<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: truth]]></title>
    <link>http://securityratty.com/tag/truth</link>
    <description></description>
    <pubDate>Wed, 13 Aug 2008 04:31:50 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Real Truth Behind The MakeUseOf.com Domain Crack]]></title>
      <link>http://securityratty.com/article/bc54477a6be86292566253949a0f70b1</link>
      <guid>http://securityratty.com/article/bc54477a6be86292566253949a0f70b1</guid>
      <description><![CDATA[I've been seeing some crazy rumours flying around the web since last night (particularly on Twitter) about Make Use Of so this blog post is to put down the whole truth and put those stupid rumours to...]]></description>
      <content:encoded><![CDATA["I've been seeing some crazy rumours flying around the web since last night (particularly on Twitter) about Make Use Of so this blog post is to put down the whole truth and put those stupid rumours to bed once and for all."<img src="http://feedproxy.google.com/~r/digg/topic/security/popular/~4/ApJUIUubSjY" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 18:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/crazy rumours">crazy rumours</category>
      <category domain="http://securityratty.com/tag/stupid rumours">stupid rumours</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/truth">truth</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/bed">bed</category>
      <category domain="http://securityratty.com/tag/night">night</category>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <source url="http://feeds.digg.com/~r/digg/topic/security/popular/~3/ApJUIUubSjY/The_Real_Truth_Behind_The_MakeUseOf_com_Domain_Crack">The Real Truth Behind The MakeUseOf.com Domain Crack</source>
    </item>
    <item>
      <title><![CDATA[Kip Hawley Responds to My Airport Security Antics]]></title>
      <link>http://securityratty.com/article/2e95c109ca3f99365400804e6c31b4dd</link>
      <guid>http://securityratty.com/article/2e95c109ca3f99365400804e6c31b4dd</guid>
      <description><![CDATA[Kip Hawley, head of the TSA, has responded to my airport security penetration testing , published in The Atlantic
Unfortunately, there's not really anything to his response. It's obvious he doesn't...]]></description>
      <content:encoded><![CDATA[<p>Kip Hawley, head of the TSA, has <a href="http://www.tsa.gov/blog/2008/10/tsas-take-on-atlantic-article.html">responded</a> to my <a href="http://www.schneier.com/blog/archives/2008/10/me_helping_evad.html">airport security penetration testing</a>, published in <i>The Atlantic</i>.</p>

<p>Unfortunately, there's not really anything to his response.  It's obvious he doesn't want to admit that they've been checking ID's all this time to no purpose whatsoever, so he just emits vague generalities like a frightened squid filling the water with ink.  Yes, some of the stunts in article are silly (who cares if people fly with Hezbollah T-shirts?) so that gives him an opportunity to minimize the real issues.</p>

<blockquote>Watch-lists and identity checks are important and effective security measures. We identify dozens of terrorist-related individuals a week and stop No-Flys regularly with our watch-list process.</blockquote>

<p>It is simply impossible that the TSA catches dozens of terrorists every week. If it were true, the administration would be trumpeting this all over the press -- it would be an amazing success story in their war on terrorism.  But note that Hawley doesn't exactly say that; he calls them "terrorist-related individuals."  Which means exactly what?  People so dangerous they can't be allowed to fly for any reason, yet so innocent they can't be arrested -- even under the provisions of the Patriot Act.</p>

<p>And if Secretary Chertoff is telling the truth when he <a href="http://www.cnn.com/2008/TRAVEL/10/22/no.fly.lists/index.html">says</a> that there are only 2,500 people on the no-fly list and fewer than 16,000 people on the selectee list -- they're the ones that get extra screening -- and that most of them live outside the U.S., then it is statistically impossible that the TSA identifies "dozens" of these people every week.  The math just doesn't make sense.</p>

<p>And I also don't believe this:</p>

<blockquote>Behavior detection works and we have 2,000 trained officers at airports today. They alert us to people who may pose a threat but who may also have items that could elude other layers of physical security.</blockquote>

<p>It does work, but I don't see the TSA doing it properly.  (Fly El Al if you want to see it done properly.)  But what I think Hawley is doing is engaging in a little bit of psychological manipulation.  Like sky marshals, the real benefit of behavior detection isn't whether or not you do it but whether or not the bad guys <i>believe</i> you're doing it.  If they think you are doing behavior detection at security checkpoints, or have sky marshals on every airplane, then you don't actually have to do it.  It's the threat that's the deterrent, not the actual security system.</p>

