<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: town]]></title>
    <link>http://securityratty.com/tag/town</link>
    <description></description>
    <pubDate>Mon, 21 Jul 2008 09:46:05 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Fourteen]]></title>
      <link>http://securityratty.com/article/73e2f5bbd0d3a35e2885b12071151835</link>
      <guid>http://securityratty.com/article/73e2f5bbd0d3a35e2885b12071151835</guid>
      <description><![CDATA[You didn't even think for a second that the supply of typosqutted domains serving packed and triple crypted to the point where the binary is not longer executing, fake security software domains is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6gDFZUyYI/AAAAAAAACek/i5D-GnO-3xw/s1600-h/microav_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6gDFZUyYI/AAAAAAAACek/i5D-GnO-3xw/s200/microav_rogue_november.png" /></a>You didn't even think for a second that the supply of typosqutted domains serving packed and triple crypted to the point where the binary is not longer executing, fake security software domains is declining? With the upcoming holidays and the usual peak of web traffic, malicious activity on all fronts is prone to increase during December. <b>YEWGATE LTD</b>, <b>Sawert Alliance</b>, and <b>Sagent Group</b>, personal favorites affiliate participants in a revenue sharing program for serving fake security software, try to maintain a decent rhythm in their typosquatting process, always worth taking a peek at. The very latest rogue security software additions include :<br />
<br />
<b>micro-antiv2009 .com</b> (91.208.0.223)<br />
<b>micro-antivir2009 .com</b><br />
<b>micro-antivirus-2009 .com </b><br />
<b>micro-av-2009 .com</b><br />
<br />
<i>Sawert Alliance<br />
Peltonen Martti&nbsp; <b>seodancer@gmail.com</b><br />
33 New Road, Upper Flat<br />
Belize City<br />
Belize<br />
Tel: +7.9602578790</i><br />
<br />
<div class="separator" style="clear: both; text-align: center;"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SS6gYmAzMwI/AAAAAAAACes/C-aMLs7jDR0/s1600-h/spyware_remover_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SS6gYmAzMwI/AAAAAAAACes/C-aMLs7jDR0/s200/spyware_remover_rogue_november.png" /></a></div><b>avmyscan .com</b> (91.203.92.186; 78.157.143.184)<br />
<b>go-your-scan .com</b><br />
<b>bestproscan .com</b><br />
<b>avproscan .com</b><br />
<b>goyourscan .com</b><br />
<b>iabestscan .com</b><br />
<b>avmyscan .com</b><br />
<b>best-scan-pro .com</b><br />
<b>avscan-pro .com</b><br />
<b>bestscanner-pro .com</b><br />
<b>avscanpro .com</b><br />
<b>iascannerpro .com</b><br />
<br />
<i>Jaroslav Voltz<br />
Email: <b>mensfult@gmail.com</b><br />
Organization: Private person<br />
Address: Biskupsk 9<br />
City: Praha<br />
State: Praha<br />
ZIP: 11000<br />
Country: CZ<br />
Phone: +420.2224811382</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SS6g2pEJdbI/AAAAAAAACe0/Xt2MaDdDgvk/s1600-h/sagent_group_rogue.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SS6g2pEJdbI/AAAAAAAACe0/Xt2MaDdDgvk/s200/sagent_group_rogue.png" /></a><b>virus-labs2009 .com</b> (66.232.113.62)<br />
<b>virus-trigger .com<br />
virusresponse2009 .com<br />
virusresplab .com<br />
virus-response .com</b><br />
<br />
<i>Roman Spitsikov<br />
Uus-Sadama 12&nbsp; <br />
Tallinn, Tallinn 10120<br />
Estonia<br />
<b>Roman.Spitsikov@gmail.com</b></i><br />
<br />
<b>virusremover2008plus .com</b> (77.245.61.80; 93.190.139.229)<br />
<br />
<i>Sagent Group&nbsp; (<b>sergbelo@gmail.com</b>)<br />
Brignal Solutions<br />
P.O. Box 3469 Geneva Place, Waterfront drive <br />
Road town,&nbsp;&nbsp; BVI<br />
BZ<br />
+1.14193017015</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6g-80BKPI/AAAAAAAACe8/33Am0K6PBKI/s1600-h/sagent_group_rogue_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SS6g-80BKPI/AAAAAAAACe8/33Am0K6PBKI/s200/sagent_group_rogue_2.png" /></a><b>antivirus-pro-scan.com</b> (84.243.197.183)<br />
<b>anti-virus-defence.com</b><br />
<b>protection-livescan.com</b><br />
<br />
<i>Aleksey Kononov <b>cndomainz@yahoo.com</b></i><br />
<i>+74954538435 fax: +74954538435</i><br />
<i>ul. Yakimanskay 34-56</i><br />
<i>Moskva Moskovskay oblast 112745</i><br />
<i>ru</i><br />
<br />
<b>rapidantivir .com</b><b> </b>(91.208.0.220)<b><br />
rapidantivirus-2009 .com<br />
securityscanner2009 .com<br />
rapidantivirus2009 .com<br />
rapid-antivir .com<br />
extraantivir .com<br />
rapid-antivirus .com<br />
rapidantivirus .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hQRW910I/AAAAAAAACfE/Z4g-Irniuz0/s1600-h/sqscan_rogue_november.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hQRW910I/AAAAAAAACfE/Z4g-Irniuz0/s200/sqscan_rogue_november.JPG" /></a><i>Sawert Alliance<br />
Peltonen Martti&nbsp; <b>seodancer@gmail.com</b><br />
33 New Road, Upper Flat<br />
Belize City<br />
Belize<br />
Tel: +7.9602578790</i><br />
<br />
<b>sgscanner .com</b> (116.50.14.185)<br />
<b>sguardscan .com<br />
scansguard .com<br />
getsg2008 .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hbmiwmxI/AAAAAAAACfM/XnmEK9R5m30/s1600-h/virus_response_rogue_november.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SS6hbmiwmxI/AAAAAAAACfM/XnmEK9R5m30/s200/virus_response_rogue_november.png" /></a><i>Vrenk Tihomil<br />
Email: <b>gray444371@gmail.com</b><br />
Organization: Private person<br />
Address: Kolodvorska 73, Sl3270 Lasko<br />
City: Lasko<br />
State: LaskoLasko<br />
ZIP: Sl1355<br />
Country: SI<br />
Phone: +386.14588324</i><br />
<br />
<b>adwaredeluxe .com</b> (64.40.118.8) (private whois)<br />
<b>antivirusadvanced .com<br />
antivirusadvance .com<br />
spydestroy .com<br />
spywareremoval .ws</b><br />
<br />
Shipping them in batches means exposing them in batches.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security_12.html">A Diverse Portfolio of Fake Security Software - Part Thirteen</a><br />
<a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Twelve</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_28.html">A Diverse Portfolio of Fake Security Software - Part Eleven</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html">A Diverse Portfolio of Fake Security Software - Part Ten</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html">A Diverse Portfolio of Fake Security Software - Part Nine</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9h0BN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9h0BN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x78xN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x78xN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=SX1Dn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=SX1Dn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=n7eun"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=n7eun" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xmqRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xmqRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4Ga4N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4Ga4N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5Lo1n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5Lo1n" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/467329268" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 04:47:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/sawert alliance">sawert alliance</category>
