<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:media="http://search.yahoo.com/mrss/" xmlns:xCal="urn:ietf:params:xml:ns:xcal" version="2.0">
  <channel>
    <title>Job: Security</title>
    <link>http://soup.rachner.us/</link>
    <image>
      <title>Job: Security</title>
      <link>http://soup.rachner.us/</link>
      <url>http://asset.soup.io/asset/0506/3271_6289.jpeg</url>
      <width>264</width>
      <height>273</height>
    </image>
    <description>Eric Rachner's observations on information security, hacking, and the business of IT risk and compliance.</description>
<item><title>Congratulations, Dan Kaminsky</title>
<description>Also, I know where you live. &#160;&lt;a href="http://www.metro.co.uk/news/836210-brit-given-a-key-to-unlock-the-internet"&gt;One down, four to go.&lt;/a&gt; &#160;;)      &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;(Oh, wait. &#160;The problem with these secret-sharing schemes is, you can never be sure which one gave you a bogus fragment of the key. &#160;Back to the drawing board, I guess.)&lt;/div&gt;</description><pubDate>Wed, 28 Jul 2010 23:11:15 GMT</pubDate><link>http://soup.rachner.us/post/67896508/Congratulations-Dan-Kaminsky</link><guid isPermaLink="false">urn:www-soup-io:1:67896508</guid><category domain="contenttype">regular</category></item>
<item><title>Told ya so.</title>
<description>&lt;div&gt;What was I saying about spies in the workplace? &#160;Something like,&#160;"&lt;i&gt;...&lt;/i&gt;&lt;i&gt;not just Google, and not just in China, and not just by China.&lt;/i&gt;"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Like, perhaps, at Microsoft, in Redmond, by Russia? &#160;From the Seattle Post-Intelligencer:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&#160;&#160; &#160;&#160;&lt;a href="http://www.seattlepi.com/local/423366_russian14.html"&gt;Redmond Man Deported as Result of Russian Spy Probe&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;h1 class="rdheadline"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/h1&gt;&lt;/div&gt;</description><pubDate>Sun, 18 Jul 2010 23:24:03 GMT</pubDate><link>http://soup.rachner.us/post/65993278/Told-ya-so</link><guid isPermaLink="false">urn:www-soup-io:1:65993278</guid><category domain="contenttype">regular</category><category domain="tag">microsoft</category><category domain="tag">espionage</category></item>
<item><title>Thought for the Day</title>
<description>Just wait until Google indexes the public record.</description><pubDate>Sun, 21 Mar 2010 20:08:56 GMT</pubDate><link>http://soup.rachner.us/post/49688539/Thought-for-the-Day</link><guid isPermaLink="false">urn:www-soup-io:1:49688539</guid><category domain="contenttype">regular</category></item>
<item><title>Offshoring Partners &amp;amp; The Hand That Feeds</title>
<description>&lt;p&gt;&lt;a href="http://mashable.com/2010/01/18/attack-google-inside-job/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Mashable+%28Mashable%29"&gt;People are catching on&lt;/a&gt; to what the &lt;a href="http://lists.immunitysec.com/pipermail/dailydave/2010-January/005995.html"&gt;smart kids knew&lt;/a&gt; all along: &lt;em&gt;of course&lt;/em&gt; Google's Chinese offices were compromised.&#160; And not just Google, and not just in China, and not just by China.&lt;br /&gt;&lt;br /&gt;Ten years ago, the disloyal insider was a fact of life about which there wasn't much to be done.&#160; You'd mitigate as best you could with careful access control (right?) and handle incidents as they occurred.&#160; Beyond that, what?&#160; Fire all your foreign visa holders?&lt;br /&gt;&lt;br /&gt;Times have changed.&#160; Global enterprises are investing in China, India, Russia, and elsewhere, creating new opportunities for an entire generation of workers to succeed without having to emigrate from their own cultures and communities.&lt;br /&gt;&lt;br /&gt;And that's how I, Eric the Prophet, can predict &lt;a href="http://www.thebigmoney.com/blogs/feeling-lucky/2010/01/18/googlechina-clinton-address-crisis-thursday"&gt;roughly what Hillary Clinton is going to say to China&lt;/a&gt; on Thursday:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;All of this investment is supposed to give you guys some skin in the game.&#160; Surely you don't prefer the previous arrangement, in which the "developed" world lures China's best and brightest abroad, and &lt;/em&gt;&lt;em&gt;China's role in the global economy is relegated to "factory?"