<p>This doesn't impress me, either:</p>

<blockquote>Items carried on the person, be they a 'beer belly' or concealed objects in very private areas, are why we are buying over 100 whole body imagers in upcoming months and will deploy more over time. In the meantime, we use hand-held devices that detect hydrogen peroxide and other explosives compounds as well as targeted pat-downs that require private screening.</blockquote>

<p>Optional security measures don't work, because the bad guys will opt not to use them.  It's like those air-puff machines at some airports now.  They're probably great at detecting explosive residue off clothing, but every time I have seen the machines in operation, the passengers have the option whether to go through the lane with them or another lane.  What possible good is that?</p>

<p>The closest thing to a real response from Hawley is that the terrorists might get caught stealing credit cards.</p>

<blockquote>Using stolen credit cards and false documents as a way to get around watch-lists makes the point that forcing terrorists to use increasingly risky tactics has its own security value.</blockquote>

<p>He's right about that.  And, truth be told, that was my sloppiest answer during the original intervied.  Thinking about it afterwards, it's far more likely is that someone with a clean record and a legal credit card will buy the various plane tickets.</p>

<p>This is new:</p>

<blockquote>Boarding pass scanners and encryption are being tested in eight airports now and more will be coming.</blockquote>

<p>Ignoring for a moment that "eight airports" nonsense -- unless you do it at every airport, the bad guys will choose the airport where you don't do it to launch their attack -- this is an excellent idea.  The reason my attack works, the reason I can get through TSA checkpoints with a fake boarding pass, is that the TSA never confirms that the information on the boarding pass matches a legitimate reservation.  If all TSA checkpoints had boarding pass scanners that connected to the airlines' computers, this attack would not work.  (Interestingly enough, I noticed exactly this system at the Dublin airport earlier this month.)</p>

<blockquote>Stopping the ‘James Bond’ terrorist is truly a team effort and I whole-heartedly agree that the best way to stop those attacks is with intelligence and law enforcement working together.</blockquote>

<p>This isn't about "Stopping the 'James Bond' terrorist," it's about stopping terrorism.  And if all this focus on airports, even assuming it starts working, shifts the terrorists to other targets, we haven't gotten a whole lot of security for our money.</p>

