<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3428659345510666362</id><updated>2011-11-02T13:09:26.350-04:00</updated><title type='text'>SHLOMI'S PARKING SPOT</title><subtitle type='html'>A place for thoughts about technology &amp;amp; life</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>25</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-1279599756717844046</id><published>2011-08-15T13:45:00.002-04:00</published><updated>2011-08-15T13:45:49.942-04:00</updated><title type='text'>We fix Stupid!</title><content type='html'>       &lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:OfficeDocumentSettings&gt;   &lt;o:AllowPNG/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;  &lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;JA&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:EnableOpenTypeKerning/&gt;    &lt;w:DontFlipMirrorIndents/&gt;    &lt;w:OverrideTableStyleHps/&gt;    &lt;w:UseFELayout/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="276"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;  &lt;!--[if gte mso 10]&gt; &lt;style&gt; /* Style Definitions */table.MsoNormalTable	{mso-style-name:"Table Normal";	mso-tstyle-rowband-size:0;	mso-tstyle-colband-size:0;	mso-style-noshow:yes;	mso-style-priority:99;	mso-style-parent:"";	mso-padding-alt:0in 5.4pt 0in 5.4pt;	mso-para-margin:0in;	mso-para-margin-bottom:.0001pt;	mso-pagination:widow-orphan;	font-size:12.0pt;	font-family:Cambria;	mso-ascii-font-family:Cambria;	mso-ascii-theme-font:minor-latin;	mso-hansi-font-family:Cambria;	mso-hansi-theme-font:minor-latin;}&lt;/style&gt; &lt;![endif]--&gt;    &lt;!--StartFragment--&gt;  &lt;br /&gt;&lt;div class="MsoNormal"&gt;Recently I had a chance to meet with a couple of very different and promising companies. One is the classic information security for the enterprise company going after the holy grail of risk management. The other one is a small startup company attempting to be the good cop of consumer privacy. Both are very successful.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Allegedly there is no connection between the two, right? While some tend to bundle privacy and security together (as well as compliance), there is a clear distinction between the two. Not to mention the very different target markets (enterprise vs. consumer).&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;So why do I bundle the two?&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Let’s take the enterprise risk management perspective first:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;When observing some of the recent data breaches (e.g. the RSA incident), there is an interesting pattern. As we know hackers target the weakest links in their quest for the prize. Occasionally these links are infrastructure vulnerabilities, but in many cases it is the ultimate weak link – the human factor. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;It should not surprise anyone that it is much easier entering a building through its main door (especially when you have the keys), rather than using a small, semi closed, side window on the 5&lt;sup&gt;th&lt;/sup&gt; floor. Since organizations will always provide employees access to their enterprise resources (so they can perform their work), all is left to the hackers is to get the keys and use the main door. But why bother trying to hack enterprise protected resources directly? &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Without getting into lengthy explanations, what bad guys do is create a “hit” list of employees with the right profile. Then they collect information about the selected targets mostly using publically available resources (such as the Wild Wild Web). Once enough information is collected a targeted campaign is launched. In many ways this campaign is very similar to consumer phishing. During this process (A.K.A spear phishing) users end up enabling the attacker to collect more information (which is not publically available), and eventually get the access they need. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Bottom line – employee’s consumer vulnerable profile is enabling an attack on enterprise resources. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Now for the consumer privacy point of view:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Simply put the objective of privacy tools is controlling the amount of private information publically available and by doing so to reduce the consumer’s attack surface.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Do I need to explain the linkage between these two companies/domains?&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;By protecting consumer-employees privacy enterprise reduce their risk of being attacked. &lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;A few things to keep in mind:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="margin-left: .25in; mso-add-space: auto; mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span&gt;&lt;span&gt;1.&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;“All or nothing” solutions are never a good idea – simply not practical. Security solutions that attempt to solve “everything” traditionally fail (DLP is a good example). Instead of applying protective controls for all employees we should apply the right controls only for the employees identified as “high risk” (relative to a defined threshold).&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: .25in; mso-add-space: auto; mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span&gt;&lt;span&gt;2.&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;How to define “high risk”? The risk is the &lt;b&gt;enterprise’s&lt;/b&gt; risk, not the employee’s. It should be defined based on a combination of the employee’s enterprise profile (e.g. systems he can access and his access level), and his consumer online profile vulnerability score (i.e. how exposed is he). &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: .25in; mso-add-space: auto; mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span&gt;&lt;span&gt;3.&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;By no means I’m promoting a “big brother” type of solutions. Enterprise should not collect\manage\care about employees’ private information but only their online vulnerability score (the likelihood of being attacked).&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: .25in; mso-add-space: auto; mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span&gt;&lt;span&gt;4.&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Coming up with an online profile vulnerability score should be done by leveraging similar techniques as consumer privacy tools, or emulating hackers’ information collection process. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;And maybe someday, some company will address this aspect of the human factor, and will be able to use the great tagline: “we fix stupid!”&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;!--EndFragment--&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-1279599756717844046?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/1279599756717844046/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2011/08/we-fix-stupid.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/1279599756717844046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/1279599756717844046'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2011/08/we-fix-stupid.html' title='We fix Stupid!'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-1583429369264472838</id><published>2011-05-27T11:21:00.000-04:00</published><updated>2011-05-27T11:21:24.956-04:00</updated><title type='text'>Drop(the ball)box?</title><content type='html'>&lt;span style="font-family: Calibri;"&gt;Dropbox is a great tool, I use it all the time. Very simple, user friendly and perfect for what I need. Its sweet spot in my opinion (and my main usage pattern) is collaboration or sharing small amount of documents (not digital media, but documents that change over time). &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;Dropbox got some bad publicity recently regarding the security state of their service.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;For those who are not familiar, a quick summary of the two main two points:&lt;/span&gt;&lt;br /&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri;"&gt;1.&lt;/span&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font: 7pt/normal &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;A relatively easy way to impersonate other users – simply put, Dropbox identify the user on the device using a file stored locally in a similar location on all Dropbox installations. All Bob has to do to impersonate Paul is copy over Paul’s identification file, and he has access to all his files.&lt;/span&gt;&lt;br /&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Calibri;"&gt;2.&lt;/span&gt;&lt;span style="font-size-adjust: none; font-stretch: normal; font: 7pt/normal &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;span lang="EN" style="mso-ansi-language: EN;"&gt;&lt;span style="font-family: Calibri;"&gt;Dropbox possesses the encryption keys for all users’ data – very common with tools that provide web access to user’s files (or other content related services). The big issue was less about the possession of the keys and more around the fact their privacy policy (and marketing messages) has mislead people to believe Dropbox does not have a copy of the key or ability to decrypt users’ data. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;While bullet #1 is an ugly security glitch, it is simple to fix and I trust the Dropbox team to take care of it.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;Bullet #2 reminds me of the main reason I buy insurance. It is not so much about the actual insurance policy and much more about the trust factor. I just want to know I can trust the insurance agent to take care of my business if something goes wrong. If for some reason the trust is broken, I will replace the insurance agent/company regardless of the price. Incidents will always happen, everyone makes mistakes. It is about bouncing back from an incident, about the reaction after dropping the ball. That’s what breaks or strengthen the trust.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;Dropbox messed up, it does not really matter what they think, it is all about the perception. So if I was Dropbox, I will be less concern about proving who is right or “fixing a problem” and more about bouncing back gracefully.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;Having said that, consumers have proven time and again that they don’t really care about security, they don’t even care about privacy…&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;Thinking that people are going to ditch Dropbox because of the recent security issues is not realistic, will simply not happen. Do you remember how many people banned Facebook during the “who owns my photos on Facebook” campaign just a couple of years ago? (hint – several hundred or thousand, while during the same period of time millions new users joined…).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;People care about serviceability, productivity, and the coolness factor. Less about privacy or security.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;The notion of personal/private information is long gone from the consumer world. Somehow (social media or even plain old email) your data moves/duplicated to the cloud/web. Once in the cloud there is no going back, and it is no longer in your control (try to really delete stuff from Facebook). The Dropbox type of tools simply extends the cloud/web further into your desktop, while your content is syncing between devices it also synced to the “mighty cloud”, and once in the cloud… &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;As for enterprise usage – this is a totally different story. &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;The consumer employees (&lt;/span&gt;&lt;a href="http://shlomidinoor.blogspot.com/2010/01/we-are-all-consumer-employees.html"&gt;&lt;span style="color: blue; font-family: Calibri;"&gt;http://shlomidinoor.blogspot.com/2010/01/we-are-all-consumer-employees.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Calibri;"&gt;) continue to build internal pressure to adopt consumer-like tools to simplify and streamline their work. The new generation file syncing/collaboration tools such as Dropbox are a good example of the phenomenon. While great tools they lack adequate controls enterprise IT/IS are expecting. My friends at CloudLock (formally Aprigo) identified a similar opportunity with Google Apps and provide a control layer on top Google’s platform. In a similar fashion vendors will continue identifying other tools originally built for consumers (by “consumer” vendors) and provide the enterprise control layer. Dropbox is a good example.&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: Calibri;"&gt;Bottom line:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;As consumers we should keep on using these great tools that improve our productivity.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Calibri;"&gt;As enterprises we should look for and work with vendors that will provide the much needed control layer (while maintaining a seamless user experience for the consumer-employee).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Calibri;"&gt;As vendors consider it as an opportunity!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-1583429369264472838?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/1583429369264472838/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2011/05/dropthe-ballbox.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/1583429369264472838'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/1583429369264472838'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2011/05/dropthe-ballbox.html' title='Drop(the ball)box?'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-720158076417593182</id><published>2011-03-22T14:28:00.000-04:00</published><updated>2011-03-22T14:28:32.542-04:00</updated><title type='text'>Focus is Golden!</title><content type='html'>&lt;span style="font-family: Calibri;"&gt;In many occasions I’ve being asked a very basic question: what is information security?&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;My two words answer is: Risk Management.