Sunday, 28 October 2007

Spamalot

Well, I know security is cool enough to attract spam, but apparently I am also now popular enough to get it in my comments. Hoo-bloody-ray. Really, I'm probably not the best person to pick on, I got this in my comments box today:
"Don't forget to visit, http://securityrules.blogspot.com have fun"
From "Visitor" at IP 221.132.113.179. A quick look at the Whois for this site reveals it to have come from somewhere in Asia Pacific. A quick look at securityrules reveals it to be chock full of adverts and links to stuff you don't want to go to. The articles are an odd mix of pseudo-relevant and advertisement, but I wonder where they are from. Anyone recognise these as your own work?

I really don't understand why people do this, and certainly not why they target me if they do. Don't they know I'm going to bite them?

Saturday, 27 October 2007

The less we write, the more they read...

...apparently, so I'll be keeping this short.

Thursday, 25 October 2007

Features or scaled down products?

Chuck Hollis of EMC has posted an interesting article this weekend. The products versus features argument is one I'm only too aware of having worked in data circles for so long.

A point which Chuck manages to scoot over quite well is the fact that, whilst "every time I see some small company getting attention over some feature they've brought to market, a part of me is saddened by the ultimate reality that it's highly unlikely they'll make it alone", he still works as VP for Technology Alliances for EMC, so he kind of has the ultimate say in whether they will make it at all these days. I guess it's not surprising, the cream always rises to the top, and he's obviously got a great eye for the right products. This isn't really the point.

What interested me was his comments about Decru and Neoscale, two companies I have had direct and indirect contact and competition with over the years. Decru are a laid back bunch, no doubt aided by their recent(ish) acquisition by NetApp, which left all concerned with reasonable pay-offs and the chance to hang on to their old jobs. Apparently NetApp haven't spent much time working them into the company as a whole, but the technology is being adopted and built in to the existing filers. It will be interesting to see what becomes of "Decru - a NetApp company" when this process is finished. Will the feature become part of the product and therefore exist no more? Will the Decru guys and girls be overly concerned if/when it does? It was undoubtedly a good acquisition for NetApp at the time, but are they kicking themselves now that they didn't try and code it themselves?

Neo on the other hand don't have the luxury of acquisition investment, and there have been various reports pertaining to the fact that their product is also just a feature - a feature which companies like EMC can apply to their storage much more easily than a device out in the SAN fabric. There are no such questions surrounding their existence as part of another company then, so is it too late for acquisition on their terms?

There was a rumour going around at RSA which I am interested to find out the truth behind. Having said that, there was a rumour about Vontu recently, which I have straight from the horse's mouth (Kevin Rowney, founder and CTO who I am having lunch with the week after next in SF) is completely fabricated. Hopefully I'll have more on the Neo story in a few days time, but due to America's strict libel laws I will keep my mouth shut - I'm flying in on Saturday and Hoff has already threatened to put me on the no-fly list, I can do without a lawsuit too. :)

Tuesday, 23 October 2007

RSA keeps it real

I've been at RSA this week, the conference, not the company. It's the first one I've attended, but the second conference I've been to at ExCeL in London - the Exhibition Centre London, way out in the East End's Docklands for those who haven't been. The first show I attended here was called Complitech, all about compliance and technology, sounds fun right? Well, it can't have been that appealing as I sat there for 2 days (I was exhibiting for Kinamik) and watched around 12 people wandering through the doors, and I'm sure 6 of those were looking for the stairlift conference (sadly I'm not making this up) next door.

Back to RSA then, and whilst there are more than 12 people (there are at least 1000 people manning the RSA stand alone) it's not as busy as other Information Security shows I've been to this year. This felt like the InfoSec shows of yesteryear, no nurses in short skirts, no gorilla outfits, Fortify had 2 men in suits - no giant from 'Hackistan' as in previous shows - but I couldn't help but look at the girl on their booth with the legs. She must have been chilly in those shorts. I wonder how much she knows about security? I'm meandering off the point for some reason... where was I?

Oh yes, the hall was embarrassingly empty when I arrived, like it had been at Complitech for the full 2 days. I was beginning to think that maybe ExCeL just isn't the right place for a show. But then "Stairlifts and Chairlifts" had been well attended, maybe all the reduced mobility domestic assistance salesmen in the UK live in East London? I couldn't prove otherwise thinking about it. Then the keynote speeches finished - shame, I would have liked to have seen Bruce Schneier's "Security 101" lecture - and the hall became modestly full. By lunchtime it was buzzing, and in the afternoon there were people chatting all over the place, deals being struck, and drinks being drunk. This is how I remember conferences in the old days, before it all became commercialised, and I'm grateful to RSA for keeping it like this. It's less noise, more signal, and I for one, as a serious security professional for a moment, appreciate this.

I managed to miss lunch altogether by getting completely engrossed in conversation with Brian Honan, over from Dublin for the duration of the conference. An interesting man with plenty of practical knowledge and a gentle yet wicked sense of humour that only the Irish seem to be able to pull off convincingly. I rather lost track of time, but I think we chatted for about 2 hours before surfacing and the conference seemed to have almost finished without us. I think today is going to be busier, and I'm looking forward to meeting some other people today too. I find people in suits less intimidating that girls in short skirts to strike up a conversation with. I'll always be the little geek at heart - despite being a rugged and handsome young man now...

[Thanks to Karen Friar for the write up and massive picture.]

