<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: rare]]></title>
    <link>http://securityratty.com/tag/rare</link>
    <description></description>
    <pubDate>Tue, 21 Oct 2008 09:58:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Communications During Terrorist Attacks are Not Bad]]></title>
      <link>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</link>
      <guid>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</guid>
      <description><![CDATA[Twitter was a vital source of information in Mumbai: News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the...]]></description>
      <content:encoded><![CDATA[<p>Twitter was a vital <a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article5245059.ece">source of information</a> in Mumbai:</p>

<blockquote>News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the carnage. 

<p>The website has a stream of comments on the attacks which is being updated by the second, often by eye-witnesses and people in the city. Although the chatter cannot be verified immediately and often reflects the chaos on the streets, it is becoming the fastest source of information for those seeking unfiltered news from the scene.</blockquote></p>

<p>But we simply have to be smarter than this:</p>

<blockquote>In the past hour, people using Twitter reported that bombings and attacks were continuing, but none of these could be confirmed. Others gave details on different locations in which hostages were being held. 

<p>And this morning, Twitter users said that Indian authorities was asking users to stop updating the site for security reasons.</p>

<p>One person wrote: "Police reckon tweeters giving away strategic info to terrorists via Twitter".</blockquote></p>

<p><a href="http://stephensonstrategies.com/2008/11/26/us-officials-must-monitor-learn-from-use-of-web-20-in-mumbai/">Another link</a>:</p>

<blockquote>I can't stress enough: people can and will use these devices and apps in a terrorist attack, so it is imperative that officials start telling us what kind of information would be relevant from Twitter, Flickr, etc. (and, BTW, what shouldn't be spread: one Twitter user in Mumbai tweeted me that people were sending the exact location of people still in the hotels, and could tip off the terrorists) and that they begin to monitor these networks in disasters, terrorist attacks, etc.</blockquote>

<p>This fear is exactly backwards.  During a terrorist attack -- during any crisis situation, actually -- the one thing people can do is exchange information.  It helps people, calms people, and actually reduces the thing the terrorists are trying to achieve: terror.  Yes, there are specific movie-plot scenarios where certain public pronouncements might help the terrorists, but those are rare.  I would much rather err on the side of more information, more openness, and more communication.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=slTEO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=slTEO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BvXZO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BvXZO" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 09:02:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/calms people">calms people</category>
      <category domain="http://securityratty.com/tag/twitter user">twitter user</category>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/helps people">helps people</category>
      <category domain="http://securityratty.com/tag/terrorist attacks">terrorist attacks</category>
      <category domain="http://securityratty.com/tag/twitter users">twitter users</category>
      <category domain="http://securityratty.com/tag/exchange information">exchange information</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/communications.html">Communications During Terrorist Attacks are Not Bad</source>
    </item>
    <item>
      <title><![CDATA[Lessons from Mumbai]]></title>
      <link>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</link>
      <guid>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</guid>
      <description><![CDATA[I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details. What we know is horrific, and my sympathy goes out to the survivors of the...]]></description>
      <content:encoded><![CDATA[<p>I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details.  What we know is horrific, and my sympathy goes out to the survivors of the dead (and the injured, who often seem to get ignored as people focus on death tolls).  Without discounting the awfulness of the events, I have some initial observations:</p>

<ul><li>Low-tech is very effective.  <a href="http://www.schneier.com/essay-087.html">Movie-plot threats</a> -- terrorists with crop dusters, terrorists with biological agents, terrorists targeting our water supplies -- might be what people worry about, but a bunch of trained (we don't really know yet what sort of training they had, but it's clear that they <a href="http://www.news.com.au/couriermail/story/0,23739,24726093-954,00.html">had some</a>) men with guns and grenades is all they needed.