&lt;br /&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;Any other answer that might imply we can achieve 100% security would simply lead me to the conclusion that we should just give up now, go home, and find a different occupation… &lt;/div&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;There is no 100% security, it is too expensive, too complex, too agonizing, takes too long, too dynamic. It is all about risk management, define your risk threshold and make sure you have the right controls to meet your goal.&lt;br /&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;Last week I’ve presented at a CISO event discussing the same topic (i.e. security and risk management), and I thought it might be a good opportunity to share my take on the topic.&lt;/div&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;br /&gt;One of the fundamental debates we have in the security community is whether to take the “All or Nothing”/”let’s boil the ocean” approach, OR focus on contained problems we can actually solve…&lt;br /&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;Large vendors tend to promote the first approach with their deep stacks (and services organizations), while pure players/smaller vendors tend to focus on their core competency.&lt;br /&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;As I believe security=risk management, it will not come as a shocker to anyone that I vote for focusing on the highest risk first (i.e. a contained problem).&lt;/div&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;br /&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;Kind of trivial, but where/how should we begin?&lt;/div&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;Everyone seems to have their quadrant, so here is Shlomi’s quadrant. It provides a good high level view where we should (and should not) invest, that is if you are out to solve the security challenge.&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt;&lt;a href="https://lh6.googleusercontent.com/-5X1AdoxYV-I/TYjHanyXtCI/AAAAAAAAAEo/eCn4-cDSqAM/s1600/Quadrant.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="214" src="https://lh6.googleusercontent.com/-5X1AdoxYV-I/TYjHanyXtCI/AAAAAAAAAEo/eCn4-cDSqAM/s320/Quadrant.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-family: Calibri;"&gt;While “All or Nothing” calls for similar controls for all types of operations, the reality is real damage comes from operations associated with the 4&lt;sup&gt;&lt;span style="font-size: x-small;"&gt;th&lt;/span&gt;&lt;/sup&gt; quadrant (powerful actor + powerful target). The advanced audience can add the context of the operation as a 3&lt;sup&gt;&lt;span style="font-size: x-small;"&gt;rd&lt;/span&gt;&lt;/sup&gt; dimension, for the sake of simplicity I left it out.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Times New Roman;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;Ok, so powerful actor + powerful target is the way to go, but how can we better evaluate the cost, time, agony and success of using the described two methods with relation to the risk addressed (i.e. coverage of your risk)?&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;Since I’m in a “graphy” mood today, let’s observe the following:&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt; text-align: center;"&gt;&lt;a href="https://lh3.googleusercontent.com/-UhBU3OpYIac/TYjhvPIu7nI/AAAAAAAAAFI/XXaRsBPuu58/s1600/Approaches+side+by+side.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://lh3.googleusercontent.com/-UhBU3OpYIac/TYjhvPIu7nI/AAAAAAAAAFI/XXaRsBPuu58/s1600/Approaches+side+by+side.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;“All or Nothing” approach to security calls for controls across the board, which is very expensive, very long to implement, extremely painful and have questionable success rates. It is somewhat linear with regards to the risk we actually address. Take any of the big security projects (e.g. DLP or IM), after all the investment you end up with partial coverage at best.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;The “high risk first” focus on the 4&lt;sup&gt;&lt;span style="font-size: x-small;"&gt;th&lt;/span&gt;&lt;/sup&gt; quadrant, no resources spent on low risk activities, achieving a sharp up warding slope up front of risk coverage.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;Now for the interesting part comes ($$$) – when placing both on the same graph:&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh5.googleusercontent.com/-wd-1bc3XVm8/TYjisqZqiFI/AAAAAAAAAFM/in2S719AQY8/s1600/Threshold+side+by+side.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://lh5.googleusercontent.com/-wd-1bc3XVm8/TYjisqZqiFI/AAAAAAAAAFM/in2S719AQY8/s1600/Threshold+side+by+side.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Using the “all or nothing” approach to achieve a given risk threshold (left side) will be more expensive, take longer, more painful, and higher likelihood to fail. While using a given a budget/time frame/pain/likelihood to fail (right side) will provide coverage for a lower addressable risk. &lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;Which approach to choose? Your decision…&lt;/span&gt; &lt;/div&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt; &lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;But the existing security controls address this mumbo-jumbo, right? Not exactly… &lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;The top 3 reasons why most security stacks/controls are missing the point are:&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;1.&lt;span style="font-size-adjust: none; font-stretch: normal; font: 7pt/normal &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Focus on known identities and personal accounts rather than high risk (privileged) accounts. &lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;Personal accounts/known users = limited access = low risk &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="mso-bidi-language: HE;"&gt;&lt;span style="mso-bidi-language: HE;"&gt;Privileged accounts and users = limitless access = high risk&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;2.&lt;span style="font-size-adjust: none; font-stretch: normal; font: 7pt/normal &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;TMI (&lt;span style="mso-bidi-language: HE;"&gt;Too Much Information)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;span style="font-family: Calibri;"&gt;&lt;span style="mso-bidi-language: HE;"&gt;&lt;span style="mso-bidi-language: HE;"&gt;Collecting all events (of high or low risk) is a waste of time. It takes too long to make sense out of it, and slows down production systems… I just want to see the important information&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-bidi-language: HE;"&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;3.&lt;span style="font-size-adjust: none; font-stretch: normal; font: 7pt/normal &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;One trick pony&lt;/div&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt; text-align: left;"&gt;&lt;span style="font-family: Times New Roman;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-language: AR-SA; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;Most solutions address verticals – data, events, access, identity, sessions &lt;/span&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-language: HE; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;(of high or low risk), rather than a horizontal (i.e. high risk across the elements)&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; line-height: 115%; mso-ansi-language: EN-US; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-language: HE; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-fareast-language: EN-US; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt; text-align: center;"&gt;&lt;span style="font-family: Calibri;"&gt;&lt;a href="https://lh6.googleusercontent.com/-iIKL8WOz0Tk/TYjlZHE9XAI/AAAAAAAAAFQ/1YN9omCyCJo/s1600/Vertical+-+Horizontal.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://lh6.googleusercontent.com/-iIKL8WOz0Tk/TYjlZHE9XAI/AAAAAAAAAFQ/1YN9omCyCJo/s1600/Vertical+-+Horizontal.png" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: Calibri;"&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-family: Calibri;"&gt;So when you are out there looking for ways to address your security risk think of tools that manage to carve out the high risk stuff, take a holistic (horizontal) view AND do not impact performance of your existing environment/personnel. &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-720158076417593182?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/720158076417593182/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2011/03/focus-is-golden.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/720158076417593182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/720158076417593182'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2011/03/focus-is-golden.html' title='Focus is Golden!'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh6.googleusercontent.com/-5X1AdoxYV-I/TYjHanyXtCI/AAAAAAAAAEo/eCn4-cDSqAM/s72-c/Quadrant.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-3517697550460323123</id><published>2011-02-08T17:06:00.000-05:00</published><updated>2011-02-08T17:06:17.628-05:00</updated><title type='text'>Cloudouflage</title><content type='html'>Have you ever wondered why some flavors of cloud computing (SaaS) are so successful while others (IPaaS = Infrastructure or Platform as a Service) are less (yet)? And what is cloudouflage?&lt;br /&gt;&lt;br /&gt;Whenever possible I advocate for simplicity, therefore I’ll try to take the simple approach (a.k.a. naïve) to address these questions. Let’s see if I can limit myself to no more than 2 bullets a section. &lt;br /&gt;&lt;br /&gt;It is very clear adoption of SaaS is exploding, regardless what numbers you are using (ballpark of $8 Bbbbbilion last year). While I could go through lengthy and intelligent description of all the reasons (including financials, agility, etc.), I want to focus on two which I find interesting:&lt;br /&gt;&lt;br /&gt;1. It is just another website, not any different than Gmail&lt;br /&gt;The usage model is very clear and simple. I open my browser, go to this website, and consume a service. Consumerization plays a big part here. Since the emergence of the web, consumer technologies are leading the way, while enterprise is a delayed copycat at best. Consumers are simply looking to consume a service, for everything they need there is an app for that. Similarly when consumer employees (&lt;a href="http://shlomidinoor.blogspot.com/2010/01/we-are-all-consumer-employees.html"&gt;http://shlomidinoor.blogspot.com/2010/01/we-are-all-consumer-employees.html&lt;/a&gt;) need a CRM service (e.g.), there is a cloud for that. &lt;br /&gt;&lt;br /&gt;2. No IT involvement&lt;br /&gt;In many cases no IT is required, not for setup nor maintenance. If something does not work you call customer support. Great for SMBs (with no internal IT expertise), and very convenient for Business in larger organizations believing no IT means No extra processes, No security policies, No regulations…&lt;br /&gt;&lt;br /&gt;Looking at IPaaS we don’t see the same crazy adoption, numbers suggest it is $1B at best (a nice number but relative to its potential - not as impressive).&lt;br /&gt;&lt;br /&gt;Notice: I’m bundling IaaS and PaaS together as I believe they will ultimately converge. We already see the IaaS vendors adding “platform” services and vice versa for PaaS vendors.&lt;br /&gt;&lt;br /&gt;IPaaS is very different from SaaS:&lt;br /&gt;&lt;br /&gt;1. Not really a packaged service but an infrastructure &lt;br /&gt;Regardless of the “aaS” suffix, IaaS is providing “virtual machines/storage/…”, from a business perspective what can I do with it? It is a starting point not the end game, now something needs to be deployed, optimized, maintained, etc. Where is the SaaS magic (i.e. I open my browser and the service is there)?&lt;br /&gt;&lt;br /&gt;2. IT involvement is inevitable &lt;br /&gt;As the SaaS magic in nowhere to be found in the IPaaS reality, real work is required for setting up the virtual infrastructure. IT assistance is required (sorry Mr. Biz – no shortcuts for you…). &lt;br /&gt;&lt;br /&gt;A simplistic representation where IaaS + PaaS converge into IPaaS, Biz uses SaaS directly (blue), and IPaaS through IT (green): &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_GlfI8n8nses/TVG7Pa0UDaI/AAAAAAAAAEk/B2MDkXqw0Tw/s1600/SaaS-IPaaS+model+2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" h5="true" height="200" src="http://4.bp.blogspot.com/_GlfI8n8nses/TVG7Pa0UDaI/AAAAAAAAAEk/B2MDkXqw0Tw/s320/SaaS-IPaaS+model+2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;So what should happen in order to drive IPaaS adoption?&lt;br /&gt;&lt;br /&gt;1. The peace pipe will finally be used&lt;br /&gt;I will not attempt to elaborate beyond the many blogs, tweets, articles, presentations, etc. done on this topic. Eventually IPaaS vendors and IT/IS will agree on a common ground regarding control, transparency, security, regulations and such. As with any peace agreement both sides will have to compromise (yeah – BOTH sides).&lt;br /&gt;&lt;br /&gt;2. &lt;strong&gt;Cloudouflage&lt;/strong&gt; &lt;br /&gt;There is still a lot of money being paid for IPaaS solutions, meaning organizations are using it for something. It does not come as a big surprise that the main use cases for IaaS today are dev &amp;amp; test, cloud burst, and high performance computing. They fit perfectly with IaaS characteristics. Yet, most of the setup/maintenance/support efforts are done ad hoc/manually/internally. &lt;br /&gt;How can we leverage these use cases to exponentially increase the IPaaS usage?&lt;br /&gt;That’s where cloudouflage comes into play. Wrapping IaaS with a relatively “thin” service layer will create an illusion (cloud-camouflage) for customers that they are consuming a packaged service rather than infrastructure (reminder - that’s what they want). Imagine a vendor providing a service to create and manage a catalog for demo environments. The management, configuration and meta data is the “thin” service layer, however whenever starting a demo environment, virtual machines are being created and built on top of the underlying IaaS solution. Same goes for dev &amp;amp; test. &lt;br /&gt;&lt;br /&gt;Bottom line: while for anything consumers need there’s an app for that, the day will come where for every service organizations will need there will be a cloud for that. The time for Service as a Service has come!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-3517697550460323123?