<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: seat]]></title>
    <link>http://securityratty.com/tag/seat</link>
    <description></description>
    <pubDate>Sun, 03 Aug 2008 09:30:52 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[America's CTO]]></title>
      <link>http://securityratty.com/article/7370017881b0de9957b3253bdde1e5eb</link>
      <guid>http://securityratty.com/article/7370017881b0de9957b3253bdde1e5eb</guid>
      <description><![CDATA[I hope this message gets through to the Obama people - Bill Joy would be an amazingly good pick for the newly created CTO cabinet post. A grand slam to the upper deck. You can count the people with as...]]></description>
      <content:encoded><![CDATA[<p>I hope <a href="http://bits.blogs.nytimes.com/2008/11/05/john-doerrs-advice-for-barack-obama-hire-bill-joy/">this message</a> gets through to the Obama people - Bill Joy would be an amazingly good pick for the newly created CTO cabinet post. A grand slam to the upper deck. You can count the people with as a good a track record in technology on one hand.</p><br /><div>Also, I could not agree more with John Doerr on these points:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">The next question from the president-elect was what single policy issue he could focus on that would most help entrepreneurs.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;"><br /></span><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">“The most important thing he’s got to do is kick-start a huge amount of research and innovation in energy,” said Mr. Doerr, who backed Google and Amazon.com and has invested heavily in clean energy technology for the last few years.</span><br /><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">The nation now invests less than $1 billion a year in renewable energy versus $32 billion a year in health care, Mr. Doerr said. “I think we’ve just scratched the surface in terms of clean ways to use energy, to produce energy. It’s the challenge of our generation.”</span><br /><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">How to do that? Double the number of engineers who graduate from American universities each year to 60,000, Mr. Doerr said. Bring more women into the field, and encourage foreigners who study engineering here to stay here.</span><br /><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px; ">“What we do is bring foreign nationals to the world’s greatest universities. We train them, invest in them and make them go home,” he said. “What kind of national strategy is that? So I would staple a green card to the diploma.”</span></p></blockquote><p><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;"><br /></span></p><div><span style="color: #333333; font-family: georgia; font-size: 10px; "><p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1.4em; line-height: 1.5em; "><span id="more-1803"></span></p></span></div><div><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;">While it is amazing that it took until 2009 for the US to have a CTO as a cabinet level position, it is very cool to think about all the things that could happen going forward. As Neal Stephenson said the US is only world class at three things - 1. Movies, 2. High speed pizza delivery and 3. Software development.</span></div><div><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;"><br /></span></div><div><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;">If you read your </span><a href="http://edgeperspectives.typepad.com/edge_perspectives/">John Hagel</a><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;"> and </span><a href="http://www.johnseelybrown.com/">JSB</a><span style="color: #333333; font-family: georgia; font-size: 14px; line-height: 21px;">, then you know that innovation is the only sustainable edge. Luckily its hard wired into our system, but it will be helpful to have a seat at the table for certain things. &#0160;</span></div>]]></content:encoded>
      <pubDate>Sat, 08 Nov 2008 13:08:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/energy">energy</category>
      <category domain="http://securityratty.com/tag/produce energy">produce energy</category>
      <category domain="http://securityratty.com/tag/renewable energy versus">renewable energy versus</category>
      <category domain="http://securityratty.com/tag/cto">cto</category>
      <category domain="http://securityratty.com/tag/clean energy technology">clean energy technology</category>
      <category domain="http://securityratty.com/tag/clean">clean</category>
      <category domain="http://securityratty.com/tag/doerr">doerr</category>
      <category domain="http://securityratty.com/tag/john doerr">john doerr</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/americas-cto.html">America's CTO</source>
    </item>
    <item>
      <title><![CDATA[New To The Team - Old To The Game]]></title>
      <link>http://securityratty.com/article/e6566b2734036051297af1e2e0797451</link>
      <guid>http://securityratty.com/article/e6566b2734036051297af1e2e0797451</guid>
      <description><![CDATA[Welcome, come on in, have a seat. There is a cold beer in the fridge, help yourself
I may be new to the team, but Im (reasonably) old to the game. My name is Tyler Shields and Im the latest addition...]]></description>
      <content:encoded><![CDATA[<p>Welcome, come on in, have a seat. There is a cold beer in the fridge, help yourself!</p>
<p>I may be new to the team, but I&#8217;m (reasonably) old to the game. My name is Tyler Shields and I&#8217;m the latest addition to the Veracode research team. I started at Veracode in September 2008 as a Senior Security Researcher and have been immediately thrown into the fire. Working for a fast paced, highly energetic company like Veracode, keeps you busy and challenges you every day. I plan to blog on the most interesting pieces of my work with Veracode and hope that you find it enlightening or at the very least entertaining.</p>
<p>In the past I have worked as the security engineer at a .com startup, as an incident response and forensics specialist for the United States Postal Service (think HUGE network), and most recently as a security consultant for @stake and Symantec. I have consulted on engagements for Fortune 500 companies, most major financial institutions, and the highest levels of the United States government. As a consultant my focus was on anything related to application security including, application penetration assessments, product security assessments, secure development lifecycle consulting, and secure application architecture engagements. I lead the @stake/Symantec Application Security Center of Excellence that was used to help guide the knowledge of the global consulting team.  I also spent time as the lead for the Symantec Vulnerability Research program in which a number of interesting vulnerabilities were discovered and publicly released. In my spare time I enjoy reverse engineering and malware research. I recently completed my graduate degree in Information Security/Computer Science from James Madison University in Virginia.</p>
<p>So&#8230; Here&#8217;s to a new job, a new blog poster, and of course lots of fun to come.</p>
]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 09:57:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/veracode">veracode</category>