&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Is anybody else just a little bit curious as to the global economy's capacity to issue pink slips in countries whose governments can't or won't prevent the emission of cyberattacks?&lt;br /&gt;&lt;br /&gt;p.s.&#160; On a personal note, I helped Microsoft select candidates for IT Security positions in China back in 2004.&#160; As I recall, wages for Chinese IT staff were on the order of US $5.00/hr.&#160; Whatever resentment I felt towards Microsoft at the time for not cutting me in on the expected savings has given way to something more like schadenfreude.&lt;/p&gt; &lt;p&gt;&lt;a href="http://mashable.com/2010/01/18/attack-google-inside-job/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Mashable+%28Mashable%29"&gt;http://mashable.com/2010/01/18/attack-google-inside-job/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+Mashable+%28Mashable%29&lt;/a&gt;&lt;/p&gt;</description><pubDate>Tue, 19 Jan 2010 03:44:24 GMT</pubDate><link>http://soup.rachner.us/post/42213514/Offshoring-Partners-amp-The-Hand-That-Feeds</link><guid isPermaLink="false">urn:www-soup-io:1:42213514</guid><category domain="contenttype">link</category><category domain="tag">china</category><category domain="tag">aurora</category><category domain="tag">google</category><category domain="tag">microsoft</category><category domain="tag">offshoring</category><category domain="tag">doingitwrong</category></item>
<item><title>Duly Noted</title>
<description>From the Blackberry Enterprise Server administration manual:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;"To ensure [system] email is not blocked or modified, the blackberry.net
domain should be whitelisted against any anti-virus, anti-spam, or
blacklisting software utilized by the email system or gateway."&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Translation:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;"Hackers interested in bypassing any anti-virus, anti-spam and blacklisting software utilized by Blackberry customers are hereby advised to use forged source addresses ending in blackberry.net."&lt;/em&gt;&lt;br /&gt;</description><pubDate>Wed, 13 Jan 2010 15:15:16 GMT</pubDate><link>http://soup.rachner.us/post/41477439/Duly-Noted</link><guid isPermaLink="false">urn:www-soup-io:1:41477439</guid><category domain="contenttype">regular</category><category domain="tag">blackberry</category><category domain="tag">doingitwrong</category></item>
<item><title>A Grain of Salt for Digital Asset Values</title>
<description>&amp;lt;!--[if gte mso 9]&gt;&amp;lt;xml&gt;
 &amp;lt;w:worddocument&gt;
  &amp;lt;w:view&gt;Normal&amp;lt;/w:view&gt;
  &amp;lt;w:zoom&gt;0&amp;lt;/w:zoom&gt;
  &amp;lt;w:trackmoves/&gt;
  &amp;lt;w:trackformatting/&gt;
  &amp;lt;w:punctuationkerning/&gt;
  &amp;lt;w:validateagainstschemas/&gt;
  &amp;lt;w:saveifxmlinvalid&gt;false&amp;lt;/w:saveifxmlinvalid&gt;
  &amp;lt;w:ignoremixedcontent&gt;false&amp;lt;/w:ignoremixedcontent&gt;
  &amp;lt;w:alwaysshowplaceholdertext&gt;false&amp;lt;/w:alwaysshowplaceholdertext&gt;
  &amp;lt;w:donotpromoteqf/&gt;
  &amp;lt;w:lidthemeother&gt;EN-US&amp;lt;/w:lidthemeother&gt;
  &amp;lt;w:lidthemeasian&gt;X-NONE&amp;lt;/w:lidthemeasian&gt;
  &amp;lt;w:lidthemecomplexscript&gt;X-NONE&amp;lt;/w:lidthemecomplexscript&gt;
  &amp;lt;w:compatibility&gt;
   &amp;lt;w:breakwrappedtables/&gt;
   &amp;lt;w:snaptogridincell/&gt;
   &amp;lt;w:wraptextwithpunct/&gt;
   &amp;lt;w:useasianbreakrules/&gt;
   &amp;lt;w:dontgrowautofit/&gt;
   &amp;lt;w:splitpgbreakandparamark/&gt;
   &amp;lt;w:dontvertaligncellwithsp/&gt;
   &amp;lt;w:dontbreakconstrainedforcedtables/&gt;
   &amp;lt;w:dontvertalignintxbx/&gt;
   &amp;lt;w:word11kerningpairs/&gt;
   &amp;lt;w:cachedcolbalance/&gt;
  &amp;lt;/w:compatibility&gt;
  &amp;lt;m:mathpr&gt;
   &amp;lt;m:mathfont m:val="Cambria Math"/&gt;
   &amp;lt;m:brkbin m:val="before"/&gt;
   &amp;lt;m:brkbinsub m:val="&amp;#45;-"/&gt;
   &amp;lt;m:smallfrac m:val="off"/&gt;
   &amp;lt;m:dispdef/&gt;
   &amp;lt;m:lmargin m:val="0"/&gt;
   &amp;lt;m:rmargin m:val="0"/&gt;
   &amp;lt;m:defjc m:val="centerGroup"/&gt;
   &amp;lt;m:wrapindent m:val="1440"/&gt;
   &amp;lt;m:intlim m:val="subSup"/&gt;
   &amp;lt;m:narylim m:val="undOvr"/&gt;
  &amp;lt;/m:mathpr&gt;&amp;lt;/w:worddocument&gt;
&amp;lt;/xml&gt;&amp;lt;![endif]--&gt;&amp;lt;!--[if gte mso 9]&gt;&amp;lt;xml&gt;
 &amp;lt;w:latentstyles deflockedstate="false" defunhidewhenused="true"
  defsemihidden="true" defqformat="false" defpriority="99"
