<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: political]]></title>
    <link>http://securityratty.com/tag/political</link>
    <description></description>
    <pubDate>Thu, 04 Sep 2008 10:16:36 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Security Matters: The Seven Habits of Highly Ineffective Terrorists]]></title>
      <link>http://securityratty.com/article/d7f6e34d46350bc3546ccbac96bdd613</link>
      <guid>http://securityratty.com/article/d7f6e34d46350bc3546ccbac96bdd613</guid>
      <description><![CDATA[Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat...]]></description>
      <content:encoded><![CDATA[<p>
Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place.
</p>

<p>
Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf.
</p>

<p>
If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections.
</p>

<p>
Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a <a href="http://maxabrahms.com/pdfs/DC_250-1846.pdf">paper</a> (.pdf) published this year in <cite>International Security</cite> that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers:
</p>

<p>
Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved.
</p>


<p>
Abrahms has an alternative model to explain all this:  People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States.
</p>

<p>
The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida.
</p>

<p>
For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist.
</p><p>
All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion.
</p><p>
This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups.
</p><p>
We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is Chief Security Technology Officer of BT, and author of </cite>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<cite>.</cite>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=16939d16056d6d01accd415177a76dbb" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=16939d16056d6d01accd415177a76dbb" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=igbdM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=igbdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=CO91m"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=CO91m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rBiKm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rBiKm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=qO8rM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=qO8rM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=0b0DM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0b0DM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=nYn4m"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nYn4m" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=EcnRm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=EcnRm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=UhYOM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UhYOM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/408903389" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/408903390" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ineffective">ineffective</category>
      <category domain="http://securityratty.com/tag/highly ineffective terrorists">highly ineffective terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/people join">people join</category>
      <category domain="http://securityratty.com/tag/people join hamas">people join hamas</category>
      <category domain="http://securityratty.com/tag/people join al-qaida">people join al-qaida</category>
      <category domain="http://securityratty.com/tag/terrorist organizations">terrorist organizations</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/408903390/securitymatters_1002">Security Matters: The Seven Habits of Highly Ineffective Terrorists</source>
    </item>
    <item>
      <title><![CDATA[CEP, Politics, and Decision Making]]></title>
      <link>http://securityratty.com/article/4e349d27b47bdef874454b93f7a7a6b2</link>
      <guid>http://securityratty.com/article/4e349d27b47bdef874454b93f7a7a6b2</guid>
      <description><![CDATA[I have changed my mind about injecting presidential politics into The CEP Blog. I thought about linking complex events and politics into a discussion on complex events and the decision making process...]]></description>
      <content:encoded><![CDATA[<p>I have changed my mind about injecting presidential politics into The CEP Blog.  I thought about linking complex events and politics into a discussion on complex events and the decision making process.</p>
<p>However, this approach risks alienating folks who take their politics serious or have other concerns.   For that reason,  I am going to go another, less political, direction on The CEP Blog.  I will not blog on the US presidential election here.</p>
<p>In my next series of  blog posts I will discuss how asymmetric event processing and asymmetric situational awareness was the genesis for complex event processing.</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 05:36:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/politics">politics</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/cep blog">cep blog</category>
      <category domain="http://securityratty.com/tag/complex events">complex events</category>
      <category domain="http://securityratty.com/tag/presidential politics">presidential politics</category>
      <category domain="http://securityratty.com/tag/blog posts">blog posts</category>
      <category domain="http://securityratty.com/tag/asymmetric situational awareness">asymmetric situational awareness</category>
      <category domain="http://securityratty.com/tag/presidential election">presidential election</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <source url="http://www.thecepblog.com/2008/09/29/cep-politics-and-decision-making/">CEP, Politics, and Decision Making</source>
    </item>
    <item>
      <title><![CDATA[John McCain: Desperate and Reckless]]></title>
      <link>http://securityratty.com/article/a299c2b37dd8172588b5324124b6f3cd</link>
      <guid>http://securityratty.com/article/a299c2b37dd8172588b5324124b6f3cd</guid>
      <description><![CDATA[Normally I would not blog about political topics here, but this is an extraordinary time in history and extraordinary times call for extraordinary posts from time-to-time
John McCain is, objectively,...]]></description>
      <content:encoded><![CDATA[<p>Normally I would not blog about political topics here, but this is an extraordinary time in history and extraordinary times call for extraordinary posts from time-to-time.</p>
<p>John McCain is, objectively, a bad decision maker, desperate and reckless.   He knows that his party is in trouble and that the Democrats have the advantage; so what does he do?</p>