      <category domain="http://securityratty.com/tag/road town">road town</category>
      <category domain="http://securityratty.com/tag/martti seodancergmail">martti seodancergmail</category>
      <category domain="http://securityratty.com/tag/upper flat">upper flat</category>
      <category domain="http://securityratty.com/tag/city">city</category>
      <category domain="http://securityratty.com/tag/road">road</category>
      <category domain="http://securityratty.com/tag/sl3270 lasko">sl3270 lasko</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/467329268/diverse-portfolio-of-fake-security_27.html">A Diverse Portfolio of Fake Security Software - Part Fourteen</source>
    </item>
    <item>
      <title><![CDATA[Anti-Terror Law Mission Creep in the U.K.]]></title>
      <link>http://securityratty.com/article/d210842070419d07ee8cfee2be4e8e51</link>
      <guid>http://securityratty.com/article/d210842070419d07ee8cfee2be4e8e51</guid>
      <description><![CDATA[First terrorists, then trash cans : More than half of town halls admit using anti-terror laws to spy on families suspected of putting their rubbish out on the wrong day
Their tactics include putting...]]></description>
      <content:encoded><![CDATA[<p>First terrorists, then <a href="http://www.dailymail.co.uk/news/article-1082225/March-dustbin-Stasi-Half-councils-use-anti-terror-laws-watch-people-putting-rubbish-wrong-day.html?ITO=1490">trash cans</a>:</p>

<blockquote>More than half of town halls admit using anti-terror laws to spy on families suspected of putting their rubbish out on the wrong day. 

<p>Their tactics include putting secret cameras in tin cans, on lamp posts and even in the homes of 'friendly' residents. </p>

<p>The local authorities admitted that one of their main aims was to catch householders who put their bins out early.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=kcA9N"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=kcA9N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=uUuPN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=uUuPN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 05:18:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/town halls admit">town halls admit</category>
      <category domain="http://securityratty.com/tag/trash cans">trash cans</category>
      <category domain="http://securityratty.com/tag/main aims">main aims</category>
      <category domain="http://securityratty.com/tag/tactics include">tactics include</category>
      <category domain="http://securityratty.com/tag/wrong day">wrong day</category>
      <category domain="http://securityratty.com/tag/secret cameras">secret cameras</category>
      <category domain="http://securityratty.com/tag/tin cans">tin cans</category>
      <category domain="http://securityratty.com/tag/local authorities">local authorities</category>
      <category domain="http://securityratty.com/tag/lamp posts">lamp posts</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/anti-terror_law.html">Anti-Terror Law Mission Creep in the U.K.</source>
    </item>
    <item>
      <title><![CDATA[The Audacity of Capital Markets]]></title>
      <link>http://securityratty.com/article/850f85c1d4f79f75ab94faca2b325146</link>
      <guid>http://securityratty.com/article/850f85c1d4f79f75ab94faca2b325146</guid>
      <description><![CDATA[It it fairly well established that overt risk tasking, greed and corporate arrogance by financial services companies have destroyed the real estate market and crippled the global economy. Countless...]]></description>
      <content:encoded><![CDATA[<p>It it fairly well established that overt risk tasking, greed and corporate arrogance by financial services companies have destroyed the real estate market and crippled the global economy.    Countless millions of folks have lost their homes and life savings.  This corporate arrogance and greed was like a &#8220;greed virus,&#8221; spreading across the world like a plague.</p>
<p>A similar arrogance is happening in CEP-land, where, it seems, each and every financial services event processing application is now a &#8220;CEP application&#8221; just because someone in capital markets puts &#8220;CEP&#8221; in the same paragraph.     I find it ridiculous that the same market of folks who have helped destroy the global economy are now the world&#8217;s self-proclaimed authorities on complex event processing.  Amazing, if you really think about it, isn&#8217;t it?</p>
<p>I read many posts these days by folks in the capital markets trading world, claiming their message routing application is &#8220;CEP,&#8221; or their algo trading application is &#8220;CEP,&#8221;  - feeds and speed, typical of what &#8220;turns on&#8221; the financial services folks.   As an editorial note: I recall when I worked for a software company, folks on the same team who worked on Wall Street would look down on folks with many years of IT experience outside of financial services.   Some would say &#8220;he is only a security guy&#8221; in their attempt to put down anyone who does not have trading floor IT experience on their resume.    I found it all quite ridiculous and foolish.</p>
<p>My resume, for what it is worth, has a number of financial services companies, including either assessing, architecting or building large scale security systems for S.W.I.F.T, Chase or SBC.   This experience does not seem to &#8220;count&#8221; with the trading floor folks, since security is more about getting things right, not just supporting a form of gaming or gambling with other peoples money, with more feeds and speeds the better.</p>
<p>Of late, as I have watched the CEP/EP space evolve,  and unfortunately, I see a similar type of &#8220;capital markets virus&#8221; spreading into CEP-land.   Folks on the trading side of financial services seem to think that whatever they say or do is right, and whatever others outside of the trading side do is wrong.  These folks are quick to ridicule others who have far more experience than they do, outside of the trading floor of capital markets.</p>
<blockquote><p>After all, mostly what they do on the trading side is route orders -  and if a little old lady in a small town in Iowa loses her life savings because of a bad investment decision, it means little to the folks on the trading floor, the market folks are into feeds and speed - just keep the beast alive.  Place your bet on this market or that one!   Away we go, faster and faster!!!!</p></blockquote>
