<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: world]]></title>
    <link>http://securityratty.com/tag/world</link>
    <description></description>
    <pubDate>Wed, 16 Jul 2008 11:00:49 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Follow the Yellow Brick Road]]></title>
      <link>http://securityratty.com/article/887593779bb99c69b570648c6cdcc8d6</link>
      <guid>http://securityratty.com/article/887593779bb99c69b570648c6cdcc8d6</guid>
      <description><![CDATA[Marc Adlerfollows on from Muddy Waters to The First Annual Fluffies for CEP where Marc also calls into question the transparency, credibility and accuracy of the various fluffy awards we see from...]]></description>
      <content:encoded><![CDATA[<p>Marc Adler follows on from <a title="Muddy Waters" rel="bookmark" href="http://www.thecepblog.com/2008/07/16/muddy-waters/"><span style="color: #105cb6;">Muddy Waters</span></a> to <a href="http://magmasystems.blogspot.com/2008/07/first-annual-fluffies-for-cep.html" target="_blank">The First Annual Fluffies for CEP</a> where Marc also calls into question the transparency, credibility and accuracy of the various fluffy &#8220;awards&#8221; we see from time-to-time.</p>
<p>When I discussed this openly with Waters in <a title="Muddy Waters" rel="bookmark" href="http://www.thecepblog.com/2008/07/16/muddy-waters/"><span style="color: #105cb6;">Muddy Waters</span></a> comments they kindly replied that &#8220;customers are loath to be a reference client for a vendor,&#8221;  like this fact somehow justifies having 600 people, most who have never actually used the software in practice, vote on how great it is.  </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>Or, as Mark Adler pointed out in his well written blog post <a href="http://magmasystems.blogspot.com/2008/07/first-annual-fluffies-for-cep.html" target="_blank">The First Annual Fluffies for CEP</a> , a secretive &#8220;panel of renowned judge&#8221; is going to tell us, via Jolt, who has the better solution?  Holy Cow Batman!   Let me buy a nice layout in your magazine  or web site,  please, so &#8220;my software company&#8221; will be on the short list for the &#8220;the awards&#8221;.  </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>All this smoke-and-mirrors. share-the-love, marketing reminds me of The Matrix a bit, where the world as we observe it, is a complete artificial construction, where most people in the Matrix believe they are &#8220;real&#8221; because they do not know that they really just a computer generated program designed to keep humans happy as they sleep in some cold goop with electrodes stuck up their you-know-what, really just bio-batteries insuring the light bill is paid.</p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>Or better yet, these fluffies are similar to most of the Webinars we see where there are questions from &#8220;the audience&#8221; but we know that most of these questions did not come from the &#8220;audience&#8221; - yet we all seem to continue &#8221;the  audience&#8221; myth just like Santa Claus and the Easter Bunny! </p>
<blockquote><p><em>Follow the Yellow Brick Road.</em></p></blockquote>
<p>The Easter Bunny, Santa Claus, the Tooth Fairy and the Fluffy Awards are real, if you want them to be real.  Just close your eyes and click your heels three times&#8230;.</p>
<blockquote><p>Follow the Yellow Brick Road. Follow the Yellow Brick Road.<br />
Follow, follow, follow, follow,<br />
Follow the Yellow Brick Road.<br />
Follow the Yellow Brick, Follow the Yellow Brick,<br />
Follow the Yellow Brick Road.</p></blockquote>
<blockquote><p>We&#8217;re off to see the Wizard, The Wonderful Wizard of Oz.<br />
You&#8217;ll find he is a whiz of a Wiz! If ever a Wiz! there was.<br />
If ever oh ever a Wiz! there was The Wizard of Oz is one because,<br />
Because, because, because, because, because.<br />
Because of the wonderful things he does.<br />
We&#8217;re off to see the Wizard. The Wonderful Wizard of Oz</p></blockquote>
]]></content:encoded>
      <pubDate>Sat, 19 Jul 2008 15:57:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/yellow brick">yellow brick</category>
      <category domain="http://securityratty.com/tag/yellow brick road">yellow brick road</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <category domain="http://securityratty.com/tag/wonderful wizard">wonderful wizard</category>
      <category domain="http://securityratty.com/tag/wizard">wizard</category>
      <category domain="http://securityratty.com/tag/awards">awards</category>
      <category domain="http://securityratty.com/tag/fluffy awards">fluffy awards</category>
      <category domain="http://securityratty.com/tag/wonderful">wonderful</category>
      <category domain="http://securityratty.com/tag/audience">audience</category>
      <source url="http://www.thecepblog.com/2008/07/19/follow-the-yellow-brick-road/">Follow the Yellow Brick Road</source>
    </item>
    <item>
      <title><![CDATA[Things that happen in China when nodoby is watching]]></title>
      <link>http://securityratty.com/article/c56b2c98388f10a613baa9f9ace01efa</link>
      <guid>http://securityratty.com/article/c56b2c98388f10a613baa9f9ace01efa</guid>
      <description><![CDATA[Here is another reason to pay attention for your own safety when you visit China - especially during the Olympics

The BBC World News ran a story yesterday of a local Beijing woman whose house was...]]></description>