      <category domain="http://securityratty.com/tag/veracode research team">veracode research team</category>
      <category domain="http://securityratty.com/tag/senior security researcher">senior security researcher</category>
      <category domain="http://securityratty.com/tag/application penetration assessments">application penetration assessments</category>
      <category domain="http://securityratty.com/tag/james madison university">james madison university</category>
      <category domain="http://securityratty.com/tag/consultant">consultant</category>
      <category domain="http://securityratty.com/tag/product security assessments">product security assessments</category>
      <category domain="http://securityratty.com/tag/major financial institutions">major financial institutions</category>
      <source url="http://www.veracode.com/blog/2008/10/new-to-the-team-old-to-the-game/">New To The Team - Old To The Game</source>
    </item>
    <item>
      <title><![CDATA[Hey Kids, How About a Little More Innovation?]]></title>
      <link>http://securityratty.com/article/19a96550c3b572502c4e764066dce91f</link>
      <guid>http://securityratty.com/article/19a96550c3b572502c4e764066dce91f</guid>
      <description><![CDATA[Tim O'Reilly's piece in the LA Times has a lot of people talking

He is urging young entrepreneurs and engineers to stop making some of the sillier software that lets Facebook users throw virtual...]]></description>
      <content:encoded><![CDATA[<p>Tim O&#39;Reilly&#39;s <a href="http://www.latimes.com/business/printedition/la-fi-oreilly10-2008oct10,0,85246.story">piece</a> in the LA Times has a lot of people talking:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">He is urging young entrepreneurs and engineers to stop making some of &#0160;</span><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">the sillier software that lets Facebook users throw virtual sheep at &#0160;</span><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">their friends or download virtual beer on iPhones, and instead start &#0160;</span><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">making a real difference in the world.</span></p><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">He says it&#39;s not just the right thing to do, but also the smart thing &#0160;</span><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">to do -- especially as the credit crunch spreads to Silicon Valley, &#0160;</span><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">venture financing becomes scarce and start-ups have to retrench.</span></p><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">When this grizzled, 54-year-old tech-industry veteran talks, Silicon &#0160;</span><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Valley tends to listen, if only to argue with him.</span></p></blockquote><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></p><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;">This is actually about the 6th time I have heard this this year. I have to say I pretty much agree on the face of it. But I wonder if its not so much a generational question as its that computers are just not as challenging as they used to be. Writing PERL shopping carts and online editors were a challenge in 1995, not so much any more. Maybe the issue is that &quot;kids&quot; of today who want to work on enabling technologies and do real innovation have migrated off to biotechs and nanotechs.&#0160;</span></div><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;">We still have a lot of problems to solve in computers, so don&#39;t get me wrong we can use help from the next generation. But you get the sense the industry is maturing and not this wide open greenfield like biotech and nanotech or early dotcom days. There are a lot of cool things going on, but a lot of it seems like incremental upgrades. Important yes, but earth shattering, not so much. Take for example, </span><a href="http://www.infinera.com/j7/servlet/HomePage">Infinera</a><span style="font-family: Helvetica; font-size: 12px; line-height: normal;">, very cool stuff but its your classic, &quot;we don&#39;t make X, we just make X work better.&quot; product. &#0160;I am not complaining - as an engineer, I like reliability. As a security person, I need better security tools. As a digital citizen, I want things to work better. But you know all of us making better brakes, better airbags, and better seat belts, is not going to be as exciting as the building the first car.&#0160;What was the last computer technology that was mind blowingly innovative to you?</span></div><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 13:25:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/silicon valley">silicon valley</category>
      <category domain="http://securityratty.com/tag/download virtual beer">download virtual beer</category>
      <category domain="http://securityratty.com/tag/cool stuff">cool stuff</category>
      <category domain="http://securityratty.com/tag/credit crunch spreads">credit crunch spreads</category>
      <category domain="http://securityratty.com/tag/cool">cool</category>
      <category domain="http://securityratty.com/tag/mind blowingly innovative">mind blowingly innovative</category>
      <category domain="http://securityratty.com/tag/virtual sheep">virtual sheep</category>
      <category domain="http://securityratty.com/tag/seat belts">seat belts</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/hey-kids-leave-those-sheep-alone-1.html">Hey Kids, How About a Little More Innovation?</source>
    </item>
    <item>
      <title><![CDATA[Hey Kids, Leave Those Sheep Alone]]></title>
      <link>http://securityratty.com/article/41e8a9a82701d0c1e97bcf06b21b217d</link>
      <guid>http://securityratty.com/article/41e8a9a82701d0c1e97bcf06b21b217d</guid>
      <description><![CDATA[Tim O'Reilly's piece in the LA Times has a lot of people talking

He is urging young entrepreneurs and engineers to stop making some of
the sillier software that lets Facebook users throw virtual...]]></description>
      <content:encoded><![CDATA[<p>Tim O&#39;Reilly&#39;s <a href="http://www.latimes.com/business/printedition/la-fi-oreilly10-2008oct10,0,85246.story">piece</a> in the LA Times has a lot of people talking:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">He is urging young entrepreneurs and engineers to stop making some of &#0160;</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">the sillier software that lets Facebook users throw virtual sheep at &#0160;</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">their friends or download virtual beer on iPhones, and instead start &#0160;</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">making a real difference in the world.</span></p><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">He says it&#39;s not just the right thing to do, but also the smart thing &#0160;</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">to do -- especially as the credit crunch spreads to Silicon Valley, &#0160;</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">venture financing becomes scarce and start-ups have to retrench.