Archive

Archive for the ‘General Rants & Raves’ Category

Got Rational Security?

June 14th, 2006 No comments

I love Google.  I found this whilst browsing this morning:
Fgotrational_1

Categories: General Rants & Raves Tags:

Full Drive Encryption on Laptops – Time for all of us to “nut up or shut up!”

June 11th, 2006 7 comments

Laptopmitm275300
…or "He who liveth in glass houses should either learn to throw small stones or investeth in glass insurance…lots and lots of glass insurance. I, by the way, have lots and lots of glass insurance ;)"

Given all of the recently disclosed privacy/identity breaches which have been demonstrated as a result of stolen laptops inappropriately containing confidential data, we’ve had an exponential increase in posts in the security blogosphere in regards to this matter.

This is to be expected.  This is what we do.  It’s the desperate housewives complex. 😉

These posts come from the many security experts, analysts, pundits and IT Professionals bemoaning the obvious poor application of policies, procedures, technology and standards that would "prevent" this sort of thing from happening and calling for the heads of those responsible…of the very people who not only perpertrated the crime, but also those responsible for making the crime possible; the monkey who put the data on the laptop in the first place.

So, since most of us who are "security experts" or IT professionals almost always utilize laptops in our lines of work, I ask you to honestly respond in comments below to the following question:

What whole-disk encryption solution utilizing two-factor authentication do you use to prevent an exposure of data should your laptop fall into the wrong hands?  You *do* use a whole-disk encryption solution utilizing two-factor authentication to secure the data on your laptop…don’t you?

Be honest. If you don’t use a solution like this then please don’t post another thing on this topic condemning anyone else.  Ever.

Sure, you may say that you don’t keep confidential information on your laptop and that’s great.  However, if you’ve got email and you’re involved in a company as a security/IT person (or management or even as a general user,) that argument’s already in the bullshit hopper.

If you say that you use encryption for specifically identified "confidential" files and information but still use a web-browser or any Office product on a Windows platform,  for example, please reference the aforementioned bovine excrement container.  It’s filling up fast, eh?

See where this is going?  If we, the keepers of the gate, don’t implement this sort of solution and we still gabble on about how crappy these errant users are, how irresponsible their bosses, how aware we should make and liable we should hold their Board of Directors, the government, etc…

I’ll ask you the same question about that USB thumb drive you have hanging on your keychain, too.

Don’t be a hyprocrite…encrypt yo shizzle.

If you don’t already, stop telling everyone else what lousy humans they are for not doing this and instead focus on getting something like this, or at a minimum, this.

/Chris

“Back From the Bleak Blog Brink of Nothingness…”

June 3rd, 2006 No comments

Yesterday I met up with Alan Shimel, StillSecure’s
Chief Strategy Officer.  I’ve known about StillSecure’s excellent
products for some time now, but I frequently read Alan’s blog and
decided that we should meet. 

Alan’s a fascinating guy, the sort of fellow that one becomes
instantly comfortable with.  You can tell he’s been through the
security sausage grinder and come out decently unscathed but with
wisdom, patience and a distilled kindness that this sort of experience
brings.

At lunch we had one of those conversations that became animated
enough that the verbal game of ping-pong encompassing the collective
turets-style outbursts of our past lives caused both of us to interject
comment after comment — even when stuffing our faces with Italian food
😉

It was truly excellent being able to sit down with someone who
really gets it and isn’t afraid to (agree to) disagree.  We seem to
share a great many views on perspectives that run the gamut of the
security panorama and it was great to meet another someone from the
blogosphere like Alan with whom I could bond intellectually.  I’ve met
some other fantastic opinionati like Mike Rothman and Pete Lindstrom under similar circumstances…you should most definitely read their blogs.

After meeting with Alan, I became inspired to retire my previous
neglected blog-bortion and commit to a full-frontal assault using
TypePad which provides a much better canvas for this sort of thing.

I’ll move a couple of entries over just for continuity’s sake.

Off to the Gartner IT Security Summit in DC from the 6th to the
8th…Crossbeam is sponsoring another amazing evening social event in
conjunction with our buddies from SourceFire.  eMail/phone me for
details.

Looking forward to more bloggage.

Chris

Categories: General Rants & Raves Tags: