<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: spin]]></title>
    <link>http://securityratty.com/tag/spin</link>
    <description></description>
    <pubDate>Fri, 18 Jul 2008 18:14:31 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Blurring the Lines Between Managed Service Provider and Cloud Computing]]></title>
      <link>http://securityratty.com/article/23238e9889824f8ebd65b8a0149c5f4a</link>
      <guid>http://securityratty.com/article/23238e9889824f8ebd65b8a0149c5f4a</guid>
      <description><![CDATA[VMware made big announcements at their VMworld conference back in September, talking about adding on a slew of virtualization management functionality to a revamped vCenter and extending into the...]]></description>
      <content:encoded><![CDATA[<p>VMware made big announcements at their <a href="http://www.vmworld.com/index.jspa" target="_blank">VMworld conference</a> back in September, talking about adding on a slew of virtualization management functionality to a revamped vCenter and extending into the “cloud” with vCloud services. Like most people, I had a lot of skepticism about what vCloud really meant; was this just more hype trying to take advantage of the cloud computing buzz? Certainly CEO Paul Maritz came from this world and virtualization itself (and especially vMotion) is an enabling technology for cloud computing. But how ready were VMware and its ecosystem of partner vendors to actually fulfill on the promise?</p>
<p>So I was very interested when I heard that <a href="http://opusinteractive.com/" target="_blank">Opus Interactive</a>, a customer of ours, had “joined the VMware vCloud initiative as a <a href="http://www.opusinteractive.com/news_detail.asp?item=40" target="_blank">VMware Service Provider</a>”. I talked to Eric Hulbert, CTO of Opus Interactive, to get some details directly from the source.</p>
<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0025.jpg" border="0" alt="clip_image002" width="202" height="74" align="left" /></p>
<p>Eric shared our own caution about making “cloud-ready” announcements. There have simply been too many companies talking about cloud solutions that lack any substance – usually based on definitions of cloud computing that are hazy or just too broad. The backlash against the cloud hype is often quite justified. But in Opus’ case, there are real components that if they don’t add up to a “full” cloud computing solution just yet, are well on their way – and enabled by <a href="http://www.vmware.com/partners/vip/service-providers/" target="_blank">VMware’s program for service providers</a> (VSPP).</p>
<p>Opus Interactive is <a href="http://www.viddler.com/explore/sciencelogic/videos/3" target="_blank">serious about virtualization</a>, which is an indispensable tool in their stated goal of creating a high-density micro-data center with the smallest footprint possible. They are 100% wind-powered and have already virtualized much of their data center, reducing the amount of hardware necessary to run the business and driving down costs to produce even more competitive advantage in a crowded marketplace.</p>
<p>VSPP for vCloud provides a rental model of VMware licenses – e.g., for Enterprise ESX or VDI. VMware Service Providers report on their customers’ virtual machines (vm) and pay only for what is actually used. This model lets Opus Interactive quickly spin up a vm to get a new customer up and running in about an hour and stay very cost competitive at the same time; Opus offers their <a href="http://opusinteractive.com/vClustr.asp" target="_blank">vClustr entry-level virtual server</a> for only $99.</p>
<p>Cost-effective, rapidly scalable computing “on-demand” based on shared resources, managed by “expert” third-parties, enabled by virtualization technology and pay-per-use vm licenses. Cloud computing? Instead of thinking about a single definition of cloud computing, perhaps it’s more relevant as the market matures to think about a continuum of cloud computing. And by that definition, Opus Interactive is providing cloud services, enabled by VMware’s VSP program. Next on the schedule, automated provisioning and perhaps in the future, API’s that make it even easier for application developers to test and deploy apps on Opus Interactive’s cloud platform – which, by the way, uses <a href="http://www.sciencelogic.com/products.htm" target="_blank">EM7</a> for its core management solution.</p>
]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 11:20:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/cloud hype">cloud hype</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/cloud-ready announcements">cloud-ready announcements</category>
      <category domain="http://securityratty.com/tag/cloud solutions">cloud solutions</category>
      <category domain="http://securityratty.com/tag/announcements">announcements</category>
      <category domain="http://securityratty.com/tag/vmware vcloud initiative">vmware vcloud initiative</category>
      <category domain="http://securityratty.com/tag/ready">ready</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <source url="http://blog.sciencelogic.com/blurring-the-lines-between-managed-service-provider-and-cloud-computing/11/2008">Blurring the Lines Between Managed Service Provider and Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[Old scam, with a new twist.]]></title>
      <link>http://securityratty.com/article/a725c48b128f79db0e6a06f8eed9917e</link>
      <guid>http://securityratty.com/article/a725c48b128f79db0e6a06f8eed9917e</guid>
      <description><![CDATA[Please dont fall for this