<p>FYI:  I did a <a href="http://www.schneier.com/interview-hawley.html">long interview</a> with Kip Hawley last year. If you haven't read it, I strongly recommend you do.  I pressed him on these and many other points, and didn't get very good answers then, either.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=eD30M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=eD30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Ih06M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Ih06M" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 02:24:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/airport">airport</category>
      <category domain="http://securityratty.com/tag/effective security measures">effective security measures</category>
      <category domain="http://securityratty.com/tag/dublin airport">dublin airport</category>
      <category domain="http://securityratty.com/tag/airport security penetration">airport security penetration</category>
      <category domain="http://securityratty.com/tag/security checkpoints">security checkpoints</category>
      <category domain="http://securityratty.com/tag/kip hawley">kip hawley</category>
      <category domain="http://securityratty.com/tag/tsa">tsa</category>
      <category domain="http://securityratty.com/tag/tsa identifies">tsa identifies</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/kip_hawley_resp.html">Kip Hawley Responds to My Airport Security Antics</source>
    </item>
    <item>
      <title><![CDATA[PCI app security: Who's guarding the data bank?]]></title>
      <link>http://securityratty.com/article/100e56effb25927ac6fe32300a54f483</link>
      <guid>http://securityratty.com/article/100e56effb25927ac6fe32300a54f483</guid>
      <description><![CDATA[While Willy Sutton never really said it, the truth is that people rob banks because that is where the money is. Today's criminals don't walk into banks with loaded guns and get-away drivers. Rather...]]></description>
      <content:encoded><![CDATA[While Willy Sutton never really said it, the truth is that people rob banks because that is where the money is. Today's criminals don't walk into banks with loaded guns and get-away drivers. Rather they connect from a remote location using a browser and are armed with hacking tools and spyware.]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/people rob banks">people rob banks</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/willy sutton">willy sutton</category>
      <category domain="http://securityratty.com/tag/get-away drivers">get-away drivers</category>
      <category domain="http://securityratty.com/tag/remote location">remote location</category>
      <category domain="http://securityratty.com/tag/spyware">spyware</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <source url="http://www.networkworld.com/news/2008/101008-pci-app-security-whos-guarding.html?fsrc=rss-security">PCI app security: Who's guarding the data bank?</source>
    </item>
    <item>
      <title><![CDATA[Root of Trust ?]]></title>
      <link>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</link>
      <guid>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</guid>
      <description><![CDATA[Ive given some talks this year about the Internets insecure infrastructure stressing that fundamental protocols such as BGP and DNS cannot really be trusted at the moment. Although they work just fine...]]></description>
      <content:encoded><![CDATA[<p>I&#8217;ve given <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080211-mailserver.pdf">some</a> <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080915-ISPsecurity.pdf">talks</a> this year about the Internet&#8217;s insecure infrastructure &#8212; stressing that fundamental protocols such as <a href="http://www.bgp4.as/">BGP</a> and <a href="http://oreilly.com/catalog/9780596100575/">DNS</a> cannot really be trusted at the moment. Although they work just fine most of the time, they are susceptible to attacks which can mean, for example, that you visit the wrong website, or your email is intercepted.</p>
<p>Steps are now being taken, <a href="http://voices.washingtonpost.com/securityfix/2008/08/dns_security_mandatory_for_all.html">rather faster</a> since Dan Kaminsky came up with a <a href="http://www.doxpara.com/?p=1185">really effective DNS poisoning attack</a>, to secure DNS by using <a href="http://www.dnssec.net/">DNSSEC</a>.</p>
<p>The basic idea of DNSSEC is that when you get an answer from the DNS it will be signed by someone you trust. At some point the &#8220;trust anchor&#8221; for the system will be &#8220;.&#8221; the DNS root, but for the moment there&#8217;s <a href="http://www.unbound.net/documentation/howto_anchor.html">just a handful of &#8220;trust anchors&#8221; one level down</a> from that. One such anchor is the &#8220;.se&#8221; country code domain for Sweden. Additionally, Brazil (.br), Puerto Rico (.pr), and Bulgaria (.bg) have signed their zones, but that&#8217;s about it for today.</p>
<p>So, wishing to get some experience with the <a href="http://www.sparknotes.com/lit/bravenew/">brave new world</a> of DNSSEC, I decided that Sweden was <a href="http://www.cartoonbank.com/item/25468">the &#8220;in&#8221; place to be</a>, and to purchase &#8220;cloudba.se&#8221; and roll out my first DNSSEC signed domain.</p>