</span></p><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">When this grizzled, 54-year-old tech-industry veteran talks, Silicon &#0160;</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Valley tends to listen, if only to argue with him.</span></p></blockquote><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></p><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;">This is actually about the 6th time I have heard this this year. I have to say I pretty much agree on the face of it. But I wonder if its not so much a generational question as its that computers are just not as challenging as they used to be. Writing PERL shopping carts and online editors were a challenge in 1995, not so much any more. Maybe the issue is that &quot;kids&quot; of today who want to work on enabling technologies and do real innovation have migrated off to biotechs and nanotechs.</span></div><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;">We still have a lot of problems to solve in computers, so don&#39;t get me wrong we can use help from the next generation. But you get the sense the industry is maturing and not this wide open greenfield like biotech and nanotech or early dotcom days. There are a lot of cool things going on, but a lot of it seems like incremental upgrades. Important yes, but earth shattering, not so much. Take for example, </span><a href="http://www.infinera.com/j7/servlet/HomePage">Infinera</a><span style="font-family: Helvetica; font-size: 12px; line-height: normal;">, very cool stuff but its your classic, &quot;we don&#39;t make X, we just make X work better.&quot; product. &#0160;I am not complaining - as an engineer, I like reliability. As a security person, I need better security tools. As a digital citizen, I want things to work better. But you know all of us making better brakes, better airbags, and better seat belts, is not going to be as exciting as the building the first car.&#0160;What was the last computer technology that was mind blowingly innovative to you?</span></div><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Helvetica; font-size: 12px; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 13:23:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/silicon">silicon</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/silicon valley">silicon valley</category>
      <category domain="http://securityratty.com/tag/download virtual beer">download virtual beer</category>
      <category domain="http://securityratty.com/tag/cool stuff">cool stuff</category>
      <category domain="http://securityratty.com/tag/credit crunch spreads">credit crunch spreads</category>
      <category domain="http://securityratty.com/tag/valley">valley</category>
      <category domain="http://securityratty.com/tag/cool">cool</category>
      <category domain="http://securityratty.com/tag/mind blowingly innovative">mind blowingly innovative</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/hey-kids-leave-those-sheep-alone.html">Hey Kids, Leave Those Sheep Alone</source>
    </item>
    <item>
      <title><![CDATA[Why Risk Management Doesnt Work (?!)]]></title>
      <link>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</link>
      <guid>http://securityratty.com/article/2dce81ab5be406fb5211a9daea174b0c</guid>
      <description><![CDATA[Several folks (Hi Daniel , Brent , David !) sent email &amp; twitters asking us our opinion on a Dark Reading article called Why Risk Management Doesnt Work which if you click on the link should come up...]]></description>
      <content:encoded><![CDATA[<p>Several folks (Hi <a href="http://dmiessler.com/">Daniel</a>, <a href="http://stateofsecurity.com/">Brent</a>, <a href="http://www.twitter.com/debix">David</a>!) sent email &amp; twitters asking us our opinion on a Dark Reading article called &#8220;<a href="http://www.darkreading.com/document.asp?doc_id=165107">Why Risk Management Doesn&#8217;t Work</a>&#8221; which if you click on the link should come up for you after seeing someone&#8217;s advertisement for a few seconds.</p>
<p>I&#8217;m assuming the author wants us to read the title as <strong>&#8220;Things to Look Out For in Performing Risk Analysis&#8221;</strong> and not <strong>&#8220;Risk Management is Folly - Stop, Stop, Stop!&#8221;</strong> The former is fine, the latter isn&#8217;t supported by the evidence presented by the subjects of the article.<br />
The subjects of the article are a <strong><a href="http://www.verizonbusiness.com/resources/security/databreachreport.pdf">good study from Wade Baker &amp; Co. at Verizon</a></strong>, and a report from RSA&#8217;s Security for Business Innovation Council. Let&#8217;s take a look at each of these and examine why what they&#8217;re saying might contribute to poor risk management, shall we?</p>
<p><strong>1.)  THE VERIZON REPORT</strong></p>
<p>The Verizon report is an analysis of some 530 forensic investigations their company performed.  It is well worth your time as it&#8217;s chock full of interesting information.  As it relates to the Dark Reading piece, a coarse summary would be that &#8220;likelihood&#8221; is &#8220;different&#8221; for different people and so you can&#8217;t use the same &#8220;likelihood&#8221; across different industries.</p>
<p>Distilled through the lens of FAIR:</p>
<blockquote><p>&#8220;different threat communities may be applicable based on Probability of Action factors which include: Value, Level of Effort and Risk (of Getting Caught).&#8221;</p></blockquote>
<p>Or, even further distilled and in the words of my six year old son,</p>
<blockquote><p>&#8220;Duh-uh&#8221;.</p></blockquote>
<p>With regards to what I assume is the purpose of the article (What Doesn&#8217;t Work in Risk Analysis) this concept  seems just to rehash the old GIGO argument regarding risk analysis.  Great.  Can&#8217;t argue with that, nor it&#8217;s corollary QIQO (quality in, quality out).</p>
<p>But let me ask you -  <strong><em>is this really a problem common in your analysis</em></strong>?  Did reading this article make you go &#8220;Crap, we&#8217;ve been using data normalized across multiple industries in our analysis! They&#8217;re all wrong!&#8221;  Or have you already been accounting for the unique value proposition your company has to the specific threat community you&#8217;re worried about?  See, maybe I&#8217;m just not your average analyst, but even in my NIST/OCTAVE days, this has *never* been an issue for me.</p>
<p>Let me be specific, this is not a problem with Verizon&#8217;s very cool report.  It&#8217;s just that I don&#8217;t see what the big deal is.  This article is starting to feel like someone is running through the motions, trying to play the &#8221; a crazy title gets people to read a boring article&#8221; game.</p>
<p>Speaking of cool reports - You know what would be cool?  I think it would be interesting to see is the quality of these companies&#8217; &#8220;risk management process&#8221; established using good criteria,  and then correlated to the frequency and magnitude of real-world losses across the aggregate sample.  In other words, can we establish evidence that strong risk management practices not just reduce &#8220;risk&#8221; but also reduce actual incidents.</p>
