<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>DrewDilloNet</title>
	<atom:link href="http://drewdillo.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://drewdillo.net</link>
	<description>IT Security, Life, Travel and whatever else comes to mind</description>
	<lastBuildDate>Mon, 16 May 2011 10:17:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='drewdillo.net' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>DrewDilloNet</title>
		<link>http://drewdillo.net</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://drewdillo.net/osd.xml" title="DrewDilloNet" />
	<atom:link rel='hub' href='http://drewdillo.net/?pushpress=hub'/>
		<item>
		<title>Fanfics of Dune</title>
		<link>http://drewdillo.net/2011/04/11/49/</link>
		<comments>http://drewdillo.net/2011/04/11/49/#comments</comments>
		<pubDate>Tue, 12 Apr 2011 01:00:56 +0000</pubDate>
		<dc:creator>Drew</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[Reading]]></category>
		<category><![CDATA[Sci-Fi]]></category>

		<guid isPermaLink="false">http://drewdillo.net/?p=49</guid>
		<description><![CDATA[When I first started travelling, I read nothing but histories and books of political discourse. The longer I travelled, the more I started leaning towards historical fiction and literature (Barnes &#38; Noble Classics, FTW). As miles racked up, I was drawn toward ever more escapist reading. Which is not to say I didn&#8217;t sprinkle a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=49&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>W<a href="http://theblathering.files.wordpress.com/2011/04/nerd6.jpg"><img class="alignright size-medium wp-image-50" title="my brain as a young man" src="http://theblathering.files.wordpress.com/2011/04/nerd6.jpg?w=193&#038;h=240" alt="" width="193" height="240" /></a>hen I first started travelling, I read nothing but histories and books of political discourse. The longer I travelled, the more I started leaning towards historical fiction and literature (Barnes &amp; Noble Classics, FTW).</p>
<p>As miles racked up, I was drawn toward ever more escapist reading. Which is not to say I didn&#8217;t sprinkle a little Sci-Fi in all along, but I doubt I would&#8217;ve read the entire Harry Potter series if I hadn&#8217;t flown 150,000 miles in a year.</p>
<p>I have for some time been basing new reading recommendations off of this list of <a href="http://home.austarnet.com.au/petersykes/topscifi/lists_books_rank1.html">Top 100 Sci-Fi Books</a>. My goal has never been to read all 100 of the books on the list, rather to use the list as a guide to navigate the most popular authors in Sci-Fi and become a more well-rounded geek.</p>
<p>Two examples: Hitchhiker&#8217;s Guide to the Galaxy &amp; 1984. Haven&#8217;t read them, not planning on reading them. I feel like pop culture has so heavily digested them that I wouldn&#8217;t really be discovering anything new for myself.</p>
<p>Of the remaining, I&#8217;ve read 25 to date, complete list below. And I haven&#8217;t really disagreed with the list in terms of quality. In terms of ranking, however, I would strongly argue Ender&#8217;s Game being above Dune. I liked Ender, reading from Ender&#8217;s Game to Xenocide, but I read Dune immediately afterward and the contrast was stark. Put simply, Dune felt like a book for adults, it felt like Sci-Fi literature.</p>
<p>Would you make changes? What should I read next?</p>
<table border="0" cellspacing="0" cellpadding="0" width="371">
<col width="19"></col>
<col width="25"></col>
<col width="133"></col>
<col width="194"></col>
<tbody>
<tr>
<td width="19" height="15"></td>
<td width="25"></td>
<td width="133">Author</td>
<td width="194">Title</td>
</tr>
<tr>
<td height="15">√</td>
<td>1</td>
<td>Orson Scott Card</td>
<td>Ender&#8217;s Game</td>
</tr>
<tr>
<td height="15">√</td>
<td>2</td>
<td>Frank Herbert</td>
<td>Dune</td>
</tr>
<tr>
<td height="15">√</td>
<td>3</td>
<td>Isaac Asimov</td>
<td>Foundation</td>
</tr>
<tr>
<td height="15"></td>
<td>4</td>
<td>Douglas Adams</td>
<td>Hitch Hiker&#8217;s Guide to the Galaxy</td>
</tr>
<tr>
<td height="15"></td>
<td>5</td>
<td>George Orwell</td>
<td>1984</td>
</tr>
<tr>
<td height="15">√</td>
<td>6</td>
<td>Robert A Heinlein</td>
<td>Stranger in a Strange Land</td>
</tr>
<tr>
<td height="15">√</td>
<td>7</td>
<td>Ray Bradbury</td>
<td>Fahrenheit 451</td>
</tr>
<tr>
<td height="15"></td>
<td>8</td>
<td>Arthur C Clarke</td>
<td>2001: A Space Odyssey</td>
</tr>
<tr>
<td height="15">√</td>
<td>9</td>
<td>Isaac Asimov</td>
<td>I, Robot</td>
</tr>
<tr>
<td height="15">√</td>
<td>10</td>
<td>Philip K Dick</td>
<td>Do Androids Dream of Electric Sheep?</td>
</tr>
<tr>
<td height="15"></td>
<td>11</td>
<td>Robert A Heinlein</td>
<td>Starship Troopers</td>
</tr>
<tr>
<td height="15"></td>
<td>12</td>
<td>William Gibson</td>
<td>Neuromancer</td>
</tr>
<tr>
<td height="15">√</td>
<td>13</td>
<td>Larry Niven</td>
<td>Ringworld</td>
</tr>
<tr>
<td height="15"></td>
<td>14</td>
<td>Arthur C Clarke</td>
<td>Rendezvous With Rama</td>
</tr>
<tr>
<td height="15"></td>
<td>15</td>
<td>Dan Simmons</td>
<td>Hyperion</td>
</tr>
<tr>
<td height="15">√</td>
<td>16</td>
<td>H G Wells</td>
<td>The Time Machine</td>
</tr>
<tr>
<td height="15"></td>
<td>17</td>
<td>Aldous Huxley</td>
<td>Brave New World</td>
</tr>
<tr>
<td height="15"></td>
<td>18</td>
<td>Arthur C Clarke</td>
<td>Childhood&#8217;s End</td>
</tr>
<tr>
<td height="15"></td>
<td>19</td>
<td>Robert A Heinlein</td>
<td>The Moon is a Harsh Mistress</td>
</tr>
<tr>
<td height="15">√</td>
<td>20</td>
<td>H G Wells</td>
<td>The War of the Worlds</td>
</tr>
<tr>
<td height="15"></td>
<td>21</td>
<td>Joe Haldeman</td>
<td>The Forever War</td>
</tr>
<tr>
<td height="15">√</td>
<td>22</td>
<td>Ray Bradbury</td>
<td>The Martian Chronicles</td>
</tr>
<tr>
<td height="15">√</td>
<td>23</td>
<td>Kurt Vonnegut</td>
<td>Slaughterhouse Five</td>
</tr>
<tr>
<td height="15"></td>
<td>24</td>
<td>Neal Stephenson</td>
<td>Snow Crash</td>
</tr>
<tr>
<td height="15"></td>
<td>25</td>
<td>Ursula K Le Guin</td>
<td>The Left Hand of Darkness</td>
</tr>
<tr>
<td height="15"></td>
<td>26</td>
<td>Niven &amp; Pournelle</td>
<td>The Mote in God&#8217;s Eye</td>
</tr>
<tr>
<td height="15">√</td>
<td>27</td>
<td>Orson Scott Card</td>
<td>Speaker for the Dead</td>
</tr>
<tr>
<td height="15">√</td>
<td>28</td>
<td>Michael Crichton</td>
<td>Jurassic Park</td>
</tr>
<tr>
<td height="15"></td>
<td>29</td>
<td>Philip K Dick</td>
<td>The Man in the High Castle</td>
</tr>
<tr>
<td height="15">√</td>
<td>30</td>
<td>Isaac Asimov</td>
<td>The Caves of Steel</td>
</tr>
<tr>
<td height="15"></td>
<td>31</td>
<td>Alfred Bester</td>
<td>The Stars My Destination</td>
</tr>
<tr>
<td height="15"></td>
<td>32</td>
<td>Roger Zelazny</td>
<td>Lord of Light</td>
</tr>
<tr>
<td height="15"></td>
<td>33</td>
<td>Frederik Pohl</td>
<td>Gateway</td>
</tr>
<tr>
<td height="15"></td>
<td>34</td>
<td>Stanislaw Lem</td>
<td>Solaris</td>
</tr>
<tr>
<td height="15">√</td>
<td>35</td>
<td>Jules Verne</td>
<td>20,000 Leagues Under the Sea</td>
</tr>
<tr>
<td height="15">√</td>
<td>36</td>
<td>Madeleine L&#8217;Engle</td>
<td>A Wrinkle In Time</td>
</tr>
<tr>
<td height="15"></td>
<td>37</td>
<td>Michael Crichton</td>
<td>The Andromeda Strain</td>
</tr>
<tr>
<td height="15">√</td>
<td>38</td>
<td>Kurt Vonnegut</td>
<td>Cat&#8217;s Cradle</td>