<p>The purchase wasn&#8217;t as easy as it might have been &#8212; when you buy a domain, Sweden <a href="http://www.iis.se/docs/general_conditions.pdf">insists</a> that people provide their <a href="http://www.papersplease.org/id.html">identity numbers</a> (albeit they have absolutely no way of checking if you&#8217;re telling the truth) &#8212; or if a company they want a VAT or registration number (which are checkable, albeit I suspect they didn&#8217;t bother). I also found that they don&#8217;t like spaces in the VAT number &#8212; which held things up for a while!</p>
<p>However, eventually they sent me a PGP signed email to tell me I was now the proud owner of &#8220;cloudba.se&#8221;.  Unfortunately, this email wasn&#8217;t in RFC3156 PGP/MIME format (or any other format that my usually <a href="http://en.wikipedia.org/wiki/Turnpike_(software)">pretty capable email client</a> understood).</p>
<p>The email was signed with key 0xF440EE9B which was reassuring because the <a href="http://www.iis.se/">.se registry</a> gives the fingerprint for this key on their website <a href="https://domainmanager.iis.se/start/customerservice">here</a>. Rather less reassuringly footnote (*) next to the fingerprint says &#8220;<em>.SE signature for outgoing e-mail. (**) June 1 through August 31.</em>&#8221; (the (**) is for a second level of footnote, which is absent &#8212; and of course it is now September).</p>
<p>They also enable you to fetch the key through a link on <a href="http://www.iis.se/support">this page</a> to their &#8220;PGP nyckel-ID&#8221; at <a href="http://subkeys.pgp.net:11371/pks/lookup?op=get&#038;search=0xFCEC5128F440EE9B">http://subkeys.pgp.net</a>.</p>
<p>Unfortunately, fetching the key shows that the signature on the email is invalid.</p>
<p>Since the email seems to have originated in the Windows world, but was signed on a Linux box (giving it a mixture of 0D 0A and 0A line endings), then pushed through a three year old copy of <a href="http://search.cpan.org/dist/MIME-tools/">MIME-tools</a> I suppose the failure isn&#8217;t too surprising. But strictly the invalid signature means that I shouldn&#8217;t trust the email&#8217;s contents at all &#8212; because the contents have definitely been tampered with since the signature was applied.</p>
<p>Since the point of the email was to get me to login for the first time to the registry website and set my password to control the domain, this is a little <a href="http://www.cartoonbank.com/item/32907">unfortunate</a>.</p>
<p>Even if the signature had been correct, then should I trust the PGP key?</p>
<p>Well it is pointed to from the registry website which is a Good Thing. However, they do themselves no favours by referencing a version on <a href="http://www.rossde.com/PGP/pgp_keyserv.html">the public key servers</a>. I checked who had signed the key (which is an <a href="http://www.pgpi.org/doc/pgpintro/#p20">alternative way of trusting its provenance</a> &#8212; since the email had arrived to a non-DNSSEC secured domain). Turned out there was no-one I knew, and of 4 individual signatures, 2 were from expired keys. The other signature was the IIS root key &#8212; which sounds promising. That has 8 signatures, once again not people I know &#8212; but only 1 from a non-expired key, so perhaps I can get to know some of the other 7?</p>
<p>Of course, anyone can sign a key on a public key server, so perhaps it makes sense for .se to suggest that people fetch a key with as many signatures as possible &#8212; there&#8217;s more chance of it being signed by someone they know. Anyway, I have now added my own signature, using an email address at my nice shiny new domain. However, it is possible that I may not have increased the level of trust <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/09/signers.png" alt="" title="Signers of the .se PGP key" class="aligncenter size-full wp-image-381"></p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 14:33:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/public key servers">public key servers</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/iis root key">iis root key</category>
      <category domain="http://securityratty.com/tag/key 0xf440ee9b">key 0xf440ee9b</category>
      <category domain="http://securityratty.com/tag/pgp">pgp</category>
      <category domain="http://securityratty.com/tag/pgp nyckel-id">pgp nyckel-id</category>
      <category domain="http://securityratty.com/tag/public key server">public key server</category>
      <category domain="http://securityratty.com/tag/pgp key">pgp key</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/29/root-of-trust/">Root of Trust ?</source>
    </item>
    <item>
      <title><![CDATA[Relentless Reflection - What it Means in Risk Management]]></title>
      <link>http://securityratty.com/article/cb97e56e5e1097f1a11d050fe2f8d396</link>
      <guid>http://securityratty.com/article/cb97e56e5e1097f1a11d050fe2f8d396</guid>
      <description><![CDATA[Picking up from yesterday, Today Id like to talk about
HANSEI - WHAT IS RELENTLESS REFLECTION? - And why were talking about it in the context of Risk Analysis
Recall from yesterdays post about how I...]]></description>
      <content:encoded><![CDATA[<p>Picking up from yesterday, Today I&#8217;d like to talk about:</p>
<p><strong>HANSEI - WHAT IS &#8220;RELENTLESS REFLECTION?&#8221;</strong> - And why we&#8217;re talking about it in the context of Risk Analysis.</p>
<p>Recall from yesterday&#8217;s post about how I got to thinking about the concept of Hansei-Kaizen, &#8220;relentless reflection&#8221; and &#8220;continuous improvement&#8221; and how we might apply that to risk management.  It&#8217;s a concept born of Toyota and is, in some way, the foundation for &#8220;Lean&#8221; production.</p>
