<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: trouble]]></title>
    <link>http://securityratty.com/tag/trouble</link>
    <description></description>
    <pubDate>Fri, 26 Sep 2008 14:54:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[LinkedIn Updates Privacy Policywith Only a Brief Notice to Users]]></title>
      <link>http://securityratty.com/article/6863cbfcaecc21c81d52ca85e2748582</link>
      <guid>http://securityratty.com/article/6863cbfcaecc21c81d52ca85e2748582</guid>
      <description><![CDATA[If you havent logged in to your linked in account in a while youll be greeted with a quick notice next time
Weve updated! On November 14, 2008, LinkedIn published revised versions of our Privacy...]]></description>
      <content:encoded><![CDATA[<p>If you haven&#8217;t logged in to your linked in account in a while you&#8217;ll be greeted with a quick notice next time:</p>
<p>&#8220;We’ve updated! On November 14, 2008, LinkedIn published revised versions of our Privacy Policy and our User Agreement. Using LinkedIn means you consent to these policies, so please take a few minutes to read and understand them.&#8221;</p>
<p>However, if you log out and back, the notice will be gone&#8211; so if you weren&#8217;t looking too closely, you might not even realize you&#8217;ve just consented.</p>
<p><span class="post-footers">Rebecca Herold at <a rel="nofollow" target="_blank" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2008/11/continued_use_of_site_means_co.htm">Realtime IT Compliance </a>looked into this and found that the FTC doesn&#8217;t much like this kind of implicit privacy changes. Instead, companies should be getting explicit consent, also called &#8220;Affirmative express consent,&#8221; says the FTC:</span></p>
<blockquote><p>As the FTC has made clear in its enforcement and outreach efforts, a company must keep any promises that it makes with respect to how it will handle or protect consumer data, even if it decides to change its policies at a later date. Therefore, before a company can use data in a manner materially different from promises the company made when it collected the data, it should obtain affirmative express consent from affected consumers.</p></blockquote>
<p>This would imply that if LinkedIn is updating its privacy policy with such a minimal notice, it may not have changed in any way &#8220;materially different&#8221; from before. But if it is different, they might face a bit of trouble.</p>]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 09:08:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/notice">notice</category>
      <category domain="http://securityratty.com/tag/linkedin">linkedin</category>
      <category domain="http://securityratty.com/tag/explicit consent">explicit consent</category>
      <category domain="http://securityratty.com/tag/consent">consent</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/protect consumer data">protect consumer data</category>
      <category domain="http://securityratty.com/tag/minimal notice">minimal notice</category>
      <category domain="http://securityratty.com/tag/affirmative express consent">affirmative express consent</category>
      <category domain="http://securityratty.com/tag/privacy policy">privacy policy</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/466570497/">LinkedIn Updates Privacy Policywith Only a Brief Notice to Users</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-19 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/359d830ca1e8df85568ee491fac7b4b0</link>
      <guid>http://securityratty.com/article/359d830ca1e8df85568ee491fac7b4b0</guid>
      <description><![CDATA[QualysGuard PCI Pass/Fail Status Criteria - Qualys
Press Releases - November 11, 2008 - Q1 Labs free, downloadable, log management and compliance product that provides organizations with visibility...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.qualys.com/products/pci/qgpci/pass_fail_criteria/">QualysGuard PCI Pass/Fail Status Criteria - Qualys</a></li>
<li><a href="http://www.q1labs.com/pr.php?id=711">Press Releases - November 11, 2008 - Q1 Labs</a><br/>
free, downloadable, log management and compliance product that provides organizations with visibility across their networks, data centers, and infrastructures</li>
<li><a href="http://www.cheapest-service.com/blog/2008/11/11/healthy-paranoia-top-50-internet-security-blogs/">&nbsp; Healthy Paranoia: Top 50 Internet Security Blogs&nbsp;by&nbsp;The Daily Netizen</a></li>
<li><a href="http://www.govcert.nl/symposium/audiovideo.html">GOVCERT.NL Symposium 2008</a></li>
<li><a href="http://sec.online.wsj.com/article/SB122461917614955373.html">Looking for Trouble - WSJ.com</a></li>
<li><a href="http://blog.clearnetsec.com/articles/2008/11/11/it%E2%80%99s-hard-to-build-a-smart-siem">ClearNet Security : It&rsquo;s hard to build a smart SIEM</a><br/>
If you find yourself evaluating SIEM products, dig in and investigate how each works - you don’t want yesterday’s product.</li>