<p>I am sometimes a little sad to observe the same audacity in the CEP world.  Instead of focusing on the hard complex problems that require accuracy, the original set of problems defined when the phrase &#8220;complex event processing&#8221; was minted, the capital market folks have hijacked the term for their marketing purposes in algo trading and order managment systems.  These same people ridicule others who are working to solve the (originally stated) complex event processing problems, problems the capital market traders seemingly cannot understand, since they have never worked on complex network or security management problems.</p>
<p>Nevermind, that these &#8220;ultra low latency&#8221; systems cannot accurately detect a complex money laundering scheme or an elaborate fraud.   Nevermind that these &#8220;CEP engines&#8221; cannot accuracy insure that Average Joe does not lose his hard earned money in a fraud scheme.</p>
<p>I have no problem with folks in capital markets using the term CEP, but they should not ridicule those in technical areas that are not focused on keeping the &#8220;trading beast&#8221; alive so people can lose their life savings in a blink of an eye; but instead focused on solving complex problems such as the class of problems called out when the three letter acronym &#8220;CEP&#8221; was created.</p>
]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 07:18:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/capital market folks">capital market folks</category>
      <category domain="http://securityratty.com/tag/market folks">market folks</category>
      <category domain="http://securityratty.com/tag/financial services">financial services</category>
      <category domain="http://securityratty.com/tag/financial services folks">financial services folks</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/capital markets">capital markets</category>
      <category domain="http://securityratty.com/tag/hard complex">hard complex</category>
      <category domain="http://securityratty.com/tag/complex money">complex money</category>
      <source url="http://www.thecepblog.com/2008/09/19/the-audacity-of-capital-markets/">The Audacity of Capital Markets</source>
    </item>
    <item>
      <title><![CDATA[RNC]]></title>
      <link>http://securityratty.com/article/be0e55d9cb445eec42568a38816bb728</link>
      <guid>http://securityratty.com/article/be0e55d9cb445eec42568a38816bb728</guid>
      <description><![CDATA[Yup, we have the RNC here in MN. Downtown is locked down pretty tight, you would need the combined powers of Chuck Norris and Bruce Schneier to even get a cup of coffee down there. Here is the round...]]></description>
      <content:encoded><![CDATA[<p>Yup, we have the RNC here in MN. Downtown is locked down pretty tight, you would need the combined powers of Chuck Norris and <a href="http://geekz.co.uk/schneierfacts/">Bruce Schneier</a> to even get a cup of coffee down there. Here is the round up from <a href="http://www.economist.com/blogs/freeexchange/2008/09/above_the_fold_251.cfm">The Economist&#39;s blog</a></p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal; ">You&#39;ll have to pardon me this morning if the round-up seems a bit off. I&#39;m still a little stunned at the spectacle of an arena full of (seemingly sober and sane) adults chanting, &quot;Drill, baby, drill&quot;.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal;"><br /></span><span style="font-family: Verdana; line-height: normal; ">So let&#39;s see, what&#39;s in the news? Well, last night Republicans trotted out a Massachusetts venture capitalist and governor, the former mayor of New York City, former executives of eBay and HP, and an Alaskan neophyte pol who as mayor of a small town delivered $4,000 in federal pork for every man, woman, and child, in railing against coastal elites and Washington politics, while supporting a candidate who&#39;s been in the Senate for 26 years.</span></p></blockquote>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 07:34:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts venture capitalist">massachusetts venture capitalist</category>
      <category domain="http://securityratty.com/tag/alaskan neophyte pol">alaskan neophyte pol</category>
      <category domain="http://securityratty.com/tag/washington politics">washington politics</category>
      <category domain="http://securityratty.com/tag/bruce schneier">bruce schneier</category>
      <category domain="http://securityratty.com/tag/rnc">rnc</category>
      <category domain="http://securityratty.com/tag/federal pork">federal pork</category>
      <category domain="http://securityratty.com/tag/drill">drill</category>
      <category domain="http://securityratty.com/tag/round-up">round-up</category>
      <category domain="http://securityratty.com/tag/pretty tight">pretty tight</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/rnc.html">RNC</source>
    </item>
    <item>
      <title><![CDATA[Risk and CVSS]]></title>
      <link>http://securityratty.com/article/041ada94b10db944de182c7d03d4b3b3</link>
      <guid>http://securityratty.com/article/041ada94b10db944de182c7d03d4b3b3</guid>
      <description><![CDATA[Chris Hayes is taking me to town in terms of risk content with his last two posts on Risk &amp; CVSS . I told you his blog was going to be a good...]]></description>
      <content:encoded><![CDATA[<p>Chris Hayes is taking me to town in terms of risk content with his last two <a href="http://risktical.com/2008/09/01/risk-and-cvss-post-2/"><strong>posts on Risk &amp; CVSS</strong></a>.  I told you his blog was going to be a good one.</p>
]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 13:33:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk content">risk content</category>
      <category domain="http://securityratty.com/tag/cvss">cvss</category>
      <category domain="http://securityratty.com/tag/chris hayes">chris hayes</category>
      <category domain="http://securityratty.com/tag/terms">terms</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/town">town</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=407">Risk and CVSS</source>
    </item>
    <item>
      <title><![CDATA[While I Was Out: Compendium of the Last Week's News]]></title>
      <link>http://securityratty.com/article/9b2e491a24c669b08b8cfdf0d0df0b47</link>
      <guid>http://securityratty.com/article/9b2e491a24c669b08b8cfdf0d0df0b47</guid>
      <description><![CDATA[You wouldn't listen, but continued to generate products, news stories, and analysis about wireless networking in my absence: Here's the run down of the last week or so's Wi-Fi and wireless stories....]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><strong>You wouldn't listen, but continued to generate products, news stories, and analysis about wireless networking in my absence:</strong> Here's the run down of the last week or so's Wi-Fi and wireless stories. (Yes, I enjoyed my time off.)</p>

<p><a href="http://www.informationweek.com/news/services/data/showArticle.jhtml?articleID=210200880"><strong>Fourth US airline to go Wi-Fi:</strong></a> Aircell says they have a fourth airline--after American, Delta, and Virgin America--on board for its in-flight Wi-Fi service. The aerial broadband provider's latest partner will be announced soon. Aircell's service went live in 15 American Airlines planes two weeks ago, and there's been a surprising lack of reporting from regular travelers or journalists since the big splash at the launch.</p>