</tr>
<tr>
<td height="15"></td>
<td>39</td>
<td>Carl Sagan</td>
<td>Contact</td>
</tr>
<tr>
<td height="15"></td>
<td>40</td>
<td>Isaac Asimov</td>
<td>The Gods Themselves</td>
</tr>
<tr>
<td height="15"></td>
<td>41</td>
<td>Vernor Vinge</td>
<td>A Fire Upon the Deep</td>
</tr>
<tr>
<td height="15"></td>
<td>42</td>
<td>Philip K Dick</td>
<td>UBIK</td>
</tr>
<tr>
<td height="15">√</td>
<td>43</td>
<td>Neal Stephenson</td>
<td>Cryptonomicon</td>
</tr>
<tr>
<td height="15"></td>
<td>44</td>
<td>John Wyndham</td>
<td>The Day of the Triffids</td>
</tr>
<tr>
<td height="15"></td>
<td>45</td>
<td>Anthony Burgess</td>
<td>A Clockwork Orange</td>
</tr>
<tr>
<td height="15"></td>
<td>46</td>
<td>Robert A Heinlein</td>
<td>Time Enough For Love</td>
</tr>
<tr>
<td height="15"></td>
<td>47</td>
<td>Kim Stanley Robinson</td>
<td>Red Mars</td>
</tr>
<tr>
<td height="15">√</td>
<td>48</td>
<td>Daniel Keyes</td>
<td>Flowers for Algernon</td>
</tr>
<tr>
<td height="15"></td>
<td>49</td>
<td>Walter M Miller</td>
<td>A Canticle for Leibowitz</td>
</tr>
<tr>
<td height="15"></td>
<td>50</td>
<td>Isaac Asimov</td>
<td>The End Of Eternity</td>
</tr>
<tr>
<td height="15"></td>
<td>51</td>
<td>L Ron Hubbard</td>
<td>Battlefield Earth</td>
</tr>
<tr>
<td height="15">√</td>
<td>52</td>
<td>Mary Shelley</td>
<td>Frankenstein</td>
</tr>
<tr>
<td height="15"></td>
<td>53</td>
<td>Jules Verne</td>
<td>Journey to the Center of the Earth</td>
</tr>
<tr>
<td height="15"></td>
<td>54</td>
<td>Ursula K Le Guin</td>
<td>The Dispossessed</td>
</tr>
<tr>
<td height="15"></td>
<td>55</td>
<td>Neal Stephenson</td>
<td>The Diamond Age</td>
</tr>
<tr>
<td height="15"></td>
<td>56</td>
<td>Iain M Banks</td>
<td>Player Of Games</td>
</tr>
<tr>
<td height="15"></td>
<td>57</td>
<td>Peter F Hamilton</td>
<td>The Reality Dysfunction</td>
</tr>
<tr>
<td height="15"></td>
<td>58</td>
<td>David Brin</td>
<td>Startide Rising</td>
</tr>
<tr>
<td height="15">√</td>
<td>59</td>
<td>Kurt Vonnegut</td>
<td>The Sirens of Titan</td>
</tr>
<tr>
<td height="15"></td>
<td>60</td>
<td>Greg Bear</td>
<td>Eon</td>
</tr>
<tr>
<td height="15">√</td>
<td>61</td>
<td>Orson Scott Card</td>
<td>Ender&#8217;s Shadow</td>
</tr>
<tr>
<td height="15"></td>
<td>62</td>
<td>Philip Jose Farmer</td>
<td>To Your Scattered Bodies Go</td>
</tr>
<tr>
<td height="15"></td>
<td>63</td>
<td>Philip K Dick</td>
<td>A Scanner Darkly</td>
</tr>
<tr>
<td height="15"></td>
<td>64</td>
<td>Niven &amp; Pournelle</td>
<td>Lucifer&#8217;s Hammer</td>
</tr>
<tr>
<td height="15"></td>
<td>65</td>
<td>Margaret Atwood</td>
<td>The Handmaid&#8217;s Tale</td>
</tr>
<tr>
<td height="15"></td>
<td>66</td>
<td>Arthur C Clarke</td>
<td>The City and the Stars</td>
</tr>
<tr>
<td height="15"></td>
<td>67</td>
<td>Harry Harrison</td>
<td>The Stainless Steel Rat</td>
</tr>
<tr>
<td height="15"></td>
<td>68</td>
<td>Alfred Bester</td>
<td>The Demolished Man</td>
</tr>
<tr>
<td height="15"></td>
<td>69</td>
<td>Gene Wolfe</td>
<td>The Shadow of the Torturer</td>
</tr>
<tr>
<td height="15"></td>
<td>70</td>
<td>Michael Crichton</td>
<td>Sphere</td>
</tr>
<tr>
<td height="15"></td>
<td>71</td>
<td>Robert A Heinlein</td>
<td>The Door Into Summer</td>
</tr>
<tr>
<td height="15"></td>
<td>72</td>
<td>Philip K Dick</td>
<td>The Three Stigmata Of Palmer Eldritch</td>
</tr>
<tr>
<td height="15"></td>
<td>73</td>
<td>Alastair Reynolds</td>
<td>Revelation Space</td>
</tr>
<tr>
<td height="15"></td>
<td>74</td>
<td>Robert A Heinlein</td>
<td>Citizen Of the Galaxy</td>
</tr>
<tr>
<td height="15"></td>
<td>75</td>
<td>Connie Willis</td>
<td>Doomsday Book</td>
</tr>
<tr>
<td height="15"></td>
<td>76</td>
<td>Dan Simmons</td>
<td>Ilium</td>
</tr>
<tr>
<td height="15">√</td>
<td>77</td>
<td>H G Wells</td>
<td>The Invisible Man</td>
</tr>
<tr>
<td height="15"></td>
<td>78</td>
<td>Robert A Heinlein</td>
<td>Have Space-Suit &#8211; Will Travel</td>
</tr>
<tr>
<td height="15"></td>
<td>79</td>
<td>Robert A Heinlein</td>
<td>The Puppet Masters</td>
</tr>
<tr>
<td height="15"></td>
<td>80</td>
<td>C S Lewis</td>
<td>Out of the Silent Planet</td>
</tr>
<tr>
<td height="15"></td>
<td>81</td>
<td>Edgar Rice Burroughs</td>
<td>A Princess of Mars</td>
</tr>
<tr>
<td height="15"></td>
<td>82</td>
<td>Ursula K Le Guin</td>
<td>The Lathe of Heaven</td>
</tr>
<tr>
<td height="15"></td>
<td>83</td>
<td>Iain M Banks</td>
<td>Use of Weapons</td>
</tr>
<tr>
<td height="15"></td>
<td>84</td>
<td>John Wyndham</td>
<td>The Chrysalids</td>
</tr>
<tr>
<td height="15"></td>
<td>85</td>
<td>Clifford Simak</td>
<td>Way Station</td>
</tr>
<tr>
<td height="15"></td>
<td>86</td>
<td>Edwin A Abbott</td>
<td>Flatland</td>
</tr>
<tr>
<td height="15"></td>
<td>87</td>
<td>Richard Morgan</td>
<td>Altered Carbon</td>
</tr>
<tr>
<td height="15"></td>
<td>88</td>
<td>John Scalzi</td>
<td>Old Man&#8217;s War</td>
</tr>
<tr>
<td height="15"></td>
<td>89</td>
<td>Arkady &amp; Boris Strugatsky</td>
<td>Roadside Picnic</td>
</tr>
<tr>
<td height="15">√</td>
<td>90</td>
<td>Cormac McCarthy</td>
<td>The Road</td>
</tr>
<tr>
<td height="15"></td>
<td>91</td>
<td>David Brin</td>
<td>The Postman</td>
</tr>
<tr>
<td height="15"></td>
<td>92</td>
<td>John Brunner</td>
<td>Stand on Zanzibar</td>
</tr>
<tr>
<td height="15"></td>
<td>93</td>
<td>Philip K Dick</td>
<td>VALIS</td>
</tr>
<tr>
<td height="15"></td>
<td>94</td>
<td>Stanislaw Lem</td>
<td>The Cyberiad</td>
</tr>
<tr>
<td height="15"></td>
<td>95</td>
<td>James Blish</td>
<td>Cities in Flight</td>
</tr>
<tr>
<td height="15"></td>
<td>96</td>
<td>Arthur Conan Doyle</td>
<td>The Lost World</td>
</tr>
<tr>
<td height="15"></td>
<td>97</td>
<td>Julian May</td>
<td>The Many-Colored Land</td>
</tr>
<tr>
<td height="15"></td>
<td>98</td>
<td>E E &#8216;Doc&#8217; Smith</td>
<td>Grey Lensman</td>
</tr>
<tr>
<td height="15"></td>
<td>99</td>
<td>David Brin</td>
<td>The Uplift War</td>
</tr>
<tr>
<td height="15"></td>
<td>100</td>
<td>Greg Bear</td>
<td>The Forge of God</td>
</tr>
</tbody>
</table>
<p>&#8212;&#8212;&#8212;<br />
Update<br />
&#8212;&#8212;&#8212;<br />
Last minute addition: <a href="http://goodnightdune.com/index.html">Goodnight Dune</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/theblathering.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/theblathering.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/theblathering.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/theblathering.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/theblathering.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/theblathering.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/theblathering.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/theblathering.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/theblathering.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/theblathering.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/theblathering.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/theblathering.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/theblathering.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/theblathering.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=49&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://drewdillo.net/2011/04/11/49/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/61fa43fe854ccce593c9083639ad8834?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">theblathering</media:title>