      <content:encoded><![CDATA[Here is another reason to pay attention for your own safety when you visit China - especially during the Olympics.<br /><br /><span id="fullpost">The BBC World News ran a story yesterday of a local Beijing woman whose house was about to be torn down, leaving her homeless.  Why was her home being demolished?  The Government had decided that her house would not look nice enough to the foreign visitors coming to Beijing for the summer Olympics.  They planned to plant flowers in the spot where her home stood.<br /><br /></span>Apparently, the authorities knew that the woman was not going to willingly accept this obvious abuse of power.  A couple of Police vans watched the house from about a block away.  Then the cameras left after interviewing the woman.  When the television cameras came back the next day, the house was gone and so was the woman.  The house had been torn down in the middle of the night when there were no witnesses.  Nobody could say what happened to her as the flower planters went about the task of digging flower beds.<br /><br />The BBC had obtained similar footage that had been covertly recorded earlier at another house.  In this instance, a couple of the homeowners tried to resist the authorities tearing down their house.  The camera graphically recorded two men who attempted to protest on the roof of their humble abode.  A couple of "heavies" pulverised the seated men with vicious blows and kicks.  One poor man was kicked full-force in the face and head several times.  The camera shot him being taken away by ambulance and his whole face was swollen and lacerated.  It seems that the Chinese Government are very serious when it comes to planting flowers.  They certainly appear to have a higher regard for flowers than they do for human rights.<br /><br />Our advice to you if you are visiting Beijing this summer - don't pick the flowers.  I have seen how they treat people when they think nobody is watching.  It isn't pretty.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sat, 19 Jul 2008 14:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/house">house</category>
      <category domain="http://securityratty.com/tag/flowers">flowers</category>
      <category domain="http://securityratty.com/tag/plant flowers">plant flowers</category>
      <category domain="http://securityratty.com/tag/bbc">bbc</category>
      <category domain="http://securityratty.com/tag/summer olympics">summer olympics</category>
      <category domain="http://securityratty.com/tag/summer">summer</category>
      <category domain="http://securityratty.com/tag/bbc world news">bbc world news</category>
      <category domain="http://securityratty.com/tag/woman">woman</category>
      <category domain="http://securityratty.com/tag/olympics">olympics</category>
      <source url="http://www.thebulletproofblog.com/2008/07/things-that-happen-in-china-when-nodoby.html">Things that happen in China when nodoby is watching</source>
    </item>
    <item>
      <title><![CDATA[Six U.S. states account for half of national piracy losses]]></title>
      <link>http://securityratty.com/article/db910425aa6219e43d241f3d860992e2</link>
      <guid>http://securityratty.com/article/db910425aa6219e43d241f3d860992e2</guid>
      <description><![CDATA[A first-time study by the Business Software Alliance (BSA) shows that while the U.S. has the lowest rate of software piracy of countries tracked around the world, there is still a long way to go to...]]></description>
      <content:encoded><![CDATA[A first-time study by the Business Software Alliance (BSA) shows that while the U.S. has the lowest rate of software piracy of countries tracked around the world, there is still a long way to go to end illegal software use here.]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/business software alliance">business software alliance</category>
      <category domain="http://securityratty.com/tag/software piracy">software piracy</category>
      <category domain="http://securityratty.com/tag/illegal software">illegal software</category>
      <category domain="http://securityratty.com/tag/first-time study">first-time study</category>
      <category domain="http://securityratty.com/tag/bsa">bsa</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/countries">countries</category>
      <source url="http://www.networkworld.com/news/2008/071708-six-us-states-account-for.html?fsrc=rss-security">Six U.S. states account for half of national piracy losses</source>
    </item>
    <item>
      <title><![CDATA[The Network Firewall is a Consensual Hallucination]]></title>
      <link>http://securityratty.com/article/c05f6f72f82ab4c25ddc9c804d1973ec</link>
      <guid>http://securityratty.com/article/c05f6f72f82ab4c25ddc9c804d1973ec</guid>
      <description><![CDATA[James McGovern asks why we don't see enterprisey folks focusing on SOA *and* security? Well there are a lot of reasons here, but lets look at some facts. Most enterprisey folks look at security in...]]></description>
      <content:encoded><![CDATA[<p>James McGovern <a href="http://duckdown.blogspot.com/2008/07/how-come-enterprise-architects-are.html">asks</a> why we don't see enterprisey folks focusing on SOA *and* security? Well there are a lot of reasons here, but lets look at some facts. Most enterprisey folks look at security in binary terms - inside the firewall or outside the firewall. When a transaction is "inside the firewall" they can do silly things like load all their transaction on to something like MQ Series with no authentication, send it to the mainframe which runs their entire book of business, and in essence run their transactional backbone on anonymous ftp. Because its "inside the firewall"</p><br><div>Problem is - its just a Visio drawing, its not reality, its historical baggage. We were trained to think about things in these terms in the 90s</div><br><div><a style="display: inline;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553a923008833-pi"><img  class="at-xid-6a00d83451c75869e200e553a923008833 selected " alt="Goodstuffbadstuff" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553a923008833-320pi" title="Goodstuffbadstuff"></a>