<li><a href="http://www.thecomplianceauthority.rsvp1.com/articles/111908_taylor.shtm">PCI Perspectives by Dave Taylor</a></li>
<li><a href="http://physicsworld.com/blog/2008/09/killed_by_complexity_1.html">Lehman Bros 'killed by complexity' (physicsworld.com Blog) - physicsworld.com</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/459218630" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet security blogs">internet security blogs</category>
      <category domain="http://securityratty.com/tag/clearnet security">clearnet security</category>
      <category domain="http://securityratty.com/tag/dave taylor">dave taylor</category>
      <category domain="http://securityratty.com/tag/compliance product">compliance product</category>
      <category domain="http://securityratty.com/tag/healthy paranoia">healthy paranoia</category>
      <category domain="http://securityratty.com/tag/labs free">labs free</category>
      <category domain="http://securityratty.com/tag/press releases">press releases</category>
      <category domain="http://securityratty.com/tag/physicsworld">physicsworld</category>
      <category domain="http://securityratty.com/tag/siem products">siem products</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/459218630/anton18">Links for 2008-11-19 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[The Ill Effects of Banning Security Research]]></title>
      <link>http://securityratty.com/article/b72a55401bc7d6c28427d7aee13f4dd4</link>
      <guid>http://securityratty.com/article/b72a55401bc7d6c28427d7aee13f4dd4</guid>
      <description><![CDATA[The Indian police are having trouble with SIM card cloning: Police had no idea that one SIM card could be used simultaneously from two handsets before the detention of Nazir Ahmed for interrogation....]]></description>
      <content:encoded><![CDATA[<p>The Indian police are <a href="http://timesofindia.indiatimes.com/PDATOI/pdaarticleshow/3670337.cms">having trouble</a> with SIM card cloning:</p>

<blockquote>Police had no idea that one SIM card could be used simultaneously from two handsets before the detention of Nazir Ahmed for interrogation. Nazir was picked up from Morigaon after an SMS from his mobile number in the name of ISF-IM claimed responsibility for Thursday's blasts in Assam. 

<p>Nazir had a Reliance connection and an Eve handset. Each handset of this particular model has a unique International Mobile Equipment Identity (IMEI) number. Cops found that two IMEI numbers were using the same SIM. Accordingly there were two record sheets of calls and SMSes from Nazir's mobile number. The record of the SMS to the media was found in only one sheet, which forced police to believe that Nazir's SIM might have been cloned and someone else was using the duplicate card, with or without the owner's knowledge. </p>

<p>"We stumbled upon this technological surprise that Nazir Ahmed's SIM card was used in two handsets," Assam IG (Law and Order) Bhaskarjyoti Mahanta said.</blockquote></p>

<p>So far, not that interesting.  There are lots of vulnerabilities in technological systems, and it's generally a race between the good guys and the bad guys to see who finds them first.  It's the last sentence of this article that's significant:</p>

<blockquote>The experts said no one has actually done any research on SIM card cloning because the activity is illegal in the country.</blockquote>

<p>If the good guys can't even participate, the bad guys will always win.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=6uyUN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=6uyUN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=mvzBN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=mvzBN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 03:26:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/sim card">sim card</category>
      <category domain="http://securityratty.com/tag/sim">sim</category>
      <category domain="http://securityratty.com/tag/nazir ahmed">nazir ahmed</category>
      <category domain="http://securityratty.com/tag/nazir">nazir</category>
      <category domain="http://securityratty.com/tag/bad guys">bad guys</category>
      <category domain="http://securityratty.com/tag/guys">guys</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/indian police">indian police</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_ill_effects_1.html">The Ill Effects of Banning Security Research</source>
    </item>
    <item>
      <title><![CDATA[Text Messaging, Facebook Can Get You in Legal Trouble]]></title>
      <link>http://securityratty.com/article/9c9651d854e6d7f964ac43a55dd475ab</link>
      <guid>http://securityratty.com/article/9c9651d854e6d7f964ac43a55dd475ab</guid>
      <description><![CDATA[How we miss the quaint times when text was just a quick way to chat with buddies. Today, these fleeting missives, now integral to so many work lives, amount to a multimillion-dollar corporate risk....]]></description>