<p><strong>2.)  THE RSA COUNCIL &#8220;EXPLORES WHY LEGACY METHODS OF EVALUATING INFORMATION SECURITY RISK DON&#8217;T WORK IN TODAY&#8217;S CONNECTED WORLD, IN WHICH ANY NEW BUSINESS INNOVATION INHERENTLY CARRIES SOME LEVEL OF RISK TO INFORMATION.&#8221;</strong></p>
<p>This report from the RSA council puts forth a seemingly obvious proposition, that risk must be balanced by reward.  Why is this news?  Now as I read the article it&#8217;s not clear if:</p>
<ul>
<li>The RSA Council is claiming that the CISO&#8217;s office should be the ones determining reward.  Absurd.</li>
</ul>
<p>or</p>
<ul>
<li>Businesses aren&#8217;t doing a good job at determining risk and reward.</li>
</ul>
<p>Let&#8217;s go with the latter.  So I&#8217;m pretty sure (good) businesses do a good job at estimating reward.  Businesses I&#8217;ve been a part of?  We LOVE(D) estimating reward.  We don&#8217;t tend to start projects all willy-nilly. No we tend to be careful to identify the size of the market and what it will cost to address the market.  So what could the problem be that this RSA council is trying to address?  Maybe it has to do with something like the following:</p>
<p>Yesterday, I got a demo of an IT-GRC application that shall remain nameless.  It seemed to be very good at the &#8220;C&#8221; bits - lots of information on regulations and expectations and even what sorts of controls would answer the regulations (which is goofy, but we&#8217;ll have to talk about that later).  It also gave you the ability to build workflow quite nicely.  But it measured NOTHING.  There really was no observable &#8220;G&#8221; and &#8220;R&#8221; was really Medium X Low X Low = High sorts of stuff.  So let&#8217;s use this relatively expensive tool as evidence of what your average CISO is armed with going into a Risk/Reward sort of meeting.  I imagine a nice board room with wood-grain paneling and glass bowls filled with little chocolate covered mints designed to give everyone involved in the meeting (CEO, CFO, CIO, CSO, VP S&amp;M, etc&#8230;) a little sugar rush when needed and fresh breath.  The conversation goes a little something like this (apologies to <strong><a href="http://securosis.com/2008/09/17/the-fallacy-of-complete-and-accurate-risk-quantification/">Rich</a></strong>):</p>
<blockquote><p><em><strong>Business Guy Who Wants to Make Money Because That&#8217;s What Businesses Do:</strong></em> Based on market studies, we believe that initial gross revenues from the new product and technology rollout will be eleventy gazillion dollars based on a 37% market penetration in Scandinavia, alone.</p>
<p><em><strong>CSO: </strong></em> Well now, we have a likelihood of &#8220;High&#8221; and a &#8220;C&#8221; impact of Medium, and an &#8220;I&#8221; impact of Low, and an &#8220;A&#8221; impact of &#8220;High&#8221; and because we are a (bank/hospital/retailer/basically any business that breathes anymore) we weight &#8220;C&#8221; by a factor of 2 - we multiplied those all together and got a &#8220;High&#8221;.</p>
<p>So can you guys delay the product rollout by 9 months and give me a bunch more money that&#8217;s not in the budget so that I can get this thing down to a &#8220;Medium&#8221;, please?</p></blockquote>
<p>Again, I just don&#8217;t see the problem with Information Risk Management being that our businesses have no idea what the rewards of business might be.  Now maybe we need get a seat in that boardroom just to be able to talk about our &#8220;Mediums&#8221;, sure.  And maybe we&#8217;re infantile in our ability to describe our problem space.  But I cannot fathom that &#8220;<em>Risk Management Doesn&#8217;t Work</em>&#8221; because businesses haven&#8217;t been considering &#8220;reward&#8221;.</p>
<p><strong>WHY RISK MANAGEMENT MAY  NOT BE WORKIN&#8217; FOR YOU</strong></p>
<p>Two meta-categories of causation:</p>
<ul>
<li>No skills</li>
</ul>
<p>and/or</p>
<ul>
<li>No resources</li>
</ul>
<p>Any ancillary &#8220;cause&#8221; can be mapped to one of these categories.  You could have significant resources but crappy models, and have conversations like our imaginary CSO, above.  You could have really good models and people trained and motivated to use them, but scarce time &amp; money, so no conversation happens.</p>
<p>Now my question for you is - which does it make sense to acquire *first* to solve the &#8220;<em>Why Risk Management Doesn&#8217;t Work</em>&#8221; problems, skills or resources?</p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 13:15:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/poor risk management">poor risk management</category>
      <category domain="http://securityratty.com/tag/information security risk">information security risk</category>
      <category domain="http://securityratty.com/tag/reduce risk">reduce risk</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/cool report">cool report</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=459">Why Risk Management Doesnt Work (?!)</source>
    </item>
    <item>
      <title><![CDATA[Sorry, Qantas, No Unfettered Broadband]]></title>
      <link>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</link>
      <guid>http://securityratty.com/article/e46bb700b1a972d41bfd64aba65817f9</guid>
      <description><![CDATA[Qantas backs off from earlier plans, changes provider for in-flight broadband: The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://www.smh.com.au/news/travel/qantas-limits-access-to-web/2008/09/17/1221330929870.html"><strong>Qantas backs off from earlier plans, changes provider for in-flight broadband:</strong></a> The Sydney Morning Herald somewhat erratically and incompletely reports that Qantas has delayed and modified its in-flight broadband plans. Aeromobile was the provider when the service <a href="http://www.breakingtravelnews.com/article.php?story=2007081609481129&query=qantas"><strong>was tested in second quarter 2007</strong></a>, but OnAir is now described as the airline's partner. This was noted by colleague Fabio Zambelli, who emailed me the news, and <a href="http://www.setteb.it/content/view/4742"><strong>has his own account</strong></a> at 7BIT (in Italian).</p>

<p><a href="http://www.onair.aero/index.php?pid=123"><strong>OnAir</strong></a> has so far tested their calling/texting-only service on two aircraft--one operated by Air France, one by TAP Portugal--even though RyanAir announced plans that its planes would started being unwired with the service by late 2007. Still no word on that fleet progress.</p>

<p>Qantas will apparently launch cached Web browsing and limited Web email (probably through a proxy) along with instant messaging, with full Internet service coming "later in 2009." This is clearly due to a lack of satellite coverage that was just remediated a few weeks ago (see below). The first plane with limited service, a new A380, should be in flight 20-October-2008.</p>

<div style="float:right; margin:0px; padding-left: 10px; padding-bottom: 0px;"><p><img src="http://wifinetnews.com//images/2008/SorryQantas.jpg" alt="SorryQantas.jpg" border="0" width="100" height="152"></p><p style="font-size: 10px">I hate in-flight<br/>broadband</p></div>To Qantas' credit, note that each seat on the plane will have a laptop opower socket, a USB port, and a multimedia system that can show 100 movies and 500 TV show episodes, play the contents of 1,000 CDs and 20 radio stations, and offer 80 games. 

