Showing posts with label f5networks. Show all posts
Showing posts with label f5networks. Show all posts

Sunday, March 7, 2010

My 2010 RSA Conference & Kaminsky Interview

logorsa I hung out at the 2010 RSA Conference last week and wanted to  share some observations from the show.  Rain early in the week reminded me of why the organizers moved it later in the Spring the past couple years but the sky’s cleared and the remainder of the week, we got the nice, crisp, sunny Bay Area weather.  F5 decided not to exhibit this year but we did attend in full force, meeting with analysts and customers along with focusing our video camera on partners and doing a Partner Spotlight Week at RSA.  It was kinda fun to attend as a typical participant. 

I got there around 11am on Tuesday, just as the Expo floor was opening.  I easily got my badge without any delay.  I remember the long lines a few years ago when we all gathered in the main entrance.  They’ve improved the check-in process over the years but I’m also guessing most attendees got their badges on Monday.  Met with some F5’ers between analyst meetings, saw a very cool demo of our BIG-IP Edge Gateway Client solution and made my way to the Expo floor.  All the usual companies were displaying their wares but I’m always amazed by all the company names I’ve never heard of along with lots of color companies – Blue that, Red this, Black the other thing.  There were many ‘systems management’ companies and a whole ton of ‘token’ companies.  I even overheard another attendee mention how many token companies there were.  And of course, Cloud.  Everyone’s got some ‘cloud’ solution, even those who really do nothing in the cloud, except maybe store your info, added ‘cloud’ to their signage.  I don’t have any official attendance numbers but it did seem a bit fuller this year verses last. 

Since we didn’t have a booth, I decided to do a ‘Partner Spotlight Week at RSA’ shooting video segments of the various F5 partners at the show.   Something I’ve been thinking about for a while and with many all in one place, it made the task easy.  Every partner was very accommodating and excited to participate.  The basic premise would be, introduce the company – talk about the integration both technically and business wise – then show a quick demo if one was available.  Even with short notice (most I just walked up to and asked on the spot) they were very engaging and all were done in a single take.  I want to thank Splunk, Layer 7 Technologies, OPSWAT and Secure Passage.  Great job guys!

The highlight of my week came on Thursday.  F5 and Infoblox will be offering a Webinar on March 10th called DNSSEC: Compliance is Easier than You Think.  I was lucky to get one of the webinar speakers, Dan Kaminsky, Director of Penetration Testing at IOActive (and the guy who exposed the serious DNS vulnerability, DNS Cache Poisoning) who was gracious to participate in an interview with me – and boy what an experience!  We talked all about the DNS infrastructure including how DNS works, his discovery, DNSSEC and many other interesting topics.  What I thought would be a quick 5 minute chat turned into a full blown half hour conversation about many things Internet related.  Great stories about the discovery and some of the challenges he faced along the way.  It was awesome – thanks so much Dan – good times!!

The Videos

ps

Technorati Tags: Pete Silva,F5,security,application security,network security, business, banks, education, economy, technology, blogging, blogs, social networking, dnssec, dns, kaminsky, webinar, video, partners

Digg This

Friday, February 19, 2010

F5 Web Media On-Demand

We’ve had some exciting announcements of late, like the BIG-IP Edge Gateway and the BIG-IP LTM VE, and lots of great content has been developed to highlight the benefits of these solutions.   It’s been a while since I’ve updated you about our Social Media sites and the various ways we deliver F5 content.   More than a year ago, we started to follow and contribute text, audio and video to the multitude of public Social Media outlets.  DevCentral has always been our social, community driven site, well before some of these newer social networks but we also recognized the need to engage with the various communities on the internet.  What started out as experiment, especially the Audio Whitepapers, multi-media has now become a mainstay of the various forms of F5 content offered, allowing you to get the latest from F5, anytime and anywhere.