<p>First, he picks a very conservative, inexperienced female governor from Alaska who, until recently, did not even have a US passport, as his running mate.  This was an obvious act of desperation, thinking that he could pull the Hillary votes in the election.  A heartbeat from the US Presidency at a time when there are two ongoing wars and our country on the verge of economic collapse and he gambles with a &#8220;Hail Mary&#8221; touchdown pass?  This is not the man we need as President.</p>
<p>Then, not even a member of the Banking committee in the Senate, and self-described &#8220;not knowledgeable on economic issues&#8221;, John McCain tries another &#8220;Hail Mary&#8221; pass by rushing off to DC to &#8220;save the world&#8221; and tries to demand Obama suspend his campaign and the debates?    The US is on the brink of economic collapse and McCain puts politics and election desperation above the future of the country?   This is not the man we need as President.</p>
<p>During the same period, Barack Obama has proven to be cool, intelligent, and a good decision maker.   This should be obvious to anyone with the mind to actually think what is good for the country and not about politics.</p>
<p>John McCain is desperate and reckless.   We don&#8217;t need desperate and reckless people leading this country.</p>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 14:54:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mccain">mccain</category>
      <category domain="http://securityratty.com/tag/john mccain">john mccain</category>
      <category domain="http://securityratty.com/tag/reckless">reckless</category>
      <category domain="http://securityratty.com/tag/bad decision maker">bad decision maker</category>
      <category domain="http://securityratty.com/tag/decision maker">decision maker</category>
      <category domain="http://securityratty.com/tag/economic collapse">economic collapse</category>
      <category domain="http://securityratty.com/tag/extraordinary time">extraordinary time</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/election desperation">election desperation</category>
      <source url="http://www.thecepblog.com/2008/09/26/john-mccain-desperate-and-reckless/">John McCain: Desperate and Reckless</source>
    </item>
    <item>
      <title><![CDATA[Palins e-mail and expert mistakes ]]></title>
      <link>http://securityratty.com/article/47c649ba36a3616ed7e1b04d9e915a8f</link>
      <guid>http://securityratty.com/article/47c649ba36a3616ed7e1b04d9e915a8f</guid>
      <description><![CDATA[Experts arent infallible. Whether they are mushroom collectors, e-mail providers, political candidates or IT professionals, they can get things wrong. If were talking mushrooms, the results can be...]]></description>
      <content:encoded><![CDATA[Experts aren’t infallible. Whether they are mushroom collectors, e-mail providers, political candidates or IT professionals, they can get things wrong. If we’re talking mushrooms, the results can be fatal.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=60153?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=60153?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mushroom collectors">mushroom collectors</category>
      <category domain="http://securityratty.com/tag/e-mail providers">e-mail providers</category>
      <category domain="http://securityratty.com/tag/mushrooms">mushrooms</category>
      <category domain="http://securityratty.com/tag/infallible">infallible</category>
      <category domain="http://securityratty.com/tag/professionals">professionals</category>
      <category domain="http://securityratty.com/tag/wrong">wrong</category>
      <category domain="http://securityratty.com/tag/experts">experts</category>
      <category domain="http://securityratty.com/tag/political">political</category>
      <category domain="http://securityratty.com/tag/fatal">fatal</category>
      <source url="http://www.networkworld.com/columnists/2008/092508backspin.html?fsrc=rss-security">Palins e-mail and expert mistakes </source>
    </item>
    <item>
      <title><![CDATA[So Logically, If She Weighs The Same As A DuckShes A Witch!]]></title>
      <link>http://securityratty.com/article/3fa3a2c5641e284f4fc5fc76430d2faa</link>
      <guid>http://securityratty.com/article/3fa3a2c5641e284f4fc5fc76430d2faa</guid>
      <description><![CDATA[I usually try to stay far away from politics and current events, but my friend Rich has put up a blog post blaming the credit crisis on quantitative analysis, and then positing that because the...]]></description>
      <content:encoded><![CDATA[<p>I usually try to stay far away from politics and current events, but my friend <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich has put up a blog post</a></strong> blaming the credit crisis on quantitative analysis, and then positing that because the economy sucks, Information Security should be only qualitative.</p>
<p>Now I&#8217;ve been &#8220;accused&#8221; of being a quant in the past (hi rybolov!) but in reality the only dogs I have in this fight are the model and the application of scientific method - and really, ethically speaking, I have to be tied to the latter while applying the former.</p>
<p>And I see a false dichotomy in this whole Quant vs. Qual thing.  We, as a profession, tend to create a political divide between the two which, if it even exists, I&#8217;d say is based more on our ignorance rather than our expertise.  After all, we are the profession that regularly multiplies across ordinal scales and uses wonderful models like R=VxTxI.   As someone  learning to deal in probabilities and rationalism, I have to recognize that this discussion is really just about the act of observation using different metrics of measurement.</p>
<p>But how we&#8217;re going about observing does not change the fact that there is measurement based on observation.  So if I&#8217;m working with you I can easily turn your qualitative scale into a quantitative one, and vice-versa.  Yes, Shrdlu, if we had the time, even your most seemingly Qual things could be Quant! (This flexible world view, btw, is an outcome of that new-fangled Bayesian thing).</p>
<p><strong>COGNITIVE BIAS A-PLENTY</strong></p>