<p>The Morning Herald seems to overstate the importance and scope of a complaint filed by the union representing American Airlines' flight attendants. The detailed coverage in the U.S. had more to do with the potential for issues, and likely attendants lack of interest in policing yet another media on the plane. Filtering doesn't work, the attendants probably already know, and this may just be a negotiating point with the airline.</p>

<p>On why Qantas is waiting until late 2009? This requires unwinding how OnAir gets its signal.</p>

<p>Aeromobile and OnAir both rely on Inmarsat satellites for their service. Both companies had several years ago staked their futures on the fourth-generation network Inmarsat was to inaugurate with three satellites that would use beamforming to allow precise delivery of nearly 500 Kbps per receiver, with hundreds or thousands of regions being able to be targeted from a single satellite. Inmarsat's third-gen network--don't confuse this with 3G cellular ground-based networks--can deliver about 64 Kbps per channel.</p>

<p>Now, unfortunately, Inmarsat was three years late on launching its trans-Pacific bird. While the company <a href="http://www.inmarsat.com/About/Newsroom/Press/00021465.aspx?language=EN&textonly=False"><strong>claims 85 percent coverage of the earth</strong></a> and 98 percent coverage of population, there's a big gap over the Pacific that also prevents them from having good overlap between the U.S. and Japan/China/Korea, as well as the southern Pacific, covering Australia. Since the biggest market for long-haul flights would likely be Australia, Japan, and China, traveling trans-Pacific or trans-hemispheric routes, that gap is rather large.</p>

<p>Aeromobile opted to build out a service, deployed only by Emirates airline as far as I can tell, that uses the 3G service since it was available, and most necessary equipment is already installed on most over-water planes. OnAir was waiting for 4G, which has necessitated a long wait, but allowed them to launch in Europe with a seemingly next-generation service. Given that OnAir is controlled by an airline-owned integration firm, SITA, and by Airbus, they're not going anywhere.</p>

<p>Inmarsat finally <a href="http://spaceflightnow.com/proton/i4f3/"><strong>lofted its third satellite on Baikonur Cosmodrome in Kazakhstan</strong></a> on 19-August-2008, and the launch and separation was reported as successful. Previously, the company has needed up to a year to verify and deploy its 4G satellites. (You can <a href="http://forum.nasaspaceflight.com/index.php?topic=12380.105"><strong>read extremely close coverage of the launch</strong></a> at a Web site devoted to space enthusiasm.)</p>

<p>However, the dirty little secret about Inmarsat's BGAN is that it costs a fortune to heft bandwidth across it. Thus, in-flight broadband over BGAN, if it's ever available, is going to be changed on an extremely high per-MB rate. None of the providers want to say this. This is in contrast to Row 44 (and, once, Connexion by Boeing), which relies on leased Ku-band transponders where they can fix costs and they require high volumes to keep per-bit costs efffectively low.</p>

<p>OnAir's launch of calling on Air France's service involves paying a few euros per minute for calls, which might help you understand what data costs could ultimately run.</p>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 06:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/satellite coverage">satellite coverage</category>
      <category domain="http://securityratty.com/tag/coverage">coverage</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service involves">service involves</category>
      <category domain="http://securityratty.com/tag/internet service">internet service</category>
      <category domain="http://securityratty.com/tag/in-flight broadband plans">in-flight broadband plans</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/inmarsat satellites">inmarsat satellites</category>
      <category domain="http://securityratty.com/tag/inmarsat">inmarsat</category>
      <source url="http://wifinetnews.com/archives/008448.html">Sorry, Qantas, No Unfettered Broadband</source>
    </item>
    <item>
      <title><![CDATA[Hansei and the CISO]]></title>
      <link>http://securityratty.com/article/345fa11bf7640e73e9bb05e7b33128f0</link>
      <guid>http://securityratty.com/article/345fa11bf7640e73e9bb05e7b33128f0</guid>
      <description><![CDATA[Continuing our series on Hansei-Kaizen, youll recall that my thoughts are about applying the concept of relentless reflection (Hansei) and continuous improvement (Kaizen) to security management. Today...]]></description>
      <content:encoded><![CDATA[<p>Continuing our series on Hansei-Kaizen, you&#8217;ll recall that my thoughts are about applying the concept of relentless reflection (Hansei) and continuous improvement (Kaizen) to security management.  Today is a good day to talk about <em><strong>what should we be reflecting about</strong></em>, and <em><strong>what is needed for reflection</strong></em>.</p>
<p>I say today is a good day for two reasons:  1.)  BT&#8217;s CSO Jill Knesek wrote an article called &#8220;<strong><a href="http://bt-securethinking.blogspot.com/2008/09/keys-to-establishing-end-to-end.html">Keys to establishing an end-to-end security strategy</a></strong>&#8221; which begs some discussion within context, and 2.)  <strong><a href="http://twitter.com/sarapeters">Sara Peters on Twitter</a></strong> last night wanted to know why I thought &#8220;risk management&#8221; requires more than what most &#8220;best practices&#8221; around the subject suggest the effort requires.</p>