Recent Videos

 

Recent Audio White Papers

 

F5 Networks Social Media & Content Sites

 

Thanks for reading, listening and watching.  If there is anything you’d like to see, let us know!!

ps

Technorati Tags: F5, BIG-IP, v10.1, Edge Gateway, Pete Silva, security, application security, network security, blogging, blogs, social networking

Digg This

Tuesday, February 9, 2010

Security - Still in the Driver’s Seat

A couple recent surveys reveal that for 2010, Security is back at the top of IT’s focus.  It seemed for a while there that Cloud Computing was starring in most questionnaires that asked about future IT spending plans.  If you remember, Security was still riding shot-gun slamming on the imaginary brakes in the passenger seat.  ‘Hey Cloud, You still can’t turn down that alley without my presence,’ Security would constantly nag from the navigator position.  Don’t get me wrong, Cloud Computing is still a powerful IT resource but according to a recent Infonetics survey,
Security upgrades, both for IT security and physical security, was the #1 change named by respondent organizations when asked what major changes they planned for their data centers over the next two years……For those who are expecting ‘the cloud’ to be a savior of the IT industry, our study is a bit of a reality check: while there is some interest in cloud-based services, particularly on the software side, the majority of respondents have no concrete plans for it. Virtualization is the more important trend and technology, as it is a critical tool for organizations to make their infrastructure more efficient and manageable,” advises Matthias Machowinski.
It’s not that Security ever took a back seat, it’s just many enterprises had to take a hard look, investigate new options and make difficult decisions over the last year on where to invest IT resources.  Unfortunately, it doesn’t seem like crooks ever need to get budget approval and continued their daily system onslaughtWhile credit cards and SSNs are still top targets, stealing Carbon Credits is the new bounty for the criminal element.  Were they just being eco-friendly?  Not in the least.  The 250,000 carbon credit permits that were taken are worth more than $4 million and was resold, probably to an unsuspecting buyer.

The Enterprise Strategy Group also released a Research Brief on the 2010 Networking Spending Trends and here too, Security took top prize.
ESG 2010 survey

Health care, financial services and federal government all indicated that they will be spending more on network hardware with 82% of financial services organizations saying they will increase network hardware spending in 2010.  What is also interesting about the ESG survey is of the Education respondents, only 38% will be increasing Network Security spending but 70% of them will be investing in Wireless LAN equipment.  To me, securing your WLAN should be part of the overall Network Security plan.  Hopefully folks remember that when all those SSID’s suddenly start broadcasting.

Security is something we strive for in many areas of our lives and at least on the corporate IT front, it looks to be a major area of focus this year.
ps

Technorati Tags: Pete Silva,F5,security,application security,network security, business, banks, banking, education, economy, technology
Digg This

Wednesday, February 3, 2010

Consolidate and Dedicate to Eradicate

Whether it be due to cloud computing, last year’s economic mess, or just the general cyclical nature of the Tech Industry, Consolidation has been a huge focus of IT departments of late.  Data Center consolidation, hardware consolidation, staff consolidation and tech sector consolidation to name a few.  I remember the days of single purpose boxes that did one thing well.  In fact, a decade ago at Exodus, that was one of my positioning points for BIG-IP over such LB units as Alteon, ArrowPoint and LocalDirector since they were switched/hardware-based appliances.  I’d say something like, ‘It’s a Floor Wax and a Dessert Topping while the BIG-IP is software based, focused only on Load Balancing.’  Boy, times have changed.

Single purpose appliances, while still big business for their particular specialty,  are becoming fewer and fewer – just look at the handheld your using.  The printer was one of the first to go that route becoming printer/copier/fax/scanner in an effort to make them more useful and appealing to the customer.  Ads tout, ‘No more bulky equipment to buy – it’s all here in this great new thing that you must have!!  All for the incredibly low price of…..’  IDS graduated to IPS and now we have IDPS units and UTM (Unified Threat Management) systems or the Next-Gen Firewalls.  They have firewall, anti-virus, spam controls, web filter, IDS and more.  We are in a multi-task society and expect our devices to behave the same.  For a while, adding more and more functionality to a piece of IT equipment would either slow it to a crawl or make it very difficult to troubleshoot.  The processing power available today allows multi-function appliances to dedicate resources to ensure all the functions run smoothly.