<p>Call me biased, but I think that Hansei - the act of &#8216;relentless reflection&#8217; made structured is the <em>analytical function</em>.  And I hate to debate (post-mortem) the father of Toyota quality success when he says that Hansei is the &#8220;check&#8221; in Plan/Do/Check/Act, but I think that Hansei also applies to the &#8220;Plan&#8221; of the P/D/C/A or Deming cycle.</p>
<p>You&#8217;ll recall the P/D/C/A cycle can be thought of even as an implementation of Scientific Method, in that it is Observation &amp; Hypothesis Creation (P), Experiment (D), Analysis (Check), and Act (Revise/New Hypothesis, etc&#8230;).  Well then as such, the Hypothesis creation involves creating a model or creating an expected outcome for data using the currently accepted model.</p>
<p>So in our industry there is an opportunity for Relentless Reflection in both the Observation and Hypothesis (Plan) creation steps, and the Check step.  We create an estimate for control strength, or probable losses in the context of risk- then we go to Experiment step.  That hypothesis can be put it into production, have an audit, have a penetration test, whatever, in the context of the Do step.  BTW - using Hansei/Analytics in Plan is one way that strong analytical functions can really make penetration testing more useful - as a means to test the estimates and inputs into a model.  It&#8217;s <strong>Penetration Testing 2.0</strong>!  (&lt;- tongue fully in cheek, yes)</p>
<p><em><br />
Those who are versed in the reasons to merge Six Sigma and Lean together are probably already seeing where I&#8217;m going with this today.  But before you think that a simple DMAIC function is all that is needed to create proper &#8220;Hansei&#8221;, let me encourage you to keep reading.</em></p>
<p><span style="color: #008000;"><strong><br />
Now if the analytical function can said to be &#8220;reflection&#8221;, why must it be relentless?</strong></span></p>
<p>One word.  <em><strong>Change.</strong></em> There are essentially four separate &#8220;landscapes&#8221; or sources of change that we face (more on those tomorrow).  But anyone who has tried to manage system compliance, log management or policy exceptions knows that change is possibly the most difficult thing we security professionals must manage.  And when you think about it, there aren&#8217;t too many other business functions like information security where significant visibility and insight about the environment is needed for &#8220;complete&#8221; information (get bullish on Log Management is my recommendation).</p>
<p><strong>HANSEI STEPS ADAPTED TO INFORMATION SECURITY</strong></p>
<p>This is one of those quality control concepts that we can <span style="text-decoration: line-through;">mangle</span> adopt.  At Toyota, Hansei-Kaizen includes the following basic steps:</p>
<p>1. Initial problem perception<br />
2. Clarify the problem<br />
3. Locate area/point of cause<br />
4. Investigate root cause (using an ask why 5 times approach)<br />
5. Countermeasure<br />
6. Evaluate<br />
7. Standardize</p>
<p>Now it&#8217;s important to note that part of this includes the concept of Go See For Yourself, called &#8220;<em><strong>Gemba</strong></em>&#8220;.  Gemba can be translated as “the actual place” or “the place where virtue or truth is found.” At Toyota this might mean going to the shop floor to see the issue at hand in the production line.  But for us, that&#8217;s a problem because we live in the virtual world.  There&#8217;s usually not much use in hanging out in the wiring closets to try to see the problems.</p>
<p>But if you combine the concept of Gemba with the concept of <em><strong>&#8220;Nemawashi</strong></em>&#8221; –the process of discussing problems and potential solutions with all those affected- we can forge a similar concept using risk analysis.  That is discussing the issue and the risk associated with an issue (what some people would call &#8220;risk management&#8221;) with the business/LOB/data owner and let them accept authority and the risk decision.  We, the risk analyst, our goal is simply to perform items 1-5 (presenting countermeasure options that include transferring or accepting risk).  By going to the line of business and involving them, responsibility is shared.  Also, if you structure organizational behavior right, <em>personal </em>risk is transferred!</p>
<p>This sort of approach is also in harmony with concepts like “mutual ownership of problems,” or “<em><a title="Genchi Genbutsu" href="http://en.wikipedia.org/wiki/Genchi_Genbutsu">genchi genbutsu</a>,</em>” (solving problems at the source instead of behind desks), and the “<em><a title="Kaizen" href="http://en.wikipedia.org/wiki/Kaizen">kaizen</a> mind,</em>” (an unending sense of crisis behind the company’s constant drive to improve).</p>
<p>One of the criticisms I have with the way most people try to implement DMAIC into &#8220;Lean&#8221;</p>
<p><strong>REQUIREMENTS</strong></p>
<p>Now to get this done, I really see three significant requirements.</p>
<p>1.)  A change in political structure.</p>
<p>2.)  Models that provide consistent, defensible analysis.</p>
<p>3.)  A Quantitative approach.  This means using actual units of measurement (not just amorphous percents, ordinal scales, etc.)  for risk and it&#8217;s subsequent factors.  Sure there are times when Q&amp;D qualitative approaches are acceptable, but policy should be to have quantitative analysis whenever and wherever possible.</p>
<p>That last item - the quantitative approach - is really quite important.  And the reasons why will be discussed further in tomorrow&#8217;s post:</p>
<p style="text-align: center;"><strong>&#8220;What should we be reflecting about? &amp; What is needed for reflection?&#8221;</strong></p>