      <content:encoded><![CDATA[How we miss the quaint times when text was just a quick way to chat with buddies. Today, these fleeting missives, now integral to so many work lives, amount to a multimillion-dollar corporate risk. Organizations sit largely unprepared while text messages replace e-mail as the digital smoking gun.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:fcb5086899660a9ea9ee439adde13ef7:3pCSZtjgfmrPxVDb%2B9ExDLaCkPSKssbgAlO7gtuCfTAgOSUjFiWAxttOFMmTtpUHWbLKLdrbqkcD'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2a8f3038f698d8f03c9978288fc004d6:KmsGQJJLlRsOXYUCyLE95VHWNV3YcuyG0FUP2sdMPqsVeJguQOBrH8H37uDukBixjHIs8tb9kCiAcg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:74e258819b93fd62ea66a88119e96491:fGhEj86nJgYFzP%2BrxAhq8L5rI15H8%2BvqVvbqXfk24J3zSCk0ZMAjVLf%2Fe0AqiLXe2oO8mq5QJJ9S7A%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:3aa33011c87981bad91eacd9a3c182ca:Nkx8nrtUQdkC8GStLsjHsr6J%2FL8FNg8YgJJVtJBUok7ZA5EVTaSferAlWsSJhBLchL68JxaQ7QpGqA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=0c325b7a870911673a3c3ab8ba3935aa"><img src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=0c325b7a870911673a3c3ab8ba3935aa" border="0" /></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=0c325b7a870911673a3c3ab8ba3935aa" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/quaint times">quaint times</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/integral">integral</category>
      <category domain="http://securityratty.com/tag/gun">gun</category>
      <category domain="http://securityratty.com/tag/missives">missives</category>
      <category domain="http://securityratty.com/tag/chat">chat</category>
      <category domain="http://securityratty.com/tag/lives">lives</category>
      <category domain="http://securityratty.com/tag/buddies">buddies</category>
      <category domain="http://securityratty.com/tag/digital">digital</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=0c325b7a870911673a3c3ab8ba3935aa">Text Messaging, Facebook Can Get You in Legal Trouble</source>
    </item>
    <item>
      <title><![CDATA[Microsoft Begins the MS08-067 Post-Mortem]]></title>
      <link>http://securityratty.com/article/8b1a636e03c8882d65a7f324bcded81f</link>
      <guid>http://securityratty.com/article/8b1a636e03c8882d65a7f324bcded81f</guid>
      <description><![CDATA[It's finger-pointing time. Who let the infamous MS08-067 RPC bug through? Did the vaunted Microsoft Security Development Lifecycle fail? Did people approve the code when they shouldn't have? Microsoft...]]></description>
      <content:encoded><![CDATA[It's finger-pointing time.

Who let the infamous MS08-067 RPC bug through? Did the vaunted Microsoft Security Development Lifecycle fail? Did people approve the code when they shouldn't have?

<a href="http://www.webbuyersguide.com/company/66/Microsoft&kc=eweekarticle110308&src=eweekarticle110308">Microsoft</a> has already begun examining these questions in <a href="http://blogs.msdn.com/sdl/archive/2008/10/22/ms08-067.aspx" target="_blank">an entry on the SDL blog.</a> The problem, the blog seems to conclude, is the complexity of the code. It's just really hard to find bugs of this nature. To have found it would have been lucky. Michael Howard, the SDL guru and blogger, isn't really pointing fingers, although commenters on the blog are.

It's a prime example of what I wrote about not long ago when I said <a href="http://www.eweek.com/c/a/Security/Still-Overflowing-After-All-These-Years/">buffer overflows would never go away.</a> The examples we all see of what overflows are and how to stop them are fairly simple things: Allocate a buffer of size b, read 2*b bytes into it. In this case, there were two problems making the problem significantly more complex: The overflow happens inside a loop, during which pointer arithmetic is done. This alone makes it harder to identify for humans to identify the bug and perhaps impossible for tools to identify it without incurring a large incidence of false positives. Stack-checking also failed in this instance.

Howard called the code in question "reasonably complex" and said at a later date he would publish source code from the function. He said Microsoft's automated tools wouldn't find this bug in this type of code. Some comments on the blog asked him whether this complexity is, in and of itself, a problem. Perhaps manual code reviews should have rejected it. Howard didn't go this far, but I sense, in between the lines, that maybe he feels the same.

As a programmer I've seen this sort of code plenty of times and written it myself. The code may have seemed particularly efficient or just plain cool to the programmer, but complex loops with pointer arithmetic sound inherently like asking for trouble. I've written before that Microsoft has a long-term way of writing for the next generation of hardware, and CPU processing power is becoming absurdly cheap. Perhaps an implementation that is slower than necessary, but clear in its operation, is the better choice. Then leave the optimizing to compilers. It's actually an old argument.