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/3517697550460323123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2011/02/cloudouflage.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/3517697550460323123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/3517697550460323123'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2011/02/cloudouflage.html' title='Cloudouflage'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_GlfI8n8nses/TVG7Pa0UDaI/AAAAAAAAAEk/B2MDkXqw0Tw/s72-c/SaaS-IPaaS+model+2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-7394582390750861327</id><published>2010-12-06T11:02:00.000-05:00</published><updated>2010-12-06T11:02:38.413-05:00</updated><title type='text'>Neuroprivilogy is the Holy Grail</title><content type='html'>Is your Neuroprivilogy vulnerable?&lt;br /&gt;The answer is most probably yes, you simply have no clue what Neuroprivilogy is (yet)…&lt;br /&gt;&lt;br /&gt;The first step with any discussion is defining a fancy term to describe the phenomenon. That’s where Neuroprivilogy came about.&lt;br /&gt;As the name suggests Neuroprivilogy is constructed from the words neural (network) and privileged (access), and can be defined as the science of privileged access points’ networks. Using the neural network metaphor, organization’s infrastructure is not flat but a network of systems (neuron=system). The connections between systems are access points similar to synapses (for neurons). Some of these access points are extremely powerful (i.e. privileged) while others are not. Regardless, access points should be accessed only by authorized sources.&lt;br /&gt;&lt;br /&gt;This privileged access points’ network is vulnerable as you’ll find out by observing the &lt;strong&gt;Neuroprivilogy vulnerability 7 fallacies&lt;/strong&gt;:&lt;br /&gt;&lt;br /&gt;1. &lt;strong&gt;These access points have limited permissions&lt;/strong&gt;&lt;br /&gt;Systems almost always use proxy accounts to interact with other systems (e.g. application to database). Now let’s be honest – when was the last time we used any type of mechanism to restrict systems’ access based on anything (e.g. propagate end user permissions to the app-database interaction)? In most cases we simply grant privileged access rights to systems. Hey, it is much easier to use most permissive access rights required as the common (permission) denominator…&lt;br /&gt;&lt;br /&gt;2. &lt;strong&gt;Given the associated high risk I&amp;nbsp;probably already have controls in place&lt;/strong&gt;&lt;br /&gt;Does anything from the following list sounds familiar? Hardcoded passwords, clear text passwords in scripts, default password never changed, if we’ll touch it everything will break… The irony is personal accounts for real users has very limited access rights, while having stricter controls (even simple ones such as mandating frequently password change).&lt;br /&gt;&lt;br /&gt;3. &lt;strong&gt;But I have all those security systems so I must be covered, right?&lt;/strong&gt;&lt;br /&gt;This topic calls for a separate blog post altogether, however I’ll point out the fundamental principle of most systems handling users and accounts (such as IAM, SIEM, GRC, etc.) - the prerequisite to all operations is identification of users. They are great tools for personal accounts correlated to known users, and not really for privileged access points used by non carbon based entities. The solution is very simple – use the adequate tools!&lt;br /&gt;&lt;br /&gt;4. &lt;strong&gt;Privileged access points vulnerability is strictly for insiders&lt;/strong&gt;&lt;br /&gt;Picture yourself as the bad guy, which of the following would you target? Personal accounts with limited capabilities protected by some controls, OR privileged access points with limitless access protected by no control? The notion of an internal access point is long gone; especially with the borderless infrastructure trend (did I say cloud?).&lt;br /&gt;&lt;br /&gt;5. &lt;strong&gt;Adding new systems (including security) should not impact my security posture&lt;/strong&gt;&lt;br /&gt;That’s where it gets interesting. Most systems interact with others, whether of infrastructure nature (such as database, user store) or services. Whenever adding a system to your environment you immediately add administrative accounts to the service, and interaction points (access points) to other systems. As already mentioned most of these powerful access points are poorly maintained, causing a local vulnerability (of the new system) as well global vulnerability (new system serves as a hopping point to other network nodes). Regardless, your overall security posture goes down.&lt;br /&gt;&lt;br /&gt;6. &lt;strong&gt;I have much more accounts for real users than access points for systems&lt;/strong&gt;&lt;br /&gt;Though this fallacy might sound right, the reality is actually very different. It is not about how many systems you have but the inter-communication between them. Per enterprise customers I’ve talked with, the complexity of the network and magnitude of this challenge will surprise many.&lt;br /&gt;&lt;br /&gt;7. &lt;strong&gt;This vulnerability is isolated to my traditional systems&lt;/strong&gt;&lt;br /&gt;Some of the more interesting attacks/breaches from the past year present an interesting yet non-expected trend. The target is no longer confined to the traditional server, application, or database. Bad guys attacked source code configuration management systems (Aurora attacks), point of sale devices, PLC (stuxnet), ATMs, Videoconferencing systems (Cisco), etc. The extent of this phenomenon is actually very surprising. I even heard the other day, pacemakers has privileged accounts (for remote management). Now this is what I call a life and death type of vulnerability!&lt;br /&gt;&lt;br /&gt;When observing these fallacies and APT attacks characteristics, you realize Neuroprivilogy vulnerability is the Holy Grail for APT attackers. It perfectly fits the APT characteristics - not about quick/easy wins, but rather very patient, methodological and persistent attacks targeting a well defined (big) “prize”. You work the privileged access points’ network until finding the way in and winning the “big prize” (limitless access to the required/targeted parts of the infrastructure).&lt;br /&gt;&lt;br /&gt;The dummy version of comparing traditional to APT attacks is: traditional = a quick and easy win, APT = keep your eyes on the prize.&lt;br /&gt;&lt;br /&gt;Now going back to my opening question – is your Neuroprivilogy vulnerable? (No need to answer, just a rhetorical question)&lt;br /&gt;&lt;br /&gt;BTW – an interesting TED talk about neural networks and how it actually defines us: &lt;a href="http://www.ted.com/talks/sebastian_seung.html"&gt;http://www.ted.com/talks/sebastian_seung.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-7394582390750861327?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/7394582390750861327/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/12/neuroprivilogy-is-holy-grail.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/7394582390750861327'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/7394582390750861327'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/12/neuroprivilogy-is-holy-grail.html' title='Neuroprivilogy is the Holy Grail'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-1984478061690502874</id><published>2010-11-22T14:21:00.000-05:00</published><updated>2010-11-22T14:21:31.237-05:00</updated><title type='text'>v1.0 is always more successful when bundled with two sunny days at Orlando</title><content type='html'>Nothing like sunny Orlando in the middle of a Boston’s November, therefore you can imagine my excitement about participating at the first Cloud Security Alliance Conference this week.&lt;br /&gt;So what did we have there (other than ~90 degrees)?&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Interesting mix of participants (customers, vendors, thought leaders, consultants, federal)&lt;/li&gt;&lt;li&gt;Lots of cloud and security related sessions&lt;/li&gt;&lt;li&gt;Securing privileged users (insiders threat) and privileged access points (API management) are top concerns&lt;/li&gt;&lt;li&gt;Sitting in a panel discussion about securing applications and data in the cloud&lt;/li&gt;&lt;li&gt;Booth at the expo center (chance to both pitch and have interesting discussions with participants) &lt;/li&gt;&lt;li&gt;AND one big debate about security and the cloud&lt;/li&gt;&lt;/ul&gt;(Basically all the ingredients for two days well spent)&lt;br /&gt;&lt;br /&gt;While I can go into lengthy descriptions of sessions and other discussions, I prefer focusing on what I perceived as the biggest debate at the conference. Which of the following is right?&lt;br /&gt;&lt;br /&gt;The cloud is new therefore requires all applications and security solutions to be re-written&lt;br /&gt;&lt;div style="text-align: center;"&gt;OR&lt;/div&gt;&lt;div style="text-align: left;"&gt;Just of the same, been around for a while, let’s move our apps and secure it using current controls&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Surprisingly (or not) most influencers seem to believe things needs to be re-written.&lt;/div&gt;Not surprising (or …) I have a different take on that. But first a couple of clarifications:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;I’m tired with this binary approach to the cloud some people present – “either everything going to the cloud (1) or nothing (0)”. Think hybrid, we are going to have mixed environments for as long as you can currently plan.&lt;/li&gt;&lt;li&gt;Tired++ from this ongoing FUD competition (though I have to admit occasionally I participate). RELAX, don’t panic, we are going to be OK. The cloud is a great thing and a decision whether to adopt it is a business decision (based on its many virtues). And yes it has vulnerabilities and issues which need to be highlighted and addressed (start with focusing on operations accountability and transparency).&lt;/li&gt;&lt;/ol&gt;It is off my chest and I can finally address the cloud-security debate. As with most cases, the answer is somewhere in the middle. The cloud represents new concepts, technologies and delivery mechanism. Given the extent of the change (and opportunities) some areas are definitely going through a revolution and require re-thinking/re-architecting or as some of my colleagues put it – re-writing. However, when looking at public IaaS there are quite a few challenges that only experience evolution and can be addressed with existing tools and expertise (only some adjustments required). I thought my friend Gilad (founder+CEO @ Porticor) presented it nicely during his session.&lt;br /&gt;Now it is true every several years products gets re-written anywhere, therefore the shift to the cloud might be a good opportunity.&lt;br /&gt;&lt;br /&gt;My recommendation (my personal crystal ball):&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;If you are in the services business – identify evolution areas and follow them.&lt;/li&gt;&lt;li&gt;A vendor? the revolution domains is where you should be looking for opportunities.&lt;/li&gt;&lt;/ul&gt;When all is said and done, looking at Friday’s financial news: Salesforce’s Q3 results exceeded expectations and their stock is on fire! Makes you wonder whether customers really care or are we simply over hyping it all…&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-1984478061690502874?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/1984478061690502874/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/11/v10-is-always-more-successful-when.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/1984478061690502874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/1984478061690502874'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/11/v10-is-always-more-successful-when.html' title='v1.0 is always more successful when bundled with two sunny days at Orlando'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-1590674550596221505</id><published>2010-09-30T10:37:00.002-04:00</published><updated>2010-09-30T10:39:01.149-04:00</updated><title type='text'>Anything you can do I can do better</title><content type='html'>During the past several years it has become a hobby of many to bash the Identity Management vendors, solutions, deployments, you name it. It is too expensive, it takes forever to deploy, eventually it provides limited coverage, it is not business aware, it is too complex, did I mention the price? As an Identity Management veteran I can admit that, despite the major consolidation the market experienced and the multibillion $$$ market, some of it (probably most of it) is kind of right…&lt;br /&gt;&lt;br /&gt;Why is it any different from the natural evolution of other domains?&lt;br /&gt;&lt;br /&gt;Sometimes you encounter a special phenomenon where: &lt;br /&gt;&lt;br /&gt;1. The problem is well understood by everyone&lt;br /&gt;&lt;br /&gt;2. It is a major problem&lt;br /&gt;&lt;br /&gt;3. Every organization experiences it&lt;br /&gt;&lt;br /&gt;4. And are willing to pay to resolve it (thus the market is defined as a multibillion $$$ market) &lt;br /&gt;&lt;br /&gt;5. There are plenty of solutions out there&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;BUT NO EXPONENTIAL GROWTH&lt;/strong&gt; &lt;strong&gt;for any of the vendors&lt;/strong&gt;, wouldn’t you expect at least one to break away?&lt;br /&gt;&lt;br /&gt;So why does it happen? Sometimes because the existing products’ coverage is limited, other cases it is too complex, too expensive, (basically most of the reasons previously described).&lt;br /&gt;&lt;br /&gt;Those familiar with the domain knows that despite the white noise (of existing vendors) the market is anxiously awaiting someone to actually “do it better”, “be greater”, “sing louder”, “go higher”…&lt;br /&gt;&lt;br /&gt;This month I’ve participated in a couple of events – VMWorld 2010 and Arcsight Protect 2010. While representing Cyber-Ark and discussing our PIM (Privileged Identity Management) technologies I had a chance to listen to what the hosting vendors had to say. &lt;br /&gt;&lt;br /&gt;I’m happy to report that there are two new players stepping into the Identity Management space claiming to do it better. Meet VMWare (provisioning, self service and SSO) and Arcsight (IdentityView).&lt;br /&gt;&lt;br /&gt;It is true both vendors are very cautious with their announcements (Arcsight – we only do monitoring, VMWare – it is only for synchronous provisioning and we only manage our systems), come-on…&lt;br /&gt;&lt;br /&gt;What do you think, if VMWare customers ask to “simply integrate with a ticketing system for approvals” would they provide it? Or “can you open the platform for plug-ins to control other systems”?