<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: rev]]></title>
    <link>http://securityratty.com/tag/rev</link>
    <description></description>
    <pubDate>Fri, 09 May 2008 10:59:51 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links List 8.22.08]]></title>
      <link>http://securityratty.com/article/e37289e3f28c0134060472b8a33b4f97</link>
      <guid>http://securityratty.com/article/e37289e3f28c0134060472b8a33b4f97</guid>
      <description><![CDATA[Ah, the opening ceremonies of the Olympics. How spectacular. Is that Li Ning running in the sky with the torch? Oooh, aah. And wait, whats that image on the wall behind him? Looks kinda familiaroops,...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="170" alt="bsod_nest_main2" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/bsod-nest-main2.jpg" width="244" align="left" border="0"> Ah, the opening ceremonies of the Olympics. How spectacular. Is that Li Ning “running” in the sky with the torch? Oooh, aah. And wait, what’s that image on the wall behind him? Looks kinda familiar…oops, it’s an <a href="http://weblog.infoworld.com/robertxcringely/archives/2008/08/geek_week_tk_tk_1.html?source=NLC-NOTES&amp;cgd=2008-08-18" target="_blank">XP blue screen of death</a>….I wonder how much Microsoft paid for advertising during the Olympics?
<p><em>(</em><a href="http://cache.gizmodo.com/assets/images/gizmodo/2008/08/bsod_nest_main2.jpg" target="_blank"><em>Photo Credit: Gizmodo</em></a><em>)</em>
<p>You lose some. You win some: Of course as NBC’s online partner, Microsoft gets a least a cut of the <a href="http://www.paidcontent.org/entry/419-online-ad-spend-tied-to-olympics-expected-to-reach-100-million/" target="_blank">$100 million dollars in online advertising</a> spent around the Olympics. And the millions of <a href="http://www.businessweek.com/technology/content/aug2008/tc20080820_627259.htm?campaign_id=rss_daily" target="_blank">downloads of Silverlight</a> aren’t too shabby either.
<p>The Internet is Falling! Arbor Networks, a security and network management company, partnered with ninety network services and content providers from around the world to publish an extensive <a href="http://www.circleid.com/posts/88181_largest_study_of_ipv6_traffic/" target="_blank">study of IPv6 traffic</a> on the Internet. Craig Labovitiz, Arbor Networks chief scientist, stated that <a href="http://asert.arbornetworks.com/2008/8/the-end-is-near-but-is-ipv6/" target="_blank">only 900 days were left until the end of the Internet</a>, or at least the exhaustion of IPv4 registry allocations. For the past year, the study shows very little IPv6 traffic – something like 1/100<sup>th</sup> of 1% of Internet traffic. Craig credits this to money issues. “The department of commerce estimates it will cost $25 billion for ISPs to upgrade to native IPv6.”
<p>Blogger <a href="http://blog.jamesurquhart.com/2008/08/cloud-computing-bill-of-rights.html" target="_blank">James Urquhart created a bill of rights for cloud computing</a>. The purpose of the bill is to “help guide would-be cloud customers to those clouds best able to guarantee their freedom.” The blogosphere is a great place to get some open debate going, and I applaud James for trying to make something yet so “cloudy” a bit more clear and concrete. But what’s up with the creating a PAC for this?? (Check out the comments.)
<p>Trying to get by on limited resources? Need more money, staff and the freedom to focus on long-term projects? Sound familiar? Then you just might be in <a href="http://blogs.wsj.com/biztech/2008/08/21/life-is-tough-for-midsize-tech-departments/?mod=djemTECH" target="_blank">IT at a midsize company</a>. (or in marketing at a young but rapidly growing IT company <img src='http://blog.sciencelogic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ) Arrow Enterprise Computing Solutions conducted a survey of 200 tech leaders at midsize companies (500 to 3000 employees). The upside: 61% of those surveyed think they’ll be spending more on IT next year – is this bullish thinking about the economy or how much their own business (rev) will be growing?
