<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: technologies]]></title>
    <link>http://securityratty.com/tag/technologies</link>
    <description></description>
    <pubDate>Mon, 29 Sep 2008 23:00:37 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Symantec's vision...]]></title>
      <link>http://securityratty.com/article/0a12c35a88cbf21c5df24b956fdc875d</link>
      <guid>http://securityratty.com/article/0a12c35a88cbf21c5df24b956fdc875d</guid>
      <description><![CDATA[And so it begins

Symantec bought out MessageLabs and is (in their own words) &quot;combining MessageLabs deep expertise in the SaaS market with Symantecs rich portfolio of technologies

The interesting...]]></description>
      <content:encoded><![CDATA[And so it begins...<br /><br /><a href="http://www.symantec.com/about/news/release/article.jsp?prid=20081008_02">Symantec bought out MessageLabs</a> and is (in their own words) "combining MessageLabs’ deep expertise in the SaaS market with Symantec’s rich  portfolio of technologies".<br /><br />The interesting thing is that Symantec does not really lead in the anti-virus market (in terms of quality, not market share. All antivirus products are about the same) or antispam (MessageLabs is excellent here).<br /><br />So, what could they possibly bring to the party that MessageLabs doesn't already have?<br /><br />DLP.<br /><br />MessageLabs has DLP but it is very simple and not really worth very much. The framework is certainly there though. Add some good DLP and voila - you have a product that is worth something.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/416721491" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 07:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/messagelabs">messagelabs</category>
      <category domain="http://securityratty.com/tag/messagelabs deep expertise">messagelabs deep expertise</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/symantecs rich portfolio">symantecs rich portfolio</category>
      <category domain="http://securityratty.com/tag/saas market">saas market</category>
      <category domain="http://securityratty.com/tag/worth">worth</category>
      <category domain="http://securityratty.com/tag/anti-virus market">anti-virus market</category>
      <category domain="http://securityratty.com/tag/market share">market share</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/416721491/symantecs-vision.html">Symantec's vision...</source>
    </item>
    <item>
      <title><![CDATA[Data Mining for Terrorists Doesn't Work]]></title>
      <link>http://securityratty.com/article/205a9261660e694f495f2a2726701cd2</link>
      <guid>http://securityratty.com/article/205a9261660e694f495f2a2726701cd2</guid>
      <description><![CDATA[According to a massive report from the National Research Council, data mining for terrorists doesn't work. Here's a good summary: The report was written by a committee whose members include William...]]></description>
      <content:encoded><![CDATA[<p>According to a <a href="http://www.nap.edu/catalog.php?record_id=12452">massive report</a> from the National Research Council, data mining for terrorists doesn't work.  <a href="http://news.cnet.com/8301-13578_3-10059987-38.html?part=rss&subj=news&tag=2547-1_3-0-20">Here's</a> a good summary:</p>

<blockquote>The report was written by a committee whose members include William Perry, a professor at Stanford University; Charles Vest, the former president of MIT; W. Earl Boebert, a retired senior scientist at Sandia National Laboratories; Cynthia Dwork of Microsoft Research; R. Gil Kerlikowske, Seattle's police chief; and Daryl Pregibon, a research scientist at Google.

<p>They admit that far more Americans live their lives online, using everything from VoIP phones to Facebook to RFID tags in automobiles, than a decade ago, and the databases created by those activities are tempting targets for federal agencies. And they draw a distinction between subject-based data mining (starting with one individual and looking for connections) compared with pattern-based data mining (looking for anomalous activities that could show illegal activities).</p>

<p>But the authors conclude the type of data mining that government bureaucrats would like to do--perhaps inspired by watching too many episodes of the Fox series 24--can't work. "If it were possible to automatically find the digital tracks of terrorists and automatically monitor only the communications of terrorists, public policy choices in this domain would be much simpler. But it is not possible to do so."</p>

<p>A summary of the recommendations:</p>

<ul><li>U.S. government agencies should be required to follow a systematic process to evaluate the effectiveness, lawfulness, and consistency with U.S. values of every information-based program, whether classified or unclassified, for detecting and countering terrorists before it can be deployed, and periodically thereafter.