clipped from it.toolbox.com

Mystery Shoppers testing out Money Gram Services Scam



With a new spin on an old scam, mystery shoppers are being recruited to test money...]]></description>
      <content:encoded><![CDATA[<div > Please dont fall for this! </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/7BD92628-49D8-455A-8851-38E0BBCC5A40/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/97ae93d9-d8a9-466a-9c4c-a97e0c8baf41/7BD92628-49D8-455A-8851-38E0BBCC5A40/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://it.toolbox.com/blogs/managing-infosec/mystery-shoppers-testing-out-money-gram-services-scam-28257" href="http://it.toolbox.com/blogs/managing-infosec/mystery-shoppers-testing-out-money-gram-services-scam-28257" style="font-size: 11px;">it.toolbox.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://it.toolbox.com/blogs/managing-infosec/mystery-shoppers-testing-out-money-gram-services-scam-28257 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">
		Mystery Shoppers testing out Money Gram Services Scam
	</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://it.toolbox.com/blogs/managing-infosec/mystery-shoppers-testing-out-money-gram-services-scam-28257 --><DIV><br />
		With a new spin on an old scam, mystery shoppers are being recruited to test money gram systems, by sending your money to the scammer.<br />
</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/7BD92628-49D8-455A-8851-38E0BBCC5A40/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_141108042528"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=141108042528&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=141108042528&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=141108042528&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_141108042528" /></a></P>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 13:25:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mystery shoppers">mystery shoppers</category>
      <category domain="http://securityratty.com/tag/scam">scam</category>
      <category domain="http://securityratty.com/tag/spin">spin</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/scammer">scammer</category>
      <category domain="http://securityratty.com/tag/toolbox">toolbox</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=658">Old scam, with a new twist.</source>
    </item>
    <item>
      <title><![CDATA[Get a Windows Server on the Fly in the Amazon Cloud]]></title>
      <link>http://securityratty.com/article/d76698803ebfafb9786b04c89ddf8556</link>
      <guid>http://securityratty.com/article/d76698803ebfafb9786b04c89ddf8556</guid>
      <description><![CDATA[Amazon's EC2 (Elastic Compute Cloud) was cool enough with its initial platform. Now it is offering Windows support on the EC2 platform . Thanks to Jesper's Blog for the tip. Like a lot about the EC2,...]]></description>
      <content:encoded><![CDATA[<a href="http://www.eweek.com/c/a/Cloud-Computing/Amazon-and-Cloud-Computing/">Amazon's EC2 (Elastic Compute Cloud) was cool enough</a> with its initial platform. Now it is offering <a href="http://aws.amazon.com/windows/">Windows support on the EC2 platform</a>. Thanks to <a href="http://msinfluentials.com/blogs/jesper/archive/2008/10/24/need-a-spare-windows-box.aspx">Jesper's Blog</a> for the tip.

Like a lot about the EC2, this turns out to be really convenient for developers. Did you ever want to develop or test a Windows Web app on a real server, not just your test desktop, and not have to get a real server to do it? Now you can just virtualize up a Windows server in the cloud and it's yours: A virtual server running Windows Server 2003, SQL Server and all the .NET stuff preinstalled.

<a href="http://developer.amazonwebservices.com/connect/entry.jspa?externalID=1767&categoryID=100%20">A security white paper from Amazon</a> describes the configuration of the Windows system images available and their differences from a standard Windows Server installation. Setup from the user's standpoint looks really easy; Jesper said it took him 5 minutes.

A Security Configuration Wizard walks you through an attack surface reduction process, which helps you to turn off services that are not needed and restrict communications channels that should not be permitted. In the end you can save the image and spin off new ones to meet your new standards as necessary.