<p><li>At the same time, the attacks were surprisingly ineffective.  I can't find exact numbers, but it seems there were about 18 terrorists.  The latest toll is 195 dead, 235 wounded.  That's 11 dead, 13 wounded, per terrorist.  As horrible as the reality is, that's much less than you might have thought if you imagined the movie in your head.  Reality is <a href="http://www.pebbleandavalanche.com/weblog/2008/11/30/blog-20081130T1857">different</a> from the movies.</p>

<p><li>Even so, terrorism is rare.  If a bunch of men with guns and grenades is all they really need, then why isn't this sort of terrorism more common?  Why not in the U.S., where it's easy to get hold of weapons?  It's because terrorism is very, very rare.</p>

<p><li>Specific countermeasures don't help against these attacks.  None of the high-priced countermeasures that defend against specific tactics and specific targets made, or would have made, any difference: photo ID checks, confiscating liquids at airports, fingerprinting foreigners at the border, bag screening on public transportation, anything.  Even<a href="http://www.upi.com/Top_News/2008/11/29/Executive_says_Taj_hotel_warned_of_attack/UPI-97361228007685/">metal detectors and threat warnings</a> didn't do any good:</p>

<blockquote>"If I look at what we had, which all of us complained about, it could not have stopped what took place," he told CNN. "It's ironic that we did have such a warning, and we did have some measures."

<p>He said people were told to park away from the entrance and had to go through a metal detector. But he said the attackers came through a back entrance.</p>

<p>"They knew what they were doing, and they did not go through the front. All of our arrangements are in the front," he said.</blockquote></ul></p>

<p>If there's any lesson in these attacks, it's not to focus too much on the specifics of the attacks.  Of course, that's not the way we're programmed to think.  We <a href="http://www.schneier.com/essay-171.html">respond to stories</a> and not analysis.  I don't mean to be sympathetic; this tendency is human and these deaths are really tragic.  But eighteen armed people intent on killing lots of innocents will be able to do just that, and last-line-of-defense countermeasures won't be able to stop them.  Intelligence, investigation, and emergency response.  We have to find and stop the terrorists before they attack, and deal with the aftermath of the attacks we don't stop.  There really is no other way, and I hope that we don't let the tragedy lead us into unwise decisions about how to deal with terrorism.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=4dGOO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=4dGOO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qnl9O"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qnl9O" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 05:03:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mumbai terrorist attacks">mumbai terrorist attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/armed people intent">armed people intent</category>
      <category domain="http://securityratty.com/tag/people focus">people focus</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/lessons_from_mu.html">Lessons from Mumbai</source>
    </item>
    <item>
      <title><![CDATA[Online Age Verification]]></title>
      <link>http://securityratty.com/article/725249e5687e0efcc97614f8d3580c39</link>
      <guid>http://securityratty.com/article/725249e5687e0efcc97614f8d3580c39</guid>
      <description><![CDATA[A discussion of the security trade-off : Child-safety activists charge that some of the age-verification firms want to help Internet companies tailor ads for children. They say these firms are...]]></description>
      <content:encoded><![CDATA[<p>A discussion of the <a href="http://www.nytimes.com/2008/11/16/business/16ping.html">security trade-off</a>:</p>

<blockquote>Child-safety activists charge that some of the age-verification firms want to help Internet companies tailor ads for children. They say these firms are substituting one exaggerated threat -- the menace of online sex predators -- with a far more pervasive danger from online marketers like junk food and toy companies that will rush to advertise to children if they are told revealing details about the users.</blockquote>