<p><li>Periodically after a program has been operationally deployed, and in particular before a program enters a new phase in its life cycle, policy makers should (carefully review) the program before allowing it to continue operations or to proceed to the next phase.</p>

<p><li>To protect the privacy of innocent people, the research and development of any information-based counterterrorism program should be conducted with synthetic population data... At all stages of a phased deployment, data about individuals should be rigorously subjected to the full safeguards of the framework.</p>

<p><li>Any information-based counterterrorism program of the U.S. government should be subjected to robust, independent oversight of the operations of that program, a part of which would entail a practice of using the same data mining technologies to "mine the miners and track the trackers."</p>

<p><li>Counterterrorism programs should provide meaningful redress to any individuals inappropriately harmed by their operation.</p>

<p><li>The U.S. government should periodically review the nation's laws, policies, and procedures that protect individuals' private information for relevance and effectiveness in light of changing technologies and circumstances. In particular, Congress should re-examine existing law to consider how privacy should be protected in the context of information-based programs (e.g., data mining) for counterterrorism.</ul></blockquote></p>

<p><a href="http://www.nytimes.com/2008/10/08/washington/08data.html">Here</a> <a href="http://blog.wired.com/27bstroke6/2008/10/data-mining-for.html">are</a> <a href="http://techdirt.com/articles/20081007/1242002479.shtml">more</a> news articles on the report.  I <a href="http://www.schneier.com/essay-108.html">explained</a> why data mining wouldn't find terrorists back in 2005.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=w2YwM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=w2YwM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=sK5kM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=sK5kM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 02:35:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/synthetic population data">synthetic population data</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/program">program</category>
      <category domain="http://securityratty.com/tag/program enters">program enters</category>
      <category domain="http://securityratty.com/tag/research scientist">research scientist</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/microsoft research">microsoft research</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/data_mining_for_1.html">Data Mining for Terrorists Doesn't Work</source>
    </item>
    <item>
      <title><![CDATA[Privacy Enhancing Technologies Symposium (PETS 2009)]]></title>
      <link>http://securityratty.com/article/d1f9c5c63e96cff3264722a39926652a</link>
      <guid>http://securityratty.com/article/d1f9c5c63e96cff3264722a39926652a</guid>
      <description><![CDATA[I am on the program committee for the 9th Privacy Enhancing Technologies Symposium (PETS 2009) , to be held in Seattle, WA, USA, 57 August 2009. PETS is the leading venue for research on privacy and...]]></description>
      <content:encoded><![CDATA[<p>I am on the program committee for the 9th <a href="http://petsymposium.org/2009/">Privacy Enhancing Technologies Symposium (PETS 2009)</a>, to be held in Seattle, WA, USA, 5&ndash;7 August 2009. PETS is the leading venue for research on privacy and anonymity, offering an enjoyable environment and stimulating discussion. If you are working in this field, I can strongly recommend submitting a paper.</p>
<p>This year, we are particularly looking for submissions from topics other than anonymous communications, so if work from your field may be applied, or is otherwise related, to the topic of privacy, I&#8217;d encourage you to consider PETS as a potential venue.</p>
<p>The submission deadline for the main session is <strong>2 March 2009</strong>. As with last year, we will also have a &#8220;HotPETS&#8221; event, for new and exciting work in the field which is still in a formative state. Submissions for HotPETS should be received by <strong>8 May 2009</strong>.</p>
<p>Further information can be found in the <a href="http://petsymposium.org/2009/">call for papers</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 04:14:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/pets">pets</category>
      <category domain="http://securityratty.com/tag/9th privacy">9th privacy</category>
      <category domain="http://securityratty.com/tag/technologies symposium">technologies symposium</category>
      <category domain="http://securityratty.com/tag/hotpets">hotpets</category>
      <category domain="http://securityratty.com/tag/field">field</category>