  latentstylecount="267"&gt;
  &amp;lt;w:lsdexception locked="false" priority="0" semihidden="false"
   unhidewhenused="false" qformat="true" name="Normal"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" semihidden="false"
   unhidewhenused="false" qformat="true" name="heading 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 7"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 8"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" name="toc 9"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="10" semihidden="false"
   unhidewhenused="false" qformat="true" name="Title"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="11" semihidden="false"
   unhidewhenused="false" qformat="true" name="Subtitle"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="22" semihidden="false"
   unhidewhenused="false" qformat="true" name="Strong"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="20" semihidden="false"
   unhidewhenused="false" qformat="true" name="Emphasis"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="59" semihidden="false"
   unhidewhenused="false" name="Table Grid"/&gt;
  &amp;lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="1" semihidden="false"
   unhidewhenused="false" qformat="true" name="No Spacing"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="60" semihidden="false"
   unhidewhenused="false" name="Light Shading"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="61" semihidden="false"
   unhidewhenused="false" name="Light List"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="62" semihidden="false"
   unhidewhenused="false" name="Light Grid"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="63" semihidden="false"
   unhidewhenused="false" name="Medium Shading 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="64" semihidden="false"
   unhidewhenused="false" name="Medium Shading 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="65" semihidden="false"
   unhidewhenused="false" name="Medium List 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="66" semihidden="false"
   unhidewhenused="false" name="Medium List 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="67" semihidden="false"
   unhidewhenused="false" name="Medium Grid 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="68" semihidden="false"
   unhidewhenused="false" name="Medium Grid 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="69" semihidden="false"
   unhidewhenused="false" name="Medium Grid 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="70" semihidden="false"
   unhidewhenused="false" name="Dark List"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="71" semihidden="false"
   unhidewhenused="false" name="Colorful Shading"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="72" semihidden="false"
   unhidewhenused="false" name="Colorful List"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="73" semihidden="false"
   unhidewhenused="false" name="Colorful Grid"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="60" semihidden="false"
   unhidewhenused="false" name="Light Shading Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="61" semihidden="false"
   unhidewhenused="false" name="Light List Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="62" semihidden="false"
   unhidewhenused="false" name="Light Grid Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="63" semihidden="false"
   unhidewhenused="false" name="Medium Shading 1 Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="64" semihidden="false"
   unhidewhenused="false" name="Medium Shading 2 Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="65" semihidden="false"
   unhidewhenused="false" name="Medium List 1 Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="34" semihidden="false"
   unhidewhenused="false" qformat="true" name="List Paragraph"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="29" semihidden="false"
   unhidewhenused="false" qformat="true" name="Quote"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="30" semihidden="false"
   unhidewhenused="false" qformat="true" name="Intense Quote"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="66" semihidden="false"
   unhidewhenused="false" name="Medium List 2 Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="67" semihidden="false"
   unhidewhenused="false" name="Medium Grid 1 Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="68" semihidden="false"