EC2 is a great development for developers and a great way for Amazon to leverage all the work it has put into building its infrastructure. I see a lot of opportunities available.
<p><a href="http://feedads.googleadservices.com/~a/oB3bliI9e8xgWRUXc4n3sQBHTso/a"><img src="http://feedads.googleadservices.com/~a/oB3bliI9e8xgWRUXc4n3sQBHTso/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/Vy537Y6vypQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 08:26:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/amazon">amazon</category>
      <category domain="http://securityratty.com/tag/windows server">windows server</category>
      <category domain="http://securityratty.com/tag/ec2">ec2</category>
      <category domain="http://securityratty.com/tag/ec2 platform">ec2 platform</category>
      <category domain="http://securityratty.com/tag/amazon describes">amazon describes</category>
      <category domain="http://securityratty.com/tag/real server">real server</category>
      <category domain="http://securityratty.com/tag/elastic compute cloud">elastic compute cloud</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/Vy537Y6vypQ/get_a_windows_server_on_the_fly_in_the_amazon_cloud.html">Get a Windows Server on the Fly in the Amazon Cloud</source>
    </item>
    <item>
      <title><![CDATA[A breach by any other name...]]></title>
      <link>http://securityratty.com/article/26a3725b2740636cc1edb285ce3dc5d2</link>
      <guid>http://securityratty.com/article/26a3725b2740636cc1edb285ce3dc5d2</guid>
      <description><![CDATA[Sometimes the spin makes me dizzy. Take, for instance, an incident which occurred in the U.K....]]></description>
      <content:encoded><![CDATA[Sometimes the spin makes me dizzy.  Take, for instance, an incident which occurred in the U.K. recently.  ]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 04:39:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/recently">recently</category>
      <category domain="http://securityratty.com/tag/spin">spin</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <category domain="http://securityratty.com/tag/instance">instance</category>
      <category domain="http://securityratty.com/tag/dizzy">dizzy</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/a-breach-by-any-other-name-27757">A breach by any other name...</source>
    </item>
    <item>
      <title><![CDATA[Fun Reading on Security - 7]]></title>
      <link>http://securityratty.com/article/c474f15d19ef80949f385cbe7b510b79</link>
      <guid>http://securityratty.com/article/c474f15d19ef80949f385cbe7b510b79</guid>
      <description><![CDATA[Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot; Fun Reading on Security .&quot; Here is an issue #7, dated August 27th, 2008
Sad,...]]></description>
      <content:encoded><![CDATA[<p>Instead of my usual &quot;blogging frenzy&quot; machine gun blast of short posts, I will just combine them into my new blog series &quot;<a href="http://chuvakin.blogspot.com/search/label/reading">Fun Reading on Security</a>.&quot; Here is an issue #7, dated August 27th, 2008.</p>  <ol>   <li>Sad, but VERY insightful story of Alan Shimmel getting 0wned (<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/im-back.html">1</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/more-frustratio.html">2</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/our-web-infrast.html">3</a>,<a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/08/why-google-is-n.html">4</a>, others on his blog) </li>    <li>A very good essay on security industry/market/community &quot;<a href="http://blog.trailofbits.com/2008/07/24/evolution-is-punctuated-equilibria/">Evolution is Punctuated Equilibria</a>&quot; <em>(&quot;Right now, Internet security is due for another period of rapid change.&quot;)</em> </li>    <li>As I like to say, most everybody in out industry is confused about risk (myself included, in fact) - here is some nice reading about the subject: &quot;<a href="http://layer8.itsecuritygeek.com/layer8/quant-love/">Quant love&quot;</a>, &quot;<a href="http://risktical.com/2008/07/31/what-is-risk/">What is Risk?</a>&quot; (&quot;<em>The probability of a threat overcoming security controls resistance to exploit a vulnerability that results in a loss.</em>&quot;) While you are at it, check <a href="http://risktical.com/2008/08/24/risk-and-cvss-post-1/">this blurb</a> about risk and <a href="http://www.first.org/cvss/">CVSS</a> (BTW, <a href="http://www.first.org/cvss/">CVSS</a> is about &quot;V&quot; - vulnerability, not &quot;R&quot; for risk!)</li>    <li>Solid gold on &quot;running IT as business&quot; (and where it hits the wall) - <a href="http://taosecurity.blogspot.com/2008/08/limits-of-running-it-like-business.html">Richard</a>, <a href="http://www.cio.com/article/print/335813">the original CIO.com piece</a>&#160;<em>(&quot;If you've tried managing an internal IT department as a bona fide business you already know that you can't take that very far, for the obvious reason that your IT department isn't a business.&quot;)</em> </li>    <li>More fun stuff from Richard <a href="http://taosecurity.blogspot.com/2008/07/counterintelligence-worse-than-security.html">on insiders and why NOT look for them</a> (sadly, same logic applies to not looking for owned boxes in your environment...). </li>    <li>Analyst firms <a href="http://www.forrester.com/Research/Document/Excerpt/0,7211,46811,00.html">shocking discovery</a>: wireless MAY have security issues (I guess count it as humor...)</li>    <li>Fun read: &quot;<a href="http://onsaas.net/2008/08/23/challenges-of-enterprise-cloud-computing/">Challenges of Enterprise Cloud Computing</a>&quot; (<em>&quot;By moving the data into the cloud, enterprise, for now, will lose some capabilities to govern their own data set.&quot;</em>) </li>    <li><a href="http://searchnetworking.techtarget.com/news/article/0,289142,sid7_gci1326271,00.html">Raffy on visualization</a>. (<em>&quot;One of the dangerous things is if you don't understand the log file itself, don't assume you'll understand the visualization of it or even generate a visualization that makes sense&quot;</em>) Amen to that! BTW, Raffy's book is finally <a href="http://www.amazon.com/gp/product/0321510100/ref=cm_cr_pr_product_top">out.</a> </li>    <li>Compliance and checkbox mentality: fun pickup from <a href="http://chuvakin.blogspot.com/2008/08/few-more-words-on-dlp-and-compliance.html">my original &quot;DLP and Compliance&quot; post</a> - <a href="http://securosis.com/2008/08/18/dont-sell-compliance-if-it-isnt-a-checkbox/">Rich</a> and <a href="http://channelmarker.blogs.techtarget.com/2008/08/19/794/">TechTarget</a>. Good stuff! (&quot;<a href="http://securosis.com/2008/08/18/dont-sell-compliance-if-it-isnt-a-checkbox/"><em>Don&#8217;t Sell &#8216;Compliance&#8217; If It Isn&#8217;t A Checkbox </em></a>&quot;) </li>    <li>RedHat is <a href="http://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html">nicely 0wned</a> (<a href="http://isc.sans.org/diary.html?storyid=4921">more info</a>)</li>    <li><a href="http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.html">BGP hole</a> to dwarf the DNS hole?</li>    <li>Chris continues the virtualization and PCI DSS theme <a href="http://rationalsecurity.typepad.com/blog/2008/08/virtualized-inf.html">here</a>. The jury is still out on this one, even though the common sense approach (that virtualization is OK in regards to PCI) will probably win.</li>    <li>NEWS FLASH! <a href="http://blog.modernmechanix.com/2008/03/31/the-national-data-center-and-personal-privacy/">Privacy dies</a>. The date of death? 1967. While <a href="http://blog.modernmechanix.com/2008/03/31/the-national-data-center-and-personal-privacy/">reading it</a>, think just how visionary some folks are...</li>    <li>Finally, just for laughs: <a href="http://www.wikihow.com/Spin-Bad-News">How to Spin Bad News</a> </li> </ol>  <p>Enjoy!</p>  <p>BTW, I am saving some fun reading for dedicated posts soon :-)</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jdwxUK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jdwxUK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=PB8ogK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=PB8ogK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=YLH24K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=YLH24K" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/376393795" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:56:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/security controls resistance">security controls resistance</category>
      <category domain="http://securityratty.com/tag/stuff">stuff</category>
      <category domain="http://securityratty.com/tag/fun stuff">fun stuff</category>
      <category domain="http://securityratty.com/tag/security issues">security issues</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/bona fide business">bona fide business</category>
      <category domain="http://securityratty.com/tag/fun pickup">fun pickup</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/376393795/fun-reading-on-security-7.html">Fun Reading on Security - 7</source>
    </item>
    <item>
      <title><![CDATA[Hacking Mifare Transport Cards]]></title>
      <link>http://securityratty.com/article/3a7dba1bb2685c0c225ca69eddd304c7</link>
      <guid>http://securityratty.com/article/3a7dba1bb2685c0c225ca69eddd304c7</guid>
      <description><![CDATA[London's Oyster card has been cracked , and the final details will become public in October. NXP Semiconductors, the Philips spin-off that makes the system, lost a court battle to prevent the...]]></description>
      <content:encoded><![CDATA[<p>London's Oyster card has been <a href="http://www.guardian.co.uk/technology/2008/jun/26/hitechcrime.oystercards">cracked</a>, and the final details will become public in October. NXP Semiconductors, the Philips spin-off that makes the system, lost a court battle to prevent the researchers from publishing. People might be able to use this information to ride for free, but the sky won't be falling. And the publication of this serious vulnerability actually makes us all safer in the long run.</p>