      <category domain="http://securityratty.com/tag/hotpets event">hotpets event</category>
      <category domain="http://securityratty.com/tag/venue">venue</category>
      <category domain="http://securityratty.com/tag/potential venue">potential venue</category>
      <source url="http://www.lightbluetouchpaper.org/2008/10/08/pets-2009/">Privacy Enhancing Technologies Symposium (PETS 2009)</source>
    </item>
    <item>
      <title><![CDATA[Virtualization and Hardware-Based Security]]></title>
      <link>http://securityratty.com/article/e399d5e4376c70300c3e9c517803b75e</link>
      <guid>http://securityratty.com/article/e399d5e4376c70300c3e9c517803b75e</guid>
      <description><![CDATA[Hypervisors allow virtualization at the hardware level. These technologies have security-related strengths as well as weaknesses. The authors examine emerging hardware and software virtualization...]]></description>
      <content:encoded><![CDATA[Hypervisors allow virtualization at the hardware level. These technologies have security-related strengths as well as weaknesses. The authors examine emerging hardware and software virtualization technologies in the context of modern computing environments and requirements.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a1d3dea0db60e226c9c0ab477673b9e1" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a1d3dea0db60e226c9c0ab477673b9e1" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/hardware">hardware</category>
      <category domain="http://securityratty.com/tag/software virtualization technologies">software virtualization technologies</category>
      <category domain="http://securityratty.com/tag/technologies">technologies</category>
      <category domain="http://securityratty.com/tag/hardware level">hardware level</category>
      <category domain="http://securityratty.com/tag/authors examine">authors examine</category>
      <category domain="http://securityratty.com/tag/weaknesses">weaknesses</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/hypervisors">hypervisors</category>
      <source url="http://www.pheedo.com/click.phdo?i=a1d3dea0db60e226c9c0ab477673b9e1">Virtualization and Hardware-Based Security</source>
    </item>
    <item>
      <title><![CDATA[Virtual Machine Introspection: Observation or Interference?]]></title>
      <link>http://securityratty.com/article/d1c6610de201f53ac191754bc494d71c</link>
      <guid>http://securityratty.com/article/d1c6610de201f53ac191754bc494d71c</guid>
      <description><![CDATA[As virtualization becomes increasingly mainstream, virtual machine introspection techniques and tools are evolving to provide methods to monitor the behavior of virtual machines. This survey...]]></description>
      <content:encoded><![CDATA[As virtualization becomes increasingly mainstream, virtual machine introspection techniques and tools are evolving to provide methods to monitor the behavior of virtual machines. This survey classifies and describes current VMI introspection technologies according to three primary classifications: threat monitoring versus interference, semantic awareness, and event replay. The authors also describe the Virtual Introspection for Xen (VIX) tool suite, which was developed to address key VMI requirements, and outline key research areas for future investigation.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=41e08c548c8eab8a20dd182ad564facb"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=41e08c548c8eab8a20dd182ad564facb"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=41e08c548c8eab8a20dd182ad564facb" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/outline key research">outline key research</category>
      <category domain="http://securityratty.com/tag/semantic awareness">semantic awareness</category>
      <category domain="http://securityratty.com/tag/future investigation">future investigation</category>
      <category domain="http://securityratty.com/tag/tool suite">tool suite</category>
      <category domain="http://securityratty.com/tag/increasingly mainstream">increasingly mainstream</category>
      <category domain="http://securityratty.com/tag/provide methods">provide methods</category>
      <category domain="http://securityratty.com/tag/virtual machines">virtual machines</category>
      <category domain="http://securityratty.com/tag/virtual introspection">virtual introspection</category>
      <category domain="http://securityratty.com/tag/event replay">event replay</category>
      <source url="http://www.pheedo.com/click.phdo?i=41e08c548c8eab8a20dd182ad564facb">Virtual Machine Introspection: Observation or Interference?</source>
    </item>
    <item>
      <title><![CDATA[Innovators, Imitators and Idiots]]></title>
      <link>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</link>
      <guid>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</guid>
      <description><![CDATA[Charlie Rose interviews Warren Buffett