dashboard Having multiple point solutions, interfaces and GUIs also makes it difficult to manage the various entities, especially if it’s a security device.  Managing multiple points of entry and enforcing a consistent security policy across the board can be challenging.  You got users connecting and requesting application access via VPN, some over the air on Wireless and others hooked right to the LAN.  They also are probably using various types of computing devices; from IT issued laptops, to home/personal machines to mobile devices.  You might have a specific policy for each type of access method/device or you enforce the same security, no matter what the connection.  Why wouldn’t you do a host check on LAN users similar to the scrutiny your remote users must pass?  In many cases, that might involve a NAC type controller and I thought we were trying to reduce the number of power suckers in the data center.  Today, IT needs a single management interface and policy enforcement point that’s easy to navigate and quick to deploy.  During a crisis, like a potential intrusion or breach, you can waste precious time trying to get to all the different appliances to assess the situation.

As consolidation continues, and more functionality is added to these multi-dedicated appliances, management of such an infrastructure especially if it’s part of a cloud, will continue to be an important driver for IT.  So, as you consolidate and are able to dedicate, that will enable you to eradicate costs, multiple management interfaces, multiple point products and with the right device, eradicate many of the threats that appear every day, the CDE way!

ps

Related resources:

External articles:

 

Technorati Tags: F5,BIG-IP,v10.1,Edge Gateway,WOM,application delivery,Pete Silva,F5,security,application security,network security

Digg This

Tuesday, January 26, 2010

The State of My Blog Address

Readers, distinguished bloggers, various feeds - A year ago this week, I crossed over into double-digit blog entries (a whopping 10 stories at the time but a relative blog newcomer) and was wondering what magical rant would make this Blog Go to Eleven.  Fidgeting with the keyboard and watching the blinking curser as nothing came to mind, I decided to dedicate January 30th as ‘Blog About Your Blog Day.’   The day that all bloggers would share stories, tips and other musings about their own blog.  Since I don’t see it as a #trendingtopic on Twitter, it might not have stuck.  Annual rituals often need a few years to take, so here’s the State of My Blog address in honor of my own made up writing holiday.


Last week, my good buddy Michael Sheehan of GoGrid (@HighTechDad on Twitter) wrote about the detailed process he goes through when creating a blog post.  I gotta give him credit for both having a process and actually documenting it since I typically just see a topic/story, fire up Live Writer and tap away.  Often stories come to mind while I’m walking the dog the evening before I post.  I think it has to do with clearing my mind of all the day’s clutter and suddenly it’s like, ‘There it is!!.’  I’ll get home, quickly jot some notes or create a title, sleep on it and write it the next day.  This was one of them.  I typically try to post at least once a week and it’s usually around mid-week.  This blog talks about how Thursday is the best day to post and this one backs it up with some statistical charts.  I’ve read a couple that indicate that Monday’s are not great since everyone is getting back into the work routine, at least for business blogs.  And speaking of Personal vs. Business blogs – Michael’s entry describes his method for personal blogs.  I really don’t have a ‘personal’ blog since most, if not all, my entries are work related and published on F5’s DevCentral.  I do feed WordPress, Ulitzer, Blogger, Posterous and others for greater coverage but our DevCentral community is my main audience.   Even with a business blog, I do tend to incorporate personal stories since what I do as a career does mix with who I am as a person.  I still remember years ago when I worked at the Milwaukee Repertory Theater an Art Director saying, ‘I am not my art!’  Always thought that was funny but interesting.
 
Even though this is a F5 branded blog, I do try to keep it focused on technology, trends, ideas and other industry topics instead of a ShamWow ad for BIG-IP.  Most of our readers are familiar with BIG-IP (and learning about the new BIG-IP Edge Gateway announced this week) and I just like to compliment what they already know, offer some new ideas or bring attention to market/technology trends and how F5 solves some of these.  Nothing too technical, security focused, a bit of humor, some personal insight and our daily lives – that’s the State of My Blog 2010.  How about yours?