<p>Here's the story. Every Oyster card has a radio-frequency identification chip that communicates with readers mounted on the ticket barrier. That chip, the "Mifare Classic" chip, is used in hundreds of other transport systems as well — Boston, Los Angeles, Brisbane, Oslo, Amsterdam, Taipei, Shanghai, Rio de Janeiro — and as an access pass in thousands of companies, schools, hospitals, and government buildings around Britain and the rest of the world.</p>

<p>The security of Mifare Classic is terrible. This is not an exaggeration; it's kindergarten cryptography. Anyone with any security experience would be embarrassed to put his name to the design. NXP attempted to deal with this embarrassment by keeping the design secret.</p>

<p>The group that <a href="http://www.ru.nl/ds/research/rfid/">broke</a> Mifare Classic is from Radboud University Nijmegen in the Netherlands. They <a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article4184481.ece">demonstrated the attack</a> by riding the Underground for free, and by <a href="http://www.youtube.com/watch?v=NW3RGbQTLhE">breaking into</a> a building. Their two papers (one is already <a href="http://www.cs.ru.nl/~flaviog/publications/Attack.MIFARE.pdf">online</a>) will be published at <a href="http://www.scc.rhul.ac.uk/CARDIS/">two</a> <a href="http://www.isac.uma.es/esorics08/">conferences</a> this autumn.</p>

<p>The second paper is the one that NXP <a href="http://news.cnet.com/8301-10784_3-9985886-7.html?hhTest=1">sued</a> <a href="http://www.secureidnews.com/news/2008/07/10/nxp-sues-to-prevent-hackers-from-releasing-mifare-flaws/">over</a>. They called disclosure of the attack "irresponsible," warned that it will cause "immense damages," and claimed that it "will jeopardize the security of assets protected with systems incorporating the Mifare IC." The <a href="http://zoeken.rechtspraak.nl/resultpage.aspx?snelzoeken=true&amp;searchtype=ljn&amp;ljn=BD7578&amp;u_ljn=BD7578">Dutch court</a> would have none of it:  "Damage to NXP is not the result of the publication of the article but of the production and sale of a chip that appears to have shortcomings."</p>

<p>Exactly right. More generally, the notion that secrecy supports security is <a href="http://www.schneier.com/crypto-gram-0205.html#1">inherently flawed</a>. Whenever you see an organization claiming that design secrecy is necessary for security — in ID cards, in voting machines, in airport security — it invariably means that its security is lousy and it has no choice but to hide it. Any competent cryptographer would have designed Mifare's security with an open and public design.</p>

<p>Secrecy is fragile. Mifare's security was based on the belief that no one would discover how it worked; that's why NXP had to muzzle the Dutch researchers. But that's just wrong. Reverse-engineering isn't hard. <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=spam__malware_and_vulnerabilities&amp;articleId=9078038&amp;taxonomyId=85">Other</a> <a href="http://www.cs.virginia.edu/~evans/pubs/usenix08/">researchers</a> <a href="http://eprint.iacr.org/2008/166">had</a> <a href="http://staff.science.uva.nl/~delaat/sne-2006-2007/p41/Report.pdf">already</a> <a href="http://www.translink.nl/media/bijlagen/nieuws/TNO_ICT_-_Security_Analysis_OV-Chipkaart_-_public_report.pdf">exposed</a> Mifare's lousy security. A Chinese company even <a href="http://www.fmsh.com/english/product_chipcard.php?product=FM11RF32">sells</a> a <a href="http://www.fmsh.com/english/products/FM11RF32_FS_ENG.pdf">compatible chip</a>. Is there any doubt that the bad guys already know about this, or will soon enough?</p>

<p>Publication of this attack might be expensive for NXP and its customers, but it's good for security overall. Companies will only design security as good as their customers know to ask for. NXP's security was so bad because customers didn't know how to evaluate security: either they don't know what questions to ask, or didn't know enough to distrust the marketing answers they were given. This court ruling encourages companies to build security properly rather than relying on shoddy design and secrecy, and discourages them from promising security based on their ability to threaten researchers.</p>

<p>It's unclear how this break will affect <a href="http://www.tfl.gov.uk/">Transport for London</a>. Cloning takes only a few seconds, and the thief only has to brush up against someone carrying a legitimate Oyster card. But it requires an RFID reader and a small piece of software which, while feasible for a techie, are too complicated for the average fare dodger. The police are likely to quickly arrest anyone who tries to sell cloned cards on any scale. TfL <a href="http://news.cnet.co.uk/software/0,39029694,49297810,00.htm">promises</a> <a href="http://www.techradar.com/news/world-of-tech/tfl-responds-to-oyster-hack-runling-428238">to</a> turn off any cloned cards within 24 hours, but that will hurt the innocent victim who had his card cloned more than the thief.</p>

<p>The vulnerability is far more serious to the companies that use Mifare Classic as an access pass. It would be very interesting to know how NXP presented the system's security to them.</p>

<p>And while these attacks only pertain to the Mifare Classic chip, it makes me suspicious of the entire product line. NXP sells a more secure chip and has another on the way, but given the number of basic cryptography mistakes NXP made with Mifare Classic, one has to wonder whether the "more secure" versions will be sufficiently so.</p>