<br></div><br><div>But the business and software worlds have changed a bit from the early 90s, even if security tooling hasn't</div><br>
<p><br>
<a href="http://1raindrop.typepad.com/photos/uncategorized/2008/05/19/innovatecompare_2.png"><img  alt="Innovatecompare_2" title="Innovatecompare_2" src="http://1raindrop.typepad.com/1_raindrop/images/2008/05/19/innovatecompare_2.png" width="300" height="167" border="0"></a></p>
<div>If you sent an alien from outer space to observe what an enterprise looks like today, and asked that alien to file an objective report as to the actual connections and message exchanges it wouldn't look like the idyllic, clear separation of good stuff from bad stuff, it would look like this</div><br><br><p><a href="http://1raindrop.typepad.com/photos/uncategorized/thenetwork.jpg"><img  class="image-full " alt="Thenetwork" title="Thenetwork" src="http://1raindrop.typepad.com/photos/uncategorized/thenetwork.jpg" border="0"></a></p><br><div>There is no firewall in any meaningful sense, there are links, federations, communities of interest, business units, integration points, outsourcing arrangements, business processes. In short, there is information and commerce in all its messy vitality. </div><br><div>Inside the firewall and outside the firewall is not a security architecture, its historical <a href="http://en.wikipedia.org/wiki/Cruft">cruft</a> a Victorian, industrial age artifact that snuck into your Visio, not something that protects your businesses' applications and data.</div><br><div>If you want to let the world access your maifnrame, SAP, Siebel, or whatever so they can buy things from you, that is probably a really good idea. But don't assume that RACF or what have you came down on stone tablets from Moses. Just because your transaction is "inside the firewall" doesnt mean that your security model can only focus on resources and objects in isolation. It has to focus on how your business just broke everything apart and then re-connected everything. The subjects are different, the sessions are different, and the transactions are different. Just because the objects and resources are the same and are "inside the firewall" means little when all the context and all the relationships are different.</div><br><div>The world is not firewalled, its federated. Just because its convenient for enterprisey folks to buy into the same hallucination doesn't make it reality.</div><br><div>Next week, I am speaking at <a href="http://www.ssosummit.com/program/Agenda-at-a-Glance.cfm">Ping's SSO Summit</a> on Web Services SSO basically everything that happens after you press <span style="font-family: Arial; line-height: normal; ">"SUBMIT" on a website. Your data has a journey as dangerous as Frodo Baggins' travels through Mordor. The talk traces the path from the website through the perils that lurk in the enterprise and legacy systems, we will look at ways to get Frodo and Sam home safely and we won't rely on Visio firewalls where Mithril is required.</span></div><div><span><br></span></div><div><span><a style="display: inline;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c410e98834-pi"><img  class="at-xid-6a00d83451c75869e200e553c410e98834 " alt="Ghostseparationwall" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c410e98834-320wi"></a>
<br></span></div><br><div>(Note - Thanks for reminding me of the analogy <a href="http://radar.oreilly.com/jims/">Jim</a>)</div>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 07:04:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firewall">firewall</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security model">security model</category>
      <category domain="http://securityratty.com/tag/business units">business units</category>
      <category domain="http://securityratty.com/tag/inside">inside</category>
      <category domain="http://securityratty.com/tag/enterprisey folks">enterprisey folks</category>
      <category domain="http://securityratty.com/tag/security architecture">security architecture</category>
      <category domain="http://securityratty.com/tag/business processes">business processes</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/the-network-firewall-is-a-consensual-hallucination.html">The Network Firewall is a Consensual Hallucination</source>
    </item>
    <item>
      <title><![CDATA[Collaboration in the Cloud, Virtual Worlds and the Hacker Mindset]]></title>
      <link>http://securityratty.com/article/451246868f8b52e293c9ac433dce53dd</link>
      <guid>http://securityratty.com/article/451246868f8b52e293c9ac433dce53dd</guid>
      <description><![CDATA[Collaboration in the Cloud
Forward thinking companies use collaboration technologies to melt away the physical distance between disparate offices, remote workers and suppliers. Investments in R&amp;D...]]></description>
      <content:encoded><![CDATA[<h4><img src="http://blogs.cisco.com/images/uploads/johnchamberspost.jpg" alt="" width="450" height="246" /></h4>
<h4>Collaboration in the Cloud</h4>
<p>Forward thinking companies use collaboration technologies to melt away the physical distance between disparate offices, remote workers and suppliers.  Investments in R&amp;D projects to create the next generation of business collaboration technologies and starting to bear early fruits and are worth paying attention to - especially if you get paid to &#8220;do security&#8221;.  One major focus area is Virtual Worlds.</p>