<p>Bill Snyder calls Dell “<a href="http://weblog.infoworld.com/tech-bottom-line/archives/2008/08/michael_dell_is.html?source=NLC-DAILY&amp;cgd=2008-08-21" target="_blank">Bozo of the Month</a>” for trying to trademark “cloud computing”. Yikes. Maybe not a “bozo” move but certainly inadvisable given how ubiquitous the term is. Here’s <a href="http://blog.sciencelogic.com/no-trademark-for-cloud-computing/08/2008" target="_blank">our take</a> on it.</p>
]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 16:15:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network management company">network management company</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet traffic">internet traffic</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/nbcs online partner">nbcs online partner</category>
      <category domain="http://securityratty.com/tag/ipv6 traffic">ipv6 traffic</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/blogger james urquhart">blogger james urquhart</category>
      <category domain="http://securityratty.com/tag/ninety network services">ninety network services</category>
      <source url="http://blog.sciencelogic.com/links-list-82208/08/2008">Links List 8.22.08</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Car-Fi, Boston Ferry-Fi, Thai-Fi]]></title>
      <link>http://securityratty.com/article/2c859bc4acfb354040b0928482e21bd1</link>
      <guid>http://securityratty.com/article/2c859bc4acfb354040b0928482e21bd1</guid>
      <description><![CDATA[Chrysler offers automotive Internet access as 2009 model option: All its newest cars and trucks will, for an undisclosed price, act as cellular relays over Wi-Fi. The news was leaked and details...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://latimesblogs.latimes.com/technology/2008/06/chrysler-to-tur.html?cid=120125120#comments"><strong>Chrysler offers automotive Internet access as 2009 model option:</strong></a> All its newest cars and trucks will, for an undisclosed price, act as cellular relays over Wi-Fi. The news was leaked and details should be available tomorrow. The LA Times writer notes that while only passengers should use the Internet while the car is in motion, there's no way to prevent the driver from surfing. Except common sense. Yeah, that'll work. (The writer has confused his megas and kilos; the likely EVDO Rev. A service that will power this system runs at 600 Kbps to 1.4 Mbps downstream and 350 to 550 Kbps upstream, according to the cell operators.)</p>

<p><a href="http://www.metrobostonnews.com/us/article/2008/06/25/03/0515-66/index.xml"><strong>Boston ferries gain Wi-Fi:</strong></a> The MTBA has put Internet access on its 11 commuter boats that serve 4,500 daily riders. Ridership is way up this year.</p>

<p><a href="http://afp.google.com/article/ALeqM5g_cp1eD_monzp7gY9odfRlPpw0cw"><strong>Bangkok builds slow Wi-Fi network, free for first year:</strong></a> The details are a bit sketchy, but the government has built a 15,000-hotspot network that offer 64 Kbps connections, and will be free (with an access card) for the first year. The government is handing out 500,000 such cards at shopping malls before this week's launch.</p>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:43:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kbps upstream">kbps upstream</category>
      <category domain="http://securityratty.com/tag/kbps">kbps</category>
      <category domain="http://securityratty.com/tag/times writer notes">times writer notes</category>
      <category domain="http://securityratty.com/tag/writer">writer</category>
      <category domain="http://securityratty.com/tag/kbps connections">kbps connections</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/000-hotspot network">000-hotspot network</category>
      <category domain="http://securityratty.com/tag/evdo rev">evdo rev</category>
      <source url="http://wifinetnews.com/archives/008378.html">Wee-Fi: Car-Fi, Boston Ferry-Fi, Thai-Fi</source>
    </item>
    <item>
      <title><![CDATA[The "E" word]]></title>
      <link>http://securityratty.com/article/9c24f7bdf82da05d57a6509c3af98480</link>
      <guid>http://securityratty.com/article/9c24f7bdf82da05d57a6509c3af98480</guid>
      <description><![CDATA[I met with a merchant this morning to talk PCI compliance. Like many of the conversations I've had with merchants, things got a bit more interesting when the discussion focused on cardholder data...]]></description>
      <content:encoded><![CDATA[I met with a merchant this morning to talk PCI compliance.  Like many of the conversations I've had with merchants, things got a bit more interesting when the discussion focused on cardholder data protection.