And here are a few other stories I considered writing about this week:
Until next time…
ps


Technorati Tags: Pete Silva,F5,security,application security,network security,blogging,blogs
Digg This

Monday, January 18, 2010

Cybercrime, the Easy Way

The Dummies series is a great collection of ‘How to’ instructions on a wide array of topics and while they have not published a ‘Cybercrime for Dummies®’ booklet (and don’t think they will), DYI Cybercrime Kits are helping drive Internet attacks.  Gone are the days when you had to visit a dark alley to get a crook’s cookbook.  You don’t need to be an expert or tied to some sophisticated crime ring but now you can infect, spam, phish and generate other dastardly deeds with the best of them.  Similar to downloading and using iTunes, P2P applications, IM services, Skype and others to accomplish those specific tasks, you can get a Cybercrime toolkit to go with your black ski mask, getaway car and evil lair hideout.  You don’t really need any technical knowledge since all you do is install the program, tell it what you want, customize the message, send the infection and wait for the program to tell you when you’ve hit gold.  The early ‘hacking’ sites like www.2600.com or www.L0pht.com use to allow you to download your favorite virus to send to friends.  Granted, many organizations used their malicious code to test their own systems and they’ve since become more industry friendly and still provide great insight into the ‘black-hat’ing’ community.  I’ve even used L0phtcrack several times over the years.  Remember, downloading a root kit isn’t necessarily a crime, it’s what you do with it that might be.
The initial data breach numbers for 2010 are already staggering.  In just a couple weeks, around 1,233,432 records have already been breached according to Privacy Rights Clearinghouse – that’s an average of over 68,000 a day.  During 2009, Panda Labs saw a 77% increase in banking theft Trojans compared to 2008 which directly corresponded with the increase in available kits.  As this trend continues, the ‘Kids with Kits’ will be competing with the ‘Established Mobs’ for your passwords, money, identity and any other valuable items/info to sell or use themselves. 
Certainly, users need to be extra vigilant when receiving suspicious emails with ‘Click Here:’ boldly pronounced and organizations need to realize that their systems will be poked, prodded and tapped even more this year.  On the web facing front, deploying a Web Application Firewall, like BIG-IP ASM, not only protects against the typical, well known attacks like SQL Injection, DoS, Brute Force and Web Scraping; but can also help with identifying that bad-boy with IP Geolocation and ASM has always helped to keep you compliantBIG-IP GTM v10.1, with the new DNSSEC feature, secures your web property against DNS Cache Poisoning and other malicious redirects.  The FirePass SSL VPN and other BIG-IP products offer End Point inspection to ensure that the requesting host abides by your security policy prior to gaining access and Encryption to keep the traffic secure.  The BIG-IP MSM takes a bite out of unwanted spam.  Even BIG-IP LTM with it’s virtualization capabilities among other security features provides some network firewall functionality and with BIG-IP PSM, you get powerful security services for HTTP(s), SMTP, and FTP at BIG-IP speeds.
Now that it’s gotten easier for anyone to become a cybercriminal, your defenses must be also be easy and quick to deploy.  F5’s BIG-IP systems give you the control, power and ease of use to thwart both the organized crime syndicates and those rookies just getting into the game.

ps
Technorati Tags: Pete Silva,F5,security,application security,network security,virus
Digg This

Wednesday, January 6, 2010

New Decade, Same Threats?

Do I call it Twenty-Ten or Two Thousand Ten?  Just not Two Thousand and Ten since that pesky decimal takes us back 10 years.  Eh, either way, the new year and decade brings out all the predictions for the coming year with this one taking the cybercriminal approach.   The various 'Year in Reviews' also make appearances since we need to understand where we came from to know where we’re going.  These are always interesting due to the various points of view even if many of the predictions are the same: social media threats, not necessarily more but smarter malware/botnets, using the cloud for crime, financial DDoS, rogue software, Mac and Mobile malware, more breaches and a whole host of others.  Compliance and Health Care, while not threats, seem to be the areas of security focus in the coming year along with online banking.

