDATA[REALLY Cool Presentation: "Grand Challenges" of Log Management]]></title>
      <link>http://securityratty.com/article/6feebc7212f6d02443181f9d9e0283e9</link>
      <guid>http://securityratty.com/article/6feebc7212f6d02443181f9d9e0283e9</guid>
      <description><![CDATA[If you are into logs and, especially, into tools that deal with logs, read this . This is my attempt to summarize everything that is challenging about log processing and analysis into one...]]></description>
      <content:encoded><![CDATA[If you are into logs and, especially, into tools that deal with logs, read <a href="http://www.slideshare.net/anton_chuvakin/grand-challenges-of-log-management-presentation">this</a>.  This is my attempt to summarize everything that is challenging about log processing and analysis into one presentation,  <span style="font-weight: bold;">'"Grand Challenges" of Log Management.'</span>  Logs are fun, but they are also painful to deal with, and there are plenty of things that we need to address before we can consider ourselves "done."<br /><br />The presentation is also embedded below:<br /><br /><div style="width:425px;text-align:left" id="__ss_645029"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/grand-challenges-of-log-management-presentation?type=powerpoint" title="&quot;Grand Challenges&quot; of Log Management">&quot;Grand Challenges&quot; of Log Management</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=innovationlogmgtgrandproblemsrel-1223497009889980-8&stripped_title=grand-challenges-of-log-management-presentation" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=innovationlogmgtgrandproblemsrel-1223497009889980-8&stripped_title=grand-challenges-of-log-management-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View SlideShare <a style="text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/grand-challenges-of-log-management-presentation?type=powerpoint" title="View &quot;Grand Challenges&quot; of Log Management on SlideShare">presentation</a> or <a style="text-decoration:underline;" href="http://www.slideshare.net/upload?type=powerpoint">Upload</a> your own. (tags: <a style="text-decoration:underline;" href="http://slideshare.net/tag/logs">logs</a> <a style="text-decoration:underline;" href="http://slideshare.net/tag/logging">logging</a>)</div></div><br /><br />Enjoy!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=loZtM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=loZtM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=1mlZM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=1mlZM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=SeNxM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=SeNxM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/415249699" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 12:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/grand challenges">grand challenges</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/deal">deal</category>
      <category domain="http://securityratty.com/tag/plenty">plenty</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/415249699/really-cool-presentation-grand.html">REALLY Cool Presentation: "Grand Challenges" of Log Management</source>
    </item>
    <item>
      <title><![CDATA[MSP Snapshot Monitoring with EM7]]></title>
      <link>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</link>
      <guid>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</guid>
      <description><![CDATA[Between the fifth anniversary for ScienceLogic and the Inc 500 milestone, weve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally...]]></description>
      <content:encoded><![CDATA[<p>Between the <a href="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008" target="_blank">fifth anniversary for ScienceLogic</a> and the Inc 500 milestone, we’ve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally designed with managed service providers in mind? Not so surprising when 5 of the first 6 employees (including all 3 founders) came from hosting and MSP backgrounds and had first-hand experience with the daily trials and tribulations of MSP operations – and the tools that didn’t quite work for them.
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas.jpg"><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="184" alt="John at Interop Vegas" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas-thumb.jpg" width="244" align="left" border="0"></a>Here we talk to John Proctor, who started out as one of our first customers (and the first MSP customer). And he believed in it so much, he eventually became part of the ScienceLogic team. (Remember &#8220;I&#8217;m not only the President, I&#8217;m also a client&#8221; from <a href="http://www.hairclub.com/inthenews_article1.php" target="_blank">the Hair Club for Men</a>?)
<p>John shares his perspectives about the service provider world and why he took a chance on a little-known product called EM7.
<p><strong>ScienceLogic:</strong> What is your background? How many years have you worked as a service provider and for what types of companies?
<p><strong>John Proctor:</strong> I have been working with Service providers for over twelve years. I worked at a major regional service provider for six years and before that I designed and built national and international networks for ISP’s and Fortune 500 companies as a consultant for PriceWaterhouseCoopers and WorldComm.
<p><strong>ScienceLogic:</strong> You were one of the first customers of EM7 – why did you choose it and how did you get over the hurdles associated with using a start-up company’s product?