<h4>Teleporting Virgins</h4>
<p>The <a href="http://blog.secondlife.com/2008/07/08/ibm-linden-lab-interoperability-announcement/">big news</a> in the <a href="http://www.secondlife.com/">Second Life</a> research community is that avatars (&#8221;virtual people&#8221;) have successfully teleported between <em><strong>distinct </strong></em>virtual worlds.  The virgin teleporters went from a Second Life Preview Grid - an experimental grid completely disconnected from the Main Grid - to a virtual world running IBM OpenSIM.</p>
<p>At this stage there is intentionally no asset transfer going on at all - in other words, you can&#8217;t take your &#8220;stuff&#8221; from one world to another - but that will come in time as the <a href="http://secondlifegrid.net.s3.amazonaws.com/docs/specs/SLGOGP-draft-1.html">Open Grid Protocol</a> is extended.  Today just login and teleport are supported.  No stealing those trade secret &#8220;assets&#8221; yet ;-).</p>
<p>Linden Labs speaks to this issue:</p>
<blockquote><p>Q: How will Linden Lab prevent property from being copied into other virtual worlds?<br />
We’re paying extremely close attention to that question. We will be designing this with the Second Life community to ensure their needs are met. We want to stress that when it does become possible to move avatars between worlds, we will take the utmost care to protect the rights of Second Life property owners and creators. Linden Lab will not design a system that lets people openly violate the permissions of SL goods and take them to other worlds. We recognize that intellectual property is the engine that drives Second Life, and we are completely committed to preserving the qualities that make Second Life the unique, innovative and dynamic place that it is today.</p></blockquote>
<p>With my &#8220;hacker-vision&#8221; &#8482; enabled I see *all kinds* of opportunities for mischief here.  I&#8217;m betting we&#8217;ll see imaginative attacks as the usual cat and mouse game of vulnerability research and vendor response plays out.  &#8220;Sorry boss, someone hijacked my avatar and now I&#8217;m stuck on this desert island for who knows how long!&#8221;.</p>
<h4>Threat Profiling Second Life</h4>
<p>Getting back to reality, people are already exploring Virtual World security.  <a href="http://www.ernw.de/">Michael Thumann of ERNW</a> in Germany is a pen-tester and security researcher and in this 10 minute video, Michael shares the result of his security research on Second Life.</p>
<p>He covers:</p>
<ul>
<li> In-game cheating</li>
<li> Identity theft</li>
<li> Attacking 3rd party servers using Linden Scripting Language (think about the liability issues and the providers ability to track abusers)</li>
</ul>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/6MoptnBsNGc&amp;hl=en&amp;fs=1" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/6MoptnBsNGc&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p>For those interested in more detail, the full presentation he gave at BlackHat Europe 2008 in Amsterdam is <a href="https://www.blackhat.com/presentations/bh-europe-08/Thumann/Whitepaper/bh-eu-08-thumann-WP.pdf">here </a>(pdf).</p>
<p>Of particular note, Michael applied a formal threat model approach to the research - <a href="http://msdn.microsoft.com/en-us/library/ms954176.aspx">STRIDE </a>from Microsoft.</p>
<p>In a future post I&#8217;ll talk more about threat profiling in the context of Cloud Computing vulnerability research and specific API security vulnerability classes we can expect to see exploited.</p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/338174255" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 11:51:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtual worlds">virtual worlds</category>
      <category domain="http://securityratty.com/tag/worlds">worlds</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/vulnerability research">vulnerability research</category>
      <category domain="http://securityratty.com/tag/security research">security research</category>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/life property owners">life property owners</category>
      <category domain="http://securityratty.com/tag/life research community">life research community</category>
      <category domain="http://securityratty.com/tag/collaboration">collaboration</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/338174255/">Collaboration in the Cloud, Virtual Worlds and the Hacker Mindset</source>
    </item>
    <item>
      <title><![CDATA[Gonzo: Two Thumbs In and Up]]></title>
      <link>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</link>
      <guid>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</guid>
      <description><![CDATA[Just saw the Hunter S. Thompson movie - Gonzo , and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view...]]></description>
      <content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Hunter_S._Thompson"></a><a style="float: left;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-pi"><img  class="at-xid-6a00d83451c75869e200e553c045c48834 " alt="180px-Gonzo_citation" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-320wi" style="margin: 0px 5px 5px 0px;"></a> Just saw the Hunter S. Thompson movie - <a href="http://www.rottentomatoes.com/m/gonzo_the_life_and_work_of_dr_hunter_s_thompson/">Gonzo</a>, and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view of the high highs and the low lows. Weaves in writing, politics, and fame seamlessly.