&lt;br /&gt;&lt;br /&gt;How about Arcsight customers requesting to be able to do some remediation actions (such as disable a suspicious account) directly from their control panel?&lt;br /&gt;&lt;br /&gt;I don’t know about you, but I think these guys are here to stay.&lt;br /&gt;&lt;br /&gt;Another market that experiences a similar phenomenon is information protection (DLP and/or ERM and/or EIP …). The extent of this challenge is huge (i.e. a major major problem for all organizations) and the current products are straggling to solve this hairy problem. However products are simply too complex, limited and fail to pick up. If I had to predict I would say waves of innovation are expected, and only a different take will manage to lift this domain to the next level. &lt;br /&gt;&lt;br /&gt;So if you are out there considering starting an information security start-up definitely look at this space, there’s alllllllllooooooooottttt to be done and it requires a fresh approach.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-1590674550596221505?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/1590674550596221505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/09/anything-you-can-do-i-can-do-better.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/1590674550596221505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/1590674550596221505'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/09/anything-you-can-do-i-can-do-better.html' title='Anything you can do I can do better'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-7052057330030160592</id><published>2010-08-05T15:12:00.008-04:00</published><updated>2010-08-05T22:49:51.304-04:00</updated><title type='text'>A Flat to Let – the Challenge of Selecting Neighbors</title><content type='html'>This week I would like to begin with a fable, based on an Eastern European folk tale translated to several other languages. Bear with me as I’m positive you’ll get (and like?) the metaphor!&lt;br /&gt;&lt;br /&gt;"At the edge of a valley so quiet and pretty, stands a five-story building far away from the city,"&lt;br /&gt;&lt;br /&gt;It begins, and describes the animal tenants on each floor: a fat hen, a cuckoo, a pampered black cat, a voracious squirrel. The fifth floor used to be inhabited by Mr. Mouse, but he disappears, and the neighbors put up a sign: "A Flat to Let." The flat is shown to many animals. Each follows the same cycle of sing-song questions and exclamations. But each visitor objects to one of the other animals, and rejects the flat.&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;img border="0" bx="true" src="http://2.bp.blogspot.com/_GlfI8n8nses/TFsK1OuQESI/AAAAAAAAAEM/B9Oh9jN1oes/s320/A+flat+to+Let.jpg" /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;“Do you like the rooms?&lt;/div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;They are nice. &lt;br /&gt;&lt;br /&gt;Do you like the kitchen?&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;It is nice.&lt;br /&gt;&lt;br /&gt;Do you like the hallway?&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;It is nice.&lt;br /&gt;&lt;br /&gt;Then dwell with us, Rabbit.&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;No, I won’t!&lt;br /&gt;&lt;br /&gt;Why?&lt;br /&gt;&lt;strong&gt;I don’t like the neighbors&lt;/strong&gt;. How can I, a mother of twenty bunnies, dwell together with a cuckoo, which deserts her children? Her children grow up in weird nests. All of them deserted, all of them neglected. What would my children learn from them?&lt;br /&gt;&lt;br /&gt;The cuckoo bird was hurt. And the rabbit went on her way.”&lt;br /&gt;&lt;br /&gt;Finding the right neighbors is tough, you don’t want end up with someone that will mow the lawn too early in the morning, drag his trash bins too late in the evening, nor have loud parties every other day. But how can you control it?&lt;br /&gt;&lt;br /&gt;Representing Cyber-Ark, I participated in Burton Catalyst 2010 conference last week. During the virtualization and cloud tracks, the inhibitors to public clouds topic was discussed. As expected security is still #1 concern, where &lt;strong&gt;multi-tenancy&lt;/strong&gt; is a big part of it.&lt;br /&gt;&lt;br /&gt;Translating it to “fable language” - organizations are very concerned about their neighbors (with whom they share infrastructure), and want to take part in the neighbors selection process. Everyone is using the example of Coke, claiming they will never agree to share infrastructure with Pepsi. Frankly, I believe they should be more concerned if Johnnie Hacker was their neighbor, but that’s just me…&lt;br /&gt;&lt;br /&gt;Some history - once upon a time infrastructure was private, no neighbors at all. Parents only had to deal with room allocations to family members (I want a bigger one, a better view, close to the kitchen, isolated, etc.).&lt;br /&gt;&lt;br /&gt;Fast forward, then there was the Cloud where infrastructure has become a shared resource for all citizens of the world, with no ability for tenants to impact the neighbors selection process.&lt;br /&gt;&lt;br /&gt;As potential tenants grew concerned with automatic allocation of neighbors, cloud vendors quickly responded offering a dedicated infrastructure option. This is obviously more expensive, to the point that the risk vs. benefit ratio is not as appealing anymore. Organizations preferred building private clouds, gaining partial capabilities of the “cloud movement”, while compromising on others.&lt;br /&gt;&lt;br /&gt;I believe we will witness evolution of new cloud computing models/offering in addition to public and dedicated, addressing the neighbors challenge.&lt;br /&gt;&lt;br /&gt;A few potential directions which come to mind:&lt;br /&gt;&lt;br /&gt;1. Co-location based on reputation - think about your car insurance policy, coverage as well as cost depends on your reputation (previous claims, driving record, etc.). Credit score is another reputation mechanism with direct impact on services you receive. An organization’s reputation (such as controls in place, attack record, load) will be used to determine their co-location. Companies with good reputation will be granted better service, lower cost and above all – reputable neighbors!&lt;br /&gt;&lt;br /&gt;2. Cloud communities – in the physical world we see communities forming around joint interests or trust. Similarly “cloud communities” with shared interests (such as regulations) or trust (community members trust each other) will be created. They will run their systems on shared infrastructures dedicated for the community. I foresee an eco-system of brokerage services helping forming these communities, and negotiating terms with cloud service providers on behalf of the community.&lt;br /&gt;&lt;br /&gt;3. The Cloud Randomizer – this started as a joke, but think about it. The cloud’s underlying technology is mainly virtualization; virtualization enables moving environments around with no down time. How about frequently moving organization’s systems around in a randomize way, reducing the likelihood of attacks (at least planned ones)?&lt;br /&gt;&lt;br /&gt;What do you think? Am I dreaming? Should I stick to folk tales?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-7052057330030160592?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/7052057330030160592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/08/flat-to-let-art-of-selecting-neighbors.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/7052057330030160592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/7052057330030160592'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/08/flat-to-let-art-of-selecting-neighbors.html' title='A Flat to Let – the Challenge of Selecting Neighbors'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_GlfI8n8nses/TFsK1OuQESI/AAAAAAAAAEM/B9Oh9jN1oes/s72-c/A+flat+to+Let.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-5367290769811591216</id><published>2010-07-23T14:30:00.000-04:00</published><updated>2010-07-23T14:30:58.497-04:00</updated><title type='text'>Hard-coded default passwords? The Ostrich for the rescue!</title><content type='html'>Some days I feel the world will be a much easier place to live in if we simply adopt the ostrich approach. If something looks slightly challenging, let’s just stick our head in the ground for a while and the problem will simply go away.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_GlfI8n8nses/TEnfpjZTzaI/AAAAAAAAAEE/zwz_aTVhdxg/s1600/ostrich+head+in+sand+sign.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="190" hw="true" src="http://1.bp.blogspot.com/_GlfI8n8nses/TEnfpjZTzaI/AAAAAAAAAEE/zwz_aTVhdxg/s200/ostrich+head+in+sand+sign.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Those of you who enjoy tracking threats, attacks, malware and the likes probably heard about the Stuxnet worm by now. For the rest of you it is malware targeting windows environments running Siemens software used by industrial companies. Once on systems, it uses Siemens default passwords to connect to the database and collect information.&lt;br /&gt;&lt;br /&gt;Does not sound like a big deal. Nobody is using default passwords these days and even in case they foolishly did, just change the password and have a good night sleep, right?&lt;br /&gt;&lt;br /&gt;ahmmm… unfortunately in that case I had to look for a different topic for my post…&lt;br /&gt;&lt;br /&gt;Those of you who follow my blog know by now that I’m not really a security radical, but rather moderate and open minded when it comes to the way security specialist grasp the world. But I can tell you that this incident is mind boggling even for me.&lt;br /&gt;&lt;br /&gt;Sin #1: using hard-coded passwords – happens from time to time, irresponsible behavior, slap on the wrist.&lt;br /&gt;&lt;br /&gt;Sin #2: sin #1’s hard-coded passwords are the default ones and are similar for all customers – doh!&lt;br /&gt;&lt;br /&gt;Sin #3: these passwords cannot be change (per Siemens) or the systems will stop working – what were these guys thinking? It is even worse than creating a system with no authentication mechanism at all, zip, open to the public, web 2.0 like... You communicate a FALSE sense of security that there are controls in place to secure usage of the system (i.e. authentication), yet the passwords are known to the public and cannot be changed?!&lt;br /&gt;&lt;br /&gt;Top it with Siemens’ response (reportedly advised customers not to change their default passwords, arguing it “may impact plant operations.”), leaving customers out there in the cold having to choose between bad and worst…&lt;br /&gt;&lt;br /&gt;There are many articles describing this incident, an example: http://tiny.cc/osg8q&lt;br /&gt;&lt;br /&gt;I’m positive Siemens will snap out of their current state of mind and resolve it, but the unfortunate part is the fact that this phenomenon and state of mind is not limited to Siemens. Some still use hard-coded passwords, some still use default passwords and some don’t change passwords.&lt;br /&gt;&lt;br /&gt;It is time to GET BACK TO THE BASICS!&lt;br /&gt;&lt;br /&gt;1. Authentication between systems should be externalized and governed by processes/tools that can rotate and secure credentials.&lt;br /&gt;&lt;br /&gt;2. Default passwords might be good for the initial bootstrap/setup procedure, however should be changed and should definitely be unique per customer&lt;br /&gt;&lt;br /&gt;3. There are tools designed to address the whole privileged accounts challenge regardless whether it is performed by humans or non carbon based entities (such as application, services, or devices).&lt;br /&gt;&lt;br /&gt;Unlike the common belief that vulnerability of internal, powerful credentials are a target for internal threat only, the reality is privileged accounts are a gem for external attackers. More frequently than you imagine external attacks target these powerful accounts, as hijacking these accounts makes external hackers’ life/job much easier.&lt;br /&gt;&lt;br /&gt;Next week is Burton Group’s Catalyst week, stay tuned for my take-aways/insights from the conference and sunny San Diego!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-5367290769811591216?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/5367290769811591216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/07/hard-coded-default-passwords-ostrich.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/5367290769811591216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/5367290769811591216'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/07/hard-coded-default-passwords-ostrich.html' title='Hard-coded default passwords? The Ostrich for the rescue!'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_GlfI8n8nses/TEnfpjZTzaI/AAAAAAAAAEE/zwz_aTVhdxg/s72-c/ostrich+head+in+sand+sign.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-6344367410285271987</id><published>2010-07-20T09:35:00.001-04:00</published><updated>2010-07-20T09:36:06.386-04:00</updated><title type='text'>The Jerry Maguire take on Security</title><content type='html'>I have a strong feeling this post is going to be my Jerry Maguire’s “Mission Statement”…&lt;br /&gt;&lt;br /&gt;A couple of comments for those who have not seen the movie:&lt;br /&gt;1. Keep reading as watching the movie is not a prerequisite&lt;br /&gt;2. You should probably consider watching it, it has some funny quotes&lt;br /&gt;&lt;br /&gt;A recap - Jerry Maguire is a 1996 film starring Tom Cruise about a sports agent who has a moral epiphany and is fired for expressing it, who then decides to put his new philosophy to the test as an independent with the only athlete who stays with him (Wikiquote.org - http://tiny.cc/sqj8p).&lt;br /&gt;&lt;br /&gt;My case is obviously different: it is not so much an epiphany but rather some thoughts/insights, and the whole firing part??? &lt;br /&gt;&lt;br /&gt;Despite the many changes the security community experienced, one thing seemed to stick with us throughout the years (especially as compliance has been bolted on to security) – FEAR. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;If we’ll scare them they will come!&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Fear as a way of thinking about the challenges, fear as a design criteria, fear as a way to prioritize features, fear as a driver for pricing, and certainly fear as a selling tactic.&lt;br /&gt;&lt;br /&gt;It is kind of a negative way of thinking, don’t you think?