<p>But back to what Rich is saying there about information security and risk - and he isn&#8217;t/won&#8217;t be the only one saying these sorts of things - we should try to understand what&#8217;s really going on rather than get caught up in the emotional hurricane.  Our profession suffers several forms of cognitive bias.  The nature of our jobs and what we do can cause us to be focused on the outcome and not the quality of the decision at the time it was made.  We want to bring in things from other professions that are useful, but at times we do view things outside our profession with false correlation to our own (unfortunately for those who write these sorts of articles, financial risk is <em><strong>completely different</strong></em> than operational risk).  We also have the tendency to focus on negative outcomes without acknowledging the positive outcomes (For example, I hear that Alan Greenspan&#8217;s new firm is up a couple of $billion in all this mess since he joined them, short sellers are doing quite well - must be because they have qualitative models or something <em>-grin-</em>).  The effect of these biases are compounded by the facts that proper correlation takes more work than we usually give it, and rational thought is not that easy when there&#8217;s a witch-hunt mentality.</p>
<div class="wp-caption alignnone" style="width: 257px"><a href="http://www.youtube.com/watch?v=zrzMhU_4m-g"><img src="http://www.riskmanagementinsight.com/media/images/weblog/peasants.png" alt="Burn her anyway!" width="247" height="219" /></a><p class="wp-caption-text">What also floats in water? (link to Youtube)</p></div>
<p><strong>WHAT SHOULD WE BE THINKING ABOUT?</strong></p>
<p>So as you and I read opinions that seem to be the polar opposite of irrational exuberance (and there will be plenty between now and the election) we&#8217;ll have to ask ourselves, &#8220;what really failed here?&#8221;  At the risk (pun) of over-simplification:</p>
<ul>
<li>Was There an Error on the part of Probability Theory?</li>
</ul>
<p>After all, Probability Science like all other fields of knowledge is always &#8220;advancing&#8221; as they say.  So perhaps probability theory is wrong somehow?</p>
<p>I&#8217;m personally disinclined to put the blame here, primarily because I would think that there would be evidence from other fields (like Quantum Mechanics) that something is amiss waaaaay before it hit a field like economics.</p>
<ul>
<li>Was There Error In The Model Used to Determine Risk?</li>
</ul>
<p>Some people who understand real estate valuation and complex derivatives and financial risk want to put the blame here.  It&#8217;s a little too early to tell, but one thing is for sure - Financial risk is so different from operational risk I couldn&#8217;t begin to hazard an opinion on the subject.   But it would seem that this is really somewhere we might look.</p>
<ul>
<li>Was There Error In The  Scale Used (Quantitative vs. Qualitative)?</li>
</ul>
<p>Honestly?  I find it extremely difficult to understand how this could be the source of financial ruin.</p>
<ul>
<li>Was There Error on the part of the Decision Maker?</li>
</ul>
<p>What if all of the above were just fine, and the decision maker chose short term gain over long term stability?  What if this was (to simplify the matter greatly) a choice of &#8220;heads&#8221; over &#8220;tails&#8221; and the coin landed on tails?  What if the model represented the right risk (probability of negative outcome vs. positive outcome), but the complex derivative was sold to someone else who had poor &#8220;risk management&#8221; (ability to make a good decisions)?</p>
<p>Now I have no clue about complex derivatives, and I&#8217;m oversimplifying to be sure - chances are like most things, there are several problems that helped create the primary cause. But it seems to me that as we go into incident response mode for the economy, it&#8217;s more helpful to do so in a rational, logical manner.<br />
<strong><br />
OTHER THINGS WE MIGHT WANT TO CONSIDER</strong></p>
<p><span style="color: #008000;"><strong>Consider the Source</strong></span><br />
Some authors (who I think tend to exploit outcome and hindsight bias,and then combine those with indirect ad hominem attacks in order to sell their books), are actually putting forth arguments against the use of analytics.  The source of this is a current epistemic debate between those who believe that only falsification is certain, and those who maintain that neither proof nor falsification are certain, there are only probabilities.    So before you go believing any &#8220;quadrants&#8221; of usefulness on faith - I encourage you to understand what is at the heart of the discussion.<br />
<span style="color: #008000;"><strong><br />
We All Have to Live In The Real World</strong></span><br />
The sun will rise tomorrow, and someone will try to find the source of the problem and do a better job.  Now chances are, they&#8217;ll be doing it in a quantitative manner.  Chances are also that at some point their models will fail and we&#8217;ll need to build new ones.  And this will happen whether the field is cosmology, economics, meteorology, information security, or professional baseball.<br />
<strong><br />
WHAT ABOUT YOU, ALEX?</strong></p>
<p>I&#8217;m far from certain and subject to change, but these days I lean towards <strong><a href="http://www.overcomingbias.com/2008/09/who-to-blame.html">Robin Hanson &amp; MIchael Lewis</a></strong> w/regards to placing blame.</p>
]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 10:59:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/financial risk">financial risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/operational risk">operational risk</category>
      <category domain="http://securityratty.com/tag/outcome">outcome</category>
      <category domain="http://securityratty.com/tag/exploit outcome">exploit outcome</category>
      <category domain="http://securityratty.com/tag/probability">probability</category>
      <category domain="http://securityratty.com/tag/qualitative models">qualitative models</category>
      <category domain="http://securityratty.com/tag/models">models</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=420">So Logically, If She Weighs The Same As A DuckShes A Witch!</source>
    </item>
    <item>
      <title><![CDATA[The NSA Teams Up with the Chinese Government to Limit Internet Anonymity]]></title>
      <link>http://securityratty.com/article/503f5010550f387cf3db2d9c00072cbb</link>
      <guid>http://securityratty.com/article/503f5010550f387cf3db2d9c00072cbb</guid>
      <description><![CDATA[Definitely strange bedfellows : A United Nations agency is quietly drafting technical standards, proposed by the Chinese government, to define methods of tracing the original source of Internet...]]></description>
      <content:encoded><![CDATA[<p>Definitely <a href="http://news.cnet.com/8301-13578_3-10040152-38.html">strange bedfellows</a>:</p>