		</media:content>

		<media:content url="http://theblathering.files.wordpress.com/2011/04/nerd6.jpg?w=241" medium="image">
			<media:title type="html">my brain as a young man</media:title>
		</media:content>
	</item>
		<item>
		<title>into a wall&#8230;</title>
		<link>http://drewdillo.net/2010/04/13/into-a-wall/</link>
		<comments>http://drewdillo.net/2010/04/13/into-a-wall/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 02:00:33 +0000</pubDate>
		<dc:creator>Drew</dc:creator>
				<category><![CDATA[cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cars]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[metaphors]]></category>

		<guid isPermaLink="false">http://drewdillo.net/?p=39</guid>
		<description><![CDATA[As a security geek, you no doubt hear from all the industry luminaries that security will someday built right into all technology. The metaphor doesn't make sense. This will never happen.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=39&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As a security geek, you no doubt hear from all the industry luminaries that security will someday built right into all technology. The overly used metaphor that you&#8217;ve no doubt heard in reference to this is the modern automobile: complete with seat belts and airbags.</p>
<p>The metaphor doesn&#8217;t make sense. This will never happen.</p>
<p style="text-align:center;"><a href="http://drewdillo.net/wp-content/uploads/2010/04/car_in_wall.jpg"><img class="aligncenter size-full wp-image-40" title="car_in_wall" src="http://drewdillo.net/wp-content/uploads/2010/04/car_in_wall.jpg" alt="" width="526" height="181" /></a></p>
<p>Conventional wisdom says that if a company is selling something that grossly endangers its customers, the government (or some other large external entity) will eventually step in and mandate protections. We do see signs of this: PCI and state privacy regulations as the modern day <a href="http://en.wikipedia.org/wiki/Automatic_seat_belts">seat belt</a>. But the similarities quickly end&#8230;</p>
<p>Let&#8217;s start diving into the metaphor itself: <strong>car? what car?</strong></p>
<p>In the PCI/privacy example, the car is a whole organization that is handling the end users&#8217; private information. This may be the largest element that can be held accountable to a customer, but this doesn&#8217;t really make sense. If there&#8217;s a hole in an obscure OS that&#8217;s exploited by a hack, isn&#8217;t the breach the fault of the company that provided that OS? There is a negligence factor with companies of a reasonable size not managing patches, upgrades, etc., but the scope of this problem is massive. It&#8217;s hard for most end-users to keep up with all the OS/network/hardware/application holes in their 1-3 home machines, much less massive organizations that aren&#8217;t technology focused.</p>
<blockquote><p>I realize this is a paper tiger, I don&#8217;t think this point is actually being argued, but this is where we are with enforcement today.</p></blockquote>
<p>So the cars are each product that reside in the <a href="http://en.wikipedia.org/wiki/OSI_model">OSI stack</a>? Seems to make the most sense, if any products within the stack are unsafe, the whole motorcade is in trouble. BUT&#8230; to call products that reside at all of those levels by one name is a very weak generalization.</p>
<p>Two of these &#8220;cars&#8221; would be database software and a switch. What do these cars have in common? One is pure software, designed to run atop a commercial OS; the other is primarily custom hardware with proprietary firmware. The seat belt that one might provide, embedded firewall, is quite a different animal than the other, transparent encryption. They could be unified by identity or access control, but even those require some external negotiation: another &#8220;car&#8221;. These aren&#8217;t Hondas and BMWs, they&#8217;re more like matter and energy. Attempting to regulate the two together would be extremely difficult and that regulation would be obsolete as soon as the next version of either one come out.</p>
<p>Let&#8217;s focus in a little, then: databases. The largest vendors here are either relational or warehouse-focused. To classify these database types as cars is to compare a backhoe to a formula one racer. The two are very different in function and their security mechanisms must also be very different. Just try to install TDE on your Oracle Warehouse node. I&#8217;ll wait&#8230;</p>
<p>Operating systems are no different. Windows, Linux, UNIX, mainframe, common security practices can be devised across each, but the application and reasoning behind these solutions is very different. They&#8217;re serve entirely different problem spaces. And what is an operating system automobile to a relational database automobile? A car carrier? It&#8217;s a stretch to say the least.</p>
<p>What it comes down to is regulating usage of these systems. Looking back a bit: you can&#8217;t take a formula 1 car on the road in the US. Nor can you drive a backhoe on the highway. Those vehicles aren&#8217;t regulated the same way. it wouldn&#8217;t matter if it was legal to drive it down to Wal-Mart anyway, because the car couldn&#8217;t be used the way it was designed. They would still have to drive the speed limit.</p>
<p>To that end, a car is a finite object in the eyes of the government four wheels that move seats forward between 1-80 MPH. It has to have the following with regard to safety and everything else is completely ancillary. There is no re-inventing the car, there is no new product category.</p>
<p>New product categories are created all the time in IT. Would you let your usage of ERP be driven by laws written for CRM? Would SalesForce have succeeded if it had to comply with regulations created for its&#8217; terrestrial competitors? Could you really mandate specialized certification for correct operation of the myriad systems that make up an IT shop? Good luck getting <em>any</em> startup off the ground with that rule.</p>
<blockquote><p>You can&#8217;t run your data warehouse so quickly, it&#8217;s unsafe.</p></blockquote>
<blockquote><p>You can&#8217;t use UNIX, you only have a Windows license.</p></blockquote>
<p>In the end, it comes down the mechanics running your shop. Companies have to hire generalists, because&#8211;no, they don&#8217;t have cars&#8211;they have vast, complex motor pools, roads connecting those motor pools, storage spaces, refueling stations, and have to maintain all of them. Sure we could all do a better job, but there&#8217;s a combinatorial problem with all the possible holes.</p>
<p>You can&#8217;t effectively regulate software vendors without missing the mark or killing innovation, you can punish companies for being particularly stupid with A/V or access control, but there&#8217;s no car in that oil. Old holes will still exist, new holes will be found. You don&#8217;t hear that about seat belts or airbags. And no one is actively trying to find ways to crash your car.</p>