<p>It's an old story: protecting against the rare and spectacular by making yourself more vulnerable to the common and pedestrian.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=ZTmiN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=ZTmiN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=m4F6N"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=m4F6N" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 21 Nov 2008 08:47:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online sex predators">online sex predators</category>
      <category domain="http://securityratty.com/tag/child-safety activists charge">child-safety activists charge</category>
      <category domain="http://securityratty.com/tag/toy companies">toy companies</category>
      <category domain="http://securityratty.com/tag/online marketers">online marketers</category>
      <category domain="http://securityratty.com/tag/pervasive danger">pervasive danger</category>
      <category domain="http://securityratty.com/tag/security trade-off">security trade-off</category>
      <category domain="http://securityratty.com/tag/junk food">junk food</category>
      <category domain="http://securityratty.com/tag/firms">firms</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/online_age_veri.html">Online Age Verification</source>
    </item>
    <item>
      <title><![CDATA[Worm Risk Spurs Critical Microsoft Patch]]></title>
      <link>http://securityratty.com/article/8cf9511bc9ea45e86f1aba005afcf898</link>
      <guid>http://securityratty.com/article/8cf9511bc9ea45e86f1aba005afcf898</guid>
      <description><![CDATA[A scary security flaw that would allow malicious worms to infect one PC and then automatically jump to others prompted Microsoft to release a rare out-of-cycle patch in October. The glitch is critical...]]></description>
      <content:encoded><![CDATA[A scary security flaw that would allow malicious worms to infect one PC and then automatically jump to others prompted Microsoft to release a rare out-of-cycle patch in October. The glitch is critical for both 32-bit and 64-bit versions of Windows XP and Windows Server 2003, and for Windows Server 2000. Microsoft says that targeted attacks exploited the hole prior to the patch's release, and that "detailed exploit code" is currently available online.]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/patch">patch</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <category domain="http://securityratty.com/tag/rare out-of-cycle patch">rare out-of-cycle patch</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/scary security flaw">scary security flaw</category>
      <category domain="http://securityratty.com/tag/malicious worms">malicious worms</category>
      <category domain="http://securityratty.com/tag/64-bit versions">64-bit versions</category>
      <category domain="http://securityratty.com/tag/critical">critical</category>
      <source url="http://www.networkworld.com/news/2008/111308-worm-risk-spurs-critical-microsoft.html?fsrc=rss-security">Worm Risk Spurs Critical Microsoft Patch</source>
    </item>
    <item>
      <title><![CDATA[Former inmate arrested for breaking into prison's IT systems]]></title>
      <link>http://securityratty.com/article/8d9baf63b54eba4f493935e7574eae67</link>
      <guid>http://securityratty.com/article/8d9baf63b54eba4f493935e7574eae67</guid>
      <description><![CDATA[It isn't uncommon for people to go to prison for breaking into corporate computers and stealing data. It's rare, though, for someone to be sent back to jail for breaking into a prison computer system...]]></description>
      <content:encoded><![CDATA[It isn't uncommon for people to go to prison for breaking into corporate computers and stealing data. It's rare, though, for someone to be sent back to jail for breaking into a prison computer system while already serving time for another crime.]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prison">prison</category>
      <category domain="http://securityratty.com/tag/prison computer system">prison computer system</category>
      <category domain="http://securityratty.com/tag/uncommon">uncommon</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/rare">rare</category>
      <category domain="http://securityratty.com/tag/crime">crime</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://www.networkworld.com/news/2008/111108-former-inmate-arrested-for-breaking.html?fsrc=rss-security">Former inmate arrested for breaking into prison's IT systems</source>
    </item>
    <item>
      <title><![CDATA[CSI 35th 2008 Discount Passes]]></title>
      <link>http://securityratty.com/article/f1ad94b6283c47c53696f0ea9e012fac</link>
      <guid>http://securityratty.com/article/f1ad94b6283c47c53696f0ea9e012fac</guid>
      <description><![CDATA[Since I am speaking at CSI 35th Annual Conference (on SIEM, believe it or now), I can again give out discount conference passes

