Thursday, June 24, 2010

Gold Rush

I have finally decided to walk the walk and make the commitment. Despite the nasty mother in law (AT&T) I’m getting an iPhone 4.
For the first time in my life I’m going to actually wake up early, stand in line and on the premiere be one on the lucky ones (as well as additional 1M people) to have the new majestic device!

So this is how it went (so far):
5:40am – woke up (going to get the iPhone 4 today, YEAH!)
5:55am – reports on the internet: already long lines (still optimistic)
6:15am – the Dinoor team is out on the road (cautiously optimistic)
6:20am – Dunkin Donuts, and we are ready for the action (carbs are always good for the spirit)
6:25am – the parking lot is half full, at 6:25 in the morning!? (Um, Oh...right)
6:30am – finally standing in line, practically at the mall’s entrance with probably 200-300 people in front of us (it is going to be a long day)
7:01am – we are moving! Actually the other line (pre-order) is moving (shall I cut my losses here and now, i.e. leave?)
7:30am – made 10 feet progress and rumors has it the pre-order line is getting in first (50:1 ratio between the lines)
8:45am – nothing (let’s pack our thing and leave, such a looser…)
9:00am – there is a God up there, I have made it! I’m the proud owner of a … ticket assuring me an iPhone (the line is still long, but who cares?)


9:15am – leaving the scene as a winner, I’ll be back later on tonight to pick it up

Stay tuned for more on how the saga ends!

Monday, June 21, 2010

Worth Repeating

I find myself quite often quoting expressions I hear at different places. Surprisingly people seem to enjoy it and even (God forbid) use it at later times...

As an entertaining exercise, I’m going to post these valuable quotes from time to time at the “Worth Repeating” section on the right (keep scrolling down).

To kick it off I’m going to start with a few I’ve heard recently:

1. “Security is like life insurance, you only win when you lose” Dr. Rainer Janßen, Munich Re CIO, EIC 2010, Munich May 2010

2. “The cloud is cloudy, not transparent” someone at EIC 2010, Munich May 2010. While discussing Cloud and security concerns

3. “The bits move faster than people, make sure to bring the people with you” Sanjay Mirchandani, (EMC CIO), EMC World, Boston May 2010. While discussing the journey to the cloud.

4. “The technology market is definitely accelerating - it took IBM 40 years to become the evil, Microsoft 25, Google 10, Facebook 5 and Twitter 2.5” JP Rangaswami, Enterprise 2.0 conference, Boston June 2010


Enjoy!

Thursday, June 17, 2010

ShaaS

Regardless of what people might say, the recent couple of years were great for the technology industry. We (technologists) exhausted the 3 and 4 letter acronyms, and at some point just when we thought 5 letters is the new 3 letter a miracle has happen.

The CLOUD was created enabling us to cloud wash everything by simply adding “aaS” as a suffix. This allowed us to start all over again with the 1-2 letters game.

As you can see I’m no different than the rest. So what is ShaaS (used in the title) all about? Is it simply Shlomi as a Service? Better guess again…

It is actually Sharing as a Service. A lot was said and written about collaboration and sharing of data but despite the chatter, solutions have not addressed some of the key challenges.

I’ll focus just on one of these challenges - modern collaboration and data sharing are dynamic by nature and cannot be controlled by static policies/controls.

Let’s follow a use case (as an example) – sharing a document with a group of people. The team can access the file, download it, read it, etc. But what happens two weeks from now when something has changed and I want to stop sharing the file with some members of the team? Using existing information protection techniques (such as DLP or DRM) will not allow me to do it as the file is already in possession of these people. Even if it was wrapped by some type of a shell (in the case of DRM), it is based on a static, outdated policy.

It is true Enterprise 2.0 guys say (rightfully) organizations should design for loss of control (including over data) as web 2.0 penetrates the enterprise. However while organizations promote sharing/collaboration they should protect their sensitive data.

Another interesting phenomenon is the different approach to data by enterprises and consumers. While the enterprise default is “secure first then ask questions”, for consumers it is all about sharing (security? privacy? No one cares!). It looks like consumers treat data as almost nonexistent unless it is shared.

It will be interesting to see a TTS (“Time To Share”) graph over time (i.e. time from actual event to when it is shared). I’m willing to bet TTS has dramatically gone down and is currently very low.