Charlie Rose
And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage. We just lost sight...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;">Charlie Rose <a href="http://www.cnbc.com/id/26982338/page/2/">interviews</a> Warren Buffett:</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage.&#0160; We just lost sight of risk and leverage of what was appropriate?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.&#0160; Again, because it pays off for a while.&#0160; You know, you can lose leverage, and it&#39;s the only way a smart guy can go broke.&#0160; If you owe money, you can&#39;t pay them out.&#0160; You just pay for everything, you do smart things, you eventually get very rich.&#0160; If you do smart things and use leverage and do one wrong thing along the way, it could wipe you out, because anything times zero is zero.&#0160; But it&#39;s reinforcing when the people around you are doing it successfully, you&#39;re doing it successfully, and it&#39;s a lot like Cinderella at the ball.&#0160; I mean you know at midnight everything is going to turn to pumpkins and mice; right?&#0160; But if the evening goes along, I mean, you know, the guys look better all the time, the music sounds better, it&#39;s more and more fun, you think why the hell should I leave at quarter of 12.&#0160; I&#39;ll leave at two minutes to 12.&#0160; But the trouble is, there are no clocks on the wall.&#0160; And everybody thinks they&#39;re going to leave at two minutes to 12.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Its effectively the job of leadership to know when to take the punch bowl away and to have the credibility to do this. This is also the risk-reward balance that infosec must try to strike, part of the answer is differentiating <a href="http://1raindrop.typepad.com/1_raindrop/2007/11/dhandho-infosec.html">risk and uncertainty</a>. As our current financial situation shows, its a hard thing to pull off</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And should wise people have known better?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">People should always know better.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">I mean people -- people don&#39;t get -- they don&#39;t get smarter about things that get as basic as greed and you can&#39;t stand to see your neighbor getting rich.&#0160; You know you&#39;re smarter than he is, and he&#39;s doing these things, you know, and he&#39;s getting rich, and your spouse is getting unhappy with you because you aren&#39;t doing -- pretty soon you start doing it.&#0160; And so you get what I call the natural progression, the three Is.&#0160; The innovators, the imitators, and the idiots.&#0160; And that&#39;s what happens.&#0160; Everybody just kind of goes along.&#0160; And you look kind of silly if you disagree.&#0160; I mean, you know, you could have these crazy Internet valuations in the late 1990s, but they prove themselves out in the market.&#0160; The next day they were selling for more than they were the day before, and people said, you know, you&#39;re crazy if you don&#39;t get in on this.&#0160; So it&#39;s very human.&#0160; Now, with housing it&#39;s something even more dramatic than that, because most people aspire to own their own home.&#0160; And if you really think that houses prices are going to go up next year and the year after, you feel if I don&#39;t buy it this year, I&#39;m going to have to buy it next year.&#0160; That&#39;s not true of an Internet stock.&#0160; But it&#39;s true of a home.&#0160; And when somebody makes it very easy for you to do it by saying you don&#39;t really have to put up my money, you can lie about your income a little, or we&#39;ll give you 100 percent mortgage, you&#39;re going to do it, because everybody that&#39;s done it has been proven right.&#0160; You have what they call social tools, and, you know, you&#39;re going to feel like an idiot if you didn&#39;t do it, because the house cost more.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">And this is why its hard to pull off. There is a lot of human emotion and envy (*). I think the point Buffett raises about innovators, imitators and idiots is a useful one for infosec. We see all kinds of new projects and technologies that have risks and rewards associated with them, its helpful to categorize these under innovation (high risk but possible game changer), imitators (so called best practices), and idiots (sheep mode - blind risk acceptance). We can get some traction here to use these concepts to understand what to do when assessing say the architectural and oeprational risk of a system.</span></div><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Finally, we should always spend some time to consider infosec decisions in a broader long term economic context and this is also true of our current financial crisis</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Oh, I think confidence will come back.&#0160; I will tell you this.