<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tuesdaynight &#187; Security</title>
	<atom:link href="http://www.tuesdaynight.org/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tuesdaynight.org</link>
	<description>spots of thoughts: ian glazer and friends rant, rave and ruminate</description>
	<lastBuildDate>Sun, 11 Sep 2011 18:33:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The role of design in protecting cyberspace: thoughts from CFP 2009</title>
		<link>http://www.tuesdaynight.org/2009/06/08/the-role-of-design-in-protecting-cyberspace-thoughts-from-cfp-2009.html</link>
		<comments>http://www.tuesdaynight.org/2009/06/08/the-role-of-design-in-protecting-cyberspace-thoughts-from-cfp-2009.html#comments</comments>
		<pubDate>Mon, 08 Jun 2009 16:56:24 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Burton Group]]></category>
		<category><![CDATA[cfp09]]></category>
		<category><![CDATA[cybersecurity]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/?p=559</guid>
		<description><![CDATA[<p>Among the sessions in this year’s Computers Freedom and Privacy conference was a panel on the recently released National review of cyber-security. Ed Felten presented three related areas that he believes have to be improved in equal measure to improve overall cyber-security:</p> Product development System administration User behavior <p>But, to me, there was something missing from the [...]]]></description>
			<content:encoded><![CDATA[<p>Among the sessions in this year’s Computers Freedom and Privacy conference was a panel on the recently released National review of cyber-security. <a href="http://www.cs.princeton.edu/%7Efelten/">Ed Felten</a> presented three related areas that he believes have to be improved in equal measure to improve overall cyber-security:</p>
<ol>
<li>Product development</li>
<li>System administration</li>
<li>User behavior</li>
</ol>
<p>But, to me, there was something missing from the list – product design.</p>
<p>Too often I have seen products whose user interface, in fact its entire user experience, was constructed after the fact.   First the special sauce gets codified, then the chrome is put on and product gets a face.  It is easy to recognize products that have been built in this way as they tend to expose their internal data models to users, forcing users to adopt the metaphors of the engineers that built the product in the first place.  These types of products make problems internal to the product problems for the end-user and this can lead to very bad things.  See Three Mile Island as an example.  Poor user experience design leads to so-called “user error,” but is it really user error if the end-user is confronted with meaningless alarms, confusing error messages, and misleading feedback?</p>
<p>At CFP, I talked to <a href="http://www.schneier.com/blog/">Bruce Schneier</a> his research that went into <a href="http://www.schneier.com/book-beyondfear.html">Beyond Fear</a> to get a better understanding of the psychology of fear and its relation to security.  As you probably know, humans (and other animals too) are fantastically bad about evaluating risk. Optimism bias and other factors cause us to either over or under-estimate risks. Combine this with the fact that how choices are presented directly influences how choices are made and you realize the crucial need to build better user experiences for security (frankly, all) products.</p>
<p>“Is everything okay with the mother ship and should we blow up Russia?” This is the question presented <a href="http://www.imdb.com/title/tt0086856/">Buckaroo Bonzai</a> and I think I’ve seen a form of it as a dialogue box in Windows.  Would it be considered user error if an end-user pressed the “Yes” button and nuked Moscow? Bad design is at the least confusing and at the worst dangerous.</p>
<p>I did talk to Ed afterwards and he acknowledged the role of design in product development. As he said, if we only attempt to improve one of the three areas product devolvement or system administration or user behavior we won’t improve cyber-security; we have to improve all three.  User experience design as a part of an improved product development processes can directly lead to better more informed user behavior. Okay you product managers and designers make your voices heard – better safer products through better design!</p>