Evolution:
1. In the past one would take photos of an event, download it to the computer, upload it to your favorite social networking tool and share it with a selected audience.
2. Then it seems all devices introduced direct social networking posting capabilities.
3. Next using telepathy capabilities, thoughts will be automatically posted.
4. And finally, the ultimate sharing tool – the Twitter generator. Based on my interests and real events will automagically generate tweets in real-time (on my behalf). I will be perceived extremely smart, how cool is that?

The reality is probably somewhere in the middle, sharing of data is fundamental for the business, yet should be controlled to protect the business. Information protection systems should be morphed with data sharing tools taking its dynamic nature into consideration.

While I leave you with this, I’ll go back to think how to make Shlomi as a Service a viable business…

Monday, May 17, 2010

The Shlomi Cloud!

Facebook owns my photos, Google owns my emails/documents/contacts, LinkedIn owns my network, Delicious owns my favorites, and even my real URLs are not in my possession (but by the Tiny URLs of the world)…

Did I totally lose it?

I recently read about a new startup offering us to manage all our social networking sites from one place. Finally you can move pictures from Picasa to Facebook and then to Google docs, all from a single location. Kind of nice, right? While it is probably very useful (haven’t tried it yet), I say - not another aggregator please!

Instead I want to use a hub and spoke model and have my own Shlomi cloud (clouds are exceptionally trendy these days) where I own/control/manage/store eeevvvverything.

I can define my network (tree/forest of relationships) in one place and carry it (or a subset of it) with me to different social network sites (today to Facebook or LinkedIn, and tomorrow to the next big thing).

I can store all my photos, documents, etc. and delete them whenever I want, knowing no zombie copies are floating in the WWW wilderness.

I can create my personas and manage them, deciding which persona to present and when.

And all the great social networking sites can focus on the services they provide while referencing my identity from the Shlomi Cloud.

What do you think? Is it time to start the MyPersonalCloud.org movement, where everyone can create, own and control his own piece of identity?

Thursday, April 1, 2010

The Global Brainstorming Event of the Year

Writing about April fools day scams is kind of corny, right?

I’m in the business of ideas and innovation, so let me ask you a question and try to answer it from my perspective:
How do you call a once in a year event, where great minds think outside the box with no boundaries or limitations, and publicly introduce theoretical innovative ideas that even sound reasonable in some cases (with no patents, NDAs, IP restrictions, etc.)?

Now you might call it April’s fools’ day, but for me it is Global Brainstorming Event of the Year (GBEY).
So welcome to GBEY 2010!

Here some of this year’s pranks. Try making some sense out of them:
1. Topeka is Google (really), now Google is Topeka
2. Starbucks introducing ridiculous new sizes
3. No Coffee for you! While Starbucks introduce new cup sizes, the FDA ban coffee causing the same Starbucks to move outside of the US.
4. Introducing Google Translate for Animals
5. HugSpot by HubSpot? New HugSpot Dating Software Helps Singles Find Love Online.
6. Chatroulette for the Enterprise, Randomized Productivity Management, i.e. RPM (who comes up with these acronyms!?).
7. Gartner publish Microsoft Decides To Open Source Windows Operating System.
8. New mobile search option, Where am I? who am I? why am I?
9. New resolution used by YouTube (TEXTp) saves YouTube bandwidth and money.
10. Redbox to Speed Up DVD Return Process by adding a return butler (i.e. real person) next to each kiosk).
11. iHOB, a new iPhone application that turns your phone into a mini-stove (great stuff!). It provides a 15 ring system to heat up in mere seconds to be warm enough to heat a can of baked beans or soup in 15 minutes and once turned off will cool down in 15 seconds.
12. A must have accessory for the iPad fans, an arcade cabinet for iPad

And the list goes on and on and on…

If you observe GBEY 2010 scams from my point of view, you might realize that with the right spin some of these crazy ideas can actually be quite good…

Tuesday, March 23, 2010

TSA plays Russian roulette, yet again…

A quick disclaimer: I have nothing against TSA, despite the fact I’ve missed a flight in the past due to long lines at the security check… They are a symptom of a greater problem rather than the problem itself.

Now that we’ve put it aside let’s observe TSA’s mission statement (http://www.tsa.gov/who_we_are/mission.shtm):
“The Transportation Security Administration protects the Nation's transportation systems to ensure freedom of movement for people and commerce”

And vision statement:
“The Transportation Security Administration will continuously set the standard for excellence in transportation security through its people, processes, and technology.”

Sounds like TSA are heavy duty on security, right?

Well, I will not discuss transportation security (though debatable by some); however history tells us a slightly different story when it comes to information security…

Looking at the past 4 years:

2007 (http://bit.ly/aoChfI) – External hard drive containing data from approximately 100,000 archived employment records went missing from a controlled area at TSA.