<p><strong>John Proctor:</strong> We were actually customer number five. Back in 2004 when we evaluated and purchased EM7 we could see that EM7 provided about 80% of what we were looking for in one integrated solution right out of the box. One of the things that sold us on EM7 was that the ScienceLogic founders had all previously worked for a service provider, so we knew they understood our business and our challenges. But in the end, it comes down to features. Once we compared EM7 functionality to the alternatives, it was clearly a “no brainer.”
<p><strong>ScienceLogic:</strong> What other alternatives were being considered?
<p><strong>John Proctor:</strong> Well, we had started with a few point solutions, but as our business and product offerings matured, this resulted in a growing number of point solutions. What started with 3 or 4 ended up as 14 separate tools. They all had strengths but what they didn’t have was integration and because of this they could not scale. And, if the tools could not scale, our business could not grow.
<p>So, naturally we started looking at framework solutions, but they are expensive to buy, expensive to implement, and expensive to maintain. At one point, we even considered some open source projects. There were several that showed promise, but we would still be stuck with tools that were not integrated. So then we considered hiring developers to cobble something together that would work for our business. The only problem with this alternative was that we felt it would take 6 to 8 months before we could have something viable to work with.
<p><strong>ScienceLogic:</strong> What products were you using before EM7? What were your goals?
<p><strong>John Proctor:</strong> Before we purchased EM7 we used 14 different point solutions to deliver our products and services to the marketplace. Tools like NetCool, Openview, Argent, Heat, What’s Up Gold as well as several other point solutions, vendor specific applications and manually updated spreadsheets. And, as I mentioned before, this does not scale. This also adds a great deal of complexity when you begin to consider business continuity and disaster recovery. All these tools were vital to the delivery of our products and services. Any service provider will tell you it is all about uptime. So if the product is uptime, the tools used to deliver it have to be available 24&#215;7x365.
<p>Our goals were simple: scale and redundancy. As it turns out, the solution was simple as well. EM7 provided a tool that could replace the functionality of almost half of the existing point solutions and the applications that could not be replaced were integrated with EM7 to provide our staff with a “single pane of glass” to see the status and performance of each area of the business from one application. We had visibility into everything from facility systems to applications using EM7.
<p>ScienceLogic also delivers an extensible configuration that addressed uptime and redundancy. We deployed collectors throughout our network that reported back to a central pair of redundant database servers and with this configuration we were able to perform backups and add capacity without taking the system down.
<p><strong>ScienceLogic:</strong> Why are service providers different from enterprises? How are their needs different?
<p><strong>John Proctor:</strong> First and foremost, service providers face the same challenges that only the largest enterprises ever face and they also have many unique challenges that only service providers experience.
<p>One challenge we faced was that we had multiple datacenters in different states. They were all interconnected with plenty of bandwidth between each site, but the tools were not designed to be used across the WAN. Our staff in our remote data center did not have the same access as our staff in the corporate office. Since EM7 is web-based, it immediately eliminated this problem.
<p>Another challenge is that service providers must manage systems across multiple domains. Back in the early version of a specific tool we were using before EM7, the only way you could implement it across multiple domains was to put the same username and password on every computer that you monitored. Beyond the security concerns, maintenance was a nightmare. Anytime we had to change the password, we would get locked out of dozens upon dozens of systems. When the password was changed on the monitoring server, it would attempt to login to the remote machines and fail. Repeated attempts would result in the account getting locked. I think that vendor eventually addressed this issue, but service providers seldom find tools that were designed for their unique situations.
<p><strong>ScienceLogic:</strong> How is EM7 geared to service providers?
<p><strong>John Proctor:</strong> Enterprise IT is a trusted part of the business; they are one of the team. Service providers are outsiders that must earn trust by showing the customer exactly what they are doing.
<p>EM7 provides a multi-tenant environment that allows service providers to manage systems across many different customers while at the same time providing the customer access to see the same information but only what’s relevant to them.
<p>EM7 was built by service providers and even includes a few features just for them. Two of my favorites are bandwidth billing and the emergency notification system. Take bandwidth billing, for instance. EM7 provides a way to collect bandwidth utilization, store subscription information, and calculate a bill from any one of about 10 different methodologies. And at the end of the billing period, EM7 sends the completed report out to whomever you chose via email.
<p>Another unique service provider feature is the emergency notification system. EM7 allows the provider to track what customers used their unique infrastructure components. If they have to perform maintenance on the infrastructure component or have a problem they can send an email to all of the impacted customers in a matter of minutes.