From a government perspective, while much has been written about compromised drones and Warplanes, the real concern at the Pentagon is Electronic Espionage – breaching the network.  Being able to not only see data, such as intelligence reports, but manipulate the data.  Imagine if an ammo request was intercepted and changed to reflect a new delivery location.  That would be bad.  I’ve written about Corporate Espionage as part of the 26 Short Series and do think it’ll continue.  Trade Secrets, product plans and customer data are all tasty treats to the cybercriminal.  One of the reasons I think that this type of data is a target is due to regulatory compliance, but maybe not in the way you  think.  I look at it from a more ‘human nature’ position.  The more locked up, secret, hidden or protected something is, creates a perception of greater value or worth.  If you see a door with 5 locks on it verses one with just a single lock, you’d probably think that Door Number 1 has the good stuff since more protection was deployed.  If you’ve ever walked through the Tower of London to see the Crown Jewels, you’ve also seen the huge, thick vault doors that keep them safe at night.  With all that security, it must be extremely valuable. 

In some ways I think compliance creates the same ‘perception’ and increases the attack potential.  Companies are required by law to protect, store, encrypt and generally safeguard certain private/sensitive data – the crown jewels so to speak.  Don’t get me wrong, I’m not advocating to ignore compliance and current regulations – such as PCI – are needed.  I even think some could go a little further in prescribing security protections but it also tells cybercriminals – this is the good stuff.  If you want a huge score, hit here.  We might see an increase in Gas Station terminal thefts as we get closer to the July 2010 PCI deadline for unattended, Point-of-Sale PIN entry devices as thieves probably want to beat the deadline too.  2009 proved that while little scams and thefts will continue, it’s the big breach of regulated data that gets the biggest payout and the most news coverage.  That’s what I see coming in 2010.

ps

Related Resources

Digg This

Wednesday, December 2, 2009

Windows Shopping

I’m really not one of those vocal Operating System lover/haters. My dad worked at IBM for 30 years and so I grew up with computers and even took a PC Jr. with a whopping 128k of RAM and a color (what we called color) monitor with me to college in the 80’s. My first work computer was a Macintosh and learned about all that AppleTalk stuff and the cool publishing Quark could do. I’ve used and administrated Win3.1, NT 4.0 (on laptops), Win95, WinME, Win2000/Server, and of course a user of XP and Vista along with a few variants of Linux. I use Windows for home and work and personally I think each OS has it’s plus’/minus’. Very non-committal, I know. Now I’m looking to buy a new computer and with that, a new Operating System.


If you’ve been avoiding the news, TV or print ads over the last year, Windows 7 is the long awaited new OS from Microsoft.  Much has been written about Vista and the delicate balance between usability and security.  People want to be protected and secure but also want to do their daily computing tasks without much interruption.  Enterprises need to secure their access points but users want to single click to everything.  There has to be a balance.  With the endless amount of threats, I want a box that has the basic protections but also want to make some security decisions myself.  I also want to make sure that the computer I choose abides by the company access policies in place, in case I need to connect to my corporate network since I probably will be doing some work from my home computer.  This has become a requirement in recent years as tele-working continues to grow.  With Windows 7, Windows Server 2008 R2 and Direct Access, folks will be able to do that with ease.  F5 recently announced solutions to optimize Win7/Server 2008 R2 deployments and our FirePass SSL VPN already supports Windows 7 clients.

Sifting through some of the recent articles about Windows 7, there is this one that indicates Windows 7 is gaining but at the expense of XP – this one that announces Windows 7 passed Mac OS X in market share – and this one that says ‘Of all new Windows 7 users, 70% said that they were "extremely satisfied" and another 24% said they were "somewhat satisfied" with the operating system.’  And it seems like they’ve answered the most recent BSOD, saying it probably was malware but will still wait to see the final outcome.  Then, of course, there’s the Windows 7 Whopper to contend with while I figure out which hardware platform I want.

ps

Related resources:

Monday, August 24, 2009

Be Our Guest

MP: (knocks on the door – Waits. Door opens with MA)
MA: (in a deep fatherly voice) May I help you?
MP: ah, Hi, Mr. App…err, sir….um I’m here to see your daughter, Oracle.
MA: Oh you are, are you? Let me take a look at you. (Looks up/down, turns him around) Have you had a cold or flu recently?
MP: No
MA: Do you always have your firewall enabled before entering unknown areas?
MP: Absolutely!
MA: Have you graduated high school & up to date on your shots?
MP: Yes sir! I’m actually attending Jr Community College Institute.
MA: Ok then (calling over shoulder) Oracle, your friend is here.