<p><a href="http://seattlepi.nwsource.com/business/376308_software25.html"><strong>Microsoft, two universities research methods for better Wi-Fi handoff for vehicles:</strong></a> The researchers developed a method they call Vi-Fi, writes the Seattle Post-Intelligencer's Todd Bishop, which allows a system to maintain connections with several base stations at once, using a primary access point for traffic until a discontinuity is predicted or encountered. This allows seamless handoffs and continuous voice conversations. </p>

<p><a href="http://www.nytimes.com/2008/08/24/technology/24digi.html?_r=1&oref=slogin"><strong>Speaking of autos and Wi-Fi, concerns raised about Chrysler's in-car Wi-Fi option:</strong></a> Randall Stross wrote nearly two weeks ago in The New York Times about the problem of distraction. With the Internet at your fingertips, can you restrain yourself? The only problem with the humorous and accurate analysis is that millions of business travelers have 3G access via laptop cards already, so you'd think we'd already be seeing the bad effects of automotive area networks.</p>

<p><a href="http://www.omaha.com/index.php?u_page=2798&u_sid=10415031"><strong>A Wi-Fi booster can't post availability signs on highway:</strong></a> The Nebraska town of Louisville has free Wi-Fi downtown, and wanted to post "Visitor Wi-Fi" on a highway sign as another amenity. The state highway department has a policy that doesn't allow the promotion of Wi-Fi, because they believe they'd be inundated. A resident who runs a local Internet firm installed his own signs on the highway; the roads department removed them; he remounted them; they were removed again. The idea of zoning and mounting a billboard apparently hasn't come to the city officials' minds (or perhaps they're prohibited).</p>

<p><a href="http://www.lisburntoday.co.uk/news/PRIMARY-PULLS-PLUG-ON-WIFI.4435678.jp"><strong>The folks spreading misinformation about Wi-Fi health effects cause Ulster school to disable network:</strong></a> I can understand why non-technical folks might think that Wi-Fi has been proven to be unsafe, given the kind of information that's available on the Internet about wireless safety. While there are ongoing studies about the safety of cellular signals--and I'm convinced at this point there's no increased risk to an adult's health by using a cell phone--there is no specific and credible research linked to Wi-Fi, which broadcasts signals at a far lower level than a cell phone, most of the time in most uses.</p>

<p><a href="http://blog.seattlepi.nwsource.com/thebigblog/archives/147374.asp"><strong>Washington state shuts down rest-area Wi-Fi:</strong></a> The $3 for 15 minutes, $7 per day, or $30 per month Wi-Fi service at 28 of Washington's 42 rest areas has been turned off after a year for lack of use. Figures. The fees charged by Parsons and Road Connect aren't unreasonable for a nationally scoped plan, but are ridiculous for limited use. States should either bite the bullet and offer these service for free, partner with national roaming operators who can resell service into large networks of business travelers, or use ads to support the service. Highways in remote areas can typically pick up cell data networks, and ongoing costs should be minimal to operate such networks.</p>

<p><a href="http://www.techworld.com/news/index.cfm?RSS&NewsID=103501"><strong>IEEE approves fast-roaming standard, 802.11r:</strong></a> This new standard is designed to improve the handoff of devices between base stations. This is accomplished in part by allowing base stations to communicate security and quality of service information so that a VoIP over WLAN phone can immediately reassociate without the delay of authentication and other handshaking.</p>

<p><a href="http://www.marketwatch.com/news/story/freefi-networks-releases-figures-wi-fi/story.aspx?guid={5252EF0E-2563-42B7-8A95-2F893580E6F6}&dist=hppr"><strong>Denver airport sees 7,000 connections on a single day last week due to Democratic National Convention:</strong></a> FreeFi released the usage figures recently to show how their service is operating. The network started with about 600 daily users when the switchover from fee to free happened 10 months ago, and now carries about 3,500 daily connections.</p>

<p><a href="http://www.centredaily.com/living/travel/story/804003.html"><strong>Coffee Bean & Tea Leaf goes free:</strong></a> The chain of about 700 cafes will have free Wi-Fi installed by now in all its company-owned stores (about 300).</p>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 10:55:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/in-car wi-fi option">in-car wi-fi option</category>
      <category domain="http://securityratty.com/tag/wi-fi handoff">wi-fi handoff</category>
      <category domain="http://securityratty.com/tag/free wi-fi downtown">free wi-fi downtown</category>
      <category domain="http://securityratty.com/tag/month wi-fi service">month wi-fi service</category>
      <category domain="http://securityratty.com/tag/rest-area wi-fi">rest-area wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi booster">wi-fi booster</category>
      <category domain="http://securityratty.com/tag/in-flight wi-fi service">in-flight wi-fi service</category>
      <source url="http://wifinetnews.com/archives/008428.html">While I Was Out: Compendium of the Last Week's News</source>
    </item>
    <item>
      <title><![CDATA[Thoughts on Token Security]]></title>
      <link>http://securityratty.com/article/e520684c06df65bce8e1084919798c74</link>
      <guid>http://securityratty.com/article/e520684c06df65bce8e1084919798c74</guid>
      <description><![CDATA[RSnake has a piece up on Token Security which raises some good points, but also misses some perspective. Firstly any article that makes a serious attempt at mitigating FUD is most welcome, especially...]]></description>
