Security Blog
- 
Password weaknessIn the xkcd comic on password strength, Randall Munroe triggers a discussion on the effectiveness of password algorithms. While he raises valid points, the real risk lies in password reuse and breaches. Moving away from passwords and exploring alternatives like SSL certificates or one-time passwords may be a more promising approach. 
- 
How certificates go badThe recent Comodo sub-CA bogus certificate issuance has sparked a loud discussion in the security community. This incident highlights the flaws in the SSL certificate authority (CA) model. Trusting numerous CAs globally creates vulnerability, and compromised registration authorities (RAs) can issue certificates for any domain. Incident response and transparency are crucial, but incidents like this… 
- 
Architecting for DDoS -DefenseDesigning a robust DDoS mitigation strategy requires understanding potential failures and the efficiency of attacks. While increasing capacity can be a simple solution, it’s crucial to push functionality to the edge, prioritize user authentication, employ caching techniques, and store user-generated content. Instead of focusing on recovery time, design for a Minimum Uninterrupted Service Target to… 
- 
Awareness TrainingImplementing a robust security awareness program is not difficult if your company prioritizes security. However, if security is not a concern, you have a significant problem. Many programs focus on meeting auditor requirements with annual training sessions and policy acknowledgments. While these are necessary, a comprehensive program integrates security into various activities and encourages employees… 
- 
NSEC3: Is the glass half full or half empty?NSEC3 is a DNSSEC specification that addresses the issue of authenticated denial of existence in DNS. It replaces the NSEC method by using a hashing function and signed hash ranges to prevent easy collection of zone file contents. While NSEC3 improves secrecy, it raises questions about the need for semi-secret public DNS names and suggests… 
- 
Contracting the Common CloudAfter attending CSO Perspectives, Bill Brenner has some observations on contract negotiations with SaaS vendors. While his panel demonstrated a breadth of customer experience, it was, unfortunately, lacking in a critical perspective: that of a cloud provider. Much of the point of SaaS, or any cloud service, in the economy of scale you get; not just in… 
- 
The Adaptive Persistent ThreatMuch ado has been made of the “Advanced Persistent Threat”. Unfortunately, pundits look at the ease of some of the attacks, and get hung up on the keyword, “Advanced.” How do we know the adversary is so advanced, if he can succeed using such trivial attacks? The relative skill of the adversary is actually uninteresting;… 
- 
Why is PCI so successful?At the RSA Conference, participating in a panel discussion on the PCI Data Security Standard, it was evident that PCI has significantly impacted the industry. The standard’s simplicity, broad applicability, and narrow focus on protecting specific data have improved security more than any other standard. It serves as a model for future compliance standards. 
- 
Why don’t websites default to SSL/TLS?HTTP is designed for web administrators to host multiple sites on fewer systems, while HTTPS (SSL/TLS) focuses on security-conscious users. SSL’s design creates scalability issues, although solutions like wildcard and SAN certificates, as well as SNI, aim to mitigate them, pending widespread SNI support. 
- 
Modeling Imperfect AdversariesBrian Sniffen’s paper at FAST highlights the importance of understanding adversaries in risk assessment, particularly in the streaming media space. It explores concepts like defense in breadth and tag-limited adversaries, emphasizing the need to consider different capabilities and attack strategies when formulating security frameworks. His work provides valuable insights into the evolving landscape of streaming… 
Leadership Newsletter
- 
Too Much Deference to Blind ComplianceLeadership Moment: Choice isn’t Frozen There are times when an organization wants to demonstrate bold leadership on as issue, as the Paris Olympic Committee did when it decided to use geothermal cooling systems instead of more effective air conditioners. Unfortunately for the POC, they didn’t anticipate the entirely predictable consequence: that many countries would bring… Read this … 
- 
Smooth Power DifferentialsLeadership Moment: Asymmetric Communication Checking into hotels has become increasingly automated. For a recent hotel stay, I received a WhatsApp message from the hotel asking me to provide some pre-checkin information, to smooth the check-in process (reading between the lines: reduce the cost to the hotel to check me in with a human). After a… Read this … 
- 
Keep the door openLeadership Moment: Product-Led Growth Via SwiftonSecurity (who else), we’re reminded of Bloomberg’s fascinating “get fired” perk: paying customers who lose their job can request a free Bloomberg terminal to bridge them over and maintain currency in the trading network while they seek a new job. In addition to the brilliance of this move (ensuring brand… Read this … 
Fiction
- 
SkeletonA necromancer and an Olympic event [Read the story] 
 
- 
Albus Dumbledore and the Rituals of ImmortalityThe words that didn’t make the Harry Potter septology that fill in the blanks for what’s really going on. [Read the story] 
 