<p>Beyond metaphors, there is a leap that security needs to make to emerge from the dark corner of the server room and into the mainstream of IT management. There is a maturity gap born of reacting, rather than anticipating the next hole&#8211;of band-aids, instead of helmets. IT system management is a discipline, but each new attack vector sends them scrabbling for gear outside established BPM. Now THAT is interesting.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/theblathering.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/theblathering.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/theblathering.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/theblathering.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/theblathering.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/theblathering.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/theblathering.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/theblathering.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/theblathering.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/theblathering.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/theblathering.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/theblathering.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/theblathering.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/theblathering.wordpress.com/39/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=39&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://drewdillo.net/2010/04/13/into-a-wall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/61fa43fe854ccce593c9083639ad8834?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">theblathering</media:title>
		</media:content>

		<media:content url="http://drewdillo.net/wp-content/uploads/2010/04/car_in_wall.jpg" medium="image">
			<media:title type="html">car_in_wall</media:title>
		</media:content>
	</item>
		<item>
		<title>tokenization, FPE, and the existence of free lunch</title>
		<link>http://drewdillo.net/2010/03/01/tokenization-fpe-and-the-existence-of-free-lunch/</link>
		<comments>http://drewdillo.net/2010/03/01/tokenization-fpe-and-the-existence-of-free-lunch/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 23:46:10 +0000</pubDate>
		<dc:creator>Drew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[aliasing]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[FPE]]></category>
		<category><![CDATA[free lunch]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[tokenization]]></category>

		<guid isPermaLink="false">http://drewdillo.net/?p=30</guid>
		<description><![CDATA[Securosis is right on a number of fronts about what you&#8217;ll see in Data Security at the RSA Conference this week. And, from the discussions I&#8217;ve been in with the analyst community recently, you&#8217;re about to be blasted with all kinds of coverage of aliasing / tokenization and format preserving encryption (FPE). Full disclosure, I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=30&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://drewdillo.net/wp-content/uploads/2010/03/freelunch.jpg"><img class="alignright size-medium wp-image-31" title="no such thing as a free lunch" src="http://drewdillo.net/wp-content/uploads/2010/03/freelunch-296x300.jpg" alt="" width="190" height="192" /></a><a href="http://securosis.com/blog/rsac-2010-guide-data-security">Securosis is right</a> on a number of fronts about what you&#8217;ll see in Data Security at the RSA Conference this week. And, from the discussions I&#8217;ve been in with the analyst community recently, you&#8217;re about to be blasted with all kinds of coverage of aliasing / tokenization and format preserving encryption (FPE).</p>
<p>Full disclosure, I do work for a company that competes in this space, but I really do have concerns about what customers are being promised and the shortfalls they may not yet understand.</p>
<p><strong>Tokenization</strong>, per Securosis:</p>
<blockquote><p>&#8230; replaces credit card numbers or other sensitive strings with random token values (which may match the credit card format) matched to real numbers only in a central highly secure database.</p></blockquote>
<p>It&#8217;s not new. Also known as &#8220;data aliasing&#8221;, Shift4 and Ingrian both offered this as a service going back as far as 2005. A number of credit card processors have also offered transaction IDs the same size/shape of credit card numbers for years. Companies I spoke with still needed, or thought they needed, credit card numbers for marketing demographic data.</p>
<p>What changed? Partially hype, partially that companies began to offer tokenization products. I do credit that hype for teaching companies their options, but, as with all hype, some of those now excited about tokenization just aren&#8217;t good candidates.</p>
<p><strong>Why it&#8217;s the best thing since sliced bread</strong>:</p>
<ul>
<li> Systems that don&#8217;t need to <em>use</em> sensitive data are taken out of PCI audit scope. Though, per the latest <a href="http://www.elementps.com/about-us/news/pdf-articles/PCI-SSC-Issues-Statement-On-Scope-of-Encrypted-Data-via-FAQ-10359.pdf">PCI FAQ</a>, a system strongly encrypted (read: entry point for FIPS in PCI), is also out of scope for PCI audits.</li>
<li>Sytems can pass around data without expanding data types to hold expanded ciphertext. There are a number of encryption modes that perserve data <em>length</em>, but who is to say that the resulting ciphertext won&#8217;t contain a character a system can&#8217;t handle (string terminator, etc)?</li>
<li>Systems may continue to use sensitive data as <a href="http://www.pcmag.com/encyclopedia_term/0,2542,t=primary+index&amp;i=49667,00.asp">primary indices</a>. This is more common for SSNs or tax IDs, which is why a lot of tokenization deployments actually begin with HIPAA or SOX compliance.</li>
</ul>
<p><strong>Why it&#8217;s worst thing since Windows Vista</strong>:</p>
<ul>
<li>This free lunch is more expensive than most. Think about it: if just one of your applications starts speaking tokens, while all others are speaking credit card numbers, the whole house of cards falls. Meaning, there is no piecemeal deployment. All systems must be changed at once, a level of coordination I have rarely seen in the enterprise.</li>
<li>This may change with some of the transparent database encryption vendors making inroads, but today, also per Securosis:<br />
<blockquote><p>No matter what anyone tells you, there are always requirements for application and database changes, but some of these approaches can minimize the pain.</p></blockquote>
</li>
</ul>
<p><strong>FPE</strong>, per Rich again:</p>
<blockquote><p>Format Preserving Encryption encrypts the numbers so you can recover them in place, but the encrypted values share the credit card number format.</p></blockquote>
<p>That&#8217;s a little high level for we tech weenies. Proponents of FPE bill it as a mode of AES that returns data of the same input type (ASCII, numeric, etc.) and the same byte-length as the input.</p>
<p>There&#8217;s a lot of interesting thought behind how this works, but no magic. If you decrease the number of inputs to a certain function, you can decrease the size of the resulting vector space by the same amount. This is legal in math and thus crypto.</p>
<p>In a wild oversimplification: a function can be found f(x), such that for values of x only being 16 bytes within the ASCII numeric range, the output y will also be within the 16 byte ASCII numeric range.</p>
<p><strong>Why it&#8217;s the best thing since sliced bread</strong>:</p>
<ul>