<p><em>P.S.  Your comments and suggestions, as always, are welcome.</em></p>
<p><em>P.P.S  Those who may be familiar with Lean/SixSigma/Kaizen sorts of mashups may be thinking - &#8220;hey, an Analytical step is built into SixSigma&#8221;.  Well, yes there is some prevision for analytical functions based on statistics, but I find SixSigma geared towards creating a State of Knowledge about operational processes, not towards creating a State of Wisdom for CISO&#8217;s around security &amp; risks &#8220;big questions&#8221;.  In otherwords, the analytical function in DMAIC is in the context of Kaizen, and a different step than &#8220;reflective&#8221; analytics. </em></p>
]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 13:55:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/call risk management">call risk management</category>
      <category domain="http://securityratty.com/tag/call">call</category>
      <category domain="http://securityratty.com/tag/relentless reflection">relentless reflection</category>
      <category domain="http://securityratty.com/tag/relentless">relentless</category>
      <category domain="http://securityratty.com/tag/reflection">reflection</category>
      <category domain="http://securityratty.com/tag/risk analyst">risk analyst</category>
      <category domain="http://securityratty.com/tag/risk decision">risk decision</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=393">Relentless Reflection - What it Means in Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Run Through PCI DSS 1.2 Changes]]></title>
      <link>http://securityratty.com/article/ce0e02f57e234e1b64d186272da31186</link>
      <guid>http://securityratty.com/article/ce0e02f57e234e1b64d186272da31186</guid>
      <description><![CDATA[Finally, I found time to read PCI DSS 1.2. change doc. So
Good news: router is now officially a firewall (it has been for a while, but many people are still stuck in &quot;security device&quot; vs &quot;network...]]></description>
      <content:encoded><![CDATA[<p>Finally, I found time to read PCI DSS 1.2. change doc. So:</p>  <ul>   <li>Good news: router is now officially a firewall (it has been for a while, but many people are still stuck in &quot;security device&quot; vs &quot;network device&quot; cloud) - see Req 1 </li>    <li>From the &quot;WTH dept&quot;: anti-virus is a MUST on <strong>ALL</strong> platforms - Req 5. Please ship me some of the stuff they are smoking; I want it! BTW, I am <a href="http://www.govcert.nl/symposium/index.html">going to Amsterdam soon</a> :-) </li>    <li>WAF or code review for web application security is still a stupid &quot;OR&quot; - Req 6.6. OMG, please, <a href="http://www.tssci-security.com/archives/2008/06/27/week-of-war-on-wafs-day-5-final-thoughts/">software security folks</a>, teach them the truth.</li>    <li>Can we kill &quot;plain text passwords&quot; once and for all? Req 8 tries to achieve that noble goal (good thing!) </li>    <li>Visit your offsite data storage - good (if costly) idea - added to Req 9. Requirements to secure electronic AND&#160; paper media&#160; are solid too.</li>    <li>Love it, love it! Req 10 explains that logs needs to be actually available: 'three months of audit trail history must be &#8220;<strong>immediately available for analysis</strong>&#8221; or <strong>quickly accessible'</strong> (bye-bye, silly log dumps...)</li>    <li>Some vulnerability stuff clarified in Req 11, mostly about ASVs and pentesting.</li>    <li>Scope of security policy is expanded to &quot;employee-facing technologies&quot; (what a term!) - Req 12</li>    <li>All over: more references to wireless&#160; (WEP, access points, hidden SSIDs, etc) - indeed, recent data losses are often due to insecure wireless.</li> </ul>  <p>Overall, a minor change that, sadly, doesn't touch a few KEY areas, such as virtualization, for one.</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=oED2TK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=oED2TK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=pUb9XK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=pUb9XK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bX5cGK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bX5cGK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/375460383" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 07:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/req">req</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/offsite data storage">offsite data storage</category>
      <category domain="http://securityratty.com/tag/insecure wireless">insecure wireless</category>
      <category domain="http://securityratty.com/tag/audit trail history">audit trail history</category>
      <category domain="http://securityratty.com/tag/silly log dumps">silly log dumps</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/plain text passwords">plain text passwords</category>
      <category domain="http://securityratty.com/tag/vulnerability stuff">vulnerability stuff</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/375460383/run-through-pci-dss-12-changes.html">Run Through PCI DSS 1.2 Changes</source>
    </item>
    <item>
      <title><![CDATA[Straight Talking Warren Buffett]]></title>
      <link>http://securityratty.com/article/c3eda8d642477dccc307b946fd1f4926</link>
      <guid>http://securityratty.com/article/c3eda8d642477dccc307b946fd1f4926</guid>
      <description><![CDATA[For those who did not hear Warren Buffett being interviewed last Friday morning on CNBC, he did not beat about the bush when talking about the former Presidential hopeful, John Edwards