After that, you don’t know if they are going to the prom, going to a movie, going to the beach or anything and if poor little Oracle is vulnerable, I don’t think any of you want to see Mr. Packet take advantage of that!

80% of NAC deployments are driven by Guest Access.  What once was the main driver, ‘Endpoint Base lining’ now only accounts for 15% of installations which might explain NAC’s downturn.  At first this was going to be a ‘NAC is whack’ post due to interoperability, standards, cost/complexity and so forth but that seems so 2007.  Plus, TCG is trying to push specifications forward.  So instead of ripping on a technology, I wanted to provide some ideas on Guest Access.  Plus, most companies most are now doing ‘Laid-Back NAC,’ since they are not sure what to do if a device is non-compliant.  According to Gartner, only 7% push/enforce device policies but when it comes to querying, checking the device is ‘good enough’ since if it’s not ours, then you must be a guest.  While compliance & protecting intellectual property are important, it’s mostly about the fear of strangers on the network.

Probably the most prevalent way visiting guests get access (internal or outbound) is Wireless.  Most companies have a WiFi AP that is visible to anyone with a radio and the password is freely given out.  Some broadcast SSID while others keep it secret and usually there is a password (not always the strongest or most secret) to jump on the wireless LAN.  Often, 802.1x will do it’s part by authenticating the user and opening a port.  After that, replay the opening scene since there’s no application awareness.  To protect internal resources, IT might VLAN (segment) the Wireless traffic so it is unable to reach internal destinations.  Another easy prevention mechanism is to only allow Outbound HTTP/HTTPS (ports: 80/443) traffic.  For many visitors, this works well since all they needed was the internet anyway; for others or internal employees that need access to internal systems, an SSL VPN can do the trick.  Just treat your Wireless users as any other ‘remote’ user {pdf}.  They have HTTPS access to the internet and all they have to do is type/bookmark the SSL VPN URL.  Host Check……authenticate…and resource assignment gives users internal access.  You could also create a portal page with available systems and depending on the request, force UN/PW then.  You get granular access control, encryption, application awareness (when coupled with BIG-IP LTM {pdf}) and whatever reports/stats needed for management.

IAM or Identity and Access Management is becoming a hot topic both for general access and NAC.  Regulatory compliance, protecting intellectual property, guest access and the fear of strangers are all driving the NAC & IAM intersection.  Who’s on my network, who has access to corporate secrets, are you one of us and how do we report and control all that are great concerns for IT.  As IAM meets NAC, the crossroads needs smarter signals. When adding Identity to NAC, the focus should be on the user rather than device (even though you’ll still probably check endpoint ‘health’) but companies are having some difficulty with role based info/authorization.  This idea is still in the Technology Trigger (early adopter) phase of the Gartner hype-cycle, but they do predict through 2011, 70% of large enterprises will have implemented authentication for all forms of network access.

ps

Friday, August 14, 2009

The Encryption Dance

S-s-s-s  A-a-a-a  F-f-f-f  E-e-e-e  T-t-t-t  Y-y-y-y

You can make the Big S while you sing along.*
Data goes where it wants to, It can leave your trace behind.

Cause the web don’t care and if it don’t care, Well it’s exposing time.

I say, data can go where it wants to, A place where they will never find.

And we can act like we come from NSA, Leave the eavesdroppers far behind.

And we encrypt.  Those things.









We can surf where we want to, Data’s masked and so am I

And we can hide real neat from our hats to our feet,

And surprise ‘em with a ‘Ha Ha’ cry.