<li>The same pluses, generally, as tokenization. Note that, unless your auditor finds FPE to be in the &#8220;strong encryption&#8221; bucket, per the new FAQ, FPE <strong>does not</strong> remove systems from audit scope.</li>
<li>&#8220;Local&#8221; options are much cleaner than tokenization. Libraries that can receive AES keys and operate remotely, POS, etc., can perform FPE autonomously for extended periods of time very easily.</li>
</ul>
<p><strong>Why it&#8217;s worst thing since Windows Vista</strong>:</p>
<ul>
<li>The same drawbacks as tokenization, there&#8217;s a large coordination/conversion effort that requires all hands on deck.</li>
<li>Some FPE AES modes are &#8220;under review&#8221; by NIST, for what that&#8217;s worth, but there is yet no standard. Meaning, the FPE you buy today may be different if/when these mode finally get approved. Or they may never be approved at all and vendor lock-in could be painful to pull out of.</li>
<li>Combinatorially speaking, decreasing the vector space to ASCII or, more so, to numeric values of ASCII, means a much smaller number of possible outcomes. Anyone attempting to crack AES CBC may have a leg up knowing that the input is a credit card and will thereby be limited to numeric ASCII, but limiting the output would seem to raise the odds of collision yet higher.</li>
<li>FPE has the same key rotation complications of regular encryption. The matter is even worse in FPE land, where these values may be all over the place and rotating them en masse means a repeat of the intial roll out for each rotation. As long as PCI requires six month to a year rotations, this is a big problem.</li>
</ul>
<p>We hear it all the time now. Mom and Pop shops calling us up and asking about tokenization/aliasing or FPE, when all they have is one Oracle database. Each definitely serve a need, but do go into each with your eyes open. They&#8217;re not quick fixes and there ain&#8217;t no such thing as a free lunch.</p>
<p>See you at the conference.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/theblathering.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/theblathering.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/theblathering.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/theblathering.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/theblathering.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/theblathering.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/theblathering.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/theblathering.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/theblathering.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/theblathering.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/theblathering.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/theblathering.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/theblathering.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/theblathering.wordpress.com/30/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=30&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://drewdillo.net/2010/03/01/tokenization-fpe-and-the-existence-of-free-lunch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/61fa43fe854ccce593c9083639ad8834?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">theblathering</media:title>
		</media:content>

		<media:content url="http://drewdillo.net/wp-content/uploads/2010/03/freelunch-296x300.jpg" medium="image">
			<media:title type="html">no such thing as a free lunch</media:title>
		</media:content>
	</item>
		<item>
		<title>cloud security: wait for trust or trust can&#039;t wait</title>
		<link>http://drewdillo.net/2010/02/11/cloud-security-wait-for-trust-or-trust-cant-wait/</link>
		<comments>http://drewdillo.net/2010/02/11/cloud-security-wait-for-trust-or-trust-cant-wait/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 05:25:33 +0000</pubDate>
		<dc:creator>Drew</dc:creator>
				<category><![CDATA[cloud]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://drewdillo.net/?p=28</guid>
		<description><![CDATA[Cloud technology, it&#8217;s only up from here. Gartner&#8217;s predictions may be wild, but they&#8217;re not wrong to think BIG when they talk about cloud technology and it&#8217;s impact on every aspect of IT. For those in the vendor space, cloud is another disruptive technology. Disruption is, as always, both opportunity and risk. Can the vendor [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=28&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="silver lining" src="http://www.ucar.edu/communications/staffnotes/0510/images/silverlining.jpg" alt="silver lining" width="346" height="237" />Cloud technology, it&#8217;s only up from here. <a href="http://www.cw.com.hk/content/gartner-20-percent-businesses-will-own-no-it-assets-2012">Gartner&#8217;s predictions</a> may be wild, but they&#8217;re not wrong to think BIG when they talk about cloud technology and it&#8217;s impact on every aspect of IT.</p>
<p>For those in the vendor space, cloud is another disruptive technology. Disruption is, as always, both opportunity and risk. Can the vendor capitalize faster than their longstanding competitors? Will new competitors emerge with tighter focus? Will they move quickly enough to keep drinking their own milkshake?</p>
<p>Cloud security is three levels of disruption:</p>
<ol>
<li>Enabling security for liftoff &#8211; making companies comfortable with the idea that their data is everywhere.</li>
<li>Managing security from the cloud &#8211; enabling security on premise and in the cloud with the redundancy, availability, flexibility of the cloud.</li>
<li>Blow it out &#8211; securing the unique collaborative capabilities of the cloud, protection in a world where the <a href="http://www.opengroup.org/jericho/">walls have fallen</a>.</li>
</ol>
<p>None of this is new or proprietary. If you are a security vendor and your company isn&#8217;t thinking like this, it&#8217;s too late. Start looking for acquisition targets.</p>
<p>The one question that does stick out in my mind, particularly in security: even if the tech is cool, will companies trust cloud-based startups to perform tasks that they already have vendors for on premise? Essentially, what&#8217;s the stickiness of on premise trust with all the pressure to move into the cloud. How much time will on-premise vendors be given to get their cloud act together?</p>
<p>I suspect I know the answer, that it will depend on how deeply ingrained a product is in an organizations&#8217; line of business or how hard it would be to strip out. This disruption, however, is still too soon to call. Too early to guess where the killer app will come from.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/theblathering.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/theblathering.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/theblathering.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/theblathering.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/theblathering.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/theblathering.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/theblathering.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/theblathering.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/theblathering.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/theblathering.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/theblathering.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/theblathering.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/theblathering.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/theblathering.wordpress.com/28/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=28&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://drewdillo.net/2010/02/11/cloud-security-wait-for-trust-or-trust-cant-wait/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/61fa43fe854ccce593c9083639ad8834?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">theblathering</media:title>