The passes cover the full conference, MondayWednesday, November 1719,...]]></description>
      <content:encoded><![CDATA[Since I am speaking at <a href="http://www.csiannual.com/">CSI 35th Annual Conference</a> (on SIEM, believe it or now), I can again give out discount conference passes:<br /><br />"The passes cover the full conference, Monday–Wednesday, November 17–19, 2008, for a <b>55% discount</b>!  To pass along your discount passes, send your guests to <a href="https://www.cmpevents.com/CSI35/a.asp?option=B" target="_blank">CSI 2008 Registration</a> to register for a CSI 2008 Conference Pass and have them enter the below Priority Code in the box provided:  <b>SPK73</b><p><b> </b></p>    <p> </p>   <p> </p>  <p><i>*Please note: This offer is only for new registrations, we cannot re-price current registrations."</i></p><p><span style="font-weight: bold;">UPDATE: THE OFFER BELOW HAVE BEEN TAKEN AS OF 5:00PM Oct 30th.</span><br /></p><p>For those rare people who read all the way to here :-), I can also give our 1 (one!) <span style="font-style: italic;">FREE </span>CSI pass; please email me for it as it will be given on "a first come, first served" basis and can only be used by my loyal blog readers :-)<i><br /></i></p>  <p><i> </i></p><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xLnxM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xLnxM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=HwgSM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=HwgSM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=DAjLM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=DAjLM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/437416234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 11:08:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/discount passes">discount passes</category>
      <category domain="http://securityratty.com/tag/discount">discount</category>
      <category domain="http://securityratty.com/tag/pass">pass</category>
      <category domain="http://securityratty.com/tag/conference pass">conference pass</category>
      <category domain="http://securityratty.com/tag/csi">csi</category>
      <category domain="http://securityratty.com/tag/free csi pass">free csi pass</category>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/discount conference passes">discount conference passes</category>
      <category domain="http://securityratty.com/tag/registrations">registrations</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/437416234/csi-35th-2008-discount-passes.html">CSI 35th 2008 Discount Passes</source>
    </item>
    <item>
      <title><![CDATA[CLOUD COMPUTING - STORMY WEATHER?]]></title>
      <link>http://securityratty.com/article/197c984b8e2d41f0d4763ab1993fed11</link>
      <guid>http://securityratty.com/article/197c984b8e2d41f0d4763ab1993fed11</guid>
      <description><![CDATA[Lots being written about the Cloud , most of it quite dark and gloomy . In fact Im surprised, that Hoff hasnt got a preso spooled up called The Toxic Cloud or something similarly ominous for his next...]]></description>
      <content:encoded><![CDATA[<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/teXOPAFMOp0&amp;hl=en&amp;fs=1" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/teXOPAFMOp0&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p>Lots being <strong><a href="http://techbuddha.wordpress.com/2008/08/29/saas-and-cloud-computing-change-the-cia-paradigm/">written</a></strong> about <strong><a href="http://lastinfirstout.blogspot.com/2008/10/cloud-outsourcing-moved-up-stack.html">the Cloud</a></strong>, most of it quite <a href="http://rationalsecurity.typepad.com/blog/2008/10/will-you-all-please-shut-up-about-securing-the-cloudno-such-thing.html#trackback">dark and gloomy</a>.  In fact I&#8217;m surprised, that Hoff hasn&#8217;t got a preso spooled up called &#8220;The Toxic Cloud&#8221; or something similarly ominous for his next speaking tour.<br />
That said, <strong><a href="http://www.economist.com/opinion/displayStory.cfm?source=hptextfeature&amp;story_id=12471098">the Economist does a great job distilling the issue</a></strong> into a simple statement -</p>
<blockquote><p>Cloud computing is a trade-off between sovereignty and efficiency.</p></blockquote>
<p>Let me ask you -  if you had to put your money on one of those horses, considering your average profit-preoccupied business, which would it be?  I&#8217;d put my bottom dollar on the thoroughbred named &#8220;Cost Center Reduction&#8221;, to place.</p>
<p><strong>WHO ARE WE TO STAND IN THE WAY OF &#8220;PROGRESS&#8221;?</strong></p>
