<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: vote]]></title>
    <link>http://securityratty.com/tag/vote</link>
    <description></description>
    <pubDate>Sat, 19 Jul 2008 15:57:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Cast your vote for the best Firewall]]></title>
      <link>http://securityratty.com/article/75712822df5cf85ff807f85a75acecfe</link>
      <guid>http://securityratty.com/article/75712822df5cf85ff807f85a75acecfe</guid>
      <description><![CDATA[over at LifeHacker theres some great info on which is the best Firewall. You can also vote for your fav


clipped from lifehacker.com

Five Best Windows Firewalls

Earlier this week we asked you to...]]></description>
      <content:encoded><![CDATA[<div > over at LifeHacker theres some great info on which is the best Firewall.<br/>You can also vote for your fav. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/4F8B1CBE-0DB5-48D3-AC79-C2CD0CD01F7E/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/5fca4620-d478-4f73-a7c0-2d31f3f034c4/4F8B1CBE-0DB5-48D3-AC79-C2CD0CD01F7E/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://lifehacker.com/5061933/five-best-windows-firewalls" href="http://lifehacker.com/5061933/five-best-windows-firewalls" style="font-size: 11px;">lifehacker.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://lifehacker.com/5061933/five-best-windows-firewalls -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;"><A class="top" href="http://lifehacker.com/5061933/five-best-windows-firewalls">Five Best Windows Firewalls</A></div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://lifehacker.com/5061933/five-best-windows-firewalls -->Earlier this week we asked you to <A href="http://lifehacker.com/5061244/best-windows-firewall">share your favorite Windows firewall</A>, and today we&#8217;re back with the five most popular answers. Keep reading for a closer look at the five best Windows firewalls, then cast your vote for your favorite.</td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/4F8B1CBE-0DB5-48D3-AC79-C2CD0CD01F7E/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_121008113442"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=121008113442&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=121008113442&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=121008113442&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_121008113442" /></a></P>]]></content:encoded>
      <pubDate>Sun, 12 Oct 2008 19:34:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <category domain="http://securityratty.com/tag/favorite windows firewall">favorite windows firewall</category>
      <category domain="http://securityratty.com/tag/favorite">favorite</category>
      <category domain="http://securityratty.com/tag/windows firewalls">windows firewalls</category>
      <category domain="http://securityratty.com/tag/vote">vote</category>
      <category domain="http://securityratty.com/tag/cast">cast</category>
      <category domain="http://securityratty.com/tag/lifehacker">lifehacker</category>
      <category domain="http://securityratty.com/tag/popular answers">popular answers</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=642">Cast your vote for the best Firewall</source>
    </item>
    <item>
      <title><![CDATA[European Parliament to postpone IP privacy issue]]></title>
      <link>http://securityratty.com/article/ae5b269f4f1f3a01a73fe7401bf93daf</link>
      <guid>http://securityratty.com/article/ae5b269f4f1f3a01a73fe7401bf93daf</guid>
      <description><![CDATA[European parliamentarians, set to vote on changes to the European telecommunications legal landscape this week, will put off at least one crucial question: Should IP addresses be considered private...]]></description>
      <content:encoded><![CDATA[European parliamentarians, set to vote on changes to the European telecommunications legal landscape this week, will put off at least one crucial question: Should IP addresses be considered private data?<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=96644?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=96644?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/european">european</category>
      <category domain="http://securityratty.com/tag/crucial question">crucial question</category>
      <category domain="http://securityratty.com/tag/legal landscape">legal landscape</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/vote">vote</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/addresses">addresses</category>
      <category domain="http://securityratty.com/tag/set">set</category>
      <source url="http://www.networkworld.com/news/2008/092208-european-parliament-to-postpone-ip.html?fsrc=rss-security">European Parliament to postpone IP privacy issue</source>
    </item>
    <item>
      <title><![CDATA[Identity Farming]]></title>
      <link>http://securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</link>
      <guid>http://securityratty.com/article/b473cbd43ff87938f8034236b68d25c8</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up. </p>

<p>Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities. </p>

<p>Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them. </p>

<p>There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop. </p>

<p>You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work. </p>

<p>Here's the real question: Do you actually have to show up for any part of your life? </p>

<p>Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China. </p>

<p>Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. Iâm told this is a common idea in Highlander fan fiction. </p>

<p>The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.schneier.com/essay-219.html">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.) </p>