&lt;br /&gt;&lt;br /&gt;Recently I have participated in the Enterprise 2.0 conference. Surprisingly these guys approach issues differently, on the verge of a Woodstock atmosphere. It is all about collaboration, opening up the organization, loosing controls, doing good for everyone (rainbows and violin background music…). Almost too much positive thinking for me…&lt;br /&gt;&lt;br /&gt;In the audience I could notice quite a few CIOs, most of which participate in our (security) conferences as well. It simply mind boggling what is going through their minds when they hear both enterprise 2.0 and security pitches. The contradiction is simply amazing. &lt;br /&gt;&lt;br /&gt;So who has it right?&lt;br /&gt;Are we right and they are naïve, or they have it right and we are simply afraid?&lt;br /&gt;&lt;br /&gt;As with most things, I believe the truth is somewhere in between.&lt;br /&gt;&lt;br /&gt;You would rightfully say organizations spend their security budgets addressing threats. And Rod Tidwell’s immortal motto is probably correct (from the movie of course): “Show me the money!” security vendors should continue addressing these threats and fears. Hey, this is our thing and we should keep on doing it.&lt;br /&gt;&lt;br /&gt;However I still believe there is a place for positive thinking in our domain (security). The infrastructure play and information our security systems are exposed to can be leveraged for positive spins. Topics such as increase awareness, productivity and reduce cost can all be addressed.&lt;br /&gt;&lt;br /&gt;Just a few simple examples (I’m keeping the real interesting ones for internal usage…):&lt;br /&gt;1. While monitoring usage of applications the system can recommend (potentially even automate) adding the more popular apps under the SSO umbrella.&lt;br /&gt;2. As we monitor behavioral patterns for fraud detection we can contribute to optimize web applications increasing productivity and reducing cost.&lt;br /&gt;3. During the access control to unstructured data we can identify usage frequency and suggest lower cost storage for hardly used documents or “cache” more frequently used data.&lt;br /&gt;4. And even small frustrating thing as laptop’s startup time can be improved as application usage is monitored, we can identify hardly used apps/services and remove them from the startup sequence.&lt;br /&gt;&lt;br /&gt;Can you imagine positive thinking can become a differentiator in the security domain?&lt;br /&gt;Do you believe customers will actually be willing to spend their security $$$ on positive things?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-6344367410285271987?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/6344367410285271987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/07/jerry-maguire-take-on-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/6344367410285271987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/6344367410285271987'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/07/jerry-maguire-take-on-security.html' title='The Jerry Maguire take on Security'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-9024855150659571674</id><published>2010-06-25T10:23:00.000-04:00</published><updated>2010-06-25T10:23:08.382-04:00</updated><title type='text'>Gold Rush – The return of the King</title><content type='html'>&lt;div class="MsoNormal"&gt;5:45pm – just as I was planning to head out to the Apple store I get the following alert:&lt;/div&gt;&lt;div class="MsoNormal"&gt;SEVERE THUNDERSTORMS PRODUCE DAMAGING WINDS AND LARGE HAIL... AS WELL AS DEADLY LIGHTNING AND TORRENTIAL RAIN. GET TO SAFE SHELTER NOW... INSIDE A STURDY BUILDING OR IN A VEHICLE. DO NOT SEEK SHELTER UNDER TREES. IF YOU CAN HEAR THUNDER... YOU ARE CLOSE ENOUGH TO BE STRUCK BY LIGHTNING. DRIVERS SHOULD BE ALERT FOR PONDING OF WATER AND AVOID FLOODED ROADS.&lt;/div&gt;&lt;div class="MsoNormal"&gt;A SEVERE THUNDERSTORM WATCH REMAINS IN EFFECT UNTIL 800 PM EDT THURSDAY EVENING FOR NORTHERN CONNECTICUT AND MASSACHUSETTS AND SOUTHERN NEW HAMPSHIRE AND CENTRAL RHODE ISLAND.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;You got to be kidding me!&lt;/div&gt;&lt;div class="MsoNormal"&gt;If you really think a deadly thunderstorm storm will hold me back from getting the prize, then think again.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;6:10pm got to the store (still alive) only 5 people in line (all with pre-orders or tickets). This obviously proves that you get a better treatment if you are invited to the party…&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;7:00pm returning home as a winner, I’m probably looking at a romantic evening where together each one is busy updating his new iPhone…&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Not sure what the big excitement is all about – after all it is just a phone (and an ipod and an email device and an app platform probably the coolest gadget around…)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I have finally figured out the name “iPhone 4”, looks like you have to wait 4 hours to get an iPhone…&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-9024855150659571674?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/9024855150659571674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/06/gold-rush-return-of-king.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/9024855150659571674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/9024855150659571674'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/06/gold-rush-return-of-king.html' title='Gold Rush – The return of the King'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-450555580050569163</id><published>2010-06-24T11:45:00.001-04:00</published><updated>2010-06-24T11:47:19.755-04:00</updated><title type='text'>Gold Rush</title><content type='html'>&lt;div class="MsoNormal"&gt;I have finally decided to walk the walk and make the commitment. Despite the nasty mother in law (AT&amp;amp;T) I’m getting an iPhone 4.&lt;/div&gt;&lt;div class="MsoNormal"&gt;For the first time in my life I’m going to actually wake up early, stand in line and on the premiere be one on the lucky ones (as well as additional 1M people) to have the new majestic device! &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;So this is how it went (so far):&lt;/div&gt;&lt;div class="MsoNormal"&gt;5:40am – woke up (going to get the iPhone 4 today, YEAH!) &lt;/div&gt;&lt;div class="MsoNormal"&gt;5:55am – reports on the internet: already long lines (still optimistic)&lt;/div&gt;&lt;div class="MsoNormal"&gt;6:15am – the Dinoor team is out on the road (cautiously optimistic)&lt;/div&gt;&lt;div class="MsoNormal"&gt;6:20am – Dunkin Donuts, and we are ready for the action (carbs are always good for the spirit)&lt;/div&gt;&lt;div class="MsoNormal"&gt;6:25am – the parking lot is half full, at 6:25 in the morning!? (Um, Oh...right)&lt;/div&gt;&lt;div class="MsoNormal"&gt;6:30am – finally standing in line, practically at the mall’s entrance with probably 200-300 people in front of us (it is going to be a long day)&lt;/div&gt;&lt;div class="MsoNormal"&gt;7:01am – we are moving! Actually the other line (pre-order) is moving (shall I cut my losses here and now, i.e. leave?)&lt;/div&gt;&lt;div class="MsoNormal"&gt;7:30am – made 10 feet progress and rumors has it the pre-order line is getting in first (50:1 ratio between the lines)&lt;/div&gt;&lt;div class="MsoNormal"&gt;8:45am – nothing (let’s pack our thing and leave, such a looser…)&lt;/div&gt;&lt;div class="MsoNormal"&gt;9:00am – there is a God up there, I have made it! I’m the proud owner of a … ticket assuring me an iPhone (the line is still long, but who cares?)&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_GlfI8n8nses/TCN9cDRVsqI/AAAAAAAAADs/RHyD713pwS8/s1600/Tickets.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_GlfI8n8nses/TCN9cDRVsqI/AAAAAAAAADs/RHyD713pwS8/s320/Tickets.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;9:15am – leaving the scene as a winner, I’ll be back later on tonight to pick it up&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Stay tuned for more on how the saga ends!&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-450555580050569163?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/450555580050569163/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/06/gold-rush.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/450555580050569163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/450555580050569163'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/06/gold-rush.html' title='Gold Rush'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_GlfI8n8nses/TCN9cDRVsqI/AAAAAAAAADs/RHyD713pwS8/s72-c/Tickets.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-8957356893692316618</id><published>2010-06-21T14:27:00.002-04:00</published><updated>2010-06-22T07:48:51.725-04:00</updated><title type='text'>Worth Repeating</title><content type='html'>I find myself quite often quoting expressions I hear at different places. Surprisingly people seem to enjoy it and even (God forbid) use it at later times...&lt;br /&gt;&lt;br /&gt;As an entertaining exercise, I’m going to post these valuable quotes from time to time at the “Worth Repeating” section on the right (keep scrolling down).&lt;br /&gt;&lt;br /&gt;To kick it off I’m going to start with a few I’ve heard recently:&lt;br /&gt;&lt;br /&gt;1. “Security is like life insurance, you only win when you lose” Dr. Rainer Janßen, Munich Re CIO, EIC 2010, Munich May 2010&lt;br /&gt;&lt;br /&gt;2. “The cloud is cloudy, not transparent” someone at EIC 2010, Munich May 2010. While discussing Cloud and security concerns&lt;br /&gt;&lt;br /&gt;3. “The bits move faster than people, make sure to bring the people with you” Sanjay Mirchandani, (EMC CIO), EMC World, Boston May 2010. While discussing the journey to the cloud.&lt;br /&gt;&lt;br /&gt;4. “The technology market is definitely accelerating - it took IBM 40 years to become the evil, Microsoft 25, Google 10, Facebook 5 and Twitter 2.5” JP Rangaswami, Enterprise 2.0 conference, Boston June 2010&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-8957356893692316618?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/8957356893692316618/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/06/worth-repeating.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/8957356893692316618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/8957356893692316618'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/06/worth-repeating.html' title='Worth Repeating'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-193338609309308286</id><published>2010-06-17T09:54:00.000-04:00</published><updated>2010-06-17T09:54:04.132-04:00</updated><title type='text'>ShaaS</title><content type='html'>Regardless of what people might say, the recent couple of years were great for the technology industry. We (technologists) exhausted the 3 and 4 letter acronyms, and at some point just when we thought 5 letters is the new 3 letter a miracle has happen. &lt;br /&gt;&lt;br /&gt;The CLOUD was created enabling us to cloud wash everything by simply adding “aaS” as a suffix. This allowed us to start all over again with the 1-2 letters game. &lt;br /&gt;&lt;br /&gt;As you can see I’m no different than the rest. So what is ShaaS (used in the title) all about? Is it simply &lt;strong&gt;Sh&lt;/strong&gt;lomi &lt;strong&gt;a&lt;/strong&gt;s &lt;strong&gt;a&lt;/strong&gt; &lt;strong&gt;S&lt;/strong&gt;ervice? Better guess again…&lt;br /&gt;&lt;br /&gt;It is actually &lt;strong&gt;Sh&lt;/strong&gt;aring &lt;strong&gt;a&lt;/strong&gt;s &lt;strong&gt;a&lt;/strong&gt; &lt;strong&gt;S&lt;/strong&gt;ervice. A lot was said and written about collaboration and sharing of data but despite the chatter, solutions have not addressed some of the key challenges.&lt;br /&gt;&lt;br /&gt;I’ll focus just on one of these challenges - modern collaboration and data sharing are dynamic by nature and cannot be controlled by static policies/controls. &lt;br /&gt;&lt;br /&gt;Let’s follow a use case (as an example) – sharing a document with a group of people. The team can access the file, download it, read it, etc. But what happens two weeks from now when something has changed and I want to stop sharing the file with some members of the team? Using existing information protection techniques (such as DLP or DRM) will not allow me to do it as the file is already in possession of these people. Even if it was wrapped by some type of a shell (in the case of DRM), it is based on a static, outdated policy. &lt;br /&gt;&lt;br /&gt;It is true Enterprise 2.0 guys say (rightfully) organizations should design for loss of control (including over data) as web 2.0 penetrates the enterprise. However while organizations promote sharing/collaboration they should protect their sensitive data. &lt;br /&gt;&lt;br /&gt;Another interesting phenomenon is the different approach to data by enterprises and consumers. While the enterprise default is “secure first then ask questions”, for consumers it is all about sharing (security? privacy? No one cares!). It looks like consumers treat data as almost nonexistent unless it is shared.&lt;br /&gt;&lt;br /&gt;It will be interesting to see a TTS (“Time To Share”) graph over time (i.e. time from actual event to when it is shared). I’m willing to bet TTS has dramatically gone down and is currently very low.&lt;br /&gt;&lt;br /&gt;Evolution:&lt;br /&gt;1. In the past one would take photos of an event, download it to the computer, upload it to your favorite social networking tool and share it with a selected audience.&lt;br /&gt;2. Then it seems all devices introduced direct social networking posting capabilities.&lt;br /&gt;3. Next using telepathy capabilities, thoughts will be automatically posted.&lt;br /&gt;4. And finally, the ultimate sharing tool – the Twitter generator. Based on my interests and real events will automagically generate tweets in real-time (on my behalf). I will be perceived extremely smart, how cool is that? &lt;br /&gt;&lt;br /&gt;The reality is probably somewhere in the middle, sharing of data is fundamental for the business, yet should be controlled to protect the business. Information protection systems should be morphed with data sharing tools taking its dynamic nature into consideration.&lt;br /&gt;&lt;br /&gt;While I leave you with this, I’ll go back to think how to make Shlomi as a Service a viable business…&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-193338609309308286?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/193338609309308286/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/06/shaas.