<p>(Cross-posted from Burton Group&#8217;s <a href="http://identityblog.burtongroup.com/bgidps/2009/06/the-role-of-design-in-protecting-cyberspace-thoughts-from-cfp-2009.html">Identity Blog</a>.)</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2009/01/29/putting-privacy-controls-in-the-hands-of-your-users.html" rel="bookmark" class="crp_title">Putting privacy controls in the hands of your users</a></li><li><a href="http://www.tuesdaynight.org/2005/12/19/taking-security-out-of-the-hands-of-users.html" rel="bookmark" class="crp_title">Taking security out of the hands of users</a></li><li><a href="http://www.tuesdaynight.org/2008/02/08/filling-the-holes-thoughts-on-an-emccourion-combo.html" rel="bookmark" class="crp_title">Filling the holes: thoughts on an EMC/Courion combo</a></li><li><a href="http://www.tuesdaynight.org/2007/08/06/a-simple-description-of-user-provisioning.html" rel="bookmark" class="crp_title">A Simple Description of User Provisioning</a></li><li><a href="http://www.tuesdaynight.org/2007/05/30/i-do-my-best-reading-in-oklahoma-notes-on-the-synthesis-of-form.html" rel="bookmark" class="crp_title">I do my best reading in Oklahoma: Notes on the Synthesis of Form</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2009/06/08/the-role-of-design-in-protecting-cyberspace-thoughts-from-cfp-2009.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>I&#8217;ll keep my paper passport, thanks</title>
		<link>http://www.tuesdaynight.org/2009/02/03/ill-keep-my-paper-passport-thanks.html</link>
		<comments>http://www.tuesdaynight.org/2009/02/03/ill-keep-my-paper-passport-thanks.html#comments</comments>
		<pubDate>Tue, 03 Feb 2009 13:58:28 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[epassport]]></category>
		<category><![CDATA[pia]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Travel]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/?p=513</guid>
		<description><![CDATA[<p>Here is a short piece on how a researcher, Chris Paget, bought a $250 RFID reader on eBay and used it to clone ePassports while driving 30 miles an hour near Fisherman&#8217;s Wharf in San Francisco.  I fully recognize that this demonstration doesn&#8217;t represent a method for fabricating complete paper-in-hand cloned passports.  Cloning is just the first [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://darkreading.com/security/privacy/showArticle.jhtml?articleID=213000321&amp;cid=RSSfeed">Here is a short</a> piece on how a researcher, Chris Paget, bought a $250 RFID reader on eBay and used it to clone ePassports while driving 30 miles an hour near Fisherman&#8217;s Wharf in San Francisco.  I fully recognize that this demonstration doesn&#8217;t represent a method for fabricating complete paper-in-hand cloned passports.  Cloning is just the first step, but it is a big step.  More importantly, it is a step that the State department has is somewhere between impossible and unlikely.  The following is a passage from the <a href="http://www.state.gov/documents/organization/109087.pdf">privacy impact assessment (PIA) of TDIS &#8211; the Travel Document Issuance System</a>:</p>
<p>The Department of State has taken extensive measures to prevent a third-party from reading or accessing the information on the chip without the passport holder’s knowledge. <em><strong>This includes safeguards against such nefarious acts as “skimming” data from the chip, “eavesdropping” on communications between the chip and reader, “tracking” passport holders, and “cloning” the passport chip in order to facilitate identity theft crimes.</strong></em> These safeguards are described in detail on the Department of State website.</p>
<p>Apparently those safeguards aren&#8217;t very strong.  </p>
<p>I invite you to read the <a href="http://travel.state.gov/passport/eppt/eppt_2788.html">State Department&#8217;s FAQ on e-Passports</a>.  Notice the incredibly defensive tone in the opening of the answer to the question, &#8220;Will someone be able to read or access the information on the chip without my knowledge (also known as skimming or eavesdropping)?&#8221;  Also notice the tacit acknowledgment that passport RFID chips can be cloned.</p>
<p>Mr. Paget intends on driving around DC this weekend to see what he can clone, and with a macbre sense of humor, I look forward to reading his results.</p>