<p><strong>WHAT SHOULD WE BE REFLECTING ABOUT?</strong></p>
<p>Jill Knesek&#8217;s article gives us a rough outline of how to develop a security strategy.  It&#8217;s fairly high-level, Pragmatic CSO-ish type stuff.  It gives us a nice outline of</p>
<ul>
<li>Get a seat at the table</li>
<li>Process</li>
<li>People</li>
<li>Technology</li>
</ul>
<p>Nothing earth-shattering there.  But it is a very nice broad CISO-level taxonomy about what we have to reflect on.  The <em><strong>need</strong></em> to reflect is driven by something Jack told me long ago,</p>
<blockquote><p>&#8220;The amount of risk we have is a function of the decisions we made and our ability to execute on them from some point in the past&#8221;.</p></blockquote>
<p style="padding-left: 30px;"><em>As an Aside:  So Sarah if you&#8217;re reading, this quote does much to explain why I said I disagree with much of what our industry calls &#8220;risk management&#8221;.  We tend to define the process of risk management as essentially a tactical &#8220;issue whack-a-mole&#8221; exercise. </em><em><strong>Find the issue.  Analyze the &#8220;risk&#8221; around the issue.  Fix the issue.  Repeat. </strong> This hamster-wheel-of-pain, while sometimes an effective tool for the CISO, is incongruous with addressing root causes (the ability to match a tactical issue to the strategic shortcoming that created the issue is up to the expertise of the analyst or consultant).  It is only Kaizen without (good) Hansei, if you will.</em></p>
<p>Back to what Jill is writing - the sorts of things we should be reflecting about can be thought of in context of her outline.  Namely:</p>
<ol>
<li>Once you have a seat at the table, what is the nature of that relationship?  Who are you reporting to and what are their concerns? What and how are you reporting and how might that be addressing their concerns?</li>
<li>What processes are in place?, How do you know that those are the processes that should be in place? If they are, what kind of job am I doing at those processes?</li>
<li>What is the quality of the skills and resources I have from a people perspective, and how do I know if they are adequate?  How do I know that the training they petition me for will effectively reduce organizational risk?</li>
<li>Are the Technology solutions I have in place effective, are we managing them effectively, and what sort of States of Knowledge could they provide me with (to make good decisions and execute upon them, from above)?</li>
</ol>
<p>This, for the CISO, is Hansei.  The continuous management of it is Kaizen.  Not to particularly pick on Jill&#8217;s article, but creating a &#8220;risk register expressed in ALE&#8221; might be fine if you&#8217;re trying to explain to the board what your &#8220;first 100 days in office&#8221; will be like - but these sorts of lists are usually not very strategic in nature, and as such, depending on the outcome of that risk register (and the models used to create it) <em><strong>it might not actually be useful.</strong></em></p>
<p><strong>WHAT IS NEEDED FOR REFLECTION?</strong></p>
<p>So what is needed for this sort of CISO-level Hansei?</p>
<p>The CISO must understand the</p>
<ul>
<li>Current State of Nature</li>
</ul>
<p>turn that into a</p>
<ul>
<li>State of Knowledge</li>
</ul>
<p>and use that to create a</p>
<ul>
<li>State of Wisdom.</li>
</ul>
<p><strong>CREATING A STATE OF NATURE FOR THE IRM PROGRAM<br />
</strong></p>
<p>This Current State of Nature determination be done by applying analytical methods to a program audit.  We must understand questions like,  &#8220;What is in that program and how is it structured?&#8221;  before we can answer questions about &#8220;how (good/bad) are we at managing risk?&#8221;</p>
<p>There are many ways to structure an IRM program, but as an example - below is a graphic shared with me by Adrian Seccombe.  For those who know Adrian and the Trust Model - this is classified as &#8220;white&#8221; so it&#8217;s OK for public display and consumption.  But here&#8217;s what Adrian is trying to build at a high level:</p>
<p style="text-align: center;"><img class="aligncenter" src="http://www.riskmanagementinsight.com/media/images/weblog/Program.jpg" alt="" width="283" height="356" /></p>
<p>So regarding Adrian&#8217;s program diagram:</p>
<ol>
<li>Is a governance framework.  Think ITIL.</li>
<li>Is a risk framework.  Think ISO 27002 using FAIR as an analytical engine.  To be fair (pun) I believe this is really issue management, and it&#8217;s a process, but that&#8217;s OK.</li>
<li>Reg compliance should be self explanatory.  That&#8217;s essentially what GRC products do for you.</li>
<li>With architecture, I think Adrian is inclined towards TOGAF.</li>
<li>Security is the ISMS in place (27001, ISM^3, PCI, whatever&#8230;)</li>
<li>Are the processes that drive execution</li>
<li><strong>M</strong><strong>onitor</strong> (audit) is creating a State of Nature and <strong>Evaluate</strong> is creating a State of Knowledge from that State of Nature around items 1-6.</li>
</ol>
<p><strong>EVALUATE - CREATING A STATE OF KNOWLEDGE ABOUT THE IRM PROGRAM</strong></p>
<p>That evaluate is Hansei/Kaizen.  Evaluation, done effectively, will drive actual organizational risk exposure.  Evaluate will even answer those four questions we raised in the &#8220;What Should We Be Reflecting About&#8221; section above:</p>