Say, they can crack if they want to, if they don’t somebody will.

And if they do break in, the data is encrypted

And they’ll look like an imbecile.









I say, we got data, we got data, Everything’s in our control

We got data, we got data, encrypting it wall to wall

We got data, we got data, everyone check their systems.

We got data, we got data, everyone’s taking a chance

Encryption Dance.



Encryption is a key element in security – both for data in transit and data at rest.  It doesn’t necessarily need to be highly sensitive data either.  Just something you want to keep secret.  I’ve written about encryption a few times, especially in context surrounding high profile image breaches like TJX and Heartland since both those might have been avoided if the data was encrypted.  It’s not as simple as the lyrics depict as Lori points out in this blog.  Sure, there is SSL, HTTPS, IPSec and encrypted drives but it’s difficult to encrypt every piece of data, especially for the enterprise.  In fact, there’s probably some data that doesn’t need to be encrypted.  Which is where a Access Control Policy can come into play.  Depending on the context of the user/device, remote and mobile workers should be connecting via an encrypted tunnel using your VPN – that’s a no brainer.  Depending on the host inspection check, your policy might only allow access to certain resources depending on the device’s posture and hopefully all that traffic is encrypted.  Internal LAN’s are no longer the ‘safe haven’ that they used to be.  Partner’s, contractor’s and even unauthorized employees might have visibility to certain restricted information.  Here again, a policy could be enforced to first, restrict access to certain areas of your network (which many do already) and second, if an authorized employee is grabbing sensitive data, why not encrypt that specific file transmission even on the internal network to thwart any prying eyes or sniffing agents.

As for PCI, there’s already plenty of articles and opinions about it’s current state and effectiveness so I won’t dive in here.  What I will point out is an upcoming deadline that many might be unaware of: The unattended, PIN entry, Point-of-Sale devices.  While the deadline for PCI-DSS has passed, the deadline for PA-DSS entry terminals is next year – July 2010.  That means that most gas station pumps that you use your debit with, are unencrypted today.  There will be a mad rush next year for Fuel Retailers to either deploy an encrypted PCI-compliant PIN entry device inside or an encrypted keypad outside.

Finally, we continue to see data exposures due to stolen or lost laptops.  Here again, depending on your policy, the type of user/device and information accessed (plus other criteria) encrypting the drive to protect against inadvertent exposure is certainly a good idea – along with strict and potential severe consequences if someone does not comply.

ps

*Sung to the tune 'Safety Dance' by Men Without Hats.

#5 out of 26 Short Topics about Security

Wednesday, August 12, 2009

Bit.ly, Twitter, Security & You

..or, what I did on my twitter vacation the other day.  This brief break from 26 Short Topics about Security is brought to you by bit.ly, twitter, security and You.  I’ve been using bit.ly for a little while both to shorten links and be able to track clicks placed on twitter (and other social sites) – as many of you do.  When the twitter outage hit last week, and many folks found themselves ‘lost’ without it, I decided to review my stats on the bit.ly links I’ve sent and found something interesting; or frightening.  :-)  (Incidentally, there was a another DDoS attack yesterday that took twitter down for about 20 minutes)

To set this up: as you might know, I cover Security within the Technical Marketing Team (Lori, Alan & Ken round out the TMM group – and we’re all interested in Security) at F5 and usually find 1 or 2 interesting ‘security’ stories that I actually tweet.  In recent weeks it’s been things like Texting Hacks, Hacking Parking Meters, and The Weak link in Security:People, along with my blog, and F5 video and audio updates.  Sometimes I find a slightly weird story like the poor guy who fell into a vat of chocolate.  Now, many of my followers/I’m following are security folks and the exchange of information is awesome.  I often see stories that I probably wouldn't have gotten to as we all try to read the entire internet on a daily basis.