<blockquote>A United Nations agency is quietly drafting technical standards, proposed by the Chinese government, to define methods of tracing the original source of Internet communications and potentially curbing the ability of users to remain anonymous.

<p>The U.S. National Security Agency is also participating in the "IP Traceback" drafting group, named Q6/17, which is meeting next week in Geneva to work on the traceback proposal. Members of Q6/17 have declined to release key documents, and meetings are closed to the public.</p>

<p>[...]</p>

<p>A second, <a href="http://politechbot.com/docs/itu.traceback.use.cases.requirements.091108.txt">apparently leaked ITU document</a> offers surveillance and monitoring justifications that seem well-suited to repressive regimes:</p>

<blockquote>A political opponent to a government publishes articles putting the government in an unfavorable light. The government, having a law against any opposition, tries to identify the source of the negative articles but the articles having been published via a proxy server, is unable to do so protecting the anonymity of the author.</blockquote></blockquote>

<p>This is being sold as a way to go after the bad guys, but it won't help.  Here's Steve Bellovin <a href="http://www.cs.columbia.edu/~smb/blog/2008-09/2008-09-04.html">on that issue</a>:</p>

<blockquote>First, very few attacks these days use spoofed source addresses; the real IP address already tells you where the attack is coming from. Second, in case of a DDoS attack, there are too many sources; you can't do anything with the information. Third, the machine attacking you is almost certainly someone else's hacked machine and tracking them down (and getting them to clean it up) is itself time-consuming.</blockquote>

<p>TraceBack is most useful in monitoring the activities of large masses of people.  But of course, that's why the Chinese and the NSA are so interested in this proposal in the first place.</p>

<p>It's hard to figure out what the endgame is; the U.N. doesn't have the authority to impose Internet standards on anyone.  In any case, this idea is counter to the U.N. Universal Declaration of Human Rights, Article 19:  "Everyone has the right to freedom of opinion and expression; this right includes freedom to hold opinions without interference and to seek, receive and impart information and ideas through any media and regardless of frontiers."   In the U.S., it's counter to the First Amendment, which has long permitted anonymous speech.  On the other hand, basic human and constitutional rights have been jettisoned left and right in the years after 9/11; why should this be any different?</p>