2009 (http://bit.ly/5REHBu) – TSA accidentally posted a document containing highly sensitive information on its airport screening procedures on a government website.

2010 (http://bit.ly/dc2Nbu) – Poor security protocols lead to TSA fired worker sabotaging TSA’s databases containing information tied to the war on terror and other law enforcement activities.

While some might argue this is an unfortunate collection of non related incidents, I would seriously doubt it. With no intent of being harsh with TSA, this comedy of errors is an indication how security is perceived at TSA.

Starting point:
It will never happen to us! (Therefore no real controls, procedures or C-level directives are necessary)

Post incident #1:
Oops, it did happen. Ok, it will never happen to us AGAIN! (Must be a random statistic glitch, our current strategy is proving itself!)

Post incident #2:
Not again, No way! (Hmmm, at least we placed on each page of the manual the following: NO PART OF THIS RECORD MAY BE DISCLOSED TO PERSONS WITHOUT A 'NEED TO KNOW.')

Post incident #3:
Doh! Let’s bring in a data breach response services company to clean out the mess (http://bit.ly/c0loLq). (Addressing the collateral damage is probably going to solve the problem!)

Most of these types of incidents can be addressed today with existing controls. These are not operator errors, but a depressing example of the overall organizational/C-Level failure to enact security policies (much which are seemingly common procedures) that secures data and protects sensitive assets.

If C-level execs don’t get it they can simply view it as an insurance policy (ensuring bad things don’t happen). People get an insurance policy not because they plan to use it on a daily basis, but mainly because if something happens it can be substantial.

Another way to look at the statistics is organizations play a game of Russian roulette, assuming it will not happen to them (there is only one bullet and five empty chambers).

With the case of TSA - it looks like the cylinder is practically full…

Today I was riding with the four horsemen of the apocalypse, so I’ll finish with a positive tone:
Spring is here, happy (belated) equinox (http://bit.ly/2qHKU1)!

Friday, March 12, 2010

Brain dump

Last week I’ve participated in the RSA conference representing Cyber-Ark. It turned out to be a pretty busy week (your sympathy is appreciated).

This week as a slightly different exercise, we will switch roles (let’s call it un-blog post). Instead of me describing my insights, I will provide some raw data from the conference in a form of a brain dump. If any of this makes any sense to you please comment or ping me with your insights.

As with any brain dump - no order, priority or importance, just partial list of raw numbers/”facts”:
  • Server Virtualization penetration in enterprise is estimated at 25%
  • 6% of ID theft comes from password guessing
  • IT spend 2/3 of their budgets on maintenance
  • CIO survey – for 51% security is the greatest concern surrounding cloud computing adoption
  • Information growth - 60% per year
  • 1B mobile devices will be accessing the internet by the end of the year
  • Survey of 2,100 companies (CIO, IT, CSO, etc.):
          - Over the last 12 months 75% experienced cyber attack
          - 100% experienced cyber lose in 2009
          - Top 3 stolen “items”:
                   1. Theft of IP
                   2. Financial/credit card data
                   3. Customer PII
  • During 2008 – 1.6M signatures (like previous 17 years combined)
  • During 2009 – 2.9M signatures
  • Customers said from their entire data only 1% matters
  • 40% of employees private machines access work resources
  • 10% of private machines are the primary working machine
  • Some organization promoting personal devices for work (subsidize)
  • Per Gartner – organization can save 9-40% on equipment cost
  • Data breach - average loss per record is $204
  • Data breach - average loss per incident is $6.75M
  • 70% of physicians are afraid to place customer data in the cloud
  • 56% of the malware written today is designed to steal data
  • 42% of data breaches involve a 3rd party (service provider, consultant, etc.)
  • Since 2008 there are more mobile devices accessing the internet than “fixed” devices
  • By the end of 2011 there will be 5B users out of 6.8B people in the world…
  • Projected data traffic increased 2009-2014 is by 3900%
  • Videos will be 66% of mobile traffic by 2013
  • Organization leveraging Amazon cloud services usually have one super admin account to purchase and manage their infrastructure:
          - It is a shared account
          - It is a standard Amazon account and can be used to purchase books or anything else…

As an epilogue to get your CPU working a quote by Marc Benioff:
“Why isn’t all enterprise software like Facebook?” It was the next iteration of the question he asked in 1999 (that spawned salesforce.com), “Why isn’t all enterprise software like Amazon.com.”