   unhidewhenused="false" name="Medium Grid 2 Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="69" semihidden="false"
   unhidewhenused="false" name="Medium Grid 3 Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="70" semihidden="false"
   unhidewhenused="false" name="Dark List Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="71" semihidden="false"
   unhidewhenused="false" name="Colorful Shading Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="72" semihidden="false"
   unhidewhenused="false" name="Colorful List Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="73" semihidden="false"
   unhidewhenused="false" name="Colorful Grid Accent 1"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="60" semihidden="false"
   unhidewhenused="false" name="Light Shading Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="61" semihidden="false"
   unhidewhenused="false" name="Light List Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="62" semihidden="false"
   unhidewhenused="false" name="Light Grid Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="63" semihidden="false"
   unhidewhenused="false" name="Medium Shading 1 Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="64" semihidden="false"
   unhidewhenused="false" name="Medium Shading 2 Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="65" semihidden="false"
   unhidewhenused="false" name="Medium List 1 Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="66" semihidden="false"
   unhidewhenused="false" name="Medium List 2 Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="67" semihidden="false"
   unhidewhenused="false" name="Medium Grid 1 Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="68" semihidden="false"
   unhidewhenused="false" name="Medium Grid 2 Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="69" semihidden="false"
   unhidewhenused="false" name="Medium Grid 3 Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="70" semihidden="false"
   unhidewhenused="false" name="Dark List Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="71" semihidden="false"
   unhidewhenused="false" name="Colorful Shading Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="72" semihidden="false"
   unhidewhenused="false" name="Colorful List Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="73" semihidden="false"
   unhidewhenused="false" name="Colorful Grid Accent 2"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="60" semihidden="false"
   unhidewhenused="false" name="Light Shading Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="61" semihidden="false"
   unhidewhenused="false" name="Light List Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="62" semihidden="false"
   unhidewhenused="false" name="Light Grid Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="63" semihidden="false"
   unhidewhenused="false" name="Medium Shading 1 Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="64" semihidden="false"
   unhidewhenused="false" name="Medium Shading 2 Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="65" semihidden="false"
   unhidewhenused="false" name="Medium List 1 Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="66" semihidden="false"
   unhidewhenused="false" name="Medium List 2 Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="67" semihidden="false"
   unhidewhenused="false" name="Medium Grid 1 Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="68" semihidden="false"
   unhidewhenused="false" name="Medium Grid 2 Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="69" semihidden="false"
   unhidewhenused="false" name="Medium Grid 3 Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="70" semihidden="false"
   unhidewhenused="false" name="Dark List Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="71" semihidden="false"
   unhidewhenused="false" name="Colorful Shading Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="72" semihidden="false"
   unhidewhenused="false" name="Colorful List Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="73" semihidden="false"
   unhidewhenused="false" name="Colorful Grid Accent 3"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="60" semihidden="false"
   unhidewhenused="false" name="Light Shading Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="61" semihidden="false"
   unhidewhenused="false" name="Light List Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="62" semihidden="false"
   unhidewhenused="false" name="Light Grid Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="63" semihidden="false"