<p>But when the Chinese government and the NSA get together to enhance their ability to spy on the world, you have to wonder what's gone wrong with the world.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=ROw6L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=ROw6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dQUlL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dQUlL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 02:34:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/chinese government">chinese government</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/articles">articles</category>
      <category domain="http://securityratty.com/tag/negative articles">negative articles</category>
      <category domain="http://securityratty.com/tag/government publishes articles">government publishes articles</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/proposal">proposal</category>
      <category domain="http://securityratty.com/tag/original source">original source</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/the_nsa_teams_u.html">The NSA Teams Up with the Chinese Government to Limit Internet Anonymity</source>
    </item>
    <item>
      <title><![CDATA[Fun Financial News Economic Meltdown Overdue?]]></title>
      <link>http://securityratty.com/article/7157e87c54b6bdfad599ca7e480ffb51</link>
      <guid>http://securityratty.com/article/7157e87c54b6bdfad599ca7e480ffb51</guid>
      <description><![CDATA[Are we in the biggest and best economic recession-turned-depression since the 1930s
If you look at the news, youll see layoffs, buyouts, bankruptcy, going-out-of-business there are a lot of companies...]]></description>
      <content:encoded><![CDATA[<p>Are we in the biggest and best economic recession-turned-depression since the 1930s?</p>
<p>If you look at the news, you&#8217;ll see layoffs, buyouts, bankruptcy, going-out-of-business&#8211; there are a lot of companies in trouble right now</p>
<p><a rel="nofollow" target="_blank" href="http://richi.co.uk/blog/2008/09/bye-bye-ebay.html">Ebay</a> &#8212; laying off around 1500 workers.</p>
<p><a rel="nofollow" target="_blank" href="http://www.pdnonline.com/pdn/content_display/esearch/e3ic20afe7664ada9ef8f01ffe7285b913e">Corbis</a> &#8212; Cutting 170 Jobs, as its start-up rival <a rel="nofollow" target="_blank" href="http://www.pdnonline.com/pdn/content_display/esearch/e3iaf02e0820238924b90d20260893cac71">Photoshelter </a>closes its doors.</p>
<p><a rel="nofollow" target="_blank" href="http://www.forbes.com/feeds/ap/2008/09/15/ap5427610.html">Washington Mutual </a>in trouble</p>
<p><a rel="nofollow" target="_blank" href="http://www.informationweek.com/news/services/outsourcing/showArticle.jhtml?articleID=210601748">HP </a>cutting 24,600 jobs</p>
<p><a rel="nofollow" target="_blank" href="http://uk.reuters.com/article/bankingfinancial-SP/idUKN1551539520080915">B of A </a>&#8211; stocks tumble as the bank buys Merrill Lync</p>
<p><a rel="nofollow" target="_blank" href="http://www.bloomberg.com/apps/news?pid=20601039&amp;refer=columnist_pauly&amp;sid=a.o3AnmqPqwU">Fannie Mae and Freddie Mac</a> taken over by the Feds a couple weeks back</p>
<p>I&#8217;ve read in many places that even though the economy is headed under, tech is still going strong. But with fewer jobs overall and less confidence, tech is sure to take a tumble as well. These are tough times that aren&#8217;t going to be solved by going out and buying buttons for your favorite political candidate.</p>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 13:00:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fewer jobs">fewer jobs</category>
      <category domain="http://securityratty.com/tag/jobs">jobs</category>
      <category domain="http://securityratty.com/tag/tumble">tumble</category>
      <category domain="http://securityratty.com/tag/stocks tumble">stocks tumble</category>
      <category domain="http://securityratty.com/tag/freddie mac">freddie mac</category>
      <category domain="http://securityratty.com/tag/economic">economic</category>
      <category domain="http://securityratty.com/tag/favorite political">favorite political</category>
      <category domain="http://securityratty.com/tag/tough times">tough times</category>
      <category domain="http://securityratty.com/tag/fannie mae">fannie mae</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/393695005/">Fun Financial News Economic Meltdown Overdue?</source>
    </item>
    <item>
      <title><![CDATA[Another VMware Founder Leaves]]></title>
      <link>http://securityratty.com/article/8e31d391fee4200c824ddc048a2d952b</link>
      <guid>http://securityratty.com/article/8e31d391fee4200c824ddc048a2d952b</guid>
      <description><![CDATA[Im getting a little depressed for my upcoming trip to Vegas next week. Instead of a festive party atmosphere, I fear VMworld (and especially the Partner Day on Monday) is going to consist of a bunch...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="Rosenblum_VMware" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/rosenblum-vmware.jpg" width="164" align="left" border="0"> I’m getting a little depressed for my upcoming trip to Vegas next week. Instead of a festive party atmosphere, I fear <a href="http://www.vmworld.com/conferences/2008/" target="_blank">VMworld</a> (and especially the Partner Day on Monday) is going to consist of a bunch of long faces on people wondering whether they should have gone to the <a href="https://www.getvirtualnow.com/main.aspx" target="_blank">Microsoft virtualization party</a> instead.