Saturday, 20 October 2007

Closing the gap

I haven't seen anything really new and interesting recently. I love seeing new technologies, and especially new security technologies. I was really happy at InfoSec this year when I saw Secerno, AppGate and Centrify. I hope I'll come across them again at RSA next week, but I'm really looking for something more.

I have an article being printed in Computer Weekly soon (I'll let you know when it hits) about US and UK security markets, and why there's such a gap. I won't spoil the surprise by discussing it here, but most people who read this will already broadly know. The outcome of it is that there is usually a space of 4 or 5 years between something becoming popular in the US, to becoming popular in the UK.

My current position is a case in point. I was at a reseller who tried to bring Ingrian into the UK 5 years ago or so, and we had real problems getting broad interest. We are now inundated with work. This isn't an Ingrian advert however.

No, what I'm looking for now are the things that are interesting, up and coming, and tearing up the market in the US right now. I don't know if I'll get to see these at RSA Europe, because of the very fact that most technologies take 4 or 5 years to become popular over here once they are established in the US. It's a bit of a Catch-22 really, but since I've won a trip to RSA2008 in SF, I'm thinking I can probably wait a few months.

Of course, there's always the chance that I'll come across some badly informed companies who are trying to break into the market here before it's taken off in the US, in which case I will do everything I can to encourage them. It's about time the UK started to encourage security a bit more, ignored the channel and encouraged new and exciting ideas. I'll be in SF in 2 weeks and I want to see some seriously good technology, but it's a hell of a long trip, I'd rather have it on my doorstep.

Friday, 19 October 2007

Swindon Communists

It's not often that I listen to something an American tells me, but a couple of weeks back I had the fortune to travel the highways and byways of Southern England with a guy from Orange County, CA. He told me various stories, many of them centering on his cousin, of whom he is obviously very fond, who lives in Swindon. Poor sod.

Said Swindoner was a mover and shaker of some sorts in the British Computer Society, one of those acronyms I've heard of and keep hearing of more regularly, and have even considered joining to the point of downloading the application forms. Then it all got a bit tricky and I gave up.

So instead of being a characteristically lazy bugger, I sat on my fat behind and emailed this chap. He got back to me quickly and I ended up talking to another geezer from Swindon about how great the BCS truly is. He then said the magic words "online application form" and I was hooked. I even got a 10% discount for my troubles.

The BCS does have some serious points to make, and this is something I took on board whilst talking to my wife again on a recent jolly back over in Spain. She was lamenting the lack of good computer teaching in schools. She trained as a teacher and never entered professionally because the kids (in Swindon - ironically and circularly) were a nightmare. I told her that I couldn't do it, and wouldn't because it wouldn't pay me anything close to what I get now.

It's true, sadly. Those who can, do, and sod the rest. I've thought about setting up schemes with Universities to share knowledge, but I just don't have the spare time. A blog is about as altruistic as I get. My ideal would be to get the pros talking to the Unis and the Unis talking to the schools, then everyone magically living in my little communist utopia happily ever after. I don't think I could make that work - certainly not with my selfish money-grabbing attitude.

The BCS are nicer than me though, probably because they've had to suffer in Swindon for so long. I'm sure there are many people in the BCS outside of Swindon who are nice too. They are aiming to share knowledge, create professional standards, and set up an infrastructure like most other long standing professions have. It's great that computerists can finally be recognised and support by their peers. Maybe it'll stop all the cliqueyness in IT? Maybe not, but I'm sure they have made Swindon a happier place.

[Disclaimer: The BCS has offices all over the UK, I just happened upon Swindon for personal reasons. Swindon is one of the loveliest places in the UK, nay the world.]

PCI project blues

I've just been talking to the PCI project manager of one of the largest retailers in the UK. I won't go into any more details in case I give away too much, but the content of the discussion was very interesting.

First of all his assertation that he didn't care about PCI was no revelation - he just wanted a tick in the box. That he said it didn't bring any benefit to the corporation - "We just want to sell things" - was also no big shakes. He'd had resellers and QSAs crawling all over him like a rash, which is sad, but hardly surprising. I expect he's paid well enough to put up with that.

What surprised me was the advice he was getting from his QSA, that all of his branch offices needed IDP/IDS. I must have reacted in the same way as he had done when told that because he smiled wrily at my furrowed brow and said: "That's bollocks isn't it?"

Well, yes, I'm afraid it is. Please correct me if I'm wrong, but no-one needs to have intrusion prevention systems installed at every branch location. Especially not when they're putting encryption in place, practically unbreakable, centrally-managed encryption at that (yes, that would be Ingrian Networks, of course). Not when they have things like firewalls in place. At head office, where the processing is done on the cards and they are stored in databases, perhaps this is valid, but at branches where they are held safely encrypted until they are sent offsite, this is just a waste of money.

I don't think the US is this stringent yet, and the UK certainly isn't. I'm sure VISA and MC would jump up and down shouting hurrah and huzzah if everyone did this, but they would have to recover from the shock first. It just doesn't happen, especially when other retailers are shelving their PCI projects altogether because they can prove they've started them when the auditors come round, and that's all that's required to be compliant right now.

Come next audit of course the latter company will have to show that they are moving again, so effectively all they are doing is making their PCI project more urgent, probably squeezing it into 6 months at the end of next year, when the aforementioned will be compliant by June '08 and squeaky clean - just in time for a change in the rules no doubt.

I have heard no more about the requirement for FIPS being introduced into PCI DSS, but it seems so unnecessary that it is almost destined to happen. Any light that can be shed on this would be much appreciated. I've got another meeting to get to.

MadKasting