      <content:encoded><![CDATA[<p>RSnake has a piece up on <a href="http://www.darkreading.com/blog.asp?blog_sectionid=403">Token Security</a> which raises some good points, but also misses some perspective. Firstly any article that makes a serious attempt at mitigating FUD is most welcome, especially in a space that is as overloaded as identity. That <span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">said, I think RSnake is taking too narrow of a view, specifically B2C, on federation and tokens</span><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">. It is true that works on the web eventually filters into the enterprise, but it is also true that sometimes that things that start out as enterprise technologies later become cost effective on the web. So I would not assume that the current status quo on the web will hold. I don&#39;t think it will, the identity problems are too big and there is too much money at stake.</span></p><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I encourage you to read his article, here are some of my thoughts<br /></span><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;consumers hate tokens.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Except that people use atm cards every day. Consumers will absolutely be inconvenienced, if there is some value created. The problem today is not the token, its the lack of a value proposition to the person you are inconveniencing.&#160;</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Everyone wants to be the single federation platform for everyone else.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">This will never work. and that&#39;s a good thing. i think most companies already realize this though. I think the walled garden model has gone the way of the dodo.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Federation will never work. It won’t work because the single most important consumer Web applications in the world are scared of it. Banks hate the concept because it becomes a weakest link in the chain problem.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Federation works quite well. have a look at google for one example. The reason banks hate federation is that their infosec people have a </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">mainframe mindset</span></a><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">, they are focused only on resource protection. the problem is they dont run mainframes on closed networks, they went and connected it to the web and so now they need to think about subject and claim security not just resource security. its not hatred its a lack of understanding stemming from a legacy mindset.</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Linking up identity providers and relying parties into a federation has been a solved problem for quite some time.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Tokens don’t actually solve most security problems, like man-in-the-middle, phishing, and keystroke-logging malware.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Rule 1. there are no silver bullets in security</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Rule 2. dont forget rule 1</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">but...</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...there is a rule 3</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">rule 3. just because a security mechanism doesnt solve all of our problems doesnt mean its worthless.</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I see this with security consultants all the time, they playa hate on static analysis or some scanning tool where they can find hundreds of things the tool doesn&#39;t. Fair point except 99.9999% of IT can&#39;t and won&#39;t find them. Engineering is about solving one incremental problem at a time.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Oh yes, and finally, consumers are going to have to carry around 13 of them just to make sure they can log into whatever they need to log into since no one will federate.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">This misses the point of federation. i carry around one atm card its up to banks, Visa, Cirrus and so on to make sure i get my cash. the funny thing about banks not understanding federation is that they have the bet example right in front of their noses, the problem is its in a different department so they never see it.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Global federation is nowhere near a solid concept in the consumer space, despite what the vendors will try to sell you.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">rule 4. do your own due diligence</span></p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Tokens and federation are important building blocks for our digital future. I will leave you with a </span><a href="http://1raindrop.typepad.com/1_raindrop/2007/01/integrated_tran.html"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">story</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> that</span><a href="http://en.wikipedia.org/wiki/Robert_Morris_%28cryptographer%29"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> Robert Morris Sr.</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> told at Defcon several years ago:</span></div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;This is a long term problem. If you work on it and make any progress against it, you&#39;ll find yourself much smarter at the far end, than you were at the near end.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When I was in Norway about 5 years ago, I was there very close to the summer solstice. I was wandering around town at 2 o&#39;clock in the morning and there was plenty of light out. You come to a sign that says New Minsk about 60 km and it points south.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">And I ask the lady &quot;what country is this?&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">She scratched her head for a bit, and said &quot;well I think its Norway&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I said &quot;well who plows the roads?&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;well Norway does, but he have to pay them.&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">There is a triple boundary in this town that I was in between Norway, Finland and Russia.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">But what I did there, was, I had a card about wallet size, I stuck it into a machine, I punched in four digits, and it gave me about 2,000 krone, whatever the hell that is.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Now there are a lot of participants in that transaction. When I put a card into that machine, punch in a pin, and it gurgles for awhile, and finally gives me, a fairly large amount of money. There are a lot of participants in that transaction. The bank that owned the machine that gave me the money, it gave some money away -- that bank wants it back. The pin is necessary to convince my own bank that I&#39;m me. But I don&#39;t want my pin to be broadcast all over the world. My bank in the us, it hasn&#39;t really given out or taken in any money, really. But there is a lot of credits involved here. Somebody needs to charge somebody else for having more money&#160;available. Even though there was actually no cash transfer.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">And the problem that I have in mind is</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- who are all the participants in an ATM transaction?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- what do those participants need to satisfy their problems?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- how is that in fact done?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In a general way, does the atm system actually work in some reasonable sense? To which the answer is by the way: yes. The atm system damn well works. With extremely high reliability and accuracy. It surprises me. Its quite a bit different than voting machines.</span></p></blockquote>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 12:35:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/global federation">global federation</category>