<p>Just a few months after CEO and founder <a href="http://blog.sciencelogic.com/diane-greene-ousted-from-vmware/07/2008">Diane Greene was ousted</a>, it <a href="http://www.virtualization.info/2008/09/mendel-rosenblum-co-founder-and-chief.html" target="_blank">comes as no surprise</a> that her <a href="http://virtualization.com/news/2008/09/09/mendel-rosenblum-vmware/" target="_blank">husband and co-founder</a>, <a href="http://www.nytimes.com/2008/09/09/technology/09vmware.html?_r=1&amp;oref=slogin" target="_blank">Mendel Rosenblum, has also resigned</a> via a company wide message last night. Turns out he’s going back to Stanford to teach. What a lovely way to get out of the political mess VMware has become. Admit it, haven’t we all had a point where we get fed up with the latest work snafu and wondered, maybe I should go back to college and teach? I had a really good time in college… Kudos to Rosenblum for doing it and doing it in style.
<p>And if you believe <a href="http://www.tarrysingh.blogspot.com/2008/09/vmware-co-founder-mendel-rosenblum.html" target="_blank">Tarry Singh</a>, <a href="http://blog.scottlowe.org/2008/09/09/as-expected-rosenblum-leaves-vmware/" target="_blank">the company knew</a> this was going to happen but waited until after registrations were closed for VMworld before making it official. Hmm.
<p>From the New York Times, more on Greene’s firing and just <a href="http://www.iht.com/articles/2008/09/09/technology/09vmware.php" target="_blank">what kind of atmosphere</a> is forcing executives to leave VMware:<br />
<blockquote>
<p>After Ms. Greene made a special presentation to VMware’s board, Mr. Tucci, who heads VMware’s parent company, EMC, pulled her aside, according to people familiar with the events, who asked for anonymity because they were not authorized to discuss internal company decisions.
<p>Inviting Mendel Rosenblum, Ms. Greene’s husband and the co-founder of VMware, into the room, Mr. Tucci told Ms. Greene she was fired, effective immediately. And he said the board wanted Mr. Rosenblum, VMware’s chief scientist, to take her seat on the board. Mr. Rosenblum declined the offer.</p>
</blockquote>
<p>Honestly, what kind of a judgement call was made to first <a href="http://www.datacenterknowledge.com/archives/2008/09/09/rosenblum-leaves-vmware/" target="_blank">fire the man’s wife in front of him</a> and then offer him her board seat? Has Tucci never seen an episode of Survivor?</p>
]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 15:23:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/board seat">board seat</category>
      <category domain="http://securityratty.com/tag/board">board</category>
      <category domain="http://securityratty.com/tag/rosenblum">rosenblum</category>
      <category domain="http://securityratty.com/tag/mendel rosenblum">mendel rosenblum</category>
      <category domain="http://securityratty.com/tag/political mess vmware">political mess vmware</category>
      <category domain="http://securityratty.com/tag/founder diane greene">founder diane greene</category>
      <category domain="http://securityratty.com/tag/greene">greene</category>
      <category domain="http://securityratty.com/tag/vmwares board">vmwares board</category>
      <source url="http://blog.sciencelogic.com/another-vmware-founder-leaves/09/2008">Another VMware Founder Leaves</source>
    </item>
    <item>
      <title><![CDATA[Business In Thailand - Part 1: The Challenge]]></title>
      <link>http://securityratty.com/article/9f1f804e00135ef904eb97970171c32e</link>
      <guid>http://securityratty.com/article/9f1f804e00135ef904eb97970171c32e</guid>
      <description><![CDATA[Recently someone asked about business in Thailand.Here is my first post on this challenging topic
First of all, as background information, I learned the Thai alphabet(script with 44 consonants and 32...]]></description>
      <content:encoded><![CDATA[<p>Recently someone asked about business in Thailand.  Here is my first post on this challenging topic:</p>
<p>First of all, as background information, I learned the Thai alphabet (script with 44 consonants and 32 vowels) nearly 20 years ago, so I have have a pretty decent foundation for the Thai language compared to most foreigners visting or working in Thailand.   I can read (slowly) and speak better than 99.99+ percent of all foreigners in Thailand.  For this reason, I thought it was &#8221;the right thing to do&#8221; to redirect my career to a &#8220;new challenge&#8221; in the business climate of Thailand as I continue to improve my foreign language skills.   I wanted to help Thailand progress in IT and IT security, so where else would I go but where I have second language skills?</p>
<p>This was no small decision as you can imagine.  Your career and life changes quite dramatically when you give up a long established consulting practice in the US and dive into business in a foreign land, seeking a new challenge.  I can frankly tell you thatit is more difficult to do business in Thailand (as a foreigner) than I expected, for a number of reasons.  Here is my first off-topic post on this topic.</p>
<p>First of all, it is not legal for foreigners to directly own land in Thailand.  Foreigners can &#8221;own&#8221; land using a variety of legal loopholes, proxy owners and shell companies; but all of this is risky and not advised.  Many foreigners lose a lot of money coming to Thailand and attempting to buy land via various &#8220;structures&#8221;.  Some get lucky, but the entire process of foreigners buying and selling land is quite risky and not recommended.</p>