<p>It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary. </p>

<p>Our data shadows can live a perfectly normal life without us.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/09/securitymatters_0904">previously appeared<a> on Wired.com.</p>

<p>EDITED TO ADD (9/9): Interesting <a href="http://www.examiner.com/x-536-Civil-Liberties-Examiner~y2008m9d4-Im-not-myself-today-or-manufacturing-a-new-you">commentary</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YzkGL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YzkGL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JDMVL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JDMVL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 01:42:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://securityratty.com/tag/shadows">shadows</category>
      <category domain="http://securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://securityratty.com/tag/photo ids glue">photo ids glue</category>
      <category domain="http://securityratty.com/tag/photo ids">photo ids</category>
      <category domain="http://securityratty.com/tag/identity databases">identity databases</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/identity_farmin.html">Identity Farming</source>
    </item>
    <item>
      <title><![CDATA[Your Companies Biggest Security Hole - What is the BGP-style Vuln Lurking in Software Security?]]></title>
      <link>http://securityratty.com/article/95b08326dc660fff6cb1103621e8f2f3</link>
      <guid>http://securityratty.com/article/95b08326dc660fff6cb1103621e8f2f3</guid>
      <description><![CDATA[My vote is MQ Series and other enterprise messaging systems. Schneier's succinct summary of BGP

It's a man-in-the-middle attack. &quot;The Internet's Biggest Security Hole&quot; has been that interior relays...]]></description>
      <content:encoded><![CDATA[<p>My vote is MQ Series and other enterprise messaging systems. Schneier&#39;s succinct <a href="http://www.schneier.com/blog/archives/2008/08/border_gateway.html">summary</a> of BGP:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-size: 12px; line-height: normal; ">It&#39;s a man-in-the-middle attack. &quot;The Internet&#39;s Biggest Security Hole&quot; &#160;has been that interior relays have always been trusted even though they are not trustworthy.</span></p></blockquote><p><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br />That could apply word for word to how MQ Series and other enterprise messaging systems are deployed. Let&#39;s say you are a bank and have been happily running your business on a mainframe for decades. Life is good, come in at 9 leave at 5, count the cash. Then some dotcommer comes along and tells you that you need to get online. What are you gonna do? Rewrite your whole system from scratch? Hard to make that case.</span></p><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Nope what you&#39;ll do is build out a web farm to talk to the consumer, but then you will realize all of your business runs on the mainframe, and you need to connect to it. How exactly? Enter MQ Series and friends, they broker the communications to legacy backends for most major corporations, but there is one slight problem - they didn&#39;t even bother to support useful security protocols until very recently, and most of the time the security protocols are not even implemented.</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">Typical anti-patterns include:</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* no authentication, no authorization (just open up a queue) - run your whole book of business transaction backbone on anonymous ftp</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">* authorization with no authentication (mq enforces authorization policy on unverifiable tokens) -&#160;run your whole book of business transaction backbone on anonymous ftp, but think that you have security</span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; font-size: 12px; line-height: normal;">What is strange about the MQ Series, enterprise messaging vulns is that there is no need for them, there are no technical excuses to not add better tokens, message security, and encryption. People don&#39;t do it, because of poor tool support,</span><span style="font-family: Verdana; font-size: 12px; line-height: normal;">&#160;a </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html">mainframe mindset</a><span style="font-family: Verdana; font-size: 12px; line-height: normal;">, silo projects, and a whole variety of reasons. But just because you choose to ignore a fact doesn&#39;t mean its not true. On the plus side, some of the open source ESBs are </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/04/cxf-axis2-and-e.html">adding support for message security</a><span style="font-family: Verdana; font-size: 12px; line-height: normal;">, so you can improve security and save your company money at the same time, what&#39;s not to like?</span></div>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 04:31:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/security protocols">security protocols</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/business runs">business runs</category>
      <category domain="http://securityratty.com/tag/business transaction backbone">business transaction backbone</category>
      <category domain="http://securityratty.com/tag/improve security">improve security</category>
      <category domain="http://securityratty.com/tag/message security">message security</category>
      <category domain="http://securityratty.com/tag/enforces authorization policy">enforces authorization policy</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/your-companies-biggest-security-hole---what-is-the-bgp-style-vuln-lurking-in-software-security.html">Your Companies Biggest Security Hole - What is the BGP-style Vuln Lurking in Software Security?</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: How to Create the Perfect Fake Identity]]></title>
      <link>http://securityratty.com/article/978beddfbfcfa8c96d83a85e27f028f6</link>
      <guid>http://securityratty.com/article/978beddfbfcfa8c96d83a85e27f028f6</guid>
      <description><![CDATA[Let me start off by saying that I'm making this whole thing up
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity...]]></description>
      <content:encoded><![CDATA[<p>Let me start off by saying that I'm making this whole thing up.
</p>