I have never really had as much fun as early on in my career in the early-mid 90s I was a web programmer in Aspen, hacking CGI/PERL. Among the most fun things was building and running HST's site. My boss, Ed, was his neighbor. Ed was also seriously allergic to bees. One day he was alone in his house and got stung. He was dying. Luckily Hunter was due over to his house to watch a basketball game, walked in and called 911. My boss woke up in the ambulance with Hunter pounding on him chest and screaming at him. Ed said - "Waking up to that face screaming at me, I didn't know if I was alive or dead."

Seeing the movie it was also great to see a lot of the Woody Creek folks again like George Stranahan, who lovingly said about Hunter - "my friend and neighbor who never paid his rent, broke up my marriage and taught my children to smoke dope. "

Of course, there was no way he could match his early productivity and this is true of almost all artists. Most of the last two decades were wasted from a writing standpoint. However his <a href="http://proxy.espn.go.com/espn/page2/story?id=1250751">piece</a> written on 9/11 is as good as its gets:

</p><blockquote><p>
	The towers are gone now, reduced to bloody rubble, along with all hopes for Peace in Our Time, in the United States or any other country. Make no mistake about it: We are At War now -- with somebody -- and we will stay At War with that mysterious Enemy for the rest of our lives. 	
	</p></blockquote><blockquote><p>It will be a Religious War, a sort of Christian Jihad, fueled by religious hatred and led by merciless fanatics on both sides. It will be guerilla warfare on a global scale, with no front lines and no identifiable enemy. Osama bin Laden may be a primitive "figurehead" -- or even dead, for all we know -- but whoever put those All-American jet planes loaded with All-American fuel into the Twin Towers and the Pentagon did it with chilling precision and accuracy. The second one was a dead-on bullseye. Straight into the middle of the skyscraper. 	
	</p></blockquote><blockquote><p>Nothing -- even George Bush's $350 billion "Star Wars" missile defense system -- could have prevented Tuesday's attack, and it cost next to nothing to pull off. Fewer than 20 unarmed Suicide soldiers from some apparently primitive country somewhere on the other side of the world took out the World Trade Center and half the Pentagon with three quick and costless strikes on one day. The efficiency of it was terrifying. 	
	</p></blockquote><blockquote><p>We are going to punish somebody for this attack, but just who or what will be blown to smithereens for it is hard to say. Maybe Afghanistan, maybe Pakistan or Iraq, or possibly all three at once. Who knows? Not even the Generals in what remains of the Pentagon or the New York papers calling for WAR seem to know who did it or where to look for them. 	
	</p></blockquote><blockquote><p>This is going to be a very expensive war, and Victory is not guaranteed -- for anyone, and certainly not for anyone as baffled as George W. Bush. All he knows is that his father started the war a long time ago, and that he, the goofy child-President, has been chosen by Fate and the global Oil industry to finish it Now. He will declare a National Security Emergency and clamp down Hard on Everybody, no matter where they live or why. If the guilty won't hold up their hands and confess, he and the Generals will ferret them out by force. 	
	</p></blockquote><blockquote><p>Good luck. He is in for a profoundly difficult job -- armed as he is with no credible Military Intelligence, no witnesses and only the ghost of Bin Laden to blame for the tragedy.