		</media:content>

		<media:content url="http://www.ucar.edu/communications/staffnotes/0510/images/silverlining.jpg" medium="image">
			<media:title type="html">silver lining</media:title>
		</media:content>
	</item>
		<item>
		<title>terrestrial</title>
		<link>http://drewdillo.net/2009/11/24/terrestrial/</link>
		<comments>http://drewdillo.net/2009/11/24/terrestrial/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 05:54:59 +0000</pubDate>
		<dc:creator>Drew</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[terrestrial]]></category>

		<guid isPermaLink="false">http://drewdillo.net/?p=21</guid>
		<description><![CDATA[It may never pass the first stage of Schopenhauer&#8217;s truth, but here is my small contribution to the world of cloud computing: terrestrial &#8211; physical IT infrastructure, housed on premise by an enterprise I was actually laughed at the first time I used it, but I see a clear logic in extension of the cloud [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=21&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-22" title="grandpa_simpson_yelling_at_cloud" src="http://drewdillo.net/wp-content/uploads/2009/11/grandpa_simpson_yelling_at_cloud-300x225.jpg" alt="grandpa_simpson_yelling_at_cloud" width="249" height="187" />It may never pass the first stage of <a href="http://www.brainyquote.com/quotes/quotes/a/arthurscho103608.html">Schopenhauer&#8217;s truth</a>, but here is my small contribution to the world of cloud computing:</p>
<blockquote><p>terrestrial &#8211; physical IT infrastructure, housed on premise by an enterprise</p></blockquote>
<p>I was actually laughed at the first time I used it, but I see a clear logic in extension of the cloud metaphor to describe the classic data center. It&#8217;s a paradigm shift to describe complex systems this way, certainly, but it&#8217;s a forceful description of the market today to say that the state of IT technology is bound to the earth.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/theblathering.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/theblathering.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/theblathering.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/theblathering.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/theblathering.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/theblathering.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/theblathering.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/theblathering.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/theblathering.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/theblathering.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/theblathering.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/theblathering.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/theblathering.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/theblathering.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=21&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://drewdillo.net/2009/11/24/terrestrial/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/61fa43fe854ccce593c9083639ad8834?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">theblathering</media:title>
		</media:content>

		<media:content url="http://drewdillo.net/wp-content/uploads/2009/11/grandpa_simpson_yelling_at_cloud-300x225.jpg" medium="image">
			<media:title type="html">grandpa_simpson_yelling_at_cloud</media:title>
		</media:content>
	</item>
		<item>
		<title>In search of the next no-brainer&#8230;</title>
		<link>http://drewdillo.net/2009/10/21/in-search-of-the-next-no-brainer/</link>
		<comments>http://drewdillo.net/2009/10/21/in-search-of-the-next-no-brainer/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 06:09:42 +0000</pubDate>
		<dc:creator>Drew</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[endpoint]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[no-brainer]]></category>

		<guid isPermaLink="false">http://drewdillo.net/?p=18</guid>
		<description><![CDATA[There comes a time in every market where the tables turn, the clouds part, the wave crashes, the metaphors mix, and the sales process goes from an uphill battle to Olympic slalom.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=18&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-19" title="hokusai_wave_1" src="http://drewdillo.net/wp-content/uploads/2009/10/hokusai_wave_1-300x201.jpg" alt="hokusai_wave_1" width="273" height="183" />There comes a time in every market where the tables turn, the clouds part, the wave crashes, the metaphors mix, and the sales process goes from an uphill battle to Olympic slalom. Typically, this is also a time of convergence in the market, the best-fed fish eat the smaller ones and sharks from a completely different food chain start eying them.</p>
<p>In the security market, we have seen two forces that drive this:</p>
<ol>
<li>A problem becomes so easy to solve that it&#8217;s virtually painless &#8212; labor or product-wise, it&#8217;s all money at the C-level, the problem just becomes cheaper to solve than it does to live with</li>
<li>A problem becomes so widespread that a company would be grossly negligent for <em>not</em> doing something about it</li>
</ol>
<p>In essence, the product becomes a no-brainer.</p>
<p>This wave has crashed a number of times in security: antivirus, firewalls, full disk encryption, to name a few. Some would say DLP, but I would argue that DLP is a foundational technology that really only answers half of a problem.</p>
<p>Sometimes the wave never crashes. Email encryption, for example, has bumped along for a decade, but never really exploded. Why? Email is terrifyingly insecure and holds yottabytes of the most sensitive information. But email protection just never became easy. No one ever created a #1 to balance out the #2. Some CISOs drove it through and slapped it in bold letters on their resume, but it&#8217;s not a no-brainer.</p>
<p>Disk encryption, particularly mobile disk encryption, was the complete opposite. It was weakly mandated at first, still an uphill battle to sell, but <a href="http://www.cnn.com/2009/POLITICS/01/27/va.data.theft/index.html">case</a> after <a href="http://www.theregister.co.uk/2009/05/28/pension_data_breach_alert/">case</a> after <a href="http://www.forbes.com/2006/09/06/laptops-hall-of-shame-cx_res_0907laptops.html">case after case after case</a> built up a powerful #2. And at that point, about two years ago, the products were at a point of maturity to make #1 true as well. Wave, convergence and now the market hangs around $250 million with a healthy rate of growth.</p>
<blockquote><p>Where&#8217;s the next wave?<br />
What&#8217;s the next no-brainer?<br />