<p>Foreigners can legally own condominiums, under certain conditions, but this &#8220;foreign market&#8221; results in inflated prices for condos in Thailand that are traded in an &#8220;artificial market place&#8221; designed for foreigners.   Condos in Bangkok and major resort areas that are up-to-par with condos in the US can easily cost more than condos in major cities in the US.  Hence, the cost of living in Thailand is not as economical as some might believe when you visit Thailand as a tourist.</p>
<p>Second, business in Thailand can best be described as protectionism with discrimination where the government has placed many barriers to entry to foreigners working and competing in Thailand.     Every foreigner must have a work permit and these work permits are expensive and time consuming to maintain.   If you own a business you must pay high professional service fees for &#8220;auditors&#8221; to perform annual and semiannual audits regardless of how much income you have (including zero).   Firms in Thailand charge thousands of dollars for these &#8221;audits&#8221;.      </p>
<p>Third, if you operate a business in Thailand, you must have a place of business (you cannot legally work from your condo you bought at high prices!), so you are forced, by law, to lease office space.   Foreigners from the US, for example, must be paid a minimum of 50,000 Thai Baht per month, so the government will take 10 percent of that each month as their share of tax withholdings.  Startups with no income simply pay income taxes against their personal savings to comply with the law.  Therefore, to start a company and maintain the business in Thailand, you are required to pay significant startup, monthly, semi-annual and annual fees, permits, tax, leases, visas, etc. </p>
<p>Forth, generating incoming revenue in Thailand can be quite difficult in a climate of both protectionism and discrimination.   In Thailand, it is easy when you are spending money.  This is the &#8221;Land of Smiles&#8221; that tourists see and experience.   However, when you are legally permitted to work in Thailand and trying to generate in-country income, you cannot help but notice the protectionism and discrimination against foreigners working and living here.  Many foreigners working in Thailand just &#8220;give up&#8221; because the barriers to business success are quite high.</p>
<p>Fifth, on top of the challenges of protectionism/discrimination regarding foreigners and foreign investments, which I have only just scratched the surface here, is the overall global business slowdown combined with a climate of political instability which I am sure you have seen in the news.  Thailand has seen 18 coups since 1932.   Currently, <a href="http://www.independent.co.uk/news/world/asia/state-of-emergency-declared-in-thailand-916866.html" target="_blank">Thailand is under a State-of-Emergency </a> which negatively impacts business even more.  Sound challenging? </p>
<p>Most people who live and work in Thailand have the opinion that it is far better to enjoy being a tourist here. Working in Thailand is very difficult for many reasons.   Being a tourist in Thailand is completely different than working here.  When you are a tourist, foreign currently flows from you into Thailand, so life in Thailand as a tourist is fun and friendly, hence the &#8220;Land of Smiles&#8221; you have heard about or experienced.     However, when you are working in Thailand and trying to generate income from Thailand versus bringing in foreign currency, you don&#8217;t see the &#8220;Land of Smiles&#8221; quite the same anymore.</p>
<p>Without getting into too many details in this post, I can simply say that a foreigner doing business in Thailand experiences both protectionism and discrimination.  I came to Thailand hoping to contribute my experience to help the Kingdom.  However, sometimes it feels like foreigners are only welcome if you are working for free, giving seminars for free, and bringing in lots of foreign currency here.</p>
<p>In a future post on business in Thailand I will dive into some details on a number of topics that might be of interest to readers who will never have a chance to come and work here.   </p>
]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 10:16:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/visit thailand">visit thailand</category>
      <category domain="http://securityratty.com/tag/thailand progressin">thailand progressin</category>
      <category domain="http://securityratty.com/tag/thailand chargethousands">thailand chargethousands</category>
      <category domain="http://securityratty.com/tag/lifein thailand">lifein thailand</category>
      <category domain="http://securityratty.com/tag/foreigners">foreigners</category>
      <category domain="http://securityratty.com/tag/foreigners canown">foreigners canown</category>
      <category domain="http://securityratty.com/tag/businessin thailand">businessin thailand</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <source url="http://www.thecepblog.com/2008/09/05/business-in-thailand-part-1-the-challenge/">Business In Thailand - Part 1: The Challenge</source>
    </item>
    <item>
      <title><![CDATA[Business In Thailand - Part 1: The Challenge]]></title>
      <link>http://securityratty.com/article/ea0ac16a8a09729fec092a6a2c0a7e21</link>