	
They joked that the new rev of the <a href="https://www.pcisecuritystandards.org/pdfs/05-14-08.pdf">PCI Standard, version 1.2</a> -- due out in October -- would eliminate the data protection requirements.  All joking aside, the truth is that data protection isn't going anywhere when it comes to the PCI DSS.  <b>While there are other alternatives, such as hashed indexes, truncation and...</b>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data protection">data protection</category>
      <category domain="http://securityratty.com/tag/data protection requirements">data protection requirements</category>
      <category domain="http://securityratty.com/tag/cardholder data protection">cardholder data protection</category>
      <category domain="http://securityratty.com/tag/talk pci compliance">talk pci compliance</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/pci standard">pci standard</category>
      <category domain="http://securityratty.com/tag/october">october</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <category domain="http://securityratty.com/tag/merchant">merchant</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1294">The "E" word</source>
    </item>
    <item>
      <title><![CDATA[Top 5: Why Customers Consider NAC]]></title>
      <link>http://securityratty.com/article/83f7c84a6d60d185873164921594ef4d</link>
      <guid>http://securityratty.com/article/83f7c84a6d60d185873164921594ef4d</guid>
      <description><![CDATA[On a daily (and nightly) basis I have the wonderful experience of talking to, chatting about, presenting on or asking questions of customers about NAC
At each of these opportunities, I like to ask Why...]]></description>
      <content:encoded><![CDATA[<p>On a daily (and nightly) basis I have the wonderful experience of talking to, chatting about, presenting on or asking questions of customers about NAC. </p><p>At each of these opportunities, I like to ask <em>&#8216;Why are you considering NAC?&#8221;</em><strong> </strong></p><p><strong>Here&#8217;s my Top 5&nbsp;of Why Customers Consider NAC</strong> (or <em>think</em> they want NAC). This is not based on any other organization&#8217;s research or polls, nor is it based on analyst analysis. It&#8217;s not based on forethought or musings of an &#8216;expert&#8217;. It&#8217;s just&nbsp;my personal experience from my daily interactions.</p><p><strong>#1: Endpoint Compliance</strong><br />I put this one first, because I think it&#8217;s the most-hyped and possibly least significant. I know, that&#8217;s harsh, especially when endpoint compliance seems to be the big bat NAC carries around. Truth be told, it&#8217;s more of an &#8216;icing on the cake&#8217; for the people I talk to. Until the auto-remediation features&nbsp;are a little more mature, the idea of checking for much beyond presence of anti-virus and possibly patches is unattractive. Frankly,&nbsp;endpoint compliance for LAN-based devices can be a Charlie Foxtrot except under the most ideal circumstances. There are many large organizations and DoD groups that <em>need</em> endpoint compliance, and that&#8217;s a primary driver for them. For the rest, one of the other reasons below is a primary compelling feature and endpoint checking is just another knob they can play with.</p><p>The lack of fervent interest in endpoint checking is why I had to disagree so strongly with Stiennon&#8217;s when he advises in his NWW article &#8220;<a class="offsite-link-inline" href="http://www.networkworld.com/community/node/27459" target="_blank">Don&#8217;t even bother investing in NAC</a>&#8221;. The entire premise of his issues with NAC center around various endpoing checking. (You can check out <a class="offsite-link-inline" href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/05/stiennon-says-n.html" target="_blank">Shimel&#8217;s response </a>&nbsp;too Stiennon&#8217;s blog here.)</p><p><strong>#2: Guest Access<br /></strong>Believe it or not, the most frequent response I get for &#8220;<em>why are you considering NAC&#8221;</em> is &#8220;<em>guest access&#8221;.</em>&nbsp;Guest access seems to be a thorn in every organization&#8217;s side. It&#8217;s a simple problem with impossibly complex solutions&#8230; <em>or so they think</em>. For years, we&#8217;ve been provisioning safe and secure guest access for&nbsp;customers with the use of clean and simple protocol-less VLANs and so, I know that about 82% of the time, there are much simpler ways to offer guest access than by rolling out a full NAC implementation. If guest access is your primary and <u>only</u> goal with a NAC solution, there&#8217;s probably a better, faster and less expensive solution. If money and time are no object, then NAC can be a good way to get from point A to B and give you a few fun technical trinkets to play with. </p><p><strong>#3: Edge Port Security</strong><br />After guest access, the next thing I hear most is interest in adding edge port security with a <a href="http://www.securityuncorked.com/security-uncorked/2008/4/2/what-is-8021x-heres-a-technology-primer-for-you.html" target="_blank">802.1X</a> NAC