	
</p></blockquote><p>


One unintended lesson I take away from Hunter's life is how important patience is. Obama is a politician and may yet disappoint us all, but I gotta believe Hunter would be seriously impressed. If he had waited another couple of years, he may have seen a lot of the stuff he fought for in 1968 and 72 come to fruition. Sometimes you are just 36-40 years ahead of your time and you have to be ok with that and figure out how to deal if possible. (Note - it sure sometimes feels this way in software security).

Speaking of security:

</p><blockquote>
	<p><a href="http://www.ram.org/contrib/security.html">Security</a> 	
	</p></blockquote><blockquote><p>by Hunter S. Thompson (1955). 	
	</p></blockquote><blockquote><p>Security ... what does this word mean in relation to life as we know it today? For the most part, it means safety and freedom from worry. It is said to be the end that all men strive for; but is security a utopian goal or is it another word for rut? 	
	</p></blockquote><blockquote><p>Let us visualize the secure man; and by this term, I mean a man who has settled for financial and personal security for his goal in life. In general, he is a man who has pushed ambition and initiative aside and settled down, so to speak, in a boring, but safe and comfortable rut for the rest of his life. His future is but an extension of his present, and he accepts it as such with a complacent shrug of his shoulders. His ideas and ideals are those of society in general and he is accepted as a respectable, but average and prosaic man. But is he a man? has he any self-respect or pride in himself? How could he, when he has risked nothing and gained nothing? What does he think when he sees his youthful dreams of adventure, accomplishment, travel and romance buried under the cloak of conformity? How does he feel when he realizes that he has barely tasted the meal of life; when he sees the prison he has made for himself in pursuit of the almighty dollar? If he thinks this is all well and good, fine, but think of the tragedy of a man who has sacrificed his freedom on the altar of security, and wishes he could turn back the hands of time. A man is to be pitied who lacked the courage to accept the challenge of freedom and depart from the cushion of security and see life as it is instead of living it second-hand. Life has by-passed this man and he has watched from a secure place, afraid to seek anything better What has he done except to sit and wait for the tomorrow which never comes? 	
	</p></blockquote><blockquote><p>Turn back the pages of history and see the men who have shaped the destiny of the world. Security was never theirs, but they lived rather than existed. Where would the world be if all men had sought security and not taken risks or gambled with their lives on the chance that, if they won, life would be different and richer? It is from the bystanders (who are in the vast majority) that we receive the propaganda that life is not worth living, that life is drudgery, that the ambitions of youth must he laid aside for a life which is but a painful wait for death. These are the ones who squeeze what excitement they can from life out of the imaginations and experiences of others through books and movies. These are the insignificant and forgotten men who preach conformity because it is all they know. These are the men who dream at night of what could have been, but who wake at dawn to take their places at the now-familiar rut and to merely exist through another day. For them, the romance of life is long dead and they are forced to go through the years on a treadmill, cursing their existence, yet afraid to die because of the unknown which faces them after death. They lacked the only true courage: the kind which enables men to face the unknown regardless of the consequences. 	
	</p></blockquote><blockquote><p>As an afterthought, it seems hardly proper to write of life without once mentioning happiness; so we shall let the reader answer this question for himself: who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed?
</p></blockquote><p>

A ship is safest at port, but thats not why we build ships. 
</p>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 06:10:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/sought security">sought security</category>
      <category domain="http://securityratty.com/tag/personal security">personal security</category>
      <category domain="http://securityratty.com/tag/national security emergency">national security emergency</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/expensive war">expensive war</category>
      <category domain="http://securityratty.com/tag/war">war</category>
      <category domain="http://securityratty.com/tag/hunter">hunter</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/gonzo-two-thumbs-in-and-up.html">Gonzo: Two Thumbs In and Up</source>
    </item>
    <item>
      <title><![CDATA[Decoders Still Trying to Crack Letter Sent to Fermilab]]></title>
      <link>http://securityratty.com/article/3335112f477a8aff5af7a2dc93bc3996</link>
      <guid>http://securityratty.com/article/3335112f477a8aff5af7a2dc93bc3996</guid>
      <description><![CDATA[The enigma began last year when a plain envelope with no return address arrived at the world-famous physics laboratory outside Chicago, addressed simply to &quot;Fermilab.&quot; Inside was a single sheet marked...]]></description>