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/193338609309308286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/193338609309308286'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/06/shaas.html' title='ShaaS'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-6316056678644467782</id><published>2010-05-17T16:31:00.000-04:00</published><updated>2010-05-17T16:31:40.022-04:00</updated><title type='text'>The Shlomi Cloud!</title><content type='html'>Facebook owns my photos, Google owns my emails/documents/contacts, LinkedIn owns my network, Delicious owns my favorites, and even my real URLs are not in my possession (but by the Tiny URLs of the world)…&lt;br /&gt;&lt;br /&gt;Did I totally lose it?&lt;br /&gt;&lt;br /&gt;I recently read about a new startup offering us to manage all our social networking sites from one place. Finally you can move pictures from Picasa to Facebook and then to Google docs, all from a single location. Kind of nice, right? While it is probably very useful (haven’t tried it yet), I say - not another aggregator please!&lt;br /&gt;&lt;br /&gt;Instead I want to use a hub and spoke model and have my own Shlomi cloud (clouds are exceptionally trendy these days) where I own/control/manage/store eeevvvverything. &lt;br /&gt;&lt;br /&gt;I can define my network (tree/forest of relationships) in one place and carry it (or a subset of it) with me to different social network sites (today to Facebook or LinkedIn, and tomorrow to the next big thing). &lt;br /&gt;&lt;br /&gt;I can store all my photos, documents, etc. and delete them whenever I want, knowing no zombie copies are floating in the WWW wilderness.&lt;br /&gt;&lt;br /&gt;I can create my personas and manage them, deciding which persona to present and when.&lt;br /&gt;&lt;br /&gt;And all the great social networking sites can focus on the services they provide while referencing my identity from the Shlomi Cloud.&lt;br /&gt;&lt;br /&gt;What do you think? Is it time to start the MyPersonalCloud.org movement, where everyone can create, own and control his own piece of identity?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-6316056678644467782?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/6316056678644467782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/05/shlomi-cloud.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/6316056678644467782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/6316056678644467782'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/05/shlomi-cloud.html' title='The Shlomi Cloud!'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-7727712451678649774</id><published>2010-04-01T17:27:00.001-04:00</published><updated>2010-04-01T17:29:39.574-04:00</updated><title type='text'>The Global Brainstorming Event of the Year</title><content type='html'>Writing about April fools day scams is kind of corny, right?&lt;br /&gt;&lt;br /&gt;I’m in the business of ideas and innovation, so let me ask you a question and try to answer it from my perspective:&lt;br /&gt;How do you call a once in a year event, where great minds think outside the box with no boundaries or limitations, and publicly introduce theoretical innovative ideas that even sound reasonable in some cases (with no patents, NDAs, IP restrictions, etc.)?&lt;br /&gt;&lt;br /&gt;Now you might call it April’s fools’ day, but for me it is Global Brainstorming Event of the Year (GBEY). &lt;br /&gt;So welcome to GBEY 2010!&lt;br /&gt;&lt;br /&gt;Here some of this year’s pranks. Try making some sense out of them: &lt;br /&gt;1. Topeka is Google (really), now &lt;a href="http://www.google.com/"&gt;Google is Topeka&lt;/a&gt; &lt;br /&gt;2. &lt;a href="http://www.starbucks.com/blog/10113/starbucks-listens-to-customer-request-for-more-sizes.aspx"&gt;Starbucks introducing ridiculous new sizes&lt;/a&gt;&lt;br /&gt;3. &lt;a href="http://bit.ly/98YVDA"&gt;No Coffee for you!&lt;/a&gt; While Starbucks introduce new cup sizes, the FDA ban coffee causing the same Starbucks to move outside of the US.&lt;br /&gt;4. &lt;a href="http://www.youtube.com/watch?v=3I24bSteJpw&amp;amp;feature=player_embedded"&gt;Introducing Google Translate for Animals&lt;/a&gt;&lt;br /&gt;5. &lt;a href="http://blog.hubspot.com/blog/tabid/6307/bid/5812/New-HugSpot-Dating-Software-Helps-Singles-Find-Love-Online.aspx"&gt;HugSpot by HubSpot?&lt;/a&gt; New HugSpot Dating Software Helps Singles Find Love Online.&lt;br /&gt;6. &lt;a href="http://www.socialtext.com/blog/2010/04/socialtext-releases-chatroulette.html"&gt;Chatroulette for the Enterprise&lt;/a&gt;, Randomized Productivity Management, i.e. RPM (who comes up with these acronyms!?).&lt;br /&gt;7. Gartner publish &lt;a href="http://blogs.gartner.com/brian_prentice/2010/04/01/microsoft-decides-to-open-source-windows-operating-system/"&gt;Microsoft Decides To Open Source Windows&lt;/a&gt; Operating System.&lt;br /&gt;8. New mobile search option, &lt;a href="http://googlemobile.blogspot.com/2010/04/our-newest-mobile-search-feature-where.html"&gt;Where am I?&lt;/a&gt; who am I? why am I?&lt;br /&gt;9. &lt;a href="http://youtube-global.blogspot.com/2010/03/textp-saves-youtube-bandwidth-money.html"&gt;New resolution used by YouTube&lt;/a&gt; (TEXTp) saves YouTube bandwidth and money.&lt;br /&gt;10. &lt;a href="http://www.insideredbox.com/redbox-to-speed-up-dvd-return-process-save-jobs/"&gt;Redbox to Speed Up DVD Return Process&lt;/a&gt; by adding a return butler (i.e. real person) next to each kiosk).&lt;br /&gt;11. iHOB, a new iPhone application that &lt;a href="http://blog.tamar.com/2010/04/tamar-announce-the-ihob-latest-innovation-in-iphone-app-technology/"&gt;turns your phone into a mini-stove&lt;/a&gt; (great stuff!). It provides a 15 ring system to heat up in mere seconds to be warm enough to heat a can of baked beans or soup in 15 minutes and once turned off will cool down in 15 seconds.&lt;br /&gt;12. A must have accessory for the iPad fans, an &lt;a href="http://www.ugo.com/the-goods/icade-the-april-fools-joke-with-a-bright-future"&gt;arcade cabinet for iPad&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And the list goes on and on and on…&lt;br /&gt;&lt;br /&gt;If you observe GBEY 2010 scams from my point of view, you might realize that with the right spin some of these crazy ideas can actually be quite good…&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-7727712451678649774?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/7727712451678649774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/04/global-brainstorming-event-of-year.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/7727712451678649774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/7727712451678649774'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/04/global-brainstorming-event-of-year.html' title='The Global Brainstorming Event of the Year'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-6495693935658228008</id><published>2010-03-23T11:24:00.000-04:00</published><updated>2010-03-23T11:24:12.571-04:00</updated><title type='text'>TSA plays Russian roulette, yet again…</title><content type='html'>A quick disclaimer: I have nothing against TSA, despite the fact I’ve missed a flight in the past due to long lines at the security check… They are a symptom of a greater problem rather than the problem itself.&lt;br /&gt;&lt;br /&gt;Now that we’ve put it aside let’s observe TSA’s mission statement (&lt;a href="http://www.tsa.gov/who_we_are/mission.shtm"&gt;http://www.tsa.gov/who_we_are/mission.shtm&lt;/a&gt;):&lt;br /&gt;“The Transportation Security Administration protects the Nation's transportation systems to ensure freedom of movement for people and commerce” &lt;br /&gt;&lt;br /&gt;And vision statement:&lt;br /&gt;“The Transportation Security Administration will continuously set the standard for excellence in transportation security through its people, processes, and technology.”&lt;br /&gt;&lt;br /&gt;Sounds like TSA are heavy duty on security, right?&lt;br /&gt;&lt;br /&gt;Well, I will not discuss transportation security (though debatable by some); however history tells us a slightly different story when it comes to information security…&lt;br /&gt;&lt;br /&gt;Looking at the past 4 years:&lt;br /&gt;&lt;br /&gt;2007 (&lt;a href="http://bit.ly/aoChfI"&gt;http://bit.ly/aoChfI&lt;/a&gt;) – External hard drive containing data from approximately 100,000 archived employment records went missing from a controlled area at TSA.&lt;br /&gt;&lt;br /&gt;2009 (&lt;a href="http://bit.ly/5REHBu"&gt;http://bit.ly/5REHBu&lt;/a&gt;) – TSA accidentally posted a document containing highly sensitive information on its airport screening procedures on a government website.&lt;br /&gt;&lt;br /&gt;2010 (&lt;a href="http://bit.ly/dc2Nbu"&gt;http://bit.ly/dc2Nbu&lt;/a&gt;) – Poor security protocols lead to TSA fired worker sabotaging TSA’s databases containing information tied to the war on terror and other law enforcement activities. &lt;br /&gt;&lt;br /&gt;While some might argue this is an unfortunate collection of non related incidents, I would seriously doubt it. With no intent of being harsh with TSA, this comedy of errors is an indication how security is perceived at TSA. &lt;br /&gt;&lt;br /&gt;Starting point:&lt;br /&gt;It will never happen to us! (Therefore no real controls, procedures or C-level directives are necessary)&lt;br /&gt;&lt;br /&gt;Post incident #1:&lt;br /&gt;Oops, it did happen. Ok, it will never happen to us AGAIN! (Must be a random statistic glitch, our current strategy is proving itself!)&lt;br /&gt;&lt;br /&gt;Post incident #2:&lt;br /&gt;Not again, No way! (Hmmm, at least we placed on each page of the manual the following: NO PART OF THIS RECORD MAY BE DISCLOSED TO PERSONS WITHOUT A 'NEED TO KNOW.')&lt;br /&gt;&lt;br /&gt;Post incident #3:&lt;br /&gt;Doh! Let’s bring in a data breach response services company to clean out the mess (&lt;a href="http://bit.ly/c0loLq"&gt;http://bit.ly/c0loLq&lt;/a&gt;). (Addressing the collateral damage is probably going to solve the problem!)&lt;br /&gt;&lt;br /&gt;Most of these types of incidents can be addressed today with existing controls. These are not operator errors, but a depressing example of the overall organizational/C-Level failure to enact security policies (much which are seemingly common procedures) that secures data and protects sensitive assets.&lt;br /&gt;&lt;br /&gt;If C-level execs don’t get it they can simply view it as an insurance policy (ensuring bad things don’t happen). People get an insurance policy not because they plan to use it on a daily basis, but mainly because if something happens it can be substantial.&lt;br /&gt;&lt;br /&gt;Another way to look at the statistics is organizations play a game of Russian roulette, assuming it will not happen to them (there is only one bullet and five empty chambers). &lt;br /&gt;&lt;br /&gt;With the case of TSA - it looks like the cylinder is practically full…&lt;br /&gt;&lt;br /&gt;Today I was riding with the four horsemen of the apocalypse, so I’ll finish with a positive tone:&lt;br /&gt;Spring is here, happy (belated) equinox (&lt;a href="http://bit.ly/2qHKU1"&gt;http://bit.ly/2qHKU1&lt;/a&gt;)!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-6495693935658228008?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/6495693935658228008/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/03/tsa-plays-russian-roulette-yet-again.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/6495693935658228008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/6495693935658228008'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/03/tsa-plays-russian-roulette-yet-again.html' title='TSA plays Russian roulette, yet again…'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-6892523522743544155</id><published>2010-03-12T16:15:00.001-05:00</published><updated>2010-03-12T16:17:27.181-05:00</updated><title type='text'>Brain dump</title><content type='html'>Last week I’ve participated in the RSA conference representing Cyber-Ark. It turned out to be a pretty busy week (your sympathy is appreciated). &lt;br /&gt;&lt;br /&gt;This week as a slightly different exercise, we will switch roles (let’s call it un-blog post). Instead of me describing my insights, I will provide some raw data from the conference in a form of a brain dump. If any of this makes any sense to you please comment or ping me with your insights.&lt;br /&gt;&lt;br /&gt;As with any brain dump - no order, priority or importance, just partial list of raw numbers/”facts”:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Server Virtualization penetration in enterprise is estimated at 25%&lt;/li&gt;&lt;li&gt;6% of ID theft comes from password guessing&lt;/li&gt;&lt;li&gt;IT spend 2/3 of their budgets on maintenance&lt;/li&gt;&lt;li&gt;CIO survey – for 51% security is the greatest concern surrounding cloud computing adoption&lt;/li&gt;&lt;li&gt;Information growth - 60% per year&lt;/li&gt;&lt;li&gt;1B mobile devices will be accessing the internet by the end of the year&lt;/li&gt;&lt;li&gt;Survey of 2,100 companies (CIO, IT, CSO, etc.):&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Over the last 12 months 75% experienced cyber attack&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - 100% experienced cyber lose in 2009&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - Top 3 stolen “items”:&lt;br /&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1. Theft of IP&lt;/div&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2. Financial/credit card data&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;3. Customer PII&lt;br /&gt;&lt;ul&gt;&lt;li&gt;During 2008 – 1.6M signatures (like previous 17 years combined)&lt;/li&gt;&lt;li&gt;During 2009 – 2.9M signatures&lt;/li&gt;&lt;li&gt;Customers said from their entire data only 1% matters&lt;/li&gt;&lt;li&gt;40% of employees private machines access work resources&lt;/li&gt;&lt;li&gt;10% of private machines are the primary working machine&lt;/li&gt;&lt;li&gt;Some organization promoting personal devices for work (subsidize)&lt;/li&gt;&lt;li&gt;Per Gartner – organization can save 9-40% on equipment cost&lt;/li&gt;&lt;li&gt;Data breach - average loss per record is $204&lt;/li&gt;&lt;li&gt;Data breach - average loss per incident is $6.75M&lt;/li&gt;&lt;li&gt;70% of physicians are afraid to place customer data in the cloud&lt;/li&gt;&lt;li&gt;56% of the malware written today is designed to steal data&lt;/li&gt;&lt;li&gt;42% of data breaches involve a 3rd party (service provider, consultant, etc.)