<p>Until then, I&#8217;ll keep my paper passport.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2008/10/23/chains-of-trust-questionable-origins.html" rel="bookmark" class="crp_title">Chains of trust, questionable origins</a></li><li><a href="http://www.tuesdaynight.org/2003/04/26/12.html" rel="bookmark" class="crp_title">12%</a></li><li><a href="http://www.tuesdaynight.org/2009/07/21/laplace%e2%80%99s-demon-santa-claus-and-tsa%e2%80%99s-secure-flight.html" rel="bookmark" class="crp_title">Laplace’s Demon, Santa Claus and TSA’s Secure Flight</a></li><li><a href="http://www.tuesdaynight.org/2009/05/15/privacy-risks-get-real-%e2%80%93-california-privacy-laws-octomom-and-kaiser-permanente.html" rel="bookmark" class="crp_title">Privacy Risks Get Real – California Privacy Laws, Octomom, and Kaiser Permanente</a></li><li><a href="http://www.tuesdaynight.org/2006/07/13/nac-stands-for-what-part-2.html" rel="bookmark" class="crp_title">NAC stands for what? Part 2</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2009/02/03/ill-keep-my-paper-passport-thanks.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Chains of trust, questionable origins</title>
		<link>http://www.tuesdaynight.org/2008/10/23/chains-of-trust-questionable-origins.html</link>
		<comments>http://www.tuesdaynight.org/2008/10/23/chains-of-trust-questionable-origins.html#comments</comments>
		<pubDate>Thu, 23 Oct 2008 13:47:54 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[chain of trust]]></category>
		<category><![CDATA[credit card fraud]]></category>
		<category><![CDATA[epassport]]></category>
		<category><![CDATA[forgery]]></category>
		<category><![CDATA[real id]]></category>
		<category><![CDATA[rfid]]></category>
		<category><![CDATA[tcb]]></category>
		<category><![CDATA[trusted computing base]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/?p=440</guid>
		<description><![CDATA[<p>If I wanted to print US Dollars at home, I&#8217;d need the printing equipment, the paper stock on which to do it, and the magical ink.  To thwart me, the government controls access to the printing plates, blank paper stock, and ink.  This, of course, hasn&#8217;t stopped people from trying to print money, but their [...]]]></description>
			<content:encoded><![CDATA[<p>If I wanted to print US Dollars at home, I&#8217;d need the printing equipment, the paper stock on which to do it, and the magical ink.  To thwart me, the government controls access to the printing plates, blank paper stock, and ink.  This, of course, hasn&#8217;t stopped people from trying to print money, but their produced fake money can be detected as fake because they do not have access to the real plates, stock, and ink.  Because the government tightly controls access to the original materials and the flow raw materials into the printing process, our money can be trusted.  (Financial crisis and the government&#8217;s predilection to just print heaps of dollars not withstanding.)</p>
<p>The government has not implemented the same model in the case of identification systems: passports and REAL ID driver&#8217;s licenses.</p>
<p>Consider <a href="http://www.washingtontimes.com/news/2008/mar/26/outsourced-passports-netting-govt-profit-56284974/print/">this article from the Washington Times</a>.  The raw materials to make a new RFID passport, namely, the blank covers with RFID chips in them, originate in Thailand.  They are then shipped here for printing and binding.  The control over access to this supply-line seems to be very weak.</p>
<p>The new RFID passports are part of a chain of trust.  Border Control allows me to re-enter the country if the passport is trustworthy and valid.  Cloning passports has been demonstrated to be a trivial process.  So one trustworthy passport can become an infinite number of trustworthy passports.  The chain of trust extends from me and the INS at the airport, back to the passport issuance office, to the State Department, to Thailand, and back to Europe where the RFID chips are made.  If any link along the chain cannot be trusted, then the entire chain of trust breaks.  And this seems to be the case.</p>
<p>This is similar to REAL ID.  In this case, municipal Departments of Motor Vehicles are responsible for protecting access to blank REAL ID stock.  That, in and of itself, isn&#8217;t any different than what happens today.  By transforming the driver&#8217;s license from a piece of plastic that says I am allowed to drive, into a proof of citizenship, REAL ID extends the chain of trust in new ways.  DMVs have been and are relatively weak targets.  This breaks this newly extended chain of trust.</p>
<p>The government, if it wants to establish and extend chains of trust, it <strong><em>must</em></strong> control the flow of raw materials into the process and must ensure that each step is trustworthy.</p>
<p>And if you think I am picking on the government, <a href="http://online.wsj.com/article/SB122366999999723871.html">here&#8217;s a third example</a> that doesn&#8217;t involve the US government.  It appears that credit card readers we altered during their construction.  These altered readers were indistinguishable from their unaltered peers.  These altered readers sent account data to unknown people in Pakistan.  Swipe a card to pay for groceries and off your data goes.  In this case, the last stop in the payment card chain of trust was effected.  If I cannot trust the card reader not to send my account information to someone I do not know, do not have a relationship with, and inherently do not trust,  then I will stop swiping my cards and just order things online or pay cash.</p>
<p>A system designed to broker trust must consider the extent of its chain of trust.  Each link in the chains must be fully vetted and strengthened.  Until I see evidence of that, I am still going to keep hold of my non-RFID passport.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2009/02/03/ill-keep-my-paper-passport-thanks.html" rel="bookmark" class="crp_title">I&#8217;ll keep my paper passport, thanks</a></li><li><a href="http://www.tuesdaynight.org/2008/07/23/chasing-the-magical-grc-animal.html" rel="bookmark" class="crp_title">Chasing the magical GRC animal</a></li><li><a href="http://www.tuesdaynight.org/2010/09/10/notes-from-the-government-as-identity-oracle-session-at-iiw-east.html" rel="bookmark" class="crp_title">Notes from the &#8220;Government as Identity Oracle&#8221; session at IIW East</a></li><li><a href="http://www.tuesdaynight.org/2006/06/12/can-i-see-some-id.html" rel="bookmark" class="crp_title">Can I see some ID?</a></li><li><a href="http://www.tuesdaynight.org/1999/11/08/arent-monopolies-fun.html" rel="bookmark" class="crp_title">Aren&#8217;t monopolies fun?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2008/10/23/chains-of-trust-questionable-origins.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>This week&#8217;s installment of security theater</title>
		<link>http://www.tuesdaynight.org/2008/10/17/this-weeks-installment-of-security-theater.html</link>
		<comments>http://www.tuesdaynight.org/2008/10/17/this-weeks-installment-of-security-theater.html#comments</comments>
		<pubDate>Fri, 17 Oct 2008 15:34:02 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/?p=438</guid>
		<description><![CDATA[<p>Jeffery Goldberg of The Atlantic tries to get arrested at a variety of US airports&#8230; and fails.  He even traveled with Bruce Schneier and you&#8217;d think by know that Bruce&#8217;s picture would have been handed to every single TSA employee with a caption like, &#8220;Known security expert.  Known to claim that Kip Hawley isn&#8217;t wearing [...]]]></description>
			<content:encoded><![CDATA[<p>Jeffery Goldberg of The Atlantic tries to get <a href="http://www.theatlantic.com/doc/200811/airport-security">arrested at a variety of US airports</a>&#8230; and fails.  He even traveled with Bruce Schneier and you&#8217;d think by know that Bruce&#8217;s picture would have been handed to every single TSA employee with a caption like, &#8220;Known security expert.  Known to claim that Kip Hawley isn&#8217;t wearing any clothes.  Assume everything he tells you is a lie.  Assume he knows your private key.&#8221;</p>
<p>Now if someone can produce a mashup of people mocking security theater and  <a href="http://tv.boingboing.net/2008/10/10/john-hodgman-in-bbtv-1.html">John Hodgman&#8217;s SPAMasterpiece Theater</a> over on <a href="http://tv.boingboing.net">boing boing TV</a>, that would be awesome!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2007/12/31/a-view-from-the-cockpit-more-on-security-theater.html" rel="bookmark" class="crp_title">A view from the cockpit: More on security theater</a></li><li><a href="http://www.tuesdaynight.org/2007/01/18/who-wants-to-be-a-security-actor.html" rel="bookmark" class="crp_title">Who wants to be a security actor</a></li><li><a href="http://www.tuesdaynight.org/2006/12/19/nyt-on-airport-security.html" rel="bookmark" class="crp_title">NYT on Airport Security</a></li><li><a href="http://www.tuesdaynight.org/2006/12/20/more-fun-with-airport-insecurity.html" rel="bookmark" class="crp_title">More fun with airport (in)security</a></li><li><a href="http://www.tuesdaynight.org/2006/01/06/default-security.html" rel="bookmark" class="crp_title">Default Security</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2008/10/17/this-weeks-installment-of-security-theater.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Photography in DC</title>
		<link>http://www.tuesdaynight.org/2008/07/23/photography-in-dc.html</link>
		<comments>http://www.tuesdaynight.org/2008/07/23/photography-in-dc.html#comments</comments>
		<pubDate>Wed, 23 Jul 2008 14:43:58 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Photography]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[dc]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/?p=378</guid>
		<description><![CDATA[<p>As you probably know, I live in Washington DC.  I take photographs in DC as well.  We&#8217;ve got a few quirky rules here about that.  For example, if you are on National Park land, you cannot use any photographic equipment that touches the ground.  As you can imagine using tripods becomes a bit tricky.  But [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.tuesdaynight.org/v/jefferson/"><img class="g2image_float_left" title="10.imgp0289.3.jpg" src="http://www.tuesdaynight.org/gallery2/d/385-3/10_imgp0289_3.jpg?g2_GALLERYSID=034a05a9ebeb5840665ada58090ae750" alt="10.imgp0289.3.jpg" width="150" height="150" /></a>As you probably know, I live in Washington DC.  I take photographs in DC as well.  We&#8217;ve got a few quirky rules here about that.  For example, if you are on National Park land, you cannot use any photographic equipment that touches the ground.  As you can imagine using tripods becomes a bit tricky.  But beyond that, I haven&#8217;t heard of many photographers getting harassed in the name of security, unlike Chicago and London.  Then I <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/07/22/AR2008072202671.html?nav=rss_metro">read this piece in the Post</a> today.  Glad to see that Eleanor Holmes Norton getting involved.  Her <a href="http://www.fas.org/sgp/congress/2007/opensoc.html">Open Society with Security Act</a> bill is certainly intriguing.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2008/08/13/mcsweeneys-28-unboxing.html" rel="bookmark" class="crp_title">McSweeney&#8217;s 28 unboxing</a></li><li><a href="http://www.tuesdaynight.org/2007/06/16/see-the-jefferson-memorial-before-it-sinks.html" rel="bookmark" class="crp_title">See the Jefferson Memorial before it sinks</a></li><li><a href="http://www.tuesdaynight.org/2007/07/08/santa-fe-wrap-up.html" rel="bookmark" class="crp_title">Santa Fe wrap-up</a></li><li><a href="http://www.tuesdaynight.org/2008/03/09/back-from-pune.html" rel="bookmark" class="crp_title">Back from Pune</a></li><li><a href="http://www.tuesdaynight.org/2008/04/08/tequila-shot-lemondrop-how-you-doin.html" rel="bookmark" class="crp_title">&#8220;Tequila shot.  Lemondrop.  How YOU doin&#8217;?&#8221;</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2008/07/23/photography-in-dc.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chasing the magical GRC animal</title>
		<link>http://www.tuesdaynight.org/2008/07/23/chasing-the-magical-grc-animal.html</link>
		<comments>http://www.tuesdaynight.org/2008/07/23/chasing-the-magical-grc-animal.html#comments</comments>
		<pubDate>Wed, 23 Jul 2008 13:55:14 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Professional]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Burton Group]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/?p=376</guid>