<p><strong>ScienceLogic:</strong> What trends do you see for service providers? What about big trends such as virtualization and cloud computing – how will they impact service providers?
<p><strong>John Proctor:</strong> Virtualization is really hot for service providers right now and for the same reasons as in the enterprise. Service providers run data centers and data centers must be powered and cooled. So, anytime they can use a virtual server instead of adding physical equipment it is a good thing. But then you add the complexity that multiple customers reside on the same host and you must track things like bandwidth utilizations by guest OS, and it all gets a little harder. Lucky for us this is not a problem for EM7.
<p>I still think it’s early days for cloud computing. Depending on who you talk to, much of what service providers (especially the big ones) have already been doing with SAAS offerings and hosted applications could be described as cloud computing already. In which case, service providers are ahead of the game. But whatever the “final” definition, cloud computing actually shares many similarities with virtualization – in that service providers (or enterprises) will need to be able to manage far more “devices” in real-time with “zero downtime” expectations by customers. What this really means is that you’re going to see much more automation in provisioning and IT monitoring tools to handle the scale and speed with which things can change in the data center given vm migration and the talked-about switching between “clouds” that can be used for high availability. </p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 12:51:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service providers experience">service providers experience</category>
      <category domain="http://securityratty.com/tag/service providers seldom">service providers seldom</category>
      <category domain="http://securityratty.com/tag/impact service providers">impact service providers</category>
      <category domain="http://securityratty.com/tag/em7 functionality">em7 functionality</category>
      <category domain="http://securityratty.com/tag/em7 sends">em7 sends</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider world">service provider world</category>
      <source url="http://blog.sciencelogic.com/msp-snapshot-monitoring-with-em7/10/2008">MSP Snapshot Monitoring with EM7</source>
    </item>
    <item>
      <title><![CDATA[Interop NY 2008: Wrap-up]]></title>
      <link>http://securityratty.com/article/1f9f6e5f6c1183d8706458aa161f8afd</link>
      <guid>http://securityratty.com/article/1f9f6e5f6c1183d8706458aa161f8afd</guid>
      <description><![CDATA[This year was a strange year at Interop NY. While the financial industry in NY was crumbling around us, things were strangely normal at Interop . Despite entire departments being laid-off at Lehman...]]></description>
      <content:encoded><![CDATA[<p>This year was a strange year at Interop NY.  While the financial industry in NY was crumbling around us, things were <a href="http://www.networkworld.com/community/node/33059" target="_blank">strangely normal at Interop</a>.  Despite entire departments being laid-off at Lehman and elsewhere, while the show was going on, the show itself seemed mostly unaffected.  We even saw this with our annual survey - in 2007 18% of respondents were from the financial services industry, this year the sector respresented 19%.</p>
<p>Interop NY 2008 was up considerably in size from the show in 2007.  <a href="http://blog.sciencelogic.com/interview-with-lenny-heymann-interop-general-manager/09/2008" target="_blank">According to Lenny Heymann</a>, the GM of Interop, this is a trend that they expect to continue.  My personal experience was that the size of the vendors was also up this year.  I think there were so few startups that &#8220;Startup City&#8221; was pulled from the show completely.  In any case, the show floor was full and there was plenty of attendee traffic to go around.</p>
<p>Definitely helping out from a traffic and draw perspective was the addition of the Web 2.0 Expo - Interop was co-located with both Mobile Business Expo and the Web 2.0 show. It seems like that buzzword still hasn&#8217;t lost most of its luster.</p>
<p>From the InteropNet perspective, the main feeling was one of being rushed.  With the show only lasting two days, and the InteropNet team only having a couple of days of ramp up time, everything was compressed into a much shorter period than in Las Vegas.  While this would normally be a challenge, it&#8217;s an even bigger challenge at the Javits where the InteropNet team was allowed to do almost nothing ourselves because of union rules.  You&#8217;d be surprised how frustrated you can make a network guy who&#8217;s told that he has to stand there and watch the electrician plug things in, rather than just doing it himself.  The only thing faster than the InteropNet team getting the Interop NY network up, was my pedicab ride to the InteropNet Booze Cruise.<br />