And how will it be strapped to the hot air balloon to the cloud?</p></blockquote>
<p>It will be hard to recognize those today, likely they are rough, not simple enough to satisfy #1. And CIOs have likely used some other technology to give themselves a false sense of security for #2.</p>
<p>Ever more atomic data protection at ever increasing levels of specificity, with less and less impact to IT practices and end-user experience. That&#8217;s the mantra here on earth and in the cloud.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/theblathering.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/theblathering.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/theblathering.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/theblathering.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/theblathering.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/theblathering.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/theblathering.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/theblathering.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/theblathering.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/theblathering.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/theblathering.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/theblathering.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/theblathering.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/theblathering.wordpress.com/18/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=18&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://drewdillo.net/2009/10/21/in-search-of-the-next-no-brainer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/61fa43fe854ccce593c9083639ad8834?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">theblathering</media:title>
		</media:content>

		<media:content url="http://drewdillo.net/wp-content/uploads/2009/10/hokusai_wave_1-300x201.jpg" medium="image">
			<media:title type="html">hokusai_wave_1</media:title>
		</media:content>
	</item>
		<item>
		<title>security, compliance and the industry in between</title>
		<link>http://drewdillo.net/2009/10/14/security-compliance-and-the-industry-in-between/</link>
		<comments>http://drewdillo.net/2009/10/14/security-compliance-and-the-industry-in-between/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 06:49:36 +0000</pubDate>
		<dc:creator>Drew</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://drewdillo.net/?p=9</guid>
		<description><![CDATA[There is always a lot of finger-pointing at compliance mandates and their application. They are not, as their critics often cite, &#8220;real&#8221; security. Real security is an abstract land where authentication is an ever-evolving heuristic dance, internal networks are impenetrable walls of malevolent retribution, every atomic element is encrypted within a FIPS Level 4 module [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=9&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-14" title="Security" src="http://drewdillo.net/wp-content/uploads/2009/10/Security-300x224.jpg" alt="Security" width="239" height="179" />There is always a lot of finger-pointing at compliance mandates and their application. They are not, as their critics often cite, &#8220;real&#8221; security. Real security is an abstract land where authentication is an ever-evolving heuristic dance, internal networks are impenetrable walls of malevolent retribution, every atomic element is encrypted within a FIPS Level 4 module and is only visible to users who absolutely need to see it that particular second, and only exists in the mind of ubergeeks and cryptography professors.</p>
<p>In the real world, the data being so rigorously protected in the above scenario becomes either so locked down as to become completely unusable or the staff required to maintain this level of security is so large as to drive a company into the ground. All this in the name of protecting the information assets that drive business.</p>
<p>On the other end of the spectrum isn&#8217;t compliance, it&#8217;s business. In business land every piece of information is available when needed, calculations and different views of information can be pulled from hundreds of millions of sources instantly, and your level of efficiency is a product you can sell. Business land built up some meager defenses, maybe even raised a militia, but they are instantly bowled over at the slightest hindrance of business.</p>
<p>This one isn&#8217;t hypothetical, it&#8217;s where most companies are:</p>
<blockquote><p>Why would I protect a customer&#8217;s confidential information? It might take seconds out of my response time. Maybe I&#8217;ll put controls around this piece of information, after all, if a competitor got everyone&#8217;s email addresses they might steal all my customers!</p></blockquote>
<p>That was the state of information security in the 90s, that&#8217;s the state of Data Protection in the late 00s. Bare minimum, protect the business as long as you don&#8217;t even slightly impact the business.</p>
<p>Now, this isn&#8217;t anything new. Risk Management is an old discipline and many attempts have been made to tie security risk management to ROI. <a href="http://www.google.com/search?hl=en&amp;q=return+on+security+investment">ROSI</a> has long been a byword among security architects, but the numbers always come out too high to be credible, even when <a href="http://www.boston.com/business/globe/articles/2007/08/15/cost_of_data_breach_at_tjx_soars_to_256m/">true</a>.</p>
<p>From the vendor perspective, every security company wades into this quagmire thinking, &#8220;We can do this, we can be the company that makes the case for security.&#8221; They put together 10 fear slides to scare the bejeebus out of the customer, slap on an architecture diagram and lose the prospect in the first five minutes. That is not to say the fear approach always fails, but the vast majority of the time, one little vendor can&#8217;t bridge the divide between security and business.</p>
<p>Businessland&#8217;s laissez-faire attitude toward security is destructive though, eventually another entity has to step in with regulation. Regulation has three goals:</p>
<ol>
<li>Helping we little guys &#8212; rare</li>
<li>Protecting a bigger fish in the pond &#8212; do-as-I-say-not-as-I-do regulation</li>
<li>Preventing legal action that could burden the legal system or cause a massive industry collapse</li>
</ol>
<p>Regulatory compliance isn&#8217;t security. It&#8217;s insurance against the wildest reaches of negligence. It&#8217;s justice for those security architects that can&#8217;t seem to convince the CFO that the sky is falling.</p>
<blockquote><p>Give us your tired, your huddled IT security masses, yearning to segment their networks&#8230;</p></blockquote>
<p>Compliance isn&#8217;t security in the same way that the local police department isn&#8217;t security. It&#8217;s a baseline intended to prevent chaos. And compliance done right is a baseline for building out a higher level of overall security.</p>
<p>As a vendor, this is a completely different conversation. Compliance is a business driver, so budget flows for compliance in ways it never will for security fear sales. And, beyond cynical business concerns, compliance gives vendors the opportunity to actually help a customer by making a real tactical impact on the bottom line. There&#8217;s also a chance here to be emissaries for Securityland, knocking down some of the fear that security is going to bring business to a halt. But that&#8217;s a topic for another time.</p>