Mr. Buffett...]]></description>
      <content:encoded><![CDATA[For those who did not hear Warren Buffett being interviewed last Friday morning on CNBC, he did not beat about the bush when talking about the former Presidential hopeful, John Edwards. <br /><span id="fullpost"><br />Mr. Buffett came straight out and accused Mr. Edwards of soliciting and taking money by deceitful means during his unsuccessful Presidential bid earlier this year.  According to Mr. Buffett, John Edwards knew back then that it was only a matter of time before the media uncovered the story of his mistress and alleged love-child.  <br />  <br /></span><br />Unfortunately, this did not stop him from asking suporters to fund his campaign.  Had people knew about the extra-marital affair, they most likely would not have sent in their hard earned dollars as there was no chance that he could continue in the race once the damning news broke.  Mr. Buffett suggested that Edwards should cut back on a few of those expensive haircuts and return those fifty and one hundred dollar donations that came in from ordinary hard working followers.<br /><br />This sentiment rings true for my industry.  At our training courses, we focus on Ethics at the beginning of the course and it runs throughout the training.  Nobody is saying that we are not human and we do not make mistakes - we all do, but covering up the truth to further your own selfish goals is a practice that would probably even disgust the animal Kingdom - except the reptiles possibly.<br /><br />Thank you Mr. Buffett for being so frank and forthright in this era of sterile political correctness.  This is why I enjoy working with successful business people and despise the empty promises and double-talking of policticians, to whatever party they belong.  To those of you in the security world, again I implore you to never forget that your word is your bond and at the end of the day, your reputation will live on after you are long gone.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 08:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/buffett">buffett</category>
      <category domain="http://securityratty.com/tag/edwards">edwards</category>
      <category domain="http://securityratty.com/tag/john edwards">john edwards</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/successful business people">successful business people</category>
      <category domain="http://securityratty.com/tag/sterile political correctness">sterile political correctness</category>
      <category domain="http://securityratty.com/tag/hard">hard</category>
      <category domain="http://securityratty.com/tag/unsuccessful presidential bid">unsuccessful presidential bid</category>
      <category domain="http://securityratty.com/tag/ordinary hard">ordinary hard</category>
      <source url="http://www.thebulletproofblog.com/2008/08/straight-talking-warren-buffett.html">Straight Talking Warren Buffett</source>
    </item>
    <item>
      <title><![CDATA[A Complex Event = Sum (Events) + Situational Knowledge]]></title>
      <link>http://securityratty.com/article/6c2bb3d926962cbe55f37d5757e6c129</link>
      <guid>http://securityratty.com/article/6c2bb3d926962cbe55f37d5757e6c129</guid>
      <description><![CDATA[Sometimes we read some opinions about CEP where folksopine thatcomplex event processing is really about processing complex events and not about complex event processing. The truth be told, processing...]]></description>
      <content:encoded><![CDATA[<p>Sometimes we read some opinions about CEP where folks opine that &#8221;complex event processing&#8221; is really about processing &#8220;complex events&#8221; and not about &#8220;complex&#8221; &#8220;event processing&#8221;.   The truth be told, processing &#8220;complex events&#8221; requires &#8220;complex&#8221; &#8220;event processing&#8221; so there is really no difference between the two ways of expressing CEP.</p>
<p>You can not process complex events in some very simple way and expect to get accurate results.  You need knowledge, represented by one or more situational models, to process complex events.</p>
<p>Some folks, like to say that a &#8220;complex event&#8221; is simply an event which is an aggregation of two more more event objects.    If you follow this (flawed) logic, then counting integers is complex event processing; because 1 plus 1 is 2, and 2 is an aggregation of 1 and 1, so 2 is a complex event (not!).  </p>
<p>Since we know that counting is not a complex processing operation, then some folks would say that you can process complex events with very simple operations because you are processing complex events , in the case adding 1 to the previous number (counting), enriching an event object.</p>
<p>This is simply nonsense.</p>
<p>The logic flaw is that the basic definition of a &#8220;complex event&#8221; (used by many people) is wrong.   A complex event is not simply an event object with two more more events as sub-components. </p>
<p>A complex event is when two event objects are combined (processed) to form a complex object with a higher degree of inference, or situational knowledge.   One plus one equals more than two in complex event processing, because the combination of event objects requires knowledge (e.g. a situational model).</p>
<blockquote><p>A Complex Event = Sum (EventsObjects) + Situational Knowledge</p></blockquote>
<p>Let there be no mistake about it.    Complex event processing is the complex processing of complex events.   You cannot accurately process complex events with simple event processing models.</p>
<p>The simple processing of complex events is not CEP, it is simple event processing (event track-and-trace, simple event object enrichment, simple event object aggregation, and so forth).<br />
 </p>
]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 05:11:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/complex events">complex events</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/process complex events">process complex events</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/event object">event object</category>
      <category domain="http://securityratty.com/tag/folksopine thatcomplex event">folksopine thatcomplex event</category>
      <category domain="http://securityratty.com/tag/event objects">event objects</category>
      <source url="http://www.thecepblog.com/2008/08/16/a-complex-event-sum-events-knowledge/">A Complex Event = Sum (Events) + Situational Knowledge</source>
    </item>
    <item>
      <title><![CDATA[Guerilla Marketing for a Conspiracy Site]]></title>
      <link>http://securityratty.com/article/2b117e772809f4fc08e74e3a0ec176ee</link>
      <guid>http://securityratty.com/article/2b117e772809f4fc08e74e3a0ec176ee</guid>
      <description><![CDATA[An image is worth a thousand words they say, especially when it's creative enough to count as a decent guerrilla marketing campaign for Alex Jones' infowars.com