<p>
Imagine you're in charge of infiltrating sleeper agents into the United States. The year is 1983, and the proliferation of identity databases is making it increasingly difficult to create fake credentials. Ten years ago, someone could have just shown up in the country and gotten a driver's license, Social Security card and bank account -- possibly using the identity of someone roughly the same age who died as a young child -- but it's getting harder. And you know that trend will only continue. So you decide to grow your own identities.
</p>

<p>
Call it "identity farming." You invent a handful of infants. You apply for Social Security numbers for them. Eventually, you open bank accounts for them, file tax returns for them, register them to vote, and apply for credit cards in their name. And now, 25 years later, you have a handful of identities ready and waiting for some real people to step into them.
</p>

<p>
There are some complications, of course. Maybe you need people to sign their name as parents -- or, at least, mothers. Maybe you need to doctors to fill out birth certificates. Maybe you need to fill out paperwork certifying that you're home-schooling these children. You'll certainly want to exercise their financial identity: depositing money into their bank accounts and withdrawing it from ATMs, using their credit cards and paying the bills, and so on. And you'll need to establish some sort of addresses for them, even if it is just a mail drop.
</p>

<p>
You won't be able to get driver's licenses or photo IDs on their name. That isn't critical, though; in the U.S., more than 20 million adult citizens don't have photo IDs. But other than that, I can't think of any reason why identity farming wouldn't work.  
</p>

<p>
Here's the real question: Do you actually have to show up for any part of your life?
</p>

<p>
Again, I made this all up. I have no evidence that anyone is actually doing this. It's not something a criminal organization is likely to do; twenty-five years is too distant a payoff horizon. The same logic holds true for terrorist organizations; it's not worth it. It might have been worth it to the KGB -- although perhaps harder to justify after the Soviet Union broke up in 1991 -- and might be an attractive option to existing intelligence adversaries like China.
</p>

<p>
Immortals could also use this trick to self-perpetuate themselves, inventing their own children and gradually assuming their identity, then killing their parents off. They could even show up for their own driver's license photos, wearing a beard as the father and blue spiked hair as the son. I’m told this is a common idea in <a href="http://www.highlander.org/"><cite>Highlander</cite></a> fan fiction.
</p>

<p>
The point isn't to create another movie plot threat, but to point out the central role that data has taken on in our lives. Previously, I've said that we all have a <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/05/securitymatters_0515">data shadow</a> that follows us around, and that more and more institutions interact with our data shadows instead of with us. We only intersect with our data shadows once in a while -- when we apply for a driver's license or passport, for example -- and those interactions are authenticated by older, less-secure interactions. The rest of the world assumes that our photo IDs glue us to our data shadows, ignoring the rather flimsy connection between us and our plastic cards. (And, no, REAL-ID won't help.)
</p>

<p>
It seems to me that our data shadows are becoming increasingly distinct from us, almost with a life of their own. What's important now is our shadows; we're secondary. And as our society relies more and more on these shadows, we might even become unnecessary.
</p>