		<description><![CDATA[<p>I&#8217;m sure you&#8217;ve been following the Terry Childs case. Mr. Childs was a sysadmin in San Francisco who decided to change a few passwords and thus locked the city out of their new wide area network. Though it is still not clear why Mr. Childs did this, he had been recently written up for poor [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m sure you&#8217;ve been following the Terry Childs case. Mr. Childs was a sysadmin in San Francisco who decided to change a few passwords and thus locked the city out of their new wide area network. Though it is still not clear why Mr. Childs did this, he had been recently written up for poor job performance. </p>
<p>Among others, Matt Pollicove wrote <a href="http://idm-thoughtplace.blogspot.com/2008/07/insider-threat.html">about this</a> and the need for trust.  Matt asserts that trust is a must and I completely agree. That being said, the last two points in his post are mistaken.</p>
<p>First he says:</p>
<blockquote><p>This means, making sure there&#8217;s no orphan or rogue accounts in the systems.</p></blockquote>
<p>While this is a generally accepted good practice, it would not have necessarily helped San Francisco keep from losing their network. Privileged account management would have been far more useful.  Discipline and control around how sysadmins gain access to and use root-like accounts, the bread and butter of privileged account management, would have helped avert some of San Francisco&#8217;s problems.</p>
<p>Second Matt says:</p>
<blockquote><p>GRC tools will be a must in this verification.</p></blockquote>
<p>This first thing that springs to my mind is a question: what aspect of governance, risk management, and compliance would have helped the city of San Francisco in this case? A good governance and risk identification and management process would have helped a great deal.  But we have to keep in mind there is no such thing as a GRC tool; there is no such animal.  In fact, GRC is starting to sound like the wonderful magical bacon animal that H<a href="http://www.imdb.com/title/tt0701158/quotes">omer Simpson dreams of</a>. If pork chops, ham and bacon all come from the magical animal in the Simpsons, then privileged account management, orphan account management and provisioning all come from the magical GRC animal. Where does it end?  The reality is that the industry has confused the benefits of good governance processes and risk management capabilities with automation tools that aid, but never replaces, those processes and capabilities.</p>
<p>Privileged account management is not and should not be considered part of the marketing fog of GRC. Does the controlled management of root-like accounts constitute good operating procedure and help reduce risk?  Absolutely. But that doesn&#8217;t make privileged account management a GRC technology.  Is orphan account removal a critical process from a security and risk mitigation perspective?  Of course. However, that doesn&#8217;t mean the technologies to do that are GRC technologies.</p>
<p>Specificity of language is crucial. Telling the city of San Francisco that the solution to their problems lay within &#8220;GRC&#8221; would have done little except lengthen the time to finding what their real problems were.  Our industry cannot take the easy route and lump every possible technology and procedure under the sun onto the GRC heap or else we&#8217;ll find ourselves chasing Homer&#8217;s magical bacon animal.</p>
<div></div>
<div><em>Originally posted on <a href="http://bgidps.typepad.com/bgidps/2008/07/chasing-the-mag.html">Burton Group&#8217;s Identityblog</a></em></div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2008/09/04/thinking-about-matts-simple-question-correlating-accounts-and-people.html" rel="bookmark" class="crp_title">Thinking about Matt&#8217;s Simple Question: Correlating accounts and people</a></li><li><a href="http://www.tuesdaynight.org/2007/10/11/oracle-buys-logicalapps-approva-remains-the-land-of-freedom.html" rel="bookmark" class="crp_title">Oracle buys LogicalApps: Approva Remains the Land of Freedom</a></li><li><a href="http://www.tuesdaynight.org/2007/05/15/sap-buys-maxware-column-fodder-in-the-fight-against-oracle.html" rel="bookmark" class="crp_title">SAP buys MaXware: Column Fodder in the Fight against Oracle</a></li><li><a href="http://www.tuesdaynight.org/2007/01/24/thoughts-on-relational-continuity-sockets-layer.html" rel="bookmark" class="crp_title">Thoughts on Relational Continuity Sockets Layer</a></li><li><a href="http://www.tuesdaynight.org/2007/04/06/you-mean-people-actually-use-this-stuff.html" rel="bookmark" class="crp_title">You mean people actually use this stuff?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2008/07/23/chasing-the-magical-grc-animal.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Schneier on CCTV in the Guardian</title>