Another thing Howard remarks on is the failure of Microsoft's fuzzing tools in this instance. All he says is they didn't find it and they'll work on that, and they are always working on their fuzzing tools. Fuzzing is cool and this episode shows how there's always more work to do in it. <a href="http://blogs.securiteam.com/index.php/archives/1151" target="_blank">Aviram on the SecuriTeam blog relates </a>how over two years ago famous researcher Dave Aitel said his fuzzer found no more bugs in the MS RPC code, so there must not be any. This was probably tongue-in-cheek, but even so, Aitel's probably biting his tongue now.

Even though many levels of tools and procedures put in place to prevent such vulnerabilities failed to do so, it would be a mistake to say the system failed altogether. This vulnerability, just about the worst class of bug we ever get, comes with significant mitigating factors, and is probably, as a practical matter, not exploitable on Windows Vista and Server 2008. Not everything failed.
<p><a href="http://feedads.googleadservices.com/~a/TOAsgjkEp3a_sBJoijuoWeC3U0s/a"><img src="http://feedads.googleadservices.com/~a/TOAsgjkEp3a_sBJoijuoWeC3U0s/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/yYUo7KKMw0Q" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 10:41:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/code plenty">code plenty</category>
      <category domain="http://securityratty.com/tag/publish source code">publish source code</category>
      <category domain="http://securityratty.com/tag/manual code reviews">manual code reviews</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/rpc code">rpc code</category>
      <category domain="http://securityratty.com/tag/securiteam blog">securiteam blog</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/howard remarks">howard remarks</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/yYUo7KKMw0Q/microsoft_begins_the_ms08-067_post-mortem.html">Microsoft Begins the MS08-067 Post-Mortem</source>
    </item>
    <item>
      <title><![CDATA[Integrating Event/Incident and Problem Management]]></title>
      <link>http://securityratty.com/article/fbba6395d7eaad30dc65321fe9f0fd16</link>
      <guid>http://securityratty.com/article/fbba6395d7eaad30dc65321fe9f0fd16</guid>
      <description><![CDATA[Change, Change, Change. What needs to change as IT organizations move towards sophisticated virtualized infrastructure ? Event/Incident and Problem Management integration of course
We have been...]]></description>
      <content:encoded><![CDATA[<p>Change, Change, Change. What needs to change as IT organizations move towards sophisticated <a href="http://blog.taragana.com/index.php/archive/virtualization-technologies-full-virtualization-versus-para-virtualization/" target="_blank">virtualized infrastructure</a>? Event/Incident and Problem Management integration of course!</p>
<p>We have been conducting polls of our customers and of IT professionals at technology trade shows for the past two years and the results are in: Pulling together all of the management pieces and processes is even more crucial in a virtualized environment.</p>
<p>So what does this mean for you? You will need to refine your <a href="http://blog.evergreensys.com/2008/01/10/meeting-tough-customers-over-incident-management/" target="_blank">incident and problem management</a> processes with new technologies in order to reduce downtime and maintain end user performance. But of course even the most basic technologies are not well integrated even in today’s world.</p>
<p>I recently participated in a <a href="Gartner%20Conference" target="_blank">Gartner Conference</a> and watched to my amazement a real-time electronic survey of the audience. To my disbelief, the audience, filled with 300+ people from Fortune 2000 companies provided real-time responses to the question:</p>
<p><em>What level of integration does your IT org have between event management and service desk applications?</em></p>
<ul>
<li>None: 10%</li>
<li><strong>Manual Phone call from IT ops to IT service desk staff member: 46%</strong></li>
<li>Manual click button on event manager to open trouble ticket: 20%</li>
<li>Automated event management system automatically opens trouble ticket without requiring human oversight or approval: 24%</li>
</ul>
<p>Unbelievable… still very few of the survey respondents have yet to formalize problem management systems with event management systems. For 56% of the audience the process is still manual!</p>
<p>Another interesting real-time survey question at the Gartner Conference was:</p>
<p><em>Who in your organization is responsible for critical problem processes and resolution?</em></p>
<ul>
<li>IT Service Desk 13%</li>
<li>IT Operations 49%</li>
<li>Process Team 12%</li>
<li>Other 9%</li>
<li>Responsibility not formalized 17%</li>
</ul>
<p><a href="http://blogs.technet.com/virtualization/archive/2008/10/10/Guest-post_3A00_-virtualization-requires-the-proper-perspective-.aspx" target="_blank">Virtualization adoption</a> and the speed with which things change in a virtualized environment require automation and will transform <a href="http://servicexen.wordpress.com/2008/07/02/implementing-service-management-processes-in-small-and-medium-companies/" target="_blank">Incident and Problem Management</a>. Clearly with <a href="http://tarrysingh.blogspot.com/2008/10/microsoft-to-train-thousands-in.html" target="_blank">this new technology we are required to re-think</a> Organizational, Behavioral and Cultural Challenges required to take advantage of the opportunities that virtualization provides.</p>