<object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/6h8JECK6naw&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/6h8JECK6naw&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object></p>
<p>In any case, everything came off without a hitch, and EM7 performed flawlessly catching a couple of power outages that last day and alerting everyone before the batteries on the UPSes had a chance to run down.</p>
<p>Over the next couple of weeks I&#8217;ll analyze the data from the show to see how many tickets were handled, amount of bandwidth consumed, etc and we&#8217;ll do a comparison to Interop Las Vegas.</p>
<p>We&#8217;re (both ScienceLogic and me personally) looking forward to Interop 2009.</p>
]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 16:48:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/interop las vegas">interop las vegas</category>
      <category domain="http://securityratty.com/tag/interopnet team">interopnet team</category>
      <category domain="http://securityratty.com/tag/mobile business expo">mobile business expo</category>
      <category domain="http://securityratty.com/tag/expo">expo</category>
      <category domain="http://securityratty.com/tag/bigger challenge">bigger challenge</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/attendee traffic">attendee traffic</category>
      <source url="http://blog.sciencelogic.com/interop-ny-2008-wrap-up/09/2008">Interop NY 2008: Wrap-up</source>
    </item>
    <item>
      <title><![CDATA[So Logically, If She Weighs The Same As A DuckShes A Witch!]]></title>
      <link>http://securityratty.com/article/3fa3a2c5641e284f4fc5fc76430d2faa</link>
      <guid>http://securityratty.com/article/3fa3a2c5641e284f4fc5fc76430d2faa</guid>
      <description><![CDATA[I usually try to stay far away from politics and current events, but my friend Rich has put up a blog post blaming the credit crisis on quantitative analysis, and then positing that because the...]]></description>
      <content:encoded><![CDATA[<p>I usually try to stay far away from politics and current events, but my friend <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich has put up a blog post</a></strong> blaming the credit crisis on quantitative analysis, and then positing that because the economy sucks, Information Security should be only qualitative.</p>
<p>Now I&#8217;ve been &#8220;accused&#8221; of being a quant in the past (hi rybolov!) but in reality the only dogs I have in this fight are the model and the application of scientific method - and really, ethically speaking, I have to be tied to the latter while applying the former.</p>
<p>And I see a false dichotomy in this whole Quant vs. Qual thing.  We, as a profession, tend to create a political divide between the two which, if it even exists, I&#8217;d say is based more on our ignorance rather than our expertise.  After all, we are the profession that regularly multiplies across ordinal scales and uses wonderful models like R=VxTxI.   As someone  learning to deal in probabilities and rationalism, I have to recognize that this discussion is really just about the act of observation using different metrics of measurement.</p>
<p>But how we&#8217;re going about observing does not change the fact that there is measurement based on observation.  So if I&#8217;m working with you I can easily turn your qualitative scale into a quantitative one, and vice-versa.  Yes, Shrdlu, if we had the time, even your most seemingly Qual things could be Quant! (This flexible world view, btw, is an outcome of that new-fangled Bayesian thing).</p>
<p><strong>COGNITIVE BIAS A-PLENTY</strong></p>
<p>But back to what Rich is saying there about information security and risk - and he isn&#8217;t/won&#8217;t be the only one saying these sorts of things - we should try to understand what&#8217;s really going on rather than get caught up in the emotional hurricane.  Our profession suffers several forms of cognitive bias.  The nature of our jobs and what we do can cause us to be focused on the outcome and not the quality of the decision at the time it was made.  We want to bring in things from other professions that are useful, but at times we do view things outside our profession with false correlation to our own (unfortunately for those who write these sorts of articles, financial risk is <em><strong>completely different</strong></em> than operational risk).  We also have the tendency to focus on negative outcomes without acknowledging the positive outcomes (For example, I hear that Alan Greenspan&#8217;s new firm is up a couple of $billion in all this mess since he joined them, short sellers are doing quite well - must be because they have qualitative models or something <em>-grin-</em>).  The effect of these biases are compounded by the facts that proper correlation takes more work than we usually give it, and rational thought is not that easy when there&#8217;s a witch-hunt mentality.</p>
<div class="wp-caption alignnone" style="width: 257px"><a href="http://www.youtube.com/watch?v=zrzMhU_4m-g"><img src="http://www.riskmanagementinsight.com/media/images/weblog/peasants.png" alt="Burn her anyway!" width="247" height="219" /></a><p class="wp-caption-text">What also floats in water? (link to Youtube)</p></div>