<ol>
<li>Once you have a seat at the table, what is the nature of that relationship?  Who are you reporting to and what are their concerns? What and how are you reporting and how might that be addressing their concerns?</li>
<li>What processes are in place?, How do you know that those are the processes that should be in place? If they are, what kind of job am I doing at those processes?</li>
<li>What is the quality of the skills and resources I have from a people perspective, and how do I know if they are adequate?</li>
<li>Are the Technology solutions I have in place effective, are we managing them effectively, and what sort of States of Wisdom do they provide me with (to make good decisions and execute upon them, from above)?</li>
</ol>
<p>If we could have a nice metric (or set of metrics) that answers these questions, we might call it something like &#8220;My Ability To Manage Risk&#8221; or MATMR for short.</p>
<p><strong>GETTING TO A STATE OF WISDOM</strong></p>
<p>What&#8217;s then missing is how you create a State of Wisdom around the State of Knowledge developed - your &#8220;MATMR&#8221; metric.  That is, given the current State of Knowledge - how can I be most effective?  This State of Wisdom requires proper models for what risk is, and what you can do to manage it applied in a probabilistic manner (because we can&#8217;t intrinsically *know* the future, we can only say with some degree of certainty what the desired course should be).</p>
<p>So the outcome of Hansei/Kaizen should be to create a State of Wisdom about Risk Management.  This is why reflection must be relentless - because your wisdom must be similarly abundant.</p>
<p>This is no small part of the reason RMI exists, why we build software and help organizations understand the things they do.</p>
]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 13:47:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management requires">risk management requires</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/hansei">hansei</category>
      <category domain="http://securityratty.com/tag/risk register">risk register</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/manage risk">manage risk</category>
      <category domain="http://securityratty.com/tag/manage">manage</category>
      <category domain="http://securityratty.com/tag/adrians program diagram">adrians program diagram</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=411">Hansei and the CISO</source>
    </item>
    <item>
      <title><![CDATA[Another VMware Founder Leaves]]></title>
      <link>http://securityratty.com/article/8e31d391fee4200c824ddc048a2d952b</link>
      <guid>http://securityratty.com/article/8e31d391fee4200c824ddc048a2d952b</guid>
      <description><![CDATA[Im getting a little depressed for my upcoming trip to Vegas next week. Instead of a festive party atmosphere, I fear VMworld (and especially the Partner Day on Monday) is going to consist of a bunch...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="Rosenblum_VMware" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/rosenblum-vmware.jpg" width="164" align="left" border="0"> I’m getting a little depressed for my upcoming trip to Vegas next week. Instead of a festive party atmosphere, I fear <a href="http://www.vmworld.com/conferences/2008/" target="_blank">VMworld</a> (and especially the Partner Day on Monday) is going to consist of a bunch of long faces on people wondering whether they should have gone to the <a href="https://www.getvirtualnow.com/main.aspx" target="_blank">Microsoft virtualization party</a> instead.
<p>Just a few months after CEO and founder <a href="http://blog.sciencelogic.com/diane-greene-ousted-from-vmware/07/2008">Diane Greene was ousted</a>, it <a href="http://www.virtualization.info/2008/09/mendel-rosenblum-co-founder-and-chief.html" target="_blank">comes as no surprise</a> that her <a href="http://virtualization.com/news/2008/09/09/mendel-rosenblum-vmware/" target="_blank">husband and co-founder</a>, <a href="http://www.nytimes.com/2008/09/09/technology/09vmware.html?_r=1&amp;oref=slogin" target="_blank">Mendel Rosenblum, has also resigned</a> via a company wide message last night. Turns out he’s going back to Stanford to teach. What a lovely way to get out of the political mess VMware has become. Admit it, haven’t we all had a point where we get fed up with the latest work snafu and wondered, maybe I should go back to college and teach? I had a really good time in college… Kudos to Rosenblum for doing it and doing it in style.
<p>And if you believe <a href="http://www.tarrysingh.blogspot.com/2008/09/vmware-co-founder-mendel-rosenblum.html" target="_blank">Tarry Singh</a>, <a href="http://blog.scottlowe.org/2008/09/09/as-expected-rosenblum-leaves-vmware/" target="_blank">the company knew</a> this was going to happen but waited until after registrations were closed for VMworld before making it official. Hmm.
<p>From the New York Times, more on Greene’s firing and just <a href="http://www.iht.com/articles/2008/09/09/technology/09vmware.php" target="_blank">what kind of atmosphere</a> is forcing executives to leave VMware:<br />
<blockquote>
<p>After Ms. Greene made a special presentation to VMware’s board, Mr. Tucci, who heads VMware’s parent company, EMC, pulled her aside, according to people familiar with the events, who asked for anonymity because they were not authorized to discuss internal company decisions.