<p>And all of this is not to say compliance is perfect. Compliance mandates sometimes adopt baffling requirements from Securityland.</p>
<blockquote><p>Is a brute force collision against a significantly-random AES256 key really the most likely attack vector?</p></blockquote>
<p>But if applied correctly, and I will call out PCI DSS in particular, they go a long way toward business-proofing a company&#8217;s security posture.</p>
<p>If I were to put forth one complaint about compliance, it would be the method of application. Auditing of compliance varies between auditing companies and even among team leads at the same company. I have worked with customers whose auditors say that they need to see source code on all data protection products to verify secure key transmission and storage and other companies where simply buying a data protection product earned the organization a one year pass.</p>
<p>The blame of uneven compliance application doesn&#8217;t fall solely to the QSAs, Businessland asserts itself again in selection of auditors. One popular auditing company in the US has had trouble overseas, where they are seen as being too strict. I won&#8217;t pretend to know the answer of how best to audit the auditors, ideally this is built into the regulation itself, either being more prescriptive or adding a periodic check on audit results.</p>
<p>Compliance is an easy target for blame, especially when you&#8217;re in a CNN moment breach, but you don&#8217;t get very far blaming the police for the theft of your unlocked car. Use the regulations, use the business case of compliance, use the auditors findings, use vendors who understand security, business, and compliance, and build toward real data protection. IT risk management may never catch on at the c-level, but compliance is an easy and achievable baseline for limiting risk and doing so with business owners&#8217; buy-in.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/theblathering.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/theblathering.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/theblathering.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/theblathering.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/theblathering.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/theblathering.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/theblathering.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/theblathering.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/theblathering.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/theblathering.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/theblathering.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/theblathering.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/theblathering.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/theblathering.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=9&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://drewdillo.net/2009/10/14/security-compliance-and-the-industry-in-between/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/61fa43fe854ccce593c9083639ad8834?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">theblathering</media:title>
		</media:content>

		<media:content url="http://drewdillo.net/wp-content/uploads/2009/10/Security-300x224.jpg" medium="image">
			<media:title type="html">Security</media:title>
		</media:content>
	</item>
		<item>
		<title>convergence</title>
		<link>http://drewdillo.net/2009/08/29/convergence/</link>
		<comments>http://drewdillo.net/2009/08/29/convergence/#comments</comments>
		<pubDate>Sat, 29 Aug 2009 05:57:43 +0000</pubDate>
		<dc:creator>Drew</dc:creator>
				<category><![CDATA[Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[virii]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://drewdillo.net/?p=5</guid>
		<description><![CDATA[It so happened two months ago, that I was sitting around considering my online persona, my line of work, and the volume of writing I had done under a nom de plume. I hadn&#8217;t blogged in months, work having taken over the late evening timeslot I used for blogging, and I decided to try to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=5&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="virus" src="http://www.healthinitiative.org/IMAGES/virus_big.jpg" alt="" width="171" height="164" />It so happened two months ago, that I was sitting around considering my online persona, my line of work, and the volume of writing I had done under a nom de plume. I hadn&#8217;t blogged in months, work having taken over the late evening timeslot I used for blogging, and I decided to try to tap something out.</p>
<p>BOOM!</p>
<p>Badware alert!</p>
<p>Google says that my site is dangerous and I should connect at my own risk. In the WordPress/malware arms race, I was the USSR. The system was totally hosed, I tried reloading the WordPress file structure a dozen times, but each time, the rogue iFrame would sneak back in and Google would get pissy with me again. All this work and I hadn&#8217;t written a darn thing.</p>
<p>Being a security professional, a software security professional, this ordeal stung on a number of levels. I didn&#8217;t even really want to keep writing under another name, I just wanted to beat the virus. Finally, I gave in to both impulses, I launched this blog, tied to my real life human name and blew away all the files from the old blog.</p>
<p>So, here we are. I, Drew Dillon, will use this space to write about the things I know and probably still blather about things I have no expertise in.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/theblathering.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/theblathering.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/theblathering.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/theblathering.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/theblathering.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/theblathering.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/theblathering.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/theblathering.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/theblathering.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/theblathering.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/theblathering.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/theblathering.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/theblathering.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/theblathering.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=drewdillo.net&amp;blog=82330&amp;post=5&amp;subd=theblathering&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://drewdillo.net/2009/08/29/convergence/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/61fa43fe854ccce593c9083639ad8834?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">theblathering</media:title>
		</media:content>

		<media:content url="http://www.healthinitiative.org/IMAGES/virus_big.jpg" medium="image">
			<media:title type="html">virus</media:title>
		</media:content>
	</item>
	</channel>
</rss>