<p>
Our data shadows can live a perfectly normal life without us.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is Chief Security Technology Officer of BT, and author of </cite>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<cite>.</cite>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=8c450d9a9d0030ff631259b1803cae6a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=8c450d9a9d0030ff631259b1803cae6a" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=snUd9L"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=snUd9L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=uzqRkl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=uzqRkl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=zVASIl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=zVASIl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=itvpML"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=itvpML" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=XRzLgL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=XRzLgL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=hSbcKl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=hSbcKl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Rk785l"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Rk785l" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=qjRx3L"><img src="http://feeds.wired.com/~f/wired/politics/security?i=qjRx3L" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/382935195" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/382935196" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data shadow">data shadow</category>
      <category domain="http://securityratty.com/tag/data shadows">data shadows</category>
      <category domain="http://securityratty.com/tag/shadows">shadows</category>
      <category domain="http://securityratty.com/tag/social security card">social security card</category>
      <category domain="http://securityratty.com/tag/financial identity">financial identity</category>
      <category domain="http://securityratty.com/tag/photo ids glue">photo ids glue</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/382935196/securitymatters_0904">Security Matters: How to Create the Perfect Fake Identity</source>
    </item>
    <item>
      <title><![CDATA['It's the data, stupid' so you'd better vote to protect it]]></title>
      <link>http://securityratty.com/article/62e082067c5c5376639f83faba7227c3</link>
      <guid>http://securityratty.com/article/62e082067c5c5376639f83faba7227c3</guid>
      <description><![CDATA[It's the data, stupid.&quot; OK, the phrase is not quite catchy enough to become a must-have bumper sticker, but it's a mantra for every organization with sensitive information. Today's article looks at...]]></description>
      <content:encoded><![CDATA["It's the data, stupid."  OK, the phrase is not quite catchy enough to become a must-have bumper sticker, but it's a mantra for every organization with sensitive information.  Today's article looks at two enterprise security platforms designed to protect corporate data.  Guardium focuses on securing the data and actions involving databases, and Symantec's Vontu platform provides data loss prevention on the network, at the endpoint, and in storage devices.]]></content:encoded>
      <pubDate>Sun, 31 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data loss prevention">data loss prevention</category>
      <category domain="http://securityratty.com/tag/enterprise security platforms">enterprise security platforms</category>
      <category domain="http://securityratty.com/tag/must-have bumper sticker">must-have bumper sticker</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/vontu platform">vontu platform</category>
      <category domain="http://securityratty.com/tag/stupid">stupid</category>
      <category domain="http://securityratty.com/tag/guardium focuses">guardium focuses</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <source url="http://www.networkworld.com/newsletters/techexec/2008/090108techexec1.html?fsrc=rss-security">'It's the data, stupid' so you'd better vote to protect it</source>
    </item>
    <item>
      <title><![CDATA[Poll #9 How Much Log Security Do You Need?]]></title>
      <link>http://securityratty.com/article/04365a7bde7f3a2fb14a3addc9540d52</link>
      <guid>http://securityratty.com/article/04365a7bde7f3a2fb14a3addc9540d52</guid>
      <description><![CDATA[Yes! YES! Y-E-S

