Lots of good an interesting stuff, plus pictures coming from BlackHat. I'll post them hopefully by the end of the week. In the mean time, check this out:
http://www.foolmoon.net/cgi-bin/blog/index.cgi?mode=viewone&blog=1185593255
No, I didn't have any specific knowledge of this beforehand. I only knew that a group of REALLY smart people were working on it and when asked, "Is it possible to break out of VMWare?" they would smirk wryly and say things like, "I don't know, and if I did, I couldn't tell you." Yeah, well, I knew better than to bet against them.
Wednesday, August 1, 2007
Monday, July 30, 2007
This Just Plain Sucks
Halvar was denied entry to the US on his way to Black Hat. This screws a good number of people including Halvar since his class was sold out. I know, I tried to register for it back in May.
But don't worry about me. David Litchfield has my brain on full and the "really meaty" stuff is coming tomorrow. So I'm calling it a night.
But don't worry about me. David Litchfield has my brain on full and the "really meaty" stuff is coming tomorrow. So I'm calling it a night.
BH2K7
Made it to Black Hat yesterday (well, today, really) despite the delays and cancellations due to the <ahem> "bad weather." Class starts in two hours, so right now I am desperately trying to figure out my coffee situation. Caesar's has me in a gorgeous room with a bathroom you could play racquetball in, but there's no coffee maker. So if you see me in the lobby this morning without a Starbuck's Venti something-or-other in hand, steer clear. I'm a little unstable at the moment.

Thursday, July 26, 2007
Certified Pre-Owned 0-Days
Monday, July 23, 2007
Penny Arcade So Closely Resembles My Life It's a Little Freaky
You know, they hire real medical examiners and forensics technicians to consult on movies and TV shows (like CSI) to achieve a hopefully-fascinating level of realism. Which is why I sometimes wonder if Hollywood just has an exceedingly low opinion of infosec, because they clearly don't hire infosec consultants.
Thursday, July 19, 2007
Play-By-Play: I Get Into It w/ Richard Bejtlich Over Metrics
So I commented yesterday about a post Richard made about outcome-based security metrics.
In short, Richard likes outcome-based security metrics because they "mean something." I like them, too, but they can be hard to define and even harder to gather good data for. So I guess I don't like them that much.
He replied in the form of a new blog post. And I just had to comment.
This time, Richard takes issue with my point that it's possible to have bad security and outcome-based metrics that don't realistically represent the poor state of your security. He's probably right that if breaches are really bad or even moderately bad very frequently, that you can't help but detect them. Eventually. But in my opinion, metrics don't help you here. And that was my point.
And then he rags on compliance metrics. And this is where I draw the line. OK, not really. Compliance metrics suck, but we do them because they have value. Actual business value. Contrived, soulless, perhaps even pointless value. But I can tie dollars to them, so they have value. But Richard doesn't believe in ROI for security, either, so... :-)
Anyway, I respect Richard and enjoy his books and his blog. This dialog is healthy for infosectarians to have. If by some freak accident you read my blog but not his, definitely check it out.
In short, Richard likes outcome-based security metrics because they "mean something." I like them, too, but they can be hard to define and even harder to gather good data for. So I guess I don't like them that much.
He replied in the form of a new blog post. And I just had to comment.
This time, Richard takes issue with my point that it's possible to have bad security and outcome-based metrics that don't realistically represent the poor state of your security. He's probably right that if breaches are really bad or even moderately bad very frequently, that you can't help but detect them. Eventually. But in my opinion, metrics don't help you here. And that was my point.
And then he rags on compliance metrics. And this is where I draw the line. OK, not really. Compliance metrics suck, but we do them because they have value. Actual business value. Contrived, soulless, perhaps even pointless value. But I can tie dollars to them, so they have value. But Richard doesn't believe in ROI for security, either, so... :-)
Anyway, I respect Richard and enjoy his books and his blog. This dialog is healthy for infosectarians to have. If by some freak accident you read my blog but not his, definitely check it out.
Good HIPAA Resource
HIPAA isn't new, but - and maybe because I work in an environment where it's the primary regulatory standard - I regularly have conversations with colleagues and vendors about how we adhere to HIPAA standards and specifically the nuances of how we believe it translates into actual best practices on the ground. Like anything that is both legal and technical, HIPAA is riddled with self-referencing jargon, and defining these terms is useful to any serious conversation about HIPAA compliance. To that end, I stumbled on a really nice encyclopedia of HIPAA terms at U of Miami's med school. Too useful not to share.
Subscribe to:
Posts (Atom)