   unhidewhenused="false" name="Medium Shading 1 Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="64" semihidden="false"
   unhidewhenused="false" name="Medium Shading 2 Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="65" semihidden="false"
   unhidewhenused="false" name="Medium List 1 Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="66" semihidden="false"
   unhidewhenused="false" name="Medium List 2 Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="67" semihidden="false"
   unhidewhenused="false" name="Medium Grid 1 Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="68" semihidden="false"
   unhidewhenused="false" name="Medium Grid 2 Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="69" semihidden="false"
   unhidewhenused="false" name="Medium Grid 3 Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="70" semihidden="false"
   unhidewhenused="false" name="Dark List Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="71" semihidden="false"
   unhidewhenused="false" name="Colorful Shading Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="72" semihidden="false"
   unhidewhenused="false" name="Colorful List Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="73" semihidden="false"
   unhidewhenused="false" name="Colorful Grid Accent 4"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="60" semihidden="false"
   unhidewhenused="false" name="Light Shading Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="61" semihidden="false"
   unhidewhenused="false" name="Light List Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="62" semihidden="false"
   unhidewhenused="false" name="Light Grid Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="63" semihidden="false"
   unhidewhenused="false" name="Medium Shading 1 Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="64" semihidden="false"
   unhidewhenused="false" name="Medium Shading 2 Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="65" semihidden="false"
   unhidewhenused="false" name="Medium List 1 Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="66" semihidden="false"
   unhidewhenused="false" name="Medium List 2 Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="67" semihidden="false"
   unhidewhenused="false" name="Medium Grid 1 Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="68" semihidden="false"
   unhidewhenused="false" name="Medium Grid 2 Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="69" semihidden="false"
   unhidewhenused="false" name="Medium Grid 3 Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="70" semihidden="false"
   unhidewhenused="false" name="Dark List Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="71" semihidden="false"
   unhidewhenused="false" name="Colorful Shading Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="72" semihidden="false"
   unhidewhenused="false" name="Colorful List Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="73" semihidden="false"
   unhidewhenused="false" name="Colorful Grid Accent 5"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="60" semihidden="false"
   unhidewhenused="false" name="Light Shading Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="61" semihidden="false"
   unhidewhenused="false" name="Light List Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="62" semihidden="false"
   unhidewhenused="false" name="Light Grid Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="63" semihidden="false"
   unhidewhenused="false" name="Medium Shading 1 Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="64" semihidden="false"
   unhidewhenused="false" name="Medium Shading 2 Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="65" semihidden="false"
   unhidewhenused="false" name="Medium List 1 Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="66" semihidden="false"
   unhidewhenused="false" name="Medium List 2 Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="67" semihidden="false"
   unhidewhenused="false" name="Medium Grid 1 Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="68" semihidden="false"
   unhidewhenused="false" name="Medium Grid 2 Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="69" semihidden="false"
   unhidewhenused="false" name="Medium Grid 3 Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="70" semihidden="false"
   unhidewhenused="false" name="Dark List Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="71" semihidden="false"