      <category domain="http://securityratty.com/tag/federation">federation</category>
      <category domain="http://securityratty.com/tag/single federation platform">single federation platform</category>
      <category domain="http://securityratty.com/tag/security mechanism">security mechanism</category>
      <category domain="http://securityratty.com/tag/resource security">resource security</category>
      <category domain="http://securityratty.com/tag/security consultants">security consultants</category>
      <category domain="http://securityratty.com/tag/consumer web applications">consumer web applications</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/thoughts-on-token-security.html">Thoughts on Token Security</source>
    </item>
    <item>
      <title><![CDATA[Let's Play Two]]></title>
      <link>http://securityratty.com/article/83bf8d018a7d0aa80e3dc49adab30013</link>
      <guid>http://securityratty.com/article/83bf8d018a7d0aa80e3dc49adab30013</guid>
      <description><![CDATA[Every year my Dad and I go to see a Red Sox series. Last weekend was this year's trip and we went to Chicago to see the World Champion Boston Red Sox (saying that never gets old) play the White Sox....]]></description>
      <content:encoded><![CDATA[<p>Every year my Dad and I go to see a Red Sox series. Last weekend was this year&#39;s trip and we went to Chicago to see the World Champion Boston Red Sox (saying that never gets old) play the White Sox. Of course, while you are in Chicago you have to see Wrigley Field, and we really lucked out. This weekend was Red Sox versus the White Sox (the battle of the Soxes they used to call it on Channel 38) on the southside and northside featured Cubs versus Cardinals! The last four World Series winners in town on the same weekend (Red Sox 04, 07, White Sox 05, Cards 06).</p><br /><div>We learned several things- first in heaven the Cubs play the Red Sox in the World Series. Those ballparks are true gems. (In hell its probably the Yankees versus Phillies). Also, the people on the southside and northside *really* have a rivalry going. Its basically Boston v NY but they live in the same town! Here is one example from the southside</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0c9d8834-pi" style="display: inline;"><img alt="IMG_0597" border="0" class="at-xid-6a00d83451c75869e200e553fc0c9d8834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0c9d8834-800wi" title="IMG_0597" /></a>
<br /></div><br /><div>One of the great things about Wrigley (and there are many despite what southsiders say), is that its in the middle of a real neighborhood</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbb38833-pi" style="display: inline;"><img alt="IMG_0486" border="0" class="at-xid-6a00d83451c75869e200e553e0bbb38833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbb38833-800wi" title="IMG_0486" /></a>
<br /></div><br /><div>Epicenter of Cub universe</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbf68833-pi" style="display: inline;"><img alt="IMG_0487" border="0" class="at-xid-6a00d83451c75869e200e553e0bbf68833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbf68833-800wi" title="IMG_0487" /></a>&#160;</div><br /><div>Lots of action before and after game time, lots of people wandering around with gloves catching batting practices homers outside the stadium...err Field. Key point - Wrigley is a field, not a Stadium. Also Fenway is a Park. The Greek root of the word &quot;paradise&quot;, means &quot;enclosed green space&quot;, not concreteopolis</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0ed98834-pi" style="display: inline;"><img alt="IMG_0489" border="0" class="at-xid-6a00d83451c75869e200e553fc0ed98834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0ed98834-800wi" title="IMG_0489" /></a>
<br /></div><br /><div>Wrigley is baseball Mecca</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc15338834-pi" style="display: inline;"><img alt="IMG_0507" border="0" class="at-xid-6a00d83451c75869e200e553fc15338834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc15338834-800wi" title="IMG_0507" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bebd8833-pi" style="display: inline;"><img alt="IMG_0515" border="0" class="at-xid-6a00d83451c75869e200e553e0bebd8833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bebd8833-800wi" title="IMG_0515" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bef48833-pi" style="display: inline;"><img alt="IMG_0533" border="0" class="at-xid-6a00d83451c75869e200e553e0bef48833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bef48833-800wi" title="IMG_0533" /></a>
<br /></div><br /><div><span style="color: #0000ff; text-decoration: underline;"><br /></span></div><div>The greatest Cub of all, Ernie Banks, was our touchstone for the day - &quot;Let&#39;s Play Two.&quot; we started at Wrigley for the day game (Zambrano got shelled) and then got crosstown for the night game.</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bce68833-pi" style="display: inline;"><img alt="IMG_0496" border="0" class="at-xid-6a00d83451c75869e200e553e0bce68833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bce68833-800wi" title="IMG_0496" /></a>
<br /></div><div>To pull this off the L is your friend. As several Chicagoans pointed out, they are the only city that can have a true subway series, because the Red Line services both the White Sox and Cubs, whereas Mets-Yankees involves numerous transfers and so on.</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0e988834-pi" style="display: inline;"><img alt="IMG_0488" border="0" class="at-xid-6a00d83451c75869e200e553fc0e988834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0e988834-800wi" title="IMG_0488" /></a>
<br /></div><br /><div>We got to US Cellular Field which is fine but a shadow of Wrigley and absolutely nothing good to <a href="http://www.nytimes.com/interactive/2008/06/08/travel/20080608_BALLPARK_GRAPHIC.html">eat</a>. Luckily we had Daisuke Matsuzaka on the hill</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc187a8834-pi" style="display: inline;"><img alt="IMG_0569" border="0" class="at-xid-6a00d83451c75869e200e553fc187a8834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc187a8834-800wi" title="IMG_0569" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc18a88834-pi" style="display: inline;"><img alt="IMG_0573" border="0" class="at-xid-6a00d83451c75869e200e553fc18a88834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc18a88834-800wi" title="IMG_0573" /></a>