&#0160; This country is going -- be living better ten years from now than it is now.&#0160; It will be living better in 20 years from now than ten years from now.&#0160; The ingredients that made this country, you know, the miracle of the world -- I mean we had a seven for one improvement in the average American standard of living in the 20th century.&#0160; Now, we had the great depression, we had two world wars, we had the flu epidemic.&#0160; You know, we had oil shock.&#0160; You know, we had all these terrible things happen.&#0160; But something about the American system unleashed more and of a potential to human beings over that hundred years so that we had a seven for one improvement in -- there&#39;s never been any -- I mean, you have centuries where if you&#39;ve got a 1 percent improvement, then it&#39;s something.&#0160; So we&#39;ve got a great system.&#0160; And we&#39;ve got more productive capacity now than we ever have.&#0160; The American worker is more productive than he&#39;s ever been.&#0160; We&#39;ve got more people to do it.&#0160; We&#39;ve got all the ingredients for a sensational future.&#0160; It&#39;s just that right now the athlete&#39;s on the floor.&#0160; But we -- this is a super athlete.</span></p></blockquote><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Again, we want to look at risk events in a broader, long term context. In Buffett&#39;s words its - &quot;be fearful when others are greedy and greedy when others are fearful.&quot; As the world panics and Jim Cramer is melting down on TV, Buffett is quietly writing checks with both hands, buying $3B of GE, $5B of Goldman, $6.5 of Wrigley/Mars and so on. Uncertainty is one thing, it could be 6 months it could be 5 years until this thing turns around, but risk is another - you hedge your risk with price and long term advantages, i.e. moats. People will still eat candy in a bad economy.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* Buffett&#39;s partner Charlie Munger calls envy the stupidest of the seven deadly sins, because only you feel bad, there is an upside to all the others. He said you can pay someone on Wall St $2 million a year and they will be perfectly happy until they find out someone across the hall is making $2.1 million and then they will be miserable. Which is an insane way tolive.</span></div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 04:32:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/oeprational risk">oeprational risk</category>
      <category domain="http://securityratty.com/tag/risk events">risk events</category>
      <category domain="http://securityratty.com/tag/risk-reward balance">risk-reward balance</category>
      <category domain="http://securityratty.com/tag/wise people">wise people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/buffett raises">buffett raises</category>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/blind risk acceptance">blind risk acceptance</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/innovators-imitators-and-idiots.html">Innovators, Imitators and Idiots</source>
    </item>
    <item>
      <title><![CDATA[PCI Bans WEP SecurityStarting 2010]]></title>
      <link>http://securityratty.com/article/5f38b99c3f2e614c14cdba03311ea183</link>
      <guid>http://securityratty.com/article/5f38b99c3f2e614c14cdba03311ea183</guid>
      <description><![CDATA[Version 1.2 for the PCI Data Security Standard was released last week
One interesting outcome is that the insecure wireless WEP protocol will be banned but not until June 2010. Says Ars Technica...]]></description>
      <content:encoded><![CDATA[<p>Version 1.2 for the PCI Data Security Standard was released last week.</p>
<p>One interesting outcome is that the insecure wireless <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081003-credit-card-processors-finally-get-clue-will-ban-wep.html">WEP</a> protocol will be <a rel="nofollow" target="_blank" href="http://wifinetnews.com/archives/008474.html">banned</a>&#8230;but not until June 2010. Says <a rel="nofollow" target="_blank" href="http://arstechnica.com/news.ars/post/20081003-credit-card-processors-finally-get-clue-will-ban-wep.html">Ars Technica</a>:</p>
<blockquote><p>Although TJX has become the poster-child for consumer data theft over WiFi, it is (by far) not the only company to use insecure wireless technologies. Wireless security manufacturer AirDefense released a report in late 2007 saying that a quarter of the 4,748 retail access points it surveyed across the US had no security whatsoever, while another quarter only used WEP, &#8220;one of the weakest protocols for wireless data encryption.&#8221; Just under half (49 percent) of the surveyed hotspots used WiFi Protected Access (WPA) or WPA 2—much stronger encryption protocols than WEP.</p></blockquote>