<p>I&#8217;m always fond of Jack&#8217;s rule that the role of information risk management boils down to three deceptively simple premises:</p>
<ul>
<li>Reduce Risk.</li>
<li>Reduce Loss.</li>
<li>Create Operational Efficiencies.</li>
</ul>
<p>So it would seem antithetical to the charter of the Chief Security Officer to stand in the way of progress as embodied by &#8220;cloud computing&#8221; (not to mention dangerous to long-term job security).  And I think that this presents opportunities to discuss strategies for managing risk, strategies that aren&#8217;t too theoretical and have practical application (though actual &#8220;cloud&#8221; use by enterprises may be rare at this point).</p>
<p><strong>ON RISK REDUCTION IN THE CLOUD (or, How To Learn From the Shortcomings of PCI DSS)</strong></p>
<p>The good news is, there&#8217;s already a well-established model for managing the risk around outsourcing the processing of &#8220;confidential&#8221; information.  The bad news is, that model kinda sucks it.</p>
<p>The Payment Card Industry, known as the &#8220;PCI&#8221; or &#8220;<em>meal ticket</em>&#8221; to many in the industry, faced a similar problem with the introduction of GLBA.  As I see it (and I&#8217;m not at all close to the PCI, at all, so this is all just abstract soliloquy) the PCI had one of two choices when faced with the prospect of other people managing their sensitive information:</p>
<ol>
<li>Accept the *massive* amount of GLBA risk their business creates and spend a TON of money to build out the infrastructure (both process and IT) to manage the consumer data themselves (in conjunction with the banks, of course) and never have it grace the computing systems of the retailer.  <em><strong>Or,</strong></em></li>
<li>Transfer the GLBA risk down to the retailer and have them bear the majority of the risk (and cost of reducing risk to a level that might be tolerable to the US Government).</li>
</ol>
<p><span style="color: #999999;"><em>(<a href="http://www.mckeay.net/">Martin</a>, <span style="color: #333333;">you may recall our Twittering about PCI a while back.  This is the crux of my view on the subj.</span>)</em></span></p>
<p>Now fortunately, the CSO&#8217;s of the world are going to be a little more &#8220;invested&#8221; in protecting the information they are stewards over, and unlike the PCI, will remain primarily responsible for the C, I, &amp; A of the data in the Cloud.  The cool thing is, this actually presents a great opportunity to start building a meaningful model for co-management of risk!  In fact, we can take the PCI model of contractual risk transference but modify where it goes all wrong, and start working to create something better.  And we can start by euthanizing some faulty assumptions.</p>
<p><strong>JUST HOW INFORMATIVE IS PCI DSS?</strong></p>
<p>What might be <em><strong>the.greatest.mistake</strong></em> of the standards compliance mentality is the assumption of value for the past-state measurement.  That is, I believe that the CSO needs more than some &#8220;past-state&#8221; assurance in order to understand their risk.    If you look at the concept of &#8220;PCI compliance&#8221; it really is an examination of a past state of nature that is assumed to be relevant to current and future states.   Many people (myself included) are not at all convinced that this past-state is nearly as informative as those who mandate it&#8217;s measurement believe it to be.</p>
<p>That&#8217;s not to condemn past-state measurements as completely non-informative,  they most certainly are useful.  It&#8217;s just that <em><strong>no self-respecting CSO sleeps well because they were deemed &#8220;PCI compliant&#8221;</strong></em> 10 months ago.  They sleep well because they have good visibility into current-state information and confidence in their strategy concerning future-state (based on that visibility and the outcomes of sound IRM models).</p>
<p><strong>MOVING PAST THE VULNERABILITY SCANNER INTO INTELLIGENCE AND WISDOM</strong></p>
<p>So realizing this new importance (to me, at least) concerning visibility and IRM models, I&#8217;m lead to the conclusion that if we are to manage risk in the Cloud, we&#8217;ll have to move beyond &#8220;PCI Compliance&#8221; or the concept that some regular &#8220;audit&#8221; of controls in place at the host is all we need to understand our ability to manage risk.  No, the CSO must have good information concerning current and probable future states.   This is that &#8220;visibility&#8221; I spoke of above.  In fact, we&#8217;ll need significant amounts of <em><strong>piercing, transparent</strong></em> visibility.  And in order to gain that visibility, our insight into Cloud Risk Management must include significant provisions for understanding a joint ability to Prevent/Detect/Respond as well as provisions for managing the risk that one of the participants won&#8217;t provide that visibility or ability via SLA&#8217;s and penalties . These SLA&#8217;s must be expressed in measurable terms (more visibility), and those metrics must have their roots in the things that help understand how we manage risk (those aforementioned IRM models).</p>