&lt;/li&gt;&lt;li&gt;Since 2008 there are more mobile devices accessing the internet than “fixed” devices&lt;/li&gt;&lt;li&gt;By the end of 2011 there will be 5B users out of 6.8B people in the world… &lt;/li&gt;&lt;li&gt;Projected data traffic increased 2009-2014 is by 3900%&lt;/li&gt;&lt;li&gt;Videos will be 66% of mobile traffic by 2013&lt;/li&gt;&lt;li&gt;Organization leveraging Amazon cloud services usually have one super admin account to purchase and manage their infrastructure:&lt;/li&gt;&lt;/ul&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - It is a shared account&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - It is a standard Amazon account and can be used to purchase books or anything else…&lt;br /&gt;&lt;br /&gt;&lt;div&gt;As an epilogue to get your CPU working a quote by Marc Benioff:&lt;/div&gt;&lt;em&gt;“Why isn’t all enterprise software like Facebook?” It was the next iteration of the question he asked in 1999 (that spawned salesforce.com), “Why isn’t all enterprise software like Amazon.com.”&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-6892523522743544155?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/6892523522743544155/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/03/brain-dump.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/6892523522743544155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/6892523522743544155'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/03/brain-dump.html' title='Brain dump'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-4279943300711527020</id><published>2010-02-26T21:22:00.002-05:00</published><updated>2010-03-31T13:35:28.671-04:00</updated><title type='text'>No Internet or Laptop for you!</title><content type='html'>A couple of weeks ago I blabbered about a &lt;a href="http://shlomidinoor.blogspot.com/2010/02/world-with-no-it-resources-should.html"&gt;world with no IT resources&lt;/a&gt;. Since then I had a chance to discuss it with friends, especially the end device ownership part and thought it is interesting enough to share with others.&lt;br /&gt;&lt;br /&gt;During the 15th century the Feudalism system was very common in Europe. The lucky ones played the role of lords and “life was good,” for the rest (vassals) the story was slightly different…&lt;br /&gt;Let’s look at the employee-employer relationship back then. A common “compensation” package a vassal could expect would include a very small component of “salary” and a relatively large component of benefits consisting of food, clothing, housing, security, and possibly heritage rights. In return the lords practically “owned” them.&lt;br /&gt;Therefore the equation was you (the vassal) will work your butt off for me (the lord) and in return I’ll give you everything you need to barely live + some change.&lt;br /&gt;&lt;br /&gt;Through the years gradually the salary portion grew while the benefit component has gone down.&lt;br /&gt;&lt;br /&gt;Looking at today’s common compensation package, it includes a large component of salary and a relatively small component of benefits. Food, clothing, housing, security, heritage rights? Are you kidding me? &lt;br /&gt;&lt;br /&gt;This trend continues and will affect the “end device ownership” dilemma previously discussed. &lt;br /&gt;&lt;br /&gt;Companies already take it for granted consumer employees will have internet access at home, so they are capable of continue working (if needed). Now who pays for the internet, electricity, etc.?&lt;br /&gt;End devices are next in line (cell phone, laptop, tablet, etc.). Surprisingly we have an unusual case of common interest. Most consumer employees will be happy using their own device for both home and work activities. We already see today some companies funding the purchase of personal device for work. &lt;br /&gt;As you are expected to show up to work dressed up, employers will mandate end devices capable of doing your work. The good news is as most/all the computing will happen in backend systems (virtual desktop solution), so the requirement for your device is going to be pretty basic. &lt;br /&gt;&lt;br /&gt;If we’ll look at the futuristic equation (right around the corner) the employer (i.e. the lords) will give you (the consumer employee) salary only, and in return you’ll be responsible for everything needed to do your work (and obviously work).&lt;br /&gt;&lt;br /&gt;Next week it is RSA conference week, therefore no post for you (but many sessions, meetings and dinners for me).&lt;br /&gt;See you in a couple of weeks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-4279943300711527020?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/4279943300711527020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/02/no-internet-or-laptop-for-you.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/4279943300711527020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/4279943300711527020'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/02/no-internet-or-laptop-for-you.html' title='No Internet or Laptop for you!'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-8531687688711862435</id><published>2010-02-17T14:09:00.002-05:00</published><updated>2010-02-17T14:12:32.041-05:00</updated><title type='text'>There is an App (war) for that</title><content type='html'>Once upon a time many, many years ago Apple has lost the OS = Operating System battle (at least the first round). Some believe the main reason was Microsoft’s smart platform play. The Redmond giant bet on building an open OS, not open source but rather a set of robust, easy to use, well documented, supported APIs. They figure out early in the game the simple ‘law of nature’ – easiness of creating applications cause more applications to be created which cause higher value to the underlying platform (OS) resulting in more money to the OS vendor (which is … Microsoft of course).&lt;br /&gt;&lt;br /&gt;&amp;lt; Side comment - today in the era of Cloud Computing Microsoft is betting again on the platform, through their Azure offering.&amp;gt;&lt;br /&gt;&lt;br /&gt;Fast forward to early 2008 (if I got it right), Apple has launched the AppStore (less than a year after launching the iPhone). Well, it seems Steve Jobs has done his homework. He created an ‘open’ platform (iPhone OS) and invested/promoted the AppStore concept (more than 150k apps and counting). &lt;br /&gt;&lt;br /&gt;Apple in the role of Microsoft? Doh!&lt;br /&gt;&lt;br /&gt;A different school of thought claims what Microsoft has done to the Macs, Google is doing now to the iPhone/AppStore. Apple still has a one HW-one SW strategy; as far as they’re concerned apps can only run on their HW. Google is making friends with many HW vendors and their Android OS/apps can run on a slew of devices. While Google only has to focus on the SW, Apple needs to be best at both fronts (HW &amp;amp; SW) in order to continue dominating the market.&lt;br /&gt;&lt;br /&gt;Though a history fan, why do I open with a history lesson?&lt;br /&gt;&lt;br /&gt;News from early this week: ‘Biggest mobile operators join forces on app store project’. It was all over the media (e.g. &lt;a href="http://tiny.cc/ktgxp"&gt;http://tiny.cc/ktgxp&lt;/a&gt;). Should we assume the battle on the apps has just begun? &lt;br /&gt;&lt;br /&gt;Of course not! This battle is as old as the Operating Systems. Mostly it was the OS owners fighting for position (Microsoft, Apple, Google, etc.), however occasionally others get greedy (given the size of the turf). It is easier making money selling services/apps in the mobile space, mainly as users are used to paying extra for extra. PC consumers expect everything to be provided as a service (over the internet) and for free. When was the last time you paid for services/apps?&lt;br /&gt;&lt;br /&gt;While these 24 carriers claim their motivation is pure - ‘developers will be able to go to one place to get their applications distributed instead of having to go through multiple application approval processes’ (Yeah right…), it is clear they are after piece of the action. Apple’s appStore and Google's Android Market are being challenged by mobile network operators (per article).&lt;br /&gt;&lt;br /&gt;Apple’s appStore, Google's Android Market and recent initiative (by mobile network operators) are all about consumer apps, but what about the enterprise?&lt;br /&gt;&lt;br /&gt;If I’m an enterprise bought into Apple’s vision and seeking to provide customized (business) apps for my staff, how do I achieve it? How can I enable the iPhone in a similar fashion to laptops? I just want to have my own apps catalogue (similar to my software catalogue solution).&lt;br /&gt;&lt;br /&gt;Is it time for a ‘private app store’ for enterprise unlike the ‘public app stores’ previously discussed? &lt;br /&gt;&lt;br /&gt;Well, the first signs are here: ‘Google to open app store for business software (&lt;a href="http://tiny.cc/W5Hwc"&gt;http://tiny.cc/W5Hwc&lt;/a&gt;). Sounds like the right direction, isn’t it? Despite the promising title it is actually not really what I was looking for. It is mainly a marketplace for business applications focusing (as a first step) on Google Apps (rather than Android Market).&lt;br /&gt;&lt;br /&gt;As for enterprise app store solutions, the Apple/Google of the world will probably approach it as an extension of their consumer solution. This will leave the door wide open for security vendors to address question such as access control, application governance etc.&lt;br /&gt;&lt;br /&gt;So do we have an App (store) for that?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-8531687688711862435?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/8531687688711862435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/02/there-is-app-war-for-that.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/8531687688711862435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/8531687688711862435'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/02/there-is-app-war-for-that.html' title='There is an App (war) for that'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-2054275791410067530</id><published>2010-02-09T09:33:00.002-05:00</published><updated>2010-03-31T13:38:39.931-04:00</updated><title type='text'>A world with no IT Resources – Should Admins get nervous?</title><content type='html'>The reality of organization’s IT resources (starting with SMBs) as we know it is about to dramatically change. The Cloud movement along with the new “Consumer employee” phenomenon (&lt;a href="http://shlomidinoor.blogspot.com/2010/01/we-are-all-consumer-employees.html"&gt;employee at day, consumer at night&lt;/a&gt;) drives organizations to reduce ownership of IT resources. Eventually IT resources free.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;How is it going to work (most of the technology is already available)? &lt;br /&gt;&lt;br /&gt;1. Server infrastructure&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Entire server infrastructure will run in the cloud (pick your favorite vendor)&lt;br /&gt;&lt;br /&gt;2. Employees workspace&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop virtualization will run on the cloud server infrastructure &lt;br /&gt;&lt;br /&gt;3. Applications&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SaaS where possible, else application virtualization on top of the cloud server infrastructure&lt;br /&gt;&lt;br /&gt;4. Desktop/Laptop/endpoint device&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; That’s where things become interesting. Since your workspace is virtualized all that is needed is a device&amp;nbsp;with basic capabilities to connect (e.g. browser). Now if the “consumer employee” prefers using his own cool/customized/private/latest/greatest device anyway, why should the organization buy an extra one? Instead, every several years (e.g. 3Y) the organization will grant each employee with an allowance (e.g. $3k) to purchase a personal device (desktop, laptop, netbook, tablet, etc.). While I think the real revolution is going to happen around the device ownership, I will leave this topic to my next post (stay tuned).&lt;br /&gt;&lt;br /&gt;Information protection is going to become key in the described setup. As data will reside elsewhere (in the cloud or personal devices), controlling who can access it, who has accessed it and where is it, are going to be critical capabilities for future security solutions. Think about asset management and even identity management in this hybrid world…&lt;br /&gt;&lt;br /&gt;I’m no prophet, by all means, but the day is coming and we better accept (even embrace, God forbid) the changing landscape and start preparing. &lt;br /&gt;&lt;br /&gt;Now regarding my opening question (should IT personnel become nervous in this world with no IT resource) - of course not! Their current role will change/expand, rather than spending most of their time deep in the infrastructure (such as AD configuration/administration), they will be instrumental with this virtual/cloudy infrastructure. Vendor selection and ongoing benchmarking will occupy a greater portion of their time.&lt;br /&gt;&lt;br /&gt;Are you convinced by now? I must be missing something and be happy to hear your take.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-2054275791410067530?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/2054275791410067530/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/02/world-with-no-it-resources-should.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/2054275791410067530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/2054275791410067530'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/02/world-with-no-it-resources-should.html' title='A world with no IT Resources – Should Admins get nervous?'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-422785907557949682</id><published>2010-02-02T11:39:00.000-05:00</published><updated>2010-02-02T11:39:16.464-05:00</updated><title type='text'>If you have the same problem for a long time, maybe it is a fact not a problem…</title><content type='html'>Recently the topic of weak passwords (= hacking made easy), has reared its ugly head once again.&lt;br /&gt;You probably mumble now – please don’t let it be yet another passwords related post, we already know our passwords are weak, hackers can (and will) share our identity and we are all going to die…&lt;br /&gt;&lt;br /&gt;Unfortunately I could not resist.&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;a href="http://4.bp.blogspot.com/_GlfI8n8nses/S2hU9I9VflI/AAAAAAAAADU/nKI1w6brZ_8/s1600-h/dilbert-password.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="138" kt="true" src="http://4.bp.blogspot.com/_GlfI8n8nses/S2hU9I9VflI/AAAAAAAAADU/nKI1w6brZ_8/s400/dilbert-password.