<p>If you&#8217;re wondering about what other impacts will have, you might want to read through the <a rel="nofollow" target="_blank" href="https://www.pcisecuritystandards.org/security_standards/supporting_documents.shtml">PCI site</a> or sign up for the<a rel="nofollow" target="_blank" href="http://www.secureworks.com/research/webcasts/20081014-gen-www"> SecureWorks webcast </a>on October 14th to learn more.</p>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 05:38:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wep">wep</category>
      <category domain="http://securityratty.com/tag/insecure wireless technologies">insecure wireless technologies</category>
      <category domain="http://securityratty.com/tag/wireless data encryption">wireless data encryption</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/retail access">retail access</category>
      <category domain="http://securityratty.com/tag/consumer data theft">consumer data theft</category>
      <category domain="http://securityratty.com/tag/secureworks webcast">secureworks webcast</category>
      <category domain="http://securityratty.com/tag/quarter">quarter</category>
      <category domain="http://securityratty.com/tag/security whatsoever">security whatsoever</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/412950080/">PCI Bans WEP SecurityStarting 2010</source>
    </item>
    <item>
      <title><![CDATA[IBM vets ID management, access control technologies on own systems]]></title>
      <link>http://securityratty.com/article/217e8d13f9228c6d834280430e360f8c</link>
      <guid>http://securityratty.com/article/217e8d13f9228c6d834280430e360f8c</guid>
      <description><![CDATA[Rather than selling only stand-alone security tools, IBM is working to embed antivirus, firewall and other security features into all of its software products, software chief Steve Mills...]]></description>
      <content:encoded><![CDATA[Rather than selling only stand-alone security tools, IBM is working to embed antivirus, firewall and other security features into all of its software products, software chief Steve Mills says.]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/stand-alone security tools">stand-alone security tools</category>
      <category domain="http://securityratty.com/tag/security features">security features</category>
      <category domain="http://securityratty.com/tag/ibm">ibm</category>
      <category domain="http://securityratty.com/tag/software products">software products</category>
      <category domain="http://securityratty.com/tag/embed antivirus">embed antivirus</category>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <source url="http://www.networkworld.com/news/2008/100208-ibm.html?fsrc=rss-security">IBM vets ID management, access control technologies on own systems</source>
    </item>
    <item>
      <title><![CDATA[When Psychology Meets Network Administration]]></title>
      <link>http://securityratty.com/article/23c491623112b8aea811acce4790d1a8</link>
      <guid>http://securityratty.com/article/23c491623112b8aea811acce4790d1a8</guid>
      <description><![CDATA[The library comic Unshelved has a fun strip todaywhere the new library intern announces she will reconfigure the network to correct the librarians snarky attitude. But can computer administrators...]]></description>
      <content:encoded><![CDATA[<p>The library comic Unshelved has a fun strip today&#8230;where the new library intern announces she will reconfigure the network to correct the librarian&#8217;s snarky attitude. But can computer administrators really control their users&#8217; behavior? Our fearless young librarian Dewey doesn&#8217;t seem too worried.</p>
<p><a rel="nofollow" target="_blank" href="http://www.unshelved.com/"><img class="alignnone" src="http://www.unshelved.com/strips/20080930.gif" alt="" width="600" height="210"/></a>Luckily we do have some technologies to warn users who still haven&#8217;t learned to stop opening spammy attachments, click pop up ads and so on&#8230;but I don&#8217;t think they&#8217;d help with the snarky attitude problems. I&#8217;m not sure I&#8217;d want my computer network to try doing that anyway.</p>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 11:17:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/snarky attitude">snarky attitude</category>
      <category domain="http://securityratty.com/tag/librarians snarky attitude">librarians snarky attitude</category>
      <category domain="http://securityratty.com/tag/library intern announces">library intern announces</category>
      <category domain="http://securityratty.com/tag/computer network">computer network</category>
      <category domain="http://securityratty.com/tag/fun strip todaywhere">fun strip todaywhere</category>
      <category domain="http://securityratty.com/tag/click pop">click pop</category>
      <category domain="http://securityratty.com/tag/librarian dewey">librarian dewey</category>
      <category domain="http://securityratty.com/tag/spammy attachments">spammy attachments</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/407690914/">When Psychology Meets Network Administration</source>
    </item>
    <item>