      <content:encoded><![CDATA[The enigma began last year when a plain envelope with no return address arrived at the world-famous physics laboratory outside Chicago, addressed simply to "Fermilab." Inside was a single sheet marked by pen with a bizarre series of hash marks, numbers and alien-looking symbols.]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 16:20:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world-famous physics laboratory">world-famous physics laboratory</category>
      <category domain="http://securityratty.com/tag/single sheet">single sheet</category>
      <category domain="http://securityratty.com/tag/return address">return address</category>
      <category domain="http://securityratty.com/tag/bizarre series">bizarre series</category>
      <category domain="http://securityratty.com/tag/hash marks">hash marks</category>
      <category domain="http://securityratty.com/tag/fermilab">fermilab</category>
      <category domain="http://securityratty.com/tag/plain envelope">plain envelope</category>
      <category domain="http://securityratty.com/tag/chicago">chicago</category>
      <category domain="http://securityratty.com/tag/simply">simply</category>
      <source url="http://digg.com/security/Decoders_Still_Trying_to_Crack_Letter_Sent_to_Fermilab">Decoders Still Trying to Crack Letter Sent to Fermilab</source>
    </item>
    <item>
      <title><![CDATA[Standing Out In A Pool of InfoSec Wannabes: Are You Special Enough?]]></title>
      <link>http://securityratty.com/article/3f007feb1742c44123232f3ca40f376d</link>
      <guid>http://securityratty.com/article/3f007feb1742c44123232f3ca40f376d</guid>
      <description><![CDATA[I stumbled across a great video on a blog post from the SOURCE Boston conference
Careers in information security are often difficult to navigate, with the industry changing more and more radically...]]></description>
      <content:encoded><![CDATA[<p><img src='http://s3.securitywannabe.com/blog/wp-content/uploads/2008/07/samp7b3d0979119e7a6b.jpg' alt='Are You Special Enough?' /></p>
<p>I stumbled across a great video on a <a href="http://www.sourceconference.com/blog/?p=35">blog post</a> from the <a href="http://www.sourceconference.com/">SOURCE Boston</a> conference.</p>
<blockquote><p>Careers in information security are often difficult to navigate, with the industry changing more and more radically every year. This is even more true in an economy that isn’t necessarily thriving. We’re going to talk about the important skills, traits and knowledge that a security pro needs to build a long-term and successful career – not just the usual stuff (like “get certified”), but the real-world knowledge that teaches you how to have the job that keeps you challenged, growing and well-compensated.</p></blockquote>
<p>If you are even thinking about a role in Information Security or wandering about your next step in the industry - this in-depth talk by Lee Kushner and Mike Murray is for you.</p>
<p><embed src="http://blip.tv/play/AbCjfIreFg" type="application/x-shockwave-flash" width="320" height="270" allowscriptaccess="always" allowfullscreen="true"></embed> </p>
<p>How do you keep yourself special?  Share in the comments&#8230;</p>
<img src="http://feeds.feedburner.com/~r/SecurityWannabe/~4/337339509" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 15:17:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/in-depth talk">in-depth talk</category>
      <category domain="http://securityratty.com/tag/source boston conference">source boston conference</category>
      <category domain="http://securityratty.com/tag/real-world knowledge">real-world knowledge</category>
      <category domain="http://securityratty.com/tag/knowledge">knowledge</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/security pro">security pro</category>
      <category domain="http://securityratty.com/tag/lee kushner">lee kushner</category>
      <category domain="http://securityratty.com/tag/special">special</category>
      <source url="http://securitywannabe.com/blog/2008/07/16/standing-out-in-a-pool-of-infosec-wannabes-are-you-special-enough/">Standing Out In A Pool of InfoSec Wannabes: Are You Special Enough?</source>
    </item>
    <item>
      <title><![CDATA[OSF DATA LOSS db a valuable resource]]></title>
      <link>http://securityratty.com/article/208e55167cf52b5f1b75426941d90324</link>
      <guid>http://securityratty.com/article/208e55167cf52b5f1b75426941d90324</guid>
      <description><![CDATA[As a longtime reader of the The Data Breach Blog , I was pleased to learn that care and feeding of Attrition.org's Data Loss Database has been assumed by the Open Security Foundation. Check out the...]]></description>
      <content:encoded><![CDATA[As a longtime reader of the <a href="http://breach.scmagazineblogs.com/">The Data Breach Blog</a>, I was pleased to learn that care and feeding of <a href="http://attrition.org/" target="_blank">Attrition.org's</a> Data Loss Database has been assumed by the Open Security Foundation. Check out the <a href="http://datalossdb.org/" target="_blank">DATA LOSS db</a> at your earliest convenience, join, and support.<br />From the site, the OSF Data Loss database is a "research project aimed at documenting known and reported data loss incidents world-wide. The effort is now a community one, with the move to OSF, and relies on the contributions of users like you to grow and prune the database."<br />Do your best not to find yourself an entry in this database. ;-)]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 13:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data loss">data loss</category>
