Showing posts with label open source. Show all posts
Showing posts with label open source. Show all posts

Tuesday, April 15, 2014

The Weekend of Discontent

This past weekend, like many of you, I started getting the blood curdling password resets from a bunch of OpenSSL affected sites. I also got a few emails from sites indicating that I had nothing to worry about. Bad news, good news. Probably the biggest security story thus far for 2014 is Heartbleed, the OpenSSL vulnerability which potentially allows attackers to extract 64 kilobyte batches of memory at random without being noticed and leaving no trace. Sounds like the perfect crime.

It also got me thinking.

First, I wondered if this was a new era of security by force. The vulnerability and the totality of the hole forced many of us to change passwords on many sites. What a pain. It was a huge reminder that no matter how many 'experts' urge regular password rotation, it is a real time consuming, frustrating task. It's no wonder that so many keep the same password for years or use the same password across multiple sites. With so many sites requiring some authentication or verification for either resources or customization, people can have hundreds username/password combinations. Sure there are password keepers but part of me is reluctant to put all my web identities with one entity. What if that gets hit? There are just some sites that I chose not to save and auto-fill but enter it every time. Then, of course, I'm susceptible to key loggers. Great.

Then there are the developers. I imagine that this past weekend was the most worked ever by the entire coding community. Administrators across many sectors were working to patch vulnerable systems all over the globe to reduce the security threat. A massive undertaking to help fix over two-thirds of the internet. The weekend work of many fingers plugging dikes was probably only surpassed by the marketers and PR folks maneuvering their stories around what it is, what's at risk, what you should do and other FAQs surrounding this security superstar. @LanceUlanoff speculated on twitter, 'Is Heartbleed the first Internet bug with its own Web site? http://t.co/M9u976X9ui'

With so many sites and so many people affected along with the massive media coverage, will things change? Or will this be like Y2K with a bunch of dire warnings only to have nothing major occur? Is this a wake up call or will it dissolve into yesterday's news as new 'breaking' stories grab our attention? I think (and hope) that this is so critical that many organizations will be taking a more detailed look at their security infrastructure even if they are not vulnerable to Heartbleed. It forces many, if not all internet users, including the administrators themselves, to take a look at how we are protecting ourselves. It'll be interesting to see if '12345678' or 'qwertyui' or even 'password' continues to be the most popular pass codes after this massive reset.

If you need assistance with your Heartbleed crisis, click here to learn how F5 can help.

ps

Related

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, July 20, 2010

CloudFucius Asks: Will Open Source Open Doors for Cloud Computing?

Konfuzius-1770 There has been a lot of press already about OpenStack’s announcement yesterday about their new open source cloud computing software.  OpenStack says that the goal is, ‘to allow any organization to create and offer cloud computing capabilities using open source software running on standard hardware.’  The software is intended to to allow companies to automatically create and manage large deployments of virtual private servers and remove the concern of vendor lock-in since the software will allow customers to span multiple cloud providers.  Customers and service providers alike can use their own physical hardware to create large cloud environments, public or private, across the globe.  It is also positioned to give customers more choice in how they want their specific cloud environment designed and deployed.  Almost 30 companies are participating with the folks at Rackspace and NASA (Nebula cloud computing platform) leading the charge.

Certainly, there are several attractive pieces to this, including the notion of cloud-standards, but will it finally open the flood gates for mass adoption of Cloud deployments?  Maybe not for the enterprise, at least initially.  Openstack honestly admits, ‘OpenStack is probably not something that the average business would consider deploying themselves yet. The big news for end customers is the potential for a halo effect of providers adopting an open and standard cloud: easy migration, cloud-bursting, better security audits, and a large ecosystem of compatible tools and services that work across cloud providers.’  This means that Openstack is really aimed at *very* technical enterprises (very large with lots of resources) and service providers.  Thus, the play for the enterprise does not exist (yet) here, *except* for management layer players who could leverage it to build something they could sell to enterprises to “make it easy” for them.  (thanks Lori!)

In addition, as Ted Julian of the Yankee Group points out in this story, security is still the great unknown since there doesn’t seem to be a security vendor on the list of Openstack participants.  I’m sure that list will grow over time, especially with the press that it’s getting, and the ever present cloud security concerns will eventually be addressed.  This project is in the very early stages and will continue to evolve as folks pick up the code, test it and decide how it might work for them.  Maybe it’ll also help push along and enable the whole Inter-Cloud notion.

And one from Confucius: The cautious seldom err.

ps

The CloudFucius Series: Intro, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13

Resources:

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, cloud, context-aware, web, internet, openstack

twitter: @psilvas

Digg This