My next logging poll is out - with it I set out to figure out the old mystery of mine, why people don't protect their log data (e.g. see this lamentation &quot; Top 11 Reasons to Secure...]]></description>
      <content:encoded><![CDATA[Yes! YES! Y-E-S! :-)<br /><br />My next logging poll is <a href="http://www.misterpoll.com/polls/351660">out </a>- with it I set out to figure out the old mystery of mine, why people don't protect their log data (e.g. see this lamentation "<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>")<br /><br /><a href="http://www.misterpoll.com/polls/351660">Vote away!</a>  As always, results will be posted.<br /><br />Past polls and analysis are all <a href="http://chuvakin.blogspot.com/search/label/poll">here</a>. <a href="http://chuvakin.blogspot.com/search/label/poll">Enjoy</a>!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=YIHHUK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=YIHHUK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=92dmRK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=92dmRK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wDFK6K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wDFK6K" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/356798798" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:59:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <category domain="http://securityratty.com/tag/poll">poll</category>
      <category domain="http://securityratty.com/tag/log data">log data</category>
      <category domain="http://securityratty.com/tag/past polls">past polls</category>
      <category domain="http://securityratty.com/tag/figure">figure</category>
      <category domain="http://securityratty.com/tag/y-e-s">y-e-s</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/mystery">mystery</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/356798798/poll-9-how-much-log-security-do-you.html">Poll #9 How Much Log Security Do You Need?</source>
    </item>
    <item>
      <title><![CDATA[McAfee's Hacker Safe nominated for a Pwnie]]></title>
      <link>http://securityratty.com/article/19cd58f1b0361803b4a478f04fdc8485</link>
      <guid>http://securityratty.com/article/19cd58f1b0361803b4a478f04fdc8485</guid>
      <description><![CDATA[Mondays don't usually include such glorious highlights but I'll gladly pass on this exception. The Pwnie Awards 2008 nominations are out, and under Lamest Vendor Response we find McAfee's Hacker Safe,...]]></description>
      <content:encoded><![CDATA[Mondays don't usually include such glorious highlights but I'll gladly pass on this exception. The <a href="http://pwnie-awards.org/2008/index.html" target="_blank">Pwnie Awards 2008</a> nominations are out, and under <a href="http://pwnie-awards.org/2008/awards.html#lamestvendor" target="_blank">Lamest Vendor Response</a> we find McAfee's Hacker Safe, specifically Joesph Pierini's response to the findings <a href="http://www.xssed.com/news/55/ScanAlerts_Hacker_Safe_badge_not_so_safe_and_PCI_compliant/" target="_blank">XSSed.com</a> and I gave to Thomas Claburn for publication in <a href="http://www.informationweek.com/news/security/cybercrime/showArticle.jhtml;jsessionid=JN2ZP21JSGB4WQSNDLOSKH0CJUNN2JVN?articleID=205900444&_requestid=339479" target="_blank">Information Week</a> this past January. <br />Joseph Pierini, director of enterprise services for the "Hacker Safe" program, stepped in it when he said that XSS vulnerabilities can't be used to hack a server:<br /><span style="font-style:italic;">Cross-site scripting can't be used to hack a server. You may be able to do other things with it. You may be able to do things that affect the end-user or the client. But the customer data protected with the server, in the database, isn't going to be compromised by a cross-site scripting attack, not directly.</span><br />As you can imagine, this one gets my vote.<br />Winners will be announced at the BlackHat USA reception at Caesar's Palace, Las Vegas on Wednesday, August 6th, 2008.<br />Should you wish further reading on the McAfee Secure / Hacker Safe fiasco, you need only utilize this <a href="http://www.google.com/search?hl=en&q=site%3Aholisticinfosec.blogspot.com+%22mcafee%22+%22hacker+safe%22&btnG=Google+Search" target="_blank">query</a> or refer to all of Nate's <a href="http://www.google.com/search?hl=en&q=site%3Ablogs.zdnet.com%2Fsecurity+%22mcafee%22+%22hacker+safe%22&btnG=Google+Search" target="_blank">coverage</a> on <a href="http://blogs.zdnet.com/security/" target="_blank">Zero Day</a>. <br />I must admit, I'm curious who McAfee will have at Black Hat to receive this prestigious award should they win. I'm torn between suggesting <a href="http://www.0x000000.com/?i=574" target="_blank">Brett Oliphant</a> or Pierini himself. ;-)<br />Cheers.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/07/mcafees-hacker-safe-nominated-for-pwnie.html&title=McAfee's%20Hacker%20Safe%20nominated%20for%20a%20Pwnie " title="McAfee's Hacker Safe nominated for a Pwnie ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/07/mcafees-hacker-safe-nominated-for-pwnie.html" title="McAfee's Hacker Safe nominated for a Pwnie ">digg</a>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 07:05:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hacker safe">hacker safe</category>
      <category domain="http://securityratty.com/tag/mcafee">mcafee</category>
      <category domain="http://securityratty.com/tag/hacker safe fiasco">hacker safe fiasco</category>
      <category domain="http://securityratty.com/tag/pierini">pierini</category>