<p><strong>THE CLOUD COMPUTING SECURITY SILVER LINING (sorry couldn&#8217;t resist)</strong></p>
<p>As I mentioned earlier, I do see an opportunity to create insight.  The need for visibility and IRM models would allow us to create a &#8220;guidance&#8221; if you&#8217;ll allow me to use the term.  Not a standard or a &#8220;best practice&#8221; to audit by, but simply a reference document that says &#8220;if you&#8217;re going to put information on somebody else&#8217;s systems <em>and still hold some significant responsibility for that information</em>, here&#8217;s the considerations, why they are considerations, and how you might go about collaborating on the management of risk&#8221;.</p>
<p>And I think that if we undertake this journey, there is going to be a lot of growth and risk management innovation along the way.  But keen insights into what it means to manage risk will be necessary, and secure and forthright collaboration will be of absolute importance.</p>
<p>I say that last bit because, if these pundits are right about the utility of a hosted computing model - the Cloud will happen regardless of the CSO&#8217;s ability or desire to manage it.</p>
]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 12:46:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management innovation">risk management innovation</category>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/glba risk">glba risk</category>
      <category domain="http://securityratty.com/tag/glba">glba</category>
      <category domain="http://securityratty.com/tag/reduce risk">reduce risk</category>
      <category domain="http://securityratty.com/tag/risk reduction">risk reduction</category>
      <category domain="http://securityratty.com/tag/toxic cloud">toxic cloud</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=496">CLOUD COMPUTING - STORMY WEATHER?</source>
    </item>
    <item>
      <title><![CDATA[New worm feeds on latest Microsoft bug]]></title>
      <link>http://securityratty.com/article/b47b570498314832b37395ea28af46b6</link>
      <guid>http://securityratty.com/article/b47b570498314832b37395ea28af46b6</guid>
      <description><![CDATA[One day after Microsoft issued a rare emergency Windows security patch, the bad guys have a few new ways to take advantage of the...]]></description>
      <content:encoded><![CDATA[One day after Microsoft issued a rare emergency Windows security patch, the bad guys have a few new ways to take advantage of the bug.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=55763?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=55763?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bad guys">bad guys</category>
      <category domain="http://securityratty.com/tag/bug">bug</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/advantage">advantage</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <source url="http://www.networkworld.com/news/2008/102408-new-worm-feeds-on-latest.html?fsrc=rss-security">New worm feeds on latest Microsoft bug</source>
    </item>
    <item>
      <title><![CDATA[Microsoft to Release Emergency, Out-of-Band Windows Update Today]]></title>
      <link>http://securityratty.com/article/fc4c89c6403b6dba992ce0ead92f3e86</link>
      <guid>http://securityratty.com/article/fc4c89c6403b6dba992ce0ead92f3e86</guid>
      <description><![CDATA[At 10 a.m. Pacific Time today, Microsoft will release an emergency security update for Windows. The details of the vulnerability were not revealed in the Advance Notification Bulletin that Microsoft...]]></description>
      <content:encoded><![CDATA[At 10 a.m. Pacific Time today, Microsoft will release an emergency security update for Windows. The details of the vulnerability were not revealed in <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-oct.mspx">the Advance Notification Bulletin that Microsoft released late last night</a>, but we can assume it's a significant one for Microsoft to go "out of band" and release it before the next scheduled Patch Tuesday, two and a half weeks from now. Out-of-band updates have been rare since Microsoft instituted the regular Patch Tuesday schedule.