<p>This essay <a href="http://www.guardian.co.uk/technology/2008/aug/07/hacking.security">originally appeared</a> in the <i>Guardian</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=lyT29K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=lyT29K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=3HhhnK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=3HhhnK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 02:07:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mifare">mifare</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <category domain="http://securityratty.com/tag/design secrecy">design secrecy</category>
      <category domain="http://securityratty.com/tag/mifare classic chip">mifare classic chip</category>
      <category domain="http://securityratty.com/tag/secrecy">secrecy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/secrecy supports security">secrecy supports security</category>
      <category domain="http://securityratty.com/tag/security properly">security properly</category>
      <category domain="http://securityratty.com/tag/chip">chip</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/hacking_mifare.html">Hacking Mifare Transport Cards</source>
    </item>
    <item>
      <title><![CDATA[SSO Summit Day One Morning Session]]></title>
      <link>http://securityratty.com/article/500327e2eca382c04451c330dcc1e875</link>
      <guid>http://securityratty.com/article/500327e2eca382c04451c330dcc1e875</guid>
      <description><![CDATA[I am at the SSO Summit , high in the Colorado mountains (9200 feet elevation to be exact), the I-70 West sign is one of my favorite road signs. Ping Identity has done a great job putting this...]]></description>
      <content:encoded><![CDATA[<div>I am at the <a href="http://www.ssosummit.com/">SSO Summit</a>, high in the Colorado mountains (9200 feet elevation to be exact), the I-70 West sign is one of my favorite road signs. <a href="http://www.pingidentity.com/">Ping Identity</a> has done a great job putting this together. It is the perfect size around 125 people. Most of the best conferences I have been to have been around 60-150 people. There are a *lot* of enterprises involved here. </div><br><div>John Haggard who has an extensive background in SSO and lately is at Passfaces kicked off the sessions with a SSO history talk. Going through a lot of mainframe centric SSO protocols from the 80s and 90s, I am no expert in these areas and it was fascinating to see the way things vacillated between strength and weakness of SSO protocols.</div><br><div>A couple of points from the presentation:</div><br><div><blockquote><p>The history of SSO is a story of extreme complexities, compromises, vulnerabilities and unintended consequences.</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>SSO is a story of one simple objective - to spin off units of computation work to execute on behalf of an authenticated user without requiring the original user's password.</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>Phishing has always been completely avoidable</p></blockquote></div><br><div>He went through the various incarnations of mainframe SSO from logon id through things like ACF2, VTAM Session managers, terminal emulators, multiplatform access to web access through facades. The implication he drew from this last step are well worth repeating: "Time to rethink everything." Problem is - of course, people don't rethink, they put MQ Series in front of the mainframe and hook a web app in front of that and go. </div><br><div>Finally, he connected some interesting dots to SAML and SOA security issues. </div><br><div><blockquote><p>SSO without strong auth is and always will be simply nuts</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>SAML gets its right</p></blockquote></div><div>His points around common weaknesses in integration in SOA and Web 2.0 technologies for companies that are *not* using SAML were excellent. Of course, I will go into some more details on this tomorrow.</div><br><div>Ping's CTO Patrick Harding took the stage and gave an overview of the next generation of SSO options from Kerberos to present and as is his wont demonstrated various real world strengths and weaknesses, quoted a Gartner analyst (shock!) saying OpenID is the hare and Cardspace is the tortoise. Nice.</div><br><div>Andrew Cameron from GM is speaking now on GM's experiences implementing SSO, and there are a lot of real world lessons learned in his presentation.  Plus my favorite identity architecture, user has Kerberos, services speak SAML. very nice, very scalable. All in all, its my starting point for how to identity in an enterprise. He also spoke about a pet peeve of mine - how to globalize authorization. This is not a problem that vendors have historically attacked with relish. They are very happy to help you solve authentication, but they are perfectly happy to keep their authorization internal either for vendor lock in reasons and/or for sloppy authorization design. This will take a LIberty-esque consortium of enterprises to resolve. </div><br><div>So many conferences are dominated by vendors and consultants who conspire to what I call the "sacred church of things YOU should be doing." Instead this conference is bringing together a great mix of real world in the trenches practitioners who have problems to solve today, with rubber meets the road deployable solutions and an eye towards longer term strategy for SSO and identity.</div>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 09:35:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sso">sso</category>
      <category domain="http://securityratty.com/tag/sso history talk">sso history talk</category>
      <category domain="http://securityratty.com/tag/sso summit">sso summit</category>
      <category domain="http://securityratty.com/tag/mainframe sso">mainframe sso</category>
      <category domain="http://securityratty.com/tag/sso options">sso options</category>
      <category domain="http://securityratty.com/tag/sso protocols">sso protocols</category>
      <category domain="http://securityratty.com/tag/real world">real world</category>
      <category domain="http://securityratty.com/tag/real world lessons">real world lessons</category>
      <category domain="http://securityratty.com/tag/authorization internal">authorization internal</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/sso-summit-day-one-morning-session.html">SSO Summit Day One Morning Session</source>
    </item>
    <item>
      <title><![CDATA[Companies getting the knack of NAC]]></title>
      <link>http://securityratty.com/article/c970d537713fe4f43fb7490094c9e20a</link>
      <guid>http://securityratty.com/article/c970d537713fe4f43fb7490094c9e20a</guid>
      <description><![CDATA[For too long we have heard the NAC knockers bad mouthing the benefits of NAC and bemoaning its lack of adoption. I have always believed that much of this was marketing spin and that companies were...]]></description>