      <category domain="http://securityratty.com/tag/joseph pierini">joseph pierini</category>
      <category domain="http://securityratty.com/tag/mcafee secure">mcafee secure</category>
      <category domain="http://securityratty.com/tag/vendor response">vendor response</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/joesph pierini">joesph pierini</category>
      <source url="http://holisticinfosec.blogspot.com/2008/07/mcafees-hacker-safe-nominated-for-pwnie.html">McAfee's Hacker Safe nominated for a Pwnie</source>
    </item>
    <item>
      <title><![CDATA[On Measuring a Markets Maturity]]></title>
      <link>http://securityratty.com/article/fab7f9ba9252b7312f5d80cd5260d882</link>
      <guid>http://securityratty.com/article/fab7f9ba9252b7312f5d80cd5260d882</guid>
      <description><![CDATA[Professor David Luckham posts a good question in Measuring a Markets Maturity . Here is a slightlyrevised reprint of our reply
A few folks have tried to tie maturity to if the code is robust or if the...]]></description>
      <content:encoded><![CDATA[<p>Professor David Luckham posts a good question in <a href="http://forum.complexevents.com/viewtopic.php?f=13&#038;p=407#p407" target="_blank">Measuring a Market&#8217;s Maturity</a>.  Here is a slightly revised reprint of our reply:</p>
<p>A few folks have tried to tie &#8220;maturity&#8221; to &#8220;if the code is robust&#8221; or &#8220;if the product has certain product features.&#8221; The way we have addressed this emerging controversy over at <a href="http://www.thecepblog.com" target="_blank">The CEP blog</a> is to center the discussion around the <a href="http://en.wikipedia.org/wiki/Hype_cycle" target="_blank">Gartner Hype Cycle</a>, which is a pretty good model for representing the maturity, adoption and business application of specific technologies.</p>
<p><a href=" http://www.thecepblog.com/2008/06/01/on-cep-maturity-and-the-gartner-hype-cycle/" target="_blank">On CEP Maturity and the Gartner Hype Cycle</a></p>
<p>Since many folks work very closely with <a href="http://www.gartner.com" target="_blank">Gartner</a>, I expect they are keenly aware of Gartner&#8217;s view on technology adoption maturity models and their definitions. Just for our readers who might not be as familar, I quote Gartner&#8217;s definitions below to be complete from <a href="http://en.wikipedia.org/wiki/Hype_cycle" target="_blank">here</a>:</p>
<blockquote><p>A hype cycle is a graphic representation of the maturity, adoption and business application of specific technologies. The term was coined by Gartner[citation needed], an analyst/research house, based in the United States, that provides opinions, advice and data on the global information technology industry.</p>
<p>Since 1995, Gartner has used hype cycles to characterize the over-enthusiasm or &#8220;hype&#8221; and subsequent disappointment that typically happens with the introduction of new technologies. Hype cycles also show how and when technologies move beyond the hype, offer practical benefits and become widely accepted. According to Gartner, hype cycles aim to separate the hype from the reality, and enable CIOs and CEOs to decide whether or not a particular technology is ready for adoption. A longer-term historical perspective on such cycles can be found in the research of the economist Carlota Perez.</p>
<p>A hype cycle in Gartner&#8217;s interpretation comprises 5 steps:</p>
<p>&#8220;Technology Trigger&#8221; — The first phase of a hype cycle is the &#8220;technology trigger&#8221; or breakthrough, product launch or other event that generates significant press and interest.</p>
<p>&#8220;Peak of Inflated Expectations&#8221; — In the next phase, a frenzy of publicity typically generates over-enthusiasm and unrealistic expectations. There may be some successful applications of a technology, but there are typically more failures.</p>
<p>&#8220;Trough of Disillusionment&#8221; — Technologies enter the &#8220;trough of disillusionment&#8221; because they fail to meet expectations and quickly become unfashionable. Consequently, the press usually abandons the topic and the technology.</p>
<p>&#8220;Slope of Enlightenment&#8221; — Although the press may have stopped covering the technology, some businesses continue through the &#8220;slope of enlightenment&#8221; and experiment to understand the benefits and practical application of the technology.</p>
<p>&#8220;Plateau of Productivity&#8221; — A technology reaches the &#8220;plateau of productivity&#8221; as the benefits of it become widely demonstrated and accepted. The technology becomes increasingly stable and evolves in second and third generations. The final height of the plateau varies according to whether the technology is broadly applicable or benefits only a niche market.</p>
<p>The term is now used more broadly in the marketing of new technologies.</p>
</blockquote>
<p>We used the <a href="http://en.wikipedia.org/wiki/Hype_cycle" target="_blank">Gartner Hype Cycle</a> in <a href="http://www.thecepblog.com/2008/07/12/two-thirds-of-our-readers-say-cep-is-still-immature/" target="_blank">Two-Thirds of Our Readers Say CEP is Still Immature</a> as a basis for having interested readers vote, and in a unscientific straw poll, the readers indicated that, in their view, CEP is still immature.</p>
<p>At the CEP Blog we ground our discussions and terminology on maturity in Gartner&#8217;s models on maturity, and we ground our discussions on event processing in the art-and-science of a long standing domain in event processing - multisensor data fusion (MSDF).</p>