<p><strong>WHAT SHOULD WE BE THINKING ABOUT?</strong></p>
<p>So as you and I read opinions that seem to be the polar opposite of irrational exuberance (and there will be plenty between now and the election) we&#8217;ll have to ask ourselves, &#8220;what really failed here?&#8221;  At the risk (pun) of over-simplification:</p>
<ul>
<li>Was There an Error on the part of Probability Theory?</li>
</ul>
<p>After all, Probability Science like all other fields of knowledge is always &#8220;advancing&#8221; as they say.  So perhaps probability theory is wrong somehow?</p>
<p>I&#8217;m personally disinclined to put the blame here, primarily because I would think that there would be evidence from other fields (like Quantum Mechanics) that something is amiss waaaaay before it hit a field like economics.</p>
<ul>
<li>Was There Error In The Model Used to Determine Risk?</li>
</ul>
<p>Some people who understand real estate valuation and complex derivatives and financial risk want to put the blame here.  It&#8217;s a little too early to tell, but one thing is for sure - Financial risk is so different from operational risk I couldn&#8217;t begin to hazard an opinion on the subject.   But it would seem that this is really somewhere we might look.</p>
<ul>
<li>Was There Error In The  Scale Used (Quantitative vs. Qualitative)?</li>
</ul>
<p>Honestly?  I find it extremely difficult to understand how this could be the source of financial ruin.</p>
<ul>
<li>Was There Error on the part of the Decision Maker?</li>
</ul>
<p>What if all of the above were just fine, and the decision maker chose short term gain over long term stability?  What if this was (to simplify the matter greatly) a choice of &#8220;heads&#8221; over &#8220;tails&#8221; and the coin landed on tails?  What if the model represented the right risk (probability of negative outcome vs. positive outcome), but the complex derivative was sold to someone else who had poor &#8220;risk management&#8221; (ability to make a good decisions)?</p>
<p>Now I have no clue about complex derivatives, and I&#8217;m oversimplifying to be sure - chances are like most things, there are several problems that helped create the primary cause. But it seems to me that as we go into incident response mode for the economy, it&#8217;s more helpful to do so in a rational, logical manner.<br />
<strong><br />
OTHER THINGS WE MIGHT WANT TO CONSIDER</strong></p>
<p><span style="color: #008000;"><strong>Consider the Source</strong></span><br />
Some authors (who I think tend to exploit outcome and hindsight bias,and then combine those with indirect ad hominem attacks in order to sell their books), are actually putting forth arguments against the use of analytics.  The source of this is a current epistemic debate between those who believe that only falsification is certain, and those who maintain that neither proof nor falsification are certain, there are only probabilities.    So before you go believing any &#8220;quadrants&#8221; of usefulness on faith - I encourage you to understand what is at the heart of the discussion.<br />
<span style="color: #008000;"><strong><br />
We All Have to Live In The Real World</strong></span><br />
The sun will rise tomorrow, and someone will try to find the source of the problem and do a better job.  Now chances are, they&#8217;ll be doing it in a quantitative manner.  Chances are also that at some point their models will fail and we&#8217;ll need to build new ones.  And this will happen whether the field is cosmology, economics, meteorology, information security, or professional baseball.<br />
<strong><br />
WHAT ABOUT YOU, ALEX?</strong></p>
<p>I&#8217;m far from certain and subject to change, but these days I lean towards <strong><a href="http://www.overcomingbias.com/2008/09/who-to-blame.html">Robin Hanson &amp; MIchael Lewis</a></strong> w/regards to placing blame.</p>
]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 10:59:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/financial risk">financial risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/operational risk">operational risk</category>
      <category domain="http://securityratty.com/tag/outcome">outcome</category>
      <category domain="http://securityratty.com/tag/exploit outcome">exploit outcome</category>
      <category domain="http://securityratty.com/tag/probability">probability</category>
      <category domain="http://securityratty.com/tag/qualitative models">qualitative models</category>
      <category domain="http://securityratty.com/tag/models">models</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=420">So Logically, If She Weighs The Same As A DuckShes A Witch!</source>
    </item>
    <item>
      <title><![CDATA[Dumb Luck IS a Strategy!]]></title>
      <link>http://securityratty.com/article/16ab612b9342a48155481fcdd1dcf4fd</link>
      <guid>http://securityratty.com/article/16ab612b9342a48155481fcdd1dcf4fd</guid>