<p>Incident and problem management processes and metrics must bridge organizational silos that have been the norm within IT. With virtualization, people have to work more closely together in the different silos than ever before. IT leaders need to break down the walls between the technology-centric silo mentalities.</p>
<p>Business Imperative Action Plan:</p>
<ol>
<li>What can you do<strong> today</strong>? &#8211;Understand the impact of virtualization on incident and problem mgt. workload, provide technology training for helpdesk/service desk staff.</li>
<li>What can you do in the <strong>next 12 months</strong>?</li>
</ol>
<p>Formalize problem management processes, metrics and personnel.<br />
Invest in tools and processes for systems on virtualized servers.<br />
Long term: On the Radar Screen!<br />
Instill teamwork into all groups responsible for the <a href="http://servicexen.wordpress.com/2008/07/02/implementing-service-management-processes-in-small-and-medium-companies/" target="_blank">virtualized environment</a> service and support. Map components and configuration items directly to end user services.</p>
<p>Final Thoughts: Know the management pieces and ensure that they fit together. It’s great to buy new technology, but be demanding to ensure that your vendors show you have they will help to link all these pieces together - Change, Inventory, Incident, Problem, Server, Capacity, Performance, Configuration, Event, and Integrated Workflow.</p>
]]></content:encoded>
      <pubDate>Tue, 14 Oct 2008 14:00:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/management">management</category>
      <category domain="http://securityratty.com/tag/event management systems">event management systems</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/management processes">management processes</category>
      <category domain="http://securityratty.com/tag/management pieces">management pieces</category>
      <category domain="http://securityratty.com/tag/management systems">management systems</category>
      <category domain="http://securityratty.com/tag/management integration">management integration</category>
      <category domain="http://securityratty.com/tag/event management system">event management system</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <source url="http://blog.sciencelogic.com/integrating-eventincident-and-problem-management/10/2008">Integrating Event/Incident and Problem Management</source>
    </item>
    <item>
      <title><![CDATA[Innovators, Imitators and Idiots]]></title>
      <link>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</link>
      <guid>http://securityratty.com/article/9f0fb5a40e7304e54d82bd150f69993b</guid>
      <description><![CDATA[Charlie Rose interviews Warren Buffett


Charlie Rose
And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage. We just lost sight...]]></description>
      <content:encoded><![CDATA[<p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;">Charlie Rose <a href="http://www.cnbc.com/id/26982338/page/2/">interviews</a> Warren Buffett:</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And so when you look at where we are going, there seems to be two issues that are apparent to me at least, risk and leverage.&#0160; We just lost sight of risk and leverage of what was appropriate?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.&#0160; Again, because it pays off for a while.&#0160; You know, you can lose leverage, and it&#39;s the only way a smart guy can go broke.&#0160; If you owe money, you can&#39;t pay them out.&#0160; You just pay for everything, you do smart things, you eventually get very rich.&#0160; If you do smart things and use leverage and do one wrong thing along the way, it could wipe you out, because anything times zero is zero.&#0160; But it&#39;s reinforcing when the people around you are doing it successfully, you&#39;re doing it successfully, and it&#39;s a lot like Cinderella at the ball.&#0160; I mean you know at midnight everything is going to turn to pumpkins and mice; right?&#0160; But if the evening goes along, I mean, you know, the guys look better all the time, the music sounds better, it&#39;s more and more fun, you think why the hell should I leave at quarter of 12.&#0160; I&#39;ll leave at two minutes to 12.&#0160; But the trouble is, there are no clocks on the wall.&#0160; And everybody thinks they&#39;re going to leave at two minutes to 12.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Its effectively the job of leadership to know when to take the punch bowl away and to have the credibility to do this. This is also the risk-reward balance that infosec must try to strike, part of the answer is differentiating <a href="http://1raindrop.typepad.com/1_raindrop/2007/11/dhandho-infosec.html">risk and uncertainty</a>. As our current financial situation shows, its a hard thing to pull off</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">And should wise people have known better?</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">People should always know better.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Charlie Rose:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Yeah.