      <content:encoded><![CDATA[<p>For too long we have heard the NAC knockers bad mouthing the benefits of NAC and bemoaning its lack of adoption. I have always believed that much of this was marketing spin and that companies were finding NAC highly useful.  Typical hype cycle kind of stuff. At the end of the day though nothing speaks like real world references by customers stepping up and publicly saying they use the product.  Of course, those of us in the security industry know that this is probably one of the hardest things to do. No one wants to stand up and say what they use for security.  This could give information to the bad guys and attract attention that many companies would rather not do.  At StillSecure this has always been a double edged sword for us. With many DoD networks using the product, we have not really been able to talk a lot about the great job our NAC product does on some of the most sensitive, mission critical networks in the world.  By the same token, usually we don’t announce or publicize many of the infrastructure providers who we partner with and who sell a re-branded version of our NAC product.</p>  <p>Recently several NAC customers have been stepping up and talking about how they use NAC and why. Last week there was a <a href="http://www.networkworld.com/news/2008/071808-estee-lauder.html?fsrc=netflash-rss">good article on Estee Lauder</a> using NAC first for guest access control and most recently an expansion of their NAC deployment to help with PCI compliance.  This week in an article with the usual left-handed compliments, Tim Greene in between quotes by the so called analyst experts, talks about several NAC companies rolling out NAC.  One is <a href="http://www.networkworld.com/news/2008/072108-network-access-control.html?page=2">American Bancard, another StillSecure customer</a> who uses NAC to help with PCI and keep their network secure. The article talks about several other companies using NAC solutions from other vendors as well, which is also very encouraging.  Of course the companies I have spoken about I know for a fact are using NAC.  With some of the competition, you cannot always be sure as <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/the-used-car-sa.html">I have written about</a> in the past.</p>  <p>In any event, I think it is important that we are starting to see some real public references for NAC deployments.  Nothing proves the point of a products value than real live customers stepping up and talking about it!</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=VrwPHb"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=VrwPHb" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=eDlNrJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=eDlNrJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wQZUwJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wQZUwJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Hbf4XJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Hbf4XJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=vuh3hJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=vuh3hJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=MifvMj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=MifvMj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=6EXjKj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=6EXjKj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/341505996" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 03:43:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nac">nac</category>
      <category domain="http://securityratty.com/tag/nac deployments">nac deployments</category>
      <category domain="http://securityratty.com/tag/nac solutions">nac solutions</category>
      <category domain="http://securityratty.com/tag/nac deployment">nac deployment</category>
      <category domain="http://securityratty.com/tag/nac companies">nac companies</category>
      <category domain="http://securityratty.com/tag/nac knockers bad">nac knockers bad</category>
      <category domain="http://securityratty.com/tag/nac customers">nac customers</category>
      <category domain="http://securityratty.com/tag/nac product">nac product</category>
      <category domain="http://securityratty.com/tag/nac highly">nac highly</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/341505996/companies-getti.html">Companies getting the knack of NAC</source>
    </item>
    <item>
      <title><![CDATA[Assessing the Security Benefits of Cloud Computing]]></title>
      <link>http://securityratty.com/article/1e09e5c89f15d3a4df4ea921f9230c2d</link>
      <guid>http://securityratty.com/article/1e09e5c89f15d3a4df4ea921f9230c2d</guid>
      <description><![CDATA[With all this talk and reporting about security concerns, lets change the channel for a moment and assess the potential security benefits of Cloud Computing
In my view, there are some strong technical...]]></description>
      <content:encoded><![CDATA[<p><a title="Is the glass half empty or half full?" href="http://www.flickr.com/photos/94094843@N00/2292559560/" target="_blank"><img class="alignright" style="border: 0; float: right; margin: 3px;" src="http://farm4.static.flickr.com/3004/2292559560_378f226531_m.jpg" border="0" alt="Is the glass half empty or half full?" /></a></p>
<p>With all this <a href="http://cloudsecurity.org">talk</a> and <a href="http://www.gartner.com/DisplayDocument?id=685308">reporting</a> about security concerns, lets change the channel for a moment and assess the <strong>potential security benefits</strong> of Cloud Computing.</p>
<p>In my view, there are some strong technical security arguments in favour of Cloud Computing - assuming we can find ways to manage the risks.</p>
<p>With this new paradigm come challenges <strong>and </strong>opportunities.  The challenges are getting plenty of attention - I&#8217;m regularly afforded the opportunity to <a href="http://www.gridtoday.com/grid/2422309.html">comment</a> on them, plus obviously I cover them on this blog.  However, lets not lose sight of the potential upside.</p>
<p>In this post, I walk through seven technical security benefits.  Some are immediate, others may arise over time and have conditions attached (some unstated for the sake of brevity).  However, I&#8217;m including the longer-range benefits now to raise awareness.  Some of the outcomes listed are available today without the Cloud, but they are either complex and slow to implement (and thus less likely to happen) or prohibitive for capital cost reasons.  I don&#8217;t claim this is a definitive list - it reflects where my thinking is today.</p>
<p>Some benefits depend on the Cloud service used and therefore do not apply across the board.  For example; I see no solid forensic benefits with SaaS.  Also, for space reasons, I&#8217;m purposely not including the &#8216;flip side&#8217; to these benefits, however if you read this blog regularly you should <a href="http://cloudsecurity.org/2008/04/24/cloud-stacks-please-mind-the-gap/">recognise some</a>.</p>