      <description><![CDATA[While still at GOVCERT.NL , I've attended a fun little presentation, describing a penetration test (I cannot provide any more details as it was a &quot;No Press&quot; presentation - this post is not about it,...]]></description>
      <content:encoded><![CDATA[<p>While still at <a href="http://www.govcert.nl/symposium/index.html">GOVCERT.NL</a>, I've attended a fun little presentation, describing a penetration test (I cannot provide any more details as it was a &quot;No Press&quot; presentation - this post is not about it, but rather was inspired by it!)</p>  <p>In any case, if you do pentests, think about all the RECENT cases where you break in to a major corporation through:</p>  <ul>   <li>a Solaris system with Internet-exposed telnet with a guessable password OR a telnet vulnerability (circa 1994!) </li>    <li>an exposed VPN appliance with a manufacturer's administrator password </li>    <li>a router with default &quot;enable&quot; password </li>    <li>or, something else entirely - but something that rivals the above example in its <strong>unparalleled, unbelievable, abysmal, deep idiocy.</strong> </li> </ul>  <p>Indeed, many of my pentesting friends still report plenty of such cases (one was also featured in the presentation mentioned above). Whenever I hear about it from a pentester, I always ask:</p>  <p><strong><font size="4">Do you think &quot;somebody bad&quot; had already passed through the hole you just discovered?</font></strong></p>  <p>Maybe an hour ago, a day ago - or a year ago?!</p>  <p><strong>I cannot see how the answer can be &quot;no.&quot; </strong></p>  <p>Even though pentesters usually don't focus on forensics (no time for this), it is not uncommon to notice &quot;your predecessor's&quot; intrusion traces while you break through systems, &quot;plant flags&quot;, change screen backgrounds [for the admins to notice that you've been there...], etc. </p>  <p>Let's think what this situation really means? Here are the choices I see:</p>  <ol>   <li><strong>Nobody discovered the hole</strong> - a law of large&#160; numbers (aka &quot;dumb luck&quot;) have &quot;shielded&quot; the company from an incident. Yes, Virginia, dumb luck IS a security strategy for some companies... AND it works for them. </li>    <li><strong>It was discovered, but not used/abused by the attacker</strong> - maybe he was busy hacking other systems, or saved this for later and never came back due to his ADD. Congratulation, you win! The immense power of dumb luck wrapped you in a protective &quot;security&quot; blanket ... again :-) </li>    <li><strong>It was discovered; the attacker went in, looked around and compromised a few others systems</strong>, but found nothing of interest (no low hanging fruits)&#160; - and he was not a bot herder. Again, you win. Next time you are in Vegas, bet on &quot;00.&quot; </li>    <li><strong>It was discovered; the attacker went in and deployed a bot on &quot;your&quot; system </strong>- given how many botnets are there, this situation is clearly <em>acceptable</em> to many organizations. In this case, dumb luck strategy, apparently, still work: so they use your box to spam and phish somebody else ... big deal!</li>    <li><strong>It was discovered; the attacker went in and stole all your credit card information (it is now for sale) </strong>- even in this case, the user of &quot;the dumb luck strategy&quot; still &quot;wins&quot; (in some perverse sense)! Unless and until the stolen information IS tracked back to you OR a friendly neighborhood PCI auditor come and jams a broomstick up your ..., you can still continue to be stupid at your leisure and ignore basic security practices. </li>    <li><strong>It was discovered; the attacker went in and stole your CEO's Inbox, including the email related to his affair (it is now on CNN) - </strong>now, in this case, you lose AND it is time to stop being stupid! Welcome to the &quot;0wned world.&quot; Time to launch (relaunch?) your security program and get serious. </li> </ol>  <p>What does this teach us about RISK? The lesson here is important:</p>  <ul>   <li>For a security professional, an Internet-exposed system with &quot;root/root&quot; is an obvious <strong>HUGE</strong> risk! </li>    <li>For your boss's boss's boss, it is <strong>NOT</strong>! </li> </ul>  <p>This is exactly why I think that <strong>the most critical problem in security today is METRICS</strong>. Metrics that <strong>a) work AND mean something to decision makers</strong> and <strong>b) can be clearly communicated to said decision makers [</strong>BTW, a) and b) are two separate problems.] Metrics that cover not only threats and vulnerabilities we face, but also the effectiveness of security countermeasures we deploy. Metrics you can act on - and ones your boss (and his boss) will act on. Metrics that lead to correct decisions about which risks to accept, which to&#160; mitigate (all while knowing with what efficiency such mitigation occurs) and which to transfer.</p>  <p>Until that time, the dreaded &quot;C-word&quot; (<strong>c</strong>ompliance) will trump &quot;the other C-word&quot; (<strong>c</strong>ommon sense) as a driver for security ... and we will continue to live in the &quot;0wned world.