</span></p><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">I mean people -- people don&#39;t get -- they don&#39;t get smarter about things that get as basic as greed and you can&#39;t stand to see your neighbor getting rich.&#0160; You know you&#39;re smarter than he is, and he&#39;s doing these things, you know, and he&#39;s getting rich, and your spouse is getting unhappy with you because you aren&#39;t doing -- pretty soon you start doing it.&#0160; And so you get what I call the natural progression, the three Is.&#0160; The innovators, the imitators, and the idiots.&#0160; And that&#39;s what happens.&#0160; Everybody just kind of goes along.&#0160; And you look kind of silly if you disagree.&#0160; I mean, you know, you could have these crazy Internet valuations in the late 1990s, but they prove themselves out in the market.&#0160; The next day they were selling for more than they were the day before, and people said, you know, you&#39;re crazy if you don&#39;t get in on this.&#0160; So it&#39;s very human.&#0160; Now, with housing it&#39;s something even more dramatic than that, because most people aspire to own their own home.&#0160; And if you really think that houses prices are going to go up next year and the year after, you feel if I don&#39;t buy it this year, I&#39;m going to have to buy it next year.&#0160; That&#39;s not true of an Internet stock.&#0160; But it&#39;s true of a home.&#0160; And when somebody makes it very easy for you to do it by saying you don&#39;t really have to put up my money, you can lie about your income a little, or we&#39;ll give you 100 percent mortgage, you&#39;re going to do it, because everybody that&#39;s done it has been proven right.&#0160; You have what they call social tools, and, you know, you&#39;re going to feel like an idiot if you didn&#39;t do it, because the house cost more.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">And this is why its hard to pull off. There is a lot of human emotion and envy (*). I think the point Buffett raises about innovators, imitators and idiots is a useful one for infosec. We see all kinds of new projects and technologies that have risks and rewards associated with them, its helpful to categorize these under innovation (high risk but possible game changer), imitators (so called best practices), and idiots (sheep mode - blind risk acceptance). We can get some traction here to use these concepts to understand what to do when assessing say the architectural and oeprational risk of a system.</span></div><div><span style="font-weight: normal;"><br /></span></div><div><span style="font-weight: normal;">Finally, we should always spend some time to consider infosec decisions in a broader long term economic context and this is also true of our current financial crisis</span></div><div><span style="font-weight: normal;"><br /></span></div></strong></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; "><strong>Warren Buffett:</strong>&#0160;&#0160;</span><br /><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">Oh, I think confidence will come back.&#0160; I will tell you this.&#0160; This country is going -- be living better ten years from now than it is now.&#0160; It will be living better in 20 years from now than ten years from now.&#0160; The ingredients that made this country, you know, the miracle of the world -- I mean we had a seven for one improvement in the average American standard of living in the 20th century.&#0160; Now, we had the great depression, we had two world wars, we had the flu epidemic.&#0160; You know, we had oil shock.&#0160; You know, we had all these terrible things happen.&#0160; But something about the American system unleashed more and of a potential to human beings over that hundred years so that we had a seven for one improvement in -- there&#39;s never been any -- I mean, you have centuries where if you&#39;ve got a 1 percent improvement, then it&#39;s something.&#0160; So we&#39;ve got a great system.&#0160; And we&#39;ve got more productive capacity now than we ever have.&#0160; The American worker is more productive than he&#39;s ever been.&#0160; We&#39;ve got more people to do it.&#0160; We&#39;ve got all the ingredients for a sensational future.&#0160; It&#39;s just that right now the athlete&#39;s on the floor.&#0160; But we -- this is a super athlete.</span></p></blockquote><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Again, we want to look at risk events in a broader, long term context. In Buffett&#39;s words its - &quot;be fearful when others are greedy and greedy when others are fearful.&quot; As the world panics and Jim Cramer is melting down on TV, Buffett is quietly writing checks with both hands, buying $3B of GE, $5B of Goldman, $6.5 of Wrigley/Mars and so on. Uncertainty is one thing, it could be 6 months it could be 5 years until this thing turns around, but risk is another - you hedge your risk with price and long term advantages, i.e. moats. People will still eat candy in a bad economy.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* Buffett&#39;s partner Charlie Munger calls envy the stupidest of the seven deadly sins, because only you feel bad, there is an upside to all the others. He said you can pay someone on Wall St $2 million a year and they will be perfectly happy until they find out someone across the hall is making $2.1 million and then they will be miserable. Which is an insane way tolive.</span></div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 04:32:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/oeprational risk">oeprational risk</category>