solution. (We call this Layer 2 NAC.) I tend to think for the time being, this is NAC&#8217;s sweet spot. Note I said <em>&#8216;for the time being&#8217;</em>, I think this may change in the next 18-24 months. But for now, the ability to lock down edge ports and secure switch-to-switch links is an extremely attractive feature. Outside of the 802.1X protocol, there aren&#8217;t really any other ways to skin this cat. I know what you&#8217;re thinking&#8230; <em>you don&#8217;t have to do NAC to use 802.1X</em>&#8230; and&nbsp;that&#8217;s certainly true, but for a network of any size, NAC makes an 802.1X implementation easier to manage and monitor centrally and gives you more of that NAC icing we all love. </p><p>When the <a href="http://www.securityuncorked.com/security-uncorked/2008/5/9/8021x-rev-ya-heard-it-here-first.html" target="_blank">802.1X-REV</a> comes out (probably early 2009) I think you&#8217;ll see organizations that have previously blown off 1X <em><strong>seriously</strong></em> considering it for all the added security and multi-user support it will bring to the table. </p><p><strong>#4: User &amp; Resource Accounting</strong><br />Unless you have a 3rd party solution or want to dig through mounds of RADIUS syslogs, you probably don&#8217;t have a good way to account for user authentication and accountability of resource access throughout the network. Most vendors&#8217; NAC solutions already have pretty good logging and reporting features built in today. Depending on the solution and integration of other devices, you may even get detailed accounts of which user viewed exactly what, when and from where. This is a great selling point to organizations that are trying to follow strict regulations for accountability of financial or extremely sensitive resources. The standards bodies (IEEE, TNC framework and IETF) are coming out with more and more ways to leverage 3rd party security devices within NAC. The IF-MAP is a great example and we&#8217;ll be seeing more I&#8217;m sure. </p><p><strong>#5: Dynamic VLAN Assignment</strong><br />Lastly, but not least, I hear a lot of customers that are looking for a good way to dynamically provision attributes, such as VLAN assignment and QoS to users or devices. It makes switch configuration and management much simpler, and eliminates the need to assign port-based VLANs. The ability&nbsp;to leverage your existing user directory and define both broad and very granular attributes is certainly a draw, and NAC is a great way to offer that. </p><p><strong>That wraps up my Top 5</strong>. Of course, there are plenty more drivers, both business-based or technology-based, but these are the 5 I hear most. </p><p># # #</p>
]]></content:encoded>
      <pubDate>Sat, 31 May 2008 18:10:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/3rd party solution">3rd party solution</category>
      <category domain="http://securityratty.com/tag/nac solution">nac solution</category>
      <category domain="http://securityratty.com/tag/bat nac carries">bat nac carries</category>
      <category domain="http://securityratty.com/tag/nac center">nac center</category>
      <category domain="http://securityratty.com/tag/vendors nac solutions">vendors nac solutions</category>
      <category domain="http://securityratty.com/tag/offer">offer</category>
      <category domain="http://securityratty.com/tag/offer guest access">offer guest access</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/5/31/top-5-why-customers-consider-nac.html">Top 5: Why Customers Consider NAC</source>
    </item>
    <item>
      <title><![CDATA[802.1X-REV: Ya' Heard it Here First!]]></title>
      <link>http://securityratty.com/article/77082a74453cca4bb68ae0eadef5e8de</link>
      <guid>http://securityratty.com/article/77082a74453cca4bb68ae0eadef5e8de</guid>
      <description><![CDATA[Well, youre not necessarily hearing it hear first, but its likely unless you read IEEE docs religiously (as I do) or read Paul Congdons standards updates at the ProCurve Networking site
If you have no...]]></description>
      <content:encoded><![CDATA[<p>Well, you&#8217;re not <em>necessarily </em>hearing it hear first, but it&#8217;s likely&#8230; unless you read <a href="http://www.ieee.org/" target="_blank">IEEE</a>docs religiously (as I do) or read <a href="http://www.procurve.com/network-pro-news/articles/insiders-look-8021.htm" target="_blank">Paul Congdon&#8217;s standards updates</a> at the ProCurve Networking site. </p><p>If you have no clue what 802.1X is, read <a href="http://www.securityuncorked.com/security-uncorked/2008/4/2/what-is-8021x-heres-a-technology-primer-for-you.html" target="_blank">my recent technology primer </a>first. If you&#8217;re already familiar with 1X, you&#8217;ve probably heard about some of the 802.1X additions- the <strong>802.1AE </strong>(MACSec) and possibly <strong>802.1af </strong>(the key agreement for MACSec)&#8230; but that&#8217;s just the tip of the iceberg, <em>and what&#8217;s hiding underneath will knock your socks off! </em></p><p>We&#8217;re