So, as I looked through my entire list of links, one jumped out: Fancy Fast Food.  Makeovers of fast food and as the site says: ‘Yeah, it’s still bad for you – but see how good it can look!’  This bit.ly link, by a decent margin, was my most popular.  Even the ‘out of’ stat (which is the total of all bit.ly’s going to that long URL) was close to 8000 clicks!  Conclusion?  Folks want fun fast food, not security.  (tongue in cheek) In seriousness, I think there is a really good piece in the fact that, on a day to day basis, people would rather see what some chef can do with a Wendy’s hamburger or Dunkin Donuts that about security.  That doesn’t mean we’re not interested in security but when you’re immersed in it all the time, a little Daily Distraction is a welcome change.  Helps us clear out those PCI headaches, bloodshot breaches and endless string of Identity Theft incidents.  At first I was a little miffed that what I found interesting wasn't so much to others, but then I realized I had actually found something that everyone found interesting not just the security minded.  And it started conversations – true social media.

ps

  • * No bit.ly links were used in this blog as to not artificially increase stats

  • * If you’re so inclined – F5 can be followed @f5networks and me @psilvas


bit.ly, a simple url shortener
http://bit.ly/ [more]

Tuesday, August 4, 2009

Remember when we drew big Clouds on whiteboards…

…with the Ace Frehley lighting bolts flying out?  We still draw those clouds but now they are smaller, there are more of them and sometimes hover over a single, private entity.  Well, the Clouds have accumulated and an umbrella isn’t going to help.

Nicholas Carr (author of Does IT Matter and The Big Switch) talks about the notion of the Internet (or Computing power) as a Utility and has compared the cloud transition to the birth of power utilities from the 19th to 20th centuries. Back then, manufactures had to provide their own energy source and many used huge water wagon wheels to generate power. In fact, the top manufacturer at the time had built the world’s largest waterwheel and had a competitive advantage.  Soon, things changed when Westinghouse came on the scene in 1886 and pioneered long-distance power transmission.  As soon as these self-generating sources could now ‘plug-in’ inexpensively, all assumptions changed. The assumption was that this (power) was something you had to buy/build and maintain yourself.  Carr feels Information Technology is next and going thru a similar transformation due to the collapse of efficiency. He notes that, Server Capacity has 80% waste, Storage has 60% waste. and upkeep/maintenance has around a 70% waste. Clouds give the ability to share assets and move to a new level of efficiency, if done right. While the notion of Utility Computing is new; disruptive technologies can move quickly, especially if it’s working well.  There is, of course, alternative views to this idea offered in this article.  It’s an interesting read on the difference between pushing/sharing electrons VS. data along with the ‘trust’ factor.  I don’t think James Urquhart is necessarily disagreeing with Carr but being more specific as to what Computing as a Utility would look like and he correctly points out that, “some have taken electricity as an analogy to cloud adoption to an extreme…” I tend to agree since an industry blessed definition of cloud computing is still evolving & Nick wrote his book over a year and a half ago when ‘Cloud’ was still a nebulous term.  Even today we’re starting to parse parts – Platform, Software and Infrastructure – all as a Service and many are jumping in.

cloud According to IDC, CIO’s choose Cloud services primarily for Ease, Fast Deployment and Lower payments. They avoid Clouds due to Security concerns, Dependability (availability/performance) and Control. Security (or Trust) is usually at the top of surveys (for good reason) but there’s also a sense of not wanted to give up control of specific applications, particularly ones that are tied to certain regulatory governance. The growth anticipated over the next couple years will be in IT Management Apps and Collaborative applications which makes sense.  Cloud is about sharing and collaborative apps are making their way to the cloud, plus IT must have a way to manage all those instances.  The goal, of course, is to Consolidate (reduce costs/improve quality), Virtualize (simplify access/improve end-to-end management) and Automate (speed/predictability & reduce labor) IT into service orientated delivery.

Clouds are not going to replace the old IT model but become another choice for sourcing to IT departments. There will be a mix of on-premise and off/cloud delivery, depending on the application (and several other factors) but performance level assurances (SLA) are very important to the buyer.  Also attributed to ISC, Cloud spending looks modest from 4% of overall IT spending to 9% in 2012 but will account for $42.3 billion with business applications taking 52% of that.

ps

Number 3 out of 26 Short Stories About Security