		<link>http://www.tuesdaynight.org/2008/07/15/schneier-on-cctv-in-the-guardian.html</link>
		<comments>http://www.tuesdaynight.org/2008/07/15/schneier-on-cctv-in-the-guardian.html#comments</comments>
		<pubDate>Tue, 15 Jul 2008 13:09:22 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cctv]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/?p=371</guid>
		<description><![CDATA[<p>Continuing my thread on CCTV cameras (here and here), Bruce Schneier wrote a solid summation of the issues of pervasive cameras.</p> Related Posts:Follow-up on &#8220;Surveillance Cameras in DC&#8221;But its such a lovely panopticon, I&#8217;d hate to have to return itD.C. to expand surveillance camera programPoorly spent funds: Surveillance cameras in DCPrivacy in Transition &#8211; No Kidding]]></description>
			<content:encoded><![CDATA[<p>Continuing my thread on CCTV cameras (<a href="http://www.tuesdaynight.org/2008/04/10/poorly-spent-funds-surveillance-cameras-in-dc.html">here</a> and <a href="http://www.tuesdaynight.org/2008/07/03/follow-up-on-surveillance-cameras-in-dc.html">here</a>), Bruce Schneier <a href="http://www.guardian.co.uk/technology/2008/jun/26/politics.ukcrime">wrote a solid summation</a> of the issues of pervasive cameras.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2008/07/03/follow-up-on-surveillance-cameras-in-dc.html" rel="bookmark" class="crp_title">Follow-up on &#8220;Surveillance Cameras in DC&#8221;</a></li><li><a href="http://www.tuesdaynight.org/2009/08/25/but-its-such-a-lovely-panopticon-id-hate-to-have-to-return-it.html" rel="bookmark" class="crp_title">But its such a lovely panopticon, I&#8217;d hate to have to return it</a></li><li><a href="http://www.tuesdaynight.org/2011/02/07/d-c-to-expand-surveillance-camera-program.html" rel="bookmark" class="crp_title">D.C. to expand surveillance camera program</a></li><li><a href="http://www.tuesdaynight.org/2008/04/10/poorly-spent-funds-surveillance-cameras-in-dc.html" rel="bookmark" class="crp_title">Poorly spent funds: Surveillance cameras in DC</a></li><li><a href="http://www.tuesdaynight.org/2008/08/18/privacy-in-transition-no-kidding.html" rel="bookmark" class="crp_title">Privacy in Transition &#8211; No Kidding</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2008/07/15/schneier-on-cctv-in-the-guardian.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Follow-up on &#8220;Surveillance Cameras in DC&#8221;</title>
		<link>http://www.tuesdaynight.org/2008/07/03/follow-up-on-surveillance-cameras-in-dc.html</link>
		<comments>http://www.tuesdaynight.org/2008/07/03/follow-up-on-surveillance-cameras-in-dc.html#comments</comments>
		<pubDate>Thu, 03 Jul 2008 20:28:21 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[big brother]]></category>
		<category><![CDATA[nanny state]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/?p=364</guid>
		<description><![CDATA[<p>Just a brief follow-up to my previous comments.  DC has written its regulations for this camera consolidation.  I have copied a version here.  Nice to see that the footage will be remained only for 10 days and then destroyed.  But it also seems like anyone can gain access to this footage if they ask nicely.</p> [...]]]></description>
			<content:encoded><![CDATA[<p>Just a brief follow-up to <a href="http://www.tuesdaynight.org/2008/04/10/poorly-spent-funds-surveillance-cameras-in-dc.html">my previous comments</a>.  DC has written its regulations for this camera consolidation.  I have copied a version <a href="http://www.tuesdaynight.org/wp-content/uploads/2008/07/regs.pdf">here</a>.  Nice to see that the footage will be remained only for 10 days and then destroyed.  But it also seems like anyone can gain access to this footage if they ask nicely.