<p>Inviting Mendel Rosenblum, Ms. Greene’s husband and the co-founder of VMware, into the room, Mr. Tucci told Ms. Greene she was fired, effective immediately. And he said the board wanted Mr. Rosenblum, VMware’s chief scientist, to take her seat on the board. Mr. Rosenblum declined the offer.</p>
</blockquote>
<p>Honestly, what kind of a judgement call was made to first <a href="http://www.datacenterknowledge.com/archives/2008/09/09/rosenblum-leaves-vmware/" target="_blank">fire the man’s wife in front of him</a> and then offer him her board seat? Has Tucci never seen an episode of Survivor?</p>
]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 15:23:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/board seat">board seat</category>
      <category domain="http://securityratty.com/tag/board">board</category>
      <category domain="http://securityratty.com/tag/rosenblum">rosenblum</category>
      <category domain="http://securityratty.com/tag/mendel rosenblum">mendel rosenblum</category>
      <category domain="http://securityratty.com/tag/political mess vmware">political mess vmware</category>
      <category domain="http://securityratty.com/tag/founder diane greene">founder diane greene</category>
      <category domain="http://securityratty.com/tag/greene">greene</category>
      <category domain="http://securityratty.com/tag/vmwares board">vmwares board</category>
      <source url="http://blog.sciencelogic.com/another-vmware-founder-leaves/09/2008">Another VMware Founder Leaves</source>
    </item>
    <item>
      <title><![CDATA[My excellent adventure at Black Hat]]></title>
      <link>http://securityratty.com/article/4911547e5865f4f749dca83e6e765ab4</link>
      <guid>http://securityratty.com/article/4911547e5865f4f749dca83e6e765ab4</guid>
      <description><![CDATA[Yesterday was a great day at Black Hat. I would tell you all about it, but it seems Mitchell thinks that it best that we don't talk about what goes on here at Black Hat . Now, far be it from me to...]]></description>
      <content:encoded><![CDATA[<p>Yesterday was a great day at Black Hat. I would tell you all about it, but it <a href="http://www.theconvergingnetwork.com/2008/08/shimel-violates.html">seems Mitchell thinks that it best that we don't talk about what goes on here at Black Hat</a>. Now, far be it from me to break "Cardinal Rules" (has anyone ever really thought about what exactly is a "cardinal rule"? Why not a Blue Jay or Falcon rule?) but if we can't talk about it, what good is it. I think Mitchell is confusing divulging the really juicy Vegas stuff, from just the mundane. So let me tell you about my excellent adventure yesterday at Black Hat.<br><br>I was one of the multitude standing in the back listening to Dan's DNS report. You probably have already heard that it is bigger and worse than originally reported. I than spent a lot of time with the Microsoft people talking to them about their security stuff. I will tell you that despite many who rail against Microsoft, these guys actually are doing a great job on security and in dealing with the security community. Much better than a certain company named for a fruit whose marketing people killed the presentation of their own security research team. After lunch I took a front row seat to watch Hoff present on virtual security. He has some very pretty slides, but the message was clear. Great presentation by Hoff. I spent most of the rest of the afternoon catching up with lots of security bloggers here. I am amazed by the number of us here at Black Hat. <br><br>Had a quiet dinner with Mitchell (I would tell you about it but you know about what happens in Vegas with Mitchell) and than went to the Breach party at the Shadow Bar (I love that place, but it was too hot last night). We than went over to the Fuente cigar bar and next thing you know we were joined by about 30 of our closest security blogger buddies. It was a great time and their are pictures floating around twitter somewhere of it. We talked and laughed into the late hours, winding up at the Augustus cafe again for an early breakfast.<br><br>Well it is back to the show today and another round of parties tonight. Ah, it is tough living the life ;-)</p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/ccf323f7-07c7-4094-9f72-65644a0714a6/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=ccf323f7-07c7-4094-9f72-65644a0714a6" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none"></img></a></div>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=j0KXcs"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=j0KXcs" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=46dXIK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=46dXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=LcowtK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=LcowtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ciyhoK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ciyhoK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=597hOK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=597hOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=KEMtMk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=KEMtMk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TXQNRk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TXQNRk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/358568409" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 07:52:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security bloggers">security bloggers</category>
      <category domain="http://securityratty.com/tag/security research team">security research team</category>
      <category domain="http://securityratty.com/tag/virtual security">virtual security</category>
      <category domain="http://securityratty.com/tag/security community">security community</category>
      <category domain="http://securityratty.com/tag/security stuff">security stuff</category>
      <category domain="http://securityratty.com/tag/security blogger buddies">security blogger buddies</category>
      <category domain="http://securityratty.com/tag/juicy vegas stuff">juicy vegas stuff</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/358568409/my-excellent-ad.html">My excellent adventure at Black Hat</source>
    </item>
    <item>
      <title><![CDATA[The Magical ATM Card and SMS Message in Thailand]]></title>
      <link>http://securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</link>
      <guid>http://securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</guid>
      <description><![CDATA[It was not too long ago that I penned Keyloggers: Why Banks Need Two-Factor Authentication . In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor...]]></description>
      <content:encoded><![CDATA[<p>It was not too long ago that I penned <a href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/">Keyloggers: Why Banks Need Two-Factor Authentication</a>. In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor authentication (2FA) with one-time password (OTP) to authenticate transactions.</p>
<p>One of my favorite banks in Thailand is <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">K-Bank</a>. With K-Bank I can simply walk up to an ATM machine and pay a mobile phone bill, purchase mutual funds, buy insurance, or transact an ever-growing list of services payable at the modern and sleek K-Bank ATM.</p>
<p>For example, tomorrow I fly to Chiang Mai in Northern Thailand and found K-Bank&#8217;s service amazingly better than in the US. For example, I booked my flight as usual (over the phone, but could have used the Internet) and told the reservation agent I was going to pay by ATM. He simply gave me a PayCode and told me I had three hours to go to the ATM and enter the PayCode to perfect my reservation.  I also got the PayCode via SMS.  This gave me the time I needed to make sure I had <a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/pictures/" target="_blank">booked the perfect boutique hotel</a> in Chiang Mai, the <strong><a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/review/" target="_blank">Fern Paradise</a>.</strong></p>
<p>Then, I went out into the beautiful Thai weather and completely my airplane reservation at the ATM machine; which also printed out a receipt with my flight details and reservation number.</p>
<p>It sometimes amazes me how much further advanced some services are in Thailand compared to the US. To me, it feels more secure not to use an on-line payment center or give out my credit card details over the phone. I can simply book a ticket, take a PayCode, and complete the transaction at a nice modern, shiny, K-Bank ATM machine.</p>
<p>Who knows, maybe soon I can select the perfect window seat at the ATM and the receipt will act as my boarding pass!</p>
]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 09:30:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/atm">atm</category>
      <category domain="http://securityratty.com/tag/k-bank atm machine">k-bank atm machine</category>
      <category domain="http://securityratty.com/tag/sleek k-bank atm">sleek k-bank atm</category>
      <category domain="http://securityratty.com/tag/k-bank">k-bank</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/atm machine">atm machine</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/perfect window seat">perfect window seat</category>
      <category domain="http://securityratty.com/tag/perfect">perfect</category>
      <source url="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/">The Magical ATM Card and SMS Message in Thailand</source>
    </item>
  </channel>
</rss>