currently at the <strong>802.1X-2004 </strong>edition, with the group working on the REV and hoping for an early-2009 release. When IEEE makes additions (such as AE and af) they&#8217;re just afterthoughts and changes tacked on to the end of the standard. But when they do a <strong>revision </strong>, as they are now, they&#8217;re opening up the whole can of worms and all parts of the standard are opened for evaluation and modification. Yee-haw! </p><p><strong>So, what&#8217;s in this new revision and what can we expect from 802.1X-REV? </strong>That&#8217;s what I wanted to know, and I&#8217;m sure you&#8217;re curious too. I was lucky enough to catch a quick call with<strong> Paul Condon </strong>earlier this week and get some of the inside scoop. Paul is ProCurve Networking&#8217;s CTO, but more importantly for our purposes today, he&#8217;s the Vice<strong> -Chair of the IEEE 802.1 </strong>working group and is intimately involved in 1X and a variety of other networking, security and authentication standards. </p><p><strong>1) Encryption &amp; Key Exchange </strong>: The first goal in updating 802.1X was to add security with encryption, specifically on switch-to-switch links. Of course, with encryption comes the need for fast, secure key exchange, so we ended up with 802.1AE and 802.1af as answers to the first set of goals. The encryption will require hardware refreshes, and vendors are already gearing up for that. The benefits of encryption are pretty obvious, so I won&#8217;t bore you with that. There are some fun little gems hidden in the AE/af set though. Even without using the encryption piece, we&#8217;ll be able to use the key exchange as a means of quickly (in ~4-5 packets) authenticating (or re-authenticating) switches to one another after a reboot. It will be a critical piece for maintaining availability and integrity in the network. And w e can do this piece without a hardware upgrade, which is pretty nifty. </p><p><strong>2) Same-Port Multiuser Support: </strong>Here&#8217;s where the 1X-REV sauce starts tasting really good. The new revision is leveraging some of its security updates to support multi-user modes on a single port. And no, not by using multi-tagged VLANs, this is <em>way </em>cooler than that. In theory, multiple PCs, phones or other connected devices can connect through a single port, which would essentially be running multiple instances of 802.1X, letting each communicate securely. It&#8217;ll be similar in practice to how wireless APs segregate and encrypt traffic between the AP and the endpoint.&nbsp;I&#8217;m sure at first&nbsp;we&#8217;ll see software-based endpoint encryption support and of course, move towards hardware encryption and see NICs with the capability baked in. That&#8217;s still down the road, but the road is getting shorter. </p><p><strong>3) Network Advertisement/Selection </strong>: Now the 1X-REV sauce is the best you&#8217;ve ever had- you&#8217;re gonna want to put this stuff on <em>everything </em>! :) The 3rd goal of the revision is to add support for network advertisements on the wired side- which would be a similar experience to selecting the wireless SSID from a list of ones available on your laptop. But, it&#8217;s happening on your wired switch. <em>Wild, right?</em> They&#8217;re going to leverage the EAPOL types here to communicate from client to network. Imagine the possibilities&#8230; </p><p><strong>All these new functions</strong> and features give 802.1X numerous new use cases. I think you&#8217;ll see parts of these technologies leveraged in various parts of critical networks everywhere. Sponsor ballots come at the end of the year, and they&#8217;re hoping to see something solid and released in early 2009. </p><p><strong>You can see why I&#8217;m excited.</strong> The 802.1X-REV may be the evil stepchild for a while, but it&#8217;s coming. When it does, it&#8217;s going to rock our little network worlds and flip our thinking about wired security and network segregation upside down. </p><p>Of course, you&#8217;ll be seeing more on this from me, so hang in there! </p><p># # # </p>
]]></content:encoded>
      <pubDate>Fri, 09 May 2008 10:59:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/1x-rev">1x-rev</category>
      <category domain="http://securityratty.com/tag/1x-rev sauce starts">1x-rev sauce starts</category>
      <category domain="http://securityratty.com/tag/1x-rev sauce">1x-rev sauce</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/same-port multiuser support">same-port multiuser support</category>
      <category domain="http://securityratty.com/tag/endpoint encryption support">endpoint encryption support</category>
      <category domain="http://securityratty.com/tag/rev">rev</category>
      <category domain="http://securityratty.com/tag/endpoint">endpoint</category>
      <category domain="http://securityratty.com/tag/encryption">encryption</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/5/9/8021x-rev-ya-heard-it-here-first.html">802.1X-REV: Ya' Heard it Here First!</source>
    </item>
  </channel>
</rss>