<p>On a sidenote, I believe the Cloud offers Small and Medium Businesses major potential security benefits.  Frequently SMBs struggle with limited or non-existent in-house INFOSEC resources and budgets.  The caveat is that the Cloud market is still very new - security offerings are somewhat foggy - making selection tricky.  Clearly, not all Cloud providers will offer the same security.</p>
<h4>Seven Technical Security Benefits of the Cloud</h4>
<h4>1. Centralised Data</h4>
<ul>
<li><strong>Reduced Data Leakage</strong>: this is the benefit I hear most from Cloud providers - and in my view they are right.  How many laptops do we need to lose before we get this?  How many backup tapes?  The data &#8220;landmines&#8221; of today could be greatly reduced by the Cloud as thin client technology becomes prevalent.  Small, temporary caches on handheld devices or Netbook computers pose less risk than transporting data buckets in the form of laptops.  Ask the CISO of any large company if all laptops have company &#8216;mandated&#8217; controls consistently applied; e.g. full disk encryption.  You&#8217;ll see the answer by looking at the whites of their eyes.  Despite best efforts around asset management and endpoint security we continue to see embarrassing and disturbing misses.  And what about SMBs?  How many use encryption for sensitive data, or even have a data classification policy in place?</li>
<li><strong>Monitoring benefits</strong>: central storage is easier to control and monitor.  The flipside is the nightmare scenario of <a href="http://www.gnucitizen.org/blog/most-attractive-targets-saas/">comprehensive data theft</a>.  However, I would rather spend my time as a security professional figuring out smart ways to protect and monitor access to data stored in one place (with the benefit of situational advantage) than trying to figure out all the places where the company data resides across a myriad of thick clients!  You can get the benefits of Thin Clients today but Cloud Storage provides a way to centralise the data faster and potentially cheaper.  The logistical challenge today is getting Terabytes of data to the Cloud in the first place.</li>
</ul>
<h4>2. Incident Response / Forensics</h4>
<ul>
<li><strong>Forensic readiness</strong>: with Infrastructure as a Service (IaaS) providers, I can build a dedicated forensic server in the same Cloud as my company and place it offline, ready for use when needed.  I would only need pay for storage until an incident happens and I need to bring it online.  I don&#8217;t need to call someone to bring it online or install some kind of remote boot software - I just click a button in the Cloud Providers web interface.  If I have multiple incident responders, I can give them a copy of the VM so we can distribute the forensic workload based on the job at hand or as new sources of evidence arise and need analysis.  To fully realise this benefit, commercial forensic software vendors would need to move away from archaic, physical dongle based licensing schemes to a network licensing model.</li>
<li><strong>Decrease evidence acquisition time</strong>: if a server in the Cloud gets compromised (i.e. broken into), I can now clone that server at the click of a mouse and make the cloned disks instantly available to my Cloud Forensics server.  I didn&#8217;t need to &#8220;find&#8221; storage or have it &#8220;ready, waiting and unused&#8221; - its just there.</li>
<li><strong>Eliminate or reduce service downtime</strong>: Note that in the above scenario I didn&#8217;t have to go tell the COO that the system needs to be taken offline for hours whilst I dig around in the RAID Array hoping that my physical acqusition toolkit is compatible (and that the version of RAID firmware isn&#8217;t supported by my forensic software).  Abstracting the hardware removes a barrier to even doing forensics in some situations.</li>
<li><strong>Decrease evidence transfer time</strong>: In the same Cloud, bit fot bit copies are super fast - made faster by that replicated, distributed filesystem my Cloud provider engineered for me.  From a network traffic perspective, it may even be free to make the copy in the same Cloud.  Without the Cloud, <strong>I </strong>would have to a lot of time consuming and expensive provisioning of physical devices.  I only pay for the storage as long as I need the evidence.</li>
<li><strong>Eliminate forensic image verification time</strong>: Some Cloud Storage implementations expose a cryptographic checksum or hash.  For example, Amazon S3 generates an MD5 hash <a href="http://docs.amazonwebservices.com/AmazonS3/2006-03-01/index.html?RESTObjectPUT.html">automagically</a> when you store an object.  In theory you no longer need to generate time-consuming MD5 checksums using external tools - its already there.</li>
<li><strong>Decrease time to access protected documents</strong>: Immense CPU power opens some doors.  Did the suspect password protect a document that is relevant to the investigation?  You can now test a wider range of candidate passwords in less time to speed investigations.</li>
</ul>
<h4>3. Password assurance testing (aka cracking)</h4>
<ul>
<li><strong>Decrease password cracking time</strong>: if your organisation regularly tests password strength by running password crackers you can use Cloud Compute to decrease crack time and you only pay for what you use.  Ironically, your cracking costs go up as people choose better passwords ;-).</li>
<li><strong>Keep cracking activities to dedicated machines</strong>: if today you use a distributed password cracker to spread the load across non-production machines, you can now put those agents in dedicated Compute instances - and thus stop mixing sensitive credentials with other workloads.</li>
</ul>
<h4>4. Logging</h4>
<ul>
<li><strong>&#8220;Unlimited&#8221;, pay per drink storage</strong>: logging is often an afterthought, consequently insufficient disk space is allocated and logging is either non-existant or minimal.  Cloud Storage changes all this - no more &#8216;guessing&#8217; how much storage you need for standard logs.</li>
<li><strong>Improve log indexing and search</strong>: with your logs in the Cloud you can leverage Cloud Compute to index those logs in real-time and get the benefit of <a href="http://blogs.splunk.com/thewilde/2008/06/24/splunk-ninja-inside-the-cloud/">instant search results.</a> What is different here?  The Compute instances can be plumbed in and scale as needed based on the logging load - meaning a true real-time view.</li>
<li><strong>Getting compliant with Extended logging</strong>: most modern operating systems offer extended logging in the form of a C2 audit trail.  This is rarely enabled for fear of performance degradation and log size.  Now you can &#8216;opt-in&#8217; easily - if you are willing to pay for the enhanced logging, you can do so.  Granular logging makes compliance and investigations easier.</li>
</ul>
<h4>5. Improve the state of security software (performance)</h4>