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;As long as users are responsible to create their own passwords, it will not matter how high the security walls are built. Let’s face it - we all want the ultimate user experience, just let me use the service without the entire authentication mumbo jumbo. When it comes to passwords, most of us create simple passwords, don’t change them at all, and use similar passwords for all our accounts (where possible). And BTW – since forgetting passwords is a hassle we tend to conveniently write it on a piece of paper or simply save it in a file on our computer (the sophisticated among us might even “hide it” by not placing it on the desktop).&lt;br /&gt;&lt;br /&gt;Through the years many vendors attempted to tackle this issue introducing a slew of solutions - secret questions, images, graphics, second passwords, and the list go on and on. These are all just sophisticated passwords (password 1.0, password 2.0 or password 3.0), still subjected to the users will/motivation.&lt;br /&gt;&lt;br /&gt;Security experts in the audience will explain that regardless of password strength or rotation frequency, hackers will manage to break them. Terms such as session hijack or Man-in-the-middle will be used to further scare us. I must admit it is all true, however with so many identities out there you simply need to be slightly better than your neighbors to postpone destiny (like the well known joke about two friends, a jungle, a hungry lion and a pair of running shoes). In addition, a large customer recently confessed that changing passwords every 90 days addressed a very large portion of their identity problems. Today I read that Twitter asks users to reset passwords after possible phishing attack (http://tinyurl.com/yhmn9y8).&lt;br /&gt;&lt;br /&gt;So why do we consistently write about it for years and years? Is it because there is no solution for the problem? It keeps changing on us? The solutions provided by vendors are not valid anymore?&lt;br /&gt;Well, as I have already stated the root cause of this problem is us, the (lazy) users. Once this parameter will change the problem will simply go away (flying angles play harp, rainbow in the background).&lt;br /&gt;&lt;br /&gt;A quick recap: &lt;br /&gt;Problem – weak passwords = hacking made easy&lt;br /&gt;Root cause – us, the (lazy) users&lt;br /&gt;Solution – replace us, the (lazy) users&lt;br /&gt;Problem solved, moving on!&lt;br /&gt;&lt;br /&gt;How can we replace us, the (lazy) users in a process intended to authenticate us (the …)?&lt;br /&gt;While there are many solutions out there strengthening user authentication (e.g. out of band), I’ll mention two ways to better manage authentication: &lt;br /&gt;1. Software replaces users – software manage the entire authentication process, including password generation (a non-lazy program will ensure password strength), maintenance (frequently modify) and seamlessly login. Implemented right this will address the challenges previously described and improve security while reducing the hassle. &lt;br /&gt;2. Behavioral characteristics – base authentication on user’s behavioral characteristics/patterns, rather than parameters subjected to his will. Answer the question “who he is” (I’m not referring to physical aspect such as fingerprint) rather than “what he knows”.&lt;br /&gt;&lt;br /&gt;Consumers are mainly concerned with their own identity. For enterprise the problem is a hairy one. Organizations measure everything using the “risk lenses” (and they should), therefore not all identities are born equal. While most identities are associated with “real” employees, some such as shared administrative accounts are not tied to any particular “real” identity. The paradox is that while the number of these accounts is relatively small the risk associated with their capabilities is huge.&lt;br /&gt;Recently we’ve heard of a financial services company with poor password management controls for shared administrative accounts that resulted in a data breach affecting 1.2 million of their customers. The realization of this challenge contributed greatly to the spike of the PIM (privileged Identity Management).&lt;br /&gt;&lt;br /&gt;My recommendation for organizations is: “worry when you should worry, don’t worry when you should not worry”. Brilliant, isn’t it? A more professional way to put it will be: your security controls should be proportional to the risk. While providing better password management capabilities and controls for the entire organizations has value, you lose focus on your priorities. Focus stands for better controls in a timely manner for the high risk accounts.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-422785907557949682?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/422785907557949682/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/02/if-you-have-same-problem-for-long-time.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/422785907557949682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/422785907557949682'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/02/if-you-have-same-problem-for-long-time.html' title='If you have the same problem for a long time, maybe it is a fact not a problem…'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_GlfI8n8nses/S2hU9I9VflI/AAAAAAAAADU/nKI1w6brZ_8/s72-c/dilbert-password.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-8433642506873305639</id><published>2010-01-26T09:58:00.001-05:00</published><updated>2010-01-26T10:01:15.060-05:00</updated><title type='text'>Please stay alive while we upgrade the software</title><content type='html'>An unbelievable, yet true story:&lt;br /&gt;&lt;br /&gt;A family member was going through a severe medical situation requiring a daily life saving treatment. Treatment took place at the hospital using an expensive medical device. After two weeks of therapy he was asked to skip the next couple days of treatment. Sounds a bit strange given the fact it was a life saving procedure, doesn’t it? Confused, he inquired for the nature of his doctor’s request and was given the answer that device is down for two days due to a &lt;strong&gt;software upgrade &lt;/strong&gt;(of the equipment).&lt;br /&gt;&lt;br /&gt;Can you believe it? Critical (life saving) medical infrastructure is down for days due to software upgrade!? It must be a bad joke…&lt;br /&gt;&lt;br /&gt;This story is an indication of the criticality of software applications in our lives. Recently there was a big discussion about the impact of a cyber terror attack knocking down the internet. Without getting into a lengthy debate I feel we are past the turning point. Software has become critical part of our lives, especially with regards to some commercial/enterprise applications. Based on the story above it can even be a life saving medicine.&lt;br /&gt;&lt;br /&gt;Despite the importance of software, in many cases the overall quality of the package is lacking. We have all heard the stories about vendor locking and challenges some customers have with upgrading commercial software (as well as enterprise software). It always looks like install and upgrade are an afterthought rather than a core capability (similar phenomenon with security and even management capabilities). Occasionally the approach is &lt;em&gt;“once it is up and running - you will get all this great functionality…”&lt;/em&gt; This phenomenon is much more common with large software vendors with stronger leverage (i.e. bargaining power) over their customer base.&lt;br /&gt;&lt;br /&gt;So how can we align quality with criticality to improve this situation?&lt;br /&gt;&lt;br /&gt;A major benefit SaaS vendors bring to the market has to do with their state of mind as companies. Unlike the common perception of SaaS companies as software companies, they are not. SaaS companies are actually SERVICES companies, which happens to develop\market\sell a product. Their state of mind is of a services organization. A CEO of such a company recently told me: &lt;em&gt;“if the service we provide is not good enough, we can (and will) be fired every day”&lt;/em&gt;. This refreshing perception of the role of software applications (and software providers) keeps these companies close to (and dependent on) their customers and might be the panacea for the quality (or lack of) delivered. I believe it might even have a positive impact on more traditional software vendors.&lt;br /&gt;&lt;br /&gt;So if you are a software vendor, keep in mind the “services state of mind”. But most important – stay healthy!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-8433642506873305639?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/8433642506873305639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/01/please-stay-alive-while-we-upgrade.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/8433642506873305639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/8433642506873305639'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/01/please-stay-alive-while-we-upgrade.html' title='Please stay alive while we upgrade the software'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-883306778035299193</id><published>2010-01-19T17:33:00.004-05:00</published><updated>2010-01-22T17:43:13.138-05:00</updated><title type='text'>We are all Consumer Employees</title><content type='html'>Like many others I anxiously await Apple’s latest iPad/iSlate/iTablet/i(“Apple’s new Tablet which is going to change our lives and blow away the competition”), one more week to the announcement (most likely).&lt;br /&gt;&lt;br /&gt;A quick disclaimer - I love Apple technologies. My household members are proud owners of several iPods, iMac, MacBook. If it was not for AT&amp;T I would have an iPhone... I have even invested in Apple’s stock.&lt;br /&gt;&lt;br /&gt;Unlike the iPhone revolution, this time the competition is not planning to be caught off guard, playing to the hands of Apple. Thinking they understand Apple direction, everyone (Google/HTC, Sony, Microsoft, Dell, HP, Nokia, Motorola, ASUS, etc.) is rushing to release a tablet message to the market followed by what seem at times pre-mature products. Eventually Apple will release their hyped device taking the market by storm…&lt;br /&gt;&lt;br /&gt;Though a gadget freak, I wonder, what does the new tablet era have to do with the title of this post?&lt;br /&gt;Well, there is an interesting phenomenon we are experiencing. Enterprise infrastructure has opened up to support remote access of employees (travel, home, remote office, etc.). In addition, mobile devices have become more powerful and many of us are getting these devices for their personal use. &lt;br /&gt;Now is the time to introduce a term I’ll be using quite often I believe in my posts - “consumer employee.” In this era the line between employees and consumers is very blurry as most of us are employees at day and consumers at night. We are going to continue purchasing (and thinking) as consumers while demanding open connection to our work environment, as employees.   &lt;br /&gt;You don’t need to be genius to connect the dots. If you (a consumer employee) had a personal fancy/cool yet powerful device (e.g. iPhone) wouldn’t you want to use it to access your work environment (e.g. email)? &lt;br /&gt;This plays nicely to Apple’s brilliant strategy. They found the secret sauce to eventually master the enterprise mobile world. Instead of battling head to head from day one with the enterprise SW/HW vendors they came up with a different approach. &lt;br /&gt;Apple’s strategy is very simple:&lt;br /&gt;1. Create a cool device with a relatively small number of really great features (e.g. iPhone)&lt;br /&gt;2. Sell this device to consumers and dominate (not in number but in hype) the market&lt;br /&gt;3. Add the necessary capabilities (again small number of features) for enterprise use (e.g. Exchange integration)&lt;br /&gt;4. Leverage the satisfied/hyped customer base to create a reverse pressure from inside the enterprise (i.e. “we want to use these devices to connect to our working environment”)&lt;br /&gt;5. IT/Security will try to push back but eventually will have to compromise and support these devices&lt;br /&gt;&lt;br /&gt;The consumer employee phenomenon is not limited to mobile devices, they also want to use social networks and other “always connected” consumer mediums during the day time when they act as employees. These new challenges are not limited to security and have to be addressed. By the way many of the IT guys responsible to watch the milk are by themselves geeky consumers (and I mean it as a positive virtue).&lt;br /&gt;&lt;br /&gt;Am I missing something? Are you convinced by now? I’ll be happy to hear your take.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-883306778035299193?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/883306778035299193/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/01/we-are-all-consumer-employees.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/883306778035299193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/883306778035299193'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/01/we-are-all-consumer-employees.html' title='We are all Consumer Employees'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3428659345510666362.post-9163438712712475276</id><published>2010-01-19T16:27:00.002-05:00</published><updated>2010-01-20T14:01:43.699-05:00</updated><title type='text'>Taking the plunge</title><content type='html'>I have finally decided taking the plunge and write my own blog where I can blabber about everything, especially technology and how it impacts life. Since my day job revolves information security (and has been so for quite some time), as a bonus from time to time I will provide my security takeaways.&lt;br /&gt;I plan to enjoy the ride, hopefully you will as well.&lt;br /&gt;&lt;br /&gt;Without delay – let the games begin!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3428659345510666362-9163438712712475276?l=shlomidinoor.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shlomidinoor.blogspot.com/feeds/9163438712712475276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://shlomidinoor.blogspot.com/2010/01/taking-plunge.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/9163438712712475276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3428659345510666362/posts/default/9163438712712475276'/><link rel='alternate' type='text/html' href='http://shlomidinoor.blogspot.com/2010/01/taking-plunge.html' title='Taking the plunge'/><author><name>Shlomi Dinoor</name><uri>http://www.blogger.com/profile/15810123660024115550</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/_GlfI8n8nses/S1YknccjJyI/AAAAAAAAACs/y1J1jH6sk1I/S220/SD.PNG'/></author><thr:total>1</thr:total></entry></feed>