      <guid>http://securityratty.com/article/ea0ac16a8a09729fec092a6a2c0a7e21</guid>
      <description><![CDATA[Recently someone asked about business in Thailand.Here is my first post on this topic
First of all, I learned the Thai alphabet nearly 20 years ago, so I have have a pretty good foundation for the...]]></description>
      <content:encoded><![CDATA[<p>Recently someone asked about business in Thailand.  Here is my first post on this topic:</p>
<p>First of all, I learned the Thai alphabet nearly 20 years ago, so I have have a pretty good foundation for the Thai language.   I can read (slowly) and speak better than 99.99+ percent of all foreigners in Thailand; so, I thought it was time to redirect my career to a &#8220;new challenge&#8221; in the business climate of Thailand.   </p>
<p>This was no small decision.  Your career changes dramatically when you give up a successful consulting practice in the US and dive into business in a foreign land for a new challenge.  I can frankly tell you that often the challenge is sometimes overwhelming.    It is quite difficult as a foreigner to do business in Thailand.</p>
<p>First of all, it is not legal for foreigners to own land in Thailand.  Foreigners can &#8221;own&#8221; land using a variety of legal loopholes, proxy owners and shell companies; but all of this is risky and not advised.  Foreigners lose a lot of money coming to Thailand and attempting to buy land.  Some get lucky, but the entire process of foreigners buying and selling land is quite risky.</p>
<p>Foreigners can own condos, under certain conditions, but this results in  inflated prices for condos in Thailand that are traded in an artificial market place.   Condos that are up-to-par with condos in the US can easily cost more than condos in major cities in the US.  Hence, the cost of living is not as cheap as some might believe.</p>
<p>Business can best be described as &#8220;protectism&#8221; where the government has placed many barriers to entry to foreigners working in Thailand.     Every foreigner must have a work permit and these work permits are expensive and time consuming to maintain.   If you own a business you must pay high professional service fees for auditors to perform annual and semiannual audits even if your business has no income yet.   Firms in Thailand charge thousands of dollars for these &#8221;audits&#8221;.      </p>
<p>In addition, if you operate a business, you must have a place of business, so you are forced to lease office space.   Foreigners from the US must be paid a minimum of 50,000 Thai Baht per month, so the government will take 10 percent of that each month as their share of tax withholdings.   Therefore, to start a company, you will pay a lot of money in startup fees, permits, tax, leases, visas, etc.  The entire system is designed to secure money from you, even if you do not have a penny of incoming revenue.</p>
<p>Of course, generating incoming revenue can be quite difficult in a climate of protectionism.   In Thailand, it is easy when you are spending money.  When you are trying to generate income from Thailand, as a foreigner the challenge can seem overwhelming at times.   Many foreigners here give up because the barriers to business here are very high.</p>
<p>On top of all these challenges, which I have not described in detail, is the overall global business slowdown combined with a climate of political instability, which I am sure you have seen in the news.  </p>
<p>Most people I know say it is better to be a tourist here.   Being a tourist is completely different.  Money flows from you, so life in Thailand is fun and friendly, complimentary to the &#8220;Land of Smiles&#8221; you have heard about.     However, when you are working to have money flow the other direction, flow to you versus away from you, you don&#8217;t see the &#8220;Land of Smiles&#8221; as tourists experience.</p>
<p>Without getting into too many details, I can simply say that a foreigner doing business in Thailand experiences protectionism and, to a certain degree, discrimination, and sometimes I wonder if coming here for a &#8220;business challenge&#8221; was a good idea.    I was seeking a &#8220;new challenge&#8221; and I got more than I bargained for!</p>
<p>In a future post on business in Thailand I will discuss issues regarding how little value is placed in intellectual property in Thailand and how this adversely impacts professional services.    I will also touch on how this lack of regard for intellectual property impacts a consulting practice.   Also, I will touch on some cultural differences in how Thais appear to view teamwork, which is very different than in the US.</p>
<p> </p>
]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 10:16:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/challenge">challenge</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/business challenge">business challenge</category>
      <category domain="http://securityratty.com/tag/global business slowdown">global business slowdown</category>
      <category domain="http://securityratty.com/tag/thailand chargethousands">thailand chargethousands</category>
      <category domain="http://securityratty.com/tag/foreigners">foreigners</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/money flows">money flows</category>
      <source url="http://www.thecepblog.com/2008/09/04/business-in-thailand-part-1-the-challenge/">Business In Thailand - Part 1: The Challenge</source>
    </item>
  </channel>
</rss>