   unhidewhenused="false" name="Colorful Shading Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="72" semihidden="false"
   unhidewhenused="false" name="Colorful List Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="73" semihidden="false"
   unhidewhenused="false" name="Colorful Grid Accent 6"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="19" semihidden="false"
   unhidewhenused="false" qformat="true" name="Subtle Emphasis"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="21" semihidden="false"
   unhidewhenused="false" qformat="true" name="Intense Emphasis"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="31" semihidden="false"
   unhidewhenused="false" qformat="true" name="Subtle Reference"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="32" semihidden="false"
   unhidewhenused="false" qformat="true" name="Intense Reference"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="33" semihidden="false"
   unhidewhenused="false" qformat="true" name="Book Title"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="37" name="Bibliography"/&gt;
  &amp;lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"/&gt;
 &amp;lt;/w:latentstyles&gt;
&amp;lt;/xml&gt;&amp;lt;![endif]--&gt;
&amp;amp;amp;amp;amp;amp;amp;amp;lt;!--
 /* Font Definitions */
 @font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;
	mso-font-charset:2;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:0 268435456 0 0 -2147483648 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:1;
	mso-generic-font-family:roman;
	mso-font-format:other;
	mso-font-pitch:variable;
	mso-font-signature:0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1073750139 0 0 159 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.0pt;
	margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;
	text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-noshow:yes;
	mso-style-priority:99;
	color:purple;
	mso-themecolor:followedhyperlink;
	text-decoration:underline;
	text-underline:single;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	mso-style-unhide:no;
	mso-style-qformat:yes;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.0pt;
	margin-left:.5in;
	mso-add-space:auto;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
p.MsoListParagraphCxSpFirst, li.MsoListParagraphCxSpFirst, div.MsoListParagraphCxSpFirst
	{mso-style-priority:34;
	mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-type:export-only;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	mso-add-space:auto;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
p.MsoListParagraphCxSpMiddle, li.MsoListParagraphCxSpMiddle, div.MsoListParagraphCxSpMiddle
	{mso-style-priority:34;
	mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-type:export-only;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	mso-add-space:auto;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
p.MsoListParagraphCxSpLast, li.MsoListParagraphCxSpLast, div.MsoListParagraphCxSpLast
	{mso-style-priority:34;
	mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-type:export-only;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.0pt;
	margin-left:.5in;
	mso-add-space:auto;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
.MsoPapDefault
	{mso-style-type:export-only;
	margin-bottom:10.0pt;
	line-height:115%;}
@&amp;amp;amp;amp;amp;amp;amp;lt;a href="&lt;a href="http://page.soup.io&amp;quot;&amp;amp;amp;amp;amp;amp;amp;gt;page&amp;amp;amp;amp;amp;amp;amp;lt;/a&amp;amp;amp;amp;amp;amp;amp;gt"&gt;http://page.soup.io&amp;quot;&amp;amp;amp;amp;amp;amp;amp;amp;gt;page&amp;amp;amp;amp;amp;amp;amp;amp;lt;/a&amp;amp;amp;amp;amp;amp;amp;amp;gt&lt;/a&gt;; Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:1023358003;
	mso-list-type:hybrid;
	mso-list-template-ids:-1676016582 67698689 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:&#61623;;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--&amp;amp;amp;amp;amp;amp;amp;amp;gt;
&amp;lt;!--[if gte mso 10]&gt;
&amp;lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin-top:0in;
	mso-para-margin-right:0in;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&amp;lt;/style&gt;
&amp;lt;![endif]--&gt;

&lt;p&gt;A &lt;a href="http://newschoolsecurity.com/2009/10/how-to-value-digital-assets-web-sites-etc/"&gt;recent&lt;/a&gt;
&lt;a href="http://blogs.forrester.com/srm/2009/10/information-asset-value-some-coldhearted-calculations-.html"&gt;flurry&lt;/a&gt;