      <category domain="http://securityratty.com/tag/data loss database">data loss database</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/research project aimed">research project aimed</category>
      <category domain="http://securityratty.com/tag/data breach blog">data breach blog</category>
      <category domain="http://securityratty.com/tag/osf">osf</category>
      <category domain="http://securityratty.com/tag/security foundation">security foundation</category>
      <category domain="http://securityratty.com/tag/longtime reader">longtime reader</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <source url="http://holisticinfosec.blogspot.com/2008/07/osg-data-loss-db-valuable-resource.html">OSF DATA LOSS db a valuable resource</source>
    </item>
    <item>
      <title><![CDATA[Interview with Paul Cannon, Mozy Software Engineer]]></title>
      <link>http://securityratty.com/article/0cc76ea91cbf8ad59a01671da9da1295</link>
      <guid>http://securityratty.com/article/0cc76ea91cbf8ad59a01671da9da1295</guid>
      <description><![CDATA[Mozy Awesome Process
Sometimes people come up to me and say, Paul, how is it that Mozy has created such an unrelenting output of Awesome
Today I have been authorized to share with you some of the...]]></description>
      <content:encoded><![CDATA[<p><span style="font-size: small;"><span style="font-weight: bold;">Mozy Awesome Process</span></span><br />
Sometimes people come up to me and say, &#8220;Paul, how is it that Mozy has created such an unrelenting output of Awesome?&#8221;</p>
<p>Today I have been authorized to share with you some of the unique facets of the Mozy Awesome Process that until now have been tightly controlled trade secrets of Mozy, Inc. It all starts with giant robots (virtually perpetual sources of raw Awesome). We attach them to special Awesome Siphons of our own design and pipe the yield directly into our engineers&#8217; development workstations. Further, peripheral Awesome needs are farmed from old He-Man reruns, a roomful of ninjas wailing on electric guitars, and our captive Happy Fun Ball.</p>
<p>The crude Awesome is skillfully transformed by Mozy engineers into powerful software and hardware configurations, then carefully inspected and regulated according to a host of eldritch acronyms: SWAGs, PMQs, PRDs, and the ever-inspiring CFRRCs. Once a successful creation is stamped with the Seal of Acronymic Approval for Mozy (SAAM), it is subjected to final endorsement by the mystical, revered Mozy Leprecorn*. Finally, a highly trained team of Box Monks put the new Awesomery into place in the Mozy systems, where it becomes available to you, the user.</p>
<p>Our rigorous Awesome Enforcement Policies and Magical Oversight have brought us to what we believe is the most Awesome-efficient development process in the world of backup software.</p>
<p>Be safe,<br />
Paul Cannon<br />
Mozy Software Engineer</p>
<p>*Leprecorn (noun): a rare but phenomenal creature; half Unicorn, half Leprechaun, and all magical.</p>
<p><a title="Mozy" href="http://www.mozy.com/?ref=3f9a896b&amp;kbid=38419&amp;m=4&amp;i=77" target="_blank">Visit Mozy now for a great reliable online backup service, I use it myself.</a></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot.jpg" alt="" /></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot-1.jpg" alt="" /></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot-2.jpg" alt="" /></p>
<p><span style="font-size: small;"><span style="font-weight: bold;">Vote for Mozy</span></span><br />
Lifehacker is currently holding an online backup showdown. Show your love for Mozy. <a title="Vote for Mozy on Lifehacker.com" href="http://click.news.mozy.com/?ju=fe3415747265057c761075&amp;ls=fdf011757767027476137173&amp;m=fef012747c6103&amp;l=fe881576736c01787d&amp;s=fe601679776d007d7014&amp;jb=ffcf14&amp;t=">Vote now</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 11:00:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mozy">mozy</category>
      <category domain="http://securityratty.com/tag/mozy systems">mozy systems</category>
      <category domain="http://securityratty.com/tag/visit mozy">visit mozy</category>
      <category domain="http://securityratty.com/tag/mozy awesome process">mozy awesome process</category>
      <category domain="http://securityratty.com/tag/mozy software engineer">mozy software engineer</category>
      <category domain="http://securityratty.com/tag/awesome">awesome</category>
      <category domain="http://securityratty.com/tag/special awesome siphons">special awesome siphons</category>
      <category domain="http://securityratty.com/tag/mozy leprecorn">mozy leprecorn</category>
      <category domain="http://securityratty.com/tag/raw awesome">raw awesome</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=504">Interview with Paul Cannon, Mozy Software Engineer</source>
    </item>
  </channel>
</rss>