      <title><![CDATA[Interop NY Survey Top IT Challenges, Trends and What IT is Spending Money On]]></title>
      <link>http://securityratty.com/article/c1238f65d5c0144adeaaf578e8e7de08</link>
      <guid>http://securityratty.com/article/c1238f65d5c0144adeaaf578e8e7de08</guid>
      <description><![CDATA[I wont belabor the point again but just mention it as context for the 2nd annual survey we conducted at Interop NY this year. As I was dragging myself to the very early keynotes at VMworld , things...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/survey-poll.jpg" border="0" alt="survey_poll" width="240" height="240" align="left" /> I won’t belabor the point again but just mention it as context for the <a href="http://www.sciencelogic.com/pressrelease_20080925.htm" target="_blank">2nd annual survey</a> we conducted at <a href="http://www.interop.com/" target="_blank">Interop NY</a> this year. As I was dragging myself to the very early keynotes at <a href="http://www.vmworld.com/vmworld/index.jspa" target="_blank">VMworld</a>, things were <a href="http://www.dailyreckoning.com.au/bailout-debate-rages-on/2008/09/25/" target="_blank">falling apart on Wall Street</a>, entire departments at <a href="http://www.doctorhousingbubble.com/lehman-brothers-the-rise-and-fall-of-lehman-brothers-a-history-that-goes-beyond-the-great-depression/" target="_blank">Lehman were being let go</a>, and the boys were in NYC getting the <a href="http://www.interop.com/lasvegas/exhibition/interopnet/" target="_blank">InteropNet</a> show network up and running.</p>
<p>By all accounts the show did go on, and we have some very interesting results to share with you all.</p>
<p>Take the Top Challenges question. Once again, “Supporting New Technologies/Enabling Innovation” was most popular. But that’s a no-brainer and as one memorable respondent told me, “the definition of what I do”. What was more important was seeing the big jump that “Reducing Management Costs” made on the list, from #5 last year to #2 this year and only 1 percentage point behind #1. Tightening the belt is top of mind for everyone. (<em>As I write, the <a href="http://eddriscoll.com/archives/014056.php" target="_blank">Dow closed down today over 700 points</a></em>)</p>
<p>Overall, IT professionals told us they were tackling the practical projects that should and could get done – from deploying Security Information Management solutions to getting Asset Management and Inventory Tools in place. For the first time, we saw a close correlation between what people said was important and what actually got done. Of low importance and even lower actual deployments – <a href="http://www.processor.com/editorial/article.asp?article=articles%2Fp2931%2F33p31%2F33p31.asp" target="_blank">ITIL</a> and <a href="http://www.processor.com/editorial/article.asp?article=articles%2Fp2931%2F33p31%2F33p31.asp" target="_blank">CMDB</a>, <a href="http://www.pcmag.com/article2/0,2817,2325880,00.asp" target="_blank">IPv6</a>, <a href="http://www.greenm3.com/2008/09/state-cios-driv.html" target="_blank">Green IT</a> and <a href="http://www.techlinks.net/blogs/publishing/archive/2008/09/22/is-the-internet-ready-for-cloud-computing.aspx" target="_blank">Cloud Computing</a>.</p>
<p>And perhaps people “fessed” up about virtualization. Instead of the usual “high importance, not so many deployments now, but more deployments planned” theme we’ve been seeing around virtualization adoption, this year the very hot trend seemed to lose a bit of steam. Across the board, the numbers were down for <a href="http://www.echannelline.com/usa/story.cfm?item=23739" target="_blank">virtualization management</a>, with close to 50% of respondents telling us that their businesses were less than 10% virtualized (4% of that with no virtualization at all).</p>
<p>2008 Detailed Results – <a href="http://www.sciencelogic.com/pdf/InteropNY2008_Survey_Trends.pdf" target="_blank">showing trends year over year</a></p>
<p>Comparison of <a href="http://www.sciencelogic.com/pdf/FOSE2008_vs_2008InteropNY.pdf" target="_blank">Results from Interop NY 2008 vs FOSE 2008</a> (government IT)</p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 23:00:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization management">virtualization management</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/top challenges question">top challenges question</category>
      <category domain="http://securityratty.com/tag/virtualization adoption">virtualization adoption</category>
      <category domain="http://securityratty.com/tag/importance">importance</category>
      <category domain="http://securityratty.com/tag/close correlation">close correlation</category>
      <category domain="http://securityratty.com/tag/2nd annual survey">2nd annual survey</category>
      <source url="http://blog.sciencelogic.com/interop-ny-survey-top-it-challenges-trends-and-what-it-is-spending-money-on/09/2008">Interop NY Survey Top IT Challenges, Trends and What IT is Spending Money On</source>
    </item>
  </channel>
</rss>