&quot;</p>  <p><strong>Possibly related posts:</strong></p>  <ul>   <li><u><a href="http://chuvakin.blogspot.com/2007/11/risk-vs-risk.htmll">Risk vs Risk</a></u>&#160;</li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=AdXkL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=AdXkL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=SqYRL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=SqYRL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=UGPML"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=UGPML" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/396385129" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 05:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dumb luck">dumb luck</category>
      <category domain="http://securityratty.com/tag/dumb luck strategy">dumb luck strategy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security countermeasures">security countermeasures</category>
      <category domain="http://securityratty.com/tag/security professional">security professional</category>
      <category domain="http://securityratty.com/tag/security program">security program</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/obvious huge risk">obvious huge risk</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/396385129/dumb-luck-is-strategy.html">Dumb Luck IS a Strategy!</source>
    </item>
    <item>
      <title><![CDATA[Gee Mike, Im sorry Im a unhappy customer]]></title>
      <link>http://securityratty.com/article/4cc0439d38d4ca868eb4001ad11ff2d8</link>
      <guid>http://securityratty.com/article/4cc0439d38d4ca868eb4001ad11ff2d8</guid>
      <description><![CDATA[You see Mike, Im still waiting to hear back from Dell customer support about the Vista BSODs I experience with my new lappie. But before that, I was a happy to use Dell customer


clipped from...]]></description>
      <content:encoded><![CDATA[<div > You see Mike, Im still waiting to hear back from Dell customer support about the Vista BSOD&#8217;s I experience with my new lappie.<br/>But before that, I was a happy to use Dell customer. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/989AB7AF-8033-4B99-90B6-1FFF93971F2E/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/213f365d-4cfc-45aa-a1b2-99f8137db686/989AB7AF-8033-4B99-90B6-1FFF93971F2E/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://money.cnn.com/2008/09/03/technology/fortt_dell.fortune/index.htm" href="http://money.cnn.com/2008/09/03/technology/fortt_dell.fortune/index.htm" style="font-size: 11px;">money.cnn.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://money.cnn.com/2008/09/03/technology/fortt_dell.fortune/index.htm -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Michael Dell &#8216;Friends&#8217; his customers</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://money.cnn.com/2008/09/03/technology/fortt_dell.fortune/index.htm --><P>Spooky? Well, this is a new Dell (<A href="http://money.cnn.com/quote/quote.html?symb=DELL&#038;source=story_quote_link">DELL</A>, <A href="http://money.cnn.com/magazines/fortune/fortune500/2008/snapshots/1053.html?source=story_f500_link">Fortune 500</A>): a little more attentive online, and a little more paranoid. When Michael Dell took back the reins of his company in early 2007, one of his first acts as CEO was to give its web strategy a kick in the pants. The computer maker had plenty of hairy business problems to deal with - financial irregularities, a stagnating stock, profits down 28% in a year - but perhaps the most embarrassing was the thrashing its brand had taken online. On tech blogs and consumer forums, Dell had become almost a byword for lousy customer service. </P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/989AB7AF-8033-4B99-90B6-1FFF93971F2E/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_110908072905"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=110908072905&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=110908072905&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=110908072905&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_110908072905" /></a></P>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 15:29:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dell customer support">dell customer support</category>
      <category domain="http://securityratty.com/tag/dell customer">dell customer</category>
      <category domain="http://securityratty.com/tag/michael dell friends">michael dell friends</category>
      <category domain="http://securityratty.com/tag/michael dell">michael dell</category>
      <category domain="http://securityratty.com/tag/dell">dell</category>
      <category domain="http://securityratty.com/tag/attentive online">attentive online</category>
      <category domain="http://securityratty.com/tag/lousy customer service">lousy customer service</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/vista bsods">vista bsods</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=614">Gee Mike, Im sorry Im a unhappy customer</source>
    </item>
  </channel>
</rss>