]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 08:10:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hype cycles aim">hype cycles aim</category>
      <category domain="http://securityratty.com/tag/hype cycles">hype cycles</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/gartner hype cycle">gartner hype cycle</category>
      <category domain="http://securityratty.com/tag/hype cycle">hype cycle</category>
      <category domain="http://securityratty.com/tag/maturity">maturity</category>
      <category domain="http://securityratty.com/tag/markets maturity">markets maturity</category>
      <category domain="http://securityratty.com/tag/cep blogwe ground">cep blogwe ground</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <source url="http://www.thecepblog.com/2008/07/20/on-measuring-a-markets-maturity/">On Measuring a Markets Maturity</source>
    </item>
    <item>
      <title><![CDATA[Follow the Yellow Brick Road]]></title>
      <link>http://securityratty.com/article/887593779bb99c69b570648c6cdcc8d6</link>
      <guid>http://securityratty.com/article/887593779bb99c69b570648c6cdcc8d6</guid>
      <description><![CDATA[Marc Adlerfollows on from Muddy Waters to The First Annual Fluffies for CEP where Marc also calls into question the transparency, credibility and accuracy of the various fluffy awards we see from...]]></description>
      <content:encoded><![CDATA[<p>Marc Adler follows on from <a title="Muddy Waters" rel="bookmark" href="http://www.thecepblog.com/2008/07/16/muddy-waters/"><span style="color: #105cb6;">Muddy Waters</span></a> to <a href="http://magmasystems.blogspot.com/2008/07/first-annual-fluffies-for-cep.html" target="_blank">The First Annual Fluffies for CEP</a> where Marc also calls into question the transparency, credibility and accuracy of the various fluffy &#8220;awards&#8221; we see from time-to-time.</p>
<p>When I discussed this openly with Waters in <a title="Muddy Waters" rel="bookmark" href="http://www.thecepblog.com/2008/07/16/muddy-waters/"><span style="color: #105cb6;">Muddy Waters</span></a> comments they kindly replied that &#8220;customers are loath to be a reference client for a vendor,&#8221;  like this fact somehow justifies having 600 people, most who have never actually used the software in practice, vote on how great it is.  </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>Or, as Mark Adler pointed out in his well written blog post <a href="http://magmasystems.blogspot.com/2008/07/first-annual-fluffies-for-cep.html" target="_blank">The First Annual Fluffies for CEP</a> , a secretive &#8220;panel of renowned judge&#8221; is going to tell us, via Jolt, who has the better solution?  Holy Cow Batman!   Let me buy a nice layout in your magazine  or web site,  please, so &#8220;my software company&#8221; will be on the short list for the &#8220;the awards&#8221;.  </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>All this smoke-and-mirrors. share-the-love, marketing reminds me of The Matrix a bit, where the world as we observe it, is a complete artificial construction, where most people in the Matrix believe they are &#8220;real&#8221; because they do not know that they really just a computer generated program designed to keep humans happy as they sleep in some cold goop with electrodes stuck up their you-know-what, really just bio-batteries insuring the light bill is paid.</p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>Or better yet, these fluffies are similar to most of the Webinars we see where there are questions from &#8220;the audience&#8221; but we know that most of these questions did not come from the &#8220;audience&#8221; - yet we all seem to continue &#8221;the  audience&#8221; myth just like Santa Claus and the Easter Bunny! </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>The Easter Bunny, Santa Claus, the Tooth Fairy and the Fluffy Awards are real, if you want them to be real.  Just close your eyes and click your heels three times&#8230;.</p>
<blockquote><p>Follow the Yellow Brick Road. Follow the Yellow Brick Road.<br />
Follow, follow, follow, follow,<br />
Follow the Yellow Brick Road.<br />
Follow the Yellow Brick, Follow the Yellow Brick,<br />
Follow the Yellow Brick Road.</p></blockquote>
<blockquote><p>We&#8217;re off to see the Wizard, The Wonderful Wizard of Oz.<br />
You&#8217;ll find he is a whiz of a Wiz! If ever a Wiz! there was.<br />
If ever oh ever a Wiz! there was The Wizard of Oz is one because,<br />
Because, because, because, because, because.<br />
Because of the wonderful things he does.<br />
We&#8217;re off to see the Wizard. The Wonderful Wizard of Oz</p></blockquote>
]]></content:encoded>
      <pubDate>Sat, 19 Jul 2008 15:57:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/yellow brick">yellow brick</category>
      <category domain="http://securityratty.com/tag/yellow brick road">yellow brick road</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <category domain="http://securityratty.com/tag/wonderful wizard">wonderful wizard</category>
      <category domain="http://securityratty.com/tag/wizard">wizard</category>
      <category domain="http://securityratty.com/tag/awards">awards</category>
      <category domain="http://securityratty.com/tag/fluffy awards">fluffy awards</category>
      <category domain="http://securityratty.com/tag/wonderful">wonderful</category>
      <category domain="http://securityratty.com/tag/audience">audience</category>
      <source url="http://www.thecepblog.com/2008/07/19/follow-the-yellow-brick-road/">Follow the Yellow Brick Road</source>
    </item>
  </channel>
</rss>