      <category domain="http://securityratty.com/tag/risk events">risk events</category>
      <category domain="http://securityratty.com/tag/risk-reward balance">risk-reward balance</category>
      <category domain="http://securityratty.com/tag/wise people">wise people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/buffett raises">buffett raises</category>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/blind risk acceptance">blind risk acceptance</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/10/innovators-imitators-and-idiots.html">Innovators, Imitators and Idiots</source>
    </item>
    <item>
      <title><![CDATA[Modelling The Global Financial Meltdown]]></title>
      <link>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</link>
      <guid>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</guid>
      <description><![CDATA[Yesterday I received a call from Penny Grosman , Senior Editor, Wall Street &amp; Technology . Penny was interested in my opinion, Will risk management applications be the next killer app for CEP on Wall...]]></description>
      <content:encoded><![CDATA[<p>Yesterday I received a call from <a href="http://www.wallstreetandtech.com/penny-crosman/" target="_blank">Penny Grosman</a>, Senior Editor, <a href="http://www.wallstreetandtech.com/" target="_blank">Wall Street &amp; Technology</a>.   Penny was interested in my opinion, &#8220;Will risk management applications be the next killer app for CEP&#8221; on Wall Street.    I enjoyed talking with Penny.  She caught up with me leaving a tailor&#8217;s shop in Chiang Mai, so I hope she did not mind hearing my stories of buying unique Northern Thai cotton fabric and designing my own casual shirts in the economic turndown.</p>
<p>We read many stories on the net where folks claim that the current financial crisis could have been avoided with more or better use of technology.     This is expected, as software companies and IT professionals will often try to piggy-backtheir business development strategy on the &#8220;crisis of the day&#8221; to sell more goods and services.    Honestly, in this current situation, the main technology that we needed was simple, accurate financial models.</p>
<p>For example, in the chart above, the US economy was doing quite well with US federal funds rates low.   Housing prices in the US were skyrocketing and there was a concern about inflation.    There was an understandable concern the sustainability of that economy.</p>
<p style="text-align: center;"><img class="aligncenter" style="vertical-align: bottom;" src="http://www.thewrittenblog.com/main_1/images/97kcpv16xjh0uvsi8k7kdhaw.gif" alt="" width="277" height="415" /></p>
<p>So, in perhaps one the most ill-advised Federal Reserve actions of many decades, the folks at the helm of the Fed decided to raise their lending rates around 500 percent over a two year period.</p>
<p>As we all know, primarily because of the action by the Fed, the world faces perhaps the worst economic disaster in modern times, while the US Executive Branch and the Congress fight over how to spend $700 Billion taxpayer dollars to inject liquidity into the markets to try to head off a global financial disaster.</p>
<p>It is amazing to me that the US Federal Government, or their advisors, does not have simple financial models with cause-and-effect analysis such as:</p>
<ul>
<li>Homeowners with adjustable rate mortuages will not be able to make payments;and</li>
<li>Housing prices will fall dramatically; then</li>
<li>Homeowners will default on loans where the collateral is much less than the asset value, and</li>
<li>Banks will suffer great losses, and</li>
<li>Lending will come to a halt, then</li>
<li>Banks will collapse, then</li>
<li>Wall Street will exit the markets in panic</li>
<li>&#8230; and more trouble&#8230;.. !!</li>
</ul>
<p>There are and continue to be a lot of discussion and opinions about how risk management needs improvement. and I agree.   We will also read folks talk about how technology can be used to help solve this problem, including CEP/EP and related software (see also <!-- This wrapper class appears only on Page and Single Post pages. --><a title="Capital Market CEP Fantasy Land" rel="bookmark" href="../2008/06/23/capital-market-cep-fantasy-land/">Capital Market CEP Fantasy Land</a>). However, as much I would be pleased to see more CEP/EP applications and use cases, I do not believe that event processing technology is really very useful to solve the core problem of the current financial crisis.</p>
<p>The core problem is, seemingly, that our &#8220;financial experts&#8221; do not even have simple models that will illustrate what will or could happen when you raise the fed lending rates 500 percent in two years in an economy pregnant with adjustable rate mortgages.</p>
<p>To me, this does not appear to be rocket science.  The negligence by the US Federal Reserve and their advisors is astonishing.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 02:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/simple financial models">simple financial models</category>
      <category domain="http://securityratty.com/tag/financial models">financial models</category>
      <category domain="http://securityratty.com/tag/current financial crisis">current financial crisis</category>