<br /></div><br /><div>Before every game, Big Papi holds court in center with some players from the other team, he is to be a very popular guy. Ozzie Guillen told him before the series that with Manny gone, he wouldn&#39;t see a pitch to hit all weekend (ps. he did and crushed a bases loaded double)</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bfa78833-pi" style="display: inline;"><img alt="IMG_0581" border="0" class="at-xid-6a00d83451c75869e200e553e0bfa78833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bfa78833-800wi" title="IMG_0581" /></a>
<br /></div><br /><br /><div>The question we got most was - what about the Manny trade? His replacement strikes out a lot, but is otherwise a promising player</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb978833-pi" style="display: inline;"><img alt="IMG_0468" border="0" class="at-xid-6a00d83451c75869e200e553e0bb978833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb978833-800wi" title="IMG_0468" /></a>
<br /></div><br /><div>The Red Sox and White Sox share a little history, most especially Pudge Fisk who hit the famous homer in the 75 world series for the Red Sox and then had a great career for the White Sox (actually played more games for Chicago than Boston, but went into Cooperstown with a B on his hat)</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb778833-pi" style="display: inline;"><img alt="IMG_0456" border="0" class="at-xid-6a00d83451c75869e200e553e0bb778833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb778833-800wi" title="IMG_0456" /></a></div><div>
<br /></div><div>Red Sox won, hanging out in Wrigley was an even bigger highlight, and Chicago is a beautiful city to visit, by far the most accessible of the big US cities. Also, lots of good places to eat courtesy of <a href="http://www.matasano.com/log/">Thomas Ptacek</a>.</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0c08f8833-pi" style="display: inline;"><img alt="IMG_0591" border="0" class="at-xid-6a00d83451c75869e200e553e0c08f8833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0c08f8833-800wi" title="IMG_0591" /></a>
<br /></div>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 08:47:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world series winners">world series winners</category>
      <category domain="http://securityratty.com/tag/world series">world series</category>
      <category domain="http://securityratty.com/tag/red sox versus">red sox versus</category>
      <category domain="http://securityratty.com/tag/red sox">red sox</category>
      <category domain="http://securityratty.com/tag/red sox series">red sox series</category>
      <category domain="http://securityratty.com/tag/series">series</category>
      <category domain="http://securityratty.com/tag/white sox">white sox</category>
      <category domain="http://securityratty.com/tag/white sox share">white sox share</category>
      <category domain="http://securityratty.com/tag/play">play</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/lets-play-two.html">Let's Play Two</source>
    </item>
    <item>
      <title><![CDATA[No, FISMA Doesnt Require That, Silly Product Pushers]]></title>
      <link>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</link>
      <guid>http://securityratty.com/article/e7338459ca02abf727eaf2b68ac02e51</guid>
      <description><![CDATA[Post #9678291 on why people dont understand what FISMA really is : Secure64 DNSSEC Press Releases
FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security...]]></description>
      <content:encoded><![CDATA[<p>Post #9678291 on <a href="http://www.guerilla-ciso.com/archives/150" target="_blank">why people don&#8217;t understand what FISMA really is</a>:  <a href="http://www.domaininformer.com/news/press/310708DNSSEC.html" target="_blank">Secure64 DNSSEC Press Releases</a>.</p>
<p style="padding-left: 30px;"><em>&#8220;FISMA Act encourages U.S. government agencies to configure their DNS servers to the DNSSEC security specifications set by the National Institute of Standards and Technology, and it has been reported that the federal government<span id="bwanpa5">’</span>s Office of Management and Budget (OMB) plans to begin enforcing DNSSEC requirements through an auditing process, setting the standard for DNS best practices.&#8221;</em></p>
<p>Yep, if you stamp FISMA on it, people will buy it, maybe in your PR department&#8217;s wettest and wildest dreams.  Guys, it&#8217;s been 6 years, that kind of marketing doesn&#8217;t work nowadays, mostly because we spent ourselves into oblivion buying junkware similar to yours and now we&#8217;re all jaded.</p>
<p>Now don&#8217;t get me wrong, DNSSEC is a good thing, especially this month.  But there is something I need to address:  FISMA requires good security management with a dozen or so key indicators, not a solution down to the technical level.  Allusions to OMB are just FUD, FUD, and more FUD because unless it&#8217;s in a memo to agency heads, it&#8217;s all posturing&#8211;something everybody in this town knows how to do very well.  OMB would rather stay out of mandating DNSSEC and maybe give a &#8220;due date&#8221; once NIST has a final standard.</p>
<p>My one word of wisdom for today:  anybody who tries to sell a product and <a href="http://www.guerilla-ciso.com/archives/216" target="_blank">uses FISMA as the &#8220;compelling event&#8221; has no clue what they&#8217;re talking about</a>.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers&amp;url=http://www.guerilla-ciso.com/archives/440&amp;version=0.7" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/440&amp;t=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/440&amp;title=No%2C+FISMA+Doesn%26%238217%3Bt+Require+That%2C+Silly+Product+Pushers" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/440" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" alt="Add 'No, FISMA Doesn&#8217;t Require That, Silly Product Pushers' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=2mnw8J"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=2mnw8J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=HAXdPj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=HAXdPj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/351599310" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 10:36:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fisma">fisma</category>
      <category domain="http://securityratty.com/tag/fisma requires">fisma requires</category>
      <category domain="http://securityratty.com/tag/fisma act encourages">fisma act encourages</category>
      <category domain="http://securityratty.com/tag/stamp fisma">stamp fisma</category>
      <category domain="http://securityratty.com/tag/dnssec">dnssec</category>
      <category domain="http://securityratty.com/tag/dnssec requirements">dnssec requirements</category>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/dns servers">dns servers</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/351599310/440">No, FISMA Doesnt Require That, Silly Product Pushers</source>
    </item>
    <item>
      <title><![CDATA[On Government Employees, Culture, and Survivability]]></title>