Alex Jones is considered by many to be...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKR8gmsdi5I/AAAAAAAACCk/7pb6K-ZlId8/s1600-h/infowars_echelon_guerilla_marketing.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKR8gmsdi5I/AAAAAAAACCk/PY2_yw9n2-8/s200-R/infowars_echelon_guerilla_marketing.jpg" style="border: 0pt none ;" /></a>An image is worth a thousand words they say, especially when it's creative enough to count as a decent guerrilla marketing campaign for <a href="http://infowars.com/alexjones.html">Alex Jones' infowars.com</a> :<br />
<br />
"<i>Alex Jones is considered by many to be the grandfather of what has come to be known as the 9/11 Truth Movement. <b>Jones predicted the 9/11 attack in a July 2001 television taping when he warned that the Globalists were going to attack New York and blame it on their asset Osama bin Laden.</b> Since 9/11 Jones has broken many of the stories which later became the foundation of the evidence that the government was involved.</i>"<br />
<br />
Sorry to disappoint, but as always, <a href="http://killtown.911review.org/lonegunmen.html">The Lone Gunmen were first to predict 9/11 in their "Pilot" episode</a>, originally aired on 03/04/2001, obviously <a href="http://www.youtube.com/watch?v=rIZ205ccX8M">several months before Alex Jones did</a>. How did they do it? By having a firm grasp of the obvious I guess.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hvjPGK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hvjPGK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TBCXkK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TBCXkK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rLOaMk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rLOaMk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6k2N4k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6k2N4k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ld6AqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ld6AqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TNX2FK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TNX2FK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=E43dXk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=E43dXk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/365022639" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 09:58:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/alex jones">alex jones</category>
      <category domain="http://securityratty.com/tag/jones">jones</category>
      <category domain="http://securityratty.com/tag/asset osama bin">asset osama bin</category>
      <category domain="http://securityratty.com/tag/decent guerrilla">decent guerrilla</category>
      <category domain="http://securityratty.com/tag/truth movement">truth movement</category>
      <category domain="http://securityratty.com/tag/firm grasp">firm grasp</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/thousand words">thousand words</category>
      <category domain="http://securityratty.com/tag/predict">predict</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/365022639/guerilla-marketing-for-conspiracy-site.html">Guerilla Marketing for a Conspiracy Site</source>
    </item>
    <item>
      <title><![CDATA[Richard Veryard on Uncertainty]]></title>
      <link>http://securityratty.com/article/4e12f6a6e0e52148942e0e8935546c7e</link>
      <guid>http://securityratty.com/article/4e12f6a6e0e52148942e0e8935546c7e</guid>
      <description><![CDATA[I enjoy reading Richard Veryards blog posts. Richard does not have an agenda, per se , or at least not one I have identified. Richard is not trying to sell us anything; he seeks facts and truth with...]]></description>
      <content:encoded><![CDATA[<p>I enjoy reading Richard Veryard&#8217;s blog posts.  Richard does not have an agenda, <em>per se</em>, or at least not one I have identified.  Richard is not trying to sell us anything; he seeks facts and truth with an open, Zen mind. </p>
<p>In his second post <a href="http://rvsoapbox.blogspot.com/2008/08/faithful-representation-2.html">Faithful Representation 2</a> and continuation, <a href="http://rvsoapbox.blogspot.com/2008/08/responding-to-uncertainty.html">Responding to Uncertainty</a>, Richard explores models, reality and uncertainty.</p>
<p>I don&#8217;t have time to comment as much as I would like today.  However, I would like to conclude that in the process of raw-event to decision-making, there one of the most important factors is the ability to assign likelihood (or certainty) to any detected situation.</p>
]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 04:31:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/richard">richard</category>
      <category domain="http://securityratty.com/tag/richard explores models">richard explores models</category>
      <category domain="http://securityratty.com/tag/uncertainty">uncertainty</category>
      <category domain="http://securityratty.com/tag/post faithful representation">post faithful representation</category>
      <category domain="http://securityratty.com/tag/assign likelihood">assign likelihood</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/seeks">seeks</category>
      <category domain="http://securityratty.com/tag/factors">factors</category>
      <category domain="http://securityratty.com/tag/ability">ability</category>
      <source url="http://www.thecepblog.com/2008/08/13/richard-veryard-on-uncertainty/">Richard Veryard on Uncertainty</source>
    </item>
  </channel>
</rss>