<ul>
<li><strong>Drive vendors to create more efficient security software</strong>: Billable CPU cycles get noticed.  More attention will be paid to inefficient processes; e.g. poorly tuned security agents.  Process accounting will make a comeback as customers target &#8216;expensive&#8217; processes.  Security vendors that understand how to squeeze the most performance from their software will win.</li>
</ul>
<h4>6. Secure builds</h4>
<ul>
<li><strong>Pre-hardened, change control builds</strong>: this is primarily a benefit of virtualization based Cloud Computing.  Now you get a chance to start &#8217;secure&#8217; (by your own definition) - you create your Gold Image VM and clone away.  There are ways to do this today with bare-metal OS installs but frequently these require additional 3rd party tools, are time consuming to clone or add yet another agent to each endpoint.</li>
<li><strong>Reduce exposure through patching offline</strong>: Gold images can be kept up securely kept up to date.  Offline VMs can be conveniently patched &#8220;off&#8221; the network.</li>
<li><strong>Easier to test impact of security changes</strong>: this is a big one.  Spin up a copy of your production environment, implement a security change and test the impact at low cost, with minimal startup time.  This is a big deal and removes a major barrier to &#8216;doing&#8217; security in production environments.</li>
</ul>
<h4>7. Security Testing</h4>
<ul>
<li><strong>Reduce cost of testing security: </strong>a SaaS provider only passes on a portion of their security testing costs.  By sharing the same application as a service, you don&#8217;t foot the expensive security code review and/or penetration test.  Even with Platform as a Service (PaaS) where your developers get to write code, there are potential cost economies of scale (particularly around use of code scanning tools that sweep source code for security weaknesses).</li>
</ul>
<h4>Your Thoughts?</h4>
<p>What benefits do you see that I haven&#8217;t included in the above list?  Where do you agree/disagree and importantly, why?</p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/341289594" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 03:00:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/benefits">benefits</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/technical security benefits">technical security benefits</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <category domain="http://securityratty.com/tag/virtualization based cloud">virtualization based cloud</category>
      <category domain="http://securityratty.com/tag/efficient security software">efficient security software</category>
      <category domain="http://securityratty.com/tag/security software">security software</category>
      <category domain="http://securityratty.com/tag/cloud market">cloud market</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/341289594/">Assessing the Security Benefits of Cloud Computing</source>
    </item>
    <item>
      <title><![CDATA[Links List 7.18.08]]></title>
      <link>http://securityratty.com/article/151ccaa0a98349de52ec7c2e94b6620f</link>
      <guid>http://securityratty.com/article/151ccaa0a98349de52ec7c2e94b6620f</guid>
      <description><![CDATA[Rodrigues &amp; Urlocker had a nice spin on an announcement about security vulnerabilities in the Spring Framework . How could these vulnerabilities have gone unnoticed for so long? After all, isnt one of...]]></description>
      <content:encoded><![CDATA[<p><a href="http://weblog.infoworld.com/openresource/archives/2008/07/do_developers_s.html" target="_blank">Rodrigues &amp; Urlocker</a> had a nice spin on an announcement about security vulnerabilities in the <a href="http://blog.springsource.com/main/2008/05/27/open-source-open-strategy-the-springsource-manifesto/" target="_blank">Spring Framework</a>. How could these vulnerabilities have gone unnoticed for so long? “After all, isn’t one of the hallmarks of open source the strong community vetting?”
<p>Stacey Higginbotham adds a “<a href="http://gigaom.com/2008/07/01/10-reasons-enterprises-arent-ready-to-trust-the-cloud/" target="_blank">dose of reality</a>” to the cloud computing craze in her post on “10 Reasons Enterprises Aren’t Ready to Trust the Cloud”. Check the link for the full list which include security, portability and <a href="http://blogs.zdnet.com/BTL/?p=8010&amp;tag=rbxccnbzd1" target="_blank">reliability</a>. Cloud Computing – the next big thing, emphasis on “next”.
<p><a href="http://www.networkperformancedaily.com/2008/07/correction_not_technically_why.html" target="_blank">This</a> just tickled my funny bone. And made me feel sorry for a certain technical marketing manager… But really, if it’s that hard to explain where the name came from, you’re not paying your marketing people enough. ;-p
<p>As IT spending growth slows, <a href="http://blogs.wsj.com/biztech/2008/07/14/tech-departments-cutting-back-on-big-projects/?mod=djemTECH" target="_blank">virtualization (and the ROI it promises) rises to the top</a>. According to a Goldman Sachs report, <a href="http://news.cnet.com/8301-13505_3-9986239-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">“server virtualization” and “consolidation” are the top priorities</a> for technology executives. Goldman predicts the overall growth in spending to slip from “<a href="http://virtualization.com/news/2008/07/10/goldman-sachs-prediction/" target="_blank">7 percent to 5 percent this year</a>.”
<p>Butler Group analyst Roy Illsley shares his advice for implementing <a href="http://www.baselinemag.com/c/a/IT-Management/10-Steps-to-Simplifying-Systems-Management/" target="_blank">holistic systems management</a> or “simplification, so that the IT department can manage the technology stack at a higher level, and therefore enable it to manage a wider range of technologies more efficiently. Hmm… simplifying IT, breaking down silos, automation, visibility across heterogeneous infrastructure…sounds very very <a href="http://www.sciencelogic.com/" target="_blank">familiar</a>. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Links+List+7.18.08&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Flinks-list-71808%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 18:14:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/server virtualization">server virtualization</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/growth slows">growth slows</category>
      <category domain="http://securityratty.com/tag/security vulnerabilities">security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/holistic systems management">holistic systems management</category>
      <category domain="http://securityratty.com/tag/goldman sachs report">goldman sachs report</category>
      <category domain="http://securityratty.com/tag/growth">growth</category>
      <source url="http://blog.sciencelogic.com/links-list-71808/07/2008">Links List 7.18.08</source>
    </item>
  </channel>
</rss>