      <link>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</link>
      <guid>http://securityratty.com/article/5480412299d0a4f28970697b7dbced94</guid>
      <description><![CDATA[A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert. One thing he said still sticks in my mind...]]></description>
      <content:encoded><![CDATA[<p>A couple of months before I was activated and went to Afghanistan, I got a briefing from a Special Forces NCO who had done multiple tours in the desert.  One thing he said still sticks in my mind (obviously paraphrased):</p>
<blockquote><p>&#8220;The Afghanis, they live in mud huts, they don&#8217;t have electricity, they are stick-people weighing 85 lbs, and to say that we could bomb them into the stone age would be an advancement in their technology level.  But never underestimate these people, they&#8217;re survivors.  They&#8217;ve survived 35 years of warfare, starting with the Soviets, then they fought a civil war before we arrived on the scene.  Never underestimate their ability to survive, and have respect for them because of who they are.&#8221;</p></blockquote>
<p>Today, I feel the same way about government employees, even more so because it&#8217;s an election year:  they&#8217;re survivors.</p>
<p>Now time for what I see is the &#8220;real&#8221; reason why the government is doing badly (if that&#8217;s what you believe&#8211;opinions differ) at security: it&#8217;s all an issue of culture. I have a friend who converted a year ago to a GS-scale employee and took a class on what motivates government employees. Some of these are obvious:</p>
<ul>
<li>Pride at making a difference</li>
<li>Helping people</li>
<li>Supporting a cause</li>
<li>Gaining unique experience on a global-class scope</li>
<li>Job stability</li>
<li>Retirement benefits</li>
</ul>
<p>And one thing is noticeably absent: better pay and personal recognition.  Hey, sounds like me in the army.</p>
<p style="text-align: center;"><em><img src="http://farm2.static.flickr.com/1348/1470902823_4a5145322e.jpg?v=0" alt="The Companion Family Plan to Survival at Home" width="362" height="500" /></em></p>
<p style="text-align: center;"><em>The Companion Family Plan for Survival at Home photo by <a href="http://www.flickr.com/photos/jikan/" target="_blank">Uh &#8230; Bob</a>.</em></p>
<p>Now I&#8217;m not trying to stereotype, but you need to know the organizational behavior pieces to understand how government security works. And in this case, the typical government employee is about as survival-aware as their Afghani counterpart.</p>
<p>Best advice I ever heard from a public policy wonk: the key to survival in this town is to influence everything you can get your hands on and never have your name actually written on anything.</p>
<p>In other words, don&#8217;t criticize, be nice to everybody even though you think they are a jerk, and avoid saying anything at all because you never know when it will be contrary to the political scene.  The Government culture is a silent culture. That&#8217;s why every day amazing things happen to promote security in the Government and you&#8217;ll never hear about it on the outside.</p>
<p>One of the reasons that I started blogging was to counter the naysayers who say that FISMA is failing and that the Government would succeed if they would just buy their product for technical policy compliance or end-to-end encryption.  Sadly, the true heroes in Government, the people who just do their job every day and try to survive a hostile political environment, are giving credit to the critics because of their silence.</p>
<p>Which brings me to my point:</p>
<p>Yes, my name is Rybolov and I&#8217;m a heretic, but this is the secret to security in the Government:  it&#8217;s cultural at all layers of the personnel stack.  Security (and innovation, now that I think about it) needs a culture of openness where it&#8217;s allowable to make mistakes and/or criticize.  Doesn&#8217;t sound like any government&#8211;local, state, or federal&#8211;that I&#8217;ve ever seen.  However, if you fix the culture, you fix the security.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" alt="Add 'On Government Employees, Culture, and Survivability' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to digg" alt="Add 'On Government Employees, Culture, and Survivability' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to reddit" alt="Add 'On Government Employees, Culture, and Survivability' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=On+Government+Employees%2C+Culture%2C+and+Survivability&amp;url=http://www.guerilla-ciso.com/archives/298&amp;version=0.7" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" alt="Add 'On Government Employees, Culture, and Survivability' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Technorati" alt="Add 'On Government Employees, Culture, and Survivability' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/298&amp;t=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" alt="Add 'On Government Employees, Culture, and Survivability' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" alt="Add 'On Government Employees, Culture, and Survivability' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/298&amp;title=On+Government+Employees%2C+Culture%2C+and+Survivability" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" alt="Add 'On Government Employees, Culture, and Survivability' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Squidoo" alt="Add 'On Government Employees, Culture, and Survivability' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/298" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'On Government Employees, Culture, and Survivability' to Bloglines" alt="Add 'On Government Employees, Culture, and Survivability' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=KQw1LJ"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=KQw1LJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=8UDDwj"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=8UDDwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/341552257" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 09:46:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/government employees">government employees</category>
      <category domain="http://securityratty.com/tag/government security">government security</category>
      <category domain="http://securityratty.com/tag/culture">culture</category>
      <category domain="http://securityratty.com/tag/government culture">government culture</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/typical government employee">typical government employee</category>
      <category domain="http://securityratty.com/tag/promote security">promote security</category>
      <category domain="http://securityratty.com/tag/silent culture">silent culture</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/341552257/298">On Government Employees, Culture, and Survivability</source>
    </item>
  </channel>
</rss>