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2008/07/15/schneier-on-cctv-in-the-guardian.html" rel="bookmark" class="crp_title">Schneier on CCTV in the Guardian</a></li><li><a href="http://www.tuesdaynight.org/2008/04/10/poorly-spent-funds-surveillance-cameras-in-dc.html" rel="bookmark" class="crp_title">Poorly spent funds: Surveillance cameras in DC</a></li><li><a href="http://www.tuesdaynight.org/2011/02/07/d-c-to-expand-surveillance-camera-program.html" rel="bookmark" class="crp_title">D.C. to expand surveillance camera program</a></li><li><a href="http://www.tuesdaynight.org/2009/08/25/but-its-such-a-lovely-panopticon-id-hate-to-have-to-return-it.html" rel="bookmark" class="crp_title">But its such a lovely panopticon, I&#8217;d hate to have to return it</a></li><li><a href="http://www.tuesdaynight.org/2008/08/18/privacy-in-transition-no-kidding.html" rel="bookmark" class="crp_title">Privacy in Transition &#8211; No Kidding</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2008/07/03/follow-up-on-surveillance-cameras-in-dc.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Poorly spent funds: Surveillance cameras in DC</title>
		<link>http://www.tuesdaynight.org/2008/04/10/poorly-spent-funds-surveillance-cameras-in-dc.html</link>
		<comments>http://www.tuesdaynight.org/2008/04/10/poorly-spent-funds-surveillance-cameras-in-dc.html#comments</comments>
		<pubDate>Thu, 10 Apr 2008 05:35:32 +0000</pubDate>
		<dc:creator>Ian Glazer</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[big brother]]></category>
		<category><![CDATA[surveillance]]></category>

		<guid isPermaLink="false">http://www.tuesdaynight.org/2008/04/10/poorly-spent-funds-surveillance-cameras-in-dc.html</guid>
		<description><![CDATA[<p>I am especially sensitive to this as one of these camera units is a block and half from my house.  Questions that come to mind are: How long will the District retain footage from these cameras? Who will maintain this footage: law enforcement or emergency management? Can I as a citizen request to see footage as part of a [...]]]></description>
			<content:encoded><![CDATA[<p>I am especially sensitive to this as <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/04/09/AR2008040904048.html?hpid=moreheadlines">one of these camera units</a> is a block and half from my house.  Questions that come to mind are:
<ul>
<li>How long will the District retain footage from these cameras?</li>
<li>Who will maintain this footage: law enforcement or emergency management?</li>
<li>Can I as a citizen request to see footage as part of a FOIA request?</li>
<li>Will INS/FBI/ATF/other Federal law enforcement agencies have access to these cameras on an ongoing basis?</li>
</ul>
<div>As I mentioned there&#8217;s one of these cameras a block and half from my house.  It sits on a very heavily trafficked corner.  People stand there waiting for the bus.  There is a huge amount of vehicular traffic that goes right by it.  There is a 7-11 right there and there is always some flavor of law enforcement officer there. There is rare street crime in the area and when it does happen it happens blocks away on darker corners.  There is no way this camera prevents crime in any way shape or form.</div>
<div> </div>
<div>If the real goal is to prevent crime, instead of spending the $10 million to set this system up, put that cash to funding more neighborhood cops who walk a beat.    </div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.tuesdaynight.org/2008/07/03/follow-up-on-surveillance-cameras-in-dc.html" rel="bookmark" class="crp_title">Follow-up on &#8220;Surveillance Cameras in DC&#8221;</a></li><li><a href="http://www.tuesdaynight.org/2009/08/25/but-its-such-a-lovely-panopticon-id-hate-to-have-to-return-it.html" rel="bookmark" class="crp_title">But its such a lovely panopticon, I&#8217;d hate to have to return it</a></li><li><a href="http://www.tuesdaynight.org/2011/02/07/d-c-to-expand-surveillance-camera-program.html" rel="bookmark" class="crp_title">D.C. to expand surveillance camera program</a></li><li><a href="http://www.tuesdaynight.org/2008/07/15/schneier-on-cctv-in-the-guardian.html" rel="bookmark" class="crp_title">Schneier on CCTV in the Guardian</a></li><li><a href="http://www.tuesdaynight.org/2008/08/18/privacy-in-transition-no-kidding.html" rel="bookmark" class="crp_title">Privacy in Transition &#8211; No Kidding</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.tuesdaynight.org/2008/04/10/poorly-spent-funds-surveillance-cameras-in-dc.html/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