      <category domain="http://securityratty.com/tag/crisis">crisis</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wall street">wall street</category>
      <category domain="http://securityratty.com/tag/main technology">main technology</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <source url="http://www.thecepblog.com/2008/10/02/modelling-the-global-financial-meltdown/">Modelling The Global Financial Meltdown</source>
    </item>
    <item>
      <title><![CDATA[Airport 'X-ray art' courts TSA trouble]]></title>
      <link>http://securityratty.com/article/b202335b37b59498ddae3e4c28f71b45</link>
      <guid>http://securityratty.com/article/b202335b37b59498ddae3e4c28f71b45</guid>
      <description><![CDATA[Techno-artist/open-source developer Evan Roth has a message for the Transportation Safety Administration -- several messages, actually -- about what he considers excessive airport security &quot;theater.&quot;...]]></description>
      <content:encoded><![CDATA[Techno-artist/open-source developer Evan Roth has a message for the Transportation Safety Administration -- several messages, actually -- about what he considers excessive airport security "theater." He also has chosen an intentionally provocative method of delivering those messages: the TSA's own X-ray screening machines.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=89965?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=89965?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/developer evan roth">developer evan roth</category>
      <category domain="http://securityratty.com/tag/transportation safety administration">transportation safety administration</category>
      <category domain="http://securityratty.com/tag/provocative method">provocative method</category>
      <category domain="http://securityratty.com/tag/messages">messages</category>
      <category domain="http://securityratty.com/tag/tsa">tsa</category>
      <category domain="http://securityratty.com/tag/x-ray">x-ray</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/theater">theater</category>
      <category domain="http://securityratty.com/tag/machines">machines</category>
      <source url="http://www.networkworld.com/columnists/2008/100208-buzz.html?fsrc=rss-security">Airport 'X-ray art' courts TSA trouble</source>
    </item>
    <item>
      <title><![CDATA[John McCain: Desperate and Reckless]]></title>
      <link>http://securityratty.com/article/a299c2b37dd8172588b5324124b6f3cd</link>
      <guid>http://securityratty.com/article/a299c2b37dd8172588b5324124b6f3cd</guid>
      <description><![CDATA[Normally I would not blog about political topics here, but this is an extraordinary time in history and extraordinary times call for extraordinary posts from time-to-time
John McCain is, objectively,...]]></description>
      <content:encoded><![CDATA[<p>Normally I would not blog about political topics here, but this is an extraordinary time in history and extraordinary times call for extraordinary posts from time-to-time.</p>
<p>John McCain is, objectively, a bad decision maker, desperate and reckless.   He knows that his party is in trouble and that the Democrats have the advantage; so what does he do?</p>
<p>First, he picks a very conservative, inexperienced female governor from Alaska who, until recently, did not even have a US passport, as his running mate.  This was an obvious act of desperation, thinking that he could pull the Hillary votes in the election.  A heartbeat from the US Presidency at a time when there are two ongoing wars and our country on the verge of economic collapse and he gambles with a &#8220;Hail Mary&#8221; touchdown pass?  This is not the man we need as President.</p>
<p>Then, not even a member of the Banking committee in the Senate, and self-described &#8220;not knowledgeable on economic issues&#8221;, John McCain tries another &#8220;Hail Mary&#8221; pass by rushing off to DC to &#8220;save the world&#8221; and tries to demand Obama suspend his campaign and the debates?    The US is on the brink of economic collapse and McCain puts politics and election desperation above the future of the country?   This is not the man we need as President.</p>
<p>During the same period, Barack Obama has proven to be cool, intelligent, and a good decision maker.   This should be obvious to anyone with the mind to actually think what is good for the country and not about politics.</p>
<p>John McCain is desperate and reckless.   We don&#8217;t need desperate and reckless people leading this country.</p>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 14:54:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mccain">mccain</category>
      <category domain="http://securityratty.com/tag/john mccain">john mccain</category>
      <category domain="http://securityratty.com/tag/reckless">reckless</category>
      <category domain="http://securityratty.com/tag/bad decision maker">bad decision maker</category>
      <category domain="http://securityratty.com/tag/decision maker">decision maker</category>
      <category domain="http://securityratty.com/tag/economic collapse">economic collapse</category>
      <category domain="http://securityratty.com/tag/extraordinary time">extraordinary time</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/election desperation">election desperation</category>
      <source url="http://www.thecepblog.com/2008/09/26/john-mccain-desperate-and-reckless/">John McCain: Desperate and Reckless</source>
    </item>
  </channel>
</rss>