of &lt;a href="http://communities.intel.com/community/openportit/it/blog/2009/10/22/how-to-value-digital-assets"&gt;blog&lt;/a&gt;
&lt;a href="http://newschoolsecurity.com/2009/10/on-the-value-of-digital-asset-value-for-security-decisions/"&gt;posts&lt;/a&gt;
by some very smart people has reminded me of how in my former life at Microsoft,
I often found myself in meetings whose agenda included tallying up the
so-called "digital assets" related to a given project.&lt;br /&gt;
&lt;br /&gt;
For the uninitiated, the "digital asset" is the starting point in
pretty much every formal and semi-formal IT risk analysis exercise, to
wit:&#160; What are we protecting, after all, if not assets? What uniquely
digital threats imperil these assets, and how awful would it be if any of those
threats should be realized, and what are the potential mitigations for each
threat, and what is the cost of each contemplated mitigation, and can I somehow
avoid being summoned to any more of these meetings, or do I need to step up my
search for a new position in the company?&lt;/p&gt;

&lt;p&gt;Granted, as a starting point for getting a handle on your
security spend, it seems only reasonable to boil everything down to a finite
list of items. &#160;The obvious next step is,
let&#8217;s appraise the items in our list according to some kind of valuation scheme,
and start sorting.&#160; There&#8217;s &lt;a href="http://www.cert.org/octave/"&gt;plenty&lt;/a&gt; of &lt;a href="http://www.octotrike.org/"&gt;methodologies&lt;/a&gt; to &lt;a href="http://msdn.microsoft.com/en-us/security/aa570413.aspx"&gt;pick&lt;/a&gt; &lt;a href="http://newschoolsecurity.com/2009/10/how-to-value-digital-assets-web-sites-etc/"&gt;from&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Except that we&#8217;re not &lt;a href="http://www.theonion.com/content/news/tina_turner_burns_down_legs_for"&gt;insuring
Tina Turner&#8217;s legs&lt;/a&gt; here.&#160; I contend that there is &lt;i&gt;no useful relationship &lt;/i&gt;between
asset value and loss-per-incident.&lt;/p&gt;

&lt;p&gt;With that claim in mind, let&#8217;s review the types of costs
associated with typical real-world hacking incidents, and ask ourselves which
of these costs will vary according to some pre-estimated value of the compromised
digital assets:&lt;/p&gt;&lt;p&gt;* Engagement of incident response specialists&lt;br /&gt;* Damage to reputation / loss of future business&lt;br /&gt;* Loss of business advantage (e.g., leakage of details concerning payroll, pending deals, R&amp;amp;D, etc.)&lt;br /&gt;* Direct financial loss (e.g., fraudulent transactions)&lt;br /&gt;* Disruption of regular business operations&lt;br /&gt;* Fines and penalties&lt;/p&gt;&lt;p&gt;&amp;lt;!--[if !supportLists]--&gt;Actually, I wrote that list in order, ranging from &#8220;no
relationship to asset values&#8221; to &#8220;perhaps some vague, tenuous relationship.&#8221;&lt;/p&gt;

&lt;p&gt;Sure, the cost of an hour&#8217;s operational disruption might be
estimable in advance, especially when service level agreements are in place.&#160; But when we attempt to quantify the cost of
downtime, are we even talking about &lt;i&gt;assets&lt;/i&gt;
any more?&lt;/p&gt;

And is it possible that when we fetishize over
the valuations of individual data assets, we&#8217;re taking our eyes off the
loss-avoidance ball?</description><pubDate>Mon, 26 Oct 2009 06:53:09 GMT</pubDate><link>http://soup.rachner.us/post/32537875/A-Grain-of-Salt-for-Digital-Asset</link><guid isPermaLink="false">urn:www-soup-io:1:32537875</guid><category domain="contenttype">regular</category><category domain="tag">threat modeling</category><category domain="tag">doingitwrong</category></item>
<item><title>Rebooting.</title>
<description>It's been quite a while since my old blog was a casualty of the &lt;a href="http://simonwillison.net/2007/Jun/6/dreamhost/"&gt;Dreamhost hacking incident&lt;/a&gt;, and I've been more than a little remiss about restoring things.&lt;br /&gt;&lt;br /&gt;But Soup.io seems to be a pretty cool way to publish, so I'm giving it a whirl.&lt;br /&gt;&lt;br /&gt;Those of you looking for Alcatraz, GPCul8r, or Scurvy will find them published again on this page in the very near future.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;- Eric&lt;br /&gt;</description><pubDate>Tue, 31 Mar 2009 09:21:35 GMT</pubDate><link>http://soup.rachner.us/post/16474727/Rebooting</link><guid isPermaLink="false">urn:www-soup-io:1:16474727</guid><category domain="contenttype">regular</category></item>
  </channel>
</rss>