The Advance Notification states that the vulnerability affects Windows 2000, Windows XP and Windows Server 2003 and is "critical" for them. It also affects Windows Vista and Windows Server 2008, but is rated "important" for those operating systems.
<p><a href="http://feedads.googleadservices.com/~a/nv4jC4Drb02ze_wUsUU1X-IMAIM/a"><img src="http://feedads.googleadservices.com/~a/nv4jC4Drb02ze_wUsUU1X-IMAIM/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/i8qhXYx2CAg" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 03:36:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/affects windows vista">affects windows vista</category>
      <category domain="http://securityratty.com/tag/vulnerability affects windows">vulnerability affects windows</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/advance notification">advance notification</category>
      <category domain="http://securityratty.com/tag/advance notification bulletin">advance notification bulletin</category>
      <category domain="http://securityratty.com/tag/band">band</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/i8qhXYx2CAg/microsoft_to_release_emergency_out-of-band_windows_update_today.html">Microsoft to Release Emergency, Out-of-Band Windows Update Today</source>
    </item>
    <item>
      <title><![CDATA[Partial Disclosure - The Good, Bad, and Ugly]]></title>
      <link>http://securityratty.com/article/0f6f787360fca21b1b1d9b08ece3672b</link>
      <guid>http://securityratty.com/article/0f6f787360fca21b1b1d9b08ece3672b</guid>
      <description><![CDATA[There is apparently a bit of fear going around information security circles that the next big trend in the disclosure wars is going to be Partial Disclosure. In the past, the vulnerability research...]]></description>
      <content:encoded><![CDATA[<p>There is apparently a bit of fear going around information security circles that the next big trend in the disclosure wars is going to be &#8220;Partial Disclosure&#8221;. In the past, the vulnerability research community has embraced the concepts of &#8220;Full Disclosure&#8221; and/or &#8220;Non-Disclosure&#8221;. Once those concepts had been sufficiently played out, the general consensus was to move towards &#8220;Responsible Disclosure&#8221; whereby the security researcher responsibly discloses the discovered vulnerability to the vendor and works in a cooperative fashion in an effort to minimize the risk to the general user populous. This has worked well in the vast majority of cases that I have had the pleasure of managing the disclosure process.</p>
<p><b>Partial Disclosure - The Good</b></p>
<p>The responsible disclosure process tends to break down in rare occasions where the vendor doesn&#8217;t want to fix the issue. When this occurs, the researcher is put into a difficult position whereby full disclosure could put users&#8217; systems at high risk of compromise. The other case where partial disclosure becomes an alternative is when the researcher has discovered a design flaw in a protocol or underlying multiple vendor component. Examples of this case include the DNS flaws published this past summer by Dan Kaminsky and the TCP denial of service condition discovered by Robert E. Lee and Jack Louis that is currently in the disclosure process. When the flaw affects a very large number of vendors and the actual problem is located within the underlying protocols that support the communications of the Internet as a whole, one possible solution is to follow a partial disclosure model where phasing the details to the general public can be used to encourage adoption and creation of patches throughout the enormous target audience.</p>
<p><b>Partial Disclosure - The Bad</b></p>
<p>What is driving the fear surrounding partial disclosure is the potential for abuse. When a major flaw is partially disclosed, a number of potential issues may occur. First and foremost, the further along the partial disclosure path we are, the more details will be released to the public, and the higher the probability that someone (either good or bad intentioned) will figure out the exploit and disclose the details. Second, when partially disclosing, the vendor&#8217;s hand is being forced into a situation that could speed up fixes, reduce testing, and cause ripple problems elsewhere within the infrastructure. It is difficult enough to dance the fine time line when doing responsible disclosure, but if we are escalated to the point of partial disclosure, additional fuel is added to the fire.</p>
<p><b>The Ugly</b></p>
<p>The real ugly part of partial disclosure is when we add to the equation the ability to spread fear, uncertainty, and doubt into the normal user community. It is generally well accepted that FUD can be used to drive additional revenue. If it is possible to increase the perceived magnitude of the &#8220;problem&#8221; that your product or service solves, it is possible to directly impact the demand for that product or service. That is the major fear imposed by the growing trend of partial disclosure. By releasing just enough information to trigger wide scale speculation into the flaw, it is possible to create buzz and garner media attention resulting in a lot of speculation and very little hard facts around the issue. The potential for abuse by the security industry at large is enormous.</p>
<p><b>The Fix</b></p>
<p>Some have suggested a group of security researchers be convened to vet the requirement of partial disclosure and to allow for independent peer review of any security research that requires the partial disclosure process. This suggestion leaves questions regarding who would stand on this group and who would be impartial enough to ensure that the right thing was always done regardless of profit potential. It also leaves open the opportunity for member researchers to utilize the information gathered during the vetting process to position themselves to profit from the data upon release. It might be wiser to rely on a higher level authority or government entity to manage this process and use the services of security researchers as required for subject matter expertise. While a group of this type wouldn&#8217;t ensure that all partial disclosure is appropriate, it would hopefully limit the potential for abuse and the ever present chance that people try to profit from the FUD that surrounds the current partial disclosure process.</p>
]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 09:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/partial disclosure">partial disclosure</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/responsible disclosure process">responsible disclosure process</category>
      <category domain="http://securityratty.com/tag/partial disclosure process">partial disclosure process</category>
      <category domain="http://securityratty.com/tag/disclosure">disclosure</category>
      <category domain="http://securityratty.com/tag/partial disclosure model">partial disclosure model</category>
      <category domain="http://securityratty.com/tag/responsible disclosure">responsible disclosure</category>
      <category domain="http://securityratty.com/tag/partial disclosure path">partial disclosure path</category>
      <category domain="http://securityratty.com/tag/disclosure andor non-disclosure">disclosure andor non-disclosure</category>
      <source url="http://www.veracode.com/blog/2008/10/partial-disclosure-the-good-bad-and-ugly/">Partial Disclosure - The Good, Bad, and Ugly</source>
    </item>
  </channel>
</rss>
